
REP27 · Regulated tech · Crypto
Article 27 GDPR · alongside MiCA and AML
Crypto businesses arriving in Europe budget for MiCA authorisation and AML programmes, and then discover a €290 obligation that has been outstanding since their first European user. Article 27 is the smallest line in the compliance file and the one with no lead time: it is also the one that cannot be argued away, because the KYC data you are legally required to keep is exactly what makes the processing continuous.
KYC filesWallet addressesTransaction historySupport ticketsMarketing

Three of these require licences, programmes and months of work. The fourth is a signature and a paragraph in a privacy notice, which is why it is so often the one still missing when the others are underway.

| Argument | Where it goes |
|---|---|
| "We are decentralised, there is no controller" | If a company runs the interface, holds KYC files and can freeze accounts, that company is a controller |
| "Wallet addresses are pseudonymous" | Pseudonymous is not anonymous. Linked to a verified identity in your database, they are personal data |
| "Our users found us, we do not target the EU" | A European language, euro pairs, EU payment rails or localised marketing all point the other way |
| "We geo-block the EU" | Then Article 3(2) may not be engaged. Effective blocking, not a checkbox, is what matters |
| "MiCA authorisation covers it" | MiCA is financial regulation. It says nothing about Article 27, and the authorities are different |
Where data subjects and supervisory authorities write, in eight languages, with everything logged.
Held and made available to authorities — the document most exchanges have never assembled, and the first one asked for after an incident.
Which banking partners and payment providers increasingly ask to see during onboarding.
Article 13(1)(a) wording naming the representative, translated for the markets you serve.
Exchanges tend to describe themselves as holding wallets. What they hold, from a European perspective, is one of the richest personal data files a private company can accumulate.
| System | What it holds | Why it matters under the GDPR |
|---|---|---|
| KYC vendor | Identity documents, selfies, liveness checks | Biometric processing and a third-country transfer in one step |
| Core ledger | Balances, transactions, linked addresses | Financial data tied to an identified person |
| Chain analytics | Risk scores on addresses and counterparties | Profiling, with consequences for the user |
| Support desk | Tickets, attachments, screen recordings | The least controlled system in most exchanges |
| Marketing stack | Emails, segments, campaign engagement | Consent state that has to be provable |
The third row is the one European regulators find most interesting, because a risk score that freezes an account is a decision about a person, taken automatically, with real consequences.
A day, and it removes the easiest finding an authority can make against you.
Owner, location, retention, and whether the vendor is inside or outside the Union.
AML minimums and GDPR minimisation pull in opposite directions; the resolution has to be written down, not assumed.
Freezes, refusals and risk scores. Article 22 asks for meaningful information about the logic and a route to human review.
Long projects with their own timelines. Nothing in them substitutes for the four steps above.
It does not authorise you under MiCA, it does not satisfy AML registration, and it does not make automated account freezes lawful. It gives supervisory authorities and users a contact point inside the Union and keeps the record of processing available. Providers implying more than that are selling something the regulation does not contain.
Designate before the marketing starts rather than after the first users arrive. The obligation attaches to the processing, so a launch that pulls thousands of European sign-ups in a week creates the gap at exactly the moment your public profile is highest.
For crypto businesses the practical pressure rarely comes from a supervisory authority first. It comes from a payment provider or a banking partner running its own onboarding review, and the data protection section of those questionnaires has become noticeably longer.
A name, an address and ideally a code they can verify without contacting you.
Country, vendor, and the transfer mechanism if it leaves the Union.
The answer has to reconcile AML minimums with a stated retention period, not simply assert both.
Automated, manual, or both — and what route a user has to human review.


No. MiCA governs crypto-asset services and is supervised by financial regulators. Article 27 governs personal data and is supervised by data protection authorities.
Not necessarily. If your interface collects analytics, emails, support tickets or optional KYC from users in the Union, you process their personal data.
Location is what makes the obligation apply, not what removes it. Article 27 exists precisely for companies established outside the Union.
When they can be linked to an identified account holder, yes. In the hands of the exchange holding the KYC file, that link exists by design.
Effective blocking can put you outside Article 3(2). A banner asking users to confirm they are not in the EU is not effective blocking.
The travel rule forces you to transmit originator and beneficiary data, which is more processing of personal data, not less. It strengthens the case for a designation.
Only if it signs the designation as the representative entity and operates the contact point. Advising you is a different service.
Notification duties fall on you as controller. The representative is the point of contact authorities can address and holds the record they will ask for.
If people in the Union can participate, yes. Sale periods are exactly when data volumes spike and complaints follow.
If that entity is genuinely established and is the controller for the processing, Article 27 does not apply to it. Group presence alone does not transfer the obligation.
Article 83(4)(a) puts it in the tier up to €10 million or 2% of worldwide annual turnover, and in this sector the absence is easy to establish from a public privacy notice.
Within 24 hours of a completed form, with the certificate and notice wording supplied at the same time.
€290 a year for Base, €490 for Standard, €890 for Multi. Against the rest of a crypto compliance budget, it is the smallest line in the file.
Related: the SaaS version · acting as a processor
A signed Article 27 designation within 24 hours, a certificate with a verification code, the Article 30 record held for you, and a desk that answers in eight languages.
See the plans