Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Users consent to Coinbase collecting and retaining name, address, telephone number, email, date of birth, taxpayer identification number, government identification, bank account details, and in some cases biometric information. Users also authorize their wireless carrier to share device and account information with Coinbase for identity verification and fraud prevention for the duration of the account.
This analysis describes what Coinbase's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the scope of personal data collection and retention, including biometric data where permitted by law, and extends to a standing authorization for wireless carrier data disclosure to Coinbase for the life of the account. The biometric data collection, where applicable, interacts with state biometric privacy laws including the Illinois Biometric Information Privacy Act.
The updated terms establish procedures for handling protocol upgrades and define Coinbase's role in migrating customer assets to new versions. Under the revised language, by maintaining a Coinbase account, customers are deemed to have instructed Coinbase to conduct Coinbase Supported Migrations on their behalf at times and in manner Coinbase solely determines appropriate. The agreement further states that Coinbase shall not be liable or responsible for any loss resulting from inability to transfer Digital Assets during a migration or from the Asset Transformation itself. This expands Coinbase's authority to act without advance notice while eliminating liability for migration-related losses.
View change record →The updated terms now explicitly disclose Coinbase's fee structure for California residents, establishing a $10 maximum fee for transactions under $200 and a 6% maximum for larger transactions, though actual fees displayed at checkout may be lower based on payment method, order size, market conditions, and location. The revised agreement also clarifies that virtual currency transactions may be irreversible and provides links to procedures for reporting unauthorized transactions, updating contact information, and accessing transaction receipts. Coinbase commits to providing California residents at least 14 days' prior notice of material changes to fees or terms affecting their accounts.
View change record →The updated terms eliminate language that previously allowed Coinbase to restrict your withdrawals if you designated USDC as Secured USDC and to comply with third-party secured party instructions without your consent. Under the revised agreement, Coinbase will not transfer, loan, or otherwise handle your Supported Digital Assets except as required by law or as you instruct. This means the One Card Secured USDC mechanism is no longer integrated into the core asset protection clause, and users no longer face withdrawal restrictions or loss of instruction authority tied to that designation. If you currently hold Secured USDC under a separate One Card cardholder agreement, that agreement remains in effect but is no longer cross-referenced in the main User Agreement's asset protection section.
View change record →⚠ Personal data collected under this provision will be retained by Coinbase for the duration of the account and, where legally required, after account closure
Cross-platform context
See how other platforms handle Identity Verification, Personal Data Collection, and Wireless Carrier Authorization and similar clauses.
Compare across platforms →Monitoring
Coinbase has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"During registration for your Coinbase Account, or at any other time deemed necessary by Coinbase, you agree to provide us with the information we request for the purposes of identity verification, providing Coinbase Services to you, and the detection of money laundering, terrorist financing, fraud, or any other financial crimes and permit us to keep a record of such information. The information we request may include certain personal information, including, but not limited to, your name, address, telephone number, e-mail address, date of birth, taxpayer identification number, government identification, and information regarding your bank account (such as the name of the bank, the account type, routing number, and account number) and in some cases (where permitted by law), special categories of personal data, such as your biometric information. You consent to us accessing, processing and retaining any personal information you provide to us for the purpose of us providing Coinbase Services to you. Further, you authorize your wireless carrier to use or disclose information about your account and your wireless device, if available, to Coinbase or its service provider for as long as you have a Coinbase Account, solely to help them identify you or your wireless device and to prevent fraud.Excerpt from Coinbase's User Agreement
1. REGULATORY LANDSCAPE: The collection of biometric information, where applicable, engages the Illinois Biometric Information Privacy Act, which imposes consent, retention schedule, and destruction requirements for biometric data. The Texas Capture or Use of Biometric Identifier Act and similar state laws may also apply. Wireless carrier data disclosure authorizations interact with the Stored Communications Act and FCC regulations. AML and KYC data collection obligations are governed by FinCEN requirements under the Bank Secrecy Act. CCPA applies to California residents and provides rights regarding personal information collection, including the right to know and the right to deletion subject to legal retention exceptions. 2. GOVERNANCE EXPOSURE: High. The breadth of the data collection authorization, including biometric data and wireless carrier account information, creates exposure under state biometric privacy laws, which impose statutory damages for violations that do not require proof of actual harm. The standing wireless carrier disclosure authorization for the duration of the account is an ongoing consent rather than a one-time collection event. 3. JURISDICTION FLAGS: Illinois BIPA creates the highest exposure for biometric data collection, with statutory damages of $1,000 to $5,000 per violation. Texas and Washington biometric privacy laws create similar obligations. California CCPA and CPRA provide additional rights for California residents, including the right to limit use of sensitive personal information, which may include biometric data. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement and vendor assessment teams should note that Coinbase may share personal data with credit reference agencies, fraud prevention agencies, and wireless carrier service providers, as stated in Section 1.3. Data processing agreements and vendor assessments for these third parties are operationally relevant for institutional compliance programs. 5. COMPLIANCE CONSIDERATIONS: Legal teams should evaluate whether Coinbase's biometric data collection practices satisfy applicable state biometric privacy law requirements in Illinois, Texas, and Washington, including whether written consent, retention schedule, and destruction policies are in place. CCPA compliance for California residents should be verified against the data collection scope described in this provision.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the scope of personal data collection and retention, including biometric data where permitted by law, and extends to a standing authorization for wireless carrier data disclosure to Coinbase for the life of the account. The biometric data collection, where applicable, interacts with state biometric privacy laws including the Illinois Biometric Information Privacy Act.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Coinbase.