CloudGrid Africa

Compliance Decoder / Issue 2

Your customer paid by M-Pesa. That's not a marketing list.

Two businesses, in different industries, made the same mistake: they had a phone number for one reason and used it for another. Both were fined KES 5 million.

. 5 minute read. By , founder of CloudGrid Africa.

Whitepath Company, which runs the Instarcash and Zuricash lending apps, pulled contact lists from its borrowers' phones and used the numbers to send debt-collection messages to the borrowers' contacts. The ODPC fined it KES 5 million.[1] Regus Kenya kept marketing to a former client after the commercial relationship had ended. The High Court upheld the finding against it in Regus Kenya Limited v Data Protection Commissioner [2025] eKLR, trimming only the penalty because it was a first offence.[2]

Different sectors, same root cause: a number was collected for one purpose and used for a second, unrelated one.

The principle behind both cases

Section 25 of the Data Protection Act sets out the principles that govern all processing of personal data, and purpose limitation is one of them: data collected for a specified purpose cannot simply be redeployed for another.[3] A number captured to complete a payment, a loan, or a delivery was collected for that transaction. Marketing to it is a second, different purpose, and it needs its own lawful basis — usually fresh, specific consent.

This is also why an opt-out notice sent after the fact doesn't fix anything. The conditions courts have applied put consent first, not last: the person must have been told marketing was a purpose when the data was collected, and must have consented to it then. An opt-out mechanism only becomes relevant once those two things are already true.[2]

Why M-Pesa specifically keeps coming up

An M-Pesa transaction sends the payer's phone number to the recipient automatically, whether that recipient is a merchant, a landlord, or a friend. That number is easy to save and easy to reuse later for something the payer never agreed to — and reusing a payment number this way is now a pattern the ODPC has fined repeatedly, not an edge case.[1]

What "authorised under law" does and doesn't cover

Section 37(1) gives a second lawful basis for commercial use of personal data, alongside consent: authorisation under a written law, provided the person was told about that use when the data was collected.[4] This is a narrow exception, not a general excuse. It requires both a specific law and a specific notice given at the point of collection. "We had a legitimate business reason" does not meet it.

Digital lenders are held to the identical purpose-limitation principle in the ODPC's own guidance to that sector: data collected for risk assessment cannot be repurposed for unrelated activities such as marketing or indefinite tracking.[5] If a lender-specific regulator's guidance draws this line that clearly, a general business claiming a payment number doubles as a marketing list has even less ground to stand on.

What to do this week

  1. List every number your business currently messages for marketing.
  2. For each one, ask what it was originally collected for: a payment, a delivery, a loan application, a booking. If the honest answer isn't "we told them we might market to this number, and they agreed," it fails purpose limitation.
  3. Anything sourced from a payment confirmation, a delivery contact, or a colleague's phone goes on a stop list, not a warning list.
  4. If you want to keep marketing to that group, get fresh, specific consent under section 32 — collected and logged the way issue 1 describes, not assumed from an existing opt-out window.
  5. Record the source of every number next to it in your consent log. "Collected at checkout, marketing box ticked" and "read off an M-Pesa alert" are not the same record, and the second one is the one that gets businesses fined.

This is general information based on public ODPC and court decisions, not legal advice. Confirm your own position with a lawyer before acting on it.

Sources

  1. Manwa Advocates, "Data Protection Compliance in Kenya for Foreign Companies" (Whitepath / Instarcash / Zuricash, KES 5 million fine) — manwaadvocates.com
  2. OLM Law, "Data Protection Compliance in Kenya: 2026 Guide" (Regus Kenya Limited v Data Protection Commissioner [2025] eKLR; burden of proof for consent) — olmllp.com
  3. CIPIT Strathmore, "An Overview of the Kenyan Law on Commercial Use of Personal Data" (section 25 principles, including purpose limitation) — cipit.strathmore.edu
  4. AB & David Africa, "Beyond the Text of the Law: Adopting Best Practices for Direct Marketing in Kenya" (section 37(1) and (2)) — abdavid.com
  5. Office of the Data Protection Commissioner, Guidance Note for Digital Lenders (purpose limitation, data minimisation) — odpc.go.ke (PDF)
CloudGrid Africa assistantAI assistant. Do not share passwords or card details.