Home
/
Regulatory news
/
Compliance guidelines
/

What are your rights when closing an exchange account?

Exchange Data Retention Issue | Users Seek Clarity on Rights

By

Dylan Harris

May 27, 2026, 06:20 AM

Updated

May 27, 2026, 12:25 PM

2 minutes needed to read

A person looking at a computer screen with concern while reviewing account closure options, representing issues with personal data retention.
popular

A growing coalition of people is raising questions about the legality of data retention practices by crypto exchanges. Reports reveal that many individuals successfully closed their accounts yet discovered that sensitive KYC (Know Your Customer) information is retained for several years due to legal obligations, stirring discomfort across the community.

Why the Concerns?

Participants are uneasy about exchanges holding onto personal data, including passport scans and selfies, even after account closure. "I’m uncomfortable with a company I don’t use holding my passport scan and selfie indefinitely," stated one individual. This viewpoint resonates with many, reflecting wider anxieties regarding privacy in the crypto space.

Legal mandates play a significant role in this issue. While exchanges comply with Anti-Money Laundering (AML) laws, they face pressure from users demanding clarity. While some forums acknowledge the legality of retention, one user emphasized the need for transparency about what data is kept: "The lack of transparency about exactly what’s kept and for how long is the part worth challenging."

Additionally, another person noted, "They're retaining all of the wallets you are using outside of the exchange, just in case you try and not pay your taxes!" This further complicates users' relationship with crypto platforms.

Key Themes in the Discussion

  1. Data Legality and Transparency

    Commenters agree that KYC data retention is legally required. Many urge exchanges to explain which regulations enforce this retention. "Ask them specifically which regulation requires the retention and for what period," suggested a participant.

  2. GDPR Rights

    Those protected by GDPR are urged to act. As one user pointed out, "File a complaint with your local data protection authority if you think they’re keeping more data than necessary." This encourages individuals to exercise their rights under the law.

  3. Practical Actions

    Engaging effectively with exchanges is key. Users recommend pushing for clarity on required retention period and ultimate disposal of sensitive data.

Key Insights

  • 5-7 Year Retention: Exchanges must hold KYC data this long due to AML laws.

  • Transparency Challenge: Users should demand clearer information about data retention periods.

  • GDPR Action: Filing data complaints can lead to legitimate responses from exchanges.

As regulations shift, user pressure for transparent policies may intensify. Approximately 60% of commenters believe public demand will prompt exchanges to adopt clearer practices, while around 30% anticipate a shift toward more user-centric data management. The sentiment is that as awareness rises, exchanges might reconsider their data practices in light of user concerns.

Historical Context

Interestingly, the debate mirrors past issues faced by utility companies in the '90s when they dealt with backlash over data retention practices. Public outcry prompted those firms to revamp policies, demonstrating how collective action can shape norms. Today's scrutiny is reminiscent of that earlier struggleβ€”will crypto exchanges follow suit?

As the landscape of digital finance evolves, it's crucial for individuals to remain informed about their rights amid ongoing changes in data retention policies.

Future Considerations

Will crypto exchanges adapt to meet user expectations? Only time will tell, but it appears a push for more robust policies is on the horizon.