PETER KHAEMBA VERSUS AVENTUS TECHNOLOGY LIMITED
1. Introduction
The dispute in this matter arises from Peter Khaemba’s complaint against Aventus Technology Limited on the repeated contact demanding repayment of loans he had no knowledge of, and the use of derogatory language and threats by the Respondent’s agents. This action is in conflict with the Data Protection Act, 2019.
Table of Contents
2. Nature of Complaint
The Complainant alleged that the Respondent unlawfully processed his personal data by repeatedly contacting him via calls and messages, demanding he contact unknown individuals about unpaid loans he had no knowledge of. The Respondent’s agents used derogatory language and threats, and failed to verify the accuracy of the information linking him to the loans.
3. Analysis of Evidence
Complainant’s Position
- Received persistent and intrusive phone calls regarding loans purportedly granted to unknown individuals
- Notified the Respondent’s representatives on multiple occasions that he had no relationship with or obligations to the alleged loans
- Agents used derogatory language and threats, causing significant emotional distress and psychological trauma
- Adduced call logs and audio recordings of calls from the Respondent’s agents between 31st July 2024 and 26th August 2024
Respondent’s Defense
- Confirmed the Complainant is its customer and his personal data was lawfully collected upon receipt of his loan application on 10th August 2023
- Claimed the Complainant consented to the processing of his data upon downloading the mobile application
- Relied on Clause 2.6 of its Terms and Conditions
- Stated that the Complainant did not allow sufficient time for internal investigations
- Claimed the Complainant has since been blacklisted in all its systems
4. Issues for Determination
- Whether the Respondent fulfilled its obligations under the Act
- Whether there was a violation of the Complainant’s rights under the Act
- Whether the Complainant is entitled to any remedies under the Act
5. Final Determination
The Data Commissioner found:
- The Respondent repurposed the Complainant’s personal data for third-party debt recovery without a lawful basis.
- The Respondent’s agents used derogatory language and threats, causing emotional distress.
- The Respondent failed to verify the accuracy of information linking the Complainant to the loans.
- The Respondent is liable for violation of the Complainant’s rights under the Act.
Orders:
- An Enforcement Notice is issued against the Respondent.
- Right of appeal to the High Court within 30 days.
6. Significance and Impact
Purpose Limitation Principle
- Establishes that personal data collected for one purpose (loan disbursement) cannot be used for another (third-party loan recovery)
- Violation of Section 25(c) and 30(2) of the Act
Right to be Informed and Right to Object
- Reinforces the obligation to inform data subjects of the use of their personal data
- Data controllers must comply with objection requests, especially when the objection is clear and explicit
Broader Impact: This outcome challenges the growing practice of digital lenders repurposing customer data for unrelated debt recovery. It affirms that the purpose limitation principle is not a technicality but a fundamental safeguard against the misuse of personal data, and that individuals cannot be harassed for debts they have no connection to.