• CoinDesk reports that Binance provided user data to Russian authorities, and that the information contributed to the arrest of a Ukrainian donor.
  • Binance says it cooperates with lawful requests from law enforcement. It closed its Russian business in 2023 as part of a compliance overhaul.
  • Leaving a market does not delete the records already collected: anti-money-laundering rules oblige exchanges to keep onboarding and transaction data for years.

Every regulated crypto exchange asks for a passport or a driving licence before it lets you trade. CoinDesk reports that Binance passed information of that kind to Russian authorities, and that it contributed to the arrest of a Ukrainian donor. Binance says it responds to lawful requests.

The documents you hand an exchange when you open an account do more than satisfy the exchange. They create a durable, searchable record of who you are and where your money went, and that record can be requested by a government later, including one you never expected to have any dealings with.

For most account holders that will never amount to more than an inconvenience. For anyone whose money touches a conflict, a sanctions regime or a government that treats certain payments as a crime, the same record is a safety question.

What an exchange actually holds about you

A close-up image of Austrian and Portuguese passports with a Bulgarian ID card.
Passports and a national ID card, the kind of identity documents every major exchange asks new customers to upload and then keeps on file. Photo by Marta Branco on Pexels.

The process of opening an account is usually called KYC, short for know your customer. It is a legal requirement in most countries, imposed on exchanges by anti-money-laundering law rather than chosen by them.

What it produces is a fuller file than most people picture. Typically that includes your legal name, date of birth and home address, a scan or photograph of an identity document, often a selfie or short video taken to match your face to it, the bank account or card you funded with, the IP addresses and devices you have logged in from, and every deposit, trade and withdrawal you have ever made on the platform.

The last item matters more than the rest. A is a public ledger, so anyone can see that a particular address sent funds somewhere. What is normally missing is the link between an address and a person. Your exchange account is exactly that link. Once someone holds your account file, a chunk of your activity stops being anonymous and becomes attributable.

How a “lawful request” works in practice

Exchanges of any size run a formal channel for police and prosecutors, usually a law enforcement request portal staffed by a dedicated team. An agency submits a request, the exchange assesses whether it is valid under the law that applies to the relevant corporate entity, and if it is, the data goes out. In many jurisdictions the customer is never told.

The phrase doing the heavy lifting there is “applies to the relevant entity”. A global exchange is not one company but dozens, incorporated in different places, and each one is answerable to the authorities where it sits. Whether a request is lawful is therefore a question about which company holds the file, not about where the customer lives.

That is the gap in a statement like “we cooperate with lawful requests”. It is accurate, and it is also compatible with a very wide range of practice. It does not tell an account holder which governments the company accepts requests from, what threshold it applies, or whether it ever refuses.

Why exiting a market does not erase the records

Binance sold its Russian business in 2023 and presented the move as part of tightening its compliance. That closed the door to new Russian customers. It did not undo the data collected while the door was open.

Anti-money-laundering rules generally require firms to retain customer identification and transaction records for a set period after an account closes, commonly five years and sometimes longer. So the files continue to exist by legal obligation, and they can still be requested. Whether they sit with a successor company, a former affiliate or the group itself is the sort of detail that decides who can compel them, and it is rarely something a customer can find out.

This is where the platform has questions to answer rather than the people affected. If a company leaves a jurisdiction on compliance grounds, saying so is a claim about the future. Account holders deserve to know what happened to the past: who now holds the records, under whose law, and on what basis they would be handed over.

What the same route looks like for a UK customer

UK exchanges face a comparable, though better-signposted, process. Police and other agencies can obtain customer data under the Data Protection Act 2018, which contains exemptions allowing disclosure for the prevention and detection of crime, and can seek court orders where a firm resists. Foreign authorities normally have to route requests through mutual legal assistance arrangements rather than approach a UK firm directly, which adds friction and a layer of oversight, but it is not a wall.

The practical point for readers here is that the protection comes from which entity holds your account and which country’s courts stand behind it. That makes Binance’s reported plan to apply for an FCA licence and relaunch in the UK, first reported by Cointelegraph, relevant beyond market access: a UK-regulated entity is a different legal proposition from an offshore one.

Holding your own coins changes what happens next rather than what happened already. It means future activity is not tied to an account file, which is one of the arguments in our guide to self-custody. It does not remove records an exchange is already required to keep.

What to watch

Whether Binance sets out publicly how many law enforcement requests it receives, from which countries, and how many it declines. Several large platforms now publish that breakdown, and its absence is the reason this story can only be told one case at a time.

Also worth watching: whether the FCA application prompts any questions about how customer data from exited markets is held, and whether other exchanges are asked what became of the records they gathered in markets they have since left. More on the regulatory side sits on our policy page.