Binance's Customer-Data Disclosure to Russian Authorities Underscores Its Global Compliance Framework
Key Takeaways
- •Binance provided Russian investigators with personal and transaction data belonging to Yuri Belenkiy, a Russian IT specialist accused of sending more than $700 in cryptocurrency to the Ukrainian military and the Azov Brigade.
- •Binance exited Russia in 2023 by selling its local operations to CommEX, which subsequently wound down, but the withdrawal did not necessarily end its compliance obligations toward Russian authorities.
- •The disclosure came after Binance's November 2023 U.S. settlement, in which it pleaded guilty to anti-money-laundering and sanctions violations, paid a $4.3 billion penalty, and accepted a five-year independent monitorship.
- •A crypto regulatory lawyer told Reuters that European data-protection rules could have restricted the transfer if Belenkiy was registered as an EU resident, because Russia is not deemed to provide adequate personal-data protection under EU law.
- •Binance declined to comment on the individual case, saying it does not discuss confidential law-enforcement requests.

Binance's disclosure of customer information to Russian authorities underscores the exchange's position that it applies a global compliance framework when responding to lawful law-enforcement requests, regardless of the jurisdiction involved. The case, reported by Reuters, illustrates the tension between law-enforcement cooperation and data-protection obligations that global exchanges must navigate — a tension sharpened by Binance's 2023 exit from the Russian market and the compliance overhaul that followed its U.S. settlement. The dilemma is not unique to Binance: under the anti-money-laundering standards set by the Financial Action Task Force, virtual-asset businesses are expected to be licensed, supervised and cooperative with authorities across the jurisdictions where they operate, even as they remain bound by the privacy laws of the countries where their users live.
The Belenkiy Case
According to Reuters, Binance provided Russian investigators with personal and transaction data belonging to Yuri Belenkiy, a Russian IT specialist accused of sending more than $700 in cryptocurrency to the Ukrainian military and the Azov Brigade, also referred to as the Azov Regiment — a unit that Moscow designates as a terrorist organisation.
Binance said it cooperates with law-enforcement agencies around the world, subject to applicable legal, privacy and regulatory requirements. The exchange's current privacy policy similarly allows the disclosure of customer information in response to legally valid law-enforcement and regulatory requests, while requiring that any such disclosure comply with applicable data-protection laws and pass internal legal review.
Exit From Russia, Not From Obligations
The case is notable because Binance announced a complete exit from Russia in 2023, saying that operating in the country was incompatible with its compliance strategy. That exit took the form of a sale of Binance's Russian operations to a platform called CommEX, announced in September 2023; CommEX subsequently wound down. The withdrawal does not necessarily mean the exchange abandoned its compliance obligations toward Russian authorities.
Rather, the case highlights Binance's broader approach: compliance requirements are applied across jurisdictions, with customer information potentially shared whenever the exchange determines that a request meets applicable legal and regulatory standards.
Post-Settlement Compliance Overhaul
Binance's compliance regime has undergone a major overhaul since its November 2023 settlement with U.S. authorities, in which the exchange pleaded guilty to anti-money-laundering and U.S. sanctions violations and its founding CEO, Changpeng Zhao, stepped down. The settlement included a $4.3 billion penalty, enhanced anti-money-laundering controls, and a five-year independent monitorship.
U.S. authorities said the reforms delivered stronger sanctions controls, dedicated law-enforcement teams, and expanded compliance resources.
EU Data-Protection Considerations
A crypto regulatory lawyer told Reuters that Binance may have faced restrictions under European data-protection rules if Belenkiy was registered as an EU resident. Russia is not considered to provide an adequate level of personal-data protection under EU law, and the bloc's General Data Protection Regulation permits transfers to such countries only under strict safeguards or narrow derogations — the legal backdrop against which exchanges must weigh requests from non-adequate jurisdictions.
The Central Question
Against this backdrop, the central question in the Russian case is not whether Binance follows different compliance standards in different countries, but whether the specific disclosure satisfied the competing legal requirements governing law-enforcement cooperation and data protection. That question has gained weight as the EU's Markets in Crypto-Assets regulation, whose rules for crypto-asset service providers took full effect at the end of 2024, brought exchanges under a harmonised European regime — one under which Binance has since obtained authorisation.
Binance has declined to comment on the individual case, saying it does not discuss confidential law-enforcement requests. For Binance, the episode demonstrates the framework the exchange rebuilt after its U.S. settlement: one under which it says it responds to lawful requests wherever they originate, while the details of individual cases remain confidential.