中文EnglishKiswahili

Home/Articles/The rules and your documents/Who sees your ID

Who Actually Sees Your ID When You Pass KYC

The rules and your documents Published 2026-09-05 Updated 2026-09-05 Jian An · ZHINVO editorial About 9 min

The fear behind this search is specific, and it is worth saying out loud rather than talking around: a stranger on the internet now has a photograph of the front and back of my identity document, plus a recording of my face, and I have no idea who that stranger is. That is the question. Not whether verification is legal, not whether the company is big. Who ends up holding the file, and what can I still do about it.

The Binance Privacy Portal page, showing a Privacy Notice Dashboard with a global row and separate regional rows beneath it
The Privacy Portal opens onto a dashboard of notices rather than a single notice. One global row, then regional ones underneath. Screenshot taken 2026-09.

Why the document is asked for at all

Exchanges do not ask for identity documents because they are curious. They ask because the countries they operate in require regulated financial businesses to know who their customers are, as part of the wider machinery aimed at money laundering and terrorist financing. That requirement lands on banks, on money transfer operators and, in most jurisdictions now, on crypto platforms too.

This page is not going to cite statute numbers or dates for that, because the rules differ by country, they get amended, and a wrong section number is worse than none. The shape is what matters here: a business that cannot say who its customers are is a business that fails its own audits first, long before anything happens to you.

Two consequences follow, and they answer most of the resentment people arrive with. The first is that the check is not addressed to you personally. It is a door everybody walks through, so being asked is not evidence that somebody suspects you. The second is that switching platforms does not escape it, because the platform you switch to is answering to the same category of obligation. Support staff cannot waive it either, which is why polite escalation gets nowhere on this particular subject.

One thing people are rarely told at the start: this is not a single event. Accounts get looked at again, when a document expires, when behaviour changes, when the rules in your country change. Verification is a state, not a gate you pass once.

And it is a state about paperwork only. Whether the money behind the account is a good idea is a separate question that this page has no view on, and a balance can go to nothing however well documented the person holding it is.

The first look is almost never a person

The word review conjures somebody at a desk opening your photograph and considering it. That is not usually the first thing that happens anywhere in this industry. The first pass is software, and it does a fairly predictable set of jobs: read the text off the document, check the layout and security features against what that type of document should look like, compare the face on the card with the face in the recording, decide whether the recording is of a live person rather than a replayed video, and screen the name against sanctions and watch lists. Anything the software will not settle goes into a human queue.

An entire industry exists to do this on behalf of other companies. Banks, brokers, car hire firms and exchanges all buy identity verification as a service rather than building it. Which company performs that work for Binance, I could not confirm from its public pages in September 2026, so I am not going to name one. Privacy notices generally cover processors as a category, meaning outside firms handling data on the platform’s instructions under contract, without listing each of them; whether Binance names any of its own, and which, is not something I can show you on a screenshot, so it stays in the unknown column.

Knowing there is a machine in front of the human explains two things that otherwise feel arbitrary.

Rejection reasons are vague because, in systems of this kind, the underlying output is a code and a score, and the detail gets flattened on the way to you, partly by systems that do not share a vocabulary and partly on purpose, since publishing exactly what failed is publishing exactly what to change. And a resubmission that changes nothing can still pass, because most of these decisions are thresholds rather than yes-or-no questions. Better light moves a score. It does not mean the first attempt was judged wrongly, it means the first attempt gave the machine less to work with.

It also explains why a long explanatory message to support rarely helps. The person at the end of the queue sees a screen with images and fields on it and a standard to apply. Fixing the material beats arguing about it.

Where Binance publishes what it does with your data

There is a public page for this, and it is worth ten minutes of your own reading rather than mine. The Binance Privacy Portal is headed Our commitment to protecting your data, and it describes its own purpose in one sentence:

We created this page to help you navigate through key aspects of our Privacy Program and learn more about your privacy rights.

The structure of the page is more informative than the sentence. Under a heading reading Privacy Notice Dashboard sits a table, and the first row is global. Underneath it, the notices are broken out by region, one entry after another.

That layout is the evidence for something this site repeats often: there is no single set of rules behind the same login. Which notice governs your data is decided by where you are, in the same way that the address document deadline is decided by where you are. If you want to know what happens to your files, the useful act is opening the notice that applies to your own region, not the global one and not a summary of either.

What I will not do is read numbers into that page. It shows a dashboard of notices; it does not show retention periods, and no screenshot of it could. Anyone quoting you a fixed number of years for how long verification records are kept, on the strength of a page like this one, is filling a gap with confidence.

What you can ask for depends on your country

Data protection law is national. That is why the same request gets different answers depending on where the person making it lives, and why the notices are split up in the first place.

For the countries this site is written for, the laws to look up by name are these. India has the Digital Personal Data Protection Act 2023. South Africa has POPIA, the Protection of Personal Information Act. Kenya has the Data Protection Act 2019. Australia has the Privacy Act. For Pakistan, this page leaves the line blank rather than putting a statute in your hands that may not be in force.

Naming a law is not the same as telling you what it gives you, and I am deliberately not summarising any of them here. Rights of access, correction and erasure appear in most modern regimes in some form, with exceptions attached, and the exceptions are exactly where identity verification records tend to sit, because financial crime rules pull in the other direction. If this matters to your situation, read the current text or ask somebody qualified in your country.

Which is also why this page keeps sending you to the regional notice rather than the global one. What you can demand about your own data is the item here with a different answer in every country, and the answer moves as the law behind it moves. None of this is legal advice, and where this page and the notice for your region disagree, the notice is the one that governs.

The question Binance answers in its own words

Question four on the identity verification help page, down in the collapsed list at the bottom, is titled Is identity verification safe? I am pointing at the existence of that question rather than paraphrasing its answer, because this is a case where the platform’s own current wording is the thing you want, and it is one click away from you.

Binance help page FAQ list with five collapsed questions, the third one opened to show that submitted documents are usually reviewed within 48 hours
Five questions, collapsed until clicked. Number three is opened here; number four is the one titled Is identity verification safe? Screenshot taken 2026-09.

The third question in the same list is opened in that screenshot, and it is the one that describes what happens to your file in the meantime:

Submitted documents are usually reviewed within 48 hours. However, it may take longer in some particular cases.

Two days as the usual case, longer sometimes. That is worth holding onto for a reason connected to this page rather than to impatience: every extra attempt you make during those two days produces another copy of your document inside somebody’s system. Which is the argument for the first item in the list below.

Three small things worth doing today

None of these change what the rules require. They change how much of your material is in circulation and how much you know about where it went.

Upload the document clean, once. Do not paint over the number, do not add a watermark saying what the file is for, do not crop away the parts you would rather not send. An edited document is a different kind of problem from a blurred one, and the trade-off in both directions is set out in the page on watermarking an ID photo. I also stopped re-uploading out of impatience a long time ago, because each attempt leaves another copy behind and none of them ever come back.

Keep your own record. One line somewhere you will find again: the date, the platform, which document you sent, and which address document went with it. It takes twenty seconds and it is the only file in this whole story that you control. When a re-check arrives in two years asking for something consistent with what you sent, you will not be reconstructing it from memory.

Start at the portal, not at a forum. Open the Privacy Portal, find the notice that covers your region rather than the global one, and read the part about your rights and how to exercise them. That is where the route for making a request is described, and it is described for your jurisdiction rather than for somebody else’s. Ten minutes there beats an afternoon of reading strangers guess.

Three items, one evening, and none of them has to be repeated. The file you sent is out of your hands; the record of what you sent, and the notice that says what can be asked about it, are both still in them.

What people ask after they press submit

Is a person actually looking at my passport photograph?

In this industry the first pass is normally software: it reads the text off the document, checks the layout against what that kind of document should look like, compares the face on the card with the face in the recording, and screens the name. A human queue exists for the cases the software will not decide on its own. How Binance splits its own review between the two is not set out on any of its public pages, so treat that description as how these systems are built rather than as a statement about one company.

Which company performs the document check for Binance?

This page does not name one, and a name recalled from memory would be worse than no name at all. Privacy notices in this industry generally cover processors as a category, meaning outside companies that handle data on the platform’s instructions, without listing every one of them by name. If it matters to you, the place to look is the privacy notice that applies to your own region, since that is where any naming would appear, and it is reachable from the Binance Privacy Portal.

Can I ask for my identity documents to be deleted?

What you can ask for depends on where you live, and the answer is written in your country’s data protection law rather than in a help article. India has the Digital Personal Data Protection Act 2023, South Africa has POPIA, Kenya has the Data Protection Act 2019 and Australia has the Privacy Act; for Pakistan, the status of its data-protection law was not something I could pin down in September 2026. Requests connected to identity checks and financial crime rules are also the ones most likely to be limited by other obligations, so read the notice for your region before deciding what to ask for.

Why does the same platform ask my friend for less than it asks me?

Because you are not under the same rules, even though you are looking at the same website. Binance publishes its privacy notices as a set rather than as a single document, with a global one and separate regional entries below it, and the same splitting runs through what you are asked for and what you can use. A screenshot from a friend in another country is a description of their obligations, not of yours.