Digital payment data privacy — understanding what eSewa, Khalti and mobile wallets collect about you in Nepal 2026 | BandhuFintech
Every time you tap "Pay" on eSewa, Khalti, or your mobile banking app, a quiet transaction runs parallel to your payment — a data transaction. Your wallet knows more about you than most people in your life. This guide reveals exactly what data digital payment platforms collect, how they use it, what Nepal's law says about your rights, and what you can do right now to take back control of your financial privacy.
The convenience of cashless payments has transformed daily life in Nepal — from buying vegetables at your local pasal to paying electricity bills and receiving remittances from abroad. But this convenience comes packaged with a significant trade-off that most users never consciously accepted: the continuous, systematic collection of deeply personal data. Understanding what is being collected, how it is stored, and who can access it is no longer optional for financially informed Nepali citizens in 2026.
Table of Contents
- Why Your Payment Data Is Valuable — And To Whom
- Category 1 — Identity and KYC Data
- Category 2 — Transaction and Financial Behaviour Data
- Category 3 — Device, Technical, and Network Data
- Category 4 — Location and Movement Data
- Category 5 — Behavioural and Usage Pattern Data
- Who Else Gets Your Data? Third-Party Sharing Explained
- Nepal's Legal Framework for Payment Data Privacy
- Data Practice Comparison — eSewa vs Khalti vs Bank Apps
- Your Privacy Rights as a Nepali Digital Payment User
- Your Data Privacy Protection Checklist
- Frequently Asked Questions
- Conclusion — Informed Consent Is Your Best Protection
Why Your Payment Data Is Valuable — And To Whom
Financial data is considered the most sensitive category of personal information by privacy researchers and regulators worldwide, and for good reason. Your payment history is a precise, timestamped record of your life — where you go, what you buy, who you pay, how much you earn, what you owe, and what your priorities are. This data has enormous commercial value, and it has significant implications for your security, your access to financial services, and your personal autonomy.
Understanding why this data is valuable helps you understand why companies collect it so comprehensively. There are four primary reasons digital payment platforms in Nepal and globally collect far more data than is strictly necessary to process a transaction. First, data improves their own product — understanding how users navigate the app helps them reduce friction and increase usage. Second, data enables credit scoring and financial products — a wallet company that understands your income, spending habits, and payment reliability can offer you loans and insurance products with significantly better risk modelling than a traditional bank with only your deposit history. Third, data has advertising value — aggregate insights about spending patterns can be monetized through targeted marketing partnerships. Fourth, regulatory compliance requires certain data — KYC (Know Your Customer) and AML (Anti-Money Laundering) obligations mandate specific data collection and retention under Nepal Rastra Bank directives.
The Spectrum of Entities Interested in Your Payment Data
- The payment platform itself: Uses data to improve services, develop new financial products (loans, insurance), and retain users through personalised experiences
- Advertising and marketing partners: Aggregate, anonymised spending data enables targeted campaigns; your data may contribute to audience segments sold to third parties
- Credit bureaus and lenders: Transaction history is increasingly used as an alternative credit signal for users without formal banking history
- Regulatory authorities: Nepal Rastra Bank (NRB) and Financial Intelligence Unit (FIU-Nepal) have legal access to transaction data for AML/CTF monitoring and investigation
- Law enforcement: Nepal Police and court orders can compel disclosure of transaction records in criminal investigations
- Affiliated companies: Parent companies and subsidiaries of wallet providers may access data under group data-sharing agreements disclosed (often obscurely) in privacy policies
- Malicious actors: Data breaches, insider threats, and compromised third-party integrations can expose your data to unauthorised parties — a persistent risk in Nepal's growing but maturing digital ecosystem
Category 1 — Identity and KYC Data
Identity & KYC (Know Your Customer) Data
High SensitivityKYC data is the most sensitive category because it is the most personally identifying and the least possible to change if compromised. Nepal Rastra Bank's Payment Service Provider and Payment System Operator regulations mandate KYC compliance for all licensed wallet operators — meaning this data collection is partly a legal requirement. However, what is legally required and what platforms actually collect and retain often differ significantly in scope.
Specific Data Points Collected
- Full legal name — as per citizenship or passport
- Date of birth — used for identity verification and age compliance
- Citizenship number or passport number — primary government ID reference
- Permanent and temporary address — at province, district, and municipality level
- Father's name and grandfather's name — required under Nepal's citizenship verification system
- Photograph — face image captured during KYC verification, often stored permanently
- Citizenship document scans / photos — front and back images retained in platform databases
- Biometric data — some platforms now use facial recognition during verification, creating a biometric template that is a separate, highly sensitive data category
- Linked bank account details — account number, bank name, IFSC/branch code
- Employer information — required for higher transaction tier verification on some platforms
- PAN (Permanent Account Number) — required for users with higher transaction volumes
️ What You Can Control
- You cannot avoid providing KYC data to use a licensed wallet — it is legally mandated. But you can minimise the tier of KYC by keeping transaction volumes below thresholds that trigger enhanced due diligence
- Request your wallet provider's data retention policy in writing — NRB requires licenced PSPs to have documented data retention schedules
- If you close your wallet account, formally request data deletion or anonymisation in writing and obtain written confirmation
- Be cautious about platforms that request KYC data beyond what is necessary for their stated service — this may indicate data harvesting beyond regulatory necessity
Category 2 — Transaction and Financial Behaviour Data
Transaction History & Financial Behaviour
High SensitivityYour transaction history is a comprehensive financial autobiography. Every payment you make through a digital wallet is permanently recorded with multiple metadata points beyond the simple fact of money moving from A to B. This data is retained for regulatory compliance periods — typically five to seven years under Nepal's AML/CFT regulations — and may be analysed continuously for commercial purposes during that retention period.
Specific Data Points Collected
- Sender and recipient identifiers — mobile numbers, wallet IDs, and merchant codes for every transaction
- Transaction amount and currency — precise NPR amount for every debit and credit
- Timestamp — date, time (to the second), and timezone of every transaction
- Transaction type — peer-to-peer transfer, merchant payment, utility bill, mobile top-up, loan EMI, etc.
- Merchant category — whether you paid a grocery store, restaurant, pharmacy, fuel station, or educational institution
- Transaction frequency patterns — how often you transact, at what times of day, on which days of the week
- Wallet balance history — running record of your wallet balance over time
- Payment remarks and descriptions — the note you add when sending money ("rent," "groceries," "loan repayment") is stored and analysed
- Failed and reversed transaction records — attempts, errors, and disputes are logged alongside successful transactions
- Refund and dispute history — patterns of complaints or chargebacks
- QR code scan data — which merchant QR codes you scanned, whether you completed payment or abandoned
- Linked account transactions — bank transfers, top-up sources, and withdrawal destinations
The commercial significance of this data is hard to overstate. A wallet company with two years of your transaction history knows your approximate monthly income (from inflows), your rent (large regular payment to the same recipient), your food spending habits, your healthcare spending, whether you have children (school fee payments), your religious practices (temple donation patterns), and your financial stress levels (frequency of small-value top-ups, payment timing relative to salary cycle). This insight profile is extraordinarily valuable for financial product targeting.
️ What You Can Control
- Keep transaction remarks minimal and non-descriptive — "payment" rather than "rent for flat 4B, Baneshwor" — remarks are stored and searchable
- Segment your financial life across different wallets if privacy is a priority — avoid using a single wallet for all payment categories
- Regularly download and review your own transaction history from the platform's export function — knowing what they have about you is the first step to managing it
- Be aware that closing an account does not erase transaction history — regulatory retention requirements keep these records for 5–7 years regardless of account status
Category 3 — Device, Technical, and Network Data
Device, Technical & Network Data
Medium SensitivityEvery time you open a payment app, your device broadcasts a stream of technical information to the platform's servers. This happens automatically, invisibly, and continuously. Most of this data is collected for legitimate purposes — fraud detection, security monitoring, and debugging — but it also creates a detailed technical fingerprint that can be used to track you across sessions, devices, and even platforms.
Specific Data Points Collected
- Device model and manufacturer — "Samsung Galaxy A35 5G," "Xiaomi Redmi Note 13 Pro," etc.
- Operating system version — Android 14, iOS 17, and patch level
- App version — which version of the wallet app you are running
- Device unique identifiers — Android ID, Advertising ID (GAID), and sometimes IMEI through system permission requests
- SIM card information — your operator (NTC or Ncell), SIM serial number in some cases
- IP address — your internet address, which can be used to infer your approximate location even without GPS
- Network type and carrier — WiFi vs mobile data, which operator's network, connection speed
- WiFi network name (SSID) — some apps read the name of your WiFi network, which reveals your home, office, and frequented locations
- Browser cookies and session tokens — for web-based payment interfaces, these persist across sessions
- Screen resolution and language settings — used for display optimisation but also contributes to your device fingerprint
- Installed app list — some Android payment apps request permission to read which other apps are installed on your device, including competing financial apps
- Clipboard access — some apps monitor clipboard content to auto-fill OTPs, but this also means they can read any text you recently copied
- Crash logs and performance data — error logs that may include app state at time of crash, potentially capturing sensitive screen content
️ What You Can Control
- Review and restrict app permissions in your phone's Settings — deny "Read Phone State," "Read Contacts," and "Read Installed Apps" permissions if the app functions without them
- Use a VPN when accessing payment apps on public WiFi — this masks your IP address and protects data in transit
- Reset your Android Advertising ID periodically — this breaks the cross-app tracking linkage (Settings → Google → Ads → Reset Advertising ID)
- On Android 12+, enable the Privacy Dashboard (Settings → Privacy → Privacy Dashboard) to see which apps accessed sensitive permissions recently
- Disable clipboard access for payment apps if your Android version supports per-app clipboard permission control
Category 4 — Location and Movement Data
Location & Movement Data
High SensitivityLocation data is among the most privacy-invasive categories of information that payment apps collect, because a detailed location history is functionally equivalent to a surveillance record of your physical life. Many payment apps request "precise location" permission (GPS-level accuracy to within a few metres) rather than the coarser "approximate location" that would be sufficient for any legitimate fraud-detection purpose. Understanding what location data is collected — and why apps want far more of it than they need — is essential to making an informed privacy choice.
Specific Data Points Collected
- GPS coordinates at transaction time — precise latitude and longitude recorded with every payment, creating a map of everywhere you spend money
- Background location access — apps with "Always On" location permission collect your location continuously, even when the app is not in use
- Location history over time — the accumulation of transaction-time locations reveals your home address, workplace, medical facilities visited, places of worship attended, and social venues
- Geofencing data — some apps use your location to trigger push notifications when you enter merchant areas, which requires ongoing location monitoring
- WiFi-based location inference — as noted above, WiFi network names can pinpoint your location without GPS by matching known network locations
- Cell tower triangulation — even without GPS permission, approximate location can be inferred through cell network data collected via the SIM information permission
A concrete example of why this matters: if your payment app has recorded GPS coordinates for every transaction over two years, it can identify that you visit a particular hospital every three weeks (likely a recurring medical treatment), that you regularly visit a specific area of the city on Friday evenings (social habits), and that you were in a different city during a specific period (travel history). None of this is information most people would voluntarily share with a commercial company, yet it is routinely collected through the incidental location recording of payment transactions.
️ What You Can Control
- Set location permission to "Only while using the app" rather than "Always" — this is the single most impactful location privacy action you can take right now on your phone
- For even stronger protection, set location to "Ask every time" — payment apps rarely have a legitimate need for location at every session
- On Android, go to Settings → Apps → [Payment App] → Permissions → Location and review the current setting
- Be aware that denying location permission may trigger additional friction (more authentication steps) in some apps, as location is used as a fraud signal — this is an intentional trade-off you are making for privacy
- If you use payment apps on a tablet or device without a SIM card connected to WiFi, consider using a privacy-focused DNS service to reduce the effectiveness of WiFi-based location inference
Category 5 — Behavioural and Usage Pattern Data
Behavioural & Usage Pattern Data
Medium–High SensitivityBeyond what you explicitly do on a payment app, the platform continuously monitors how you interact with it — your navigation patterns, the features you visit, the time you spend on each screen, and the sequence of your actions. This behavioural data is used to optimise the user experience, detect fraud (anomalous behaviour patterns often precede account takeovers), and build predictive models of your future financial behaviour and product preferences.
Specific Behavioural Data Collected
- Screen navigation flow — which screens you visit, in which order, and how long you stay on each
- Feature usage frequency — which functions you use most (P2P transfer, utility bills, QR scan), how often, and at what times
- Session duration and timing — how long you use the app per session, which days of the week and hours of day you are most active
- Search queries within the app — if you search for merchants or services within the app, those queries are logged
- Push notification interaction — whether you open, dismiss, or ignore notifications, and how quickly you respond
- Typing patterns and speed — some advanced fraud systems use keystroke dynamics (the rhythm and speed of your typing) as a behavioural biometric
- Scroll depth and touch patterns — how you scroll through screens and the pattern of your touches on the interface
- App open and close events — every time you open and close the app is logged with a timestamp
- Abandoned flows — when you start a payment and don't complete it, this incomplete transaction attempt is logged and analysed
- Referral and acquisition source — how you first found and installed the app (via which ad, link, or referral code)
️ What You Can Control
- Opt out of analytics and personalisation in the app's privacy settings if available — some platforms provide a settings toggle labeled "Analytics," "Personalisation," or "Usage Data"
- Disable push notifications for payment apps to prevent notification interaction tracking — you will receive in-app alerts when you open the app instead
- Close the app fully between sessions rather than leaving it running in the background — this limits passive behavioural data collection to your active usage periods
- Periodically clear the app's cache (Settings → Apps → [Payment App] → Storage → Clear Cache) to remove locally stored behavioural tracking data
Who Else Gets Your Data? Third-Party Sharing Explained
Your data does not stay exclusively within the platform you gave it to. Every major digital payment platform integrates with a range of third-party services — analytics tools, cloud infrastructure providers, fraud detection engines, marketing platforms, and credit bureaus. Understanding this ecosystem of data sharing is critical because your privacy is only as strong as the weakest link in this chain.
Common Third-Party Data Recipients
Analytics and crash reporting services: Most payment apps use third-party analytics SDKs (software development kits) embedded in their code that automatically send behavioural and device data to analytics companies. This data transfer happens every time you use the app and typically includes device information, session data, and app events.
Cloud infrastructure providers: Your data is stored on servers operated by cloud providers — predominantly Amazon Web Services (AWS), Google Cloud Platform, or Microsoft Azure. While these providers have strong security certifications, your data is physically hosted on infrastructure outside Nepal, in data centres in Singapore, Mumbai, or elsewhere in the Asia-Pacific region. This raises questions about the applicability of Nepali data protection law to data stored abroad — a legal question Nepal's framework has not yet fully resolved.
Fraud detection and cybersecurity partners: Payment platforms use specialised third-party fraud intelligence services that may receive transaction metadata, device fingerprints, and behavioural signals to assess transaction risk in real-time. These services maintain their own databases of fraud patterns and share intelligence across their client networks — meaning data about your transactions may contribute to fraud models used by companies you have no direct relationship with.
Credit bureaus and lending partners: eSewa and Khalti have moved into financial products — particularly micro-loans. When you access these products, your transaction and repayment data may be shared with credit bureaus such as Credit Information Bureau (CIB) Nepal and potentially with lending partners who underwrite the products. This sharing is typically disclosed in the terms and conditions but rarely highlighted prominently.
Merchant partners: When you pay a merchant through a wallet's QR system, the merchant receives your transaction details. The wallet platform may also provide merchants with aggregate analytics about customer payment patterns. The extent of data sharing with merchants varies and is rarely clearly communicated to users.
⚠️ The Privacy Policy Problem in Nepal
- Privacy policies are rarely read: A 2024 study found the average privacy policy of a fintech app takes 22 minutes to read — and most are written in legal language designed to be technically compliant rather than genuinely informative
- Consent is often bundled: Most platforms require you to accept their entire privacy policy as a condition of service — you cannot consent to necessary data collection while declining optional uses
- Policies change without meaningful notice: Updates to privacy policies are often communicated via email or in-app notifications that users routinely dismiss, meaning your consent to new data practices may be implied from continued app use
- Vague language obscures actual practices: Phrases like "we may share your data with trusted partners for service improvement purposes" can encompass an enormous range of actual data sharing that the average user would not anticipate
- Nepali language versions lag English: For many fintech apps, the authoritative privacy policy is in English, creating an accessibility barrier for Nepali-language-primary users who form a significant portion of the user base
Nepal's Legal Framework for Digital Payment Data Privacy
Nepal's data protection legal landscape is evolving but remains incomplete as of 2026. Understanding which laws apply — and where the gaps are — is essential for knowing the actual, rather than aspirational, level of protection available to Nepali digital payment users.
Individual Privacy Act 2018 (Byaktigat Gupta Sambandhi Ain 2075)
Nepal's primary privacy legislation recognises the right to privacy of personal information and prohibits unauthorised collection, use, and disclosure of personal data without consent. However, the Act predates Nepal's digital payment boom and lacks specific provisions for financial data, data breach notification requirements, and enforcement mechanisms adequate for digital-era privacy challenges. The Act does not establish a dedicated data protection authority, which significantly limits its practical effectiveness.
Nepal Rastra Bank Directives
NRB's Payment Service Provider directives and Payment System Operator regulations require licensed payment companies to implement data security measures, maintain customer data confidentiality, and retain transaction records for defined periods (typically five years for AML compliance). NRB can and does conduct supervisory reviews of payment companies' data handling practices, providing the most practically effective regulatory oversight of digital payment data in Nepal's current framework.
Electronic Transactions Act 2008 (Amended)
The Electronic Transactions Act provides a legal basis for digital contracts and electronic records, and includes provisions related to cybercrime, but does not specifically address data privacy in the modern sense. Its provisions related to unauthorised access to computer systems provide some protection against data breaches, but its framework is not calibrated for the complexity of contemporary data collection practices.
Financial Intelligence Unit — AML/CFT Framework
The FIU-Nepal operates under the Asset (Money) Laundering Prevention Act and associated regulations, which mandate transaction monitoring, suspicious transaction reporting, and data sharing between financial institutions and the FIU. This framework gives regulatory authorities significant access to your financial transaction data in the context of AML/CFT compliance — a legitimate public interest purpose but one that significantly constrains the absolute privacy of financial data in Nepal.
What Is Coming: Nepal's Data Protection Bill
- A dedicated Data Protection Bill has been in draft stage in Nepal — expected to introduce a formal data protection framework closer to international standards
- The draft proposes categories of sensitive personal data (including financial data and biometric data) that would require explicit, specific consent for processing
- It is expected to establish a Data Protection Authority with enforcement powers, including the ability to impose financial penalties on non-compliant organisations
- Draft provisions include the right to access your own data, the right to correction, and a limited right to deletion — rights not currently enforceable under existing Nepali law
- Until this legislation passes, Nepali digital payment users rely primarily on NRB supervision and the terms of their individual contracts with payment providers for data protection
- For current awareness on this legislation, the Nepal Law Commission (lawcommission.gov.np) and NRB's official website (nrb.org.np) publish updates on relevant regulatory developments
Data Practice Comparison — eSewa, Khalti, and Mobile Banking Apps
The following comparison is based on publicly available privacy policies and terms of service as of mid-2026. Privacy practices can change — always review the current privacy policy of any platform you use.
| Data Practice | eSewa | Khalti | NMB Mobile | ConnectIPS |
| Full KYC data collection | Yes (mandatory) | Yes (mandatory) | Yes (mandatory) | Yes (mandatory) |
| Transaction history retention | 5+ years | 5+ years | 7+ years | 5+ years |
| GPS location at payment | Yes | Yes | Optional | Not stated |
| Third-party analytics SDKs | Yes | Yes | Limited | Limited |
| Data shared with credit bureau | Yes (loan products) | Yes (loan products) | Yes (all products) | Not applicable |
| Marketing data usage | Yes | Yes | Limited | No |
| In-app opt-out for analytics | Not available | Not available | Limited | Limited |
| Data breach notification policy | Not explicit | Not explicit | Yes (per RBI/NRB) | Not explicit |
| User data download available | Transaction history only | Transaction history only | Transaction history only | Limited |
Your Privacy Rights as a Nepali Digital Payment User
While Nepal's data protection framework is not yet as comprehensive as the GDPR in Europe, you do have meaningful rights and practical options to exercise greater control over your payment data. Understanding and proactively exercising these rights is the foundation of good digital financial hygiene.
Right to Access
You can request a copy of the personal data held about you by any payment platform. Most platforms provide transaction history download, but full personal data access requests may require a formal written request to the company's data/privacy officer.
✏️ Right to Correction
You have the right to request correction of inaccurate personal data. If your address, name spelling, or other personal details are incorrect in a platform's records, you can request correction through their customer support channels.
️ Right to Deletion
A limited right to deletion exists — you can request account deletion and associated personal data removal. However, transaction records required for regulatory compliance (AML/CFT) cannot be deleted before the legally mandated retention period expires, regardless of your request.
Right to Object
You can object to your data being used for marketing and promotional purposes. Most platforms provide an unsubscribe option for marketing communications, though opting out of analytics and product improvement uses is rarely as straightforward.
Right to Complain
If a payment platform violates your privacy rights or NRB's data handling directives, you can file a complaint with Nepal Rastra Bank's Financial Sector Regulation Department (fsrd@nrb.org.np) or escalate through Nepal's court system under the Individual Privacy Act.
Right to Data Portability
While not yet formally established in Nepali law, you can request your data in a portable format and most platforms will provide transaction exports in PDF or CSV format. Full portability rights are expected to be formalised under the forthcoming Data Protection Act.
️ Your Complete Payment Data Privacy Checklist
App Permissions
- Set location to "Only while using" for all payment apps
- Deny "Read Phone State" permission unless truly necessary
- Deny "Read Contacts" unless you use contact-based P2P features
- Review and audit all app permissions monthly in phone Settings
- Deny "Read Installed Apps" permission if requested
- Disable microphone permission for payment apps
- Check for clipboard access permission and restrict if available
Account Practices
- Read the key sections of the privacy policy before signing up
- Keep transaction remarks minimal and non-descriptive
- Regularly download your transaction history and review it
- Close unused payment accounts formally — don't just uninstall
- Opt out of marketing communications in account settings
- Reset your Android Advertising ID every 3 months
- Clear app cache periodically to remove local tracking data
Device and Network
- Keep payment apps updated — updates patch security vulnerabilities
- Use a VPN when transacting on public WiFi networks
- Enable screen lock with biometric or strong PIN
- Do not use payment apps on rooted or jailbroken devices
- Enable Android Privacy Dashboard to monitor permission usage
- Use a dedicated email address for payment app accounts
- Enable two-factor authentication wherever available
Frequently Asked Questions
Does eSewa or Khalti sell my personal data to other companies?
Based on their publicly available privacy policies as of 2026, eSewa and Khalti do not explicitly claim to sell personal data to third parties in the traditional sense. However, both platforms state that they share data with "trusted partners" and service providers — categories that can encompass analytics companies, marketing platforms, and financial product partners. The distinction between "selling" data and "sharing" it with partners for commercial purposes is legally significant in some jurisdictions but functionally minimal from a user privacy perspective. The most accurate answer is: your data is shared beyond the platform with multiple third parties, though it may not be explicitly sold in the way that advertising brokers operate.
Can the Nepal government access my digital payment transaction history?
Yes, under specific legal circumstances. Nepal's AML/CFT framework gives the Financial Intelligence Unit (FIU-Nepal) and authorised regulatory bodies access to transaction data from licensed payment service providers for purposes of investigating money laundering, terrorist financing, and related financial crimes. Nepal Police and courts can obtain transaction records through proper legal process (court orders, investigation warrants) for criminal investigations. NRB as the payment system regulator also has supervisory access to transaction data. Routine, mass surveillance of all transactions without legal basis would not be permitted under current law, but targeted access for legitimate law enforcement purposes is well-established and routinely used.
What happens to my data if I delete my eSewa or Khalti account?
Account deletion removes your active account access but does not erase all associated data. Under Nepal's AML/CFT regulations and NRB directives, licensed payment service providers are required to retain transaction records for a minimum of five years — this obligation applies regardless of whether the customer has closed their account. Your KYC identity documents are similarly retained for the regulatory period. Behavioural and analytics data retention practices vary and are typically governed by the platform's internal data retention policy rather than specific regulatory requirements. When closing an account, formally request in writing what data will be retained, for how long, and under what legal basis — reputable providers should be able to answer this.
Is it safer to use mobile banking apps or third-party wallets like eSewa from a data privacy perspective?
This is a nuanced comparison. Mobile banking apps operated by licensed commercial banks are subject to NRB's comprehensive banking regulations, which include strong data security and confidentiality requirements that have been established over decades. Banks also typically have more conservative data monetisation approaches — their business model is built on interest and fees, not data commercialisation. Third-party wallets like eSewa and Khalti, while also NRB-regulated, operate in a more competitive fintech environment where data insights are a more central part of their commercial model. On balance, regulated commercial bank mobile apps tend to have more conservative data practices, though the difference is narrowing as banks adopt more digital-native approaches. Neither category offers complete data privacy — both collect extensive transaction and device data as a fundamental feature of their operation.
Can I use digital payments in Nepal while minimising data collection?
You can meaningfully reduce but not eliminate data collection associated with digital payments. Practical steps that substantively reduce your data exposure include: restricting app permissions to the minimum necessary, using payment amounts that stay below enhanced KYC thresholds, keeping transaction remarks minimal, disabling location for payment apps, using a VPN on public WiFi, resetting your advertising ID regularly, and closing unused accounts. For transactions where maximum privacy is desired, cash remains the most private payment method — it generates no digital record, requires no identity verification for routine amounts, and involves no third-party data intermediaries. The privacy-convenience trade-off in digital payments is real, and the appropriate balance depends on your individual risk tolerance and specific circumstances.
What should I do if I suspect a payment platform has misused my data?
Document your concern with as much specificity as possible — what data you believe was misused, how you became aware of this, and what harm you believe resulted or may result. First, contact the payment platform directly through their official customer service and privacy or data protection contact channel, and request a formal response. If the platform's response is unsatisfactory, escalate to Nepal Rastra Bank's Financial Sector Regulation Department at fsrd@nrb.org.np, providing your documented complaint. For matters involving potential criminal breach of data confidentiality, Nepal Police Cyber Bureau at 1-44-23-10-00 or cybercrime.police.gov.np handles cybercrime complaints including data-related offences. The Individual Privacy Act 2018 also provides a pathway for civil legal action, which can be pursued through Nepal's courts with the assistance of a legal practitioner.
Conclusion — Informed Consent Is Your Best Protection
Digital payment platforms collect far more data about you than is strictly necessary to move money from one account to another. This is not inherently malicious — much of the data serves legitimate purposes including fraud prevention, regulatory compliance, and product improvement. But the scale, scope, and commercial use of payment data in Nepal has evolved far faster than user awareness, regulatory frameworks, or platform transparency have kept pace.
The goal of this guide is not to discourage digital payments — they are enormously beneficial, safer than cash in many respects, and increasingly essential to economic participation in modern Nepal. The goal is to ensure that your choice to use these services is genuinely informed. Here is what that looks like in practice:
- Read the key sections of privacy policies before you create new accounts — particularly the sections on data sharing and data retention
- Review and restrict app permissions as your first action after installing any payment app — location, contacts, and phone state permissions deserve particular scrutiny
- Stay engaged with Nepal's regulatory developments — the forthcoming Data Protection Act and NRB's evolving directives will significantly change your rights and protections
- Exercise your existing rights proactively — request your data, correct inaccuracies, opt out of marketing, and close accounts you no longer use
- Share this knowledge — privacy is a collective concern; the more Nepali users understand their digital payment data rights, the stronger the market and regulatory pressure for better practices
- Follow official sources for updates — NRB (nrb.org.np) and the Nepal Law Commission (lawcommission.gov.np) publish relevant regulatory developments that affect your payment data rights
As Nepal's digital payments ecosystem matures, the conversation about data privacy will only grow more important. The platforms that build genuine trust — through transparent data practices, meaningful user controls, and proactive compliance with evolving regulations — will be the ones that earn lasting loyalty from an increasingly informed Nepali user base.
The information in this article reflects publicly available privacy policies and the regulatory framework as of July 2026. Regulations and platform practices change — always refer to your payment provider's current privacy policy and NRB's official directives for the most up-to-date information.
Discussion