TL;DR
- That regulated crypto businesses identify and verify their customers, keep records, monitor activity and report suspicion, under anti-money-laundering law that applies the standards written for banks to "virtual asset service providers". The international standard comes from the Financial Action Task Force and is addressed to countries; the duties that bind firms and individuals, with their thresholds and dates, come from each jurisdiction's own law and supervisors' rules, and they differ.
- The identity file collected at verification (documents, address, sometimes biometrics, source-of-funds answers), then the activity record: deposits, trades, withdrawals, login and device data, and the on-chain addresses used with the venue. The file grows as you use the account and is retained for the period the venue's regime requires.
- Different recipients for different purposes: the venue's compliance staff and contracted providers to run the service and meet legal duties; financial intelligence units, tax authorities and law enforcement under statutory reporting or legal process; and, in the documented breach record, criminals. Which sharing is lawful depends on jurisdiction and on the stated purpose of the processing.
- A verified venue is a point where your identity meets the public ledger, and the link persists in the venue's records and, potentially, in analytics clusters. Lawful hygiene means knowing which regime applies, answering what it requires accurately and in full, using the data rights the applicable law grants, keeping venue-facing addresses separate from long-term holding addresses, and treating breach history as counterparty risk. Each habit limits exposure and leaves every legal obligation in place.
In einem Block
Know-your-customer (KYC) is an anti-money-laundering control that requires regulated financial businesses to identify and verify their customers; where a jurisdiction's law covers crypto businesses, it applies to exchanges alongside record-keeping, transaction monitoring and suspicious-activity reporting. Each jurisdiction sets its own duties, thresholds and start dates.
What do KYC and AML rules actually require?
Schnelle Antwort
That regulated crypto businesses identify and verify their customers, keep records, monitor activity and report suspicion, under anti-money-laundering law that applies the standards written for banks to "virtual asset service providers". The international standard comes from the Financial Action Task Force and is addressed to countries; the duties that bind firms and individuals, with their thresholds and dates, come from each jurisdiction's own law and supervisors' rules, and they differ.
The international standard
Anti-money-laundering (AML) law originates in banking regulation: financial institutions must know their customers, keep records and report suspicious activity. The Financial Action Task Force (FATF), the intergovernmental body that sets the global AML standard, extended those obligations to "virtual asset service providers" (VASPs), its term for exchanges, custodians and similar businesses, and its updated guidance of October 2021 states that VASPs are subject to the same relevant FATF measures that apply to financial institutions and should be licensed or registered (FATF, Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs, 28 October 2021). FATF standards are not law anywhere on their own, and they impose no duties directly on users or on firms. Member jurisdictions implement them through national legislation and supervisory rules, and it is that national law that binds a venue and its customers, with variation in scope, thresholds, timing and enforcement. FATF's Seventh Targeted Update of 16 July 2026 reports progress since its 2025 update and states that "significant gaps remain" in areas including operationalising licensing or registration frameworks and identifying persons or entities conducting VASP activities (FATF, 16 July 2026).
How jurisdictions implement it
In the United States, FinCEN's interpretive guidance of 18 March 2013 treats exchangers and administrators of convertible virtual currency as money transmitters under its Bank Secrecy Act regulations, which brings FinCEN registration, an AML programme, record-keeping and suspicious activity reporting for those businesses (FinCEN, FIN-2013-G001). In the European Union, Regulation (EU) 2023/1113 (Article 38) amended the Anti-Money Laundering Directive, Directive (EU) 2015/849, to make crypto-asset service providers obliged entities from 30 December 2024, and the Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114, Title V) requires those providers to be authorised, with its service-provider rules applying from the same date (EUR-Lex, Regulation (EU) 2023/1113, Articles 38 and 40; ESMA, MiCA interactive rulebook). In the United Kingdom, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 require cryptoasset businesses within their scope to register with the FCA, which has been the AML supervisor for firms carrying on certain cryptoasset activity since 10 January 2020 (FCA, Cryptoassets: our work). That duty is separate from the UK's new authorisation regime under the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026, made on 4 February 2026, for which the FCA said, as of 24 September 2026, that applications would open on 30 September 2026 and which it expects to come into force on 25 October 2027 (FCA, new regime for cryptoasset regulation; FCA, cryptoasset regime policy statements, 30 June 2026). The guide to how stablecoins are regulated around the world covers the licence-first regimes in Asia and the wider timetable by jurisdiction.
In practice a venue in one of these regimes must collect identity information and verify it, screen customers against sanctions and politically-exposed-person lists, assess risk and tier its checks (a document, address and often a selfie for ordinary accounts; source-of-funds evidence for higher-risk or higher-value activity), monitor transactions against patterns, and report suspicious activity to the national financial intelligence unit. The duties are enforced: on 21 November 2023 the US Department of Justice announced that Binance Holdings Limited had pleaded guilty to charges relating to the Bank Secrecy Act, failure to register as a money transmitting business and the International Emergency Economic Powers Act (a US sanctions statute), and had agreed to a total financial penalty of about $4.3bn and to retain an independent compliance monitor for three years (US Department of Justice, 21 November 2023).
Why "no ID" is not a test of regulation
It is tempting to conclude that a venue which does not ask for ID must be operating outside regulation. That inference is not reliable, because the duties differ in at least five ways. First, thresholds: some regimes allow simplified or deferred verification below a monetary limit, or apply the heaviest checks only to certain activities. Second, exemptions: a business that only provides software, or that never takes custody, may fall outside a regime's definition of a service provider, and FATF's own July 2026 update notes that jurisdictions still struggle to identify which entities are conducting VASP activity (FATF, Seventh Targeted Update, 16 July 2026). Third, timing: MiCA's service-provider rules applied from 30 December 2024, the UK's new authorisation regime is expected to come into force on 25 October 2027 while its Money Laundering Regulations registration already applies, and other jurisdictions are at different stages; a venue may be operating under a transitional arrangement that its regime provides. Fourth, jurisdiction: a venue may be regulated where it is established and unregulated where you are, or the reverse. Fifth, a venue may verify identity because a bank, card network or payment partner requires it, which reflects the terms of its banking relationships; its licence is a separate question. These five points explain why an ID check, or its absence, says little about a venue's status. They describe how regimes are drafted and offer no route around verification: arranging activity to avoid identification or to stay under a threshold is the compliance-avoidance case set out later in this guide, and in some jurisdictions it is an offence.
The reverse inference is also weak: asking for ID does not prove a venue is authorised. FATF's July 2026 update reports significant gaps in operationalising licensing and registration frameworks and the continued presence of offshore VASPs operating without oversight (FATF, 16 July 2026). The reliable questions are the ones the exchange safety pillar asks: which regime covers the venue, for which activities, under which named supervisor, from what date, and whether that register entry can be checked. Where a venue verifies nobody, the same questions apply, and their answers are the test.
What does a verified account actually accumulate?
Schnelle Antwort
The identity file collected at verification (documents, address, sometimes biometrics, source-of-funds answers), then the activity record: deposits, trades, withdrawals, login and device data, and the on-chain addresses used with the venue. The file grows as you use the account and is retained for the period the venue's regime requires.
The identity layer
Verification visibly collects a government document, a proof of address, often a liveness-checked selfie, and, for larger or higher-risk activity, questions about occupation, wealth and the source of deposited funds. Regimes set minimum retention periods for this material. In the EU, obliged entities must keep records for at least five years after the business relationship ends (Directive (EU) 2015/849, Article 40(1)); in the UK, the Money Laundering Regulations 2017 set five years from the end of the relationship or the completion of an occasional transaction, and do not require transaction records to be kept for more than ten years (regulations 40(3) and 40(4)); in the US, records required under FinCEN's rules are kept for five years (31 CFR 1010.430(d)). The file therefore outlives the account.
The activity layer
The quieter accumulation is the activity record: fiat deposits with their bank details, trades, withdrawals with their destination addresses, crypto deposits with their source addresses, plus the logins, devices and locations around them. Many venues also contract chain-analysis providers to screen deposits and withdrawals, and those providers cluster addresses across the public ledger. A withdrawal to an address you provided tells the venue that you gave it that address; clustering may then associate that address with others.
What the venue's record does not establish is ownership. A withdrawal address can belong to a friend, a merchant, another exchange, a contract or a wallet you control; the venue's own data shows only that you instructed a transfer to it. That is why EU law adds a separate duty: for transfers above EUR 1,000 to or from a self-hosted address, the service provider must take measures to assess whether the address is owned or controlled by its customer, which some venues do by asking the customer to prove control, for example by signing a message or making a small transfer from the address (Regulation (EU) 2023/1113, Articles 14(5) and 16(2)). Absent such a check, "known to the venue" and "owned by the customer" are different facts, and the venue's file records the first. The on-chain privacy guide covers how clustering works and where it breaks.
The travel rule layer
FATF Recommendation 16, the "travel rule" (defined with KYC, AML and VASP in the crypto glossary), requires financial institutions to send identifying information about the originator and beneficiary along with a transfer, and FATF's 2021 guidance applies it to transfers between VASPs (FATF, 28 October 2021). Each jurisdiction has set its own scope:
- European Union: Regulation (EU) 2023/1113 requires the originator's service provider to send the originator's name, distributed ledger address or account number, and either address, identity document number and customer number or date and place of birth, together with the beneficiary's name and address or account number, with every transfer of crypto-assets regardless of amount, applying from 30 December 2024 (EUR-Lex, Regulation (EU) 2023/1113, Articles 14 and 40).
- United States: FinCEN's recordkeeping and travel rule binds banks and other financial institutions, including money transmitters, for transmittals of funds of $3,000 or more, and FinCEN's 2019 guidance confirms that transmittals in convertible virtual currency "qualify as transmittals of funds, and thus may fall within the Funds Travel Rule" (31 CFR 1010.410(e) and (f); FinCEN, FIN-2019-G001, 9 May 2019).
- United Kingdom: under Part 7A of the Money Laundering Regulations 2017, cryptoasset businesses have had to collect, verify and share travel-rule information since 1 September 2023, with separate FCA expectations for transfers to or from jurisdictions that have not implemented the rule (FCA, statement of 17 August 2023, updated 6 February 2026).
The practical consequence is that a transfer between two regulated venues carries your identity from one file into the other, and the receiving venue can attach your name to the incoming funds before you have told it anything. FATF's July 2026 update reports progress on implementing the travel rule and states that significant gaps in implementation remain across its global network, so what actually travels depends on the law in both venues' jurisdictions (FATF, 16 July 2026).

Who can see your file, and on what basis?
Schnelle Antwort
Different recipients for different purposes: the venue's compliance staff and contracted providers to run the service and meet legal duties; financial intelligence units, tax authorities and law enforcement under statutory reporting or legal process; and, in the documented breach record, criminals. Which sharing is lawful depends on jurisdiction and on the stated purpose of the processing.
Sharing by purpose and jurisdiction
In the EU, the General Data Protection Regulation (Regulation (EU) 2016/679, applying since 25 May 2018), and in the UK its domestic counterpart, the UK GDPR, require controllers to collect personal data for specified, explicit purposes and to process it on a lawful basis, and to state those purposes in the information they give customers, usually a privacy notice (GDPR, Articles 5(1)(b), 6 and 13). In practice three bases do most of the work. Processing needed to perform the contract covers running the account. Processing needed to comply with a legal obligation covers AML verification, record retention, suspicious activity reports to the financial intelligence unit and tax reporting. Processing in the venue's legitimate interests covers things like fraud analytics and some marketing; Article 21 gives the customer a right to object to such processing, which the venue may continue only if it demonstrates compelling legitimate grounds or needs the data for legal claims, and a right to object to direct marketing at any time. Article 15 gives a right of access to the data held and to the recipients or categories of recipient to whom it has been or will be disclosed, and Article 23 allows national law to restrict these rights for purposes that include the prevention, investigation and prosecution of criminal offences. Outside the EU and UK the rules differ; in the United States, what a venue may share is set by a mix of federal and state rules and the venue's own privacy notice, which this guide does not summarise.
Statutory sharing is the part customers do not see. Suspicious activity reports go to the financial intelligence unit, and the law keeps them from the customer: in the EU, Member States must prohibit disclosing to the customer that a report has been made (Directive (EU) 2015/849, Article 39(1)). Tax reporting follows the same pattern of standard and implementation. The OECD's Crypto-Asset Reporting Framework is an international standard for automatic exchange of crypto-asset information between tax authorities (OECD, October 2024); it binds a venue only once a jurisdiction writes it into law. In the EU, Directive (EU) 2023/2226 (DAC8) requires Member States to apply, from 1 January 2026, rules obliging reporting crypto-asset service providers to report on their users to tax authorities (EUR-Lex, DAC8, Articles 2 and 8ad). Reporting by a venue leaves an individual's own tax position to the law of the jurisdiction concerned; tax treatment differs by jurisdiction, and professional advice applies to individual circumstances. Law enforcement access runs through subpoenas, court orders and information requests, whose thresholds depend on the jurisdiction.
What has gone wrong
The breach record is the reason the data practices of a venue belong in a counterparty assessment. Two documented cases show the pattern; the first is also logged in the Wallet Vulnerability Ledger. In 2020 an unauthorised party gained access to part of the hardware-wallet maker Ledger's e-commerce and marketing database via a third party's API key, according to Ledger. Ledger said the full contents of the stolen databases were made public on a forum on 20 December 2020, including more than one million email addresses and about 272,000 customer records with name, postal address and phone number, that no payment information or passwords were involved, and that criminals were attacking its customers with phishing attempts (Ledger, statements of 29 July 2020 and 13 January 2021). On 15 May 2025 Coinbase disclosed that criminals had bribed and recruited a group of overseas support agents who abused their access to its customer support systems to take account data, including names, addresses, phone numbers, email addresses, the last four digits of social security numbers, masked bank account details, government ID images, and account balance and transaction history snapshots, for less than 1 percent of monthly transacting users. Coinbase said login credentials, private keys and the ability to move customer funds were not affected, and that it would reimburse customers who were tricked into sending funds to the attacker through social engineering, after a review of the facts (Coinbase, 15 May 2025). Contact after a breach from someone claiming to represent a venue, or from a service offering to recover lost funds for a fee, fits a known follow-on scam pattern; reports go to the police or to national reporting services such as the FBI's IC3 in the US, Report Fraud (formerly Action Fraud) in England, Wales and Northern Ireland, and Police Scotland on 101 in Scotland, and a report does not guarantee recovery. The threats, scams and privacy guides, including the guide to physical security and coercion, cover the risk that follows when names, addresses and balance information circulate together, and the guide to responding to a hack or theft covers the steps after a leak. A venue's disclosed breach history is the identity-side equivalent of the solvency history recorded in the Exchange Failure Index, and the exchange safety pillar's assessment treats it that way.
What does this mean for privacy, and what is lawful hygiene?
Schnelle Antwort
A verified venue is a point where your identity meets the public ledger, and the link persists in the venue's records and, potentially, in analytics clusters. Lawful hygiene means knowing which regime applies, answering what it requires accurately and in full, using the data rights the applicable law grants, keeping venue-facing addresses separate from long-term holding addresses, and treating breach history as counterparty risk. Each habit limits exposure and leaves every legal obligation in place.
Privacy hygiene versus avoiding compliance
The two are easy to blur. Avoiding compliance means structuring activity to defeat a legal duty: splitting transfers to stay under a reporting threshold, giving false information at verification, using another person's identity, or using a venue precisely because it will not report. Depending on the jurisdiction, those acts can be criminal offences, and the venue's monitoring is designed to detect them. In the United States, for example, 31 U.S.C. 5324 prohibits any person from structuring, or assisting in structuring, transactions with domestic financial institutions to evade specified federal reporting requirements. Privacy hygiene means limiting what is exposed within the rules: reading the privacy notice, leaving genuinely optional fields blank, exercising access and objection rights, and managing your own addresses so that a single venue record does not map your whole holding. It never involves incomplete or false answers to required questions, and it leaves unchanged what a venue must report and what an individual must declare to a tax authority. Compliance avoidance aims at what the authorities can know; privacy hygiene limits what a breach, an analytics provider or a marketing partner can learn, and authorities keep the access the law gives them.
The habits
Knowing the regime comes first: which supervisor, which activities, which data-protection law, where the data is stored, and what the published retention period is. Providing what the regime requires comes second: required answers are given accurately and in full, venues may ask for more than the legal minimum under their own risk policies, and fields marked optional are left to the customer. Using data rights comes third: in the EU and UK, access requests show what is held and the recipients or categories of recipient it has been disclosed to, within the restrictions national law sets, and objection rights cover legitimate-interest processing and direct marketing. Address separation comes fourth: because a venue's record links your identity to the addresses you use with it, the tiering in the wallet security pillar acquires a privacy dimension, with addresses that touch venues kept apart from long-term holding addresses and address reuse avoided, as the on-chain privacy guide explains. Separation limits what a leaked venue record reveals, and leaves unchanged what the venue records about its own customer's transfers, what it reports, and an individual's tax reporting duties. Reading breach history comes fifth: disclosed incidents, regulatory penalties for AML failures and the jurisdiction of data storage are public facts that belong beside custody and solvency in the pillar's assessment.
Self-custody wallet software does not carry out venue verification, and some peer-to-peer arrangements and decentralised protocols collect none, although whether a regime treats a given arrangement, or the people operating it, as within its scope differs by jurisdiction and can change; the guides to DeFi and crypto wallets describe what those arrangements lack, including segregation duties, a supervisor and recourse, and the key-loss risk that falls on the holder. The individual's own legal duties, including tax reporting, are the same whichever arrangement holds the asset, and using any arrangement to disguise activity that a regime requires to be reported is the compliance-avoidance case above, whatever the technology. This guide describes these arrangements without recommending them.

Frequently asked questions
Does every way of using crypto involve KYC?
This answer describes where verification duties fall, for understanding only; it is not a guide to avoiding them. Wallet software that only lets a person hold their own keys does not carry out venue verification, and the rules around it still apply. Where a business that exchanges or holds crypto for customers falls within a regime's scope, as crypto-asset service providers do in the EU under Directive (EU) 2015/849 as amended from 30 December 2024, it must verify customers whatever interface it offers (Regulation (EU) 2023/1113, Article 38). An individual's own legal duties, such as declaring taxable gains where a tax authority requires it, do not depend on whether anyone verified their identity. The DeFi guide and the exchange safety pillar describe what arrangements without a verified venue lack, including a supervisor and recourse.
If a crypto exchange does not ask for ID, is it unregulated?
Not by itself, and the practical check is a public register. Where a regime keeps one, an entry naming the firm, the activities covered and the supervisor answers the question for that jurisdiction on the date it is read. In the EU, ESMA publishes an interim MiCA register that includes authorised crypto-asset service providers, which it says it updates weekly (ESMA, Markets in Crypto-Assets Regulation page, accessed 24 September 2026). A register entry records authorisation status only; a venue's solvency and custody practices are separate questions, which the exchange safety pillar covers.
Do crypto exchanges report to tax authorities?
Where domestic law requires it. The OECD's Crypto-Asset Reporting Framework is a standard that binds a venue only once a jurisdiction implements it in its own law. In the EU, Directive (EU) 2023/2226 (DAC8) requires Member States to apply, from 1 January 2026, rules under which reporting crypto-asset service providers report on their users (EUR-Lex, DAC8). The venue's report and the user's own tax position are separate matters: the first is the venue's duty, and the second is set by the tax law of the user's jurisdiction. Tax treatment differs by jurisdiction, and professional advice applies to individual circumstances.
Does an exchange know my wallet address is mine?
It knows that its customer instructed a transfer to that address. A worked example from EU law shows where ownership comes in. Take two withdrawals from an EU venue to a self-hosted address, one worth EUR 800 and one worth EUR 1,200. For both, the venue must obtain and hold the originator and beneficiary information and ensure the transfer can be individually identified. Only the second, above EUR 1,000, adds a duty to take adequate measures to assess whether the address is owned or controlled by the customer (Regulation (EU) 2023/1113, Article 14(5)). The example shows how the regulation is written; venues apply their own risk-based checks on top of it, and deliberately arranging transfers around a threshold is the kind of pattern their monitoring is designed to detect. Chain-analysis clustering may then associate the address with others, as the on-chain privacy guide explains.
Why does a crypto exchange ask where my money came from?
Source-of-funds checks are part of risk-based due diligence, and a regime's thresholds or risk indicators decide when they apply. The law also sets what happens when due diligence cannot be completed. In the UK, regulation 31 of the Money Laundering Regulations 2017 says a firm that cannot apply customer due diligence measures must not carry out transactions or establish a business relationship with the customer, must terminate an existing relationship, and must consider whether a disclosure is required under the Proceeds of Crime Act 2002 or the Terrorism Act 2000. The documents requested, such as bank statements, payslips or a sale contract, are set by each venue's own procedures.
Can I ask a crypto exchange to delete my KYC data?
A request can be made, and the law limits what it achieves. Under the GDPR, the right to erasure does not apply to the extent processing is necessary to comply with a legal obligation (Article 17(3)(b)), and AML law requires records to be kept, in the EU for at least five years after the business relationship ends, with deletion due once the retention period expires unless national law provides otherwise (Directive (EU) 2015/849, Article 40(1)). Data held for other purposes, such as marketing, falls outside that obligation, and an access request under Article 15 shows what is held.
Sources and further reading
- Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers. FATF, 28 October 2021. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-rba-virtual-assets-2021.html (accessed 23 September 2026)
- Seventh Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs. FATF, 16 July 2026. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/targeted-updated-virtualassets-vasps-2026.html (accessed 23 September 2026)
- Application of FinCEN's Regulations to Persons Administering, Exchanging, or Using Virtual Currencies (FIN-2013-G001). FinCEN, 18 March 2013. https://www.fincen.gov/resources/statutes-regulations/guidance/application-fincens-regulations-persons-administering (accessed 23 September 2026)
- Application of FinCEN's Regulations to Certain Business Models Involving Convertible Virtual Currencies (FIN-2019-G001). FinCEN, 9 May 2019. https://www.fincen.gov/sites/default/files/2019-05/FinCEN%20Guidance%20CVC%20FINAL%20508.pdf (accessed 23 September 2026)
- 31 CFR 1010.410, Records to be made and retained by financial institutions (recordkeeping and travel rule). eCFR, current. https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-D/section-1010.410 (accessed 23 September 2026)
- Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets. EUR-Lex, 31 May 2023. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1113 (accessed 23 September 2026)
- Markets in Crypto-Assets Regulation (EU) 2023/1114, interactive single rulebook. ESMA, current. https://www.esma.europa.eu/publications-and-data/interactive-single-rulebook/mica (accessed 23 September 2026)
- Cryptoassets: our work. FCA, current. https://www.fca.org.uk/firms/cryptoassets (accessed 24 September 2026)
- New regime for cryptoasset regulation. FCA, current. https://www.fca.org.uk/firms/new-regime-cryptoasset-regulation (accessed 24 September 2026)
- FCA sets out expectations for UK cryptoasset businesses complying with the Travel Rule. FCA, 17 August 2023, updated 6 February 2026. https://www.fca.org.uk/news/statements/fca-sets-out-expectations-uk-cryptoasset-businesses-complying-travel-rule (accessed 24 September 2026)
- Cryptoasset regime: policy statements. FCA, 30 June 2026. https://www.fca.org.uk/publications/policy-statements/cryptoasset-regime (accessed 24 September 2026)
- The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, regulation 31. legislation.gov.uk, current. https://www.legislation.gov.uk/uksi/2017/692/regulation/31 (accessed 24 September 2026)
- The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, regulation 40. legislation.gov.uk, current. https://www.legislation.gov.uk/uksi/2017/692/regulation/40 (accessed 24 September 2026)
- Directive (EU) 2015/849 (Anti-Money Laundering Directive), consolidated text, Articles 39 and 40. EUR-Lex, consolidated 9 July 2024. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02015L0849-20240709 (accessed 24 September 2026)
- 31 CFR 1010.430, Nature of records and retention period. eCFR, current. https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-D/section-1010.430 (accessed 24 September 2026)
- 31 U.S.C. 5324, Structuring transactions to evade reporting requirement prohibited. Office of the Law Revision Counsel, current. https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title31-section5324&num=0&edition=prelim (accessed 24 September 2026)
- Markets in Crypto-Assets Regulation (MiCA), including the interim MiCA register. ESMA, current. https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/markets-crypto-assets-regulation-mica (accessed 24 September 2026)
- Binance and CEO Plead Guilty to Federal Charges in $4B Resolution. US Department of Justice, 21 November 2023. https://www.justice.gov/opa/pr/binance-and-ceo-plead-guilty-federal-charges-4b-resolution (accessed 23 September 2026)
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 5, 6, 13, 15, 17, 21 and 23. EUR-Lex, 27 April 2016. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679 (accessed 23 September 2026)
- Council Directive (EU) 2023/2226 amending Directive 2011/16/EU on administrative cooperation in the field of taxation (DAC8). EUR-Lex, 17 October 2023. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023L2226 (accessed 24 September 2026)
- Crypto-Asset Reporting Framework and amended Common Reporting Standard: OECD releases IT format and interpretative guidance. OECD, October 2024. https://www.oecd.org/en/about/news/announcements/2024/10/crypto-asset-reporting-framework-and-amended-common-reporting-standard-oecd-releases-it-format-for-transmitting-information-and-issues-interpretative-guidance.html (accessed 23 September 2026)
- Addressing the July 2020 e-commerce and marketing data breach. Ledger, 29 July 2020. https://www.ledger.com/addressing-the-july-2020-e-commerce-and-marketing-data-breach (accessed 23 September 2026)
- Update: Efforts to Protect Your Data and Prosecute the Scammers. Ledger, 13 January 2021. https://www.ledger.com/blog/update-efforts-to-protect-your-data-and-prosecute-the-scammers (accessed 23 September 2026)
- Protecting Our Customers: Standing Up to Extortionists. Coinbase, 15 May 2025. https://www.coinbase.com/blog/protecting-our-customers-standing-up-to-extortionists (accessed 23 September 2026)
- Report Fraud service goes live with full public launch in January 2026 (replacement for Action Fraud in England, Wales and Northern Ireland). City of London Police, 4 December 2025. https://www.cityoflondon.police.uk/news/city-of-london/news/2025/december/report-fraud-service-goes-live-with-full-public-launch-in-january-2026/ (accessed 24 September 2026)
Kurzes Quiz: Hat es geklebt?
Ein paar Fragen zur Überprüfung der Grundlagen sind gelandet. Es folgen Antworten mit Erläuterungen und niemand außer Ihrem zukünftigen Portfolio bewertet Sie.
Sie haben ein Quiz zu „Why Do Exchanges Ask for Your ID? KYC and What They Know“ abgeschlossen! Teilen Sie Ihren Erfolg in den sozialen Medien.




