8 Total
2 High severity
6 Medium severity
0 Low severity
Summary

This document establishes Coinbase's practices for collecting, using, and sharing personal information from users of its cryptocurrency exchange and related products. Coinbase collects government-issued identification documents, bank account details, transaction records, device identifiers, IP addresses, and biometric data, and authorizes sharing this information with identity verification vendors, analytics firms, blockchain analytics companies, payment processors, and government agencies. The policy establishes data subject rights for California residents and EU users, including mechanisms to request data access, deletion, and opt-out of certain data uses through Coinbase's privacy request portal.

Technical / Legal Breakdown

This document is Coinbase's Global Privacy Policy, governing the collection, use, storage, and disclosure of personal information for users of Coinbase's cryptocurrency exchange platform and related services, with legal basis varying by jurisdiction including consent, contractual necessity, legal obligation, and legitimate interests. The policy states that Coinbase collects personal identifiers (name, email, phone, government-issued ID), financial information (bank account numbers, transaction history, crypto wallet addresses), device and usage data (IP address, browser type, operating system, cookies), biometric data for identity verification, and geolocation data; the terms authorize sharing this information with identity verification partners, payment processors, analytics providers, marketing partners, blockchain analytics firms, and government or law enforcement agencies upon legally required or permissible request. The policy authorizes sharing of transaction data with blockchain analytics companies and the use of on-chain transaction data for compliance and fraud purposes, which is operationally distinct given the immutable and publicly traceable nature of blockchain records; the agreement asserts broad discretion over how aggregated or de-identified data may be used, though applicable law in specific jurisdictions may constrain these assertions. The policy engages GDPR and UK GDPR for EU and UK users, CCPA and CPRA for California residents, and financial services data obligations under FinCEN and BSA requirements relevant to Coinbase's status as a registered money services business; SEC-related data obligations may apply depending on the specific Coinbase entity and product used. Material compliance considerations include the policy's cross-border data transfer provisions referencing Standard Contractual Clauses for EU data flows, the scope of biometric data processing which may engage Illinois BIPA and similar state-level biometric laws, and the retention periods tied to regulatory recordkeeping requirements that may extend significantly beyond account closure.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

9 important changes detected

9 versions captured · Last updated: May 2026

May 28, 2026

unknown
What changed Coinbase updated their Coinbase Privacy Policy on May 28, 2026. Change detected: 5 sentence(s) modified. Document contained 229 sentences after update.
View full change record →
What changed Coinbase made five minor editorial corrections to its Privacy Policy on May 1, 2026. The changes include fixing a spelling inconsistency (changing 'endeavour' to 'endeavor'), adding missing spaces before periods in three email addresses, and correcting a typo ('reside' to 'reside') in the Argentina data protection authority section. These are formatting and spelling corrections with no material impact on the substantive rights, obligations, or procedures described in the policy.
Why this matters This change has no material impact on consumer rights or data governance practices. The updated policy corrects spelling and formatting errors in contact information for data protection requests and complaint procedures. The substance of how users can contact Coinbase or relevant regulatory authorities remains unchanged. No action is required on the part of consumers.
View full change record →

April 29, 2026 low

Coinbase updated internal section references in its Privacy Policy on April 29, 2026 by renumbering sections throughout the document. The policy previously referenced Section 7, 11, 4, and 9 for …

View change record →
April 19, 2026 low

Coinbase's privacy policy was updated on April 19, 2026, with a minor modification to a sentence describing how the platform uses customer data to provide access to Verified Pools, a …

View change record →
April 5, 2026 low

Coinbase modified a single sentence in their Privacy Policy on April 5, 2026, regarding the Verified Pools blockchain protocol. The change involved adding a single space character in the description …

View change record →
April 3, 2026 low

Coinbase removed a single sentence from its privacy policy that previously provided a link to access the prior version of the policy. The updated policy no longer includes explicit language …

View change record →
April 2, 2026 low

Coinbase removed a single sentence from its privacy policy that previously stated 'Previous Privacy Policy can be found here.' This removal eliminates the direct link or reference to accessing prior …

View change record →
March 25, 2026 low

Coinbase modified language in its Privacy Policy on March 25, 2026. One sentence was added and one was modified, though the specific text of these changes was not provided in …

View change record →
March 6, 2026 low

Coinbase updated its Privacy Policy on March 6, 2026, making primarily technical and formatting corrections. The changes include correcting section reference numbers throughout the policy (for example, changing references from …

View change record →

Recent Provision Changes May 28, 2026

Added (1)
EU and UK User Rights (GDPR and UK GDPR) Medium

Addition of explicit GDPR/UK GDPR rights provision demonstrates increased regulatory compliance transparency for EU and UK users, filling a gap that previously only mentioned California residents.

Removed (5)
Extensive KYC/Identity Data Collection

Removal of this standalone provision represents consolidation into 'Government ID and Biometric Data Collection,' removing specific examples like passport, driver's license, and tax ID that made the scope explicit.

Broad Third-Party Data Sharing Including Advertising and Analytics

Removal of explicit mention of advertising partners and targeted advertising, combined with downgrading severity from high to medium, suggests a de-emphasis of advertising-related data sharing in the updated policy.

Blockchain Analytics Data Sharing

Removal of this standalone provision consolidates blockchain analytics sharing into the broader third-party sharing provision, removing the explicit justifications about AML compliance and ecosystem integrity that were previously highlighted.

California Consumer Privacy Rights

Removal of California-specific CCPA provision represented by revised 'California Resident Rights (CCPA/CPRA)' with updated language that adds CPRA requirements, so this is a substantial revision rather than true removal.

Children's Data and COPPA Compliance

Complete removal of children's data and COPPA compliance provision suggests either a policy change regarding child user handling or consolidation into general terms of service.

Modified (6)
Government ID and Biometric Data Collection

Current version consolidates biometric and KYC data collection into a single provision and changes language from 'may collect' to 'collect,' emphasizing active collection of government-issued ID alongside biometric data.

Law Enforcement and Government Disclosure

Text is substantively identical; provision name simplified from 'Law Enforcement Disclosure Without User Notification' to 'Law Enforcement and Government Disclosure' to be more concise.

Third-Party and Blockchain Analytics Data Sharing

Current version consolidates three separate sharing provisions into one, removes specific mention of advertising partners and targeted advertising, downgraded from high to medium severity, and removes detailed justifications about AML and ecosystem integrity.

Data Retention Policy

Current version replaces specific reference to post-closure retention for AML/financial reporting with a more general multi-factor retention assessment framework, and text appears truncated in the current version.

Cookies and Device Tracking

Current version explicitly mentions third-party service providers and tracking technologies like web beacons, removes reference to 'referring URLs' and 'usage patterns/interactions,' and adds 'pages visited' and 'browsing activity.'

View full change record →
High — 2 provisions
Medium — 6 provisions

Monitoring

Coinbase has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Automated Decision-Making and Profiling and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FCRA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
GLBA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗

Related Analysis

Consumer Rights · April 14, 2026
Coinbase Requires Mandatory Arbitration. You Have 30 Days to Opt Out.

Coinbase's User Agreement includes a mandatory arbitration clause that most users may not have reviewed. Here is what the clause states and…

Archival ProvenanceSource & Archival Record
Last Captured May 28, 2026 00:04 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000048
Version ID CA-V-003052
SHA-256 378e242ef7ef7357a0930156715c137fefbd818ce139f51127d06e5ba9cd315b
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans