

KYC stands for "know your customer". It is the identity check a crypto exchange or app runs before it lets you buy, deposit or withdraw: you photograph an ID document, take a selfie, and the exchange confirms that the document is real and that the face on it is yours.
The exchange is not asking out of curiosity. In most countries, a company that holds and exchanges other people's crypto is required by law to know who its customers are, just as a bank is. Below: what exactly it asks for, why, how safe your documents are, and what happens if the check fails or you say no.
The check happens inside the app, and a typical set looks like this:
The camera screen often belongs to a verification company the exchange hires, so a different logo there is normal. Many exchanges verify in levels: the basic check unlocks buying with modest limits, and more documents unlock more.

A blockchain records every transfer, but its addresses carry no names. The exchange is where crypto turns into bank money and back, so that is where the law puts the name check. If stolen coins or a ransom pass through an account, investigators can ask the exchange whose account it is. The same data lets the exchange check your name against sanctions lists.
So the duty falls on companies that hold your money and trade for you: centralized exchanges, brokers, apps with a wallet they manage on your behalf. If you're not sure which kind you're using, here is how a centralized exchange differs from a decentralized one.
Where the main rules stand as of 11 September 2026:
The check looks alike from country to country because governments follow a shared standard set by the Financial Action Task Force, which covers crypto companies too. This is a general explanation, not legal advice: your account is governed by the law of the country where the exchange is registered.
You'll often see KYC next to AML, short for anti-money laundering. AML is the whole set of rules, and KYC is the part about you as a person. Another part watches the money itself: how a service screens the coins and the address they came from.
Source of funds is proof that the money you deposit reached you legally: a payslip, a sale contract, an inheritance document, a bank statement. Exchanges ask for it when a sum is large or doesn't fit what they know about you. EU anti-money-laundering law, for one, tells them to find out where the money came from when a customer's activity calls for it.
Say someone who buys €100 of bitcoin a month suddenly deposits €40,000 after selling a car. The sale contract and the bank statement showing the payment answer the question. Crypto bought years ago counts too: a transaction history exported from the old exchange shows where the coins started.
It is as safe as the company that stores them. In the EU and the UK, data protection law (GDPR) obliges the company to guard your documents and use them only for the stated purpose. No law rules out a leak, though: in 2025, one of the largest US exchanges disclosed that bribed overseas support contractors had copied customer data, passport and driving-licence images included.
A photo of your passport won't let anyone withdraw your crypto. What it gives a scammer is a script: they contact you as "support", know your name, address and roughly your balance, and ask you to move funds "to safety". That is what the data stolen in 2025 was meant for, and it's worth knowing how money actually gets taken from wallets.
A few habits lower the risk:

Most failures are technical, and a second attempt fixes them. The usual causes:
Fix the account details first, then retake the photos in daylight with the whole document on a flat, dark surface. Exchanges often limit the number of attempts; after that, a person reviews the case, which takes longer.
Some refusals don't change on a retry: the exchange doesn't work in your country, you're under age, or your name matches a sanctions list. If the match is a namesake, extra documents can clear it.
Sometimes the exchange refuses without a reason, and that can be the law at work: in the EU and the US, a company that has reported a suspicion to the authorities is not allowed to tell the customer. Companies also keep their risk rules private, so silence on its own proves nothing.
A licensed exchange can't serve you without it. Depending on the country and the company, an unverified account either can't buy, deposit or withdraw at all, or works within small limits. If money is already in the account, the exchange may hold withdrawals until you pass the check, so ask support what your options are before you give up.
Turning down one particular company is a fair choice. The honest alternative is another licensed exchange whose handling of data you trust more, and it will ask for a similar check.
KYC is the ID check a regulated crypto service must run on you before it moves your money, because the law of the country where it is registered demands it. Send documents only through the official app of a company you've found in a public register, retake a failed check with clean photos, and expect your data to be kept for years.
Do crypto wallets need KYC? A self-custodial wallet, where only you hold the keys, is an app rather than a company holding your money, so it doesn't verify you. It also means nobody can restore your access: with your own wallet, keeping the keys safe is on you. A wallet inside an exchange or app, managed by the company, works like an account and does ask for KYC. In the EU, when you send more than €1,000 from an exchange to your own wallet, the exchange has to check that the wallet is really yours.
Why is the exchange asking me to verify again? Documents expire, and anti-money-laundering rules, in the EU for instance, require the exchange to keep your details up to date. A new check can also follow a change in how you use the account: bigger sums, a move abroad, a new kind of transaction. On its own, a repeat check doesn't mean you're under suspicion.
Can I ask the exchange to delete my documents? You can ask, but not straight away. EU anti-money-laundering law makes the company keep verification records for five years after you close the account, and EU data protection law lets it refuse deletion while that duty lasts. Once the period ends, EU rules require deletion unless national law sets a longer term. US rules also require these records to be kept for five years.
Create an account and connect the checkout yourself, or talk to sales and we will plan the integration with you.