A chicken seller in Kiambu took a customer's M-Pesa payment, then used the number from that payment to send him promotional messages about the business. The customer complained to the Office of the Data Protection Commissioner (ODPC). The Commissioner found the business had unlawfully used his data for direct marketing and awarded him KES 250,000 in damages. The business appealed, and the High Court cut the award to KES 50,000 — but it did not overturn the finding that the marketing was unlawful.[1]
The court's reasoning is the part worth keeping. The business argued its texts were "after-sale customer engagement," not marketing, and that the customer's own failure to opt out cured any problem with consent. The court rejected both. It set out cumulative conditions that must all be true before direct marketing is lawful: the data must be collected directly from the person, they must be told marketing is an intended purpose, they must consent to it, a simple opt-out must exist, and they must not have used it. No evidence was produced that the customer was told his number would be used for marketing, or that he consented, or that an opt-out mechanism even existed. His silence could not fix an absent yes. (Jaggys (Kienyeji Chicken) v Gichunge [2026] KEHC 6856 (KLR).)[1]
The rule behind the case
Under section 32(1) of the Data Protection Act, the burden of proving consent sits with the data controller, not the data subject.[1] Consent itself must be express, unequivocal, informed and freely given.[1] Two further points from other ODPC determinations sharpen this:
- Verbal consent counts only if it was documented at the time it was given — an unwritten assurance is treated as no consent at all. The ODPC applied this directly in Comfort Muthoni Gachiri v The Storage Trading Company Limited.[2][8]
- Consent obtained for one purpose does not extend to a different one. Payment consent is not marketing consent — the ODPC made this point in its Bohemian Flowers determination.[2]
This is not a one-off ruling. Pepinos Pizza Inn was fined KES 250,000 by the ODPC for marketing SMS, after arguing that consent was captured during an M-Pesa payment transaction — the ODPC rejected that outright.[3] Regus Kenya was fined KES 5 million for continuing to market a former client after the relationship had ended; the High Court upheld the finding against it in Regus Kenya Limited v Data Protection Commissioner [2025] eKLR, reducing only the penalty in recognition of a first offence.[4] Oppo Kenya was fined KES 5 million for posting a customer's photograph on Instagram with no consent on record.[4] In 2025 the ODPC determined 96 complaints and issued penalties of up to KES 1.5 million — almost double the complaint volume of the year before.[5]
What to keep
One row per person, per purpose. Marketing SMS and photo use need separate rows, since consent for one doesn't cover the other.[2]
- Name and phone number or email
- Date and time consent was given
- Channel — checkout form, WhatsApp, paper form, event sign-up
- Purpose — SMS offers, WhatsApp offers, email, photo use
- The exact wording shown, with a version number
- Evidence — a screenshot, form ID, or a scan of the signed paper
- Who collected it
- Opt-out date, if any, and who processed it
The wording matters too. Before seeking consent, the person must be told who is asking, why the data is wanted, and what data will be used.[6] A sentence that does the job, with the box left unticked by default:
"Tick to get offers from [Business] by SMS or WhatsApp. We use your number only for this, and you can stop any time by replying STOP."
Make opting out easy
Kenya's Data Protection (General) Regulations, 2021 require an opt-out mechanism that is clearly explained, takes minimal effort to use, provides a direct communication channel, and is free or only nominally priced. Once someone opts out, their data must not be used for direct marketing again.[7] Record the opt-out the day it arrives and remove the number from every list you use, not just the one it came in on.
Photos
Get written consent before using a customer's image, and say exactly how it will be used. "I found it online" is not consent, and WhatsApp marketing is covered by the same law as SMS or email.[2]
Do this week
- Export every list you message: WhatsApp broadcast, SMS tool, email.
- For each list, ask where the numbers came from. Any sourced from M-Pesa statements or a customer database, with no recorded yes, should stop being used until you have one.
- Add the tick-box wording above to your checkout, form, or sign-up sheet.
- Start the log today, even as a spreadsheet.
- Write down who handles STOP requests, and how fast they're processed.
This is general information based on public ODPC and court decisions, not legal advice. Confirm your own position with a lawyer before acting on it.
Sources
- Mutie Advocates, "High Court Reduces ODPC Compensation Award from Kshs. 250,000 to Kshs. 50,000 and Clarifies Principles for Assessing Data Protection Damages" — case: Jaggys (Kienyeji Chicken) v Gichunge [2026] KEHC 6856 (KLR) — mutie-advocates.com
- Njogu Associates, "What SMEs Need to Know About Data Protection in Kenya" — njoguassociates.com
- Techweez, "Sending Marketing SMS Without Consent Can Get You Fined" — techweez.com
- Manwa Advocates, "Data Protection Compliance in Kenya for Foreign Companies" — manwaadvocates.com
- OLM Law, "Data Protection Compliance in Kenya: 2026 Guide" — olmllp.com
- Kenya Law, The Data Protection (General) Regulations, 2021, regulation 14 (information to be given when seeking consent) — new.kenyalaw.org
- Kenya Law, The Data Protection (General) Regulations, 2021, on opt-out mechanisms and direct marketing — new.kenyalaw.org
- Office of the Data Protection Commissioner, determination in Comfort Muthoni Gachiri v The Storage Trading Company Limited (primary source PDF) — odpc.go.ke
Need help building a consent log or reviewing your marketing lists against the Data Protection Act?