Kenya payments data sharing has become the buzzword in African fintech circles after the government unveiled a draft Payments Bill that could compel banks and licensed fintechs to exchange customer information. The proposal, first reported in September 2026, aims to level the playing field between traditional banks and mobile money providers, but it also raises serious questions about data privacy, consumer consent, and the future of financial services across the continent. What the Bill Proposes The draft legislation seeks to loosen the grip that banks and mobile money operators have on their customers by mandating that any licensed fintech with a recognised payment licence can access basic customer data – such as name, phone number, and transaction history – from banks and mobile money platforms. In return, fintechs would be required to adhere to strict data‑security standards and obtain explicit consent from users before using the data for new services. According to the TechCabal report, the move is intended to foster competition, spur innovation, and accelerate financial inclusion. By allowing fintechs to build on existing customer relationships, the government hopes to reduce the friction that often stalls the rollout of new payment solutions, especially in underserved regions. Why Kenya Payments Data Sharing Is Pushed Kenya has long been a leader in mobile money, with M‑Pesa setting the benchmark for digital cash transfers across Africa. Yet, the market is now facing saturation, and regulators are looking for ways to keep the ecosystem vibrant. The Payments Bill is part of a broader strategy to modernise the financial sector, align it with the African Continental Free Trade Area (AfCFTA) digital agenda, and attract foreign fintech investment. For Nigerian and South African fintechs, the bill signals a potential opening to tap into Kenya’s massive user base without having to build costly onboarding pipelines from scratch. However, the same openness could also expose customers to new risks if data‑handling practices are not uniformly enforced. Potential Benefits for Consumers and Fintechs Proponents argue that the bill could deliver several tangible benefits: Faster onboarding: Fintechs could verify customers instantly using bank‑held data, cutting down on KYC delays. Richer product offerings: Access to transaction histories enables personalised credit scoring, micro‑loans, and tailored insurance products. Greater financial inclusion: Rural users who already have bank accounts but lack mobile money access could be served by new digital wallets. In Nigeria, similar data‑sharing frameworks have been discussed within the Central Bank’s Open Banking roadmap, and Kenya’s bill could serve as a regional prototype. South African banks have already piloted data‑exchange APIs under the Financial Sector Conduct Authority’s (FSCA) sandbox, showing that the concept is not entirely new. Moreover, the Kenya payments data sharing model promises to streamline cross‑border fintech collaborations. Privacy Concerns and Regulatory Safeguards While the bill promises innovation, privacy advocates warn that mandatory data sharing could erode consumer trust. The legislation stipulates that fintechs must obtain “explicit consent” before accessing data, but the definition of consent remains vague. Critics fear that consent screens could become perfunctory, leading users to click “agree” without fully understanding the implications. To mitigate these risks, the bill includes provisions for: Independent data‑protection oversight by the Data Protection Commissioner. Mandatory encryption and regular security audits for all participating entities. Heavy penalties – up to 5% of annual turnover – for breaches or misuse of data. These safeguards echo the Nigerian Data Protection Regulation (NDPR) and the South African Protection of Personal Information Act (POPIA), but enforcement capacity varies across the continent. Implications for Regional Fintech Hubs Kenya’s move could set a precedent for other African economies. Ghana, for instance, is currently drafting its own Open Banking framework, and Ethiopia is exploring a digital payments strategy under its Vision 2030 plan. If Kenya successfully balances innovation with privacy, it may become a model for harmonised data‑sharing standards across the African Union. The Kenya payments data sharing initiative could therefore influence policy debates far beyond its borders. Conversely, a misstep could trigger backlash, prompting regulators in Nigeria, Tanzania, and Rwanda to adopt more cautious approaches. The cross‑border nature of fintech means that any data‑sharing rule in one market can ripple through supply chains, affecting everything from payment gateways to cross‑border remittance services. How Banks Are Responding Major Kenyan banks, such as KCB and Equity Bank, have expressed mixed reactions. While they acknowledge the potential for new revenue streams through API licensing, they also warn that forced data sharing could undermine their competitive advantage and increase operational costs. In Nigeria, the Central Bank of Nigeria (CBN) has been monitoring the development closely. A CBN spokesperson noted that “any data‑sharing regime must align with the NDPR and protect the rights of Nigerian consumers, even when they use services abroad.” This stance reflects a broader regional trend of aligning fintech regulation with existing data‑privacy laws. What Nigerian Readers Should Watch For Nigerian entrepreneurs and investors, the key takeaways are: Stay informed about Kenya’s implementation timeline – the bill is expected to be tabled for parliamentary debate in early 2027. Assess whether your fintech solution can integrate with Kenya’s upcoming APIs without compromising data‑security standards. Consider the impact on cross‑border services – many Nigerian remittance firms already operate in Kenya, and data‑sharing could streamline settlement processes. Moreover, keep an eye on the CBN’s own Open Banking roadmap, which may incorporate lessons from Kenya’s experience. FAQ Will Kenyan banks be forced to share all customer data? No. The bill limits data sharing to basic identification and transaction information, and only after the customer gives explicit consent. How does the bill affect mobile money providers like M‑Pesa? Mobile money operators will also be required to share data with licensed fintechs under the same consent framework, potentially opening up their ecosystems to new services. What penalties exist for data breaches under the new law? Entities that violate data‑protection rules could face fines up to 5% of their annual turnover, plus possible revocation of their payment licence. As Africa’s fintech landscape continues to evolve, Kenya’s payments data sharing bill could become a watershed moment. Whether it drives inclusive growth or sparks privacy debates will depend on how regulators, banks, and fintechs balance innovation with consumer protection. For Nigerian and broader African stakeholders, the story is still unfolding – and the outcomes will shape the continent’s digital finance future for years to come. Related Reading From Lockdown Queues to AI Receipt Scanning: How Nigerian Founders Built Expense AI Nigeria Formalises Fiscal‑monetary Coordination with New CBN MoU South Africa Revamps Its Payments System to Power Africa’s Fintech Future Related posts: Kenya’s New Capital Rule Could Reshape Africa’s Fintech Landscape From Somalia to Nairobi: How One Ex-soldier Built Africa’s Fastest $1bn African Fintech Lender Russia’s Nuclear Threat to Lithuania Raises Alarm Across Africa User Safety in Nigeria and Africa: A 2026 Guide Post navigation The Complicated Joy of a Child Leaving Home: Embracing the Empty Nest KCB’s 22.23% Stake in Pesapal Signals New Wave of African Payments Integration