Exchanges close every year. Everyone asks about the coins — almost nobody asks where the KYC file goes. It outlives the company, and you are not told who inherits it.

When a crypto exchange announces it is winding down, the conversation is always about the coins. How long is the withdrawal window, will the last tranche clear, is the team still answering support.
Those are the right first questions. But there is a second one almost nobody asks, and it has a worse answer:
The company is closing. Your identity file is not.
To open the account you handed over a government ID, a selfie taken under instruction, your home address, and — over the life of the account — a complete record of what you traded and where you withdrew it. That bundle was a legal requirement for them to collect.
Here is the uncomfortable part: it is also a legal requirement for them to keep. Anti-money-laundering rules in most jurisdictions require customer records to be retained for around five years after the relationship ends. A business closing its doors does not end that obligation. If anything it sharpens it, because a firm winding up under supervision is being watched on exactly this point.
So the file survives the company by design. The only open question is who is holding it, and that is the question no shutdown notice answers.
A successor or acquirer. In an orderly wind-down the book is often sold, and customer records move with it. You did not choose the buyer, you were not asked, and the privacy policy you originally agreed to was written by a company that no longer exists.
An administrator or liquidator. In an insolvency, records pass to whoever is running the estate — a law firm or insolvency practitioner whose competence at custodying biometric data is not what they were hired for, and whose engagement ends when the estate closes.
The verification vendor, who had it all along. This is the one most people miss. The exchange almost certainly did not do the identity check itself; it used a specialist. That vendor's copy is unaffected by the exchange's closure, sits under a separate retention schedule, and was never mentioned to you. We went through where those files actually live, and what the public record shows when they leak, in what happens to your ID after you upload it.
In all three cases the same thing is true: the set of people who can lose your passport has grown, and your ability to influence any of them has gone to zero.
You would expect a dying company's data to matter less over time. The opposite tends to be true.
A functioning business has a security team, an access review, someone who notices an unusual export. A company in wind-down is shedding exactly those people, often the most employable ones first. Systems stay switched on for the regulator while the staff who watched them leave. Credentials outlive the employees they were issued to.
And this is before anyone attacks anything. The Revolut disclosure this month is the clearest recent illustration: a fully-staffed, well-resourced firm released passports, selfies and complete Bitcoin transaction histories because a request arrived from a convincing address. No breach, no malware — a process that behaved as designed, aimed at the wrong person. Now picture the same request arriving at a skeleton crew whose job ends next month.
Not the file. That is the honest starting point — once uploaded, it is gone from your control permanently, and no shutdown, deletion request or GDPR form reliably claws it back from every copy.
What you can control is how much of your activity is standing behind that file when the company fails.
A non-custodial position does not have a wind-down. There is no operator to fail, no estate to administer, no successor to inherit a file, because no file was created. The contract does not know who you are, so there is nothing to pass on when anything happens to anyone.
That is a narrower claim than it sounds and worth keeping narrow. Self-custody does not make you anonymous — your on-chain history is public and permanently linkable, and the exchange you originally bought through still holds your ID and knows where you sent the funds. It does not remove key-management risk, which is real and unforgiving. What it removes is one specific failure mode: the document bundle in someone else's database, waiting on the worst day of a company you no longer have a relationship with.
If you are reading this because an exchange you use has announced a wind-down, the withdrawal deadline is the urgent thing and you should deal with that first. See the 2026 closures and what they had in common. Then, when the coins are safe, spend ten minutes thinking about the file — because that part has no deadline, and no way back.
Nothing in this article is financial or legal advice. Retention periods vary by jurisdiction; the five-year figure is the common standard under FATF-aligned regimes and is not universal.