KENNEDY WAINAINA MBUGUA VERSUS BOLT OPERATIONS OU AND BOLT SUPPORT KENYA LIMITED
1. Introduction
The case is in respect to the complainant, Kennedy Wainaina Mbugua against Bolt Operations OU and Bolt Support Kenya Limited, on the unlawful access and processing of his personal information resulting in the disclosure of his Bolt driver account details to third parties for fraudulent purposes. This action is in breach of the Data Protection Act, 2019.
Table of Contents
2. Nature of Complaint
The complainant’s Bolt account was compromised, resulting in 17 fraudulent rides under his identity. Despite reporting to the Respondent and the police, no resolution was reached, and internal employees of the Respondent were found to be involved in the fraud.
3. Analysis of Evidence
Complainant’s Position
- On 15th May 2023, he was contacted by a lady regarding his Bolt account being used by a different driver
- Sent selfies holding a newspaper and his ID in an attempt to regain control of his account
- On 16th May 2023, his email and password were no longer recognized by the system
- Discovered unauthorized rides being taken under his account totalling an implausible distance within a short timeframe
- The 17 completed rides were all corporate rides with payments from corporate client banks
Respondent’s Defense
- Takes unlawful access and processing of personal data seriously and is committed to upholding the Act
- Processing of the Complainant’s personal data was necessary for the performance of the contract
- The incident was caused by a phishing attack where the Complainant shared his login credentials with perpetrators
- Identified procedural oversights involving customer support agents
- The outsourced customer support agent followed user verification guidelines that were not applicable to the Kenyan Market
4. Issues for Determination
- Whether there was a personal data breach with regards to the Complainant’s incident
- Whether there was an infringement of the Complainant’s rights under the Act
- Whether the Respondent fulfilled its obligations under the Act
- Whether the Complainant is entitled to any remedies under the Act and the attendant Regulations
5. Final Determination
The Data Commissioner found:
- The Respondent failed to recognize and act on the Complainant’s data subject rights requests.
- Procedural oversights in customer support led to the compromise of the Complainant’s account.
- The Respondent failed to conduct a Data Protection Impact Assessment as required under Section 31.
- The Respondent is liable for violation of the Complainant’s rights under the Act.
Orders:
- Compensation of Ksh 500,000 to the Complainant.
- An Enforcement Notice is issued against the Respondent.
- Right of appeal to the High Court within 30 days.
6. Significance and Impact
Personal Data Breach and Phishing
- Establishes that unauthorized access to user accounts constitutes a personal data breach under the Act
- Data controllers are liable for breaches even when caused by phishing, where procedural failures exist
Data Subject Rights and Customer Support
- Reinforces the obligation to recognize and act on data subject rights requests
- Human error in customer support does not absolve data controllers of liability
Broader Impact: Across Africa’s growing gig economy, ride-hailing platforms must implement robust safeguards to protect user data from phishing attacks. This determination establishes that platforms cannot rely on customer support errors or user negligence to avoid liability for data breaches.