Privacy guide

Ask better questions about personal data

You can ask what a provider needs, why it needs it, which rule or policy applies, how the information is used, and whether another compliant route exists.

Pause before answering

A provider may ask why you are buying cryptocurrency, who will receive it, what it will be used for, or where the money came from. A question like this can be part of a legitimate customer or transaction review. It can also come from the provider's own risk policy rather than a rule that applies identically everywhere.

The questions below apply to personal-data collection in general. For answers about why you are buying and what you plan to do with the cryptocurrency, read when a platform asks about your intended use.

You do not need to react angrily or answer immediately. Ask for enough context to make an informed choice.

Ask whether the information is mandatory

Useful wording includes:

  • “Is this information required to complete this transaction?”
  • “Is the request based on applicable law, your provider policy, or an optional service?”
  • “Can you identify the applicable requirement or explain the risk concern?”
  • “What happens if I choose not to provide it?”
  • “Is there another compliant purchase method or limit with different requirements?”

A support agent may need to refer the question to a privacy, compliance, or legal team. Ask for the answer in writing when the distinction matters.

Ask about purpose and scope

Before sharing personal information, ask:

  • “What specific purpose will this information serve?”
  • “Which fields are required and which are optional?”
  • “Can the purpose be met with less detailed information?”
  • “Will this information be used for marketing, profiling, or another secondary purpose?”
  • “Will the provider make an automated decision using it?”

Provide accurate information when it is genuinely required. Do not submit extra documents “just in case” or add unrelated personal details to a free-text field.

Ask about retention and sharing

The provider should be able to point you to information about its handling practices. Ask:

  • how long the information and document copies will be kept;
  • when the retention period begins and what determines it;
  • which companies process or store the data;
  • whether data is transferred to another country;
  • which authorities or transaction counterparties may receive it;
  • how you can request access, correction, or deletion where available;
  • how to contact the person responsible for privacy questions.

“We keep it for compliance” is not a complete explanation when a more specific purpose and period can reasonably be provided.

Protect sensitive submissions

Use only the provider's official upload page or app. Check the company name and domain carefully. Do not upload identity documents through social media, a personal email address, or remote-support software.

Never provide a wallet recovery phrase, private key, account password, or unsolicited one-time code. Those items do not verify who you are. They give access to an account or wallet.

Decide without evading requirements

After receiving the explanation, you can provide the minimum accurate information genuinely required, pause while you seek advice, or choose another compliant provider. Do not split transactions, use someone else's identity, or misdescribe the recipient to avoid a legitimate control.

If a provider will not explain an unusual request, that lack of transparency is useful information when deciding whether to continue.

Official references

The Office of the Privacy Commissioner of Canada explains principles for identifying purposes, limiting collection, and limiting retention. The GDPR similarly includes transparency, purpose limitation, and data minimisation in Article 5.