Simbwa Phillip v Chipper Technologies Uganda Limited
Observed later treatment
No later-treatment classification is recorded for this judgment.
Citator coverage is limited to judgments in the Wakilii corpus and source-matched treatment records. Absence of a signal is not an assertion that the case remains good law.
AI-generated summary. This summary was generated by AI from the full text of the judgment. It may contain errors or omissions—always read the source judgment before relying on it.
Holding
The Personal Data Protection Office held that the respondent's retention of KYC and transactional data for ten years under the Anti-Money Laundering Act was lawful and did not infringe the complainant's data deletion rights. However, the respondent must obtain explicit consent before processing or sharing retained data beyond regulatory compliance purposes. The respondent's privacy notice adequately addressed notification obligations regarding data breaches and subcontractor access. No infringement was found, but the respondent was directed to amend its privacy notice to clarify consent requirements for additional data processing.
Outcome
Complaint dismissed with no infringement found; respondent directed to amend privacy notice to clarify consent requirements for data processing beyond regulatory compliance
Facts
On 25 November 2024, the complainant requested Chipper Technologies Uganda Limited to delete his personally identifiable information and KYC data. The respondent replied on 26 November 2024, requiring the complainant to cash out all funds before deletion and committing to address the request within 12-24 working hours. Dissatisfied, the complainant lodged a complaint with the Personal Data Protection Office on 27 November 2024. The respondent informed PDPO that it had fulfilled the deletion request but retained KYC and transactional data to comply with the ten-year retention requirement under the Anti-Money Laundering Act. The complainant raised additional concerns including lack of explicit consent for data processing beyond retention, notification of data breaches, notification when subcontractors access his data, and provision of a copy of all collected data. The PDPO reviewed the parties' submissions and the respondent's privacy notice.
Issues
- Whether there was an infringement of the Complainant's rights under the Data Protection and Privacy Act Cap. 97.
- If there was infringement, what remedies are available to the Complainant.
Orders
- PDPO finds no infringement of the Complainant's rights under the Data Protection and Privacy Act Cap. 97.
- The Respondent is required to explicitly clarify in its Privacy Notice that processing or sharing of retained personal data beyond regulatory compliance obligations necessitates prior explicit consent from data subjects.
- The Complainant retains the right to seek remedies through legal action pursuant to Section 33 of the Act Cap. 97 should the Respondent breach its commitments.
- Failure by the Respondent to adhere to this decision constitutes an offence under Regulation 48 of the Data Protection and Privacy Regulations, punishable by a fine of three currency points per day of default or imprisonment not exceeding six months, or both.
- Any party aggrieved by this decision may appeal to the Minister of ICT and National Guidance within thirty days from the date of receipt of this decision.
Rules and key headnotes
Legislation cited (10)
- Data Protection and Privacy Act Cap. 97 s.3(f)
- Data Protection and Privacy Act Cap. 97 s.16(1)(b)
- Data Protection and Privacy Act Cap. 97 s.23(1)
- Data Protection and Privacy Act Cap. 97 s.23(2)
- Data Protection and Privacy Act Cap. 97 s.24
- Data Protection and Privacy Act Cap. 97 s.33
- Data Protection and Privacy Regulations 2021 reg.29(1)(b)
- Data Protection and Privacy Regulations 2021 reg.46
- Data Protection and Privacy Regulations 2021 reg.48
- Anti-Money Laundering Act Cap. 118 s.8(3)
Full judgment
The original judgment as reported. Read the original PDF before relying on any passage.