Privacy guide

Why requirements vary

There is no single worldwide KYC checklist. Applicable law, provider type, location, product, payment method, transaction details, and risk assessment can all change the process.

Rules are implemented locally

International standards influence how countries address financial crime, but each country implements its own laws, thresholds, regulators, and procedures. A provider must consider the rules that apply to its company, service, customer, and transaction.

This means a process used in one country should not be presented as the universal legal rule. It also means an old description of a provider's requirements may no longer be accurate.

Providers make their own risk decisions too

Applicable law is only one layer. Providers also create account, fraud, payment, security, and risk policies. Those policies can be stricter than the legal minimum or can differ between providers serving the same location.

A provider question may therefore fit one of three categories:

  1. Applicable requirement: the provider says a law or regulator requires the information for this transaction.
  2. Provider policy: the provider requires it under its own risk or service rules.
  3. Optional use: the information supports a feature, personalization, analytics, or marketing that is not necessary for the transaction.

The category affects your choices. Ask the provider to identify it instead of assuming.

Transaction details can change the process

Requirements may differ according to:

  • your country of residence and current location;
  • the country and legal entity providing the service;
  • account opening compared with a one-time purchase;
  • card, bank, cash, mobile-wallet, or local payment methods;
  • transaction amount, frequency, or pattern;
  • personal-wallet delivery compared with vendor custody;
  • a wallet you control compared with a third-party recipient;
  • currency, network, and cross-border details;
  • information already verified and whether it remains current;
  • a fraud, sanctions, or other risk alert.

These factors explain why two users can see different screens. They do not prove that every additional question is required by law.

What to do when a provider says “required”

Ask whether it means required by applicable law or required by provider policy. Request the relevant privacy notice, terms, help page, or written explanation. Ask what minimum information satisfies the requirement and what happens if you decline.

Do not ask support to help bypass a control. Do not use false information or someone else's account. If you are uncomfortable with the answer, pause before paying and compare another compliant provider available in your location.

For an important or disputed request, seek advice from a qualified professional or the relevant privacy or financial regulator. This website cannot determine which rule applies to an individual transaction.

Avoid fixed privacy promises

Labels such as “no KYC,” “anonymous,” or “private” can leave out important conditions. A provider may still collect device, payment, transaction, or network information, and it may introduce checks when a limit or risk condition is reached.

Read the current rules for the exact provider, location, payment method, amount, currency, network, and destination before relying on a privacy claim.

Official reference

The Financial Action Task Force describes a risk-based approach for virtual assets and service providers, while its virtual-assets overview notes that countries and providers implement customer due diligence and related controls. Implementation and provider policy are not identical in every place or transaction.