
NCBA Bank has been slapped with a Sh250,000 fine by the Office of the Data Protection Commissioner (ODPC) for violating Kenya’s data privacy laws after it inadvertently shared a customer’s personal information to the wrong email address.
The fine, issued under the provisions of the Data Protection Act, 2019, marks a growing regulatory crackdown on companies that mishandle personal data in Kenya.
It also underscores the increasing emphasis on digital accountability and customer data protection in the financial sector.
The data breach occurred when NCBA dispatched a customer’s confidential account information to an unintended recipient.
The details included bank statements and possibly other personal identifiers. The affected customer reported the incident to the ODPC, prompting an investigation into whether the bank had followed lawful data handling procedures.
Following the probe, the ODPC found that NCBA had failed to implement necessary safeguards to ensure the confidentiality and integrity of customer information during digital communication.
Specifically, the bank was found to have violated Section 25 of the Data Protection Act, which obligates data controllers to ensure personal data is processed lawfully, transparently, and securely.
In its ruling, the ODPC stated that NCBA did not demonstrate sufficient diligence in verifying the email address used before dispatching sensitive financial data, thereby exposing the customer to potential risk of financial fraud or identity theft.
The Data Protection Act, enacted in 2019, mandates organizations to protect personal data against unauthorized access or accidental disclosure.
It provides for administrative penalties of up to KSh5 million or 1% of an entity’s annual turnover—whichever is lower—for breaches of data protection principles.
“The bank’s actions amounted to a breach of the confidentiality principle, which is fundamental to data protection,” said a spokesperson from the ODPC. “All data controllers and processors are required to adopt technical and organizational measures to safeguard personal data.”
The NCBA case highlights a wider concern about data security in Kenya’s banking sector, where the growing digitization of services also increases risks of data mishandling.
With rising public concern over data misuse, the ODPC’s enforcement action sends a clear signal: institutions must prioritize compliance or face punitive consequences.
Legal experts say the fine, although modest, sets a strong precedent and should spur companies—especially those handling sensitive financial or health data—to invest in stronger data management systems.
As of this publication, NCBA had not released a formal public response to the ODPC’s decision. However, sources within the banking industry suggest the bank is reviewing its internal data protection protocols and could roll out fresh measures to prevent future lapses.




