KEVIN KIPROTICH RONO vs. SBM BANK KENYA
1. Introduction
The case is in respect to the complainant, Kevin Kiprotich Rono against SBM Bank Kenya, on the receipt of multiple emails regarding PIN/Password/OTP alerts and promotional offers despite not being a customer. This action contravenes the Data Protection Act, 2019.
Table of Contents
2. Nature of Complaint
The complainant alleged that he received 327 emails from the Respondent since May 2023 consisting of PIN/Password/OTP alerts, login notifications, transaction alerts, password reset alerts, account statements, and promotional offers despite not being a customer. He further alleged that his numerous calls and emails instructing the Respondent to stop using his email address were ignored, and the Respondent raised several ticket numbers but took no action.
3. Analysis of Evidence
Complainant’s Position
- His email address contains his name as a personal identifier
- Made numerous calls to the Respondent’s customer care line instructing them to stop using his email
- Wrote to the Respondent five times on diverse dates in August 2023 instructing them to stop using his email address
- Attached a call log and emails sent to the Respondent as proof
Respondent’s Defense
- Stated the email address was provided by one of their customers with a similar name who opened a bank account on 12th April 2023
- Claimed they had no capacity to verify whether the email address belonged to a different person
- Argued the Complainant was not a customer and therefore they cannot be in breach of confidentiality
- Upon receipt of the complaint, they reached out to the customer who admitted inadvertently providing the wrong email address
- Claimed they expunged the Complainant’s email address from their database
4. Issues for Determination
- Whether there was a violation of the Complainant’s rights under the Act
- Whether the Complainant is entitled to any remedies under the Act and the attendant Regulations
5. Final Determination
The Data Commissioner found:
- The Respondent processed the Complainant’s personal data without a lawful basis.
- The Respondent failed to respond to the Complainant’s objections despite multiple calls and emails.
- The Respondent is liable for violation of the Complainant’s rights under the Act.
Orders:
- Compensation of Ksh 450,000 to the Complainant.
- The Respondent is directed to ensure it collects personal details from its customers in an accurate manner to avoid such incidents.
- Right of appeal to the High Court within 30 days.
6. Significance and Impact
Data Accuracy and Onboarding Procedures
- Establishes that banks must accurately capture customer data during onboarding
- Data controllers have an obligation to verify the accuracy of personal data they collect
Right to Object and Timely Response
- Reinforces the obligation of data controllers to respond to objections promptly
- Failure to act on objections constitutes a violation of the right to object
Broader Impact: Across Africa, inaccurate data capture during customer onboarding leads to the unlawful processing of third-party personal data. This determination establishes that financial institutions must implement robust verification mechanisms and respond promptly to data subject objections, setting a critical standard for data accuracy across the continent.