Where Your Identity Documents Actually Go
Both sides of the card, a held-up photo, a few seconds of video of your face. Once uploaded they are out of sight. Who keeps them, for how long, and what they may be used for all have documented answers — just not in the dialog you clicked through.
Independent guide · Not affiliated with any platform · Not investment or legal advice
“What happens to my ID photo” is a fair thing to worry about, and it is usually asked as one question when it is three:
- How long that copy sits in a system;
- What it may be used for beyond the check itself — marketing, risk scoring, model training;
- Who has it: only the platform, or a vendor in the middle as well.
The three answers come from different places and do not overlap. They only make sense apart.
How long: five years, and what happens after
The most-misread part first: retention is not a preference, it is an obligation. Article 40(1) of Directive (EU) 2015/849 requires obliged entities to keep a copy of the documents and information needed for customer due diligence “for a period of five years after the end of the business relationship with their customer or after the date of an occasional transaction”.
That single clause explains a frustration people read as stonewalling: while the relationship is live, “delete my ID photo” is not something the other side can agree to. Not unwilling — not permitted.
The rest of the same article is less quoted and works in your favour:
Upon expiry of the retention periods referred to in the first subparagraph, Member States shall ensure that obliged entities delete personal data, unless otherwise provided for by national law … That further retention period shall not exceed five additional years.
So this is not a permanent file. The default is deletion after five years; extending it requires a national-law basis and an assessment of necessity and proportionality, and it is capped at five more.
Asking “do you keep my data forever” rarely gets a useful answer. Ask instead: what retention period applies to my records, and from what date does it run? That has a statutory answer. And note the start date is the end of the business relationship, not the day you uploaded — leave the account open and the clock has not started.
What for: the purpose is locked by statute
This is the part worth carrying away, because it is far more concrete than “we store your data securely”. Article 41(2) of the same directive:
Personal data shall be processed by obliged entities on the basis of this Directive only for the purposes of the prevention of money laundering and terrorist financing … and shall not be further processed in a way that is incompatible with those purposes. The processing of personal data on the basis of this Directive for any other purposes, such as commercial purposes, shall be prohibited.
“Such as commercial purposes, shall be prohibited” is statutory text, not a promise in a privacy policy. The file you handed over to pass a check cannot, on this legal basis, be turned into marketing data or sold on — independently of how well any given policy is drafted.
Note the limit of the limit: it binds processing on the basis of this Directive. Other data processed on another legal basis sits outside it. So it is not a blanket shield — but for the KYC file specifically, the boundary is hard.
Who holds it: there is a layer past the platform
Most people assume the file stays with the platform. In practice the check is frequently outsourced, and you agreed to that in the terms. Clause 7.3 of Binance's terms of use puts it plainly: you authorise it to make enquiries directly or through third parties, and you acknowledge that your personal data may be disclosed to identity verification, compliance data recording, credit reference, fraud prevention or financial crime agencies — and that those agencies may respond to its enquiries in full.
Read the last part again: the pipe runs both ways.
That layer usually does not say who it is. A few platforms publish the list. Coinbase maintains a page naming the identity verification vendors it may use; on the day we read it the page showed a last-updated date of 9 December 2025 and named Jumio, Onfido, Au10tix, Shufti, Refinitiv, Unico and Persona. Three details on it are worth any user's time, whichever platform they are on:
- Vendors keep their own clocks. The page states that biometric information handled by Persona “will be stored for no more than 3 years”. That is not the same clock as the platform's five years. Your data is being timed on two chains at once.
- The same platform may use different vendors by region. The page notes Unico is used for Brazil users. So “it worked for me and not for them, on the same platform” has a mundane explanation: you were not judged by the same system.
- Vendors recognise returning faces. Of Onfido, Au10tix and Refinitiv the page says the same thing — facial scan data may be used to determine whether that vendor has previously verified your identity on the platform's behalf. The middle layer keeps its own memory of you.
That chain deserves its own piece: the vendor chain behind an identity check; which parts of it run automatically and which wait for a person is covered in what happens during those hours in the review queue.
Your rights, and the two places they give way
The GDPR gives you a set of rights. In this particular context two of them are expressly curtailed, and any honest account has to say so.
| Right | Where it gives way | What that means in practice |
|---|---|---|
| Erasure | GDPR Article 17(3)(b): paragraphs 1 and 2 do not apply where processing is necessary for compliance with a legal obligation | During the relationship and the statutory retention period, “delete my ID now” has no legal footing |
| Access | Directive 2015/849 Article 41(4): Member States shall adopt legislative measures restricting, in whole or in part, the right of access, to the extent that this is a necessary and proportionate measure in a democratic society with due regard for the legitimate interests of the person concerned, so as not to obstruct enquiries | Records tied to suspicion reporting may be withheld — and you need not be told why |
The second row surprises people. Anti-money-laundering regimes carry a no-tipping-off principle, and to make it work your right of access is lawfully trimmed. That is not a support agent brushing you off.
What survives is still useful: confirmation that your data is being processed, rectification of inaccurate fields, and erasure once the retention period has run. Rectification is the practical one — a misspelled name, a stale address, the wrong country of residence are all fixable through ordinary channels.
Why your face is treated differently
An ID number and a face are not the same class of thing in law. GDPR Article 4(14) defines biometric data as personal data resulting from specific technical processing relating to physical, physiological or behavioural characteristics “which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data”.
Article 9(1) then says processing of biometric data for the purpose of uniquely identifying a natural person shall be prohibited — unless one of the exceptions in Article 9(2) applies.
Prohibited by default, permitted by exception. That structure explains two things you can observe: why a separate consent step appears before a face capture, and why retention and purpose language around face data tends to be more specific than for other fields. Not extra courtesy — a different starting point.
What you can do, and what you cannot
Worth doing:
- Ask for the applicable retention period and its start date rather than asking whether data is kept forever.
- Correct wrong fields. Name spelling, address, country of residence. This is routine, not a fight. The name field has its own traps: entering your name exactly as your ID shows it.
- Hand the file to a chain you can trace — the official site or app, nothing routed through an intermediary. This matters more than anything you can do afterwards.
- Close accounts you have finished with. The clock runs from the end of the relationship; a dormant open account never starts it.
- Only climb as far as you need to. Every tier costs another file on the same retention clock — whether a tier is worth it is covered in why verification comes in tiers.
Not worth your time, because there is no footing for it: withdrawing a completed verification, demanding deletion inside the retention period, or requiring disclosure of the decision logic or of which vendor was used.
Precisely because the file cannot be recalled or deleted on request, who you hand it to is the one step that is entirely yours and entirely irreversible. Anything that asks you to send document photos and a face video to a person, through a messaging app, or to a service offering to complete verification for you is asking you to copy an undeletable thing to a party you will never be able to hold to account. The costs are set out in why “guaranteed verification” services are always a trap.
Retention, purpose limitation and the restriction on access come from the consolidated text of Directive (EU) 2015/849 (EUR-Lex, version of 9 July 2024), Articles 40(1), 41(2) and 41(4). The definition of biometric data, the default prohibition and the erasure exception come from Regulation (EU) 2016/679 (GDPR), Articles 4(14), 9(1) and 17(3)(b). All read on 2 September 2026.
“Directly or through third parties”, and disclosure to identity verification and financial crime agencies, is clause 7.3 of Binance's terms of use, read on the same day. The vendor list, Persona's three-year biometric retention, the Brazil-only note on Unico and the statements about vendors recognising a previously verified face come from Coinbase's published third-party identity verification vendors page, which showed a last-updated date of 9 December 2025. We cite it because published vendor lists are rare, not as an endorsement or assessment of that platform.
The legal framework discussed here is the EU one. Retention periods, available rights and their limits differ by jurisdiction; what applies to you is set by your local law and your agreement with the platform. This is not legal advice.
While writing this we did not log into any account, did not submit verification material, and did not file a data subject request with any platform or vendor. So nothing here describes any platform's internal retention implementation, names any platform's vendor beyond what the disclosure page above states about itself, or predicts what answer a request of yours would receive.
Questions people actually ask
Can I make a platform delete my ID photo?
Usually not while the relationship is live and the statutory retention period is running. Article 40 of Directive (EU) 2015/849 requires obliged entities to keep customer due diligence records for five years after the end of the business relationship, and GDPR Article 17(3)(b) states that the right to erasure does not apply where processing is necessary for compliance with a legal obligation. A refusal is therefore not stonewalling. After the period expires the position reverses: the directive requires deletion of personal data unless national law provides otherwise, and any extension is capped at five additional years.
So is my file kept forever?
Not under the EU framework. Article 40(1) sets the period at five years after the end of the business relationship or after the date of an occasional transaction, and on expiry Member States must ensure obliged entities delete the personal data unless national law provides otherwise. Further retention requires an assessment of necessity and proportionality and cannot exceed five additional years. Note the start date is the end of the relationship, not your upload date, so an account left open never starts the clock.
Can my documents be used for marketing, or sold on?
Not on this legal basis. Article 41(2) of Directive (EU) 2015/849 states that personal data processed on the basis of the directive may be processed only for anti-money-laundering and counter-terrorist-financing purposes, may not be further processed incompatibly with those purposes, and that processing for any other purposes, such as commercial purposes, shall be prohibited. The limit binds processing on that basis; other data on another legal basis is outside it.
Who else has my documents besides the platform?
Typically an identity verification vendor. Clause 7.3 of Binance's terms of use has you authorise enquiries made directly or through third parties, and acknowledges that your personal data may be disclosed to identity verification, compliance data recording, credit reference, fraud prevention or financial crime agencies, which may respond to those enquiries in full. That layer usually does not identify itself; a few platforms publish a list. Coinbase's vendor page, read on 2 September 2026 and showing a last-updated date of 9 December 2025, named Jumio, Onfido, Au10tix, Shufti, Refinitiv, Unico and Persona, and stated that Persona stores biometric information for no more than three years and that Unico is used for Brazil users.
Why is there a separate consent step before a face scan?
Because biometric data is its own legal category. GDPR Article 4(14) lists facial images as an example of biometric data, and Article 9(1) provides that processing biometric data for the purpose of uniquely identifying a natural person shall be prohibited unless one of the Article 9(2) exceptions applies. The default is that it may not be processed at all, so a separate basis has to be established. It is also why retention and purpose wording around face data is usually more specific than for other fields.
Legal texts (read 2 September 2026): five-year retention and post-expiry deletion are in Article 40 of the consolidated Directive (EU) 2015/849; purpose limitation and the access restriction are Articles 41(2) and 41(4) of the same text. The biometric definition, the Article 9 prohibition and the Article 17(3)(b) erasure exception are in the consolidated GDPR.
Platform and vendor side (read 2 September 2026): enquiries “directly or through third parties” and disclosure to verification and financial crime agencies are clause 7.3 of Binance’s terms of use. The vendor list with per-vendor retention and regional notes is Coinbase: Third Party Identity Verification Service Vendors (last updated 9 December 2025 as displayed).
Splitting the worry into how long / what for / who holds it, and the observation that the platform's five years and a vendor's own period are two separate clocks, are this site's synthesis of the sources above. Neither represents any institution's position, and neither is legal advice.