The Quiet Invasion:
One minute you’re simply submitting your identification number to open a digital wallet.
The next, another app is demanding a clear photograph of your international passport, a live selfie while holding the document, and a recent utility bill as proof of address.
What begins as a routine verification quickly escalates into a harvest of sensitive information that few other tech sectors demand with less frequency. Fintech apps have perfected this escalation.
After the identification number comes the request for next-of-kin details: full name, phone number, residential address, and exact relationship. These are not abstract data points; they belong to a real person who has never even downloaded the app, never agreed to any terms of service, and may have no knowledge that their personal information is now sitting in a company’s database.
Some platforms go further still, requesting access to phone contacts, employment history, estimated salary range, a full scan of a national identity card, and a tax identification number—all justified under the broad and convenient banner of “Know Your Customer” compliance.
The irony is striking. For years, many of us assumed that social media platforms or messaging apps were offenders when it came to careless data practices. We criticized them for tracking preferences, location, or browsing habits. Yet fintech has quietly surpassed them in the sensitivity of what it collects.
This level of data collection is routinely framed as necessary for security, fraud prevention, and regulatory compliance. In reality, the volume and breadth of information requested frequently exceed what is strictly required for the service being offered. Once collected, the data is stored, processed, and in some cases shared with third parties under lengthy privacy policies that few users read. The individual whose next-of-kin details were submitted without their knowledge has no practical way to withdraw consent or even discover that the information exists in the system.
Users are told that sharing more personal information is the price of convenient financial services, while the platforms accumulate ever richer profiles that can be leveraged for risk scoring, marketing, or sale.
Meanwhile, the risk of breaches, misuse, or unauthorized access falls almost entirely on the people whose data has been gathered.
At the end of the day, the question still remains whether fintech apps are still within the level of the jurisdiction for the level of data collection.
The secondary question is: are our data protected?