> You're calling a collection and storage of your personal information as "benign"?!
All major cloud services already collect this information. I filled in the bare minimum on AWS, and they've got my full name, address, phone number, email, and credit card details.
You should really read patio11's article on KYC [0]. A relevant paragraph:
> Many people believe that the law requires a bank to see your government-issued ID in person to open a bank account. Again, this is incorrect; the law very rarely requires any particular action. The most prescriptive the US gets is that the sort of KYC information required about a customer include their true identity, including a name (not, incidentally, their “true” name because governments actually have some glimmer of understanding that that is not a thing which exists), a residential address, their date of birth, and an identifying number.
Looks like his argument is that randomized and client to client based rules are better. To some extent I agree.
However, it's inconsistent and we have a government that is punitive, which is why I see that these KYC approaches are reactive to that. There's not punitive measures for violating privacy concerns and storing/profiting from this data.
In practice, to buy crypto, you have to give a disreputable private entity (crypto exchanges have a terrible history of not being scummy.. is cryptobase good? only time will tell) very sensitive documents.
Your biometrics and gov ID data don't have to be collected or stored by the provider.
They can be used during the identity check and deleted right after, without ever entering the provider's infrastructure (assuming they are using a trusted 3rd party).
> They can be used during the identity check and deleted right after, without ever entering the provider's infrastructure
You trust them to delete it right after? What about the human reviewers in other countries that are working at home taking pictures of their laptops with your id on it?
> trusted 3rd party
You trust that 3rd party's intent and word? It's pretty weird to bring another company to steal your data and details.
At a quick reading, it doesn't sound like those are requirements. It also doesn't look like any documentation is technically required. One of the methods permitted is "Verification through non-documentary methods".
> * gives them a "reasonable belief that it knows the true identity of each customer"
> * and "a sound basis to verify the true identity of their customer and beneficial owners and reflect reasonable due diligence efforts".
I'm reading in to that in a conservative manner where it's "internally justified" that going the full privacy abusive route is justified. "Reasonable due diligence" is respective to the organization that could be punished, not a public sense.
Given that it's on the company's discretion of diligent checks, I can completely see that their more aggressive requirements of: "your biometrics, copies of your official documents, 20 years of criminal background checks, a polygraph, approval by the Democratic National Party for appropriate speech, history of pornography consumption" being the standard.
We're not getting a solution from the government that's a secure "is this person a US citizen?"/"Valid for IaaS service?" data point. The business is receiving all of the data to ask that question and are not trustable entities.
Going down the argument of "don't use anyone you don't trust" brings up the argument of.. well why are you paying Experian?
Where I'm getting to this is: We often times don't have a choice, that choice that looks like we have it is untrustable in the future, and we're being aggressively pushed into a situation where you have people of questionable interests. This rule/law encourages them to collect it, but there's no aggressive lifestyle ending punishments for crossing the line.
The TL;DR is that the must collect name, address, email, phone number, IP address, and payment information and use that information for "verifying the identity of each foreign customer to the extent it enables the U.S. IaaS provider or foreign reseller of U.S. IaaS products to form a reasonable belief that it knows the true identity of each customer."
AWS already has all of this information on my account.
It doesn't correspond to location any more than "name" does. But it is useful, in conjunction with other things, for determining identity, which is what those requirements are about.