Open Finance and Privacy: How Cryptographic Guarantees Strengthen Data Governance
How cryptographic privacy enables safer data sharing across open-finance ecosystems.

Written by
Berwin D
Learn
Jul 4, 2026
Open finance promises to democratize financial data. Customers consent to sharing their financial records across institutions, enabling better lending decisions, personalized products, and competitive services. The Account Aggregator ecosystem in India, the Consumer Data Right in Australia, PSD2 in Europe, and similar frameworks in Singapore, Brazil, and the US all enable this flow.
The growth is real. India's Account Aggregator ecosystem grew 1,059% in FY 2023-24, making it the fastest-growing open finance network in the world. As of August 2024, the ecosystem included 155 Financial Information Providers (FIPs) across banks, insurance firms, investment platforms, pension funds, and tax authorities, alongside 475 Financial Information Users (FIUs).
But the architecture has a structural privacy gap. When a customer consents to data sharing, the receiving institution (the FIU) gets plaintext access to the full financial dataset. The consent governs who receives the data. It does not govern what the receiver can do with it once received.
The Plaintext Visibility Problem
In the current Account Aggregator design, data flows from Financial Information Providers (FIPs) to Financial Information Users (FIUs) through the AA pipeline. The data is encrypted in transit. The AA itself cannot decrypt it. But once the data reaches the FIU, it is decrypted and processed in plaintext.
This creates three problems that scale with the ecosystem.
Data liability concentrates at the FIU. Since the FIU holds a plaintext copy of the financial data, it becomes the custodian. Any data leak or security breach at the FIU creates liability for both the FIU and reputational risk for the FIP that provided the data. As the HedgeDoc paper notes, this leads FIPs to have reservations about the quality of FIU data governance, which adds to slower response times in consented data movements and limits participation.
Purpose limitation is not enforced by code. India's Digital Personal Data Protection Act requires that data fiduciaries specify a purpose of processing and that the processing must be necessary to achieve the stated purpose. In the current design, the FIU receives the full dataset in plaintext. There is no technical mechanism to prevent the FIU from processing the data beyond the consented purpose. Compliance relies on contractual assurance, not architectural enforcement.
The trust gap throttles adoption. Approximately 80% of countries now have active or draft privacy legislation. Three in four respondents believe financial institutions collect more data than required. The combination of plaintext visibility and missing purpose limitation creates friction that slows the data flow the ecosystem depends on.
The Cryptographic Alternative: Inference Sharing for Open Finance
The solution is to change what moves across the boundary. Instead of sharing raw financial data with the FIU, the system shares only the inference: the credit score, the eligibility decision, the risk assessment. The raw data stays with the FIP. The FIU receives the output it needs without ever seeing the underlying records.
This is inference sharing: the principle that organizations exchange computation results, not the data that produced them.
Silent Compute from Silence Laboratories provides the infrastructure for this architecture. The Cryptographic Computing Virtual Machine (CCVM) enables FIPs and FIUs to compute jointly on financial data without either party seeing the other's raw inputs. Consent is enforced cryptographically, not contractually. The CCVM produces a verifiable proof that the computation was performed correctly and within the bounds of the consented purpose.
The HedgeDoc paper proposes a design adaptation at the FIU level that ensures the FIU never gains plaintext visibility of data, while still receiving the analytical outputs it needs for lending, underwriting, and risk assessment.
How It Works in Practice
Credit underwriting. A lender (FIU) needs a credit assessment based on a customer's banking history held by a bank (FIP). Today, the full banking history is sent to the lender. With inference sharing, the computation runs across both parties' encrypted data. The lender receives a credit score or eligibility result. The banking history stays with the bank.
Cross-border MSME lending. Silence Laboratories won the G20 TechSprint 2025 with Proxtera for a cross-border MSME credit inference engine. The system enables cross-border sharing of credit information for small business underwriting without exposing raw financial records across jurisdictions. The approach was recognized in the Trust and Integrity in Scalable and Open Finance category.
Sanctions screening. A bank needs to check whether a customer appears on a sanctions list held by a counterparty in another jurisdiction. The BIS Project Mandala case study used Silence Laboratories' MPC infrastructure for privacy-preserving sanction screening and capital flow management across regulatory jurisdictions.
Fraud detection. Financial institutions want to check whether a flagged identity appears across multiple institutions' databases. The anti-fraud consortium pattern enables cross-institutional fraud signal sharing without exposing customer records.
Regulatory Alignment
India DPDP Act (2023). The Digital Personal Data Protection Act requires purpose limitation and data minimization. Inference sharing satisfies both: the FIU receives only the output needed for the stated purpose, and no raw data is transferred or stored beyond the FIP's environment.
PSD2 / PSD3 (EU). The revised Payment Services Directive governs open banking in the European Union. Privacy-preserving computation addresses GDPR Article 25 (data protection by design) in the context of cross-institutional data flows mandated by PSD2.
Consumer Data Right (Australia). The CDR framework enables consumer-directed data sharing across banking, energy, and telecommunications. MPC-based computation allows CDR participants to extract value from shared data without creating new data custody obligations.
MAS (Singapore). The Monetary Authority of Singapore's open banking initiatives align with MAS TRM requirements for technology risk management. Silence Laboratories, headquartered in Singapore, builds Silent Compute for deployment environments subject to MAS oversight.
Open Banking (US). The Consumer Financial Protection Bureau's Section 1033 rulemaking establishes open banking requirements in the US. Privacy-preserving computation offers a path to compliance that reduces the data governance burden on both data providers and data recipients.
Comparison: Traditional Open Finance vs Cryptographic Open Finance
Dimension | Traditional Open Finance | Cryptographic Open Finance (Silent Compute) |
|---|---|---|
Data visibility at FIU | Full plaintext access | Inference only; raw data stays at FIP |
Purpose limitation | Contractual | Cryptographically enforced |
Consent auditability | Log-based | Cryptographic proof of compliant processing |
FIU data liability | High; FIU holds plaintext copy | Reduced; no plaintext data at FIU |
FIP participation incentive | Slowed by data governance concerns | Strengthened by cryptographic guarantees |
Regulatory defensibility | Contractual DPAs | Architectural privacy by design |
Databricks Partnership
Silence Laboratories' Privacy-Preserving Financial Analytics Toolkit is available on the Databricks Marketplace. The toolkit enables financial institutions to run private set intersection (PSI) and other MPC-based analytics on their existing Databricks infrastructure. This lowers the deployment barrier for institutions that want to adopt privacy-preserving computation without building MPC infrastructure from scratch.
Related Reading
Anti-Fraud Consortium: Privacy-Preserving Fraud Signal Sharing
Private APIs: The Infrastructure Layer for Verification and Trust
FAQ
What is the privacy problem in open finance? When a customer consents to data sharing in open finance, the receiving institution (FIU) gets plaintext access to the full financial dataset. Consent controls who receives the data, but there is no technical mechanism to limit what the receiver does with it. This creates data liability, regulatory exposure, and trust friction.
What is inference sharing in open finance? Inference sharing means the FIU receives only the computation result (a credit score, eligibility decision, or risk assessment) without seeing the underlying financial data. The raw data stays with the FIP. The computation runs on encrypted or distributed data through MPC.
How does the Account Aggregator ecosystem benefit from MPC? MPC enables FIPs and FIUs to compute jointly on financial data without the FIU gaining plaintext access. This reduces FIU data liability, strengthens FIP participation incentives, and enforces purpose limitation cryptographically rather than contractually. The result is faster data flows and higher ecosystem participation.
Has this been deployed in production? Silence Laboratories won the G20 TechSprint 2025 with Proxtera for a cross-border MSME credit inference engine. The BIS Project Mandala case study used the same architecture for sanctions screening across jurisdictions. The Privacy-Preserving Financial Analytics Toolkit is available on the Databricks Marketplace.
SHARE
