ROSE WAMBUI MUIGAI VERSUS NCBA BANK PLC
1. Introduction
The dispute in this matter concerns Rose Wambui Muigai’s complaint against NCBA Bank PLC on the disclosure of her personal data to former employees who contacted her with her motor vehicle and insurance details without a lawful basis. This action is in breach of the Data Protection Act, 2019.
Table of Contents
2. Nature of Complaint
The Complainant held a financial account with the Respondent and subscribed to motor vehicle financing and insurance services. She received calls from former employees of the Respondent who disclosed her personal data, including her full name, mobile phone number, motor vehicle details, and insurance renewal information. Despite her demand letter, the Respondent failed to adequately address the breach.
3. Analysis of Evidence
Complainant’s Position
- Holds a financial account with the Respondent opened on 31st May 2021
- Subscribed to motor vehicle financing and annually renewable insurance premium services
- On 25th May 2023, received a call from a third party (D**** M****) who disclosed her personal data and informed her that her motor vehicle insurance was due for renewal
- Received subsequent calls from R**** M**** who also disclosed her personal data and requested a copy of her logbook
- Discovered that the callers were former employees of the Respondent
- Issued a demand letter on 23rd June 2023, but the Respondent requested her to follow through directly with the former employees
Respondent’s Defense
- Confirmed the Complainant is a customer and held an active account
- Confirmed the third parties identified were former employees who left in February 2021 and November 2021
- Stated that upon termination, their access and credentials to internal systems were disabled
- Sent cease and desist letters to the former employees
- Denied liability, stating that it was unclear where the Complainant’s details originated from
4. Issues for Determination
- Whether the Respondent fulfilled its obligations under the Act
- Whether the Complainant is entitled to remedies under the Act
5. Final Determination
The Data Commissioner found:
- The Respondent’s customer data was accessed and used by former employees after their termination.
- The Respondent failed to implement adequate measures to prevent former employees from accessing customer data.
- The Respondent failed to report the data breach to the ODPC within 72 hours.
- The Respondent is liable for violation of the Complainant’s rights under the Act.
Orders:
- Compensation of Ksh 250,000 to the Complainant.
- An Enforcement Notice is issued against the Respondent.
- Right of appeal to the High Court within 30 days.
6. Significance and Impact
Data Controller Obligations and Former Employees
- Establishes that data controllers remain liable for personal data breaches involving former employees
- Banks must implement robust measures to prevent former employees from accessing customer data
Technical and Organizational Measures
- Reinforces the obligation under Section 41 to implement appropriate security measures
- Data controllers must identify risks and establish safeguards against unauthorized access
Broader Impact: This decision confronts a persistent vulnerability in Africa’s banking sector: the exposure of customer data through former employees. It establishes that banks cannot simply disable system access and assume their obligations are fulfilled; they must proactively audit and secure data against post-employment exploitation.