Digital Privacy in the Corporate Boardroom: The Bharat Thakrar v. WPP Scangroup PLC Precedent
A Critical Analysis of Data Minimization and Employee Privacy Rights in Internal Investigations
This analysis details the determination of the Office of the Data Protection Commissioner (ODPC) regarding Complaint Nos. 1159, 1160, and 1161 of 2024.
1. Litigants
Complainant: Bharat Thakrar, the founder and former CEO of WPP Scangroup PLC.
Respondents:
WPP Scangroup PLC (the Company).
WPP PLC (the majority shareholder).
Control Risks Group (CRG) (a third-party investigator engaged by the other respondents).
2. Issue for Determination
The central issue was whether the respondents infringed upon the complainant’s constitutional right to privacy (Article 31) and his rights under the Data Protection Act, 2019, through the unlawful and unjustified processing of his personal information during investigations into allegations of gross misconduct. The ODPC had to determine if the respondents had a lawful basis for accessing the complainant’s private data, including WhatsApp messages and iCloud data, and if they complied with data minimization principles.
3. The Panel
The determination was issued by the Office of the Data Protection Commissioner (ODPC) following an investigation conducted by the Office into the allegations filed by the complainant.
4. Arguments in Court (Proceedings)
Complainant’s Arguments: Mr. Thakrar asserted that the respondents unlawfully accessed and processed his personal data without his consent or a legitimate basis. He argued that this processing—which extended to private communications—caused him significant personal and professional harm.
Respondents’ Arguments: The respondents contended that the data processing was justified as part of a formal investigation into serious misconduct. They claimed exemptions based on legal privilege, confidentiality, and public interest to justify the investigation and the access of information on company-issued devices.
5. Judgment
The ODPC ruled in favor of the complainant, determining that the respondents breached data protection principles. Key findings included:
Right of Access: The respondents failed to provide the complainant access to his employment-related personal data, incorrectly claiming blanket exemptions for legal privilege.
Lawful Basis & Data Minimization: The respondents failed to demonstrate a lawful basis for the specific processing activities and violated the principle of data minimization by failing to separate the complainant’s private communications (e.g., WhatsApp) from work-related data.
Compensation: The respondents were ordered to pay a total of KES 1,950,000 in compensation for the breach of rights and distress. This was apportioned as follows:
WPP Scangroup PLC: KES 700,000
WPP PLC: KES 700,000
Control Risks Group: KES 550,000
Directives: The respondents were ordered to grant the complainant access to his personal data within 7 days and were issued an Enforcement Notice.
6. Takeaway
The case establishes a critical precedent that corporate investigations do not grant companies a “blanket” right to access an employee’s private personal data. Organizations must strictly adhere to the principle of data minimization, ensuring that investigative processes distinguish between business data and private employee communications. Relying on general claims of legal privilege or public interest is insufficient to override a data subject’s rights under the Data Protection Act.
Status of the Matter
The respondents expressed disagreement with the ODPC’s determination and indicated an intent to pursue an appeal.

