
Author: Lennox Angugu
The Office of the Data Protection Commissioner recently issued three penalty notices to three data controllers for failing to observe privacy rights and not complying with the law. In a statement from ODPC; Mulla Pride Ltd, a digital credit provider which operates KeCredit and Falcrash mobile lending apps, received a penalty of Sh2,975,000. This was after it was found culpable of using names and contact information of the complainants, which were obtained from third parties, and subsequently used to send threatening messages and phone calls.
The Constitution of Kenya 2010, provides a right to consumer protection under Article 46 read together with Article 31. There are established principles for good business practice in the financial services sector as highlighted in United Nations Conference on Trade and Development (UNCTAD), Manual on Consumer Protection 2016. Consumer protection Act, part 7 is the provision established under Kenyan law to deal with matters involving credit agreements.
The Central Bank of Kenya is established under Article 231 of the Constitution of Kenya, 2010. The Central Bank has a duty to promote financial stability through regulation, supervision and licensing of financial institutions under its mandate. Financial consumer protection is a constitutional right and it ought to be treated as such. This bestows enormous responsibility on the regulators of the financial sector to inculcate and enforce it.While much of the regulatory function of the CBK is prudential, there is no doubt that prudential regulation is in itself important in ensuring the health and stability of financial institutions, and this is key to consumer protection because the collapse of such institutions is arguably, the ultimate blow to consumer interests.
Digital credit lending has become an increasingly prominent source of borrowing . Digital lenders leverage non-traditional data (e.g. mobile phone usage data) instead of financial histories for credit assessment and deliver consumption credit via widely-spread mobile money networks . The Digital Credit Providers Regulations, 2022 purpose was to address the increasing complaints by consumers over the methods employed by DCPs in debt collection and their apparent disregard for consumer protection and data protection principles. The legal framework enhances transparency ensuring customers are informed of the terms of any loan agreement entered into and, limit amounts recoverable upon default on loan repayment.
Conduct of DCPs – in the regulations (section 20 )DCPs are prohibited, in their recovery efforts, from using threat, violence or other means to harm borrowers, their reputation or property; or accessing borrowers’ contacts lists and using obscene or profane language for purposes of shaming them; or using improper or unconscionable debt collection tactics, methods or conduct.
Privacy – DCPs are to put in place (section 24,25,26 )appropriate policies, procedures and systems to ensure confidentiality of customer information and transactions.This is also in line with article 31 of COK and Data Protection Act.
Transparency and Informed Consent – DCPs( section 25) must inform their customers of the terms and conditions of the loan before granting the loan. Any changes must be notified to the customer at least 30 days before their effective date. Customers are also entitled to receipts of transactions and upon request, a comprehensive statement of transactions carried out by them. Advertisements must not include false, misleading or deceptive representation.
Complaints reporting and resolution – DCPs ( section 22) are also required to establish and inform their customers of the complaints redress mechanisms. Customer complaints should be resolved within thirty days and a record of all complaints and the outcome of their resolution kept.
CONCLUSION
The modern era requires the state via its agencies to enhance its fight against rogue business owners who disrespect the Constitution and to ensure the consumers are always protected.