Authority: | ODPC |
---|---|
Jurisdiction: | Kenya |
Relevant law: | Section 26, 29, 40(2) Data Protection Act, 2019 |
Type: | Violation |
Outcome: | Violation |
Started: | 24 June 2023 |
Decided: | 21 September 2023 |
Published: | N/A |
Fine: | N/A |
Parties: | Grace Gatambu vs. AAR Health Services Ltd |
Case No.: | 1085 of 2023 |
Appeal: | N/A |
Original Source: | ODPC |
Original contributor: | MZIZI Africa |
AAR Healthcare Kenya Limited (the “Respondent”) was found liable for violating the Complainants right to privacy when sensitive personal data given to them by the Complainant in the course of accessing medical services, was released to a third party insurance firm, who used it for marketing purposes.
Grace Gatambu (the “Complainant”) alleges that AAR Health Services Ltd (”Respondent”) released personal data contained in a medical form, to third party insurance company whose employees then used the information to contact her in order to market insurance products.
The Respondent confirmed that information was mistakenly posted to the wrong insurance provider by an employee but did not activate appropriate responsive mechanisms to deal with the breach.
The Respondent acknowledged the breach but stopped short of issuing a formal apology for the breach to the Complainant which caused the Complainant to file the complaint with the ODPC.
The ODPC found that: