6 ms·
Worrying yes, but i think it's required. KYC laws in the US mandate a 5 year retention AFTER the account is closed: https://bsaaml.ffiec.gov/manual/Appendices/
by joewadcan 4y ago
Worrying yes, but i think it's required. KYC laws in the US mandate a 5 year retention AFTER the account is closed:
https://bsaaml.ffiec.gov/manual/Appendices/17 https://bsaaml.ffiec.gov/manual/Appendices/17
> A bank must retain the identifying information about a customer for a period of five years after the date the account is closed, or in the case of credit card accounts, five years after the account becomes closed or dormant.
- mike_d 4y agoKYC as well as account recovery. If you ask someone to provide photo ID or a verification photo to remove a 2FA token for example, having a previously supplied photo of the same ID helps a lot.
- DamnYuppie 4y agoI have a Coinbase account and when they asked for ID they referenced the KYC regulations as the reason. https://www.investopedia.com/terms/k/knowyourclient.asp https://www.investopedia.com/terms/k/knowyourclient.asp
- jstx1 4y agoHow do those US KYC laws interact with EU's GDPR?
- mytailorisrich 4y agoGDPR only say not to collect more data than needed and then not to keep them longer than needed. If you have a legal obligation to collect specific data and to keep them for a specific duration the GDPR are fine with that. There are similar KYC regulations and data retention laws in Europe.
- mike_d 4y agoFor a US based company? American laws win every time.
- deleted 4y ago[deleted]
- jstx1 4y agoNot how it works at all - they're serving EU customers which is what matters to GDPR. Apparently the two aren't in conflict like some other comments pointed out, but it has nothing to do with Coinbase being an American company.
- ronsor 4y agoGDPR has exceptions for mandatory retention due to financial regulations
- voxic11 4y agoThe GDPR right to erasure doesn't apply when there is a legal obligation to keep the data. > The General Data Protection Regulation (GDPR) gives individuals the right to ask for their data to be deleted and organisations do have an obligation to do so, except in the following cases: ... > there is a legal obligation to keep that data; https://commission.europa.eu/law/law-topic/data-protection/reform/rules-business-and-organisations/dealing-citizens/do-we-always-have-delete-personal-data-if-person-asks_en https://commission.europa.eu/law/law-topic/data-protection/r...