Open Finance and Privacy: How Cryptographic Guarantees Strengthen Data Governance

How cryptographic privacy enables safer data sharing across open-finance ecosystems.

Portrait of Berwin D

Written by

Berwin D

Learn

Jul 4, 2026

Open finance promises to democratize financial data. Customers consent to sharing their financial records across institutions, enabling better lending decisions, personalized products, and competitive services. The Account Aggregator ecosystem in India, the Consumer Data Right in Australia, PSD2 in Europe, and similar frameworks in Singapore, Brazil, and the US all enable this flow.

The growth is real. India's Account Aggregator ecosystem grew 1,059% in FY 2023-24, making it the fastest-growing open finance network in the world. As of August 2024, the ecosystem included 155 Financial Information Providers (FIPs) across banks, insurance firms, investment platforms, pension funds, and tax authorities, alongside 475 Financial Information Users (FIUs).

But the architecture has a structural privacy gap. When a customer consents to data sharing, the receiving institution (the FIU) gets plaintext access to the full financial dataset. The consent governs who receives the data. It does not govern what the receiver can do with it once received.

The Plaintext Visibility Problem

In the current Account Aggregator design, data flows from Financial Information Providers (FIPs) to Financial Information Users (FIUs) through the AA pipeline. The data is encrypted in transit. The AA itself cannot decrypt it. But once the data reaches the FIU, it is decrypted and processed in plaintext.

This creates three problems that scale with the ecosystem.

Data liability concentrates at the FIU. Since the FIU holds a plaintext copy of the financial data, it becomes the custodian. Any data leak or security breach at the FIU creates liability for both the FIU and reputational risk for the FIP that provided the data. As the HedgeDoc paper notes, this leads FIPs to have reservations about the quality of FIU data governance, which adds to slower response times in consented data movements and limits participation.

Purpose limitation is not enforced by code. India's Digital Personal Data Protection Act requires that data fiduciaries specify a purpose of processing and that the processing must be necessary to achieve the stated purpose. In the current design, the FIU receives the full dataset in plaintext. There is no technical mechanism to prevent the FIU from processing the data beyond the consented purpose. Compliance relies on contractual assurance, not architectural enforcement.

The trust gap throttles adoption. Approximately 80% of countries now have active or draft privacy legislation. Three in four respondents believe financial institutions collect more data than required. The combination of plaintext visibility and missing purpose limitation creates friction that slows the data flow the ecosystem depends on.

The Cryptographic Alternative: Inference Sharing for Open Finance

The solution is to change what moves across the boundary. Instead of sharing raw financial data with the FIU, the system shares only the inference: the credit score, the eligibility decision, the risk assessment. The raw data stays with the FIP. The FIU receives the output it needs without ever seeing the underlying records.

This is inference sharing: the principle that organizations exchange computation results, not the data that produced them.

Silent Compute from Silence Laboratories provides the infrastructure for this architecture. The Cryptographic Computing Virtual Machine (CCVM) enables FIPs and FIUs to compute jointly on financial data without either party seeing the other's raw inputs. Consent is enforced cryptographically, not contractually. The CCVM produces a verifiable proof that the computation was performed correctly and within the bounds of the consented purpose.

The HedgeDoc paper proposes a design adaptation at the FIU level that ensures the FIU never gains plaintext visibility of data, while still receiving the analytical outputs it needs for lending, underwriting, and risk assessment.

How It Works in Practice

Credit underwriting. A lender (FIU) needs a credit assessment based on a customer's banking history held by a bank (FIP). Today, the full banking history is sent to the lender. With inference sharing, the computation runs across both parties' encrypted data. The lender receives a credit score or eligibility result. The banking history stays with the bank.

Cross-border MSME lending. Silence Laboratories won the G20 TechSprint 2025 with Proxtera for a cross-border MSME credit inference engine. The system enables cross-border sharing of credit information for small business underwriting without exposing raw financial records across jurisdictions. The approach was recognized in the Trust and Integrity in Scalable and Open Finance category.

Sanctions screening. A bank needs to check whether a customer appears on a sanctions list held by a counterparty in another jurisdiction. The BIS Project Mandala case study used Silence Laboratories' MPC infrastructure for privacy-preserving sanction screening and capital flow management across regulatory jurisdictions.

Fraud detection. Financial institutions want to check whether a flagged identity appears across multiple institutions' databases. The anti-fraud consortium pattern enables cross-institutional fraud signal sharing without exposing customer records.

Regulatory Alignment

India DPDP Act (2023). The Digital Personal Data Protection Act requires purpose limitation and data minimization. Inference sharing satisfies both: the FIU receives only the output needed for the stated purpose, and no raw data is transferred or stored beyond the FIP's environment.

PSD2 / PSD3 (EU). The revised Payment Services Directive governs open banking in the European Union. Privacy-preserving computation addresses GDPR Article 25 (data protection by design) in the context of cross-institutional data flows mandated by PSD2.

Consumer Data Right (Australia). The CDR framework enables consumer-directed data sharing across banking, energy, and telecommunications. MPC-based computation allows CDR participants to extract value from shared data without creating new data custody obligations.

MAS (Singapore). The Monetary Authority of Singapore's open banking initiatives align with MAS TRM requirements for technology risk management. Silence Laboratories, headquartered in Singapore, builds Silent Compute for deployment environments subject to MAS oversight.

Open Banking (US). The Consumer Financial Protection Bureau's Section 1033 rulemaking establishes open banking requirements in the US. Privacy-preserving computation offers a path to compliance that reduces the data governance burden on both data providers and data recipients.

Comparison: Traditional Open Finance vs Cryptographic Open Finance

Dimension

Traditional Open Finance

Cryptographic Open Finance (Silent Compute)

Data visibility at FIU

Full plaintext access

Inference only; raw data stays at FIP

Purpose limitation

Contractual

Cryptographically enforced

Consent auditability

Log-based

Cryptographic proof of compliant processing

FIU data liability

High; FIU holds plaintext copy

Reduced; no plaintext data at FIU

FIP participation incentive

Slowed by data governance concerns

Strengthened by cryptographic guarantees

Regulatory defensibility

Contractual DPAs

Architectural privacy by design

Databricks Partnership

Silence Laboratories' Privacy-Preserving Financial Analytics Toolkit is available on the Databricks Marketplace. The toolkit enables financial institutions to run private set intersection (PSI) and other MPC-based analytics on their existing Databricks infrastructure. This lowers the deployment barrier for institutions that want to adopt privacy-preserving computation without building MPC infrastructure from scratch.

Related Reading

FAQ

What is the privacy problem in open finance? When a customer consents to data sharing in open finance, the receiving institution (FIU) gets plaintext access to the full financial dataset. Consent controls who receives the data, but there is no technical mechanism to limit what the receiver does with it. This creates data liability, regulatory exposure, and trust friction.

What is inference sharing in open finance? Inference sharing means the FIU receives only the computation result (a credit score, eligibility decision, or risk assessment) without seeing the underlying financial data. The raw data stays with the FIP. The computation runs on encrypted or distributed data through MPC.

How does the Account Aggregator ecosystem benefit from MPC? MPC enables FIPs and FIUs to compute jointly on financial data without the FIU gaining plaintext access. This reduces FIU data liability, strengthens FIP participation incentives, and enforces purpose limitation cryptographically rather than contractually. The result is faster data flows and higher ecosystem participation.

Has this been deployed in production? Silence Laboratories won the G20 TechSprint 2025 with Proxtera for a cross-border MSME credit inference engine. The BIS Project Mandala case study used the same architecture for sanctions screening across jurisdictions. The Privacy-Preserving Financial Analytics Toolkit is available on the Databricks Marketplace.

No headings found on page

SHARE

Continue reading