Safaricom has introduced an additional data-minimisation measure on M-PESA that limits the personal information displayed to recipients of person-to-person money transfers.
Under the feature, a recipient of money sent through M-PESA can see only the sender’s first and last name and a partially masked mobile number. Instead of displaying the sender’s complete phone number, the transaction message shows a format such as 0722***000.
The change is designed to prevent recipients from using information obtained through an M-PESA transaction to make unwanted calls, send messages, add customers to WhatsApp groups or initiate other unsolicited contact.
In a video explaining the feature (https://youtu.be/95BZQOB8ECM), Safaricom highlights situations in which customers send money to people with whom they do not have an established relationship, such as service providers or individuals receiving a tip.
Previously, the recipient could obtain the sender’s contact details from the transaction message and use them to contact the customer afterwards.
Safaricom Head of Customer Privacy and Data Protection Sharon Holi said some customers had received calls or messages from people asking for friendship, contributions to harambees or assistance with expenses such as school fees after completing an M-PESA transaction.
The company says the new system gives customers greater control over when their complete personal details can be shared.
Sender’s consent required to reveal full details
Where a recipient has a legitimate reason to obtain additional information about a sender, Safaricom has provided a consent-based verification process.
The recipient can forward the relevant M-PESA transaction message to the shortcode 334. The sender then receives a request asking for permission to disclose their full details.
The information is released only when the sender approves the request. If permission is declined, the recipient is informed that the sender has not consented to sharing the details.
Only one request can be made for each transaction, and the request remains valid for 24 hours.
Safaricom describes the approach as being built around transparency, choice and consent, allowing customers to decide whether their information should be disclosed beyond what is necessary to confirm a transaction.
Protecting privacy without disrupting transactions
The data-minimisation feature applies to person-to-person M-PESA transactions and does not prevent customers from sending or receiving money.
It also does not interfere with the reversal process because M-PESA reversals are processed using transaction codes rather than the sender’s visible phone number or full name.
Safaricom says limiting the information displayed during transactions can help reduce unwanted communication, fraud, spam and social-engineering attempts in which criminals use personal information to manipulate customers.
The company processes about 150 million transactions each day, according to Safaricom Group Chief Executive Officer Peter Ndegwa, making the protection of customer information an important part of maintaining trust in the platform.
Part of a wider M-PESA privacy programme
The person-to-person data-minimisation feature is the latest in a series of privacy measures Safaricom has introduced across the M-PESA ecosystem.
In 2020, the company introduced privacy protections through Pochi La Biashara, where a sender does not retain the recipient’s complete phone number after making a payment.
Safaricom subsequently reduced the customer information visible to members of staff in 2021 and began masking mobile numbers displayed on M-PESA statements in 2022.
The company also introduced data-minimisation measures for large organisations using M-PESA integrations, including Buy Goods and customer-to-business payment systems, during 2023 and 2024.
Safaricom says these measures form part of its “privacy by design” approach, under which privacy considerations are incorporated into the development and operation of its products.
The latest change means sending someone money through M-PESA will no longer automatically give that person access to the sender’s complete mobile number.
Customers can still share their details when necessary, but that disclosure must now happen with their knowledge and consent.
