U.S. Securities and Exchange Commission (SEC) Commissioner Hester Peirce has called on financial institutions to stop accumulating massive stockpiles of customer data, advocating instead for reusable digital credentials to eliminate high-risk Know Your Customer (KYC) data honeypots.
Speaking on her own behalf, Peirce urged regulators and firms to adopt attribute-based credentials. These technologies allow institutions to verify specific facts—such as age, citizenship, or sanctions compliance—without needing to collect or store raw underlying personal records. Asking "Does more than one firm need to collect it?", Peirce argued that technology already exists to reduce data exposure.
Key Takeaways
- Hester Peirce proposes attribute-based digital credentials to limit identity surveillance and corporate data collection.
- Recent breaches compromised 69,461 Coinbase users and exposed customer identity files at Revolut.
- Implementation rules for the GENIUS Act threaten to expand mandatory five-year customer identity retention to stablecoin issuers.
High-Profile Breaches Highlight Systemic Risks
Peirce's remarks follow a series of security incidents where institutions accumulated identity records to satisfy anti-money laundering (AML) mandates. Last year, a security breach at Coinbase impacted 69,461 customers after attackers bribed overseas support staff. Stolen records included customer names, addresses, phone numbers, email addresses, partial Social Security numbers, government ID images, account balances, and transaction histories.
Following the breach, Coinbase Chief Executive Officer Brian Armstrong challenged current AML data mandates, stating, "We don't want to collect it, and our customers hate it," while calling on Congress to review the Bank Secrecy Act.
More recently, Revolut disclosed an incident where an unauthorized party utilized a legitimate government email domain to submit fraudulent data requests. The breach exposed customer names, contact details, passport and driver's license copies, verification selfies, and transaction histories, though Revolut confirmed customer funds remained secure.
Warning against expanding identity collection, Peirce stated: "Today society is at a crossroads. Down one path lies the status quo: more data collection, more intermediary surveillance, more 'know your customer' requirements that turn our financial rails into a panopticon. Down the other path lies an opportunity to use new technologies to improve our ability to catch criminals while collecting less personal information than ever before, and monitoring more sparingly to protect Americans’ privacy."
GENIUS Act Stablecoin Rules Threaten Further Data Collection
The issue comes as federal agencies establish regulatory frameworks for digital asset issuers. Under proposed Federal Reserve rules to implement the GENIUS Act for stablecoins, permitted payment stablecoin issuers must collect customer names, dates of birth or formation, addresses, and ID numbers for direct issuance or redemption accounts.
Under these rules, issuers would be required to retain identity records for five years after an account closes, while verification logs must be kept for five years post-creation. Although FinCEN confirmed banks may incorporate government-issued mobile driver's licenses into customer identification programs, current regulatory proposals fall short of the portable zero-knowledge credential system Peirce advocated.
Why It Matters
Mandatory KYC data retention has unintentionally transformed financial compliance databases into prime targets for extortion and social-engineering attacks. By requiring companies to act as perpetual data vaults, traditional regulatory frameworks increase security risks for consumers even when financial private keys remain uncompromised. If regulators adopt Peirce's vision for attribute-based credentials within stablecoin and crypto frameworks, the industry could set a global standard for privacy-preserving compliance without sacrificing law enforcement capabilities.