BusinessCourtsCrime WatchHomeIn-Depth NewsIn-Depth News and InvestigationsMain StoryNational NewsNewsPoliticsTechTechnology

Safaricom found liable for breaching 11.5 million subscribers’ data

The subscribers alleged that their sensitive information, including M-Pesa records, IMEI device identifiers, geolocation data, betting patterns, and full subscriber profiles, were extracted and shared with multiple third parties, including betting firms Betika, Odibet, and Kwikbet

A landmark High Court ruling has indicted Kenya’s largest telecommunication firm, Safaricom PLC for unlawfully accessing and sharing subscribers’ personal data involving 11.5 million subscribers.

The court found the Chief Executive Officer (CEO) Peter Ndegwa’s led telco for the breach, a move that could raise safety and security concerns of subscribers’ personal data held by Safaricom and possible risk threats millions of Kenyans could be exposed to if a similar calamity befall them including subscribers’ financial MPesa records.

In a judgment delivered by Justice Bahati Mwamuye, the court held that the telco failed to safeguard the personal data of more than 11.5 million subscribers, which was accessed and shared with third parties between 2018 and May 2019.

The court awarded a total of Sh9.9 million in general damages to 11 petitioners, each receiving Sh900,000, plus interest at court rates from the date of judgment until full payment.

“I award general damages for breach of constitutional rights in the sum of Kshs900,000, to each of the petitioners, to be borne by the respondent. The said award shall attract interest at court rates from the date of the judgment until payment in full,” said the judge.

The subscribers alleged that their sensitive information, including M-Pesa records, IMEI device identifiers, geolocation data, betting patterns, and full subscriber profiles, were extracted and shared with multiple third parties, including betting firms Betika, Odibet, and Kwikbet.

Evidence presented in court showed that former Safaricom employees unlawfully accessed subscriber data and shared it for commercial gain.

The petitioners argued that the telco never explained what happened to the information once it was in the hands of third parties and has admitted that the data remains with them.

See also  Kenya confirms 212 new COVID-19 cases, 4 deaths

The petitioners included Austine Taabu, Joseph Ojiambo, Sabastian Ogoma, George Ouma, and Ann Kongo.

They accused Safaricom of failing to put safeguards in place, allowing its former employees to access, sell, and benefit from the illegal scheme.

In an affidavit, Musungu said he was an active punter before May 2019, with private information including identity numbers, passport details, certificate of incorporation numbers, financial transactions, betting activity, and location data all exposed. He noted that over 11.5 million subscribers were affected.

Safaricom opposed the case, arguing that the matter had already been addressed in multiple ongoing proceedings, including civil suits and criminal cases.

The company also argued it could not be held liable for the criminal acts of former employees, claiming these actions fell outside the scope of employment and were carried out for personal gain.

The petitioners stated that Safaricom stood in a position of constitutional trust as custodian and controller of intimate subscriber data and exercised immense technological and informational power over millions of citizens, which trust it chose to breach.

“By harvesting and disseminating their personal and behabioural data without their consent or lawful authority, the company fundamentally breached that constitutional trust, abused informational dominance and undermined their dignity and legitimate expectation of confidentiality in communications,” the petitioners said.

They contended that gambling activity on the Kenyan social context often carries moral judgment and familial consequences and the involuntary exposure of such data therefore, inflicted harm far beyond pecuniary loss.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button