S.M.M. VERSUS AAR INSURANCE KENYA LIMITED
1. Introduction
This complaint emanates from S.M.M.’s grievance against AAR Insurance Kenya Limited on the sharing of his family’s health insurance information with a third party without obtaining consent, leading to unsolicited marketing messages. This action is in gross violation of the Data Protection Act, 2019.
Table of Contents
2. Nature of Complaint
The Respondent entered into a partnership with CarePay and CSL Services to manage its schemes on the M-TIBA Platform. The complainant alleged that the Respondent shared his family’s health insurance information with an external entity without obtaining his consent, and the external entity subsequently sent him engaging and intrusive SMS marketing messages without obtaining consent.
3. Analysis of Evidence
Complainant’s Position
- The Respondent shared his family health information with an external entity without consent
- The external entity proceeded to send engaging and intrusive SMS marketing messages without obtaining consent
- Provided screenshots of the SMS messages as proof
Respondent’s Defense
- Entered into a Partnership Agreement with CarePay and CSL Services to manage its schemes on the M-TIBA Platform
- Relied on consent from the Application Form signed by the Complainant and Section 30(1)(b)(i) and (vii) as the lawful basis
- Admitted the Complainant’s details were erroneously excluded from the notification of the upgrade to M-TIBA
- Provided a written apology and has taken extensive mitigation measures
- Asserted that CarePay and CSL are lawfully processing the Complainant’s personal data
4. Issues for Determination
- Whether the Respondent fulfilled its obligations under the Act
- Whether the Complainant is entitled to any remedies under the Act and the attendant Regulations
5. Final Determination
The Data Commissioner found:
- The Respondent shared the Complainant’s personal data with a third party without proper notification.
- The Respondent failed to inform the Complainant of the third-party processors as required under Section 29(d).
- The Respondent acknowledged the error and took mitigation measures, including a written apology.
- The Respondent is liable for violation of the Complainant’s rights under the Act.
Orders:
- Compensation of Ksh 25,000 to the Complainant.
- Right of appeal to the High Court within 30 days.
6. Significance and Impact
Duty to Notify and Third-Party Data Sharing
- Reinforces the obligation to notify data subjects of third parties with whom personal data will be shared
- Data controllers must inform data subjects of the identities of third-party processors
Data Sharing Agreements
- Confirms that entering into written data sharing agreements with processors demonstrates compliance
- Proper documentation can mitigate liability
Broader Impact: This case highlights the growing complexity of insurance data ecosystems, where customer information flows through multiple platforms and third-party processors without adequate transparency. Insurers across Africa must ensure that notifications about data sharing are comprehensive, accurate, and timely, rather than an afterthought.