Tax nakedness & Transparency of Virtual Assets Service Providers

Published: 2026-05-21T09:47:50 · Updated: 2026-05-21T07:48:52Z

Tax nakedness & Transparency of Virtual Assets Service Providers

The Financial Bill 2026, seeks to introduce mandatory reporting of all the virtual-asset users transactions to the commissioner. (A commissioner created by the VASP Act). The regulations & proposed amendment have not stipulated to what extent of data should be reported to the commissioner.

The reporting frequency proposed through the Virtual Assets Service Providers Regulations, was already a burden. Creating a one size fits all mechanism for reporting is unfair. Despite the size and complexities. All players operate at different levels. Banks file monthly, quarterly and annual reporting with each report categorizing what is to be reported. Customer data is not mandated for reporting. However the Central Bank of Kenya has put a uniform threshold of transactions that need to be reported. Through the Proceeds of Crime and Anti Money Laundering Act, banks are mandated to report all transactions suppressing 10,000 usd to the Financial Reporting Centre (FRC).

The proposed amendment to the Virtual Assets Service Providers Act does not provide a limit on the cash transactions that need to be reported to FRC. Unlike for bank transactions. Considering the nature of the Virtual Assets, regulations need to make a provision and reporting procedure for both the end user and the VASPs. A procedure that is recognized while reporting to the commissioner and filing with FRC. img Through the VASP Act and nature of processing data, virtual assets service providers ought to be licensed under the Data Protection Act 2019. As processors and controllers. The VASP Act, mandated virtual assets service providers to store client data for up to 7 years. The Data Protection Act advises the processors and controllers to enforce data minimization, taking into record data that is deemed necessary to access the services. Through a rigorous Know Your Customer Process (KYC), VASPs are able to collect necessary data. Allowing the customer to access their services and product offerings. Section 51 of the DPA, provides for exemption of data privacy, allowing the tax man with probable cause to access your data.

According to the Tax Procedure Act (TPA), Section 59, by notice the tax man can request access to your data. If access is denied, section 60 of the TPA allows for access through a court order. The court may grant them full and free access to any building, place, property, documents, or data storage device for the purposes of administering a tax law. To prevent a fishing expedition, a clear guideline on the extent of data that the tax man needs access to and reasons for warranting access to customer data should be established.

The elephant in the room is; To what extent of data shall the virtual assets service provider file and deem reportable to the commissioner or FRC, without infringing customer data. With the novelty of virtual assets, this presents a unique approach differentiating Decentralized finance (DiFi) and Traditional Finance (TradFi). Without treating one like another while ensuring standards that are promoting fairness and innovation are enforced.

img

For record purposes, the DPA advocates for data minimization, which the virtual assets services providers can share. Blockchain technology enabling virtual assets, is built on transparency and trust. Warranting further data for virtual-asset users or those deemed as reportable users without a warrant and probable cause would be a breach of data privacy.

The big questions lies on: How much data should be reported to the commissioner? To what extent of data should the tax man have access to? What cash transaction limit a should a virtual assets service provider report to the Financial Reporting Center (FRC).