| Authority: | ODPC - Kenya |
|---|---|
| Jurisdiction: | Kenya |
| Relevant law: | Legal Provisions Reviewed |
| Type: | Suo Moto INvestigations |
| Outcome: | Violation |
| Started: | 13 May 2024 |
| Decided: | 18 Dec4ember 2024 |
| Published: | Yes |
| Fine: | N/A |
| Parties: | Nala Maternity & Nursing Home Limited |
| Case No.: | 0010 of 2024 |
| Appeal: | N/A |
| Original Source: | ODPC |
| Original contributor: | MZIZI Africa |
The ODPC initiated a suo motu investigation into Nala Hospital following reports of unauthorized disclosure of a patient’s sensitive health data on social media. The hospital was found to have breached data protection laws. The ODPC issued an enforcement notice requiring corrective actions, including policy updates, staff training, and security improvements.
On May 13, 2024, the Office of the Data Protection Commissioner (ODPC) initiated a suo motu investigation against Nala Maternity & Nursing Home Limited, a medical facility based in Kakamega. The investigation was triggered by growing public concern over the facility’s data processing practices, particularly the handling of sensitive health data.
The ODPC raised five main areas of concern:
In its email dated May 20, 2024, Nala Maternity & Nursing Home defended its practices, asserting that: