BusinessMain StoryNational NewsNews

MPs reject push by KRA to snoop on Kenyans’ bank accounts

KRA had defended the proposal, saying it will enable it to catch up with tax cheats and those engaging in money laundering

A parliamentary committee has rejected a proposal by the Kenya Revenue Authority (KRA) to integrate its system with banks.

While tabling the report at the Assembly yesterday, National Assembly Committee on Finance and Economic Planning chairman Kuria Kimani stated that the proposal by KRA does not meet the constitutional threshold, which guarantees every Kenyan the right to privacy.

“On the proposal to grant the Kenya Revenue Authority (KRA) unrestricted access to personal data, the Committee previously deliberated and concluded that such a provision does not meet the constitutional threshold set under Article 31(c) and (d) of the Constitution of Kenya, which guarantees every individual the right to privacy. In its analysis, the Committee also referenced Section 51 of the Data Protection Act, which outlines specific conditions under which exemptions to data protection may be permitted,” the report by the committee reads in part.

According to the committee, KRA already has enough access to relevant data from taxpayers.

“Moreover, the Committee noted that the existing legal framework, specifically Section 60 of the Tax Procedures Act, already provides sufficient authority for the Commissioner or an authorized officer to access relevant data, provided they obtain a judicial warrant. This ensures that tax enforcement powers are exercised within a framework of legal oversight and due process,” the Kimani-led committee report noted.

The move by the Finance Committee comes after many Kenyans expressed the same reservations on the Bill proposal during the Public participation in the Finance Bill.

“One of the issues that is coming out clearly from the counties that we have visited is the issue of data privacy. Many Kenyans have come out and said that they do not think KRA, having access to their private data, is good,” Kuria had stated previously during the public participation process.

See also  100 businesses to lose goods as KRA announces auction

The 2025 Finance Bill seeks to do away with section 59 (1) (B) of the Tax Procedures Act that bars the revenue collector from integrating its system with businesses.

The Finance Bill 2025 seeks to do away with Section 59, 1B of the Tax Procedures Act, which bars KRA from integrating its systems with those of a business.

“Section 59 (A) of the Tax Procedures Act is amended by deleting subsection (1B),” the Finance Bill states in part.

KRA had, however, defended the proposal, saying it will enable it to catch up with tax cheats and those engaging in money laundering.

“If KRA wants to know whether entity A is declaring their fair share of tax, we ask them for their bank account, and then they will provide us with their bank statements. KRA will then look at the bank statements and compare them with what has been declared as their income, and if there are any variances, we always come back and ask why there are any differences,” Nickson Omondi, the Manager of the KRA Digital Tax Office explained last month while defending the proposal.

The Kenya Bankers Association (KBA) had rejected the push, saying it violates the Data Protection Act.

“The process stalled due to the absence of an appropriate legal framework to support banks to share customer personal information,” KBA Chief Executive Officer Raimond Molenje.

KRA had defended the move saying it aimed to integrate its systems with financial institutions to monitor real-time transactions, identify tax evaders, enhance tax compliance, and boost revenue collection.

See also  Cost of paint to rise as High Court dismisses tax suit 

However, the Data Protection Act safeguards individuals’ rights to privacy by regulating how personal data is collected, stored, and shared.

Banks had argued that giving KRA direct access to customer transaction data may violate this act.

At the same time, integrating systems would have increased the risk of data breaches and cyberattacks in the absence of robust cybersecurity measures.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button