Cases
Chepkoech Lorna & 22 Others vs Firch International Company Limited T/A Pesa Pay
Case Summary
Twenty-three Complainants lodged formal complaints with the Office of the Data Protection Commissioner (ODPC) against Firch International Company Limited, trading as Pesa Pay. The complaints alleged that the Respondent unlawfully accessed mobile phone contacts, sent unwarranted messages, demanded repayment of loans not owed, and disclosed personal data to third parties without consent. Additionally, one Complainant accused the Respondent of publishing his personal mobile number on the application interface without consent. The ODPC conducted investigations pursuant to the Data Protection Act, 2019 and relevant regulations. The Respondent acknowledged certain practices, including the use of users’ phonebook contacts by its external partners for debt collection, and claimed to have taken remedial steps such as contacting these partners to halt further messaging and expressing intent to terminate its operations in Kenya.
Issues for Determination
- Whether the Respondent obtained contacts from its clients’ phonebooks and contacted the Complainants regarding loans they had not consented to guarantee.
- Whether the Respondent put the personal mobile number of one of its employees on the face of its Pesa Pay application without his consent.
- Whether there was any infringement of the Complainants' rights as data subjects under the Data Protection Act, 2019.
Determination
The Respondent was found liable for:
- Accessing and using personal contact information from users’ phonebooks without proper consent from the Complainants.
- Publishing a Complainant’s mobile number on the Pesa Pay application without his consent and ignoring requests for its removal.
- Violating multiple provisions of the Data Protection Act, including Sections 26, 28, and 61, by failing to inform data subjects of processing purposes, collecting data indirectly, and obstructing the Data Commissioner.
An enforcement notice was issued against the Respondent, and the parties were advised of their right to appeal to the High Court.
Analysis
This case underscores the importance of obtaining explicit, informed consent from all data subjects before collecting or processing their personal data. The Respondent failed to comply with Section 28(1) of the Data Protection Act, which mandates that data should be collected directly from the data subject. Further, the use of personal data without notification violated Section 26, which guarantees the right to be informed, object, and request deletion.
By publishing an employee's mobile number without consent, the Respondent violated the rights to object to processing and to deletion. Its failure to remove the number even after requests highlights the importance of respecting data subject rights under Section 26 of the Data Protection Act. Additionally, its attempt to evade service of the complaint notification contravened Section 61, which prohibits obstruction of the Commissioner’s duties.
The determination reinforces the need for digital lenders and other entities to implement robust consent mechanisms, notify individuals of data use, and ensure transparency and accountability in personal data handling.