On May 13, 2026, Kenya's High Court delivered a ruling that most companies handling customer data in the country should read carefully, even though most of the coverage that followed focused on the money involved rather than the actual mechanism of the breach. In Constitutional Petition E095 of 2026, Justice Bahati Mwamuye found Safaricom PLC liable for violating the constitutional rights of eleven subscribers whose personal and financial data had been extracted from the company's systems and passed on to outside parties without their knowledge. Each petitioner was awarded KSh 900,000, bringing the total direct payout to KSh 9.9 million, a modest figure for a company of Safaricom's size. What made the ruling significant was not the amount. It was the reasoning behind it.
The underlying facts, as they emerged through the litigation, described a breach that took place between 2018 and 2019, involving subscriber and betting-related data, including M-Pesa transaction records and geolocation information, that court records show was repeatedly transmitted to multiple third parties, among them entities linked to betting platforms, for commercial purposes. The individuals responsible reportedly held privileged, insider-level access to Safaricom's systems, the kind of architecture-level visibility that comes with certain technical and auditing roles rather than the standard access given to an ordinary employee.
The Incident: A Breach That Lived Inside the Permission System, Not Outside It
This is the detail worth sitting with, because it is the part most relevant to any Kenyan business thinking about its own exposure. This was not a case of an external hacker breaking through a firewall. It was a case of individuals who were already inside the system, with legitimate credentials and legitimate reasons to be there for parts of their job, using that same access for purposes it was never meant to serve.
Safaricom's defence in court rested on a familiar argument, one that companies across many industries have relied on when something goes wrong internally: that the individuals responsible acted outside their authority, and that the company itself should not bear constitutional responsibility for what amounted to rogue conduct by a small number of employees. The court did not accept this. Justice Mwamuye's ruling found that the breach reflected systemic weaknesses in Safaricom's own data governance, internal oversight, and security controls, and held that a company cannot delegate away its constitutional duty to protect personal data simply because the actual wrongdoing was carried out by individual staff members. The ruling also established that Article 31 of Kenya's Constitution, the right to privacy, imposes what the court described as a non-delegable duty on any organisation acting as a data controller.
Why This Case Matters Beyond Safaricom
It would be a mistake to treat this ruling as a story specific to one telecom company. The pattern it describes, a small number of individuals with elevated system privileges using that access for purposes far removed from their actual job function, over an extended period, without being detected through the company's own internal controls, is a structural risk that exists in any organisation where certain roles carry broad access to sensitive systems. Banks, fintech firms, hospitals, insurers, and any company running its own data centre or server infrastructure in Kenya face a version of the same underlying exposure.
What the ruling does not spell out, because it was not the central legal question before the court, is exactly how that kind of extended, undetected insider access typically continues for as long as it did in cases like this. Security professionals who study insider threats generally point to a consistent pattern: organisations tend to invest far more heavily in guarding against external, digital intrusion, firewalls, intrusion detection, encrypted traffic, than they do in monitoring and limiting what their own privileged staff can quietly do once they are already inside the system, including the physical spaces where that system's core infrastructure actually sits.
Where Physical Access Controls Intersect With This Kind of Risk
This is where physical security and cybersecurity, often treated as entirely separate departments within a company, actually need to work together. An employee with architecture-level access to a subscriber database is, in most organisations, also someone who can physically walk into a server room, network operations centre, or data centre without triggering any particular scrutiny, precisely because their role already grants them legitimate reasons to be there.
A properly converged security approach treats this overlap seriously. Role-based physical access, meaning that even staff with legitimate system privileges do not automatically receive unrestricted physical access to every server room or data centre zone, is one part of this. Requiring a second, independent authorisation for physical entry into the most sensitive infrastructure areas, separate from a person's regular digital credentials, is another. Logging physical entry against a specific, verified individual, rather than a shared or generically issued access card, closes the same kind of gap that made it difficult, in cases like this one, to trace exactly how and when unauthorised extraction actually occurred.
None of this suggests that Safaricom's specific breach involved a physical security failure. The public record centres on system-level privilege abuse, not a described physical intrusion, and it would be inaccurate to claim otherwise. What the case usefully illustrates, though, is the broader principle that insider risk rarely respects the boundary between physical and digital security, and companies that treat the two as unrelated disciplines, managed by entirely separate teams with little coordination, tend to have larger blind spots than they realise.
Comparing This Case to a Purely External Breach Scenario
It is worth contrasting this kind of insider-driven breach against a more conventional external intrusion, since the appropriate response differs meaningfully between the two. A company breached by an external attacker exploiting a software vulnerability typically responds by patching systems, strengthening perimeter defences, and reviewing network monitoring, technical fixes aimed at keeping unauthorised outsiders out.
An insider-driven breach, by contrast, cannot be solved through perimeter hardening alone, since the person responsible already has legitimate access by design. The more relevant response involves tighter role segregation, so that no single individual holds broad, unmonitored access across multiple sensitive systems, combined with converged physical-digital audit trails that make unusual patterns of access, digital or physical, visible before they continue for months or years undetected. The Safaricom case, on the facts that became public through litigation, sits clearly in this second category, and it is a useful reminder that a company can have genuinely strong external cybersecurity defences while still carrying a significant, unaddressed insider risk.
What Kenyan Businesses Should Take From the Ruling
For any company handling customer financial or personal data in Kenya, the practical takeaway from this ruling is not primarily legal, though the precedent around non-delegable data protection duties matters considerably and is worth discussing with a qualified data protection lawyer or compliance professional given how directly it affects corporate liability. The more operational takeaway is that privileged access, whether to a database, a server room, or both, needs to be treated as a standing risk requiring active management, not a one-time provisioning decision made when someone joins a technical team.
Reviewing who currently holds broad system privileges, whether that access is still necessary for their actual role, and whether physical entry to sensitive infrastructure is logged against verified individuals rather than shared credentials, is a reasonable starting exercise for any Kenyan business handling data at meaningful scale. Companies without in-house expertise to design this kind of converged physical-digital access review often benefit from bringing in a security integrator with genuine experience in both domains rather than treating it as purely an IT project. At Secuwatch, we can help businesses identify vetted security technology providers in Kenya with relevant experience in access control and physical-digital security convergence, a more specialised combination than standard CCTV or guarding services. We'd recommend confirming a provider's PSRA licensing status and specific track record with this kind of integrated system directly before committing.
Conclusion
The Safaricom ruling will likely be remembered mainly for the legal precedent it set around corporate accountability and the rejection of the "rogue employee" defence. For anyone responsible for security at a Kenyan company, though, its more immediate lesson sits a level below the legal reasoning: privileged access, left unmonitored across both digital systems and the physical spaces that house them, is one of the more persistent and least visible risks a business can carry. Closing that gap requires physical security and cybersecurity teams to stop operating as separate departments and start reviewing insider access as the single, converged risk it actually is.