Digital lender Tuma Cash has been accused of breaching Kenya’s data protection laws and flouting Central Bank of Kenya regulations after a borrower alleged that the company accessed and shared personal information without consent while using threats and public shaming to force repayment.
In the latest case against predatory digital lenders in Kenya, the borrower says what began as an attempt to secure urgent funds quickly spiraled into harassment. The individual claims that after taking a loan through Tuma Cash, the app accessed private data and began circulating personal details to third parties.
These actions directly contravene the Data Protection Act, which restricts the collection and sharing of personal information without clear consent.
The borrower further alleges that the lender used intimidation and humiliation as tools of debt collection.

Kenyan regulations issued by the Central Bank of Kenya prohibit digital lenders from accessing a customer’s phonebook and from using debt shaming, threats, or abusive language to recover loans.
These rules were introduced to curb widespread complaints about rogue loan apps exploiting borrowers.
In a direct appeal for help, the borrower shared the following message Cyprian Nyakundi:
“Hello Cyprian. Kindly hide my ID. This Tuma Cash loan app is breaching data privacy policy by shaming their customers and sharing data with third parties who are not trained or professional in any way. Kindly raise an alarm on the harassment that is being done. Below are some of the messages.”

The statement reflects a growing frustration among Kenyans who have turned to digital lenders for quick credit, only to face aggressive recovery tactics. Many borrowers rely on such platforms during financial emergencies, making them vulnerable to unfair practices.
While digital lending has expanded access to credit, cases like this raise serious questions about compliance and accountability.

Kenya’s Data Protection Act was enacted to safeguard citizens from misuse of their personal information. It requires companies to obtain clear consent before collecting or sharing data and to use that data only for legitimate purposes.
Any unauthorized disclosure or use of personal details can attract penalties.
At the same time, the Central Bank has tightened oversight of digital lenders to ensure they operate within the law. Licensing requirements and strict conduct rules were put in place to eliminate exploitative behavior.


