The Bitcoin Legal Commons ← All resources

What may be collected at onboarding

Read the lists below as a range, not as a description of any one firm

No single platform collects everything set out here. What is gathered differs substantially between firms, between jurisdictions, and according to the risk rating attached to a particular account, and identity verification is frequently carried out by a third-party provider with its own separate retention policy. Treat each item as something that may be collected, and read the privacy policy of the specific firm for what it actually does.

Far more than the documents you consciously upload.

What you provide

What is collected without you providing it

The item people underestimate

Withdrawal addresses. Once an exchange records an address as yours, it has linked your verified identity to a position on a permanent public ledger. Everything that address has ever done, and everything it does afterwards, is publicly visible and now attributable. This is the most consequential single piece of data in the list, and it is collected silently.

Where it goes

The exchange is rarely the only holder. A typical verification touches several parties.

Identity verification vendors

Most exchanges do not verify documents themselves. They use specialist providers who receive your document images and biometric data directly. These vendors serve many clients, and your data sits in their systems under their retention policy, governed by their contract with the exchange.

Blockchain analytics firms

Exchanges use analytics providers to screen addresses and transactions. The exact flow of data depends on the arrangement, but the effect is that your on-chain activity is assessed against commercial risk-scoring databases built from many sources.

Sanctions and PEP screening providers

Your name and details are checked against sanctions lists, politically exposed persons databases and adverse media, at onboarding and then periodically.

Other regulated firms, under the travel rule

When you send coins to another regulated business, identifying information about you may be transmitted to that business, which then retains it, even though you never had an account there. Whether it happens on a given transfer depends on the applicable rules, the value involved and the thresholds in force, which differ by jurisdiction and are not uniform. The point is that it can happen without any action by you, not that it always does. See the travel rule for what governs this.

Government authorities

Through several distinct channels: suspicious activity reports filed by the exchange, direct requests and subpoenas from law enforcement, tax reporting obligations, and automatic exchange of information regimes between tax authorities.

Corporate affiliates and successors

Group companies, and whoever acquires the business. When an exchange is sold, the customer database is generally part of the sale.

How long it is kept

Longer than the relationship. Anti-money laundering law in most jurisdictions requires records to be retained for a defined minimum period after the relationship ends, and longer where national rules require it or where an investigation is open. The period is set by your own jurisdiction, and the firm's privacy policy will state the one it applies.

Two consequences follow, and they surprise people.

Closing your account does not delete your data. It usually starts the retention clock rather than triggering erasure.

Deletion requests are lawfully refused for this material. Data protection rights generally give way to a legal obligation to retain. An exchange declining to erase your KYC file is usually complying with the law rather than ignoring your rights.

The breach problem

This data set is unusually dangerous if it escapes: a verified identity document, a home address, a face, and evidence of crypto holdings, in one record.

Two exposures follow from any breach, and they are different in kind.

Identity fraud, which is bad but has established remedies. Documents can be reissued, credit can be frozen, banks have processes.

Physical targeting, which does not. A leaked record showing a named individual at a known address holding a bearer asset is a different category of harm, and it is the reason coercive robbery of crypto holders has become a recognised category of crime rather than a curiosity.

You cannot undo this exposure once it happens, and the retention rules mean the data persists for years after you stop using the platform.

Assume permanence

Treat every KYC submission as permanent and potentially public at some future point. Not because any particular exchange is careless, but because the data will exist across multiple organisations for years, and the aggregate probability across all of them over a decade is not small.

What rights you actually have

This depends entirely on where you are. In the EU, the UK and jurisdictions with comparable frameworks, individuals generally have some version of the following. Availability elsewhere varies widely.

RightWhat it doesThe limit
AccessObtain a copy of the personal data held about youMaterial relating to suspicious activity reporting and crime prevention is typically exempt
RectificationCorrect inaccurate dataGenerally works, and worth using
ErasureHave data deletedDefeated by the legal retention obligation for KYC records
PortabilityReceive your data in a machine-readable formatNarrower than it looks: it covers data you provided, not the firm's own analysis or risk scoring, and under the European regime it applies only where the processing rests on consent or on a contract. Records kept to satisfy a legal obligation, which is most of a KYC file, fall outside it entirely
ObjectObject to certain processingDoes not apply where processing is required by law
InformationBe told who receives your data and where it goesUsually answered by pointing at the privacy policy

The access right is the most useful in practice. It costs little, it is usually free, and it reveals which vendors hold your data and what the platform has recorded about you. Expect the response to be partial for the reasons above.

Practical steps that actually reduce exposure

None of this is about avoiding verification, which is a legal requirement for regulated platforms in most places. It is about limiting how much of your position is concentrated in one record.

The honest summary

Verification is not optional on regulated platforms, and the data collected is broader than the documents you upload, is shared with more parties than you interacted with, and persists for years after you leave.

That is not a scandal, it is how the regulatory framework is designed to work. But it is worth knowing precisely, because the decisions that follow, how many platforms to use, how much to leave on them, and what to understand about the addresses you withdraw to, are yours to make and are much easier to make well before you verify than after.

Why this page has no dates or figures

Everything here is written to stay true. It explains how the machinery works rather than what today's numbers are, because thresholds, rates and deadlines change every year and a stale legal page is worse than no page at all. Where a current figure matters to your decision, this page tells you how to find it rather than guessing on your behalf.

General information, not legal advice. This site does not provide legal advice, and no professional or advisory relationship is created. Data protection rights, retention requirements and the treatment of crypto platforms vary substantially between jurisdictions. What any particular exchange collects, shares and retains is set out in its own privacy policy and terms, which govern your relationship with it and which you should read directly. Consult a qualified lawyer licensed where you live regarding your specific rights.