Cases
Eric Migwi &Scholastica Onon vs- Whitepath Company Limited
Case Summary
The case involves Eric Mwangi and Scholastica Onon, who filed complaints against Whitepath Company Limited (the Respondent) with the Office of the Data Protection Commissioner in Kenya. The complaints revolve around the complainants allegedly receiving constant messages from the Respondent demanding payment as guarantors of loans they claim to know nothing about. In response to the complaints, the Respondent stated that the second complainant, Scholastica Onon, was listed as an emergency contact by a loan applicant named Anthony Mbatha, who applied for a loan from the Respondent. The Respondent claimed that Scholastica Onon was notified of this nomination as an emergency contact and did not opt out, thereby consenting. Upon receiving the Respondent's response, investigations were conducted as required by Regulation 13(1) of the Data Protection (Complaints Handling Procedure and Enforcement) Regulations 2021. The Data Protection Commissioner decided based on the findings of the investigations, as outlined in Regulation 14 of the same regulations.
Issues for Determination
- Whether the Respondent obtained valid consent from the complainant to process their personal data.
- Whether the complainant's personal information was handled per the law.
- Whether the complainant's personal information was lawfully processed.
Determination
Whitepath Company Limited was found liable for unlawfully processing the personal data of complainants Eric Mwangi and Scholastica Onon. The Commissioner determined that the Respondent failed to provide evidence demonstrating that the complainants had consented to the processing of their personal data, leading to the conclusion of unlawful data processing. An enforcement notice was issued to the Respondent, outlining corrective actions to address the non-compliance with data protection regulations. Additionally, all parties were informed of their right to appeal the decision to the High Court of Kenya, allowing for further legal review if desired.
Analysis
In this case, the key issues and analysis revolved around consent to data processing, communication of personal information, compliance with regulations, and liability.
● Consent to Data Processing: The primary issue was whether the Respondent obtained valid consent from the complainants to process their personal data. The Respondent had the burden of proof to establish consent. However, investigations revealed a lack of evidence supporting the Respondent's consent claim, leading to the determination that the Respondent processed the data unlawfully. Section 28 of the Data Protection Act on collecting personal data provides for circumstances where personal data may be indirectly collected, including where the data subject has consented to the collection from another source. Such consent was not given in this case; as such, the collection of the complainant’s personal information was unlawful.
● Communication of Personal Information: Another key issue was the Respondent's communication and handling of personal information. The complaints alleged that the Respondent demanded payment from the complainants as guarantors of loans they were unaware of. The Respondent's response regarding the second complainant being listed as an emergency contact without explicit consent raised concerns about transparency and proper handling of personal information. This links to section 29(b) of the Data Protection Act, which requires the data controller or processor to notify the data subject that their data is being collected.
● Compliance with Regulations : The case also focused on whether the Respondent complied with the Data Protection (Complaints Handling Procedure and Enforcement) Regulations 2021. The Respondent's response to the complaints, provision of requested information, and adherence to data protection policies were assessed to determine compliance with regulations. This analysis was essential in evaluating the Respondent's adherence to legal requirements.
● Liability and Enforcement: The final determination addressed the liability of the Respondent for unlawfully processing personal data. The issuance of an enforcement notice highlighted the need for corrective actions to rectify non-compliance with data protection regulations. Enforcement notices are prescribed under section 58, the purpose of which is to require the offender to take measures to remedy the breach in data or non-compliance within a specified period of time. Additionally, the burden of proof of establishing a data subject's consent lies with the data controller and processor per section 32(1).
This case holds significant implications for data protection and especially regulatory compliance. Addressing issues such as consent to data processing, communication of personal information, compliance with data protection regulations, and liability for unlawful data processing underscores the importance of upholding individuals' privacy rights and ensuring the lawful handling of personal data. The case serves as a reminder of the legal obligations and responsibilities associated with processing personal data, emphasising the need for organisations to raise awareness about data protection laws and regulations. It highlights the crucial role of regulatory authorities, like the Data Protection Commissioner, in enforcing regulations and holding organisations accountable for non-compliance. Moreover, the provision of legal remedies, such as enforcement notices and the right to appeal to the High Court of Kenya, underscores the availability of mechanisms for addressing data privacy violations and maintaining trust with data subjects. Overall, this case exemplifies the significance of respecting privacy rights, ensuring regulatory compliance, and providing avenues for redress in cases of data protection breaches.