Coin Center has urged a group of US financial regulators to take a narrower and more privacy-focused approach to customer identification rules for permitted payment stablecoin issuers under the GENIUS Act. In a comment letter dated August 21, the advocacy group asked FinCEN, the OCC, the Federal Reserve, the FDIC and the NCUA to allow privacy-preserving digital identity tools to serve as a primary compliance method rather than relying mainly on conventional data-heavy checks.

The filing argues that existing customer identification practices force institutions to collect and store large volumes of sensitive personal information, creating what Coin Center described as security and surveillance risks without delivering strong anti-money-laundering results. Its proposal centers on user-controlled digital identity systems that could verify required facts while limiting how much personal data issuers need to gather and retain.

Alternative identity methods at the center of the filing

Coin Center said the agencies' proposal largely carries over traditional customer identification program requirements already used by financial institutions. In its view, permitted payment stablecoin issuers offer a chance to test a different model, one based on verifiable digital credentials, zero-knowledge proofs, multi-party computation and open blockchain networks.

According to the letter, those tools could let a customer prove attributes such as age, citizenship or verified account status without disclosing complete identity records to every institution they deal with. Coin Center said this kind of system should be open, decentralized and portable across providers, rather than controlled by a central gatekeeper that determines participation and handles sensitive information.

The group asked regulators to state clearly in the final rule that a stablecoin issuer may use user-controlled digital identity, or a comparable privacy-preserving proof, as a primary means of identification and verification. It also said issuers should not be required to retain underlying identity documents or the full set of personal data if another method achieves the same compliance outcome.

Why Coin Center says current KYC practices are flawed

The letter repeats arguments Coin Center has made in earlier submissions to Treasury and FinCEN, where it called current identification systems costly, invasive and weak at stopping illicit finance. It pointed to an estimate that US financial institutions spend roughly $26 billion a year on AML and sanctions compliance, while only 0.2% of criminal proceeds are intercepted and recovered.

Coin Center also argued that mandatory collection and retention of customer information creates new attack surfaces for cybercrime and fraud. It cited reporting from FinCEN, the FBI, the FTC and NIST to support the claim that large identity databases can become targets for malicious actors.

In that framing, the issue is not whether stablecoin issuers should comply with AML and counter-terrorist financing rules, but how they do it. Coin Center said regulators should judge success by whether compliance reduces illicit finance and unnecessary risk, not by how much personal data institutions gather.

Push to keep CIP obligations out of the secondary market

A major part of the filing focuses on when a relationship with a stablecoin issuer should count as an account. Coin Center backed the idea that merely holding or controlling a stablecoin does not by itself create a direct relationship with the issuer, and said AML and CFT duties should stay with the primary market.

It asked regulators to replace the term formal relationship with contractual relationship in the final definition of an account. In Coin Center's view, that standard should require notice of service terms, an affirmative indication of assent, acceptance of the request for service, and reciprocal enforceable obligations. The group said that would draw a clearer legal line between direct customers and downstream market participants.

Coin Center opposed extending customer identification rules to secondary-market activity. It argued that doing so would amount to unusually broad blockchain surveillance, create privacy risks, interfere in transactions involving people with no direct issuer relationship and raise constitutional concerns.

Redemption-only activity and what comes next

The letter also asks regulators not to treat redemption-only interactions as accounts. Coin Center described direct redemption of stablecoins with an issuer as an isolated event that should not trigger broad obligations to collect and keep sensitive personal information.

Instead, it said privacy-preserving proofs could be used to check whether a person is eligible to redeem and whether sanctions restrictions apply, without permanently linking an identity to a wallet address. Coin Center added that agencies could consider a pilot or safe-harbor framework allowing verified attributes to substitute for static identifiers in some onboarding cases.

The next confirmed step is the agencies' review of comments on the proposed rule. Coin Center's submission asks them to write a final framework that keeps customer identification tied to contractual issuer relationships, avoids pushing CIP requirements into secondary trading, and explicitly permits privacy-preserving identity systems for stablecoin issuers.

Source: www.coincenter.org