KYC Hygiene: An Annual Routine for Scattered IDs
If you share your ID a handful of times a year, you have a problem you almost never look at: a slowly growing pile of copies sitting in mailboxes, shared drives, ticketing systems, and chat threads you forgot about months ago. Each one is a permanent liability you no longer track. A KYC hygiene routine is the once-a-year discipline that turns that invisible pile into a list you can actually act on — inventory it, clear what you can, and lock down what you can't.
Think of it the way you think of rotating passwords or reviewing standing orders. It's boring, it takes an afternoon, and it's the difference between knowing exactly where your passport copies live and finding out the hard way when one surfaces somewhere it shouldn't.
Why an annual pass beats ad-hoc panic
Most people only think about a shared ID copy at two moments: when they send it, and when something goes wrong. The years in between are a blind spot. Documents expire, deals collapse, vendors get acquired, support inboxes get archived — and your data rides along, untracked, into systems you have zero visibility into.
An annual routine fixes the cadence problem. You stop relying on memory and start relying on a recurring calendar entry. The goal isn't perfection; it's to shrink the gap between "copies that exist" and "copies you know about" once every twelve months.
Step 1: Inventory every copy you've shared
You can't clean up what you can't see. The first pass is pure reconstruction. Go source by source:
- Email "sent" folders — search for
Ausweis,Reisepass,ID,passport, common attachment types, and the names of banks or platforms you onboarded with. - Messenger and chat — WhatsApp, Signal, Slack, Teams. People send passport photos far more casually here.
- Cloud storage and shared links — Google Drive, Dropbox, OneDrive. Check both your files and links others created.
- Platform accounts — anywhere you completed a KYC flow: banks, brokers, crypto exchanges, PSPs, marketplaces.
Write each one down. A simple table is enough — and it's the seed of a standing record you maintain rather than rebuild every year. If you don't keep one yet, building a personal KYC data register is the natural companion to this routine.
| Recipient | What I shared | Channel | Date | Still needed? | Action |
|---|---|---|---|---|---|
| Bank A | Passport + Meldezettel | Upload portal | 2024-03 | Yes (active account) | Leave, note retention |
| Marketplace B | ID front/back | 2024-07 | No | Request deletion | |
| Old broker C | Passport | ShareKYC link | 2025-01 | No | Revoke link |
Step 2: Revoke stale shares you still control
This is the highest-leverage step, so do it before the slow ones. Any share you issued through a controllable channel — a scoped link, a portal grant, a platform permission — can be cut off unilaterally. No request, no waiting, no cooperation from the other side.
Go through your inventory and kill every link or grant tied to a relationship that's over: the deal that fell through, the exchange you stopped using, the onboarding you abandoned halfway. If you sent copies as raw email attachments, this step won't help you — and that gap is exactly the point of revoking access after sharing. For controllable shares, revocation is instant and final.
This is the practical argument for sharing via scoped links in the first place: the cleanup is a one-click operation a year later, not a deletion request you have to beg for.
Step 3: Request deletions for the rest
Now the slow part — the copies sitting in inboxes and systems you don't control. For each one your inventory marked "no longer needed," send a deletion request. Keep it short, specific, and dated:
Under DSGVO Art. 17 I request deletion of the copy of my identity document I provided on [date] for [purpose]. Please confirm in writing once deleted, or state the legal basis for any retention.
Expect two kinds of reply. Some recipients delete and confirm — done. Others invoke a retention duty, typically the GwG's multi-year record-keeping obligation. That refusal isn't necessarily illegitimate, but it has limits worth knowing: a retention duty justifies keeping a record, not unlimited reuse, and it ends. The boundary between what a recipient must keep and what they must delete is its own topic in retention and deletion of KYC copies.
Log every response. A confirmed deletion closes the row; a retention claim parks it with a review date.
Step 4: Rotate documents and re-scope
The final pass is forward-looking. Two things to check:
Document changes. If you've renewed your passport or ID, replaced a card, moved address, or changed your name, every old copy floating around is now stale data tied to a superseded document. Note which recipients hold outdated copies — those are priority deletion targets, since the data is both exposed and wrong.
Scope creep. Look at what you typically send and ask whether it's more than recipients need. A lot of people default to handing over a full passport when a name and date of birth on a redacted card would do. Tightening your default scope is the cheapest long-term win — see which fields to actually share.
Handling the copies you can't clear
Some rows in your inventory won't close, and that's fine — the routine's job is to make the open ones visible and managed, not to force everything to zero. Two categories will resist:
Retention-locked copies. A bank or other obliged entity will refuse deletion while the GwG clock runs. Don't treat that as a failure. Record the retention end-date they cite and diary a deletion request for when it lapses. Next year's pass picks it up automatically. The thing you're guarding against is a copy that's retained past its lawful term because nobody ever followed up — your register is what closes that gap.
Unverifiable copies. An email attachment or a messenger image you sent years ago can be deletion-requested but never confirmed. Mark these honestly as "requested, unverifiable" rather than pretending they're gone. They're also your strongest argument for changing how you share going forward: every uncontrolled copy you create this year becomes an unclearable row next year.
A short rule keeps the routine sane: clear what you can, diary what's retention-locked, and stop manufacturing copies you can never verify the deletion of.
A routine you can actually keep
The whole thing fits in a recurring checklist. Block ninety minutes once a year and work top to bottom:
- Reconstruct the inventory from email, chat, cloud, and platform accounts
- Revoke every stale link or grant you still control
- Send dated DSGVO Art. 17 deletion requests for uncontrolled copies
- Log confirmations and retention claims with review dates
- Flag copies tied to expired or replaced documents
- Tighten your default sharing scope for next year
This is also where tooling earns its keep. The reason ShareKYC exists is to collapse most of this into the share itself: data verified once and held AES-256 encrypted in an EU-hosted vault, shared through links with expiry, access limits, downloads off, instant revocation, and a full audit log. When every share is already scoped and revocable, your annual hygiene pass is mostly clicking "revoke" down a list you can see — not archaeology across a dozen inboxes.
The point of the exercise
KYC hygiene isn't about paranoia; it's about closing the gap between the copies that exist and the copies you can account for. Run it once and the second year is far faster, because half the work is maintaining a register instead of rebuilding one.
Start small: open your "sent" folder, find the first ID copy, and decide whether to revoke it or request its deletion. If you'd rather every future share came pre-built for this kind of cleanup, that's exactly the default ShareKYC is designed to give you.
Frequently asked questions
How often should I run a KYC hygiene routine?
Once a year is the realistic floor for anyone who shares ID a few times annually. Run an extra pass whenever you change your ID document, your address, or your name.
Do I have a legal right to demand deletion of an old ID copy?
Often yes, under DSGVO Art. 17 — but it is blocked where the recipient has a statutory retention duty under the GwG. The routine separates the copies you can clear from the ones you cannot.
What is the single highest-value step in the routine?
Revoking stale shares you still control. It is the only step that needs no cooperation from the other side and closes the window immediately.