AML law requires financial institutions and virtual asset service providers to collect identity data at scale — to verify it, retain it for years, and share it across institutions with every qualifying transaction. Data privacy law then imposes full governance obligations on everything collected. Most compliance programmes treat these as sequential exercises. They are not. This article examines what that gap looks like in practice, where it produces harm, and what it means for AML-obligated institutions that want to comply with both bodies of law simultaneously.
- What AML-mandated KYC collection actually puts on your books — and why the data profile is routinely understated
- What the legal obligation basis authorises — and what it does not suspend
- Three enforcement cases that illustrate different dimensions of the compliance gap
- The Travel Rule multiplier — an additional structural amplifier for VASPs specifically
- A mapped gap across six compliance dimensions, from minimization to individual rights
- Six governance recommendations for treating KYC obligations and privacy obligations as concurrent
The legal obligation created the data. It did not create the governance. That distinction is where the next wave of enforcement will land — and where the gap between compliant collection and compliant governance is most exposed.
01 — The Framing Paradox
Two bodies of law govern the same data, at the same time, at the same institution.
The first — AML law, embodied in FATF Recommendations, the EU's Transfer of Funds Regulation, the US Bank Secrecy Act, and equivalent legislation in over 85 jurisdictions — says: collect identity data, verify it, retain it for years, and share it across institutions with every qualifying transaction.
The second — data privacy law, embodied in GDPR, PIPL, PDPA, APPI, PIPEDA, and their equivalents — says: minimise what you collect, protect what you hold, honour individual rights in relation to it, and be accountable for what you do with it.
Both apply to KYC data. Simultaneously. In full.
The legal obligation that justifies collecting the data does not govern what happens to it afterward. That is a separate question — and most compliance programmes do not treat it as one.
Most organisations treat these obligations as sequential. Satisfy KYC requirements first; address privacy separately, if at all. This is a structural error. The obligations are concurrent. They operate on the same data, at the same time, under the same governance perimeter.
This paper examines what that tension looks like specifically in the context of AML/KYC compliance — where the legal obligation to collect is clearest, the data most sensitive, and the governance gap most consequential. The principle it illustrates — that a legal obligation basis answers only the question of whether collection is lawful, not the question of how the collected data must be governed — is not unique to AML. But it is here, in KYC programmes, that the gap between compliant collection and compliant governance is most exposed.
02 — What KYC Actually Puts on Your Books
It is worth being precise about what AML-mandated KYC collection actually generates, because the data profile is frequently understated in governance discussions.
At onboarding, a standard KYC programme collects government-issued identity documents, date and place of birth, residential address, nationality, and — increasingly — biometric data for liveness checks. For crypto businesses specifically, the onboarding process also collects wallet addresses and links them to the verified identity.
Once that linkage exists, the entire on-chain transaction history associated with that wallet address becomes personally identifiable data. Not prospective — retroactive to the first transaction the wallet ever made. A wallet address that was previously pseudonymous becomes, from the moment of KYC linkage, a precise record of every transaction that address has ever executed.
A single KYC event does not create a record of who someone is. It creates a record of who someone is, what they own, and everything they have ever done with it in that ecosystem.
Retention requirements compound the exposure. Most AML frameworks mandate retention of five to ten years from the end of the customer relationship. In practical terms, this means that comprehensive financial identity data — including the wallet-to-identity linkage and the retroactive transaction history — is retained and queryable for years after the customer relationship ends.
The data profile that KYC compliance puts on an institution's books — identity, biometrics, financial history, transaction patterns, wallet-to-identity linkages — is not ordinary financial services data. It is among the most sensitive, most targeted, and most complete profiles of individual financial behaviour that any private institution holds.
03 — What Privacy Law Then Requires
The legal obligation basis — Article 6(1)(c) under GDPR and its equivalents under other privacy frameworks — is widely understood as the instrument that authorises KYC collection. This understanding is correct but incomplete.
The legal obligation basis establishes a lawful ground for processing. It does not disapply the other obligations that privacy law imposes on that processing. The following is a non-exhaustive account of what it does not suspend.
Privacy law requires that even legally-mandated collection be limited to what is strictly necessary for the specific legal purpose. The AML framework defines minimum collection requirements; it does not define maximum authorised collection. Fields captured for workflow convenience — but not required by the AML rule itself — are not covered by the legal obligation basis. This distinction is operationally significant: most KYC workflows collect more than the AML minimum, often because the data is commercially useful and because collection is technically easy.
A statutory retention minimum — "retain for five years" — is a floor, not a ceiling, and not an instruction to keep everything indefinitely. Privacy law requires that retention periods be defined for each data category, aligned to purpose, and actively enforced through deletion. Many KYC governance programmes have retention schedules that specify minimums. Far fewer have deletion programmes that enforce them.
When KYC data is transferred to a third party — whether a KYC vendor, a correspondent institution, or a counterparty VASP under Travel Rule obligations — the transferring institution does not transfer its privacy law obligations along with the data. It retains accountability and must ensure that the recipient provides adequate protections through contract, adequacy determination, or equivalent mechanism.
The obligation to implement appropriate technical and organisational security measures is calibrated to the nature of the data. KYC data — government IDs, biometrics, financial history, wallet-to-identity linkages — sits at the upper end of the risk spectrum. Security measures appropriate for average financial services data are not appropriate for KYC data. The Coinbase and Ledger cases below illustrate what happens when security investment does not reflect the actual value and sensitivity of the data held.
The legal obligation basis limits some individual rights — an institution cannot delete KYC data that it is legally required to retain. But it does not suspend all individual rights. Individuals retain the right to access their data, the right to rectification, the right to information about processing, and — under many frameworks — the right to know about cross-border transfers. The legal obligation basis covers retention. It does not cover the institution's failure to respond to access requests or correct inaccurate data.
04 — Where the Tension Becomes Harm: Three Cases
The following three cases are not chosen for their severity, though each is serious. They are chosen because each illustrates a different dimension of what happens when KYC compliance and privacy governance are treated as separate exercises.
In 2025, Coinbase disclosed that data on approximately 70,000 users had been accessed by internal contractors who were subsequently bribed. The compromised records included names, residential addresses, partial Social Security numbers, government-issued identity documents, and account details — the precise data profile that a standard KYC programme generates.
The estimated remediation cost was USD 180–400 million. The DoJ launched an investigation. Class action proceedings followed. The SEC made inquiries into KYC governance practices. The breach was a centralised access problem: the data that regulators required Coinbase to collect and retain was held in systems that contractors with legitimate access had the ability to exfiltrate.
The dimension illustrated: security investment calibrated to regulatory requirement, not to actual data sensitivity. The legal obligation to collect did not create the security architecture needed to protect what was collected.
Ledger, a hardware cryptocurrency wallet manufacturer, suffered a data breach in mid-2020 affecting its customer database. The breach exposed the names, postal addresses, email addresses, and telephone numbers of 272,000 customers.
The consequences were not confined to digital harm. In the months following the breach, affected customers reported targeted phishing campaigns, SIM-swapping attacks, and physical threats — including armed robbery attempts at home addresses. The data that Ledger had collected for ordinary e-commerce purposes became a targeting database for individuals known to hold cryptocurrency.
Ledger's breach did not involve government-mandated KYC collection — the company's product is non-custodial and formal KYC obligations did not fully apply at the time. The case is included here because it illustrates a principle that applies with greater force to mandated KYC collection: data collected about people who hold cryptocurrency is qualitatively different from ordinary consumer data. It identifies individuals by name, home address, and financial behaviour. The Coinbase breach involved regulated KYC data; the Ledger breach involved ordinary commercial data. The physical safety consequences were similar.
The dimension illustrated: the sensitivity of data about crypto holders does not derive from its regulatory classification. It derives from what the data enables — and data governance must reflect that reality.
The ACE Exchange case represents the far end of the spectrum — not a governance failure through negligence, but a governance failure by design. ACE and its affiliated Alfred Wallet platform collected KYC data at physical storefronts, creating the appearance of a regulated, legitimate exchange. The underlying data architecture was structured to do something different.
The wallet was designed as a custodial system with off-chain transaction flows — meaning transactions were not publicly queryable on the blockchain. The backend included wallet address manipulation capability. The architecture combined identity data (from KYC) with financial control (from the custodial structure) in a way that inverted every principle of data governance: data was collected for regulatory cover, retained for operational control, and structured to evade accountability.
The KYC collection was real. Users attended physical storefronts, submitted identity information, and received what appeared to be a legitimate account. The legal obligation basis authorised the collection. The governance that should have surrounded it did not exist — by design. Losses exceeded NT$800 million. Approximately 1,200 victims were identified. The Taichung and Changhua prosecutors' offices indicted the company's founder, chief strategy officer, system engineer, and compliance personnel under the Organised Crime Prevention Act.
The dimension illustrated: the legal obligation basis authorised the collection. It did not create the governance that should have surrounded it. That gap — between the legal right to collect and the obligation to govern — is where the harm in this case was structured.
05 — The Travel Rule Multiplier
VASPs The cases above concern data held at a single institution. For virtual asset service providers specifically, there is an additional structural amplifier built directly into the AML compliance framework: the Travel Rule.
FATF Recommendation 16 — now implemented in over 85 jurisdictions — requires that VASPs collect and transmit originator and beneficiary identity information with every qualifying virtual asset transfer. The EU's Transfer of Funds Regulation applies a zero-threshold rule since December 2024, meaning every transfer, regardless of amount, requires full identity transmission.
The practical consequence is that KYC data does not stay within the governance perimeter of the institution that collected it. It travels, with every qualifying transaction, to counterparty VASPs in other jurisdictions, under other regulatory regimes, with different data protection standards.
Under GDPR and most equivalent frameworks, this transmission is a data transfer to a third-party processor or controller. It requires a Data Processing Agreement — and, where the counterparty is in a jurisdiction without an adequacy determination — appropriate safeguards: Standard Contractual Clauses, Binding Corporate Rules, or equivalent mechanisms. Most Travel Rule compliance implementations do not include these safeguards as a matter of standard practice.
There is also a compounding risk that is rarely discussed: the data transmitted under the Travel Rule includes not just identity but implicitly a record of transaction behaviour. A sequence of Travel Rule transmissions, across multiple institutions, builds a cross-institutional transaction profile for each individual. No single institution holds the complete profile — but the profile exists, assembled across the institutions that received Travel Rule data, and its assembly is a foreseeable consequence of compliance with the rule.
Privacy-preserving technical approaches to Travel Rule compliance do exist — zero-knowledge proofs, encrypted envelopes, and threshold encryption have all been proposed and in some cases deployed. They are not yet standard practice.
For organisations that are not VASPs but transact with VASPs — institutional investors, treasury operations, corporate entities executing on-chain transactions — Travel Rule data about their transactions is collected and transmitted by the VASP counterparty. These organisations are not directly obligated by the Travel Rule, but their data is subject to it. The governance obligation that attaches to that data belongs to the institution that collected it.
06 — The Compliance Gap, Precisely
The gap between KYC compliance and privacy compliance is not theoretical. It is measurable, specific, and addressable. The table below maps where the gap sits across six dimensions.
| Dimension | KYC Position | What Privacy Law Requires | Where the Gap Sits |
|---|---|---|---|
| Data minimisation | Legal obligation basis covers collection of AML-mandated fields | Minimise even legally-mandated collection to what is strictly necessary for the specific purpose | Most KYC workflows collect beyond the AML minimum; additional fields are not covered by the legal obligation basis |
| Retention | AML mandates minimum retention periods (5–10 years) | Define retention periods per data category, aligned to purpose; actively enforce deletion when periods expire | Retention minimums are widely observed; deletion programmes that enforce the ceiling are not |
| Third-party accountability VASPs | Travel Rule requires transmission of identity data to counterparty VASPs | Data Processing Agreements with recipients; adequate safeguards for cross-border transfers | Travel Rule implementations rarely include DPAs with counterparty VASPs or analysis of transfer safeguards |
| Security | No specific AML security standard beyond general financial services baseline | Security calibrated to the actual nature and sensitivity of the data held | KYC data is treated as standard financial data; security investment does not reflect the full value profile |
| Cross-border transfers VASPs | Travel Rule transmissions cross jurisdictions as a structural feature of the rule | Adequate safeguards required for transfers outside jurisdictions with adequacy determinations | Travel Rule flows are not routinely analysed as cross-border data transfers under applicable privacy law |
| Individual rights | Legal obligation basis limits erasure during mandatory retention period | Access, rectification, and information rights survive; DSARs must be responded to | Legal obligation basis is frequently cited to deflect all rights requests, including those it does not actually suspend |
The pattern across all six dimensions is the same: the legal obligation basis makes collection easy and provides cover for it. It creates no automatic compliance across any of these dimensions — and regulators are increasingly aware of that distinction.
07 — What Good Governance Looks Like
The starting posture is a reframe. KYC data is not ordinary compliance data that happens to be sensitive. It is the most sensitive data most financial institutions hold — by volume, by completeness, and by the consequences of its misuse. Governance should reflect that reality.
In practical terms, this means the following.
Map every field collected, the legal basis for each, the retention period, who it is shared with, under what contractual terms, and whether any of those transfers implicate cross-border transfer requirements. Most institutions have AML data maps. Very few have applied a privacy law lens to the same map. The exercise will reveal collection beyond the AML minimum and third-party relationships that lack adequate contractual coverage.
Identify the minimum dataset that satisfies the AML obligation in each relevant jurisdiction, and make that the collection standard. Additional fields — however commercially useful — require a separate legal basis. If that separate basis does not exist, the field should not be collected. This is not a concession to privacy law at the expense of AML compliance. It is treating both bodies of law seriously, simultaneously.
A retention schedule tells you how long to keep data. A deletion programme tells you what happens when the retention period expires. Most KYC governance frameworks have the former. Few have the latter — an operational process that identifies records at end-of-retention, executes deletion across all systems where the data is held (including backups, analytics environments, and third-party processors), and produces an auditable record of completion.
Every institution receiving KYC data under Travel Rule obligations is processing personal data on your behalf or jointly with you, depending on the arrangement. A Data Processing Agreement is required. Where the counterparty is in a jurisdiction without an adequacy determination under GDPR or applicable equivalent, appropriate transfer safeguards — Standard Contractual Clauses or equivalent — are additionally required. This is not optional; it is a direct consequence of Travel Rule compliance under privacy law.
Access controls, encryption at rest and in transit, audit logging, insider threat detection, and incident response planning should all be calibrated to the sensitivity of KYC data — not to the baseline of average financial services data. The Coinbase case is the clearest illustration of what the alternative looks like: regulatory compliance with data retention requirements, paired with security investment that did not reflect the actual value of the data held.
Every time Travel Rule data crosses a jurisdiction boundary, a cross-border transfer analysis is required under applicable privacy frameworks. GDPR's Chapter V requirements, PIPL's outbound transfer rules, and equivalent provisions in PDPA, APPI, and other frameworks all apply to Travel Rule transmissions. The analysis should identify the jurisdiction of each counterparty, the applicable adequacy determination status, and the transfer mechanism in place. Most VASPs have not conducted this analysis. The enforcement risk is foreseeable.
08 — Closing
The KYC framework was designed to protect the financial system from illicit finance. It works by requiring institutions to know their customers — to collect, verify, and retain identity data at scale. The argument in this paper is not against that framework.
It is an argument that the obligation to collect creates a corresponding obligation to govern. The data that KYC programmes generate is not made safe by the legal requirement that created it. It is made safe by the governance that surrounds it — and that governance is the institution's responsibility, not the regulator's.
The enforcement signal is becoming clearer. Regulators are increasingly treating KYC data breaches not only as cybersecurity failures but as privacy compliance failures. The GDPR enforcement actions following the Ledger breach, the SEC's inquiry into Coinbase's KYC governance practices, and the FSC's sanctions against Taiwan VASPs for personal data management failures in 2024 all point in the same direction: the data that AML law requires you to hold is data that privacy law requires you to govern.
The gap between what KYC law requires and what privacy law then demands of that data is closable. It requires treating the two bodies of law as concurrent obligations rather than sequential ones, and it requires governance infrastructure that reflects the actual sensitivity of the data held.
The legal obligation created the data. The governance is the institution's responsibility.
How CloudVista Can Help
CloudVista works with financial institutions, fintech companies, and organisations with significant crypto exposure on the intersection of AML compliance and data privacy obligations — across GDPR, PIPL, PDPA, and their equivalents, and across sectors from virtual asset service providers to institutional investors navigating on-chain exposure.
- ›KYC Privacy Gap Assessment — data inventory with privacy law applied, identification of collection beyond the AML minimum, and gap assessment across minimisation, retention, third-party accountability, and individual rights. Data Privacy services →
- ›Travel Rule Data Governance — Data Processing Agreement framework for counterparty relationships, cross-border transfer analysis for Travel Rule flows, and privacy-by-design review of Travel Rule implementation. Data & AI Governance services →
- ›KYC Data Inventory and Minimisation Programme — field-level review of KYC collection against AML minimum requirements, deletion programme design, and retention enforcement infrastructure.
- ›Breach Response Programme Design — incident detection procedures, notification protocol aligned to the 72-hour GDPR window and equivalent requirements, and tabletop simulation for KYC data breach scenarios.
反洗錢 (AML) 法律要求金融機構與虛擬資產服務提供者大規模蒐集身份資料——加以驗證、保留數年,並在每筆符合條件的交易中跨機構傳輸。資料隱私法律則對所蒐集的一切資料課以完整的治理義務。多數合規計畫將這兩項義務視為前後相繼的工作步驟,但事實並非如此。本文審視這個缺口在實務中的樣貌、它在何處造成損害,以及對於希望同時遵循兩套法律的AML義務機構意味著什麼。
- AML法規強制要求的KYC蒐集,究竟在機構帳上留下什麼——以及為何資料輪廓在治理討論中普遍遭到低估
- 法律義務依據所授權的範圍,以及它並未暫停適用的義務
- 三件執法案例,分別呈現合規缺口的不同面向
- Travel Rule的倍增效應——VASP特有的額外結構性放大器
- 六個合規維度的缺口地圖,從資料最小化到個人權利
- 六項治理建議,以並行而非序列的方式處理KYC義務與隱私義務
法律義務催生了資料,但並未催生治理。這個區別,正是下一波執法行動的著力點——也是合規蒐集與合規治理之間缺口最為裸露之處。
第一節 — 框架弔詭
兩套法律體系同時規範同一批資料,在同一機構、同一時間運作。
其一——反洗錢 (AML) 法律,包含金融行動特別小組 (FATF) 建議、歐盟資金移轉規則 (TFR)、美國《銀行保密法》及超過85個司法管轄區的同等法規——規定:蒐集身份資料、進行驗證、保留數年,並在每筆符合條件的交易中跨機構傳輸。
其二——資料隱私法律,包含GDPR、中國《個人信息保護法》(PIPL)、台灣《個人資料保護法》(PDPA)、日本APPI、加拿大PIPEDA及其各地等同法規——規定:最小化蒐集範圍、保護所持有的資料、尊重個人的相關權利,並對資料的使用方式承擔問責義務。
這兩套法律同時、完整地適用於KYC資料。
授權蒐集資料的法律義務,並不規範資料在蒐集之後的處理方式。那是另一個問題——而多數合規計畫並未如此認識。
多數機構將這兩項義務視為先後相繼的工作:先滿足KYC要求,再另行處理隱私問題(如果有的話)。這是一個結構性錯誤。兩項義務是並行的——它們在同一時間、針對同一批資料、在同一個治理邊界內運作。
本文專就AML/KYC合規的脈絡審視這種張力——在此脈絡中,蒐集的法律義務最為明確,資料最為敏感,治理缺口的後果最為深遠。本文所呈現的原則——法律義務依據僅回答蒐集是否合法的問題,而非回答所蒐集的資料應如何治理的問題——並非AML所獨有。但在KYC計畫中,合規蒐集與合規治理之間的缺口,是暴露最為徹底之處。
第二節 — KYC實際在帳上留下什麼
有必要精確說明AML強制要求的KYC蒐集究竟產生了什麼資料,因為在治理討論中,這份資料輪廓經常遭到低估。
在入職時,標準KYC程序蒐集政府核發的身份證明文件、出生日期與地點、居住地址、國籍,以及——日益增多地——用於活體檢測的生物辨識資料。對虛擬資產業務而言,入職過程還蒐集錢包地址,並將其連結至已驗證的身份。
一旦這個連結建立,與該錢包地址相關的整條鏈上交易歷史,便成為可識別個人的資料——不是往後的,而是追溯至該錢包有史以來的第一筆交易。一個此前以假名形式存在的錢包地址,從KYC連結的那一刻起,便成為該地址曾執行的每一筆交易的精確記錄。
單一KYC事件所建立的,不是一份關於某人身份的記錄。而是一份關於此人是誰、擁有什麼、以及在這個生態系統中做過什麼的完整記錄。
留存要求加劇了風險敞口。多數AML框架要求在客戶關係終止後保留五至十年。實務上,這意味著全面的金融身份資料——包括錢包與身份的連結及追溯性交易歷史——在客戶關係結束後仍持續留存並可供查詢多年。
KYC合規在機構帳上所形成的資料輪廓——身份、生物辨識、金融歷史、交易模式、錢包對身份的連結——並非普通的金融服務資料。它是任何私人機構所持有的個人金融行為中,最敏感、最具針對性、也最完整的輪廓之一。
第三節 — 隱私法律隨後的要求
法律義務依據——GDPR第6條第1款第(c)項及其他隱私框架中的等同條款——普遍被理解為授權KYC蒐集的工具。這種理解正確,但並不完整。
法律義務依據確立了處理的合法依據,但它並未暫停隱私法律對該處理所課加的其他義務。以下是它所未暫停的內容(非詳盡清單)。
隱私法律要求,即使是法定義務所要求的蒐集,也應限於特定法律目的所嚴格必要的範圍。AML框架界定了蒐集的最低要求,但並未界定最高授權蒐集範圍。為工作流程便利而蒐集的欄位——但並非AML規則本身所要求的——並不受法律義務依據的涵蓋。這個區別具有重要的操作意義:多數KYC工作流程蒐集的資料超出AML最低要求,往往是因為這些資料在商業上有用,且在技術上蒐集容易。
法定留存最低期限——「保留五年」——是一個下限,而非上限,更不是無限期保留一切的指示。隱私法律要求每個資料類別分別界定留存期限、與目的保持一致,並透過刪除程序主動執行。許多KYC治理計畫備有規定最低留存期限的留存時程表,但具備執行刪除程序的卻寥寥無幾。
當KYC資料被傳輸至第三方——無論是KYC供應商、往來機構,或Travel Rule義務下的交易對手VASP——傳輸機構並不連同資料一起轉移其隱私法律義務。其仍保有問責責任,並必須確保接收方透過合約、充分性認定或其他適當機制提供充分的保護。
實施適當技術與組織安全措施的義務,係按資料性質校準的。KYC資料——政府核發身份證件、生物辨識、金融歷史、錢包對身份的連結——處於風險光譜的高端。適用於一般金融服務資料的安全措施,不足以應對KYC資料。下文所述的Coinbase和Ledger案例,說明了當安全投資未能反映所持資料的實際價值與敏感度時將發生什麼。
法律義務依據限制了部分個人權利——機構不能刪除其法定義務要求留存的KYC資料。但它並未暫停所有個人權利。個人仍保有存取資料的權利、更正的權利、知悉處理情況的權利,以及——在許多框架下——知悉跨境傳輸的權利。法律義務依據涵蓋留存,但不涵蓋機構未能回應存取請求或更正不準確資料的情形。
第四節 — 張力演變為傷害:三件案例
以下三件案例之所以入選,並非因其嚴重性(雖然每件都相當嚴重),而是因為每件案例各自呈現了KYC合規與隱私治理被視為各自獨立工作時所產生的不同面向。
2025年,Coinbase披露約70,000名用戶的資料遭到受賄的內部承包商存取。遭侵害的記錄包括姓名、居住地址、部分社會安全號碼、政府核發身份證件及帳戶詳情——正是標準KYC程序所產生的資料輪廓。
預估補救成本為1.8億至4億美元。司法部展開調查,集體訴訟隨之而來,美國證券交易委員會 (SEC) 就KYC治理實踐提出查詢。此次事件是一個集中存取的問題:監管機構要求Coinbase蒐集和保留的資料,被存放在擁有合法存取權限的承包商有能力竊取的系統中。
本案所呈現的面向:安全投資按監管要求校準,而非按實際資料敏感度校準。蒐集的法律義務並未催生保護所蒐集資料所需的安全架構。
硬體加密貨幣錢包製造商Ledger於2020年中遭受資料外洩,影響其客戶資料庫。此次外洩暴露了272,000名客戶的姓名、郵寄地址、電子郵件地址及電話號碼。
後果並不局限於數位層面。在外洩事件發生後的數月內,受影響的客戶報告了有針對性的網路釣魚攻擊、SIM卡劫持,以及人身威脅——包括在家庭住址發生的武裝搶劫未遂事件。Ledger為普通電子商務目的而蒐集的資料——送貨地址、聯絡資訊——成為針對已知持有加密貨幣人士的定向資料庫。
Ledger的外洩事件並不涉及政府強制要求的KYC蒐集——該公司的產品是非托管型,當時的正式KYC義務並不完全適用。本案之所以納入分析,是因為它說明了一個對強制KYC蒐集更具說服力的原則:關於加密貨幣持有者的蒐集資料,在性質上有別於一般消費者資料,因為它以姓名、家庭住址和金融行為來識別個人。Coinbase事件涉及的是受監管的KYC資料;Ledger事件涉及的是普通商業資料,但人身安全後果相似。
本案所呈現的面向:加密貨幣持有者相關資料的敏感性,並非源自其監管分類,而是源自該資料所能實現的目的——資料治理必須反映這個現實。
ACE Exchange案位於光譜的另一極端——不是由於疏失造成的治理失敗,而是出於設計的治理失敗。ACE及其關聯的Alfred Wallet平台在實體門市蒐集KYC資料,製造受監管、合法交易所的假象,而底層資料架構的設計目的卻截然不同。
該錢包被設計為托管系統,採用鏈下交易流——意即交易無法在區塊鏈上公開查詢。後端具有錢包地址操控功能。這個架構將來自KYC的身份資料與來自托管結構的財務控制合而為一,以一種顛覆資料治理每一項原則的方式運作:資料因監管掩護而蒐集,因運營控制而留存,並在架構上規避問責。
KYC蒐集是真實的。用戶前往實體門市、提交身份資訊,並獲得看似合法的帳戶。法律義務依據授權了蒐集,但本應圍繞其周邊的治理,卻出於設計而付之闕如。損失超過新台幣8億元,約1,200名受害者被確認。台中與彰化地方檢察署依組織犯罪防制條例起訴了該公司創辦人、首席策略官、系統工程師及合規人員。
本案所呈現的面向:法律義務依據授權了蒐集,但並未催生本應圍繞其周邊的治理。這個缺口——蒐集的法律權利與治理義務之間——正是本案危害的結構所在。
第五節 — Travel Rule的倍增效應
VASP專屬 上述案例關注的是單一機構所持有的資料。對虛擬資產服務提供者 (VASP) 而言,AML合規框架中還內建了一個額外的結構性放大器:Travel Rule(旅行規則)。
FATF第16號建議——目前已在超過85個司法管轄區實施——要求VASP在每筆符合條件的虛擬資產轉移中,蒐集並傳輸發起方和受益方的身份資訊。歐盟的資金移轉規則自2024年12月起適用零門檻規定,意即每筆轉移,無論金額大小,均需完整的身份傳輸。
實際後果是:KYC資料不會留在蒐集它的機構的治理邊界內。它隨著每筆符合條件的交易,傳輸至其他司法管轄區、其他監管制度、不同資料保護標準的交易對手VASP。
依據GDPR及多數等同框架,這種傳輸是向第三方處理者或控管者的資料傳輸,需要資料處理協議 (DPA),以及——在交易對手位於未獲充分性認定的司法管轄區時——適當的保護措施:標準合約條款 (SCCs)、具約束力的公司規則 (BCRs) 或等同機制。多數Travel Rule合規實施並未將這些保護措施作為標準實踐納入。
還有一個鮮少被討論的複合風險:依Travel Rule傳輸的資料,不僅包含身份,還隱含了一份交易行為記錄。跨越多個機構的一系列Travel Rule傳輸,為每個個人建立了一份跨機構的交易輪廓。沒有任何單一機構持有完整的輪廓——但這份輪廓確實存在,由所有收到Travel Rule資料的機構共同拼湊而成,而其形成是遵守規則的可預見後果。
Travel Rule合規確實存在保護隱私的技術方法——零知識證明、加密封套和門限加密均已被提出,部分已付諸實施。但這些方法尚未成為標準實踐。
對於並非VASP、但與VASP進行交易的機構——機構投資者、財務管理部門、執行鏈上交易的企業法人——其交易的Travel Rule資料由VASP交易對手蒐集和傳輸。這些機構不直接受Travel Rule義務約束,但其資料受其規範。附著於該資料的治理義務,屬於蒐集它的機構。
第六節 — 合規缺口的精確定位
KYC合規與隱私合規之間的缺口並非理論問題,它是可衡量、具體且可解決的。下表在六個維度上映射了缺口所在。
| 維度 | KYC所處立場 | 隱私法律的要求 | 缺口所在 |
|---|---|---|---|
| 資料最小化 | 法律義務依據涵蓋AML強制要求的欄位 | 即使是法定義務要求的蒐集,也應限於特定目的所嚴格必要的範圍 | 多數KYC工作流程蒐集超出AML最低要求;額外欄位不受法律義務依據涵蓋 |
| 留存期限 | AML規定最低留存期限(5至10年) | 依資料類別分別界定留存期限、與目的保持一致;在期限屆滿時主動執行刪除 | 留存最低期限普遍被遵守;執行上限的刪除程序則付之闕如 |
| 第三方問責 VASP | Travel Rule要求向交易對手VASP傳輸身份資料 | 與接收方簽訂資料處理協議 (DPA);跨境傳輸須有適當保護措施 | Travel Rule實施鮮少包含與交易對手VASP的DPA或傳輸保護措施分析 |
| 安全措施 | AML法規無特定安全標準,僅有一般金融服務基準 | 安全措施須按所持資料的實際性質與敏感度校準 | KYC資料被當作標準金融資料對待;安全投資未能反映完整的資料價值輪廓 |
| 跨境傳輸 VASP | Travel Rule傳輸跨越司法管轄區,是規則的結構性特徵 | 向未獲充分性認定之司法管轄區以外傳輸,須有適當保護措施 | Travel Rule流動鮮少依適用隱私法律被分析為跨境資料傳輸 |
| 個人權利 | 法律義務依據在強制留存期間內限制刪除權 | 存取、更正和知悉資訊的權利仍然存在;資料主體存取請求 (DSAR) 必須予以回應 | 法律義務依據頻繁被援引以迴避所有權利請求,包括實際上並未暫停的那些 |
六個維度的模式相同:法律義務依據使蒐集變得容易,並為其提供了保護傘,但在這六個維度中,它均未自動創設合規性——而監管機構對這個區別的認識日益清晰。
第七節 — 良好治理的樣貌
起點是一個框架的重塑。KYC資料不是碰巧比較敏感的普通合規資料,而是多數金融機構所持有的最敏感資料——無論從數量、完整性,還是從其被濫用的後果來看。治理應當反映這個現實。
在實務上,這意味著以下各點。
逐一梳理每個蒐集欄位、各自的法律依據、留存期限、共享對象、合約條款,以及是否涉及跨境傳輸要求。多數機構有AML資料地圖,但鮮有人以隱私法律的視角審視同一份地圖。這個工作將揭示超出AML最低要求的蒐集,以及缺乏充分合約保障的第三方關係。
確定在各相關司法管轄區滿足AML義務所需的最低資料集,並以此作為蒐集標準。額外欄位——無論商業上多麼有用——均需要獨立的法律依據。如果這個獨立依據不存在,該欄位就不應被蒐集。這不是以犧牲AML合規為代價向隱私法律讓步,而是同時認真對待兩套法律。
留存時程表告訴你保留資料多久。刪除程序告訴你留存期限屆滿時會發生什麼。多數KYC治理框架備有前者,鮮有後者——一個能識別到期記錄、在所有持有資料的系統(包括備份、分析環境和第三方處理者)執行刪除,並產生可供稽核的完成記錄的操作流程。
每個依Travel Rule義務接收KYC資料的機構,都是代表你處理個人資料,或與你共同處理,視具體安排而定。資料處理協議 (DPA) 是必要的。在交易對手位於GDPR或適用等同法規下未獲充分性認定的司法管轄區時,還另需適當的傳輸保護措施——標準合約條款 (SCCs) 或等同機制。這不是可選的,而是Travel Rule合規在隱私法律下的直接後果。
存取控制、靜態和傳輸中的加密、稽核日誌、內部威脅偵測和事件回應規劃,都應按KYC資料的敏感度校準——而非按一般金融服務資料的基準。Coinbase案是最清晰的說明:在資料留存要求上達到監管合規,卻配以未能反映所持資料實際價值的安全投資。
每當Travel Rule資料跨越司法管轄區邊界,依適用隱私框架即需進行跨境傳輸分析。GDPR第五章要求、PIPL境外傳輸規則,以及PDPA、APPI等其他框架中的等同條款,均適用於Travel Rule傳輸。分析應確認每個交易對手的司法管轄區、適用的充分性認定狀態,以及已到位的傳輸機制。多數VASP從未進行過這項分析。執法風險是可預見的。
第八節 — 結語
KYC框架的設計初衷,是保護金融體系免受非法金融的侵害。它透過要求機構了解其客戶——大規模蒐集、驗證和留存身份資料——來發揮作用。本文的論點並非反對這個框架。
本文的論點是:蒐集義務催生了相應的治理義務。KYC程序所產生的資料,並非因創造它的法律義務而得到保護,而是因圍繞其周邊的治理而得到保護——而那份治理是機構的責任,不是監管機構的責任。
執法信號正在變得愈加清晰。監管機構越來越多地將KYC資料外洩不僅視為網路安全失敗,也視為隱私合規失敗。Ledger外洩事件後的GDPR執法行動、SEC對Coinbase KYC治理實踐的查詢,以及金融監督管理委員會 (FSC) 在2024年因個人資料管理缺失而對台灣VASP的裁罰,都指向同一方向:AML法律要求你持有的資料,也是隱私法律要求你治理的資料。
KYC法律所要求與隱私法律隨後對該資料所要求之間的缺口,是可以彌合的。這需要將兩套法律視為並行義務而非序列義務,也需要反映所持資料實際敏感度的治理基礎設施。
法律義務催生了資料。治理是機構的責任。
CloudVista 如何協助
CloudVista 與金融機構、金融科技公司以及具有重大加密資產敞口的機構合作,處理AML合規與資料隱私義務交匯所產生的問題——跨GDPR、PIPL、PDPA及其等同框架,以及虛擬資產服務提供者、具鏈上敞口的機構投資者和跨境Travel Rule實施等不同場景。
- ›KYC隱私缺口評估 — 以隱私法律視角進行的資料清點、識別超出AML最低要求的蒐集,以及跨最小化、留存、第三方問責和個人權利各維度的缺口評估。資料隱私服務 →
- ›Travel Rule資料治理 — 交易對手關係的資料處理協議框架、Travel Rule流動的跨境傳輸分析,以及Travel Rule實施的隱私設計審查。資料與AI治理服務 →
- ›KYC資料清點與最小化計畫 — 依AML最低要求對KYC蒐集進行欄位層級審查、刪除程序設計,以及留存執行基礎設施建立。
- ›事件回應計畫設計 — 事件偵測程序、對齊GDPR 72小時時限及等同要求的通知協議,以及針對KYC資料外洩情境的桌面推演。