Success message
Error message
Digital Assets - DLT
Published: 11 Feb 2026, by Wing Chiu
Hong Kong's eight digital banks ("DBs") were set up with a clear goal: to bring banking services to people who have been left out by traditional banks. But the numbers tell a troubling story. As of December 2024, all eight DBs are still losing money. More worrying is that their impaired loan ratios ("ILR"), a measure of how many loans are considered as bad debts, are unusually high. ZA Bank, Mox Bank, and WeLab Bank recorded ILRs of 3.26%, 5.76%, and 6.36% respectively, compared to just 0.87% and 1.05% for DBS Bank Hong Kong and Bank of China (Hong Kong). This is a big gap, and it raises a serious question: why are DBs getting so many loans wrong?
The Root Problem: Incomplete Data
The answer lies in how DBs assess whether someone is creditworthy before lending to them. To do this, they need reliable data about a person's financial behaviour. The problem is that the current retail credit data assessed by DBs cannot overcome the reality that the data indicating retail customers’ creditworthiness such as payment behaviour, obligations and financial footprints are widely spread across numerous unconnected institutions and service providers. This fragmentation forces them to accept elevated credit risk from incomplete data as under the expectation of promoting financial inclusion, DBs should not replicate traditional banks’ stringent credit assessment.
DBs currently access credit reports through the HKMA's Credit Data Smart program, which pulls information from credit reference agencies. But these reports only cover basic information like repayment records, bankruptcy records, and credit scores. They leave out what is called "alternative data", such as utility payment patterns, telecommunication billing behaviour and payment transaction histories. For many underbanked individuals who have little formal credit history, this alternative data could be exactly what tells a lender whether they are reliable or not.
The Proposed Solution: A Blockchain-based Credit Data Sharing Framework
This article proposes a framework that allows DBs to securely share and access retail credit data from multiple sources using blockchain technology ("the Framework"). Here is how it would work in practice.
First, customers would give explicit consent before any of their data is accessed. They would be told clearly what data is being looked at, who is looking at it, and why. They can also withdraw consent at any time.
Second, blockchain technology is used to keep an unchangeable record of every data request and access. Importantly, no personal data is actually stored on the blockchain itself. The blockchain just keeps track of who accessed what and when, acting as an audit trail. The actual data stays with whoever originally holds it, such as the utility company, the bank, or the payment platform.
Third, the Framework uses a technology called zero-knowledge proof ("ZKP"). This allows a lender to verify that a customer meets certain criteria, for example, that they have paid their utility bills on time consistently, without ever seeing the actual bills or personal details. It is a way of proving something is true without revealing the underlying information.
Fourth, the Framework opens the door to alternative data. Utility companies, telecom providers, and payment platforms can all participate as data sources, giving DBs a much fuller picture of a customer's financial behaviour.
It Is Already Being Done — Just Not for Retail Customers
This kind of blockchain-based credit data sharing already exists in Hong Kong, but only for small and medium-sized businesses ("SMEs"). The HKMA launched the Commercial Data Interchange ("CDI") exactly for this purpose. The CDI lets lenders access alternative data about SME borrowers through a blockchain infrastructure, improving the accuracy of credit assessment for businesses.
The Framework simply takes the same idea and applies it to individual retail customers. The HKMA has even signalled interest in connecting with the Land Registry to improve loan assessment for individuals, suggesting regulators are open to expanding this model to the retail sector.
Does It Comply with Hong Kong's Privacy Law?
Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") governs how personal data can be collected and used. Since the Framework deals with individual retail customers, it must comply fully with the PDPO's data protection principles ("DPPs").
The key requirements could be met in the following ways. On consent, customers must give clear and voluntary consent before their data is accessed, and this consent is recorded on the blockchain. On data minimization, thanks to ZKP, only the minimum necessary information is shared, and raw personal data is never transmitted. eliminating the need to retrieve the full datasets of retail individuals that would otherwise risk breaching the necessity and proportionality requirements. On security, because no raw data travels between parties, the risk of data leaks is reduced significantly. Last but not least, on transparency, participating institutions are required to publish their data practices publicly.
The Framework itself does not store any personal data, so the obligations around data retention and access rights remain with the original data holders.
What This Means for Financial Inclusion
Better data leads to better lending decisions, which directly supports financial inclusion. When DBs can assess risk more accurately, they are less likely to suffer losses, which means they can keep serving underbanked customers rather than pulling back.
The Framework also works as what can be called a borrower discipline device. Because all participating institutions share the same network, a customer's poor repayment behaviour with one institution will be visible to others when they apply for credit elsewhere. This gives borrowers a real incentive to repay on time, which in turn reduces defaults across the board and helps DBs extend credit to more people with greater confidence.
Final Thoughts
Hong Kong's DBs were built to serve those left behind by traditional banks. But high loan losses are putting that mission at risk. The Framework offers a practical, privacy-compliant, and technically feasible way to fix the underlying problem, fragmented and incomplete credit data. With regulatory precedent already set by the CDI and a supportive FinTech policy environment, the conditions are in place.
Ultimately, the Framework should be viewed as a sustainable financial inclusion strategy that aligns the commercial viability of DBs with their policy role in promoting financial inclusion, rather than a mere technological enhancement.