The National Treasury and the Central Bank of Kenya (CBK) opened public consultation on September 21 on the draft National Payment System Bill, 2026, which would repeal the National Payment System Act (Cap. 491A) and, among other things, require banks and mobile money providers to build systems capable of "securely sharing customer data with third parties for open finance purposes" once a customer consents. Submissions close October 9, with public forums running in Nairobi, Mombasa, Kisumu, Nakuru, Nyeri, Meru and Kitale in between.
The case for prying data loose
The strongest argument for the bill is structural, not ideological. Safaricom controls roughly 70% of Kenya's mobile subscriptions and 88% of mobile money transfers, and by mid-2026 had also become the country's largest home-broadband provider with over a million subscribers. That concentration means an enormous share of Kenyans' financial behavior — savings patterns, transaction history, creditworthiness signals — sits inside one company's systems, and inside the ledgers of a handful of banks. A lending fintech, a budgeting app, or a challenger payments provider cannot build a competitive product without that data, and today it has no legal right to it even with the customer's blessing. Open banking regimes in the UK, the EU (PSD2) and India's Account Aggregator framework were all built on the same premise: data portability, done properly, breaks incumbency and lets customers — not the institution holding their money — decide who gets to see their financial history. The bill's own text frames this as the goal, giving the CBK power to require sharing "once customers have given consent," and creating two new licence categories — payment initiation service providers and account information service providers — that don't need to hold customer funds at all, precisely so smaller players can compete on service rather than balance-sheet size.
What the bill leaves unbuilt
The trouble is the load-bearing word in that sentence — "consent" — does almost no work in the draft. The bill states providers must be capable of sharing data once consent exists, and that CBK "may require" providers to enable it and "shall make regulations" later specifying what data moves, on what terms and at what cost. That is a mandate to build plumbing with the standards to be decided after the pipes are laid. Nothing in the September 21 draft, per CBK's own posting and TechCabal's reporting, addresses how consent will be captured, scoped, timestamped, revoked or audited at the API level — the operational detail that determines whether "consent" is a real control or a checkbox a bank's terms-of-service already buries.
That gap doesn't fall into a vacuum. Kenya already has a consent regime: the Data Protection Act, 2019, defines consent as a "freely given, specific, informed, and unambiguous indication" of the data subject's wishes, puts the burden of proving valid consent on the controller, and lets the Office of the Data Protection Commissioner (ODPC) fine violators up to KES 5 million or 1% of annual turnover, whichever is lower. The ODPC has used that power before in a fact pattern close to this one: in 2023 it fined a digital credit provider KES 2.975 million for using contact information obtained from third parties, without the data subjects' consent, to send debt-collection messages. It has also published a Data Sharing Code setting out what controllers must do before passing personal data to another party. The precedent shows the ODPC is willing to police exactly this kind of third-party data misuse — but it does so one complaint at a time, against individual violators, well after harm has occurred. The payments bill would generate a nationwide, always-on data-sharing pipeline between the country's dominant financial institutions and an unspecified population of third-party providers. Retrofitting that scale of flow onto a regulator built for case-by-case adjudication is a mismatch the bill doesn't acknowledge, let alone resolve.
Capital floors that cut against the stated goal
A second tension sits in the bill's own market-structure design. Alongside the data-sharing mandate, CBK is proposing minimum core capital requirements from KES 5 million for basic data services up to KES 250 million (~$1.93 million) for electronic money issuers — and explicitly excluding shareholder loans and convertible debt from qualifying as core capital. Existing banks get simplified authorisation and can draw on reserves already booked; early-stage fintechs, the very entrants open finance is supposed to empower, face the highest capital bar just as the door notionally opens. A bill that unlocks data access while raising the price of market entry risks handing the resulting advantage to well-capitalised incumbents rather than the challengers it was written for.
The proportionate fix is sequencing, not retreat
None of this argues against open finance — unlocking M-PESA's and the banks' data silos is genuinely good for competition and for Kenyan consumers who currently can't take their financial history anywhere. But proportionate regulation means the consent-verification architecture — dynamic, revocable, auditable consent receipts at the API layer, ideally specified jointly by CBK and ODPC — should ship before sharing is mandated, not as a regulation to be written after banks have already built the pipes. Kenya has eighteen days left to say so before the comment window closes on October 9.