SEC Commissioner Hester Peirce is urging financial firms to use reusable digital credentials to verify customer facts without repeatedly collecting the underlying personal data. Her call comes as proposed GENIUS Act rules would require permitted payment stablecoin issuers to collect customer-identifying information and retain it for years. Peirce said the views were her own, not the SEC’s.
Why it matters
KYC records can create risks even when accounts and funds remain secure. Coinbase disclosed that 69,461 customers were affected after attackers bribed overseas support personnel to access internal information, including identity documents and transaction histories. Revolut separately said a fraudulent information request led it to disclose customer identity and contact details, with some records also including verification selfies, account statements and transaction histories. It said its systems and customer funds were unaffected.
Peirce’s proposal is to verify attributes, such as age, citizenship or sanctions status, without disclosing unrelated details like a person’s name, income or address. That differs from simply changing how firms check identity: the proposed stablecoin rules generally require covered issuers to obtain specified identifying information and keep it for five years after an account closes.
Market impact
The proposal does not cover every stablecoin holder. It applies to customers establishing covered relationships with permitted issuers, including direct issuance or redemption. Regulators say the requirements implement the GENIUS Act’s direction to treat permitted issuers as financial institutions under the Bank Secrecy Act.
The rulemaking leaves room for the final requirements to address verifiable credentials and reliance on checks performed by other regulated institutions. The outcome will shape whether stablecoin issuers build another layer of identity databases or can meet compliance obligations while retaining less raw customer data.
Frequently asked questions
-
What does Peirce mean by reusable digital credentials?
They could let customers prove attributes such as age, citizenship or sanctions status without disclosing unrelated personal information to each institution.
-
How long would covered stablecoin issuers retain customer information?
Under the proposed rules, identifying information would generally be retained for five years after a covered account closes.
-
Do the proposed KYC rules apply to every stablecoin holder?
No. They target customers establishing covered relationships with permitted issuers, including direct issuance or redemption.
-
What customer information was exposed in the Coinbase incident?
The compromised information included identity and contact details, government-issued ID images, account balances and transaction histories. Coinbase said 69,461 customers were affected.
-
What remains undecided in the stablecoin rulemaking?
The final rules could clarify whether issuers may rely more broadly on checks performed elsewhere and how verifiable credentials can be used to reduce duplicate data collection.
CryptoSlate