ODPC faults LOLC Kenya over data breach, orders deletion of client data

ODPC faults LOLC Kenya over data breach, orders deletion of client data
Data Commissioner Immaculate Kassait

NAIROBI, Kenya, April 19 – The Office of the Data Protection Commissioner (ODPC) has found LOLC Kenya Microfinance Bank Limited liable for unlawfully processing and publishing a former employee’s personal data, in a ruling that reinforces oversight on corporate data practices.

In a determination dated April 14, Data Commissioner Immaculate Kassait said the lender breached provisions of the Data Protection Act 2019 after posting the complainant’s images and details on its social media platforms without consent.

The complaint, filed in January 2026 by Peter Macharia Waithira, alleged that the institution published notices warning customers against transacting with him even after he had resigned in July 2025.

“It is undisputed that the Respondent posted the Complainant’s images on their Facebook platform. The Respondent did not demonstrate the lawful basis for processing the Complainant’s personal data,” the ruling states.

The regulator noted that the bank failed to respond to a formal notice issued in March, limiting its opportunity to justify the processing of the data or demonstrate compliance with legal requirements.

ODPC has directed the lender to delete the complainant’s personal data from all online platforms within 14 days or face further enforcement action.

The Commissioner also recommended prosecution of the company’s directors for obstruction after failing to cooperate with the investigation, with penalties including fines of up to Sh5 million or a two-year jail term upon conviction.

The decision adds to a growing list of enforcement actions shaping Kenya’s data protection landscape as businesses expand digital engagement.

Parties have 30 days to appeal the ruling at the High Court.