Key Details of the Data Protection Enforcement Action
The Office of the Data Protection Commissioner (ODPC) has taken a significant step in enforcing Kenya’s Data Protection Act, 2019. In a recent ruling, the ODPC ordered Liquid Telecommunications Kenya Ltd to compensate a complainant Sh700,000 for unlawfully processing personal data without consent. This decision marks one of the latest enforcement actions under the legislation, highlighting the regulator’s commitment to protecting individuals’ data rights.
According to the ODPC’s determination, Liquid Telecom was found to have recorded and processed the personal data of a complainant named Andrew Alston without his consent. Additionally, the company failed to honor his right to erasure as required by law. The case underscores the importance of transparency and accountability in data handling practices.
In her ruling, Data Commissioner Immaculate Kassait emphasized that the respondent violated the complainant’s right to be informed of the use of his personal data under Section 26(a) of the Act. She also noted that the company breached the complainant’s right to erasure under Section 40(1)(b). These violations demonstrate a clear disregard for the legal obligations imposed on data controllers.
The ODPC further pointed out that despite being notified of the data subject’s request for deletion, the company continued to process the complainant’s data “one year later.” This delay was deemed unreasonable and contrary to the data protection principles of lawful and fair processing. The regulator stressed the need for organizations to act promptly when individuals exercise their rights.
As a result of these findings, the regulator directed the telecom operator to pay Sh700,000 in compensation. An Enforcement Notice was also issued, compelling the company to comply with Kenya’s data protection framework. The notice serves as a formal warning to ensure that the company adheres to the legal requirements moving forward.
“Having found that the Respondent processed the Complainant’s personal data without a lawful basis, the Office hereby orders compensation and issues an Enforcement Notice to ensure compliance,” the ODPC stated in its ruling.
Implications of the Ruling
This enforcement action sets a precedent for how data protection laws are applied in Kenya. It signals to businesses that non-compliance with data protection regulations will not be tolerated. The ruling emphasizes the importance of obtaining proper consent and respecting individuals’ rights to control their personal data.
For companies operating in Kenya, this case serves as a reminder of the legal obligations they must uphold. Failure to do so can lead to financial penalties and damage to their reputation. The ODPC’s decision reinforces the role of regulatory bodies in ensuring that data protection laws are enforced effectively.
Steps for Compliance
Organizations handling personal data should take the following steps to ensure compliance with the Data Protection Act:
- Review their data processing activities to ensure they have a lawful basis for collecting and using personal data
- Implement procedures for handling data subject requests, including the right to erasure
- Provide clear and transparent information to individuals about how their data is used
- Train employees on data protection principles and legal requirements
By taking these steps, businesses can avoid potential legal issues and build trust with their customers.
Conclusion
The ODPC’s ruling against Liquid Telecommunications Kenya Ltd highlights the growing importance of data protection in Kenya. As more organizations collect and process personal data, it is essential that they adhere to the legal standards set forth in the Data Protection Act, 2019. This case serves as a reminder that data protection is not just a legal obligation but also a critical component of building trust and maintaining consumer confidence.