Once an exchange verifies your identity, that file does not sit only with the exchange. It typically moves through a compliance vendor, gets checked against public watchlists, and then sits in storage for a legally set minimum period – commonly five years, sometimes longer – regardless of whether you close your account or ask for it to be deleted. That retention floor comes from anti-money-laundering law, not from the exchange’s own preference.
A KYC file is rarely a single document. OneKey’s blog, updated 12 May 2026, breaks a typical profile into layers: a basic identity layer (legal name, date of birth, email, phone), an identity-verification layer (ID scans, a selfie holding the ID, sometimes a liveness video and the facial biometric data extracted from it), an address layer (residential address plus proof-of-address documents), and for higher-risk accounts, a financial layer covering source of funds, occupation and expected trading volume. OneKey also describes an on-chain linkage layer: once a wallet address deposits to or withdraws from a KYC’d exchange, that address can become tied to a real identity inside compliance and analytics systems, according to OneKey.
KYC2020, a compliance vendor whose site describes itself as helping Canadian money-service businesses “stay FINTRAC-ready,” lists its own three roles in that data flow: it acts as a data processor when screening a client’s users, and as a data controller both for people who visit its own site and for the watchlists it builds from public sources – sanctions lists, politically-exposed-person lists, adverse media and corporate registries, per KYC2020’s privacy policy (last updated 28 May 2026).
OneKey’s blog reports that many exchanges outsource identity verification to third-party providers such as Jumio, Onfido and Sumsub rather than handling checks entirely in-house, and notes that users rarely get to review the contracts between an exchange and its verification vendor. ChangeNOW’s AML/KYC policy, updated 17 July 2026, states that verification is handled by “our trusted provider Sumsub,” which stores and processes submitted documents as an independent data processor under GDPR and UK GDPR.
ChangeNOW’s policy also describes a verification link that stays active for three days, after which an unresolved case is reviewed individually. The same policy says ChangeNOW shares data with authorities only on receipt of “a valid and lawful request” that includes a legal basis and verifiable contact details, naming bodies such as Interpol and Europol as examples of who might make one. Kraken’s privacy notice, last updated 5 August 2026, points US residents to a separate US Privacy Notice and lays out categories of data Kraken collects; the excerpt reviewed for this page cuts off before its retention and disclosure clauses, so this page relies on Terms.Law’s separate summary for those specifics rather than Kraken’s notice directly.
Not every platform requires this pipeline at all. Rango Exchange’s Terms of Use, last modified 7 May 2025, describe a different model: instead of collecting identity documents, Rango restricts access by wallet jurisdiction and sanctions-list matching, blocking wallets connected to a list of prohibited territories and to persons on sanctions lists such as those maintained by the UN, the EU or OFAC. That approach may avoid building an identity file the way an exchange’s KYC pipeline does. Rango’s Terms of Use state that a separate Privacy Policy “is incorporated herein by reference,” but that document itself is not part of the evidence reviewed for this page, so this page cannot describe what data Rango actually collects or how long it keeps it.
The retention period is not something an exchange chooses. FlagRight’s compliance guide, published 17 January 2024 and updated 8 July 2026, traces it to FATF Recommendation 11, which requires financial institutions to keep transaction records and customer due-diligence files for at least five years, counted from the end of the business relationship. The US Bank Secrecy Act applies the same five-year floor to customer identification files, according to FlagRight – and OFAC separately extended its own retention requirement for sanctions-related records, such as blocked-property files, from five years to ten years, effective 12 March 2025. Where property remains blocked, FlagRight notes the ten-year clock does not even start until the asset is unblocked, meaning retention can run indefinitely.
In the EU, FlagRight describes a similar five-year floor under the current AML Directive framework, with individual member states allowed to extend it up to ten years – the Netherlands and France apply the five-year minimum, FlagRight reports, while Spain and Luxembourg require ten. That inconsistency is due to disappear on 10 July 2027, when the EU’s new Anti-Money Laundering Regulation (Regulation (EU) 2024/1624, or AMLR) applies a single harmonized rule across the bloc, per FlagRight.
Terms.Law’s comparison of six exchanges – Coinbase, Kraken, Gemini, Crypto.com, Binance.US and OKX – published 7 December 2025, found the same pattern under different wording. Terms.Law describes Kraken as unusually direct about it, reporting that Kraken’s privacy materials refer to retaining key AML records for “around 5+ years” after the business relationship ends. Terms.Law reports that Binance.US ties retention of biometric data directly to the periods required by financial law, and describes other personal data as retained “as long as necessary” for AML, tax, accounting, security and dispute-related purposes. Coinbase’s financial privacy materials, per Terms.Law, describe ongoing retention and sharing as necessary for “everyday business purposes” that continue even after a customer relationship ends, while Crypto.com carves GLBA-covered financial data out of standard state deletion rights. Gemini and OKX, in Terms.Law’s reading, use softer formulations such as “as long as reasonably necessary to provide services and comply with legal obligations,” without naming a specific number of years. Terms.Law’s own analysis concludes all six land on a similar legal floor once AML and tax obligations are factored in. This is Terms.Law’s own qualitative reading of published policies, not an independent measurement of what any exchange actually stores.
Largely, no – not the core file. KYC2020’s own policy states this without softening it: in the table covering its watchlist database, the right to erasure is marked as generally overridden by legal obligations, and the right to rectification is marked not applicable, because the data comes from official public sources, according to KYC2020’s privacy policy. FlagRight’s guide makes the general legal point behind that language: AML retention exists specifically so regulators and investigators can reconstruct financial activity months or years after a transaction. Read alongside KYC2020’s clause, the implication is that a retention rule built for after-the-fact investigation sits awkwardly with a right to immediate erasure – though FlagRight’s guide does not address erasure requests directly. OneKey’s blog advises that GDPR’s right to be forgotten can still apply to the parts of a profile not covered by AML law, but that core identity and transaction records tied to a statutory retention period will survive an erasure request regardless.
People who close an exchange account, or send a GDPR or CCPA deletion request, often assume the file is gone. It usually is not. According to FlagRight’s guide, AML retention periods run from the end of the business relationship, not from the moment a user stops using a platform. KYC2020’s own policy states this override explicitly, marking erasure as generally overridden by legal obligations rather than leaving it implicit.
Everything above is what a company or vendor says it does in its own published policy. None of it is independently audited here, so this page cannot tell a reader what actually happens inside any exchange’s or vendor’s systems – only what each has committed to on paper. Terms.Law’s High/Medium-High/Medium comparison of six exchanges is one outlet’s qualitative reading of public policies, not a measured audit, and should be read as a classification rather than a score. The Kraken source consulted for this page, dated 5 August 2026, includes the notice’s outline of data categories collected but cuts off before its retention and disclosure clauses; this page cannot describe those clauses directly and relies on Terms.Law’s separate summary instead. This page also does not cover data-breach history for any named exchange – OneKey’s blog discusses breach risk only in general terms, with no specific verified incident cited, so no breach claim appears here. Finally, none of the sources let a reader see the actual contract between an exchange and its verification vendor, so how a processor like Sumsub, Jumio or Onfido handles a file in practice – versus what the exchange’s policy merely permits – remains unverifiable from the outside.
Every fact above is attributed to one of these reports. Where they disagree, the article says so.
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect