Safaricom is facing renewed scrutiny over the handling of customer data after a subscriber was forced to go to the High Court to find out who had sought access to her communications, telecommunications data, financial transactions and M-Pesa activity.
Naomi Jepkemboi Matey did not go to court with a conspiracy theory. She wanted her own records.
Her request covered two phone numbers and a period running from March 2024 to January 2025. She wanted to know who had asked Safaricom for information relating to her and, crucially, the legal basis for any such requests.
Justice David Mburu has now ordered Safaricom to provide the information within 21 days.
The September 18, 2026 ruling in Matey v Safaricom PLC requires the telecommunications giant to provide certified subscriber details, particulars of requests for access or disclosure, and any access logs, audit trails and disclosure records still held by the company.
The judge, however, made clear that Safaricom cannot be ordered to produce records that never existed or those that were lawfully deleted under an applicable retention policy.
The ruling nevertheless raises an uncomfortable question for one of Kenya’s most powerful companies: why did a customer have to sue before being allowed to establish who had accessed information about her?
The battle over a simple question
Matey wrote to Safaricom on June 2, 2026.
Two days later, the company responded through fraud department official Mercelynne Awuor Okelo, advising her to lodge a formal request at Safaricom’s headquarters.
The company subsequently argued in court that the correspondence did not amount to an investigative complaint and that Matey had not supplied enough dates and supporting material to sufficiently narrow her request.
Safaricom also argued that it does not ordinarily maintain records described in broad terms as “surveillance”, “monitoring” or “querying”.
According to the company’s position, such records are “neither generated nor maintained in the ordinary course of its business.”
The dispute ultimately landed before the High Court.
Justice Mburu rejected Safaricom’s attempt to send the matter back into an internal process after the company had already indicated that disclosure would require a court order.
The decision relied on Article 35 of the Constitution and the Data Protection Act, which provide data subjects with rights concerning information held about them and how their personal data is used.
Matey’s request was therefore not for somebody else’s private information.
She was asking what had happened to her own data.
Yet she had to sue to get the answer.
A question that goes beyond one subscriber
The period covered by Matey’s request is particularly significant.
Her records relate to March 2024 through January 2025, a period that included the Finance Bill protests, the June 2024 demonstrations, the nationwide internet disruption on June 25, and a growing national debate over alleged surveillance, disappearances and access to telecommunications data.
On June 25, 2024, internet connectivity across Kenya experienced a major disruption as protesters converged on Parliament.
NetBlocks recorded the disruption, while other internet monitoring organisations also documented a significant decline in connectivity.
The government had stated the previous day that it had no intention of shutting down the internet.
Safaricom and Airtel attributed the disruption to problems affecting undersea cables, while civil society organisations questioned the timing and circumstances of the outage.
Safaricom has since categorically denied involvement in any alleged internet shutdown.
The issue, however, became part of a much larger debate about the extent to which telecommunications data can be accessed by state agencies.

Human Rights Watch documented allegations of abductions, unlawful detention and killings during the protest period. The Kenya National Commission on Human Rights also documented cases of enforced disappearances following the demonstrations.
Some activists subsequently abandoned Safaricom lines because of fears that call records and location information could be used to identify them.
Those claims have been disputed by Safaricom.
In a response cited by Amnesty International, the company maintained that customer information is shared only through lawful means and for lawful purposes and said its systems are not designed to track the live location of subscribers.
But the questions have not disappeared.
The Mokaya case and the surveillance debate
One of the cases that has intensified the debate involves David Ooga Mokaya.
Mokaya was traced to Eldoret, arrested and taken to Nairobi before being prosecuted over a social media post. He was subsequently acquitted.
Records cited in litigation and media reports indicate that Safaricom produced information relating to his digital activity following a request from the Directorate of Criminal Investigations.
The information reportedly included his telephone number, call detail records and location information.
A police officer stationed at Safaricom was also described as confirming that triangulation and tracing had been conducted without a court order.
The allegations have become part of a wider petition filed by the Law Society of Kenya against Safaricom, the DCI and other state agencies.
The petition alleges an institutional system through which subscriber information, call records and geolocation data were accessed without the safeguards required by law.
Those allegations remain contested.
Safaricom has repeatedly maintained that it does not share customer information without lawful authority.
The Safaricom liaison office
The controversy also echoes an October 2024 investigation by the Daily Nation’s Namir Shabibi and Claire Lauterbach.
The investigation examined Safaricom’s Law Enforcement Liaison Office, the presence of police officers within the company’s structures and technology used to manage telecommunications data.
It also examined Neural Technologies, a British company that Safaricom brought on board in 2012.
Safaricom rejected suggestions that its systems provided security agencies with unfettered access to customer information.
In an October 31, 2024 position statement, the company maintained that customer information was not shared without a court order and argued that call detail records were billing records rather than live-tracking tools.
It also said Neural Technologies had been engaged for fraud management and denied third-party access to customer information.
The company pointed to its information security and privacy controls, including ISO 27701 certification.
But civil society organisations continued to raise questions about how law enforcement access operates in practice.
The Kenya Human Rights Commission and Muslims for Human Rights were among organisations that questioned aspects of the system and called for greater transparency.
When the alleged leak came from inside
The surveillance debate is only one part of Safaricom’s growing data privacy controversy.
A separate case concerns allegations that rogue employees extracted and trafficked customer information covering millions of subscribers.
Petitioners led by Austin Taabu alleged that information relating to approximately 11.5 million subscribers had been compromised.
The information was said to include names, identification documents, location information, financial records and betting-related information.
Safaricom disputed the allegations and challenged the evidence linking the individual petitioners to the alleged database.
In May 2026, however, Justice Bahati Mwamuye found Safaricom liable in the case brought by 11 petitioners over the failure to protect their personal data.
The court awarded each petitioner Sh900,000, together with interest and costs.
The ruling placed the focus not only on the conduct of alleged rogue employees but also on the responsibility of the data controller to protect information entrusted to it.
That finding has added another layer to the questions now surrounding Safaricom’s handling of personal information.
Who gets access and who gets an answer?
This is where Matey’s case becomes particularly uncomfortable for Safaricom.
A customer seeking information about access to her own data was required to pursue the matter through the courts.
At the same time, allegations contained in separate court proceedings and investigations have raised questions about how easily law enforcement agencies can obtain telecommunications information.
The two situations are not legally identical.
Law enforcement access, where properly authorised, is governed by different procedures from a customer’s request for access to personal information.
But the contrast raises an important transparency question.
How many requests for customer information does Safaricom receive from government agencies?
How many are granted?
How many are rejected?
How many are supported by warrants or court orders?
And how many customers are ever told that their information has been accessed?
These are questions that could be answered more easily through detailed transparency reporting.
The state and Safaricom’s ownership
The controversy is also unfolding against a changing ownership structure.
For years, the Government of Kenya held a 35 per cent stake in Safaricom.
In June 2026, Vodacom completed a transaction that changed the respective ownership interests, leaving the Kenyan government with approximately 20 per cent.
The transaction itself became the subject of litigation, with petitioners raising questions about the treatment of Safaricom as strategic digital infrastructure.
A three-judge bench subsequently nullified the divestiture on procedural grounds, while the Attorney-General moved to challenge the decision.
The ownership dispute is separate from Matey’s privacy case.
But the broader question remains relevant: Safaricom is simultaneously a listed commercial company, a major payments platform, a telecommunications infrastructure provider and a company in which the Kenyan state remains a substantial shareholder.
That makes transparency over access to subscriber data an issue extending beyond an ordinary commercial dispute.
What Safaricom must now produce
Justice Mburu’s order does not establish that Matey was secretly monitored.
It does not establish that Safaricom unlawfully disclosed her information.
What it does is require the company to disclose what records it has concerning requests for her information.
That distinction matters.
Within 21 days, Safaricom is expected to provide the records covered by the court’s order.
If the records exist, they could reveal who requested information, what was requested and the basis cited for the request.
If records no longer exist, the company can explain that they were not created or were lawfully deleted under its retention policies.
Either way, the case has exposed a fundamental weakness in the relationship between Kenyan consumers and the companies holding their most sensitive digital information.
For millions of Kenyans, a mobile phone number is connected to far more than calls and text messages.
It can provide access to M-Pesa, banking services, business transactions, personal communications and location-linked information.
That makes the question raised by Matey’s case difficult to ignore.
Who accessed the data? When was it accessed? Who requested it? On what legal authority? And why did a customer have to go to the High Court to find out?
There's no story that cannot be told. We cover the stories that others don't want to be told, we bring you all the news you need. If you have tips, exposes or any story you need to be told bluntly and all queries write to us [email protected] also find us on Telegram
