Millions at Risk as Their Mobile Money Transaction Data is Breached

By David Indeje / Published December 1, 2017 | 11:54 am



insurance

Financial inclusion in Kenya currently stands at 75.3 percent with internet penetration at 88 percent has allowed the efficient adaptability of mobile banking services.

However, according to a new Privacy International report says the financial industry is helping itself to consumers’ personal data without any checks or monitoring from governments.

The Privacy International report outlines how fintech threatens privacy and other fundamental rights by focusing on two case studies.

Using research that analyses the India Stack initiative, built upon the Aadhaar identification number in India, and credit scoring apps and services in Kenya, the report shows how information that is traditionally considered irrelevant to the financial sector, such as social media usage and smartphone habits underpin credit rating strategies.  

According to the report, consumers’ social media behaviour is not only monitored by employers, but also by credit ratings financial institutions, such as banks and insurance companies.

The information gathering has now expanded to include call logs, text messages, and social networks. What is being evaluated is no longer individual decisions and behaviour, but who individuals are and with whom they interact, and how.

The report features Tala, Branch and M-Kopa operations to illustrate the tradeoffs Kenyans are making between Privacy and credit access.


Tala App

Tala, previously known as Mkopo Rahisi, started operating in Kenya in 2014.

“This app asks for a wide range of permissions, including access to installed apps, contacts, precise location via GPS, the content of SMS messages, and the call log. The Tala app uploads data to Tala’s US-based servers every 24 hours, whether the user has even opened the app or not.. Customers are encouraged to keep the app on their phone, even if they have been rejected: the app will continue to send their data back to Tala.”

Tala analyses call logs: their analysis has found that people who make regular calls to family are 4 percent more likely to repay their loan. To do this analysis, they need to know who your family is: from the content of text messages that call someone “mama”, and the pattern of calls.

 


Branch App

Branch: is a California-based startup with operations in Kenya but looking to expand elsewhere in developing markets.

Branch also makes use of Facebook for authentication; as discussed below, this is allowed under Facebook’s terms and conditions. Another factor that Branch uses for its decision-making is the behaviour of your friends and their repayment patterns for Branch loans.

The app gains access to permissions including the content of the user’s call log, contacts, SMS messages, and precise location via GPS.


M-kopa solar

M-Kopa: differs from Branch and Tala, in the sense that it does not use a mobile app but rather is a fintech that offers loans for its solar panel system, as well as other goods.

The devices that M-Kopa sells contain a 2G SIM card, the main purpose of which is for billing. According to Chad Larson, one of the founders and current Finance Director, the data transmitted from the device is used for further analysis. Even though a side effect, they are taking advantage of this: they have a team of data scientists based in Nairobi.

M-Kopa’s website states that “After completing payments, customers own the product outright.” However, the customer does not own their data. The terms and conditions of a M-Kopa loan make the company’s position on data clear: “M-KOPA shall have absolute and sole ownership of … the data which is obtained by the Customer’s use of the Device.”


Kenya is yet to enact the Data Protection Bill 2013 which seeks to provide for protection of personal information and hereby give effect to the constitutional right of a person not to have information relating to their family or private affairs unnecessarily required or revealed as enshrined in Article 31 of the Constitution of Kenya and Article 17 of the 1948 Universal Declaration of Human Rights; which Kenya is among the more than 160 signatories.

Read:

Data protection framework with global standards, opportunities for Kenya 

We are open to innovations, but conscious of potential risks – Central Bank 

“The fintech sector is using vast sources of our personal information to create our financial identity – data from our spending, our social networks, our phones. The sector must begin to recognise the risks and harms are emerging from its work, particularly in parts of the world with limited or non-existent data protection legislation. We need governments and regulators to ensure that advancements in fintech do not violate privacy,” PI Research Officer Dr. Tom Fisher says.

“The fintech sector is using vast sources of our personal information to create our financial identity – data from our spending, our social networks, our phones.

“The sector must begin to recognise the risks and harms that are emerging from its work, particularly in parts of the world with limited or non-existent data protection legislation. We need governments and regulators to ensure that advancements in fintech do not violate privacy,” he said.




About David Indeje

David Indeje is a writer and editor, with interests on how technology is changing journalism, government, Health, and Gender Development stories are his passion. Follow on Twitter @David_IndejeDavid can be reached on: (020) 528 0222 / Email: info@sokodirectory.com

View other posts by David Indeje


More Articles From This Author








Trending Stories










Other Related Articles










SOKO DIRECTORY & FINANCIAL GUIDE



ARCHIVES

2024
  • January 2024 (238)
  • February 2024 (227)
  • March 2024 (190)
  • April 2024 (133)
  • May 2024 (157)
  • June 2024 (145)
  • July 2024 (136)
  • August 2024 (154)
  • September 2024 (61)
  • 2023
  • January 2023 (182)
  • February 2023 (203)
  • March 2023 (322)
  • April 2023 (298)
  • May 2023 (268)
  • June 2023 (214)
  • July 2023 (212)
  • August 2023 (257)
  • September 2023 (237)
  • October 2023 (264)
  • November 2023 (286)
  • December 2023 (177)
  • 2022
  • January 2022 (293)
  • February 2022 (329)
  • March 2022 (358)
  • April 2022 (292)
  • May 2022 (271)
  • June 2022 (232)
  • July 2022 (278)
  • August 2022 (253)
  • September 2022 (246)
  • October 2022 (196)
  • November 2022 (232)
  • December 2022 (167)
  • 2021
  • January 2021 (182)
  • February 2021 (227)
  • March 2021 (325)
  • April 2021 (259)
  • May 2021 (285)
  • June 2021 (272)
  • July 2021 (277)
  • August 2021 (232)
  • September 2021 (271)
  • October 2021 (305)
  • November 2021 (364)
  • December 2021 (249)
  • 2020
  • January 2020 (272)
  • February 2020 (310)
  • March 2020 (390)
  • April 2020 (321)
  • May 2020 (335)
  • June 2020 (327)
  • July 2020 (333)
  • August 2020 (276)
  • September 2020 (214)
  • October 2020 (233)
  • November 2020 (242)
  • December 2020 (187)
  • 2019
  • January 2019 (251)
  • February 2019 (215)
  • March 2019 (283)
  • April 2019 (254)
  • May 2019 (269)
  • June 2019 (249)
  • July 2019 (335)
  • August 2019 (293)
  • September 2019 (306)
  • October 2019 (313)
  • November 2019 (362)
  • December 2019 (318)
  • 2018
  • January 2018 (291)
  • February 2018 (213)
  • March 2018 (275)
  • April 2018 (223)
  • May 2018 (235)
  • June 2018 (176)
  • July 2018 (256)
  • August 2018 (247)
  • September 2018 (255)
  • October 2018 (282)
  • November 2018 (282)
  • December 2018 (184)
  • 2017
  • January 2017 (183)
  • February 2017 (194)
  • March 2017 (207)
  • April 2017 (104)
  • May 2017 (169)
  • June 2017 (205)
  • July 2017 (189)
  • August 2017 (195)
  • September 2017 (186)
  • October 2017 (235)
  • November 2017 (253)
  • December 2017 (266)
  • 2016
  • January 2016 (164)
  • February 2016 (165)
  • March 2016 (189)
  • April 2016 (143)
  • May 2016 (245)
  • June 2016 (182)
  • July 2016 (271)
  • August 2016 (247)
  • September 2016 (233)
  • October 2016 (191)
  • November 2016 (243)
  • December 2016 (153)
  • 2015
  • January 2015 (1)
  • February 2015 (4)
  • March 2015 (164)
  • April 2015 (107)
  • May 2015 (116)
  • June 2015 (119)
  • July 2015 (145)
  • August 2015 (157)
  • September 2015 (186)
  • October 2015 (169)
  • November 2015 (173)
  • December 2015 (205)
  • 2014
  • March 2014 (2)
  • 2013
  • March 2013 (10)
  • June 2013 (1)
  • 2012
  • March 2012 (7)
  • April 2012 (15)
  • May 2012 (1)
  • July 2012 (1)
  • August 2012 (4)
  • October 2012 (2)
  • November 2012 (2)
  • December 2012 (1)
  • 2011
    2010
    2009
    2008
    2007
    2006
    2005
    2004
    2003
    2002
    2001
    2000
    1999
    1998
    1997
    1996
    1995
    1994
    1993
    1992
    1991
    1990
    1989
    1988
    1987
    1986
    1985
    1984
    1983
    1982
    1981
    1980
    1979
    1978
    1977
    1976
    1975
    1974
    1973
    1972
    1971
    1970
    1969
    1968
    1967
    1966
    1965
    1964
    1963
    1962
    1961
    1960
    1959
    1958
    1957
    1956
    1955
    1954
    1953
    1952
    1951
    1950