SEC Commissioner Seeks End to KYC Honeypots with Reusable Digital Credentials
US Securities and Exchange Commission (SEC) Commissioner Hester Peirce is calling for financial institutions to stop stockpiling customer data after recent security incidents exposed the cost of mandatory identity collection. According to her, society has reached a crossroads where it can either continue with the status quo of more data collection, intermediary surveillance, and 'know your customer' requirements or use new technologies to improve crime detection while collecting less personal information.
Pierce cited recent security incidents at Revolut and Coinbase as examples of how breaches can turn KYC records into targets for extortion and impersonation. She argued that technology already exists to reduce the amount of customer data collected and shared between institutions, and suggested using reusable digital credentials to establish facts about customers without requiring them to reveal their personal information.
The question of whether institutions need particular pieces of information or merely need confirmation of certain facts is becoming increasingly relevant as Washington builds a new compliance regime for stablecoins. The GENIUS Act requires permitted payment stablecoin issuers to maintain customer-identification programs, and regulators are proposing rules that would continue requiring covered issuers to obtain and retain identifying information from customers.
Regulators have left the question open in the proposed stablecoin rule, asking whether the final rule should address digital identity systems or verifiable credentials. This creates room for the final rules to determine how much duplicate collection survives, and whether compliance requires building databases containing customer identity information or investing in systems designed to verify required attributes while holding less raw data.