{"id":19474,"date":"2019-08-28T18:09:17","date_gmt":"2019-08-28T18:09:17","guid":{"rendered":"http:\/\/ci027cfe6eb00c2697"},"modified":"2019-08-28T18:09:17","modified_gmt":"2019-08-28T18:09:17","slug":"localbitcoins-new-kyc-rules-raise-privacy-concerns","status":"publish","type":"post","link":"https:\/\/bitcoinmagazine.com\/culture\/localbitcoins-new-kyc-rules-raise-privacy-concerns","title":{"rendered":"LocalBitcoins\u2019 New KYC Rules Raise Privacy Concerns"},"content":{"rendered":"<div id=\"bsf_rt_marker\"><\/div><figure><img decoding=\"async\" src=\"https:\/\/bitcoinmagazine.com\/wp-content\/uploads\/2024\/11\/localbitcoins-kyc-rules-raise-privacy-concerns.jpg\" title=\"\"><\/figure>\n<p><em>Updated with comments from LocalBitcoins<\/em><\/p>\n<p>Beginning September 1, 2019, legacy peer-to-peer bitcoin exchange LocalBitcoins will extend its know-your-customer\/anti-money laundering (KYC\/AML) requirements and, as a consequence, limit user ability to retain privacy.&nbsp;<\/p>\n<p>According to <a href=\"https:\/\/localbitcoins.com\/blog\/id-verification-update\/\" target=\"_blank\" rel=\"noopener\">an official blog post<\/a> published on June 18, 2019, the exchange has teamed up with identity verification technology provider Onfido, and a new account tier system will be established. Depending on the amount a user trades each year on the exchange, they will have to provide specific data regarding their identity.<\/p>\n<p>For instance, somebody who trades less than $1,109 (1,000 euro) in a year will have to provide their full name, country of residence, email address and phone number. A user who trades beyond this threshold will be required to provide ID verification and full KYC info. Furthermore, proof of residence and additional ID verification will become compulsory for anyone who trades bitcoin worth more than $22,180 (20,000 euros) per year.<\/p>\n<h2><strong>Losing Privacy at LocalBitcoins<\/strong><\/h2>\n<p>Earlier this year, LocalBitcoins also removed offers for in-person cash trades and enforced its <a href=\"https:\/\/www.finanssivalvonta.fi\/en\/publications-and-press-releases\/supervision-releases\/2019\/fin-fsa-regulations-and-guidelines-42019-concerning-virtual-currency-providers-enter-into-force-on-1-july-2019\/\" target=\"_blank\" rel=\"noopener\">first batch of KYC requirements<\/a>.&nbsp;<\/p>\n<p>The new measures at LocalBitcoins, which is based in Helsinki, stem from Finland\u2019s <a href=\"https:\/\/www.finanssivalvonta.fi\/en\/publications-and-press-releases\/supervision-releases\/2019\/virtual-currency-providers-to-be-supervised-by-the-fin-fsa--briefing-for-virtual-currency-providers-on-15-may\/\" target=\"_blank\" rel=\"noopener\">Act on Virtual Currency Service Providers<\/a>, which comes into full effect in November 2019.&nbsp;<\/p>\n<p>In its early days, the Finnish exchange was a pioneer in its field, empowering individuals to make pseudonymous bitcoin-to-fiat trades. More recently, it\u2019s been reported that Venezuelans used the peer-to-peer service to trade <a href=\"https:\/\/bitcoinmagazine.com\/articles\/bitcoin-trading-in-venezuela-hits-all-time-high\">almost 20 billion bol\u00edvars<\/a> in July 2019 alone as a salvation from their own crumbling fiat economy. In the context of these new KYC\/AML additions, it\u2019s very likely that people in countries with authoritarian regimes will no longer have access to services \u2014 or will have to limit their trades to amounts less than 1,000 euros per year.<\/p>\n<h2><strong>The Decentralized Exchange Perspective on AML\/KYC<\/strong><\/h2>\n<p>As such, it\u2019s fair to ask if LocalBitcoins still truly qualifies as a \u201cdecentralized exchange.\u201d To answer the question, we spoke with representatives from Hodl Hodl, a peer-to-peer bitcoin exchange that has worked to maintain access for Iranian investors even as they have been <a href=\"https:\/\/bitcoinmagazine.com\/articles\/localbitcoins-denies-service-iranian-users\">excluded from LocalBitcoins<\/a>, and Bisq, a decentralized bitcoin exchange that <a href=\"https:\/\/bitcoinmagazine.com\/articles\/five-years-making-bisq-exchange-launches-its-bitcoin-dao\">recently launched<\/a> the space\u2019s first DAO. LocalBitcoins did not respond to multiple requests for comment.<\/p>\n<p>\u201cLocalBitcoins has never been a decentralized exchange, because user funds have always been stored in their wallets,\u201d <a href=\"https:\/\/bitcoinmagazine.com\/articles\/hodl-hodl-kicks-off-liquidity-week\">Hodl Hodl<\/a> CEO Max Keidun told <em>Bitcoin Magazine<\/em>.<\/p>\n<p>A Bisq contributor who requested anonymity largely agreed, adding a little more context. They told <em>Bitcoin Magazine<\/em>:<\/p>\n<p>\u201cDecentralization has become a buzzword which tends to contribute more noise than signal in a sentence. The only way I can see LocalBitcoins being \u2018decentralized\u2019 is in its sourcing of offers, since they come from many people who are not a part of the LocalBitcoins company (as opposed to a single order book maintained by the company). However, that\u2019s really no different from the way Facebook and Twitter source their media, and calling them \u2018decentralized social media\u2019 would be ridiculous.\u201d<\/p>\n<p>The two representatives were also asked why privacy matters and to what extent KYC\/AML data collection can be a honeypot for user information.&nbsp;<\/p>\n<p>\u201cIn the digital age, data privacy matters a lot,\u201d Keidun said. \u201cIf you take a look at the recent Binance leak of KYC\/AML data, you will realize that it\u2019s harmful for users to have their personal data (such as ID, photos, addresses) publicly available. I think it\u2019s also dangerous because if your data is leaked from a cryptocurrency exchange then you might deal with a lot of bad actors who assume you may own a lot of bitcoins. The KYC data often includes proof of residency, so thieves can simply come to your place and try to steal something from you or harm you in other ways.\u201d<\/p>\n<p>Again, the two exchange spokespeople saw eye to eye, as the Bisq representative outlined similar concerns around data privacy:<\/p>\n<p>\u201cData privacy is everything. It allows a user to maintain control over their property. Isn\u2019t that part of what Bitcoin is all about? We spend so much effort on \u2018not your keys, not your coins\u2019 but not on \u2018not your machine, not your control.\u2019 In general, data privacy enables people to keep potentially great ideas alive when those in charge are wrong, so that the rest of humanity may prosper when the time for those ideas has come. Without data privacy, Bitcoin could never reach its potential.\u201d<\/p>\n<p>Finally, we asked the two exchange representatives to answer the question \u201cAre KYC\/AML-compliant exchanges data honeypots?\u201d<\/p>\n<p>Keidun answered in the affirmative.<\/p>\n<p>\u201cMany exchanges are more concerned about securely stored assets that they neglect the ethical and safe storage of KYC\/AML documents,\u201d he said. \u201cI think KYC is a honeypot for user information and there\u2019s nothing you can do about that as a user.\u201d<\/p>\n<p>To illustrate his point, Hodl Hodl\u2019s CEO pointed to a rising trend in hacks through which bad actors obtain personal information instead of funds.<\/p>\n<p>\u201cHackers have figured out that they can blackmail exchanges with the confidential KYC\/AML data they steal, and ultimately this is detrimental for both the user and the exchange itself,\u201d he continued. \u201cIf providing personal data was optional on these services, then I\u2019m sure that 99.9 percent of users would avoid filling in any form.\u201d<\/p>\n<p>The Bisq representative indicated a similar pessimism around the safety of user data on exchanges.<\/p>\n<p>\u201cWhatever can get hacked will get hacked if there\u2019s a sufficient motive, and the only asset that is perhaps more valuable than a whole lot of bitcoin is a honeypot of data about people who own a whole lot of bitcoin,\u201d they explained. \u201cFor customers, not only is there the potential of identity theft, but extortion, physical harm and who knows what else. Why take the chance?\u201d<\/p>\n<p>While LocalBitcoins embraces a stricter set of KYC\/AML rules that are enforced by its jurisdiction, Hodl Hodl and Bisq remain alternatives that don\u2019t collect such data and aim to maximize users\u2019 financial sovereignty. For now, bitcoin traders who want to maintain a level of pseudonymity will have to consider them as alternatives to LocalBitcoins.<\/p>\n<p><em>Update &#8211; September 2, 2019: A LocalBitcoins representative contacted Bitcoin Magazine and issued the following statement:<\/em><\/p>\n<p><em>&#8220;LocalBitcoins does not buy or sell bitcoins as a company. All trades happen between our users themselves, and in that sense we do not identify as a centralised exchange. However, traders use their LBC wallet to send BTC in and out when selling or buying coins.<\/em><\/p>\n<p><em>\u201cOur user base has requested better verification measures to prevent fraud and promote a safer trading environment, even before AML regulatory changes. LocalBitcoins wants to provide a safe platform for users and with added security and KYC policies complies with the AML regulation in Finland.<\/em><\/p>\n<p><em>\u201cLocalBitcoins takes data security and privacy matters seriously. All personal and KYC\/AML data is handled in accordance to EU General Data Protection Regulation (GDPR). We are open about what we do with users\u2019 data in our Privacy Policy and have high standards in data protection processes and technical controls.\u201d<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Can an exchange with KYC\/AML be \u201cdecentralized\u201d?<\/p>\n","protected":false},"author":3423,"featured_media":19475,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[544,3091,3166,357,1852,542,1691,73],"class_list":{"0":"post-19474","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-culture","8":"tag-aml","9":"tag-bisq","10":"tag-decentralized-exchange","11":"tag-exchanges","12":"tag-hodl-hodl","13":"tag-kyc","14":"tag-localbitcoins","15":"tag-privacy"},"author_data":{"id":3423,"name":"Vlad Costea","nicename":"vladcostea","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/dcf8df0c5a9b46a72d343c10a23bf0777a27a34001a19284e14f1439f3bfacca?s=96&d=robohash&r=g"},"featured_image_url":"https:\/\/bitcoinmagazine.com\/wp-content\/uploads\/2024\/11\/localbitcoins-kyc-rules-raise-privacy-concerns.jpg","_links":{"self":[{"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/posts\/19474","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/users\/3423"}],"replies":[{"embeddable":true,"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/comments?post=19474"}],"version-history":[{"count":0,"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/posts\/19474\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/media\/19475"}],"wp:attachment":[{"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/media?parent=19474"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/categories?post=19474"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitcoinmagazine.com\/wp-json\/wp\/v2\/tags?post=19474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}