Home Crypto Regulation & Policy Coin Center Challenges FinCEN to Modernize AML Protocols Through Data Minimization and Privacy Preserving Technologies

Coin Center Challenges FinCEN to Modernize AML Protocols Through Data Minimization and Privacy Preserving Technologies

by admin

Coin Center, a leading non-profit research and advocacy group focused on cryptocurrency policy, has formally submitted a comprehensive comment to the Financial Crimes Enforcement Network (FinCEN) urging a fundamental shift in the nation’s anti-money laundering (AML) and countering the financing of terrorism (CFT) frameworks. The filing, directed toward the Department of the Treasury and FinCEN, comes as part of a broader federal effort to modernize the Bank Secrecy Act (BSA) to better suit the digital age. Coin Center’s primary contention is that current regulatory expectations for data collection are not only outdated but are actively creating new vulnerabilities that sophisticated criminals and foreign adversaries can exploit.

The core of Coin Center’s argument rests on the premise that the "overcollection" of sensitive customer information has transformed financial institutions into high-value targets for cybercriminals. By requiring banks and cryptocurrency exchanges to maintain massive "honeypots" of personally identifiable information (PII)—such as scans of driver’s licenses, Social Security numbers, and home addresses—regulators may be inadvertently facilitating the very identity theft and fraud they seek to prevent. Coin Center asserts that a modern AML/CFT regime must move beyond the volume of data collected and instead focus on the effectiveness of identity verification through privacy-preserving technologies.

Historical Context and the Push for BSA Modernization

The Bank Secrecy Act, originally passed in 1970, was designed for an era of physical ledgers and manual oversight. Over the decades, it has been amended multiple times, most significantly by the USA PATRIOT Act in 2001 and the Anti-Money Laundering Act of 2020. This latest round of modernization efforts by FinCEN is intended to address the complexities of the 21st-century financial system, which includes high-frequency digital transactions, decentralized finance (DeFi), and the global nature of cryptocurrency.

FinCEN has recently signaled an openness to innovative technologies, recognizing that financial institutions are often best positioned to assess their own unique risk profiles. However, Coin Center’s filing suggests that the regulatory culture remains anchored in "legacy expectations." Financial institutions often prioritize "examiner comfort"—collecting the same invasive data they have always collected to satisfy regulators—over actual public safety. This "ritual" of compliance, according to Coin Center, forces law-abiding citizens to overshare their personal lives while failing to stop determined illicit actors who use forged or stolen credentials.

The Rising Tide of Identity-Related Cybercrime

To support its claims, Coin Center highlighted a series of alarming statistics regarding the state of cybercrime and data breaches in the United States. Citing the Identity Theft Resource Center’s (ITRC) 2025 annual report, the filing notes a shift from mass identity theft toward pervasive identity fraud, where stolen credentials are "weaponized with precision." Criminals are increasingly prioritizing "static identifiers"—data points that cannot be easily changed, such as Social Security numbers and driver’s license details—over replaceable data like credit card numbers.

The scale of this problem is reflected in federal data. The Federal Trade Commission’s (FTC) Consumer Sentinel Network Data Book reveals a staggering trajectory: fraud and identity theft reports rose from approximately 860,000 in 2004 to nearly 6.5 million in 2024. Furthermore, the FBI’s 2025 Internet Crime Report documented over 67,000 complaints involving personal data breaches and over 31,000 complaints specifically involving identity theft.

A 2024 study from the University of Brasília underscored that financial institutions are the primary targets for these attacks. Because these institutions are required by law to collect and retain the exact information needed to defeat identity controls, they have become the most breached sector among publicly traded U.S. companies. When a financial institution is compromised, the damage extends beyond the immediate loss of funds; it provides criminals with the "raw materials" to open new fraudulent accounts and launder money in the names of innocent victims.

NIST and the Failure of Legacy Identity Systems

Coin Center’s filing also draws on research from the National Institute of Standards and Technology (NIST). In its recent publications on digital identities and Mobile Driver’s Licenses (mDL), NIST identified an urgent need for secure, privacy-preserving identity solutions. NIST’s research found that inadequate digital identity systems cost institutions an estimated 3.1% of their annual revenue.

FinCEN’s own data corroborates this crisis. In 2021, the agency linked $212 billion to identity-related suspicious activity. By 2023, that figure had ballooned to as much as $394 billion. Despite these losses, the regulatory framework continues to emphasize the collection of "cheap but invasive" data. Coin Center argues that if the collection of this data was truly effective at deterring money laundering, these figures would be trending downward rather than reaching record highs.

The emergence of artificial intelligence (AI) has further complicated the landscape. FinCEN has noted that AI and synthetic identities allow bad actors to exploit identity processes more quickly and inexpensively than ever before. In this environment, the traditional method of sending a photo of a driver’s license to a centralized database is no longer a viable security measure; it is a liability.

The Case for Privacy-Preserving Digital Identity

The alternative proposed by Coin Center involves a transition to privacy-preserving digital identity systems. These technologies, which include portable credentials, attribute-based proofs, and dynamic risk-scoring mechanisms, allow institutions to verify a user’s eligibility or identity without requiring the transmission or retention of raw PII.

For example, through the use of zero-knowledge proofs, a user could prove they are over 18, a U.S. citizen, or not on a sanctions list without ever revealing their actual birthdate, name, or address. This "data minimization" approach ensures that even if a financial institution’s database is breached, there is no sensitive information for a hacker to steal.

Coin Center is calling on FinCEN to:

  1. Quantify Operational Risk: Direct financial institutions to include the risk of data breaches and "honeypot" creation in their AML/CFT risk assessments.
  2. Encourage Innovation: Explicitly permit and reward the use of alternative onboarding methods that preserve privacy.
  3. Redefine Success: Measure the effectiveness of an AML program by its ability to reduce illicit finance and fraud, rather than the sheer volume of customer data it archives.

Privacy as a National Security and Civil Rights Issue

Beyond the technical risks of cybercrime, Coin Center’s filing touches on the broader implications of financial surveillance. Detailed transaction histories can reveal a person’s political affiliations, religious beliefs, and intimate associations. In the hands of a hostile government agency or a foreign adversary, this data can be used for harassment, "debanking," or the targeting of dissidents and journalists.

The advocacy group argues that a modern AML framework should protect the "freedom, dignity, and security of everyday Americans." By allowing for anonymous or pseudonymous verification methods, the U.S. can maintain a robust financial monitoring system that does not compromise the constitutional values of privacy and association.

Industry Reaction and Future Implications

The reaction from the broader fintech and cryptocurrency industry has been largely supportive of Coin Center’s stance. Many firms have long complained about the "compliance tax"—the massive overhead required to store and protect customer data that they would prefer not to have in the first place. Privacy advocates have also joined the call, noting that the "Travel Rule" and other AML requirements have created a global surveillance net that is increasingly vulnerable to state-sponsored hacking.

However, some regulatory traditionalists express concern that moving away from centralized data collection could make it harder for law enforcement to conduct "look-back" investigations once a crime has been discovered. The challenge for FinCEN will be to balance the need for forensic evidence with the urgent requirement to harden the nation’s financial infrastructure against identity-based attacks.

As FinCEN reviews the comments on its proposed rulemaking, the debate over the future of the Bank Secrecy Act will likely center on this tension between surveillance and security. Coin Center’s filing serves as a stark reminder that in the digital age, privacy is not just a civil liberty—it is a critical component of a secure and resilient financial system. The outcome of this modernization effort will determine whether the U.S. continues to rely on a 1970s-era model of data collection or leads the way in developing a 21st-century framework that prioritizes the protection of its citizens.

You may also like

Leave a Comment

Purel Crypto
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.