Cases Detail

Cases

Brian Githaiga v NCBA Bank Kenya LTD.

Country: Kenya
Court: ODPC
Status: Determination
Tags: Data subject rights

Case summary

The complainant lodged a case on the 29th May 2019, pursuant to section 56 of the Act and regulation by the advocates of the complainant, on their behalf. The respondent captured the wrong email address when the complainant opened a business account under Versatile enterprises with the Respondent’s Lavington Branch. A third party who was the owner of that email complained that they were receiving emails and details of various transactions. On the 7th February 2024, the complainant noticed that the respondent had not effected the change of email and was still sending details to the wrong email which is for a third party. The complainant stated that the respondent negligently declined to update the correct email business for the business and the third party still receives the transaction rights.The respondent refutes capturing the complainants wrong email address stating that it lawfully obtained and recorded the contact information provided by the complainant during the account opening process. The respondent conducted investigations and stated that the said email of the complainant that was erroneously captured, had been deleted on 3rd of July 2023. Both parties adduced various documents such as screenshots for evidence.

Issues for determination

  1. Whether there was an infringement of the complainants rights under the Act?
  2. Whether the complainant is entitled to any remedies under the Act and the attendant regulations?

Determination

The respondent was found liable for violating the complainant’s right to erasure under Section 40(1)(b) of the Act and therefore the respondent was ordered to erase the complainants email address from the complainants account and compensate ksh 250,000 to the complainant. The parties had a right to appeal within 30 days.

Analysis

The complainant had the right of erasure pursuant to Section 40(1)(b) of the Act. The section provides for the right of erasure and rectification. It states that a data subject may request a data controller to erase or destroy data without undue delay, personal data that the data controller is no longer authorized to retain or was obtained unlawfully. The complainant exercised this right by issuing written instruction to the respondent to delete her email address given she did not have an account with the respondent. Despite the respondents statement that the instructions for erasure were executed, the complainant adduced evidence to the contrary therefore the right of erasure of the respondent was violated.The complainant was entitled to remedies under Regulation 14(2) and 14(3)of the Enforcement Regulations. Therefore they sought for an order that the respondent should amend the business details as well as an entitlement for damages under sections 65(4) and 14(3)(e) of the Data protection Act.

Frequently Asked Questions

Frequently Asked Questions

A data subject is a natural person who is the subject of personal data held by a controller and who can be identified, directly or indirectly, through that personal data.

Each data subject has the right:

  • to be informed whether or not his or her personal data is being processed,
  • to request information about the processing, if data has been processed,
  • to be informed of the purpose of the processing and whether the data is being used in accordance with those purposes,
  • to be informed about third parties who receive personal data in Kenya and abroad,
  • to request the rectification of incomplete or inaccurate processed data, and
  • to request the erasure or destruction of personal data.

Data processing refers to any operation performed on personal data, either entirely or partially, automatically or manually. This includes collection, recording, storage, preservation, modification, revision, disclosure, transmission, assignment, making available, classification, or prevention of use.

Data controller: is a natural or legal person who determines the purposes and means of personal data processing and is accountable for the data filing system's establishment and administration.

Data processor: is a natural or legal person that processes personal data on the basis of a data controller's authorization.

The data controller or processor is required to provide the following information: the purpose of the processing, the recipients of the processed data and the purpose of the transfer, the method used to collect personal data and its legal basis, and any other rights granted to the data subject by law.

The principles governing data processing are as follows: it must be processed fairly and lawfully, it must be accurate and up to date, it must be processed for specified, explicit, and legitimate purposes, it must be adequate, relevant, and not excessive in relation to the purposes for which it is processed, and it must be retained for the duration specified by law or for no longer than is necessary for the subsequent processing.

A Data Protection Impact Assessment can be used to identify and mitigate high risks associated with data processing that may impact the rights and freedoms of data subjects.

A data controller is a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purpose and means of processing of personal data. On the other hand, a data processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller.