Prior to 2020, digital lending witnessed an unprecedented rise and growth in Kenya. According to a 2019 FSD report, the boom was fuelled by widespread use of mobile phones, high demand for credit and a lax regulatory environment. Digital lenders fall into two main categories: mobile banking loans(i.e. loans by licensed banks such as M-Shwari) and digital loans (i.e. loans granted by unregulated firms like Tala and Branch). The regulatory environment made it very easy for unregulated providers to enter the market. By 2020, Kenya had over 120 digital lending platforms.
Parliament is now considering ways of regulating digital lending in Kenya through the Central Bank of Kenya (Amendment) Bill 2021. When passed, the law will provide a much needed lifeline for unregulated digital lenders in Kenya. However, more regulatory challenges lie ahead. A good case in point being the new Data Protection Act which is set to heavily impact digital lending.
What is digital lending?
Data privacy in digital lending
The transfer of personal data and financial information through digital channels raises data privacy concerns. For example, in 2019/2020, the use of non-financial data by digital lenders caused great indignation and public outcry among Kenyans. Debtors accused digital lenders of using mined phone data to engage in debt shaming practices such as informing their family, friends and employers of the existing debt. The CBK also decried this intrusive practice revealing that it had led to mental anguish and suicide among affected persons.
1. Transparency and fairness in data collection and processing
- the types of data collected
- methods of collection
- the purposes for collection
- the lawful basis for collection
- how the data will be processed
- how the data will be shared and stored
- the period of data retention
2. Transparency and fairness in credit scoring
In digital lending, credit scoring involves making decisions by automated means. The Act (and its supporting draft regulations) has introduced a host of new requirements relating to automated decision making. In summary, the lenders must:-
- inform customers that credit scoring involves automated processing
- provide meaningful information about the logic involved in processing
- explain the significance and possible consequences of the processing to customers or regulators
- ensure the prevention of errors, bias and discrimination
- process personal data in a way that prevents discriminatory effects
- ensure that a customer can obtain human intervention and express their point of view
3. Effective management of data processors
4. International data transfers
- proves to the Data Commissioner that the lender has put in place adequate safeguards with regards to security and protection of the personal data.
- proves to the Data Commissioner that the data will be transferred to jurisdictions with commensurate data protection laws and that the recipient of the data is bound by those laws.
- informs the data subject of the safeguards and implications of the cross-border transfer and obtains the data subject’s consent to transfer the data outside the country.
- safeguards the data from misuse or unintended disclosures by the recipient.
- enters into a cross-border agreement with the recipient of personal data.
5. Facilitating data subject rights
One of the key features of the the Data Protection Act is that it gives data owners the right of control over the use of their data. To this end, the Act grants data owners certain rights over their personal data. These include rights of access, rectification, erasure, objection and restriction to processing of personal data. Consequently, digital lenders must ensure that data subjects can exercise the rights when necessary. For example, a customer may request the lender to delete or erase all personal data after repayment of a loan. The digital lender must respond to the request either by complying or by declining the request and giving reasons for the refusal. The supporting regulations for the Act have defined time-limits for responding to the requests which in most cases is within 14 days.
6. Privacy by design and by default
- proactively manages privacy-invasive events before they occur.
- only collects and uses personal data that is relevant for their circumstances.
- ensures that the digital lending platform is automatically protected from personal data loss such that customers do not have to take any further action to protect their privacy.
- avails its privacy policies to the customer prior to processing customer data.
- offers strong privacy defaults, user-friendly options and controls and respects user preferences.
- respects data subject rights.
- guarantees security of personal data.
- retains data for specifies periods of time and thereafter disposes the data from its records.
- effectively manages any third parties handling personal data on their behalf.
7. Marketing
Digital lenders intending to market their products directly to existing or prospective customers cannot do so without obtaining the consent of the customer. For consent to be valid, it must be express, free, specific informed and it must involve clear affirmative action on the part of the data subject. Digital lenders often use direct marketing channels such as sms or email marketing for promotions. The consent requirement demands that they have appropriate mechanisms in place to seek consent or opt-ins from customers. They must also provide customers with an easy way of opting out of the promotional communication. For more on the digital marketing requirements, please see our previous article.






