SEC’s Peirce Urges Zero-Knowledge Proofs to Reduce KYC Data Collection
SEC Commissioner Hester Peirce has advocated for using zero-knowledge proofs to limit how much customer identity data institutions collect during KYC processes. She also urged firms to reuse prior identity verifications instead of repeatedly storing customer details, while making clear her privacy recommendations would not alter existing compliance obligations.
Why It Matters
Peirce's proposals could reduce the amount of personal data held by financial firms, lowering privacy and security risks without changing firms' regulatory responsibilities. That approach seeks to balance customer privacy with ongoing anti-money-laundering and know-your-customer enforcement.
Key Facts
- Proponent: SEC Commissioner Hester Peirce
- Technology advocated: Zero-knowledge proofs (ZKPs)
- Operational change urged: Reuse identity checks instead of repeatedly storing customer details
- Effect on rules: Privacy proposals do not change existing compliance rules
SEC Commissioner Hester Peirce has called for broader use of zero-knowledge proofs as a way to reduce the quantity of customer identity data that financial institutions collect during know-your-customer (KYC) procedures. She argued that cryptographic techniques like ZKPs can allow firms to verify required attributes about customers without retaining full identity details.
In addition to promoting ZKPs, Peirce encouraged firms to reuse prior identity verifications rather than repeatedly storing copies of customer information every time a new check is performed. That practice, she suggested, could limit the accumulation of sensitive data across institutions.
Peirce emphasized that her privacy-oriented recommendations are intended to work within the current regulatory framework and would not modify existing compliance obligations. Firms would still be expected to meet anti-money-laundering and KYC requirements while exploring privacy-preserving verification methods.
Her remarks frame privacy improvements as complementary to, not a substitute for, regulatory compliance, proposing technical and operational changes that aim to reduce data exposure without loosening legal responsibilities.