Authority: ODPC
Jurisdiction: Kenya
Relevant law: Section 26, 29, 40(2) Data Protection Act, 2019
Type: Violation
Outcome: Violation
Started: 24 June 2023
Decided: 21 September 2023
Published: N/A
Fine: N/A
Parties: Grace Gatambu vs. AAR Health Services Ltd
Case No.: 1085 of 2023
Appeal: N/A
Original Source: ODPC
Original contributor: MZIZI Africa

Contents

  1. Summary
    1. Facts
    2. Holding
  2. Comment
  3. Further resources
  4. The Decision

Summary

AAR Healthcare Kenya Limited (the “Respondent”) was found liable for violating the Complainants right to privacy when sensitive personal data given to them by the Complainant in the course of accessing medical services, was released to a third party insurance firm, who used it for marketing purposes.

Facts

Grace Gatambu (the “Complainant”) alleges that AAR Health Services Ltd (”Respondent”) released personal data contained in a medical form, to third party insurance company whose employees then used the information to contact her in order to market insurance products.

The Respondent confirmed that information was mistakenly posted to the wrong insurance provider by an employee but did not activate appropriate responsive mechanisms to deal with the breach.

The Respondent acknowledged the breach but stopped short of issuing a formal apology for the breach to the Complainant which caused the Complainant to file the complaint with the ODPC.

The ODPC found that:

Holding