VICTORY OWINO VERSUS MHASIBU HOUSING COMPANY LIMITED & MHASIBU NWDT SACCO SOCIETY LIMITED
1. Introduction
The case is in respect to the complainant, Victory Owino against Mhasibu Housing Company Limited and Mhasibu NWDT SACCO Society Limited, on the use of her personal data for marketing purposes without obtaining consent or having a lawful basis for processing. This action contravenes the Data Protection Act, 2019.
Table of Contents
2. Nature of Complaint
The complainant was a member of the 2nd Respondent’s SACCO and inherited a property transaction from her late father with the 1st Respondent. The complainant alleged that the 1st Respondent sent her marketing messages via WhatsApp without informing her that her data would be used for any other reason other than the land sale transaction, and that the 2nd Respondent did not inform her of the use and to whom it would distribute her data.
3. Analysis of Evidence
Complainant’s Position
- Joined the 2nd Respondent’s SACCO in 2019 and exited in October 2022
- Her late father bought property through the 1st Respondent, and she took over as beneficiary of the transaction
- Provided copies of WhatsApp messages from the 1st Respondent and emails from the 2nd Respondent as proof
- Raised concerns about the absence of data privacy policies, failure to register as data controllers, and retention of data
Respondents’ Defense
1st Respondent (Mhasibu Housing Company Limited):
- Lawfully obtained the Complainant’s personal data from her as she supplied a Certificate of Confirmation of Grant proving she was entitled to inherit the property
- She attended the Juja 2 plots selection event and willingly provided her phone contacts
- Stated it is in the process of completing registration as a data controller
- Denied sending any emails to the Complainant, only marketing WhatsApp messages
2nd Respondent (Mhasibu NWDT SACCO Society Limited):
- Denied sharing any data with the 1st Respondent
- Stated it has a Data Privacy Policy published on its website which outlines the rights of a data subject
- Is registered as a Data Controller and provided a copy of its Certificate of Registration
- Sent only three non-commercial emails to the Complainant (Customer Service Week, feedback invitation, and Family Fun-day invitation)
4. Issues for Determination
- Whether the 2nd Respondent shared the Complainant’s personal data with the 1st Respondent
- Whether the Respondents used the Complainant’s personal data for commercial purposes without obtaining consent
- Whether the 1st Respondent shared the Complainant’s personal data with third parties
- Whether there was an infringement of the Complainant’s rights under the Act
- Whether the Complainant is entitled to any remedies under the Act and the attendant Regulations
5. Final Determination
The Data Commissioner found:
- The 1st Respondent used the Complainant’s personal data for marketing purposes without obtaining express consent.
- The 1st Respondent failed to inform the Complainant of the purpose of collecting her personal data.
- The 2nd Respondent did not share the Complainant’s data with the 1st Respondent.
- The 1st Respondent is liable for violation of the Complainant’s rights under the Act.
Orders:
- Compensation of Ksh 650,000 to the Complainant.
- An Enforcement Notice is issued against the 1st Respondent.
- The complaint against the 2nd Respondent is dismissed.
- Right of appeal to the High Court within 30 days.
6. Significance and Impact
Right to be Informed and Commercial Use of Data
- Establishes that collecting contact details at events does not constitute express consent for marketing purposes
- Data controllers must inform data subjects of the purpose of collection
Separate Legal Entities and Data Sharing
- Clarifies that separate legal entities cannot be held liable for each other’s data processing without proof of data sharing
- Membership in one entity does not automatically create liability for affiliated entities
Broader Impact: This determination addresses a widespread challenge across Africa’s real estate and financial services sectors, where customer data collected for specific transactions is repurposed for marketing without consent. It establishes that businesses cannot assume consent from attendance at events or transactions, setting a critical standard for data protection in property and financial services across the continent.