Home
/
Regulatory news
/
Compliance guidelines
/

Can you force an exchange to delete your data?

Users Push Back Against Crypto Exchange Data Retention | Calls for Transparency Grow

By

Nina Duval

May 27, 2026, 06:21 AM

Updated

May 27, 2026, 12:25 PM

3 minutes estimated to read

A concerned user looks at a laptop screen showing a warning about KYC data retention after account closure
popular

A rising group of people is voicing concerns about crypto exchanges storing their sensitive personal information even after account deactivation. The issue of data retention rights has captured attention, particularly regarding compliance with regulatory oversight, as many are uneasy about their KYC data lingering in the hands of exchanges.

Background on Data Retention

Recently, one user reported attempting to close their account on an unused exchange. Although the account closure was confirmed, the exchange insisted they must keep Know Your Customer (KYC) data for several years per regulatory requirements. This situation has fueled worries over privacy and data control.

What People Are Saying

Commenters on various user boards are actively discussing the legality of data retention policies. One comment reads, "Its all legal. They're even keeping records of all the wallets youโ€™ve used, just in case you're trying to dodge taxes!" Another chimed in, stating, "The retention is legal, but banks should be more open about what's held and for how long."

In another remark, someone noted, "Yes, it is legal that they hold your data for a period. If law enforcement, like the tax office, comes asking for transaction info, theyโ€™d be in hot water if they had deleted it." This shows that while legal obligations exist, clarity and transparency on what data is retained remains a significant concern.

Main Themes Emerging

  • Legal Justifications: Users agree that exchanges are legally required to hold KYC data to comply with Anti-Money Laundering (AML) laws and other regulations.

  • Transparency Issues: Many users highlight frustration over a lack of information regarding what data is kept and how long it will be stored. "The lack of transparency is what needs to be challenged," stated a contributor.

  • Consumer Rights and Actions: While users in the EU and UK can leverage GDPR to request data visibility and deletions, the practical application of these rights seems complicated and under-communicated by many exchanges.

"File a complaint with your local data protection authority if you believe they're keeping more than legally necessary," advised one user.

Key Considerations

  • Retention Legality: Exchanges must explain why they keep KYC data for specific lengths of time.

  • Scope of Retained Data: Users can contest unnecessary data retention.

  • Practical Next Steps: People in GDPR areas can submit Subject Access Requests for clarity on stored data and applicable laws.

As the landscape shifts, the struggle for balance between regulatory compliance and personal privacy keeps growing. Can crypto exchanges meet emerging expectations without losing the trust of their customers?

Consequences of Current Policies

Through user commentary, a pattern suggests that many individuals feel trapped by current policies. The discontent over the unclear retention duration points to a potential demand for better communication. A person noted, "If they had deleted my info, it could have led them into trouble with the law," highlighting the tension between consumer rights and compliance.

Reflections from Other Industries

Looking at how social media platforms have evolved, they once faced intense backlash for data mismanagement post-account deletion. Similar to past experiences, crypto exchanges may need to revise their standard practices to align with user expectations and regulatory mandates. The saga of user privacy continues to unfold, illustrating how consumer demand can drive industry improvements.

Keep watching this space as regulations evolve and more details emerge regarding crypto data retention practices.

Key Insights

  • ๐Ÿ“œ Many exchanges must retain KYC data for compliance.

  • ๐Ÿ”’ Users have rights to request deletion of unnecessary data held.

  • โš–๏ธ Those in GDPR regions can challenge retention duration and scope.