Kenya Kenya data protection authority ODPC

Kenya's Open Finance Bill Mandates Data Sharing but Leaves Consent Enforcement to an Under-Resourced Regulator

The draft Payment System Bill would force M-PESA and banks to open customer data to fintechs on consent — but Kenya's data authority still polices consent case by case.

Kenya's Open Finance Bill: The Consent Gap People of Internet Research · Kenya 18 days Public consultation window Treasury and CBK opened comments o… KES 5M or 1% Max data protection fine ODPC can fine consent violations u… $1.93M E-money issuer capital floor Proposed minimum core capital for … KES 2.975M Prior fintech-adjacent ODPC fine 2023 penalty against a digital cre… peopleofinternet.com
Kenya's Open Finance Bill: The Consent… People of Internet Research · Kenya 18 days Public consultation win… KES 5M or 1% Max data protection fine $1.93M E-money issuer capital floor KES 2.975M Prior fintech-adjacent… peopleofinternet.com

Key Takeaways

The National Treasury and the Central Bank of Kenya (CBK) opened public consultation on September 21 on the draft National Payment System Bill, 2026, which would repeal the National Payment System Act (Cap. 491A) and, among other things, require banks and mobile money providers to build systems capable of "securely sharing customer data with third parties for open finance purposes" once a customer consents. Submissions close October 9, with public forums running in Nairobi, Mombasa, Kisumu, Nakuru, Nyeri, Meru and Kitale in between.

The case for prying data loose

The strongest argument for the bill is structural, not ideological. Safaricom controls roughly 70% of Kenya's mobile subscriptions and 88% of mobile money transfers, and by mid-2026 had also become the country's largest home-broadband provider with over a million subscribers. That concentration means an enormous share of Kenyans' financial behavior — savings patterns, transaction history, creditworthiness signals — sits inside one company's systems, and inside the ledgers of a handful of banks. A lending fintech, a budgeting app, or a challenger payments provider cannot build a competitive product without that data, and today it has no legal right to it even with the customer's blessing. Open banking regimes in the UK, the EU (PSD2) and India's Account Aggregator framework were all built on the same premise: data portability, done properly, breaks incumbency and lets customers — not the institution holding their money — decide who gets to see their financial history. The bill's own text frames this as the goal, giving the CBK power to require sharing "once customers have given consent," and creating two new licence categories — payment initiation service providers and account information service providers — that don't need to hold customer funds at all, precisely so smaller players can compete on service rather than balance-sheet size.

What the bill leaves unbuilt

The trouble is the load-bearing word in that sentence — "consent" — does almost no work in the draft. The bill states providers must be capable of sharing data once consent exists, and that CBK "may require" providers to enable it and "shall make regulations" later specifying what data moves, on what terms and at what cost. That is a mandate to build plumbing with the standards to be decided after the pipes are laid. Nothing in the September 21 draft, per CBK's own posting and TechCabal's reporting, addresses how consent will be captured, scoped, timestamped, revoked or audited at the API level — the operational detail that determines whether "consent" is a real control or a checkbox a bank's terms-of-service already buries.

That gap doesn't fall into a vacuum. Kenya already has a consent regime: the Data Protection Act, 2019, defines consent as a "freely given, specific, informed, and unambiguous indication" of the data subject's wishes, puts the burden of proving valid consent on the controller, and lets the Office of the Data Protection Commissioner (ODPC) fine violators up to KES 5 million or 1% of annual turnover, whichever is lower. The ODPC has used that power before in a fact pattern close to this one: in 2023 it fined a digital credit provider KES 2.975 million for using contact information obtained from third parties, without the data subjects' consent, to send debt-collection messages. It has also published a Data Sharing Code setting out what controllers must do before passing personal data to another party. The precedent shows the ODPC is willing to police exactly this kind of third-party data misuse — but it does so one complaint at a time, against individual violators, well after harm has occurred. The payments bill would generate a nationwide, always-on data-sharing pipeline between the country's dominant financial institutions and an unspecified population of third-party providers. Retrofitting that scale of flow onto a regulator built for case-by-case adjudication is a mismatch the bill doesn't acknowledge, let alone resolve.

Capital floors that cut against the stated goal

A second tension sits in the bill's own market-structure design. Alongside the data-sharing mandate, CBK is proposing minimum core capital requirements from KES 5 million for basic data services up to KES 250 million (~$1.93 million) for electronic money issuers — and explicitly excluding shareholder loans and convertible debt from qualifying as core capital. Existing banks get simplified authorisation and can draw on reserves already booked; early-stage fintechs, the very entrants open finance is supposed to empower, face the highest capital bar just as the door notionally opens. A bill that unlocks data access while raising the price of market entry risks handing the resulting advantage to well-capitalised incumbents rather than the challengers it was written for.

The proportionate fix is sequencing, not retreat

None of this argues against open finance — unlocking M-PESA's and the banks' data silos is genuinely good for competition and for Kenyan consumers who currently can't take their financial history anywhere. But proportionate regulation means the consent-verification architecture — dynamic, revocable, auditable consent receipts at the API layer, ideally specified jointly by CBK and ODPC — should ship before sharing is mandated, not as a regulation to be written after banks have already built the pipes. Kenya has eighteen days left to say so before the comment window closes on October 9.

Sources & Citations

  1. CBK: Draft National Payment System Policy and Bill, 2026
  2. ODPC Data Sharing Code
  3. TechCabal: Kenya's new payments bill could force banks to share customer data
  4. TechCabal: Kenya proposes up to $1.93m capital requirement for payment firms
  5. Clyde & Co: ODPC issues penalty notices to three data controllers
  6. Securiti: Kenya Data Protection Act Compliance Guide