ODPC SUO MOTU INVESTIGATION NO. ODPC/SM/0010/2024
ODPC SUO MOTU INVESTIGATION NO. ODPC/SM/0010/2024
ODPC VERSUS NALA MATERNITY & NURSING HOME LIMITED

1. Introduction

This matter concerns a suo motu investigation instituted by the Office of the Data Protection Commissioner, taking cognizance of public interest generated by Nala Maternity and Nursing Home Limited’s personal data processing practices as a medical facility handling high volumes of health data. This action is inconsistent with the Data Protection Act, 2019.

2. Nature of Investigation

The ODPC conducted a suo motu investigation into the Respondent’s data processing practices following concerns regarding inappropriate use of personal data, violation of data subjects’ rights, unlawful data transfers, and inadequate processing of collected data, including health data.

3. Analysis of Evidence

ODPC Investigative Findings
  • Not registered as a data controller or data processor
  • No functional data governance framework, data protection policy, or retention policy
  • No Data Protection Impact Assessment conducted
  • No data protection training for staff
  • No functional data breach incident response plan
  • No mechanism for handling data subject requests
  • Sharing information with third parties without data sharing agreements
  • No Role Based Access controls or data minimization applied
  • Data subjects not adequately informed of the use of data being collected
Respondent’s Position
  • Claimed awareness of the Data Protection Act and that it has put in place all necessary measures to comply
  • Stated information is collected solely for offering services, stored securely, and only collected by authorized staff
  • Claimed they have signed data protection agreements with partners
  • Asserted they let clients know the kind of information collected and for what purpose before collection

4. Issues for Determination

  1. Whether the Respondent has complied with the Act and its attendant regulations

5. Final Determination

The Data Commissioner found:

  1. The Respondent failed to register as a data controller or data processor.
  2. The Respondent lacks foundational data protection frameworks including policies, DPIAs, and staff training.
  3. The Respondent is liable for violation of its obligations under the Act.

Orders:

  • An Enforcement Notice is issued against the Respondent.
  • Right of appeal to the High Court within 30 days.

6. Significance and Impact

Healthcare Sector Data Protection
  • Establishes that healthcare providers must implement robust data protection frameworks
  • Health data requires heightened protection measures under the Act
Data Governance and Compliance
  • Confirms that data controllers must be registered, conduct DPIAs, and have data protection policies
  • Non-compliance with foundational obligations constitutes a violation of the Act

Broader Impact: This determination sends a clear signal to healthcare providers across Africa that processing sensitive health data without proper governance frameworks will not be tolerated. It underscores that foundational compliance, registration, policies, DPIAs, is non-negotiable, and that regulatory oversight applies proactively even in the absence of complaints.

Leave a Reply

Your email address will not be published. Required fields are marked *