Tell HN: Coinbase keeps photos of your ID indefinitely

I verified my identity with Coinbase in 2017. I recently submitted a privacy access request and Coinbase sent me back unredacted photos of my ID, as well as previous addresses and phone numbers I no longer possess. I’m not sure if this is due to regulation, I’ve worked with ID verification and sensitive data was redacted after 30 days. Indefinite retention seems pretty dangerous. There have been quite a few reports of Coinbase account takeovers, so this provides a vector for bad actors to gain full copies of your ID. Not to mention the data being leaked if Coinbase itself is hacked.
Story Published at: February 2, 2023 at 08:22PM