Safaricom—Kenyan High Court ordered Safaricom to pay KES 9.9M for failing to protect customer data
On May 18, 2026 the High Court of Kenya ordered Safaricom to pay 9.9 million Kenyan shillings to a customer over a client data breach, holding that Safaricom could not escape liability by blaming individual employees. The judgment established that companies bear institutional responsibility for documented access controls, monitoring systems, and breach detection. Local commentary described the ruling as exposing systemic failures in Safaricom's customer-data protection regime.
Scoring Impact
| Topic | Direction | Relevance | Contribution |
|---|---|---|---|
| Consumer Protection | -against | secondary | -0.50 |
| Data Security | -against | primary | -1.00 |
| User Privacy | -against | primary | -1.00 |
| Overall incident score = | -0.357 | ||
Score = avg(topic contributions) × significance (high ×1.5) × confidence (0.57)× agency (negligent ×0.5)
Evidence (1 signal)
Safaricom ordered to pay KES 9.9 million over client data breach by Kenyan High Court
Techweez and The Informant Digital reported the Kenyan High Court judgment ordering Safaricom to pay 9.9 million Kenyan shillings for failing to protect customer data, holding the telecom institutionally responsible for documented access controls and breach detection rather than blaming individual employees.