Fintech
Data Protection and Open Banking in Emerging Markets
By Veronica Shiroya
Rapid technological advancement has fundamentally transformed the global financial ecosystem. The long-standing notion that “cash is king” is increasingly losing relevance as digital financial services become deeply embedded in everyday life. From paying for basic necessities to receiving salaries, sending remittances, or purchasing goods across borders, digital payments now underpin economic participation in both developed and emerging economies. This transformation has been accelerated by globalization, where individuals work remotely across jurisdictions, companies hire talent from different regions, and consumers routinely transact with international e-commerce platforms. In this interconnected world, digital financial infrastructure is no longer a convenience but a necessity.
At the center of this transformation lies the growing reliance on data. Access to financial services requires individuals to share personal and financial information from the moment they register an account to the completion of each transaction. As financial services evolve beyond traditional banking into a diverse ecosystem of financial technology providers, payment service providers, digital lenders, and data aggregators, the volume, velocity, and sensitivity of personal financial data being processed has increased significantly. This shift has brought about new opportunities for innovation and financial inclusion, while simultaneously introducing complex data protection and privacy risks, particularly in emerging markets where regulatory capacity and digital literacy remain uneven.
Open banking has emerged as a key framework for managing data sharing in this evolving financial landscape. Broadly, open banking refers to a system in which consumers can authorize third-party providers to securely access their financial data held by banks and other financial institutions through standardized application programming interfaces. By enabling data portability and interoperability, open banking seeks to foster competition, innovation, and consumer choice while placing individuals at the center of data governance. However, the success of open banking depends not only on technical infrastructure but also on robust data protection frameworks capable of safeguarding consumer rights in increasingly complex data ecosystems.
The promise of open banking for consumers and businesses
At its core, open banking is designed to give individuals greater control over their financial data. By securely sharing access to bank account information, consumers can access new, tailored financial services that respond more closely to their needs and circumstances. For example, many individuals maintain multiple accounts across different banks, mobile money platforms, or brokerage services. Open banking enables these consumers to aggregate their financial information into a single, real-time dashboard, allowing them to view and manage their finances holistically. This consolidation enhances transparency, improves financial planning, and reduces the cognitive burden associated with managing fragmented accounts.
Beyond aggregation, open banking can make financial services more intelligent and responsive. Some financial service providers leverage artificial intelligence and data analytics to offer actionable insights based on consumer data. These tools can help users track spending patterns, create personalized budgets, identify savings opportunities, and anticipate future financial needs. Such innovations illustrate how data sharing, when governed responsibly, can enhance consumer empowerment rather than undermine it.
Open banking also introduces more efficient and secure payment mechanisms. Instead of navigating multiple applications or payment interfaces, consumers can initiate bank transfers directly through the service they are using, reducing friction and transaction costs. This functionality is particularly relevant for e-commerce and digital services, where seamless payment experiences are essential to user adoption and trust.
Small and medium-sized enterprises (SMEs) also stand to benefit significantly from open banking. SMEs constitute approximately 90 percent of businesses worldwide and account for more than half of global employment. In developing economies, they play a critical role in economic diversification, job creation, and poverty reduction. Open banking-enabled tools can integrate with business accounting and back-office systems, allowing SMEs to manage payments, collections, and cash flow in real time. Enhanced financial visibility can improve creditworthiness, facilitate access to financing, and support sustainable business growth.
Open banking as a driver of financial inclusion
One of the most compelling arguments for open banking in emerging markets is its potential to advance financial inclusion. Traditional financial systems often exclude individuals and businesses that lack formal credit histories, stable income streams, or proximity to banking infrastructure. Open banking challenges these limitations by enabling alternative data sources to inform financial decision-making.
Individuals with thin or non-existent credit files, such as retirees without debt histories, informal sector workers, or recent immigrants, frequently face barriers to accessing loans and other financial products. Conventional lenders rely heavily on credit reports that may not capture the full financial reality of such individuals. Open banking allows consumers to demonstrate creditworthiness through other forms of data, including payroll information, rental payment histories, transaction patterns, and overall cash flow. By broadening the evidentiary basis for lending decisions, open banking can reduce exclusion and improve access to credit.
In emerging and developing economies, particularly in Sub-Saharan Africa, the case for open banking is especially strong. The region’s financial landscape is characterized by limited traditional banking infrastructure alongside widespread adoption of mobile money services. With more than one-third of adults owning a mobile money account, Sub-Saharan Africa is uniquely positioned to leverage open finance frameworks to expand financial services into areas such as insurance, savings, and investment products. Innovations such as M-Pesa and Airtel Money illustrate how mobile-based financial services can reach remote and underserved populations, enabling individuals with basic feature phones to participate in the digital economy.
By facilitating interoperability between mobile money platforms, banks, and fintech providers, open banking can support the leapfrogging of legacy financial systems and promote inclusive growth. However, this same data-driven ecosystem also raises critical concerns about consumer protection, privacy, and accountability, particularly in contexts where regulatory oversight is still evolving.
Data protection risks in open banking ecosystems
While open banking offers substantial benefits, it also amplifies the risks associated with large-scale data sharing. In theory, open banking is built on strong consumer consent and control mechanisms. Individuals decide whether to share their data, which data elements to share, with whom, and for how long. Consent can be withdrawn at any time, and data processing is expected to comply with applicable data protection laws. These frameworks typically grant data subjects rights to be informed, to access their data, to rectify inaccuracies, to request deletion, and to object to certain forms of processing.
In practice, however, the effectiveness of these safeguards varies significantly across jurisdictions and population groups. Data protection regimes in emerging markets often mirror global standards in form but face challenges in implementation. A central concern relates to the concept of informed consent. Meaningful consent requires that individuals understand what data is being collected, how it will be used, how long it will be retained, and with whom it will be shared. In low-literacy and low-digital-literacy contexts, these requirements are difficult to fulfil.
Many users access financial services through basic feature phones, limited user interfaces, and multiple local languages. Explaining complex data flows, algorithmic processing, and downstream uses of data in such environments is inherently challenging. As a result, consent risks becoming a formalistic exercise rather than a substantive protection. Users may experience consent fatigue or misunderstand permissions entirely, undermining the foundational principles of data protection.
Another significant challenge concerns liability in fragmented data ecosystems. Open banking typically involves multiple actors, including banks, data aggregators, fintech applications, and lenders. Personal data may pass through several intermediaries before being used to deliver a service. In the event of a data breach or misuse, determining responsibility can be complex. Emerging markets often lack clear legal precedents, regulatory guidance, or insurance mechanisms to address distributed liability. This ambiguity can leave consumers without effective remedies and weaken accountability across the ecosystem.
Regulatory approaches in emerging markets
Different emerging markets have adopted varying regulatory strategies to address data protection risks in open banking systems. In South Africa, for example, data access requests can be initiated by customers or by third-party providers with customer consent. Regulatory authorities require that consent be well-informed, freely given, specific, and unambiguous. Consent must not be bundled with unrelated agreements or made a condition for accessing unrelated services. Access must be time-limited and easily revocable, and third-party providers must ensure that customers understand the implications of data sharing.
These requirements align with the principles enshrined in the Protection of Personal Information Act of 2013, which establishes standards for lawful processing, purpose limitation, data minimization, and security safeguards. South Africa’s regulatory framework also addresses technical risks associated wit practices such as screen scraping. The Financial Sector Conduct Authority has recommended the development of technical standards for APIs guided by principles of openness, interoperability, transparency, and stability. Industry bodies are exploring policy options that range from adopting European-style payment services frameworks to enforcing technical standards such as the Payment Card Industry Data Security Standard.
Further safeguards proposed in South Africa include restrictions on data identifiability, strict purpose limitation, and strong customer authentication measures. Third-party providers are discouraged from retaining customer data beyond what is strictly necessary, and liability mechanisms are emphasized to ensure compliance. The creation of a regulated class of third-party providers, particularly those engaging in screen scraping, has also been proposed to enhance oversight and accountability.
In Nigeria, the Nigerian Data Protection Regulation provides specific rules for open banking ensuring responsible data flows. Providers are prohibited from using or storing customer data for purposes beyond those explicitly requested by the user. Data retention requirements mandate that certain financial data be retained for minimum periods, while technical and organizational safeguards are required to protect stored data. Providers must maintain detailed records of data-sharing requests and associated actions to ensure traceability and accountability.
India has adopted a more procedural approach in some contexts, with data controllers issuing GDPR-compliant checklists to ensure that data subjects are informed and protected. While this approach reflects an effort to harmonize with international norms, it also highlights the administrative burden placed on users and the risk that compliance processes may become inaccessible to less literate populations.
Kenya represents another evolving regulatory landscape. The Central Bank of Kenya has expressed its intention to develop a financial data protection and governance framework that complements the Data Protection Act of 2019. This initiative involves research into how financial data is collected, stored, and shared, with the aim of addressing emerging risks proactively. Additionally, the Office of the Data Protection Commissioner has issued guidelines for digital credit providers, outlining compliance requirements for processing personal data in line with the administration of digital credit services.
Toward rights-respecting open banking in emerging markets
The experiences of emerging markets demonstrate that open banking cannot be separated from broader questions of data governance, consumer protection, and digital equity. While the technical architecture of open banking emphasizes consent, interoperability, and security, these principles must be adapted to local realities. Legal frameworks alone are insufficient if users lack the capacity to understand and exercise their rights, or if regulators lack the resources to enforce compliance effectively.
A rights-respecting approach to open banking in emerging markets requires investment in digital literacy, user-centered consent mechanisms, and culturally appropriate communication strategies. It also demands clearer allocation of liability across complex data ecosystems and stronger institutional capacity to investigate and remedy data protection violations. Importantly, financial inclusion should not come at the expense of privacy and autonomy. Instead, open banking should be designed as a tool for empowerment, enabling individuals and businesses to participate in the digital economy on fair and secure terms.
As emerging markets continue to innovate and expand digital financial services, the challenge lies in balancing openness with protection. Open banking holds transformative potential, but its long-term legitimacy depends on trust. Building that trust requires regulatory foresight, technical robustness, and a firm commitment to upholding data protection as a fundamental right rather than a procedural formality.