Most companies say they take privacy seriously. The harder question is what actually happens behind the login screen, inside the office and before a new product reaches customers.
Safaricom embeds privacy and security into the design of its products and services through secure-by-design principles, alongside restricted access controls, continuous monitoring, independent audits, enhanced authentication and privacy management practices aligned with ISO 27701.
Nick Mulila, Group Chief Risk Officer, told NewsTrendsKE that privacy cannot sit with a few compliance officers and still work across a company of Safaricom’s scale.
“It cannot be five guys sitting in an office somewhere who control the whole company. It has to be baked in.”
Before a product goes live
Safaricom applies what it calls privacy by design and security by design — the company says security questions are considered while a product is being built, not added after customers have already started using it.
“Before we go live on any technology or any product, we make sure privacy and security by design are embedded and tested by our cybersecurity professionals.”
Technology vendors are also expected to meet minimum baseline security standards. Managers remain responsible for keeping the controls working, and Mulila said employees who try to bypass them can face disciplinary action.
What My OneApp does when the SIM moves
My OneApp is designed around the customer’s SIM and an initial network authentication. After activation, the customer can use Wi-Fi. But removing the SIM triggers a fresh check when it is put back.
“When you remove your SIM card, if you put it back, you will have to start the authentication process once again.”
That extra step is intended to make unauthorised access harder after a SIM change or attempted takeover.
Opening My OneApp is not enough to move money
Safaricom says sensitive financial actions require another verification step. Services such as Ziidi Trader and transactions within financial mini apps ask the customer to re-authenticate before processing.
“Even if I am on the app, for me to complete a transaction, I still have to re-authenticate. It is like a double layer of security.”
The app also supports biometrics, including fingerprint or facial recognition depending on the device, and contains fraud-awareness banners and an option to report suspicious activity.
More than 100 privacy champions
Safaricom says it has trained more than 100 data protection champions across the company, acting as privacy contacts within their teams and raising issues that may not immediately reach the central privacy office.
Annual privacy and information-security training is mandatory, with a pass mark. Mulila said employees can be locked out of systems if they fail to complete it.
“We have over 100 data protection champions. They’re kind of like our eyes and ears on the ground, so they will surface any issues they see.”
AI monitoring, audits and board reporting
Safaricom says its cybersecurity monitoring runs around the clock and uses AI-powered tools to flag suspicious behaviour, with weekly reporting to the Chief Risk Officer, annual internal audits and quarterly reporting to the board’s Risk and ESG Committee.
“We have AI-powered tooling to detect suspicious behaviour, or anything that is going wrong, and to immediately stop and investigate behaviour that we do not approve of across the network.”
The company says it began preparing for stronger privacy regulation in 2016, before Kenya’s Data Protection Act was enacted. In 2019, it appointed a dedicated compliance officer and conducted a company-wide data protection impact assessment.
Safaricom says it later completed two independent privacy maturity assessments and achieved ISO 27701 Privacy Information Management System certification in 2024, which can be verified on the issuing certification body’s public register; and the PCI DSS version 4.0 (Payment Card Industry Data Security Standard) certification. It says areas handling high volumes of information, including M-PESA, billing and customer support, continue to undergo independent testing.
What happens when a customer complains, and what you should actually do
Customers can report suspected misuse through customer care, Safaricom Shops, fraud channels or the company’s Data Protection Office. Mulila said customers should provide specific evidence to help Safaricom investigate a complaint effectively.
“Can they show some evidence? Quite often, it’s really difficult to investigate without some specific instances of what a person has seen go wrong.”
Screenshots, messages, suspicious numbers, transaction details and dates can all help. Safaricom’s position is that customers should first raise the issue with the service provider, then approach the Office of the Data Protection Commissioner if it is not resolved to their satisfaction.
That two-step path; company first, regulator second, is the one concrete, actionable takeaway for any reader who ends up on the wrong side of a privacy complaint: keep your evidence, give the company a real chance to respond, and know that the regulator is where the conversation goes next if it doesn’t.
