Skip to main content
company

Safaricom

Kenya's largest telecommunications operator and creator of M-Pesa, the world's most successful mobile money platform. Partially owned by Vodafone Group.

Track Record

Following Vodacom's June 30, 2026 completion of a deal buying a controlling 55% stake in Safaricom (KES 204bn/EUR1.36bn for 15% from the Kenyan government plus KES 68bn/EUR450m for 5% from Vodafone), Safaricom sought and won shareholder approval on July 31, 2026 to remove long-standing governance protections tied to Kenyan-government ownership. The changes give Vodafone/Vodacom the right to nominate the CEO and all executive and shareholder-appointed directors (previously requiring board/government input), remove the requirement for government approval before regional expansion including into Ethiopia, eliminate the requirement that the executive committee be 'predominantly Kenyan', replace prior 10%/40% ownership-threshold protections with a single 50% threshold, and drop the mandatory dividend policy. Vodacom subsequently appointed two South African executives to Safaricom's board, increasing its board representation to 5 seats while Kenyan-government ownership fell from 35% to 20%.

negligent $34K

On July 13, 2026 Justice Asenath Ongeri ruled that Safaricom and Diamond Trust Bank must compensate a customer who lost KES 4.4 million to SIM-swap fraud, apportioning 60% of liability (about KES 2.63 million) to Safaricom and 40% to the bank. The court found that permitting the fraudulent SIM swap was 'a direct and proximate cause of the loss', rejected the argument that a correctly entered PIN absolves the providers, and dismissed Safaricom's cross-appeal against its liability share. The ruling sets a consumer-protection precedent for Kenya's mobile-money ecosystem.

Al Jazeera's 'Invisible Eyes' documentary (May 2026) exposed that Safaricom allowed Kenyan security agencies access to subscriber location data, call records, and M-Pesa financial transactions -- often without court orders -- to surveil, locate, and track activists and protesters. A Safaricom employee admitted in court to complying with a government data request without a court order. The Law Society of Kenya filed a constitutional petition seeking a court audit of all data requests from June 2024 to December 2025.

negligent $77K

On May 18, 2026 the High Court of Kenya ordered Safaricom to pay 9.9 million Kenyan shillings to a customer over a client data breach, holding that Safaricom could not escape liability by blaming individual employees. The judgment established that companies bear institutional responsibility for documented access controls, monitoring systems, and breach detection. Local commentary described the ruling as exposing systemic failures in Safaricom's customer-data protection regime.

negligent

Kenya's High Court (Constitutional Petition E095 of 2026, Justice Bahati Mwamuye) ruled on May 13, 2026 that Safaricom violated the constitutional data-privacy rights of 11 subscribers whose personal information was harvested and offered for sale by a Safaricom employee in 2019. The employee, who had unrestricted access to subscriber records, extracted data on roughly 11.5 million betting-platform customers (names, IDs, mobile numbers, gambling activity, device identifiers, and location data) and attempted to sell it to a rival betting company before informants exposed the scheme. Court records showed Safaricom's litigation team initially denied any breach occurred in a 2019 affidavit, only admitting the incident three months later. The court awarded each of the 11 petitioners KES 900,000 (total KES 9.9 million) and established that data controllers owe a 'positive and non-delegable' constitutional duty to safeguard customer data that cannot be shifted onto individual 'rogue' employees, and that harm need not be financial to be compensable.

After Safaricom's billing system failed to charge daily Fuliza overdraft fees between February 26 and March 20, 2026, the company applied a single lump-sum 'catch-up adjustment' deducting the accumulated unbilled fees from affected M-Pesa accounts simultaneously, without itemized statements or advance customer consent. Affected customers, including a Nairobi law firm partner who called the deduction 'theft,' said they received no forewarning before funds were withdrawn. Safaricom confirmed the one-time adjustment covered all affected accounts and said no further adjustments would follow, but did not offer itemized billing or an opt-out. The episode adds to a pattern of customer complaints about non-consensual Fuliza-linked deductions from M-Pesa balances.

In March 2026, Safaricom introduced mandatory masking of sender mobile numbers displayed in M-Pesa transaction messages, a data-minimization measure intended to curb fraud and unwanted contact enabled by exposed phone numbers. The company said the change was part of a wider privacy-by-design push, alongside its ISO/IEC 27701:2019 privacy certification. The feature applies broadly to P2P transactions and cannot be opted out of, though transaction verification and reversal mechanisms remain in place.