A crypto exchange wants your ID and a selfie
A licensed exchange genuinely has to run the full check. The question worth your time is whether it is licensed at all.
Short answer
- Do not redact anything you send to a licensed exchange. Anti-money-laundering rules require the complete document; a covered field is a failed check, not a privacy setting.
- Check the register before you check the fields. ESMA publishes the EU-wide list of authorised crypto-asset service providers, and every national regulator publishes its own.
- Nobody outside a supervised firm is entitled to this. A fake airdrop, an unlock-your-withdrawal message and a peer-to-peer counterparty all want the same document set with none of the obligations.
- The copy has a defined lifespan. Anti-money-laundering law sets a retention period, and a GDPR erasure request does not override it — but you can ask who else is holding a copy.
Almost every other page on this site tells you to cover fields before you send a document. This one does the opposite, and it is worth being blunt about why: if the exchange is licensed, send the complete document, unredacted, and do not watermark it.
Why a licensed exchange needs the whole document
A crypto exchange operating in the EU is no longer an unregulated business. Regulation (EU) 2023/1114 — MiCA — requires a crypto-asset service provider to be authorised by a national competent authority, and authorisation drags the firm into the anti-money-laundering framework alongside banks: the 4th and 5th AML Directives today, and the directly applicable AML Regulation (EU) 2024/1624 from 10 July 2027.
The duty sits on the exchange, not on you, and it is a duty to capture, not to glance. The onboarding system reads name, date of birth, document number, expiry and usually the machine-readable zone, then matches the photograph against a live image of your face. A black bar over any of that is a missing field. A watermark across the data page is, to some capture systems, a tampering signal.
Worse, the failure is not free. Repeated failed verification attempts do not read as a cautious customer; they read as a suspicious one, and the ordinary consequence is a review with the account restricted while it runs — which is a genuinely bad place to be if a withdrawal is pending. This is the same boundary set out in when redacting your ID won’t work and in more detail for banks in you cannot redact your ID for a bank.
The question that actually deserves your caution
So the decision is not which fields do I cover. It is is this a supervised firm at all — because an unlicensed operation collects exactly the same document set, in exactly the same order, with none of the retention limits, none of the security obligations and nobody to complain to.
That question has a real answer you can look up in about a minute:
- The EU-wide list. ESMA publishes the MiCA register of authorised crypto-asset service providers — and, in the same place, a list of entities it has flagged as non-compliant. ESMA also runs a plain-language is the firm regulated? page for consumers.
- Your national regulator’s list. Spain’s CNMV, Germany’s BaFin, Austria’s FMA and their counterparts each publish the firms they have authorised. An authorisation granted in one member state passports across the EEA, so a Spanish user may legitimately find their exchange on an Irish or Maltese register — but it must be on one of them.
- Match the legal entity, not the brand. Exchanges market under a trading name and are authorised under a company name. If the register entry and the terms of service do not name the same company, you have not confirmed anything.
Two honest caveats. Being on the register does not mean the regulator vouches for the firm’s solvency or its security — it means the firm is supervised and carries obligations, including obligations about your document. And the MiCA transitional period ran out on 1 July 2026 under Article 143(3), so “we are still in the transition” is no longer an available explanation for a firm that is not on any list.
Who is asking, and what to send
| Who is asking | Is it legitimate? | What to send |
|---|---|---|
| An exchange you found on the register, in its own app, in a flow you started | Yes — a real legal duty | The complete document, unredacted, plus the live selfie step |
| An exchange that appears on no register anywhere | No | Nothing. Do not open the account |
| An email or DM from “support” saying your withdrawal is frozen pending KYC | No | Nothing. Log in yourself and look for a pending task |
| A site offering an airdrop or bonus that must be “unlocked” by verifying | No | Nothing |
| A recovery service offering to get back crypto you already lost | No | Nothing — this targets people who have already been defrauded once |
| Your counterparty in a peer-to-peer trade | No | Nothing. The platform verifies, never the other trader |
| A licensed exchange asking you to email the document as an attachment | No — right firm, wrong channel | Nothing. Complete it in the app |
The last two rows matter most. A peer-to-peer counterparty asking for ID is not a lighter version of a KYC check; it is a stranger asking for a document, and it belongs with a marketplace buyer who wants to see your ID — a request you decline, or answer with a redacted copy if you decide the trade is worth it. And a legitimate exchange that has emailed you asking for an attachment has almost certainly not: impersonating the verification step is one of the most productive ways to harvest complete document copies.
What happens to the copy after the check passes
The exchange does not simply keep it forever, and it cannot simply delete it on request either.
Retention is set by law. The AML Regulation fixes a five-year retention period running from the end of the business relationship, and national rules still vary above that — Germany’s Geldwäschegesetz sets five years, Spain’s anti-money-laundering law sets ten. Retention is a duty on the firm, so it survives your preferences.
Erasure has a hole in it, and it is the right one. Under the GDPR, Article 17(3)(b) disapplies the right to erasure where processing is necessary for compliance with a legal obligation. An exchange refusing to delete your ID during the AML retention window is not stonewalling you; it is doing what the law tells it to. Once the period expires, the obligation flips: the data should go.
Ask where the second copy is. Most exchanges do not build identity verification themselves — they buy it. That means your document and your face were processed by a named third-party provider, under a contract, in a jurisdiction that may not be yours. A subject access request will tell you which one. It is the single most useful question here, because “who has my passport photo” almost always has more than one answer. Can a company legally keep a copy of your ID? covers the mechanics of asking.
Use the in-app flow, always. Not email, not chat, not a support portal that asks you to upload to a general-purpose file service. A document sent inside the verification flow goes into the retention regime described above. A document sent as an email attachment sits in an inbox with no retention period at all.
The selfie and the liveness step
The selfie is not an extra intrusion bolted onto the document check — it is the part that makes the document check mean anything. A copy proves a document exists; only a live capture ties it to the person sitting there.
This is also why the format of the request tells you so much. A real check turns on the camera itself, asks you to turn your head or follow a moving target, and picks its own frames, precisely because it assumes what you hand it might be a photo of a photo. A request to take a still picture of yourself holding your document — especially with today’s date on a handwritten note — is the opposite: it produces a portable file that can be forwarded to somebody else’s manual review. Is it safe to send a selfie holding your ID? goes through the tells in full.
So: inside a licensed exchange’s own live capture, let it run and change nothing. Anywhere else, the photo is the product.
Nothing on this site helps you pass a KYC check, and Anonymize my ID is no exception — it is for the requests with no regulator behind them, the counterparty in a trade, the group chat, the platform support desk. For a supervised exchange, the tool is the register, not the redaction.
Frequently asked questions
Do I really have to send my ID to a crypto exchange?
If it is licensed, yes. Since MiCA came into application, firms offering crypto-asset services in the EU need an authorisation, and that brings them under the same anti-money-laundering identification duties as a bank. There is no version of the check that works on a partial document. If you are not willing to identify yourself to a supervised firm, the answer is not to redact — it is not to open the account.
Can I redact or watermark the copy I send to an exchange?
No. The onboarding system reads the document's fields and usually compares the photograph to a live capture of your face, so a black bar is a missing field and a watermark across the data page can be scored as tampering. In practice you get asked again, sometimes with the account restricted while it is pending, and you send the full document anyway from a worse position.
How do I check whether a crypto exchange is actually licensed?
Look it up in a register rather than on the exchange's own website. ESMA publishes the EU-wide list of authorised crypto-asset service providers together with a list of entities flagged as non-compliant, and each national regulator publishes its own — the CNMV in Spain, BaFin in Germany, the FMA in Austria. Match the exact legal entity name, not the brand you saw in an advert.
A site says I must complete KYC to release an airdrop or unlock a withdrawal. Is that real?
Almost never. A genuine identity check happens when you open an account or hit a threshold, inside the app, in a flow you started. A demand that arrives as a message, blocks money you believe you already have, and points you at a form on an unfamiliar domain is the standard pattern for collecting a complete document set. The unlock fee that follows is the tell.
The other person in a peer-to-peer trade wants a photo of my ID. Is that normal?
No. Where a peer-to-peer platform has identification duties, the platform performs the check itself — it never delegates it to your counterparty. A trading partner asking you directly for a document has no obligation to hold it, no retention limit and no supervisor. It is the same request as a marketplace buyer asking to see your ID before paying, and the same answer applies.
How long does an exchange keep my ID copy, and can I have it deleted?
Anti-money-laundering law sets the period, not the exchange's preference — typically five years from the end of the business relationship, longer in some member states. GDPR Article 17(3)(b) means an erasure request does not override a legal retention duty, so expect a refusal while the period runs. What you can usefully ask for is a copy of what they hold and the name of any third-party provider that ran the check.