Data protection fines in Africa are on the rise as more authorities enforce compliance with data protection laws. Data protection authorities in Angola and Kenya have hit the ground running by enforcing data protection laws. In this article, we highlight two recent case studies where data protection authorities in Angola and Kenya fined organisations for non-compliance with data protection laws. We also provide some insights into what organisations can learn from the fines that the authorities issued.
Angola
Angola has a robust regulatory framework that governs data protection. Law 22/11 on the Protection of Personal Data governs all kinds of personal data processing relating to identifiable natural persons. In 2016, a Presidential Decree established Angola’s regulatory body, the National Data Protection Agency (NDPA).
Case study 1 | NDPA fined Africell $150 000 for failing to get prior authorisation
The NDPA had been investigating Africell’s data processing practices for some time. In January 2023, the NDPA announced that they fined Africell $150 000. This was the second fine that the NDPA issued. In April 2022, they fined Banco de Poupança e Crédito (BPC) $525 000 for disclosing employee personal data on BPC’s special media pages. In comparison, the fine on Africell was not a very large sum, but still, an important one that we can learn from.
The NDPA said that Africell did not get prior authorisation from the NDPA when they processed their customers’ personal data. The NDPA showed some leniency towards Africell by imposing a lower fine on them because they:
- took immediate steps to ensure that they would comply with Law 22/11 in the future.
- did not violate data protection laws in the past. This was their first incident on record.
- was very cooperative during the NDPA’s investigation.
- did not gain economically despite processing their customer’s personal data without prior authorisation.
Key takeaways from this case study
When we study and compare the Data Protection Laws of Africa, we can gauge that the laws are 80% similar. For example, getting prior authorisation from a data protection authority to process certain types of personal data is a common requirement in most African countries. Organisations can avoid this type of fine altogether by ensuring that they obtain prior authorisation from a data protection authority if the law requires them to do so. The law generally states when you need to obtain prior authorisation. For example, if you process children’s personal data, or sensitive personal data like health data, in most countries, you may need authorisation from the data protection authority first.
If you receive a fine from a data protection authority, you can apply for a reduced fine in some instances, or you can make a payment arrangement if the law provides for it. A data protection authority is likely going to show leniency to your organisation if you are transparent, and you are willing to work with them and not against them.
Kenya
The Data Protection Act, 2019 is Kenya’s main data protection law. The law gives effect to the right to privacy as enshrined in the Kenyan Constitution. The Office of the Data Protection Commissioner (ODPC) regulates and enforces compliance with the provisions of the Act.
Case study 2 | The ODPC fined Oppo, Kenya KES 5 million for not complying with an enforcement notice
Oppo manufactures smart devices worldwide. In December 2022, the ODPC issued its first penalty notice against Oppo, Kenya. The ODPC announced that they fined Oppo KES 5 million because Oppo did not comply with a penalty notice (or enforcement notice in other jurisdictions) from the ODPC. A data subject lodged a complaint against Oppo because Oppo published the data subject’s photo on its social media page without the data subject’s consent. In the enforcement notice, the ODPC instructed Oppo to implement:
- A policy to get consent from data subjects to use their personal data for commercial purposes.
- An internal complaints process to enable data subjects to complain to Oppo directly.
Key takeaways from this case study
An enforcement notice from a data protection authority contains a list of actions that a controller should take, within a prescribed period, to rectify their non-compliance with the data protection law. It is an offence not to comply with an enforcement notice and you will get fined if you ignore it.
If you receive an enforcement notice from a data protection authority do not ignore it. Take the time to look at what the authority is asking you to rectify and do it. Make sure that you complete the order in the enforcement notice within the prescribed time period to avoid non-compliance.
You can avoid enforcement notices by implementing measures like a complaints policy and procedure on your website. Not only does this build trust between you and your data subjects, but it also enables data subjects to lodge complaints with you directly and prevents those complaints from reaching a data protection authority.
What does this mean for South Africa?
Although there were only three fines from African data protection authorities over the last year, we expect to see many more fines in 2023. South Africa’s data protection authority, the information regulator, is investigating complaints and has already referred the Department of Health to the enforcement committee for investigation. It’s therefore likely that the next fine will be from South Africa.
Actions you can take
- Keep updated with data protection developments in Africa by joining the Data Protection Programme.
- Get a customized Data Protection Laws of Africa report by asking us for a quote.