The independent comparison desk Independent resource Disclaimer: This is not the official CryptoCompare website. cryptocompare.uk is an independent, unaffiliated guide. All product facts are sourced from the official cryptocompare.com site and public documentation.

Compare Identity Verification Systems for Crypto: Who Checks Your Passport, and What Happens Next

Every regulated exchange will, at some point, ask you to photograph your passport and your face. Most people comply in ninety seconds without asking the only questions that matter: who is processing that photo, where it is stored, and for how long. This guide compares the identity verification systems behind crypto onboarding — the same way an auditor would, with the marketing switched off.

If you want to compare identity verification systems for crypto, you first have to accept an uncomfortable fact: when an exchange “verifies” you, the exchange itself usually does almost nothing. Your passport photo travels to a third-party KYC provider — Sumsub, Onfido, Jumio, Veriff, Persona, iDenfy or one of a dozen others — whose name you were never asked to approve and whose privacy policy you have never read. That provider runs document forensics, checks that your face is a live human and not a printout, screens your name against sanctions lists, and returns a verdict. The exchange sees “approved”. The provider, in many setups, keeps the data. This page maps that hidden industry: what KYC verification actually checks, how the major providers differ, what happens to your documents after upload, and how to protect yourself before you ever press “submit”.

We write from the position we always write from: independent, unaffiliated, cynical about vendor marketing. Where we quote a specific capability — document coverage, verification speed — it comes from the provider’s own official website, and you should treat it as a sales claim until proven in your own onboarding. Nobody on this page is selling you a verification.

2024
MiCA fully in force in the EU
€0
EU Travel Rule threshold — every transfer counts
5 yrs
Typical AML record-keeping after account closure
1
Passport — you can’t rotate it like a password

What KYC and AML actually are — and why every regulated venue demands them

KYC (“know your customer”) is the identification step: proving you are a real, specific person. AML (anti-money-laundering) is the ongoing programme it feeds: screening you against sanctions and politically-exposed-person lists, monitoring your transactions for patterns that resemble laundering, and reporting suspicions to financial-intelligence units. Exchanges do not run KYC because they enjoy friction — friction costs them customers at the exact moment of sign-up. They run it because the law leaves them no choice, and in 2026 the law is tighter than it has ever been:

  • MiCA — the EU’s Markets in Crypto-Assets regulation — has been fully in force since the end of 2024. Crypto-asset service providers now need authorisation in an EU member state, and that licence comes welded to full AML obligations. There is no “light” tier.
  • The Travel Rule requires exchanges to attach sender and recipient identity information to crypto transfers between service providers, the way banks have long done for wires. In the EU it applies from the first euro — no de-minimis threshold. The UK has enforced its own version since September 2023.
  • In the UK, cryptoasset businesses must register with the FCA under the Money Laundering Regulations before serving UK customers at all, and the FCA has rejected a large share of applicants. The days of an exchange “sort of” serving the UK are over.

The practical consequence: any venue that lets you deposit fiat, trade, and withdraw without ever seeing your ID is either operating outside these regimes on purpose, or lying about where it operates. Both should worry you — we come back to that below. And note the custody angle that runs through everything on this site: an exchange account is a bank-like claim, not a vault. The exchange holds the keys; KYC is the price of that arrangement. A non-custodial wallet — your personal safe, where a lost seed phrase means no support desk on Earth can help — asks for no ID at all, because there is no company in the middle. Our wallet comparison guide covers that side of the fence.

The crypto KYC provider landscape in 2026

Six names dominate crypto onboarding. You rarely choose between them — the exchange does — but knowing who they are tells you a lot about where your passport goes. All capability claims below are taken from the providers’ official websites and marketing pages as of mid-2026; treat exact figures as vendor-stated, and check the official page before relying on any of them.

ProviderDocument coverage (vendor-stated)Liveness detectionTypical verification time (vendor-stated)Data retention stance
SumsubClaims coverage of thousands of ID document types across 220+ countries and territories, per its official siteActive and passive liveness plus deepfake detection; heavily marketed since the 2024–25 wave of AI-generated fraudAdvertises average checks in under a minute for most usersPositions itself as GDPR-compliant with configurable retention set by the client platform; the exchange, not you, picks the retention period
Onfido (Entrust)Claims support for roughly 2,500 document types across most of the world’s jurisdictions, per its official siteMotion-based liveness (“turn your head”) plus passive video analysisAdvertises most automated checks completing in seconds to minutesAcquired by Entrust in 2024; publishes GDPR/UK-GDPR documentation and acts as processor for client-defined retention
JumioClaims 5,000+ ID types from 200+ countries and territories, per its official siteCertified liveness with screen-replay and mask detectionAdvertises decisions in seconds for automated flows; manual review adds timeLong-standing enterprise player; retention configurable per client, with published GDPR and ISO/SOC compliance claims
VeriffClaims one of the largest coverage sets in the industry — over 11,000 document specimens from 230+ countries and territories, per its official siteVideo-first approach; analyses the full session, not a single selfie frameAdvertises most decisions in well under a minuteEstonian company under EU jurisdiction by default; GDPR-native, retention driven by client configuration
PersonaGlobal document coverage with a configurable “building blocks” model rather than one fixed flow, per its official siteSelfie and video liveness modules that clients switch on per risk tierDepends entirely on how the client assembles the flow — from near-instant to manual reviewUS-based; publishes GDPR/CCPA documentation, retention set by the client platform
iDenfyClaims 3,000+ document types from 200+ countries, per its official site3D liveness with human review as a backstop — every automated decision can be double-checked by an analystAdvertises rapid automated checks with human review adding minutes, not daysLithuanian, EU-jurisdiction; markets GDPR compliance and per-client retention configuration prominently

Read that last column again, because it is the one that matters most and the one nobody advertises on the sign-up screen: in almost every deployment, the exchange decides how long the KYC provider keeps your documents, within the bounds of AML law. The provider is legally a “processor”; the exchange is the “controller”. When you want your passport photo deleted, your GDPR request goes to the exchange — and the exchange will usually answer that AML law obliges it to retain records for around five years after your relationship ends. That answer is, annoyingly, correct.

What actually happens to your passport photo after upload

Walk through the pipeline. You photograph your passport and face inside the exchange’s app. The images travel — over TLS, if everyone did their job — to the KYC provider’s infrastructure. There they are processed: the document’s security features (MRZ checksum, fonts, holograms where detectable) are analysed, your selfie is matched to the document photo, the liveness model checks you are not a screen, a mask or an AI-generated face, and your name and date of birth are screened against sanctions and PEP lists. A verdict returns to the exchange in seconds or minutes. So far, so clean.

Then comes storage. Your document images, the biometric template derived from your face, and the extracted data typically remain on file — split between the provider and the exchange — for the life of your account plus the AML retention period. That makes KYC databases some of the most attractive targets in the industry: a database of passports with matching live selfies is exactly what an identity thief needs to open accounts elsewhere. The industry’s history here is not reassuring. In 2019, images alleged to be Binance customers’ KYC photos circulated publicly, with the exchange pointing at a third-party vendor from an earlier era. In 2024, security reporting revealed that credentials at AU10TIX — a verification vendor used by major consumer platforms — had been left exposed, potentially opening access to users’ identity documents. Neither incident, according to public reporting, involved the six providers in the table above, but both illustrate the structural point: every extra copy of your passport is an extra breach waiting for a date.

Your GDPR rights, honestly stated: if you are in the EU or UK, you can demand access to the data held about you (Article 15), correction of errors (Article 16), and erasure (Article 17) — but erasure yields to legal retention duties. What you can realistically achieve: confirmation of exactly what is stored and where, deletion after the statutory retention clock runs out, and deletion of anything collected beyond what AML law requires. File the request with the exchange, in writing, and mention the KYC vendor by name if you know it.

Verification levels: what each tier unlocks

Exchanges almost never run a single all-or-nothing check. Onboarding is tiered, and the tiers map to risk:

  1. Email-only / unverified. On regulated venues in 2026 this tier is close to decorative: you can browse markets and sometimes deposit crypto, but fiat rails and withdrawals are locked. MiCA and FCA rules have all but killed the old “trade freely until you want fiat” model.
  2. Basic KYC. Government ID plus a liveness selfie, sometimes proof of address. This unlocks fiat deposits, trading and withdrawals up to daily and monthly ceilings that vary wildly by venue — check the official limits page of your exchange rather than trusting any third-party table, ours included. For most retail users this tier is the terminal stop.
  3. Enhanced due diligence (EDD). Triggered by large volumes, corporate accounts, high-risk jurisdictions or suspicious patterns. Expect source-of-funds questionnaires, bank statements, payslips or tax returns, and sometimes a video call. Unpleasant, slow, and non-negotiable: refuse, and the account gets restricted — often with your funds inside until you comply.

That last clause deserves emphasis. The most common KYC horror story of the past few years is not a rejected sign-up; it is a user who passed basic KYC, deposited meaningful money, and then hit an EDD wall on withdrawal. Plan for it: keep records of where your crypto came from, and read our guide to comparing crypto exchanges — a venue’s reputation for withdrawal-time document demands is a selection criterion, not a footnote. The same logic applies when cashing out; the off-ramp comparison covers which exit routes ask for what.

Why “no-KYC exchanges” are shrinking — and what using one actually risks

Search interest in no-KYC venues remains stubbornly high, and the supply keeps shrinking. Under MiCA, an unlicensed platform cannot lawfully serve EU customers; the FCA position in the UK is equally blunt. What remains are offshore entities in thin jurisdictions, decentralised protocols (a genuinely different category — a DEX smart contract has no operator to run KYC, though the fiat on-ramps around it do), and outright grey-market operations. If you are tempted, price in the real risks rather than the imagined ones:

  • Frozen funds with no appeal. No-KYC venues routinely freeze withdrawals “pending verification” — demanding, ironically, more documents than a regulated exchange ever would, precisely when you have the least leverage.
  • Exit scams. A platform with no licence, no named executives and no jurisdiction has no reason not to disappear with deposits. It has happened repeatedly and will happen again.
  • No recourse. No ombudsman, no regulator to complain to, no bankruptcy process in which you are a creditor. Your loss is a tweet, not a claim.
  • Tainted coins. Funds that have passed through unregulated venues score worse in the chain-analytics tools regulated platforms use, and can trigger the very EDD you were trying to avoid — on the next exchange you touch.

Auditor’s rule: the cheapest KYC you will ever do is the one at a regulated exchange on day one. The most expensive is the one demanded by an offshore platform that already holds your money.

The 2026 privacy trend: prove who you are without handing over the passport

The interesting news is that the industry knows the current model — scatter passport copies across dozens of vendor databases — is indefensible, and three replacement patterns are maturing:

Reusable KYC

Verify once with an identity provider, then share a signed attestation with each new platform instead of re-uploading documents. Several of the vendors in our table now market reusable-identity products. The catch: it concentrates risk in one provider, so its security posture becomes your security posture.

Zero-knowledge proofs of identity

Cryptography that proves a statement — “over 18”, “not on a sanctions list”, “EU resident” — without revealing the underlying document at all. Pilots exist across several identity networks and L2 ecosystems; regulators have been cautiously receptive because the proof can be made auditable. Still early, still rare in mainstream exchange onboarding, but this is the direction of travel.

eIDAS 2.0 and the EU Digital Identity Wallet

The revised eIDAS regulation obliges every EU member state to offer citizens a government-backed digital identity wallet, with the rollout deadline landing in 2026. For crypto onboarding, this could eventually mean presenting a state-signed credential from your phone instead of photographing a passport — selective disclosure included. Adoption by exchanges will lag the legal deadline, but MiCA-licensed venues have every incentive to accept it: cheaper than paying per-check vendor fees, and less toxic to store.

Before you upload your ID: the checklist

Warning — fake KYC pages are passport-harvesting machines: the single most dangerous moment in crypto onboarding is a phishing page that imitates an exchange’s verification flow. Hand it your passport photo and a liveness video and you have gift-wrapped everything needed to impersonate you at banks, brokers and other exchanges — and unlike a password, you cannot rotate your face. Type the exchange URL yourself, never follow “complete your verification” links from email, SMS or Telegram, and treat any KYC request arriving outside the official app or site as hostile until proven otherwise.
  1. Verify the venue first. Is the exchange actually licensed where you live — MiCA-authorised in the EU, FCA-registered in the UK? Regulator registers are public and searchable. If the venue is not on them, stop before the passport ever leaves your pocket.
  2. Check the connection. The verification flow must run over HTTPS on the exchange’s real domain or its documented KYC subdomain. A padlock alone proves encryption, not identity — read the domain character by character; lookalikes bank on you skimming.
  3. Identify the processor. The privacy policy must name the KYC vendor or at least the category of processor and the retention period. A venue that cannot tell you who processes your passport does not deserve it.
  4. Minimise what you send. Upload exactly the documents requested, nothing more. Never send ID photos over email or chat “to speed things up” — legitimate compliance teams use the in-app flow, full stop.
  5. Record the moment. Note the date, the documents submitted and the vendor involved. If a breach headline appears in three years, you will know instantly whether you are affected — most people have no idea which companies hold their passport.

When verification fails — and how to fix it

Rejection is usually mechanical, not personal. The recurring causes, in rough order of frequency:

  • Image quality. Blur, glare across the hologram, cropped corners, a photo of a photocopy. Fix: daylight, matte surface, all four corners in frame, no flash directly on the document.
  • Name and data mismatches. The account name must match the document exactly — transliteration differences (“Aleksandr” vs “Alexander”), missing middle names and maiden names are classic silent killers. Fix: re-enter your details exactly as printed, diacritics included where the form allows.
  • Expired or unsupported documents. An expired passport fails instantly; some venues also refuse specific document classes from specific countries. Fix: check the accepted-documents list on the official page before your third attempt, not after.
  • Liveness failures. Dim light, glasses, hats, filters, or trying to verify from a screenshot. Fix: bare face, even lighting, follow the motion prompts slowly.
  • VPN and geo conflicts. Documents from one country, IP address from another the venue does not serve — the fraud model flags it even when your reasons are innocent. Fix: switch the VPN off for onboarding, and if you genuinely live somewhere the venue does not support, stop; opening the account through a VPN violates the terms and is grounds for a later freeze.

If an automated flow rejects you twice, stop retrying — repeated failures can flag the account — and open a support ticket asking for manual review. Providers such as iDenfy explicitly market human review as a backstop precisely because automated models misfire on worn documents and unusual names.

The bottom line

KYC is the toll gate of regulated crypto, and in 2026 there is no lawful route around it — only choices about who you pay the toll to and how carefully. Verify the venue before it verifies you, know which vendor holds your documents, use the tiers deliberately, and remember that identity checks exist only on the custodial side of the fence: once your coins sit in self-custody, nobody asks for a selfie again — and nobody resets your seed phrase either. For choosing the venue, start with the exchange comparison; for the exit, the off-ramp guide; and for everything this independent comparison desk covers on the self-custody side, the logical next step for any balance you would mind losing is the best crypto wallets guide — hardware wallets remain the boring, correct answer for large amounts.

Frequently asked questions

What is KYC verification on a crypto exchange?

KYC (“know your customer”) is the legally mandated identity check regulated exchanges run before granting full access: a government ID, a liveness selfie, and screening against sanctions and PEP lists. It is usually performed by a third-party provider such as Sumsub, Onfido, Jumio, Veriff, Persona or iDenfy, which returns an approve/reject verdict to the exchange.

Which KYC provider is best for crypto?

You rarely get to choose — the exchange picks the provider. All six majors advertise broad document coverage, liveness detection and fast automated decisions on their official sites. From a user’s standpoint the bigger differences are jurisdiction (Veriff and iDenfy are EU-based, Persona and Jumio US-rooted, Onfido now part of Entrust) and how the exchange configures data retention. Judge the exchange, and the provider comes with it.

Can I delete my passport photo after verification?

Not immediately. GDPR gives you the right to erasure, but AML law obliges exchanges to retain identity records — typically for around five years after your account closes — and that legal duty overrides your deletion request. What you can do: file a subject-access request to learn exactly what is held, demand deletion of anything collected beyond legal requirements, and demand full erasure once the statutory retention period expires.

Are no-KYC crypto exchanges legal in 2026?

In the EU and UK, an exchange serving local customers without KYC is operating unlawfully — MiCA authorisation and FCA registration both come welded to AML duties. Using one exposes you to frozen withdrawals, exit scams, zero legal recourse and coins that trigger enhanced checks on the next regulated venue. Decentralised protocols with no operator are a separate category, but their fiat on-ramps and off-ramps are regulated all the same.

Why does my crypto KYC keep getting rejected?

The usual suspects: blurry or glare-covered document photos, a name that does not exactly match the document (transliteration and middle names are classic), an expired or unsupported document, failed liveness because of poor lighting or filters, or a VPN putting your IP in a country that conflicts with your papers. Fix the specific cause, and after two automated failures request manual review instead of retrying.

Do non-custodial wallets require KYC?

No. A non-custodial wallet is software or hardware you control — there is no company holding your funds, so there is nobody with a legal duty to identify you. KYC applies where a business takes custody or exchanges money: centralised exchanges, brokers, fiat on- and off-ramps. The trade-off is absolute responsibility: lose the seed phrase and no support desk can recover it.