Oppo fined Sh5m for breach of privacy laws

Mobile phone firm Oppo Kenya has found itself on the wrong side of the recently enacted privacy laws after it was fined Sh5 million by the office of the Data Protection Commissioner (ODPC).

The amount is the maximum allowable penalty, for ‘infringement on the privacy of a complainant’.

The Data Commissioner said Oppo had defaulted on compliance and was issued an enforcement notice on November 3.

“ODPC on November 3, 2022, issued an enforcement notice against Oppo Kenya (Company) after it infringed on the privacy of a complainant by using their photo on the company’s Instagram account (stories) without the complainant’s consent,” said the Data Commissioner in a statement.

“Oppo Kenya is therefore required to pay to the ODPC a penalty of Kenya Shillings Five Million pursuant to Section 63 of the Data Protection Act, and Regulation 20 of the Data Protection (Complaints Handling Procedure and Enforcement).”

The ODPC said Oppo had refused to cooperate as it has not come up with a policy for compliance with Section 37 of the Act.

The new privacy laws prohibits the use of personal data that has been obtained pursuant to the Act for commercial purposes without consent from the data subject or authorisation under any written law.

Oppo was also accused of failing to prove that it had developed an internal complaints mechanism to address data subjects’ complaints.

The privacy laws, which received a parliamentary nod in March of this year, require all data controllers and data processors to register with the ODPC.

The set of regulations includes the data protection (General) regulations 2021, the Data Protection (Complaints Handling and Enforcement Procedures) Regulations, 2021, and the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021.

Companies that breach the rules face fines of not more than Sh5 million or up to one percent of their annual turnover.

Data Commissioner Immaculate Kassait yesterday urged entities to comply with the laws by implementing data protection principles and safeguards to all processing activities that relate to the collection and storage of sensitive personal data.

“ODPC urges data controllers and data processors to ensure that the processing of personal data is in accordance with the Act. Failure to comply with the Act will result in instituting enforcement procedures,” said Kassait.

 

 

George Musyoki

Recent Posts

KHOMIAKOV: The long game of crypto: Mastering risk management and security

The crypto world is full of opportunities but can also pose risks. Whether it’s market…

3 weeks ago

Is this the longest battery life for AI glasses? Loomos A1 smart glasses review

When it comes to wearable AI, one of the biggest drawbacks has always been battery…

3 weeks ago

Kenya’s healthcare leaders bet on AI to cut costs and expand coverage

Health insurance and technology leaders in Kenya see Artificial Intelligence (AI) and real-time data as…

3 weeks ago

Nairobi to host global investors as Africa’s startup boom takes center stage

More than 1,500 global leaders, investors, and entrepreneurs are set to convene in Nairobi for…

3 weeks ago

PATEL: Africa’s digital future hinges on affordable smartphone access

Imagine a world where access to education, financial services, and healthcare depends on owning a…

3 weeks ago

Samsung Galaxy S25 series smartphones now available in Kenya

The Galaxy S25 series of smartphones is now available for purchase in Kenya through authorized…

3 weeks ago