Background
In Arthur V.O Opinya, and 2 Others v Brainstorm Insurance Brokers Limited the Complainants, who are professionals employed by Nile Capital Insurance Brokers, alleged that the Respondent unlawfully processed their personal data by falsely presenting itself as being associated with them.
Specifically, the Respondent published the Complainants’ names, professional titles and professional accolades on its website and included the same information in a license application, despite the fact that there was no employment or other professional relationship between the parties.
The Respondent’s Response:
The Respondent admitted that it had no lawful basis for processing the Complainants’ personal data. It attributed the publication of the Complainants’ information on its website to an inadvertent error by its web developer, who allegedly uploaded the information during a routine website update.
The Respondent also stated that, upon becoming aware of the issue, it promptly removed the information from its website and implemented additional internal review procedures, including an approval protocol for all website content updates, to prevent a recurrence.
Determination
The Data Commissioner held as follows:-
- Contrary to section 26 (a) and 29 of the Act, the Complainants were not informed that their personal data and professional accolades will be published on a website or used in the Respondent’s license application. Therefore, they were denied the opportunity to understand, approve or object to the use of their personal data.
- The Respondent failed to establish any lawful basis for processing the Complainant’s personal data. In particular, contrary to sections 25 (b), 30 and 32 of the Act, Respondent used the Complainants’ names, professional titles and professional accolades without their consent.
- The Respondent violated Sections 25(a) and (b) of the Act by failing to process the Complainants’ data in accordance with their right to privacy, and by processing it in a manner that was neither lawful, fair nor transparent.
- Although the Respondent attributed the incident to a web developer error, the ODPC held that this did not absolve them of their responsibility. Further, the ODPC 1 www.mutie-advocates.com held that the Respondent failed to implement appropriate safeguards to limit processing to necessary purposes, control access or prevent unauthorised use and failed to identify and mitigate foreseeable risks associated with handling personal data.
- The Respondent failed to demonstrate that the indirect collection of the Complainants’ personal data fell within the permissible grounds under Section 28(2) of the Act, or that such collection was lawful, specific and explicitly defined as required under Section 28(3) of the Act.
- Consequently, the Data Commissioner issued an Enforcement Notice and ordered the Respondent to pay each of the three Complainants Kes 337,500, amounting to a total of Kes 1,012,500, as compensation for the unlawful processing of their personal data.






