Skip to main content

SafaricomKenya High Court found Safaricom liable for 2019 subscriber data breach, rejecting 'rogue employee' defense

Kenya's High Court (Constitutional Petition E095 of 2026, Justice Bahati Mwamuye) ruled on May 13, 2026 that Safaricom violated the constitutional data-privacy rights of 11 subscribers whose personal information was harvested and offered for sale by a Safaricom employee in 2019. The employee, who had unrestricted access to subscriber records, extracted data on roughly 11.5 million betting-platform customers (names, IDs, mobile numbers, gambling activity, device identifiers, and location data) and attempted to sell it to a rival betting company before informants exposed the scheme. Court records showed Safaricom's litigation team initially denied any breach occurred in a 2019 affidavit, only admitting the incident three months later. The court awarded each of the 11 petitioners KES 900,000 (total KES 9.9 million) and established that data controllers owe a 'positive and non-delegable' constitutional duty to safeguard customer data that cannot be shifted onto individual 'rogue' employees, and that harm need not be financial to be compensable.

Scoring Impact

TopicDirectionRelevanceContribution
Consumer Protection-againstsecondary-0.50
User Privacy-againstprimary-1.00
Overall incident score =-0.372

Score = avg(topic contributions) × significance (high ×1.5) × confidence (0.66)× agency (negligent ×0.5)

Evidence (2 signals)

Confirms Legal Action May 19, 2026 documented

Court rejected Safaricom's 'rogue employee' defense, citing WhatsApp evidence of unrestricted data access

Coverage of the ruling detailing how WhatsApp chat messages presented as evidence showed Safaricom employees had unrestricted access to subscriber data, and that the court rejected the company's attempt to characterize the breach as isolated individual misconduct rather than a systemic control failure.

Confirms Legal Action May 13, 2026 verified

Kenya High Court ruling (Constitutional Petition E095 of 2026) finds Safaricom liable for subscriber data breach

High Court of Kenya judgment (Justice Bahati Mwamuye, Constitutional Petition E095 of 2026) held Safaricom liable under Articles 28, 31 and 46 of the Constitution for failing to prevent an employee from harvesting and attempting to sell subscriber data, awarding KES 900,000 to each of 11 petitioners.

Related: Same Topics