The rise of unsolicited promotional messages in Kenya is transforming direct marketing from being a commercial nuisance into a legal and constitutional concern. Recent enforcement action from the Office of Data Protection Commissioner (ODPC), Precisely, in Quincy Jesse Kiptoo v Pepino’s pizza Inn ODPC Complainant No. 0474 OF 2025 signaled a decisive relocation in how consent, purpose limitation and the interpretation of commercial use of data (under the Data Act, 2019).
Ergo from the foregoing, this paper seeks to interrogate the emerging jurisprudence on Commercial use of Data together with Direct Marketing, it argues that Business owners in Kenya have systemically misconstrued transactional data collection (precisely through mobile money and retail transactions) as implied consent for advertising, a position now firmly rejected by the regulator.
Drawing illustration from the Pepino’s decision as a focal case study, the paper addresses the legal and statutory thresholds for “express, free, specific, informed and unequivocal consent” under section 26(a) and 37 of the Data Protection Act 2019, it demonstrates why routine transactions won’t ground commercial messaging(lawfully). It positions this enforcement trend with the CoK provisions under article 31, accentuating the plight of purpose creep and the deterioration of consumer autonomy. The paper extends its analysis through sectoral reviews of enforcement actions against telecommunication companies, betting companies, supermarkets and banks, all revealing a recurring pattern of compliance failures (including but not limited to bundled consent)
Conclusively, the paper postulates that the ODPC’s approach marks an important normative shift from data use grounded in rights and data use for convenience. It proposes regulatory and designbased reforms, aiming at strengthening consumer trust and curbing the normalization of unlawful commercial use of data in Kenya.