What KYC means in crypto, why exchanges require it, what documents you need, how ID, liveness and screening checks work, what happens to your data, and KYC in DeFi.

KYC in crypto means "know your customer": the identity checks a crypto exchange, broker or custodial wallet must run before it lets you trade, deposit or withdraw. In practice you upload a government ID, take a live selfie, and give your address and, increasingly, your tax number, and the platform screens you against sanctions and politically-exposed-person lists. Exchanges do it because anti-money-laundering law requires it, not because they choose to.
This is a plain explainer of what KYC is and how it works: why platforms ask, what they ask for, how the checks run behind the scenes, what happens to your data afterwards, and where DeFi, KYB and no-KYC exchanges fit. If you run a platform and want to compare verification vendors, our separate guide to the best crypto KYC software providers in 2026 covers that.
KYC is the customer-facing part of a broader legal duty called customer due diligence (CDD). Banks have done it for decades. A regulated business has to establish who its customer is, verify that identity against reliable sources, understand what the relationship is for, and keep monitoring it afterwards. In crypto, the "customer" is whoever opens an account with a centralised service: an exchange, a broker app, a custodial wallet, a crypto card issuer or a fiat on-ramp.
The EU's new Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, which applies from 10 July 2027, gives a clear picture of the minimum. For an individual, Article 22 requires at least:
The business must also verify this information, typically against an identity document, and understand the purpose of the relationship. That last part is why exchanges ask about your occupation, expected volumes and source of funds.
Three layers of rules make KYC unavoidable for regulated crypto businesses.
Global standards. The Financial Action Task Force (FATF) sets the anti-money-laundering standards most countries follow. In October 2018 it updated Recommendation 15 to cover virtual assets, and in June 2019 it issued guidance that brought virtual asset service providers (VASPs) under the same customer due diligence logic as banks and extended Recommendation 16, the "travel rule", to them (Wikipedia, citing FATF). Adoption is uneven but rising: FATF's targeted update of 15 July 2026 found that 83% of the jurisdictions surveyed on the point had Travel Rule legislation in force (Notabene summary, 17 July 2026).
The Travel Rule. When you send crypto from one exchange to another, the sending platform must pass your identifying details to the receiving one. In the EU this is the Transfer of Funds Regulation, applying since 30 December 2024, and it covers crypto transfers regardless of amount. A platform can only send verified data if it verified you first. See the crypto Travel Rule explained.
Licensing. In the EU, crypto businesses need a licence under MiCA, and authorised crypto-asset service providers are obliged entities under AML law. Since the MiCA transitional period ended on 1 July 2026, a firm serving EU clients needs that authorisation. From 10 July 2027, the AMLR requires crypto-asset service providers to run full due diligence even on occasional transactions of EUR 1,000 or more (Article 19(3)) and bans anonymous crypto accounts (Article 79). Our pillar guide, what is MiCA, explains the licensing side.
Requirements vary by platform and country, but a standard individual onboarding in 2026 usually includes:
Our practical guide to ID verification tips for crypto exchanges covers the common reasons a check fails, such as glare on the document, a cropped photo or a name mismatch.
Most exchanges do not build verification in-house. They plug in a specialist identity verification provider, such as iDenfy, whose software runs a sequence of checks in a few minutes. The details differ by vendor, but the steps are broadly the same:
KYC does not stop once you are approved. Under the AMLR, from July 2027 customer information must be kept up to date at intervals that depend on risk and never exceed one year for higher-risk customers or five years for everyone else (Article 26). Exchanges also monitor transactions and screen the wallets you deposit from and withdraw to. Under the Transfer of Funds Regulation, for a transfer of more than EUR 1,000 to or from your own self-hosted wallet, the exchange should verify that the address is owned or controlled by you, which is why some platforms ask you to sign a message or make a small test transfer.
Many platforms split verification into tiers. The law sets the duty to verify customers; how a platform stages that process is a business decision, so tier names and limits differ from one exchange to the next. A typical structure looks like this:
Enhanced due diligence can also be triggered by events rather than by your choice: a large deposit, a transfer from a high-risk wallet, a match on a PEP list, or a change in your activity. If a platform asks for more documents later, that is usually the reason.
This is the part most users never think about. Your documents and selfie are usually processed by the verification vendor and stored by the exchange, and AML law requires the exchange to keep them. Under the AMLR, which applies from 10 July 2027, due diligence records must be retained for five years after the business relationship ends, and regulators can require up to five years more in specific cases (Article 77). Closing your account does not delete your passport scan the next day.
That retention creates risk. Identity data has leaked from exchanges and their suppliers, and when an exchange shuts down, your data does not disappear with it. We cover this in detail in what happens to your KYC data, what happens to your passport when an exchange shuts down and the Revolut data leak and self-custody. Under the GDPR you can ask any EU platform what it holds about you and on what legal basis; you cannot make it delete records that AML law requires it to keep.
Decentralised finance works differently. When you use a non-custodial protocol, you interact with smart contracts from your own wallet. No company takes custody of your funds or opens an account in your name, so there is usually no onboarding step where KYC would happen. That is a structural difference, not a loophole: the rules attach to intermediaries that provide services to customers.
The picture is not black and white. Some front ends screen connecting wallets against sanctions lists and block flagged addresses. Some protocols, especially those dealing in tokenised securities or real-world assets, use permissioned pools where only verified wallets can take part. Where an identifiable company provides or controls a service, regulators may treat it as an intermediary. And the moment you move funds between DeFi and a regulated exchange, the exchange's KYC and Travel Rule obligations apply to that transfer. Our explainer on KYC in DeFi covers the debate in more depth.
JewelSwap is non-custodial DeFi software on MultiversX, Sui and Radix. It is not a crypto-asset service provider and is not regulated, it does not hold user funds, and its money markets are currently paused.
KYC verifies individuals. KYB, "know your business", verifies companies: a firm opening an exchange account, a market maker, an OTC counterparty or a payment partner. KYB checks that the company exists and is in good standing in the company register, who its directors are, and, above all, who its ultimate beneficial owners are, meaning the natural persons who own or control it. Those beneficial owners then go through KYC themselves.
KYB is slower and more document-heavy because corporate structures can hide ownership behind layers of holding companies. Our KYB compliance checklist explains the process step by step, and KYB in crypto covers the tooling.
Some centralised platforms advertise trading without identity checks. Before using one, it is worth understanding what that actually means:
None of this is a recommendation for or against any platform, and you should not try to get around a platform's verification requirements. If privacy is the concern, self-custody of your own assets and careful choice of which regulated platforms you share data with are lawful routes. Our self-custody guide covers the first.
KYC means "know your customer". It is the identity verification a regulated crypto business, such as an exchange or custodial wallet, must carry out before serving you: collecting your personal details, checking an ID document and a live selfie, and screening you against sanctions and PEP lists.
Because anti-money-laundering law requires it. FATF standards have covered virtual asset service providers since 2018 and 2019, the EU's Transfer of Funds Regulation requires identifying data to travel with crypto transfers, and licensed EU crypto firms are obliged entities under AML law.
Usually a passport, national ID card or driving licence, plus a live selfie. Some platforms or higher tiers also ask for proof of address and source-of-funds documents, and EU platforms now ask for your tax residence and tax identification number.
Under the EU Anti-Money Laundering Regulation, which applies from 10 July 2027, due diligence records must be kept for five years after the business relationship ends, and regulators can require up to five more years in specific cases.
Most non-custodial DeFi protocols do not, because there is no intermediary opening an account for you. Some front ends screen wallets against sanctions lists, some pools are permissioned, and moving funds to or from a regulated exchange brings its KYC rules into play.
KYC verifies individual customers. KYB verifies businesses: that the company exists, who runs it and who its ultimate beneficial owners are. Those beneficial owners are then verified with KYC.
This article is educational and is not legal or financial advice. Legal references are to Regulation (EU) 2024/1624 and Regulation (EU) 2023/1113 as published in the Official Journal, checked on 5 October 2026. Register counts come from ESMA's interim MiCA register as downloaded on 5 October 2026. Other sources are linked inline, including EUR-Lex and Notabene.