Emerging Data Protection Principles on Direct Marketing

Direct marketing has become an essential tool, enabling organization to promote their products and services, engage with existing and prospective customers and strengthen brand visibility in a cost-effective and efficient manner. However, the use of personal data for marketing purposes is subject to strict legal requirements under Kenya’s data protection framework.
Under section 37 of the Data Protection Act, the use of personal data for commercial purposes is prohibited unless the person using the data has first sought and obtained the consent of the data subject. In addition, Regulation 14 of the Data Protection (General) Regulations 2021, provides that personal data is deemed to be used to advance commercial interests where it is used for direct marketing, including by sending promotional catalogues through any medium addressed to a data subject, displaying an advertisement on an online media site where a data subject is logged in using their personal data, or sending an electronic message to a data subject about a sale, promotion or other advertising material relating to a sale, using personal data provided by the data subject.
This article examines the emerging principles from recent determinations/decisions on direct and indirect marketing, specifically, sending unsolicited promotional messages to customers (data subjects) without fulfilling the requirements of the Data Protection Act and its Regulations.

1. Direct marketing requires the prior consent of the data subject

In Steve Onwonga v CJ’s Limited, the Complainant lodged a complaint alleging that the Respondent used his personal data to send unsolicited promotional messages to his mobile phone without his consent and without providing an option to opt out of future communications. The complaint arose after the Respondent sent the Complainant a promotional message advertising free delivery services during the festive season. Notably, the message did not contain an opt-out mechanism.

The Data Commissioner held that the Respondent’s processing of the Complainant’s personal data was unlawful as it had been undertaken without the Complainant’s prior consent. The Commissioner further found that the processing was unfair and non-transparent, contrary to the principles set out under section 25 of the Data Protection Act.

2. The Data Commissioner considers postbreach remedial measures when assessing compensation

In Steve Onwonga v CJ’s Limited, the Respondent submitted that, upon receiving the complaint, it conducted an internal inquiry and established that three promotional messages had been sent to the Complainant’s phone number on 15, 22 and 25 September 2025. Following this finding, the Respondent immediately ceased all promotional communications to the number, permanently removed the Complainant’s details from its marketing database and assured him that no further messages would be sent to him.

The Respondent further stated that it sought to resolve the matter amicably by inviting the Complainant to a meeting, during which it explained the remedial measures taken, issued an apology and offered a goodwill dining voucher worth KES 10,000. In addition, the Respondent informed the Data Commissioner that it had implemented corrective measures to prevent a recurrence of the incident, including introducing consent-based marketing controls, establishing opt-out mechanisms, adopting internal data handling policies, conducting staff training and commencing the process of registration with the Office of the Data Protection Commissioner.
The Data Commissioner acknowledged the steps taken by the Respondent after the breach had been identified, including ceasing further communications, engaging with the Complainant, issuing an apology, offering a goodwill gesture and implementing measures to strengthen its data protection compliance framework. However. the Commissioner held that while these actions mitigated the severity of the breach, they did not absolve the Respondent of liability for the unlawful processing of the Complainant’s personal data. Consequently, the Data Commissioner awarded Kes. 75,000/- as compensation to the data subject.

3. A data controller cannot rely on inherited consent for direct marketing purposes

In Catherine Gabriela v Penda Health, the Office of the Data Protection Commissioner considered whether an organisation that acquires personal data through a corporate acquisition may rely on consent previously obtained by another entity to send direct marketing communications.

The complaint arose after the Respondent sent promotional messages to the Complainant using personal data acquired through its acquisition of the Grace Health App. The Respondent maintained that the personal data had been lawfully transferred as part of the acquisition and that it was entitled to continue communicating with subscribers on the basis of the consent allegedly obtained by the previous operator of the App.
However, the Complainant had not been informed that her personal data had been transferred to a new data controller or given an opportunity to consent to receiving promotional communications from the Respondent.
The Data Commissioner held that the lawful transfer of personal data through a corporate acquisition does not relieve the acquiring entity of its obligations under the Data Protection Act. In particular, the Commissioner found that the acquiring entity remains under a continuing obligation to notify data subjects of any change in data controller in accordance with section 29 of the Act. The Commissioner further held that the Respondent’s use of the Complainant’s personal data to send promotional messages was intended to advance its commercial interests and therefore constituted direct marketing. As such, the Respondent was required to obtain the Complainant’s express consent before using her personal data for that purpose.
Accordingly, the Commissioner rejected the Respondent’s reliance on the consent allegedly obtained by the previous operator of the App and found that the promotional communications had been sent in contravention of the Data Protection Act. The Respondent was consequently directed to pay the Complainant KES 50,000 as compensation.

4. Data controllers must honour a data subject's objection to direct marketing communications

In Gachiri Ndungo v Nairobi City Water & Sewerage Company, the Complainant lodged a complaint alleging that the Respondent continued to send SMS communications to his mobile phone despite having expressly objected to such processing and issued a ceaseand-desist request.

In response, the Respondent maintained that the Complainant’s mobile number had been obtained through legitimate customer service interactions and was primarily used for customer support and service-related communications. The Respondent further acknowledged that the Complainant had objected to receiving further communications but stated that, due to an internal administrative lapse, the objection was not actioned immediately, resulting in the continued transmission of SMS messages. The Respondent stated that, upon discovering the error, it permanently removed the Complainant’s mobile number from its communication systems and implemented measures to prevent any further communications.
The Data Commissioner held that section 26(c) of the Data Protection Act grants data subjects the right to object to the processing of their personal data. The Commissioner further observed that, once such an objection is made, section 36 of the Act requires the data controller to cease processing unless it can demonstrate a compelling legitimate interest that overrides the rights of the data subject or establish that the processing is necessary for the establishment, exercise or defence of a legal claim.
The Commissioner also held that the Respondent had failed to demonstrate any lawful basis for continuing to process the Complainant’s personal data after receiving the objection. She further held that an internal administrative lapse could not excuse noncompliance with a data subject’s rights, as data controllers are required to implement appropriate technical and organisational measures to ensure that objections are acted upon without undue delay.
Accordingly, the Respondent was found liable for violating the Complainant’s right to object under sections 26(c) and 36 of the Data Protection Act and ordered it to pay the Complainant KES 250,000 as compensation.

5. Data controllers remain accountable for direct marketing conducted by their agents

In Mary Ogwena Immaculate v Momentum Credit, the Complainant alleged that between February and May 2025, she received more than fifty unsolicited promotional text messages on her mobile phone from individuals marketing the Respondent’s products and services. The Complainant maintained that she had never been a customer of the Respondent and had never consented to the use of her mobile phone number for marketing purposes. The Complainant further stated that, upon receiving the messages, she expressly instructed the individuals sending the communications to cease all further contact. Despite her objection, the promotional messages continued over an extended period. She therefore contended that the Respondent had unlawfully processed her personal data and failed to respect her right to object to such processing.

In response, the Respondent denied having processed the Complainant’s personal data and argued that the Complainant was not contained in its marketing database. However, the evidence before the Office showed that the promotional messages expressly marketed the Respondent’s products and services and originated from an agent engaged by the Respondent as part of its marketing operations.
The Data Commissioner noted that section 26(c) of the Data Protection Act grants data subjects the right to object to the processing of their personal data, while section 36 requires data controllers and data processors to act on such objections without delay. The Commissioner further held that the Respondent had failed to demonstrate that any effective steps had been taken to block, delete or suppress the Complainant’s contact details following her objection. In addition, the Respondent did not provide evidence to show that the continued communications were sent independently of its authority or outside the scope of its relationship with the agent.
In the circumstances, the Commissioner held that the continued transmission of promotional messages after the Complainant had objected to the processing constituted a violation of her rights under sections 26(c) and 36 of the Act. The Commissioner further found that the Respondent had failed to establish any lawful basis for processing the Complainant’s personal data and that the use of her mobile phone number to promote the Respondent’s products amounted to the use of personal data for commercial purposes contrary to section 37 of the Act and Regulation 14 of the Data Protection (General) Regulations.
Consequently, the Respondent was found liable for the unlawful processing of the Complainant’s personal data and was directed to pay KES 500,000 as compensation.

6. Personal data obtained during a commercial transaction cannot automatically be used for direct marketing

In Jaggys (Kienyeji Chicken v Gichunge [2026] KEHC 6856 (KLR)), the Complainant lodged a complaint with the Office of the Data Protection Commissioner alleging that, after purchasing chicken from the Respondent and making payment through M-Pesa, the Respondent extracted his mobile phone number from the payment details and used it to send promotional and feedback messages without his consent.

The Respondent contended that the communication was sent in good faith as part of its customer engagement and after-sales marketing activities. It further argued that the Complainant had not requested that the communications cease before lodging the complaint with the Data Commissioner.
In its determination, the Data Commissioner found that while the Respondent had generally complied with its obligations relating to notice and disclosure under sections 28 and 29 of the Data Protection Act, the Complainant’s mobile phone number had been obtained in the context of a commercial transaction and not for direct marketing purposes. Consequently, the Respondent’s subsequent use of the number to send promotional communications amounted to further processing for a new purpose without a lawful basis and in contravention of the Data Protection Act. The Commissioner therefore awarded the Complainant KES 250,000 as compensation.
On appeal, however, the High Court upheld the finding that the Respondent had unlawfully processed the Complainant’s personal data but reduced the award of compensation from KES 250,000 to KES 50,000. The Court observed that compensation under the Data Protection Act must be proportionate to the nature of the infringement and the actual harm suffered by the data subject. In the circumstances, the Court found that the award made by the Data Commissioner was excessive and substituted it with a lower award.
The decision establishes two important principles. First, personal data collected for one purpose cannot subsequently be repurposed for direct marketing without a lawful basis under the Data Protection Act. The fact that personal data is lawfully obtained during a commercial transaction does not entitle an organisation to use that data for unrelated marketing activities. Second, while data subjects are entitled to compensation for unlawful processing, compensation awards must be proportionate and supported by the circumstances of the particular case. The High Court’s intervention signals that compensation under the Data Protection Act is intended to be compensatory rather than punitive and that excessive awards may be subject to judicial review.

Conclusion

The recent determinations and court decisions demonstrate an increasingly strict regulatory approach to direct marketing practices in Kenya. They make it clear that organisations or businesses can no longer treat marketing communications as a routine commercial activity separated from their data protection obligations. Essentially, the use of personal data for direct marketing must be supported by a lawful basis, underpinned by valid consent, and must be carried out in a manner that upholds the rights of data subjects.