ShareKYC Blog
Guides on KYC, identity and data protection
Plain-English articles on verifying identity, meeting anti-money-laundering duties and sharing sensitive documents without losing control.
How to Push Back on Insecure KYC Requests
Ready-to-use scripts for when someone asks you to email your ID. Offer a secure link instead, set the terms, and know when and how to escalate.
6 min readIndustriesWhen the Notary Asks for Your ID
Identification at a Beurkundung: why in-person presentation beats a copy in an inbox, what the notary's GwG duties actually require, and how to keep data minimal.
7 min readHow-to guidesHow to Watermark ID Documents the Right Way
Bind every ID copy to a purpose, date, and recipient. Visible vs. invisible forensic watermarks, what each protects against, and what a watermark cannot do.
6 min readComparisonsEmail Encryption vs. Secure Link for Documents
S/MIME and PGP friction versus a controlled share link with expiry, revocation, and audit. A head-to-head comparison and a reasoned recommendation for sensitive files.
7 min readCompliance & AMLThe GDPR Rights That Actually Apply to KYC
Which GDPR rights bite in a KYC context: access under Art. 15, the erasure-vs-AML-retention conflict under Art. 17, and objection — plus how to exercise each in practice.
7 min readCompliance & AMLRetention and Deletion of KYC Copies: What the Other Side May Do
The GwG retention duty versus the GDPR right to deletion: how long a recipient may keep your ID copy, when they must delete it, and how to demand it cleanly.
7 min readIndustriesThe Founder's KYC Marathon: How to Cut It Short
Serial founders repeat UBO checks, Firmenbuch extracts and bank-PSP-notary onboarding endlessly. How to streamline the KYC marathon across multiple companies.
7 min readData protection & securityShare Your ID Without Losing Control
The five levers that keep you in control when you share ID or KYC data: expiry, access limits, downloads off, instant revocation, and watermarking.
6 min readData protection & securityRedacting ID Copies: What You Can Black Out
Which ID fields you may redact, how the diagonal Sperrvermerk note works, and when a full unredacted copy is legally required versus merely requested.
6 min readData protection & securityRevoking Access After You've Shared — Impossible With Email
Why an emailed ID copy can never be recalled, what real revocation actually means, and how expiring, revocable links with an audit log give you a working undo.
7 min readIndustriesBuying Property: Three Parties, One ID
Agent, notary, and bank each run their own KYC on the same purchase. How to satisfy all three from one verified profile with controlled, scoped shares.
6 min readHow-to guidesA Secure ID-Upload Workflow for Freelancers
Stop emailing your passport to every new client. A concrete, step-by-step ID-upload workflow for freelancers: one verified profile, controlled shares, full audit trail.
7 min readData protection & securityIdentity Theft From an ID Copy: Real Risks
A practical threat model for what an attacker can and can't do with a static ID copy versus the physical document or eID, plus the protections that move the needle.
7 min readHow-to guidesKYC Hygiene: An Annual Routine for Scattered IDs
A concrete yearly KYC hygiene routine: inventory every ID copy you've shared, request deletions, rotate documents, and revoke stale shares before they leak.
6 min readData protection & securityWhat Banks Are Actually Allowed to Require for KYC
Where GwG due-diligence duties end and GDPR data minimisation begins: spotting over-collection in KYC and how to push back without derailing onboarding.
5 min readHow-to guidesHow Often Must You Re-Verify? Cutting Re-KYC Busywork
Re-KYC frequency explained: the periodic-review triggers banks use, document validity windows, and how reusing verified data removes most repeat verifications.
7 min readData protection & securityYour ID Data Leaked: Immediate Steps and Damage Control
A concrete first-48-hours response when your ID copy leaks: block hotlines, fraud monitoring, and a clear-eyed read on what an attacker can and cannot do with a copy.
7 min readHow-to guidesKeep Track of Where Your KYC Data Went
Build a personal KYC register: the exact columns to track who holds your ID data, when, via which channel, and when to trigger revocation and deletion.
7 min readData protection & securityData Minimization: Which Fields a Bank Actually Needs
A field-by-field walkthrough of KYC data minimization: which identity attributes a bank can demand, which you can withhold, and the legal basis for each.
7 min read