Emerging Trends in Banking, Fintech and Telecommunications Consumer Disputes in Kenya
19 September 2026
Introduction
The relationship between consumers and financial service providers in Kenya has undergone an exponential transformation, driven by the convergence of traditional banking, mobile money, digital lending, and telecommunications infrastructure. This article provides a thematic analysis of emerging trends in consumer disputes in banking, fintech, and telecommunications in Kenya, drawing upon recent judicial decisions from the High Court, the Court of Appeal, and the Small Claims Court, and situating those decisions within broader regulatory developments.
The article identifies twelve distinct themes that characterise the evolving jurisprudence. First, it examines the tension between the bank’s traditional “correct PIN defence” and the emerging “gatekeeper duty” that requires banks to act on red flags and maintain robust fraud detection systems. Second, it analyses the application of vicarious liability to bank employees’ misconduct, distinguishing this from direct constitutional liability under the Bill of Rights. Third, it explores the constitutional obligations of telecommunications providers as data controllers under Article 31 of the Constitution, particularly in light of the landmark Musungu v Safaricom decision, which affirmed a positive and non-delegable duty to secure subscriber data.
Fourth, the article interrogates the vulnerability of Know Your Customer (KYC) and digital onboarding processes, arguing that the information used to open a physical account years ago is insufficient for verifying a new digital profile. Fifth, it examines the constitutional privacy crisis arising from phone number reassignment, as addressed in Odhiambo v Attorney General, where the High Court declared that a registered mobile phone number constitutes a digital identifier protected under Article 31 of the Constitution of Kenya. Sixth, it considers the bank’s duty to flag suspicious transactions and act on red flags, with particular reference to Diamond Trust Bank v Kariuki and Shalimar Flowers v KCB.
Seventh, the article analyses the apportionment of liability in multi-party fraud chains, where courts allocate responsibility among telecommunications providers, banks, and other actors based on each party’s independent failure. Eighth, it examines the recognition of consumer data as a constitutional asset, with systemic breaches affecting millions of subscribers constituting constitutional violations warranting damages. Ninth, it addresses the horizontal application of constitutional rights to private entities, affirming that the Bill of Rights binds banks, fintechs, and telecommunications providers.
Tenth, the article considers the evidentiary significance of partial refunds or recoveries as evidence of negligence. Eleventh, it clarifies the role of Credit Reference Bureaus and the liability of reporting entities, distinguishing between liability for CRB listings and liability for data breaches. Twelfth, it examines the customer’s duty of prompt notification and its impact on bank liability, recognising that consumer negligence may be a mitigating factor but does not absolve structural failures.
The article concludes that the traditional contractual framework governing consumer disputes has been supplemented by a constitutional framework that recognises the consumer as a constitutional actor whose rights to privacy, dignity, and consumer protection are entitled to protection against private entities. The courts have laid a strong foundation for the protection of consumer rights in the digital economy, but significant gaps remain, particularly in the implementation of regulatory safeguards and the technical feasibility of court-ordered reforms. This article contributes to the ongoing development of legal doctrine in this rapidly evolving field, offering practitioners, regulators, and consumers a clear and accurate understanding of the current state of the law.
I. The Bank’s Gatekeeper Duty versus Technical Compliance with Customer Credentials
The relationship between a bank and its customer has long been understood as contractual in nature. The bank undertakes to receive money and collect bills for the customer’s account. The customer undertakes not to mislead the bank or facilitate forgery. This contractual framework, however, is now subject to a more demanding standard. The courts have made it clear that a bank cannot hide behind a correct Personal Identification Number (PIN) defence when its systems fail to detect obvious fraud. The bank is a gatekeeper, and the gate must be secure.
The Correct PIN Defence
The starting point for this analysis is the principle that a Personal Identification Number (PIN) is intended to be known only to the customer. When a transaction is initiated using the correct PIN, the bank is entitled to presume that the customer authorised the transaction. This principle was affirmed in Stanbic Bank Kenya Limited v Simba (Civil Appeal E114 of 2022) [2023] KEHC 22277 (KLR). The respondent in that case claimed that a total sum of KShs 257,900 had been fraudulently withdrawn from his account on 8 January 2022. The bank argued that the instructions for the disputed transactions were issued from the respondent’s registered phone number through the USSD platform and that a transaction can only be successful when the customer inputs their PIN to authorise the same. The High Court, per Mong’are J, allowed the appeal and set aside the judgment of the lower court. The court held that the bank had satisfactorily proved that the transactions in question were initiated through the USSD Code Channel and that the bank acted within its fiduciary duty in honouring the transactions as they were initiated through the registered mobile number.
The reasoning in Stanbic Bank v Simba reflects the traditional understanding of the banker-customer relationship. The customer holds the PIN. The customer is responsible for keeping it confidential. If the PIN is used, the customer must bear the consequences unless they can prove that the bank was negligent. This approach has the virtue of clarity. It allocates risk to the party best positioned to control it. The customer knows their PIN. The customer chooses whether to share it. The customer can take steps to protect it.
The Limits of the Correct PIN Defence
The courts have, however, recognised that the correct PIN defence has limits. In Diamond Trust Bank Kenya Ltd v Kariuki & another (Civil Appeal E121 of 2024) [2026] KEHC 9771 (KLR), the High Court rejected the bank’s argument that it was not liable simply because the correct PIN was entered. The facts of that case are instructive. The respondent, Mercy Wairimu Kariuki, held a bank account with Diamond Trust Bank. On 6 February 2022, she received a SIM swap alert on her Safaricom line, which she immediately reported to Safaricom. Her line was reinstated on 7 February 2022. However, on 8 February 2022, she received alerts showing that a total of KShs 4,418,601 had been withdrawn from her account via the bank’s mobile banking platform and Pesalink. The bank argued that all the disputed transactions were initiated using the respondent’s mobile banking application upon successful input of her secret PIN and that the bank was entitled to deem that successful input as sufficient proof of identity without making further checks.
The court, per Ongeri J, held that the bank breached its duty of care owed to the respondent. The court rejected the bank’s argument that it was not liable simply because the correct PIN was entered, finding that the bank had ignored significant red flags, including the rapid succession of large transactions and transfers to multiple unrelated accounts and mobile numbers, which should have prompted further verification. The court stated:
A bank cannot hide behind a customer’s PIN when it is presented with a series of transactions that are so glaringly out of the ordinary that a reasonable banker would have been put on inquiry. A bank is expected to flag suspicious transactions.
The court further held that while the SIM swap was the enabling event that gave the fraudsters control of the respondent’s phone line, the financial loss occurred when the bank’s banking system permitted the fraudulent withdrawals. The bank’s reliance on the principle of novus actus interveniens to break the chain of causation was not persuasive. The fraud was a continuous sequence of events. The SIM swap compromised the respondent’s line, which was then used to access her bank account and transfer funds. The bank’s failure to act on the red flags was not a new and independent cause that superseded the SIM swap. It was a failure to discharge its own duty to safeguard the customer’s funds.
The Gatekeeper Metaphor
The metaphor of the bank as gatekeeper has gained currency in recent judgments. In Family Bank Limited v Kiarie (Commercial Appeal E078 of 2026) [2026] KEHC 9414 (KLR), the court stated:
“A bank is the keeper of the gate through which its customer’s money passes; where it is warned that the gate stands open and does not close it, it cannot afterwards be heard to say that the thief carried the right key.”
This metaphor captures the essence of the duty of every bank. The bank does not merely process transactions. The bank controls access to the customer’s funds. If the gate is insecure, if the lock can be picked, if the warning signs are ignored, the bank cannot escape liability by pointing to the customer’s PIN. The gate must be secure. The bank must ensure that it is.
The gatekeeper metaphor was applied with particular force in James Njoroge v Stanbic Bank Kenya Limited (SCCCOMM/E6743/2026). The claimant, a customer of the bank for over ten years, was robbed on the morning of 13 July 2025. His physical wallet, containing his National ID, ATM cards, and mobile phone linked to his bank account, was stolen. On the same day, at 14:48 hours, a new digital banking profile (OMNI) was self-registered on the claimant’s account. Shortly thereafter, between 15:09 and 15:25 hours, three unauthorised transactions totaling KShs. 1,001,000 were processed. The claimant’s spouse reported the incident to the bank at 17:19 hours, and the account was restricted at 17:59 hours. The bank was able to recover KShs 490,000 from a receiving account, which was credited to the claimant. The claimant sought to recover the outstanding balance of KShs 511,000, alleging negligence and breach of fiduciary duty on the part of the bank.
The court, per Kerubo RM/Adjudicator, found that the bank’s self-registration process for its OMNI digital platform was fundamentally flawed and insecure. The claimant had never used nor registered for mobile or online banking, preferring to conduct all his banking transactions physically at the branch. The bank allowed a complete stranger to the bank, using only the items stolen in a robbery (ID card, mobile phone), to create a full digital banking profile and drain a significant sum of money in less than an hour. The bank’s self-registration process relied on knowledge-based information (ID number, Date of Birth, account number) and an OTP sent to a stolen mobile phone. The court found that this was a multi-factor authentication, but it was insufficient. The court held:
The Respondent did not just fail to close the gate after being warned; its gate was designed in a way that allowed a thief to easily pick the lock.
The court further held that the bank’s “Know Your Customer” (KYC) and onboarding process for new digital channels was inherently insecure. A bank’s duty of care must extend to ensuring that a significant change to an account, such as the activation of digital banking, is verified with a high degree of certainty. The bank’s argument that the customer provides these details during the initial account opening was circular and insufficient. The information provided ten years ago to open a physical account is the same information that the fraudster now possesses. It does not serve as a robust verification for a new and powerful channel. The court entered judgment for the claimant in the sum of KES 511,000.
Systemic Attacks on Banking Systems
The vulnerability of banking systems to systemic attacks was underscored by a real-world incident that came to light in 2025. A 26-year-old IT dropout installed unauthorised Java software inside a microfinance institution’s system to steal KSh 11.4 million, bypassing the payment system and erasing critical system logs. This confirms the real-world risk of system-level attacks that courts referenced when criticising insecure digital onboarding processes. The case demonstrates that the threat to consumer funds is not limited to external fraudsters stealing credentials. It extends to insiders with technical knowledge who can exploit vulnerabilities in the bank’s own systems.
The Regulatory Response
In 2017, the Central Bank of Kenya responded to these developments by issuing guidance on cybersecurity and fraud management. In a survey conducted in 2025 on the adoption of this Guidance, it was found that all commercial banks have a dedicated cybersecurity governance framework in place, with cybersecurity budgets ranging from KSh 2.5 million to KSh 600 million annually. The survey also revealed that 97% of banks conduct regular audits to evaluate the effectiveness of cybersecurity controls, while 95% assess and manage cybersecurity risks posed by third-party vendors. However, the survey identified emerging areas requiring attention, including artificial intelligence and machine learning, cloud computing governance, API security, and enhanced controls on mobile money fraud detection.
The tension between the correct PIN defence and the gatekeeper duty is likely to persist. The courts will continue to scrutinise the facts of each case to determine whether the bank’s systems were adequate and whether the bank acted reasonably in the circumstances. The burden of proof will shift depending on the nature of the transaction and the evidence available. The consumer who claims that their PIN was used without authorisation must provide evidence to support that claim. The bank that relies on the correct PIN defence must demonstrate that it had no reason to suspect fraud. The gate must be secure, but the consumer must also take reasonable steps to protect their key.
II. Vicarious Liability for the Actions of Bank Employees
The principle that an employer is liable for the acts of its employees committed in the course of their employment has a long history in the common law. The doctrine of respondeat superior is rooted in the recognition that the employer, who benefits from the employee’s services, should bear the risk of the employee’s negligence or misconduct. In the banking context, this principle has been applied to hold banks liable for the fraudulent or negligent acts of their employees, particularly where those acts were enabled by the employee’s access to the bank’s systems and the bank’s failure to supervise.
The Classic Statement of Vicarious Liability
The classic statement of vicarious liability in the Kenyan context was provided by the Court of Appeal in Kenya Bus Services Ltd v Dina Kawira Humphrey [2003] KECA 179 (KLR). The court affirmed that an employer is liable for wrongful acts of employees committed in the course of employment, even where such acts are negligently or improperly executed. The controlling inquiry remains whether the impugned conduct is sufficiently connected to the employee’s authorised functions and the employer’s enterprise.
In the banking context, this principle has been applied in a number of cases. In Fidelity Commercial Bank Limited v Italian Market Kenya Limited (Civil Appeal No. 248 of 2015) [2017] KECA 370 (KLR), the Court of Appeal held the bank liable for allowing one director to link personal credit cards to a corporate account without verifying with the other director. The bank’s failure to verify the authorisation with the third director constituted negligence. The bank was held vicariously liable for the actions of its employees who processed the unauthorised debits.
The facts of Fidelity Bank v Italian Market are instructive. Stephano Sala, his wife Monica Garibaldi, and John Nguli were all directors of Italian Market Kenya Limited. The company opened and maintained a current account with Fidelity Commercial Bank Limited, whose signatories were Stephano and John. The signing mandate was that either director could sign. The bank invited Stephano to apply for a Visa Gold Card, in his personal capacity. Stephano accepted and also extended the same to his wife. They were consequently issued two Visa Gold Credit Cards in their personal names. Stephano and Monica then signed an auto credit authorisation form, authorising the bank to link the said Visa cards to the company account. This meant that all monies expended through the said cards would automatically be offset from the company funds and became a liability on the company. John Nguli, the other director of the company, was apparently not privy to this arrangement. The bank continued to debit the company’s account with the amounts utilised through the use of the said credit cards from July 2007 to January 2010, which amounted to KShs 2,889,764 plus interest at bank rates.
The Court of Appeal found that the bank was negligent in not confirming the instructions from the company. The court held that a bank has a duty under its contract with its customer to exercise reasonable care and skill in carrying out its part with regard to operations within its contract with its customer. The bank was expected to apply its skill, expertise, and all manner of safeguards to ensure that the customer’s money was safe from third parties and other unauthorised persons. The court found that the bank failed to discharge this duty and was vicariously liable for the actions of its employees.
Vicarious Liability for Fraudulent Transfers
In Co-operative Bank of Kenya Ltd v Biwott (Civil Appeal 18 of 2019) [2022] KEHC 9946 (KLR), the bank was found vicariously liable for its staff’s role in facilitating a fraudulent transfer. The respondent, Simon Kiplagat Biwott, was a customer of the bank. He became interested in the bank’s fixed deposit account services and was advised that he could earn an interest of 12.5 per cent per annum on a fixed deposit account. On 2 March 2016, he transferred KShs 10,000,000 from his KCB account to his account at the bank. On 3 March 2016, he visited the bank’s branch with the view of operationalising the fixed deposit account. He met the bank’s staff who, acting under guise of operationalising a fixed deposit account, induced him to execute an application for funds transfer in blank. The bank’s staff dated and endorsed the application with the bank’s official stamp on 3 March 2016. On 7 March 2016, the bank allowed the transfer of KShs 10,000,000 from the respondent’s account to Kingdom Securities, a subsidiary of the bank.
The bank argued that it acted unilaterally and without obtaining the respondent’s consent. The court found that the bank failed to discharge its duty of care to the respondent in the manner it maintained the respondent’s account. The bank’s staff acted in the course of their employment, using the bank’s systems and authority. The bank was vicariously liable for their actions. The court held:
A bank has a duty under its contract with its customer to exercise reasonable care and skill in carrying out its part with regard to operations within its contract with its customer. The standard of that reasonable care and skill is an objective standard applicable to bankers. Whether or not it has been attained in any particular case has to be decided in the light of all the relevant facts, which can vary almost infinitely.
The bank was found liable for the full amount of KShs 10,000,000, although the award of general damages for breach of contract was set aside on appeal.
Vicarious Liability for Theft by Employees
In Co-operative Bank of Kenya Ltd v Mutuku (Civil Appeal 183 of 2024) [2025] KEHC 4324 (KLR), the court held that the theft of funds was planned and executed by the bank’s agents, servants, or employees. The respondent, Beatrice Mukii Mutuku, successfully sued the bank for damages in regard to a sum of KShs 140,125, which she alleged was unlawfully debited from her account. The bank argued that it was the respondent who made the withdrawals at the ATM using her debit card and PIN. The court, per Maina J, found that the respondent had proved on a balance of probabilities that the money was withdrawn without her consent. The court held:
“I am persuaded that the debits were without the approval and consent and even knowledge of the Respondent. It behoves the Appellant to investigate who the culprit is and bring them to book so as to indemnify itself.”
The bank could not run away from its responsibility simply because negligence was not pleaded or investigations were yet to be concluded. If indeed it had evidence that the money was withdrawn by the respondent, then it ought to have tendered that evidence. In the absence of that evidence, the court was persuaded that the debits were without the approval and consent of the respondent. The bank was vicariously liable for the actions of its employees.
The Problem of Insider Collusion
The problem of insider collusion has come under scrutiny in recent years. In 2025, the Senate investigated a suspected syndicate targeting retirees’ pension payouts. Senator Eddy Oketch raised concerns that fraudsters appear to have access to pensioners’ banking details in unclear circumstances, allegedly enabling them to monitor and drain accounts as soon as funds are deposited. Senator Okongo Omogeni called for the bank CEO to explain cases where customers lose money shortly after leaving the bank. This points to possible insider collusion, exactly the kind of employee misconduct that banks are vicariously liable for.
In 2025, KCB Group fired 60 employees for fraud, nearly double the previous year’s figure, confirming that internal employee misconduct remains a major threat. This suggests that banks are taking a tougher stance and using technology to detect internal misconduct earlier. As digital banking expands, the threat from within is a major operational risk. Banks must implement robust internal controls, including access controls, audit trails, and monitoring systems, to prevent and detect employee misconduct.
The Distinction between Vicarious Liability and Direct Constitutional Liability
It is important to distinguish between vicarious liability under the common law and direct constitutional liability under the Bill of Rights. Vicarious liability arises from the employment relationship. The employer is liable for the acts of the employee committed in the course of employment. Direct constitutional liability arises from the obligations imposed by the Constitution on every person, including private entities, to respect and protect the rights of others.
In Musungu & 11 others v Safaricom Plc (Constitutional Petition E095 of 2026) [2026] KEHC 3809 (KLR), the court addressed this distinction. The petitioners alleged that between 2018 and 2019, Safaricom’s employees, acting in the course of their employment, accessed and transmitted sensitive subscriber information including financial transaction data, betting activity, device identifiers, and geolocation data to third parties without consent or lawful authority. The respondent denied constitutional liability, attributed the breach to criminal acts of former employees, and relied on WM Morrison Supermarkets PLC v Various Claimants [2020] UKSC 12, where the UK Supreme Court held that an employer is not vicariously liable for rogue employee conduct that is not closely connected to the employee’s duties or business purposes.
The court, per Mwamuye J, held that the respondent cannot evade constitutional responsibility merely by attributing the impugned conduct to rogue employees. While the doctrine of respondeat superior limits common law vicarious liability in cases of purely personal wrongdoing, the present matter is anchored in affirmative constitutional obligations arising under Article 31 of the Constitution. Those obligations impose a positive and non-delegable duty upon data controllers to implement adequate safeguards against foreseeable misuse, extraction, and dissemination of personal data. The court found that the impugned conduct occurred through systems wholly within the respondent’s custody and control and was facilitated by systemic failures in data governance, internal oversight, and data-security safeguards. Liability in this context therefore arises not merely from employment categorisation, but from institutional failure to secure constitutionally protected personal information.
The court further held:
In constitutional litigation implicating informational privacy and data protection, that inquiry is necessary but not sufficient. The constitutional architecture under Article 31 imposes obligations that are not merely derivative of employment relationships, but affirmative, structural, and non-delegable in character upon any entity that collects, controls, and processes personal data at scale.
III. Telecommunications Providers as Data Controllers with Constitutional Obligations
The traditional view of telecommunications providers was that they are infrastructure providers. Their role is to provide the communication infrastructure and maintain the integrity of subscriber identification. They are not financial institutions. They do not make lending decisions. They do not report to Credit Reference Bureaus. This view was articulated in Wachira v Safaricom Company Limited (Civil Suit E005 of 2022) [2024] KEHC 16425 (KLR), where the court held that a telecom provider is not liable for unauthorised lending or CRB listings, as it neither makes lending decisions nor reports to CRBs. Its role is strictly limited to providing telecommunications infrastructure.
This traditional view, however, has been significantly modified by recent constitutional jurisprudence. The courts have recognised that telecommunications providers are data controllers with constitutional obligations under Article 31 of the Constitution. In Odhiambo & another v Attorney General & another (Petition E290 of 2024) [2026] KEHC 3809 (KLR), the court declared that a registered mobile phone number constitutes a digital identifier linking personal data that qualifies for protection under Article 31. The court held:
Given the elaborate legislative registration scheme that connects SIM registration to the official personal identification records of the subscriber, the mobile number is for all purposes a digital identifier that record provides a means a person can be identified directly or indirectly. A registered phone number has now become the means for authentication and verification credentials for online transactions where security codes such as OTPs are sent to authenticate transactions. The registered mobile number thus provides link to delicate personal data that qualifies for protection under the right to privacy under Article 31 of the Constitution.
The court further held that the provision in the existing regulations that allows deactivation of registered telephone numbers without interrogating if there exists a valid reason for non-use is unreasonable and arbitrary. It does not meet the constitutional standards of Article 24 or 47 of the Constitution. There are no public notices issued whether in newspapers, electronic media or websites indicating any intention to deactivate and/or reassign mobile numbers and no opportunity is given for providing explanation for non-use. As for prisoners, not even the Kenya Prison Service is given the opportunity to liaise with the Network Operators so that prisoners desirous of maintaining their digital identity with a view to protecting the privacy of their personal data linked to this particular digital identity is provided. There is no room for preservation of these numbers.
The court issued a mandatory order directing the Attorney General, within six months from the date of the judgment, to take all necessary and appropriate measures to safeguard digital identity associated with the registered mobile telephone number against unfettered deactivation, and subsequent arbitrary reassignment or recycling. The measures shall ensure reassignment of any deactivated and previously registered number shall only be possible if there is the previous registered owner’s informed and verifiable consent; after expiry of reasonable period following issuance of public notice which must be preceded by thorough documented verification process aimed at confirming the original registered owner cannot be located or has unequivocally revoked the rights to the number; and technical safeguards be put in place and implemented to prevent unauthorised exposure or transfer of personal data linked to previous registered owner to third parties upon reassignment or recycling of the number.
The Safaricom Data Breach Case
The full scope of a telecommunications provider’s constitutional obligations was articulated in Musungu & 11 others v Safaricom Plc (Constitutional Petition E095 of 2026) [2026] KEHC 3809 (KLR). The petitioners alleged that between 2018 and 2019, Safaricom’s employees, acting in the course of their employment, accessed and transmitted sensitive subscriber information including financial transaction data, betting activity, device identifiers, and geolocation data to third parties without consent or lawful authority, thereby violating the petitioners’ rights to privacy, dignity, and consumer protection.
The respondent denied constitutional liability, attributed the breach to criminal acts of former employees, challenged the admissibility and sufficiency of the petitioners’ evidence, and further contended that the petition was an abuse of court process in light of parallel criminal and civil proceedings. The court, per Mwamuye J, made a number of significant findings.
First, the court found that the present petition was not an abuse of process despite the existence of parallel proceedings. While the factual background was common, the legal questions were not co-extensive. The present petition raised broader constitutional questions under Articles 28, 31, and 46, including systemic data governance obligations, horizontal application of constitutional duties to private actors, and structural remedies affecting millions of subscribers. These issues extended beyond the narrower factual or individualised inquiries in the related proceedings. The court held that the existence of parallel proceedings does not, without more, bar constitutional litigation.
Second, the court admitted the affidavit of Benedict Kabugi, a key witness in the related proceedings, but treated it with appropriate circumspection and relied upon it only to the extent that its contents were corroborated by independently verifiable material.
Third, the court found that a data breach did in fact occur within the respondent’s systems during the material period, characterised not merely by isolated internal extraction of subscriber data, but by sustained and unauthorised dissemination of such data to external third parties within the betting and gambling ecosystem. The evidentiary record, including forensic material, internal WhatsApp communications produced by the respondent itself, witness statements, and admissions emerging from related proceedings, established, on a balance of probabilities applicable in constitutional adjudication, that sensitive subscriber information was unlawfully accessed, extracted, transferred, and commercially exploited beyond authorised channels.
Fourth, the court held that the respondent cannot evade constitutional responsibility merely by attributing the impugned conduct to rogue employees. The court found that the impugned conduct occurred through systems wholly within the respondent’s custody and control and was facilitated by systemic failures in data governance, internal oversight, and data-security safeguards. Liability in this context arises not merely from employment categorisation, but from institutional failure to secure constitutionally protected personal information.
Fifth, the court found that the petitioners had successfully demonstrated violations of their constitutional rights under Articles 28 and 31 of the Constitution, read together with Article 46. The unlawful extraction, dissemination, and commercial exploitation of personal, financial, and behavioural subscriber data relating to subscriber activity constitutes a serious infringement of informational privacy and dignity, while the absence of demonstrable safeguards and adequate transparency engages consumer protection guarantees under Article 46. The violations are systemic in nature and affect not merely individual subscribers but a defined and extensive class of persons whose data was within the respondent’s custody and control.
Sixth, the court awarded general damages for breach of constitutional rights in the sum of Kenya Shillings Nine Hundred Thousand (KShs 900,000) to each of the petitioners. The court held:
The award is not punitive in character but is intended to vindicate the infringement of constitutional rights, affirm the sanctity of informational privacy under Article 31 of the Constitution, and underscore the dignity interest protected under Article 28 within the evolving architecture of the digital economy. It further serves as a principled affirmation that constitutional guarantees cannot be rendered illusory in the face of large-scale data processing systems, and that where violations are established, the Court will not hesitate to grant effective and meaningful relief commensurate with the gravity of the breach.
The Distinction between Liability for CRB Listings and Liability for Data Breaches
It is important to maintain the distinction between liability for CRB listings and liability for data breaches. In Wachira v Safaricom (supra), the court held that a telecom provider is not liable for unauthorised lending or CRB listings, as it neither makes lending decisions nor reports to CRBs. The plaintiff’s claim should have been properly directed at the relevant lending institutions and credit reference bureaus. This remains good law. A telecom provider does not make lending decisions. It does not report to CRBs. It is not the correct party to sue for a CRB listing arising from a default on a loan.
However, a telecom provider is the correct party to sue for a data breach arising from the unauthorised extraction and dissemination of subscriber data. The telecom provider collects, processes, stores, and controls vast quantities of personal and sensitive data, including identity particulars, financial transaction histories, betting behaviour, device identifiers, geolocation data, and subscriber usage profiles. This information places the telecom provider in a position of exclusive control and constitutional trust as data custodian, thereby imposing upon it a non-delegable duty to safeguard the confidentiality, integrity, and privacy of that data.
The distinction is very important. The telecom provider is not a financial institution. It is not liable for the financial consequences of lending decisions. But the telecom provider is a data controller. It is liable for the consequences of its failure to secure the personal data entrusted to it by its subscribers.
IV. The Vulnerability of KYC and Digital Onboarding Processes
Know Your Customer (KYC) processes are the cornerstone of the banking relationship. The bank must know who its customer is. It must verify the customer’s identity. It must maintain records of that verification. The purpose of KYC is to prevent fraud, money laundering, and terrorist financing. It is also to protect the customer from identity theft and unauthorised access to their account.
The traditional KYC process involved the customer appearing in person at the bank branch, presenting their identification documents, and signing account opening forms. The bank would verify the documents, take copies, and maintain them on file. The customer would be issued with a cheque book and, later, an ATM card. The process was physical, paper-based, and time-consuming. But it was also relatively secure. The customer was required to be physically present. The bank’s staff could compare the customer’s face to the photograph on the ID. The risk of impersonation was low.
The Vulnerability of Digital Onboarding
The digital onboarding process is fundamentally different. The customer can open an account online, using their mobile phone. They can take a photo of their ID, upload it, and complete a form. The bank may verify the ID using a third-party service or by checking against government databases. The process is fast, convenient, and accessible. But it is also vulnerable. The bank may never see the customer in person. The ID may be forged. The customer’s personal information may have been stolen.
The vulnerability of digital onboarding was starkly illustrated in James Njoroge v Stanbic Bank Kenya Limited (supra). The claimant, a customer of the bank for over ten years, had never used nor registered for mobile or online banking. He was robbed of his wallet containing his National ID, ATM cards, and mobile phone linked to his bank account. On the same day, a new digital banking profile (OMNI) was self-registered on the claimant’s account using the stolen ID and phone. Within 16 minutes, three unauthorised transactions totalling KShs 1,001,000 were processed. The bank’s self-registration process relied on knowledge-based information (ID number, Date of Birth, account number) and an OTP sent to a stolen mobile phone. The court found that this was a multi-factor authentication, but it was insufficient. The court held:
The Respondent’s ‘Know Your Customer’ (KYC) and onboarding process for new digital channels was inherently insecure. A bank’s duty of care must extend to ensuring that a significant change to an account, such as the activation of digital banking, is verified with a high degree of certainty. The Respondent’s argument that the customer provides these details during the initial account opening is circular and insufficient. The information provided 10 years ago to open a physical account is the same information that the fraudster now possesses. It does not serve as a robust verification for a new and powerful channel.
The court further held that the fact that the bank allowed the creation of a new OMNI profile and the subsequent transfer of KShs 1,001,000 within 16 minutes, on an account with no historical digital activity, was a clear indication of a systemic failure. The court found it incredulous that the bank’s fraud detection algorithms did not flag such an anomaly. Large, rapid transfers to a new, unrelated account after the activation of a digital profile on a previously dormant account are exactly the kind of red flags that a reasonably competent bank should have systems in place to detect and halt.
The Problem of Forged Documents
The vulnerability of KYC processes to forged documents was illustrated in Kenya Grange Vehicle Industries Ltd v Southern Credit Banking Corporation Ltd (Civil Case 220 of 2006) [2014] KEHC 4092 (KLR). The plaintiff was a company in the business of selling vehicles and providing motor vehicle repairs, fitting, and maintenance services. On 16 November 2004, it delivered ten cheques totalling KShs 4,000,182.95 to its bank for deposit. None of the cheques were ever credited to its account. Investigations revealed that a bank account had been opened on or about 20 November 2004 apparently in the name of the plaintiff company at the Eldoret Branch of the defendant bank. The account was opened by two individuals posing as directors of the plaintiff company, presenting a number of documents purporting to emanate from the plaintiff company. The two signatories were neither directors nor shareholders of the plaintiff company.
The court found that the defendant bank was negligent in the opening of the account. The bank’s officials failed to notice discrepancies in the account opening forms, including that the fraudsters indicated that the company was purportedly incorporated on 20 November 2004 while the PIN certificate supplied was issued on 10 December 2003. They also failed to notice the glaring discrepancy between the forged Certificate of Incorporation which showed that the company was incorporated on 24 December 2003 while the PIN Certificate indicated that the company was issued with the PIN on 10 December 2003. The court held that these discrepancies should have aroused the bank’s suspicions. The bank’s failure to carry out any official search at the Companies Registry, to request for any references, and to inquire on the physical address of the company all constituted negligence.
Regulatory Responses to KYC Vulnerabilities
The vulnerability of digital onboarding processes has prompted regulatory responses. The Central Bank of Kenya has issued guidelines on KYC and AML compliance. The Office of the Data Protection Commissioner has received over 5,200 complaints against digital lenders for data misuse, breaches of confidentiality, and consumer protection failures. This reinforces the vulnerability of digital financial services to identity theft and data breaches.
Parliament passed the Virtual Asset Service Providers Act 2025, bringing cryptocurrencies under CBK and CMA oversight. The Act requires service providers to have a physical office in Kenya, comply with KYC and AML rules, and undergo IT audits. This is a direct regulatory response to the kind of identity verification weaknesses identified in the case law. The Act reflects a recognition that digital financial services require a higher standard of verification than traditional physical banking.
The Need for a Higher Standard
The cases discussed in this section demonstrate that the same information used to open a physical account years ago is insufficient for verifying a new digital profile. A higher standard is required. The bank must verify the customer’s identity with a high degree of certainty before allowing a significant change to the account, such as the activation of digital banking. The bank must implement robust fraud detection systems capable of flagging anomalous transactions. The bank must not rely solely on knowledge-based information and OTPs sent to a mobile phone. Additional verification measures, such as biometric verification, physical appearance, or a physical signature, should be considered.
The consumer, for their part, has a duty to safeguard their credentials. The consumer must not share their PIN or password. The consumer must report any loss or theft of their ID or mobile phone promptly. The consumer must review their account statements regularly and report any discrepancies. The courts have recognised that the consumer has a duty to act reasonably. But the primary obligation rests on the bank. The bank is the gatekeeper. The gate must be secure.
V. Phone Number Reassignment as a Constitutional Privacy Crisis
The reassignment of mobile phone numbers after a period of inactivity has long been standard practice in the telecommunications industry. When a subscriber does not use their number for a specified period, typically 90 days, the number is deactivated and eventually reassigned to a new subscriber. The purpose of this practice is to ensure the efficient use of numbering resources. Mobile numbers are finite. If numbers were held indefinitely by inactive subscribers, the numbering system would eventually be exhausted.
The practice, however, has significant privacy implications. When a number is reassigned, the new subscriber may receive messages intended for the previous subscriber. Banks, government agencies, and other institutions continue to send one-time passwords, transaction alerts, and other sensitive information to the number. The new subscriber, who has no relationship with these institutions, becomes the unintended recipient of the previous subscriber’s private information. This constitutes a breach of the previous subscriber’s privacy. The previous subscriber’s data is disclosed to a third party without their consent.
The problem is particularly acute for prisoners, who are unable to use their phones for extended periods due to their incarceration. Prisoners who are sentenced to lengthy terms lose their numbers. Their data is disclosed to strangers. Their digital identity is erased. The same problem affects students in boarding schools, patients in hospital, migrant workers abroad, and families of deceased persons.
The Odhiambo Case
The constitutional dimensions of this problem were addressed in Odhiambo & another v Attorney General & another (Petition E290 of 2024) [2026] KEHC 3809 (KLR). The petitioners were prisoners serving long sentences. The first petitioner stated that upon his conviction, he lost his phone number due to lengthy duration of non-use. He stated that he had six children who required his advice, mentorship and presence as a father. Their schools had his mobile number through which they would share regular updates concerning the children’s progress but he is now unable to access that information. His business collapsed after he was convicted because he was no longer able to communicate with his employees. His number was registered with institutions such banks, social organisations, Kenya Revenue Authority, insurance companies, among others. Regular updates from those institutions and other sensitive information is now being received by third parties in breach of his right to privacy.
The second petitioner stated that he was sentenced to death on 12 October 2011 for the offence of murder, later re-sentenced to 20 years. Following his arrest on 24 January 2009, he never accessed his mobile phone and phone number again. His line was registered to Safaricom M-Pesa services, Cooperative Bank, Kenya Commercial Bank, Equity Bank, KRA, Nairobi Hospital among many others. His line has since been issued to another person. His information continues to be shared on this line.
The court made four important findings. First, the court declared that a registered mobile phone number constitutes a digital identifier linking personal data that relates to an individual’s private affairs hence qualifies for protection under Article 31 (c) and (d) of the Constitution to safeguard the right not have information relating to private affairs unnecessarily required or disclosed. The court held:
Given the elaborate legislative registration scheme that connects SIM registration to the official personal identification records of the subscriber, the mobile number is for all purposes a digital identifier that record provides a means a person can be identified directly or indirectly. A registered phone number has now become the means for authentication and verification credentials for online transactions where security codes such as OTPs are sent to authenticate transactions. The registered mobile number thus provides link to delicate personal data that qualifies for protection under the right to privacy under Article 31 of the Constitution.
Second, the court found that the provision in the existing regulations that allows deactivation of registered telephone numbers without interrogating if there exists a valid reason for non-use is unreasonable and arbitrary. It does not meet the constitutional standards of Article 24 or 47 of the Constitution. There are no public notices issued whether in newspapers, electronic media or websites indicating any intention to deactivate and/or reassign mobile numbers and no opportunity is given for providing explanation for non-use.
Third, the court issued a mandatory order directing the Attorney General, within six months from the date of the judgment, and in collaboration with all relevant Departments, to take all necessary and appropriate measures to safeguard digital identity associated with the registered mobile telephone number against unfettered deactivation, and subsequent arbitrary reassignment or recycling. The measures shall ensure reassignment of any deactivated and previously registered number shall only be possible if there is the previous registered owner’s informed and verifiable consent; after expiry of reasonable period following issuance of public notice which must be preceded by thorough documented verification process aimed at confirming the original registered owner cannot be located or has unequivocally revoked the rights to the number; and technical safeguards be put in place and implemented to prevent unauthorised exposure or transfer of personal data linked to previous registered owner to third parties upon reassignment or recycling of the number.
Fourth, the court ordered the Attorney General, in conjunction with the Kenya Prisons Service, to formulate and gazette an internal regulatory scheme that ensures the preservation of digital identity of the prisoners or persons deprived of liberty which has already been acquired through the registration of the mobile telephone number until the lawful incarceration is served. In default of implementing the above orders, at the expiry of the 6th month, in particular, the midnight of 19 September 2026, the reassignment and/or recycling of deactivated previous registered mobile numbers shall automatically cease to safeguard constitutional protection afforded by Article 31 (c) and (d) of the Constitution.
The Practical Implications of the Odhiambo Judgment
The Odhiambo judgment has far-reaching implications for telecommunications providers, banks, and consumers. The judgment recognises that a mobile phone number is not merely a service, but a digital identifier that connects the subscriber to their personal data. The subscriber has a constitutional interest in maintaining that connection. The telecommunications provider cannot arbitrarily sever it.
The judgment imposes a number of obligations on telecommunications providers. First, they must obtain the previous registered owner’s informed and verifiable consent before reassigning a number. This means that the provider must make reasonable efforts to contact the owner and obtain their consent. If the owner cannot be located, the provider must issue a public notice and conduct a thorough documented verification process. Second, they must implement technical safeguards to prevent unauthorised exposure or transfer of personal data linked to the previous registered owner to third parties upon reassignment or recycling of the number. This means that the provider must take steps to ensure that data intended for the previous owner does not reach the new owner. Third, they must preserve the digital identity of prisoners until the lawful incarceration is served. This means that the provider must not deactivate or reassign a prisoner’s number during their incarceration.
The judgment also imposes obligations on banks and other data controllers. The court’s reasoning applies equally to every data controller that uses mobile numbers as the primary means of authenticating data subjects. When a bank continues sending one-time passwords to a number that no longer belongs to the data subject, the bank is processing personal data in reliance on an identifier that is no longer accurate. The bank does not know this, but ignorance does not excuse the breach. Under Section 43 of the Data Protection Act, data controllers must notify the Data Commissioner of any personal data breach within 72 hours. A breach includes unauthorised disclosure of personal data. When a stranger receives your bank alerts, that is unauthorised disclosure. The bank is the disclosing party. The telco merely delivered the message.
The Data Spillover Problem
The problem of data spillovers is one of the most challenging aspects of number reassignment. A mobile number is not a container of data. It is a pointer. When a bank sends a message to a particular number, it does not consult the telco’s registry of current subscribers. It sends the message to the number. The telco delivers it to whatever SIM card currently bears that number. The bank has no way of knowing whether the number has changed hands unless the telco tells it. And the telco has no obligation to tell it, at least in terms of what the law is at the moment.
This means that data spillover is not a failure of the telco’s internal systems. It is a feature of the architecture. The number itself carries no memory of its prior associations. The problem is not that the telco fails to scrub the line. The problem is that the line has no independent existence. It is merely an identifier that third parties use to route information. When that identifier changes hands, the third parties do not learn of the change automatically. They continue routing information to the same address, now occupied by a different person.
The court’s solution was to require technical safeguards. But the only technical safeguard that would work is a notification mechanism that alerts every data controller who has ever associated that number with a data subject that the number has changed hands. No such mechanism exists in Kenya. Building one would require telcos to maintain a permanent registry of every association between every number and every data controller. That registry would itself be a massive database of personal data, creating new privacy risks. The gap between what the court ordered and what is technically possible is wide enough to swallow the entire reform effort.
VI. The Bank’s Duty to Flag Suspicious Transactions and Act on Red Flags
The bank’s duty to flag suspicious transactions and act on red flags is closely related to the gatekeeper duty discussed in Theme 1. The bank must not only have secure systems but must also monitor those systems for signs of fraud. The bank must act on those signs. The bank cannot process transactions on autopilot, ignoring warning signs that would alert a reasonable banker to the possibility of fraud.
The Shalimar Flowers Case
The classic statement of this duty was provided by the High Court in Shalimar Flowers Self Help Group v Kenya Commercial Bank (Civil Case 17 of 2015) [2016] KEHC 6238 (KLR). The plaintiff was a self-help group registered as a society. Its membership was mainly drawn from flower farm workers at the Shalimar Flowers Company, Naivasha. The group operated several bank accounts with the defendant bank. The signatories of the two accounts were the four officials of the group and one James Kelmanson, the General Manager of the Shalimar Flowers Company, who was the mandatory signatory. The group was a beneficiary of cash commissions given by the company’s flower customers abroad under the Fair Trade arrangement. Such payments would be deposited into the group’s accounts.
Between June 2008 and January 2009, a series of cheque payments and transfers were made from the group’s two accounts. Through four cheques, a total sum of KShs 2,216,182 was paid from the local currency account to a payee known as Tri-systems Technology. Similarly, between December 2008 and January 2009, there were five letters of instructions for cash transfers from the group’s Euro account. Four of the payments were to the Tri-systems Technology account and one to Marrs Innovations. The letters authorising these transfers and the cheques all bore the purported signatures of the authorised officials. The group’s former chairman and secretary were charged in court with various offences in connection with the payments.
The court found that the bank was negligent. The court held that all the red flags were waving in this case but the bank, by not exercising reasonable care and skill, missed or ignored them, thereby allowing the withdrawal, in quick succession, of large sums of money donated to flower workers as commissions. The court found on a balance of probability that the bank was negligent in the manner in which it handled and approved the nine payments and was 100 per cent liable.
The factors that constituted red flags included the nature of the plaintiff as a self-help group, the purpose of the account, the amounts involved, and the frequency of the transactions. The court took judicial notice of the fact that most flower farm labourers have as little formal education and eke out a livelihood being farm hands on the myriad flower farms around Naivasha. The sophistication of the majority of the equipment being paid for by the cash transfers would no doubt ring an incongruent bell in the mind of a reasonably discerning banker. The bank’s witness, the Operations Manager, called the first number on the specimen card and on all occasions the call was received by one of the signatories, the chairman, who was the seeming architect of the fraud. The court held that the bank ought to have satisfied itself that the signatories were not misusing their positions to defeat the intentions and purposes of the group.
The Diamond Trust Bank Case
The duty to flag suspicious transactions was affirmed in Diamond Trust Bank Kenya Ltd v Kariuki & another (supra). The court held that a bank is expected to flag suspicious transactions and that large, rapid transfers to unrelated accounts are exactly the kind of red flags that should be detected. The bank’s failure to act on the red flags was a breach of its duty of care.
The Equity Bank Case
In Equity Bank Kenya Limited v Kagai (Civil Appeal E094 of 2022) [2025] KEHC 7753 (KLR), the bank’s nine-month delay in investigating the customer’s report was itself negligent. The respondent lost his wallet containing his ATM card. He reported the loss to the police on 28 February 2019 and to the bank on the same day. However, investigations only commenced on 8 November 2019. The bank gave no explanation why a delay of almost nine months took place in conducting its own internal investigations. The court held:
Considering the nature of the claim it was required of them, to avail in evidence a detailed report of the investigation the bank did within their capacity, outside the role of the DCI. As it is, it seems like the bank did not take active steps with the urgency needed, to recover any amounts they could from the trail left by the fraudsters. The evidence shows that the investigation began slightly over 8 months later. Even then, the details of the investigations done by the bank on its own accord in evidence is scant. My analysis in the foregoing paragraphs, show how the defendant owed the plaintiff a duty of care and how the breached it and as a result he suffered damages. I find that the bank was negligent in this regard.
Proactive Fraud Detection
The importance of proactive fraud detection was underscored by the Safaricom Sacco case. Three suspects were detained over KSh 10 million stolen from Safaricom Sacco’s account at Cooperative Bank. The bank flagged suspicious transactions and alerted the Sacco, leading to the arrest of the suspects. This confirms that fraud detection systems are meant to work and that banks have the capacity to flag suspicious activity. They simply choose not to, or fail to, in many cases.
The Regulatory Response
The Central Bank of Kenya has issued guidelines on fraud management and cybersecurity. Banks are required to implement robust fraud detection systems, including real-time monitoring, transaction limits, and customer notification. The CBK’s stress tests now explicitly include cybersecurity risks. The regulator expects banks to invest in systems capable of detecting and preventing fraud.
VII. Apportionment of Liability in Multi-Party Fraud Chains
One of the most complex questions in consumer disputes is how to apportion liability when fraud involves multiple independent actors. A SIM swap by a telecommunications provider enables fraud in a bank account. A bank’s failure to flag suspicious transactions enables funds to be transferred to a third party. A fintech’s insecure systems enable identity theft. In each case, the question is not simply whether a particular party was negligent, but how liability should be apportioned among the parties.
The Diamond Trust Bank Case
The leading case on apportionment of liability in multi-party fraud chains is Diamond Trust Bank Kenya Ltd v Kariuki & another (supra). The court apportioned liability 60% to Safaricom (for the SIM swap) and 40 % to the bank (for failing to protect the account after the swap). The court held that both the bank and the mobile service provider had concurrent duties of care to the respondent. The SIM swap was the catalyst, but the bank’s failure to protect the account was equally an operative cause of the loss. The trial court correctly identified that both parties were negligent and that their actions jointly led to the respondent’s loss. The finding that the bank was 40% liable for the sum of KShs 1,788,601 was a reasonable and just apportionment of liability.
The reasoning of the court is important. The court rejected the bank’s argument that the SIM swap was the sole proximate cause of the loss. The court held that while the SIM swap was the enabling event that gave the fraudsters control of the respondent’s phone line, the financial loss occurred when the bank’s banking system permitted the fraudulent withdrawals. The fraud was a continuous sequence of events. The SIM swap compromised the respondent’s line, which was then used to access her bank account and transfer funds. The bank’s failure to act on the red flags was not a new and independent cause that superseded the SIM swap. It was a failure to discharge its own duty to safeguard the customer’s funds.
The VASP Act and Multiple Actor Liability
The Virtual Asset Service Providers Act 2025 reinforces the principle that multiple actors in the financial chain have independent obligations and can be held separately accountable for their failures. The Act requires crypto service providers to have a physical presence in Kenya and comply with AML/KYC rules. This means that each actor in the financial chain bears responsibility for their own compliance. A failure by one actor does not absolve another of their own duty.
The Restitutionary Principle
The restitutionary principle was applied in Lim & Another v Diamond Trust Bank Kenya Limited & 7 Others [2025] KEHC, where the court ordered recovery of funds from third parties who could not demonstrate bona fide receipt for value. This principle offers banks a secondary avenue of recovery, but it does not dilute the bank’s primary obligation to restore the customer’s funds. The bank must restore the customer’s funds and then pursue the fraudsters to indemnify itself.
In James Njoroge v Stanbic Bank Kenya Limited (supra), the court noted that two out of the fraudulent transactions (KShs 490,000 and KShs 361,000) were processed in favour of the same person, Patrick Njenga. Since the perpetrator was identifiable by the respondent, they ought to have restored the customer’s funds and conducted further investigations to indemnify themselves.
VIII. Consumer Data as a Constitutional Asset: Systemic Breach and Mass Harm
The traditional approach to consumer disputes focused on individual transactions. A customer lost money. The customer sued the bank. The court determined whether the bank was liable. The remedy was a refund of the lost funds, with or without interest. This approach was adequate for individual disputes. But it is not adequate for systemic breaches affecting millions of subscribers.
The Musungu Case
The Musungu case fundamentally changed the character of consumer disputes. The petitioners alleged a large-scale unlawful extraction, access, and dissemination of their personal and subscriber data by Safaricom, affecting approximately 11.5 million subscribers. The court found that the breach was not isolated but sustained, organised, and profit-driven, involving repeated transfers of data through digital platforms such as Google Drive, WhatsApp communications, email, and physical storage devices. The court held that the respondent’s conduct amounted to violations of the rights to dignity, privacy, and consumer protection. The unauthorised disclosure of betting patterns, financial transactions, geolocation data, and identity information exposed subscribers to stigma, reputational harm, psychological distress, and commercial exploitation.
The court’s reasoning on the nature of constitutional harm is important. The court held that once a systemic breach affecting a defined class of subscribers is established or reasonably inferred, it would defeat the very purpose of constitutional protection of informational privacy to require each affected individual to demonstrate the precise extraction or dissemination of his or her personal data. In matters involving large-scale digital data systems, such an evidentiary threshold would impose an impossible burden upon data subjects while simultaneously insulating data controllers from constitutional accountability by virtue of their exclusive possession of the underlying records.
In such circumstances, constitutional harm may properly be inferred from the nature, scale, and scope of the compromise itself, particularly where the respondent retains exclusive access to the technical records necessary for granular proof.
The court awarded general damages for breach of constitutional rights in the sum of Kenya Shillings Nine Hundred Thousand (KShs 900,000) to each of the petitioners. The court held:
The award is not punitive in character but is intended to vindicate the infringement of constitutional rights, affirm the sanctity of informational privacy under Article 31 of the Constitution, and underscore the dignity interest protected under Article 28 within the evolving architecture of the digital economy. It further serves as a principled affirmation that constitutional guarantees cannot be rendered illusory in the face of large-scale data processing systems, and that where violations are established, the Court will not hesitate to grant effective and meaningful relief commensurate with the gravity of the breach.
The Regulatory Framework for Data Protection
The Data Protection Act 2019 provides the statutory framework for data protection in Kenya. The Act defines personal data as any information relating to an identified or identifiable natural person. The Act requires data controllers to implement appropriate technical and organisational measures to ensure the security of personal data. The Act gives data subjects the right to rectification and erasure of personal data. The Act gives the Data Commissioner the power to enforce compliance and impose penalties.
The Data Commissioner’s Office has been active since its establishment. It imposed a five million shilling fine on Oppo Kenya in 2022 for processing personal data without consent. It has issued guidance on data protection impact assessments. It has registered data controllers and processors. The number reassignment issue gives the Commissioner an opportunity to define what compliance looks like in the telecommunications sector.
The Horizontal Application of Constitutional Rights
The Musungu case affirmed the horizontal application of constitutional rights to private entities. The court held that the Bill of Rights binds private entities that collect, process, and control personal data. The court held:
The constitutional architecture under Article 31 imposes obligations that are not merely derivative of employment relationships, but affirmative, structural, and non-delegable in character upon any entity that collects, controls, and processes personal data at scale.
This means that consumers can now hold banks, fintechs, and telecoms directly liable under the Constitution for systemic failures, not just under contract or tort. The consumer is no longer merely a party to a contract. The consumer is a constitutional actor whose digital identity, personal data, and privacy interests are entitled to protection not only against the state but against private entities.
IX. The Horizontal Application of Constitutional Rights to Private Entities
The horizontal application of the Bill of Rights is one of the most significant developments in Kenyan constitutional jurisprudence. Article 20(1) of the Constitution provides that the Bill of Rights applies to all law and binds all State organs and all persons. The term all persons includes private entities. This means that private entities, including banks, fintechs, and telecommunications providers, are bound by the Bill of Rights. They must respect and protect the rights of their customers and subscribers.
The Traditional View of Private Law
The traditional view was that constitutional rights protect individuals against the state. The Bill of Rights was a shield against state power. Private entities were subject to private law, including contract and tort. The courts could imply duties into contracts, but the duties were contractual in nature. They did not arise from the Constitution.
This view has been modified by the recognition that the Constitution applies horizontally. Private entities are bound by the Bill of Rights. They must respect the rights of others. They cannot violate the Constitution with impunity. This is particularly important in the context of data protection, where private entities collect, process, and control vast quantities of personal data. The data subject is in a vulnerable position. The data controller has the power. The Constitution must protect the data subject against the data controller.
The Musungu Case on Horizontal Application
The Musungu case is the leading authority on the horizontal application of constitutional rights to private entities. The court held that the respondent, as a data controller, bore a positive and non-delegable duty to secure subscriber data under Article 31. The court rejected the respondent’s reliance on WM Morrison Supermarkets PLC v Various Claimants (supra), holding that the reasoning in that case is confined to the sphere of private law tortious liability and does not define constitutional obligations arising from the protection of personal data under a written bill of rights.
The court held:
In constitutional litigation implicating informational privacy and data protection, that inquiry is necessary but not sufficient. The constitutional architecture under Article 31 imposes obligations that are not merely derivative of employment relationships, but affirmative, structural, and non-delegable in character upon any entity that collects, controls, and processes personal data at scale.
The court further held:
Common law vicarious liability, though relevant, does not conclusively resolve the question. The determinative inquiry is whether the Respondent discharged its constitutional obligation as a data controller to secure subscriber data against foreseeable misuse. Liability, if any, therefore arises not merely from the employment relationship, but from the Respondent’s direct constitutional duty under Article 31 to respect, protect, and safeguard personal data.
The Implications of Horizontal Application
The horizontal application of the Bill of Rights has great implications for consumer disputes. Consumers can now bring constitutional claims against private entities. They can seek declarations that their constitutional rights have been violated. They can seek constitutional damages, which are distinct from tortious damages. They can seek structural remedies, including orders directing the private entity to implement new policies and procedures.
The horizontal application also imposes new obligations on private entities. They must implement policies and procedures that comply with the Constitution. They must respect the rights of their customers and subscribers. They cannot hide behind contractual terms and conditions. The Constitution is supreme. It overrides any law or contract that is inconsistent with it.
X. Partial Refund or Recovery as Evidence of Negligence
A bank’s voluntary refund or recovery of funds can imply its recognition that the transactions were suspect. This principle was applied in a number of cases.
The Family Bank Case
In Family Bank Limited v Kiarie (supra), the bank’s voluntary refund of KShs 150,000 was an implied admission of the very wrong it now denies. The court held that the trial court was entitled to read the refund as an implied admission. The respondent had for over two decades held an account with the bank. Between the 7th and 10th of February 2022, a series of withdrawals which she said she neither authorised nor knew of drained a total of KShs 720,000 from her account. She reported the losses to the bank and, through the Banking Fraud Investigation Unit, to the police. Of the sum lost, KShs 40,000 was recovered by the police and a further KShs 150,000 was reimbursed by the bank on 24 April 2023, after her claim had already been filed. The court found that the bank owed the respondent a duty of care to safeguard her account and that, from the moment the fraud was reported, that duty was not discharged. The bank’s voluntary refund was a factor that the court considered in finding liability.
The James Njoroge Case
In James Njoroge v Stanbic Bank Kenya Limited (supra), the bank’s recovery of KShs 490,000 from a recipient was a factor to consider and demonstrated the bank’s own recognition that the transactions were suspect. The court held that while the recovery was not a complete admission of liability, it demonstrated the bank’s own recognition that the transactions were suspect and that it had a measure of responsibility to attempt recovery.
The Co-operative Bank Case
In Co-operative Bank of Kenya Ltd v Mutuku (supra), the court held that it behoves the bank to investigate who the culprit is and bring them to book so as to indemnify itself. The bank’s partial refund or recovery does not absolve it of its duty to investigate and pursue the fraudsters.
XI. The Role of Credit Reference Bureaus and the Liability of Reporting Entities
Credit Reference Bureaus play an important role in the financial system. They collect and maintain information about the credit history of individuals and businesses. They provide this information to lenders who use it to assess creditworthiness. The purpose of the CRB system is to enable lenders to make informed lending decisions, to reduce the risk of default, and to facilitate access to credit for borrowers with good credit histories.
The Wachira Case
The leading case on the role of Credit Reference Bureaus is Wachira v Safaricom Company Limited (supra). The plaintiff’s grievance stemmed from the alleged unauthorised registration of a mobile phone number under his national identity card, which he claimed led to unauthorised borrowing and subsequent adverse credit listing. The plaintiff sought declarations that the registration of the mobile number was unlawfully and illegally done; that the defendant was under obligation to pay any loans that may have been taken by the number; that the defendant was obliged to clear the plaintiff from any Credit Reference Bureau arising from any transaction involving the number; and general damages for personal data breach, mental anguish, and damaging plaintiff’s reputation as credit worthy citizen.
The court held that the mere fact that unauthorised lending occurred through a mobile number did not automatically establish liability on the part of the telecommunications provider. The court found that the defendant was in compliance with its regulatory obligations in the registration process, and operated within clear boundaries that did not extend to financial lending or credit reporting. To hold them liable for the independent actions of third parties who utilised their platforms would extend liability far beyond established legal principles and practical business realities.
The court further held that the plaintiff had not established a sufficient causal link between the defendant’s actions and his alleged damages. While the plaintiff suffered inconvenience and potential damage to his credit standing, those injuries could not be legally attributed to the defendant’s actions or omissions in the SIM card registration process. The plaintiff’s claim should have been properly directed at the relevant lending institutions and credit reference bureaus, not the telecommunications provider.
The Regulatory Framework for Digital Lenders
The Central Bank of Kenya has licensed 252 digital credit providers as of July 2026, following the approval of 25 additional firms. This licensing programme, introduced under the Digital Credit Providers Regulations 2022, has transformed a previously unregulated sector into a supervised consumer credit market with stricter standards on governance and customer protection. More than 800 applications have been received since March 2022. Licensed providers had disbursed 8.37 million loans valued at KSh 150.56 billion as of May 2026.
This means there is a clear regulatory framework identifying which entities are responsible for lending decisions and CRB reporting. Under the Regulations, licensed providers may disclose credit information to Credit Reference Bureaus, but must notify customers at least thirty days before submitting negative information. Consumers should direct complaints about CRB listings to these specific licensed entities, not to telecoms. The CBK is enforcing data protection and consumer protection standards among digital lenders. Licensed providers must obtain a certificate under Section 19 of the Data Protection Act from the Office of the Data Protection Commissioner as a pre-licensing condition, and must develop a robust data protection policy. The CBK is working closely with the ODPC to coordinate enforcement and ensure consistent application of data privacy standards.
The Problem of Unauthorised Lending
The problem of unauthorised lending through mobile numbers was highlighted in the Wachira case. The plaintiff’s mobile number was used to borrow loans from mobile apps which had not been paid, leading to adverse listing. The plaintiff brought this to the attention of the defendant who referred him to Kenya Police. The Police in turn referred the matter to the Office of Data Protection. The court held that the plaintiff’s grievance might be more appropriately directed at the lending institutions or credit reference bureaus who made the actual decisions that led to his alleged damages. The defendant, as a telecommunications provider, neither made lending decisions nor reported to credit reference bureaus.
This reflects the clear delineation of services and responsibilities in the financial system. The telecommunications provider provides the communication infrastructure. The lending institution makes the lending decision. The Credit Reference Bureau maintains the credit history. Each actor has their own duties and responsibilities. A consumer who suffers a loss must direct their claim to the appropriate actor.
XII. The Customer’s Duty of Prompt Notification and Its Impact on Bank Liability
The consumer has a duty to act reasonably. This includes a duty to safeguard their credentials and a duty to notify the bank promptly of any loss or theft. The consumer’s failure to notify the bank promptly can be a mitigating factor but does not necessarily absolve the bank, especially where structural failures exist.
However, the consumer’s duty is not absolute. The courts have been careful not to place an undue burden on consumers, particularly where structural failures are evident. In James Njoroge, the court recognized that a victim of violent robbery who has been drugged cannot be expected to report fraud within minutes.
The Equity Bank Case
In Equity Bank Kenya Limited v Kagai (supra), the bank was only held liable for transactions occurring after notification. The respondent lost his wallet containing his ATM card on 26 February 2019. He reported the loss to the police on 28 February 2019 and to the bank on the same day. The fraudulent transactions occurred on 26 February 2019, before the bank was notified. The court held that the bank would not have known that the transactions were fraudulent absent flagged notifications from the customer. The bank was not liable for the transactions that occurred before notification. However, the bank was liable for its nine-month delay in investigating the customer’s report after notification.
The James Njoroge Case
In James Njoroge v Stanbic Bank Kenya Limited (supra), while the bank argued an 11-hour delay was fatal, the court found the bank’s structural failure was the primary cause. The claimant was robbed on the morning of 13 July 2025. The fraudulent transactions occurred at 14:48 hours and 15:09 to 15:25 hours. The claimant’s spouse reported the incident to the bank at 17:19 hours. The bank argued that the delay materially contributed to the loss. The court considered the evidence that the claimant was a victim of a violent robbery and had been drugged. His wife reported the matter as soon as was practicable. More importantly, the delay was not the root cause of the loss. The theft occurred because the bank’s security protocols were inadequate. The loss would have been prevented if the bank had a robust verification process for new digital profiles. The delay in reporting does not excuse the bank’s structural negligence.
The Family Bank Case
In Family Bank Limited v Kiarie (supra), the bank was held liable for failing to act after notification, having admitted its practice was to freeze accounts upon fraud reports. The bank’s own practice required an account to be frozen once a fraud complaint is made. In this case, this was not done. The bank refunded the sum lost after the complaint. The court held that the bank’s duty to act was engaged from the moment the fraud was reported. The correct PIN defence was no answer to a breach that consists not in failing to divine the fraud, but in failing to act once the fraud was known.
Conclusion
The emerging trends in consumer disputes in banking, fintech, and telecommunications in Kenya reflect a fundamental shift in the relationship between consumers and service providers. The traditional contractual framework, with its emphasis on the correct PIN defence and the customer’s duty to safeguard their credentials, has been supplemented by a constitutional framework that recognises the consumer as a constitutional actor whose rights to privacy, dignity, and consumer protection are entitled to protection against private entities.
The gatekeeper duty of banks has been affirmed in a series of cases. The correct PIN defence is not absolute. The bank must act on red flags. The bank must have robust systems capable of detecting and preventing fraud. The bank cannot hide behind technical compliance when its systems fail.
The vicarious liability of banks for the actions of their employees has been affirmed. The bank is responsible for the acts of its employees committed in the course of their employment. The bank cannot evade liability by attributing the conduct to rogue employees where the conduct occurred through systems under the bank’s control and was facilitated by systemic failures.
The constitutional obligations of telecommunications providers as data controllers have been established. The mobile phone number is a digital identifier protected under Article 31. The unfettered deactivation and reassignment of phone numbers without consent is unconstitutional. The breach of subscriber data by employees constitutes a violation of Articles 28 and 31. The telecommunications provider bears a positive and non-delegable duty to secure subscriber data.
The vulnerability of KYC and digital onboarding processes has been exposed. The information used to open a physical account years ago is insufficient for verifying a new digital profile. A higher standard is required. The bank must verify the customer’s identity with a high degree of certainty before allowing a significant change to the account.
The apportionment of liability in multi-party fraud chains has been addressed. When fraud involves multiple independent actors, courts apportion liability based on each party’s independent failure. Each actor in the financial chain bears responsibility for their own compliance. A failure by one actor does not absolve another of their own duty.
Consumer data is now recognised as a constitutional asset. Systemic breaches affecting millions of subscribers constitute constitutional violations. Constitutional harm may be inferred from the nature, scale, and scope of the compromise itself. The courts will not hesitate to grant effective and meaningful relief commensurate with the gravity of the breach.
The horizontal application of constitutional rights to private entities has been affirmed. The Bill of Rights binds private entities that collect, process, and control personal data. Consumers can bring constitutional claims against private entities. They can seek declarations, constitutional damages, and structural remedies.
The role of Credit Reference Bureaus and the liability of reporting entities has been clarified. Liability for negative CRB listings rests with the entity that reported the default. The telecommunications provider is not the correct party to sue for a CRB listing. The consumer must direct their claim to the appropriate actor.
The customer’s duty of prompt notification has been recognised as a factor in assessing liability. The consumer must act reasonably. The consumer must safeguard their credentials and notify the bank promptly of any loss or theft. The consumer’s failure to notify the bank promptly can be a mitigating factor but does not necessarily absolve the bank, especially where structural failures exist.
The future of consumer disputes in banking, fintech, and telecommunications will be shaped by these emerging trends. The courts will continue to develop the law in response to new technologies and new forms of fraud. The regulators will continue to issue guidance and enforce compliance. The consumers will continue to seek redress for violations of their rights. The challenge for all stakeholders is to ensure that the legal framework keeps pace with technological change and that the rights of consumers are protected in an increasingly digital world.
As artificial intelligence and biometric verification become mainstream, the principles articulated in these cases will require further refinement. The courts have laid a strong foundation. The legislature and the regulators must now build upon it.
Authored by Benson Odiwuor Otieno Advocate of the High Court of Kenya.
This article is a publication of the Litigation Practice Notes series, featured in The BOLD Newsletter. For questions, clarifications, or suggestions on this or related subjects, contact the author directly: insights@bensonodiwuor.com / info@benodiwuor.com.
