Binance delivered to Russia the data of a client accused of financing Ukraine.

The information, obtained by Reuters from documents of the Russian security forces, was incorporated as evidence in the case against a 49-year-old computer scientist.

2 minutes

fotonoticia 20260624182723 1920

fotonoticia 20260624182723 1920

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

2 minutes

Most read

Binance delivered last year to Russian authorities personal information and about the operations of a Russian citizen subsequently accused of financing terrorism by sending cryptocurrencies to organizations linked to Ukraine, according to an investigation by Reuters based on documents from Russian security forces. The delivery occurred despite the platform announcing in 2023 its complete exit from the Russian market.

The affected individual is Yuri Belenkiy, a 49-year-old IT specialist with a Russian passport and residence permit in Bulgaria. He is in pre-trial detention in Russia awaiting trial. According to the documents examined by Reuters, the Russian Investigative Committee requested from Binance his transaction history and received information identifying Belenkiy as the user who had made cryptocurrency transfers to an address disseminated by exiled Russian journalist Arkady Babchenko.

The documentation included in the investigation indicates that Belenkiy allegedly sent more than 700 dollars between 2023 and 2024. Russian authorities claim that the money was intended for the Ukrainian Armed Forces and the Azov group, considered a terrorist organization by Russia. The documents provided by Binance included, in addition to the transaction history, personal data such as his date of birth, address, phone number, passport number, and copies of his Russian passport and Bulgarian residence permit.

Data protection

The case also raises questions about the protection of data of European citizens. Mike Bystrov, a lawyer specialized in cryptocurrency regulation, believes that if Belenkiy was registered with Binance as a resident of the European Union, he could be protected by the General Data Protection Regulation (GDPR), which establishes restrictions for transferring personal information to countries without an adequate level of protection. Binance rejects that it is up to the company to decide on the legality of the investigations and asserts that, like other international financial entities, it cooperates with legal requests from authorities while respecting applicable privacy and regulatory obligations.

The case is not completely new. Memorial identifies Belenkiy as a political prisoner and recalls that the Russian investigation claims he made six transfers of about 62,000 rubles to addresses disseminated by Babchenko. The journalist, however, denied that Belenkiy had made contributions to his accounts and assured that his campaigns were intended exclusively to acquire medical material for emergency workers and health workers in Ukraine.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What requirements does the GDPR establish for transferring personal data from the European Union to countries like Russia?

The GDPR (General Data Protection Regulation) establishes a tiered system to regulate the transfer of personal data from the EU to third countries like Russia. The central idea is that when data "leaves" the European Economic Area, it can only do so if an essentially equivalent level of protection to the European one is guaranteed.

1. Starting point: when is there an "international transfer"?

There is an international transfer when a controller or processor subject to the GDPR (for example, a company or administration in Spain) communicates, grants access to, or hosts personal data in a third country, or allows remote access from that country (such as technical support from Russia). It does not matter if the server is in the EU: if an entity from a third country can access the data, for GDPR purposes it is usually considered a transfer.

2. Countries with adequacy decisions (Art. 45 GDPR)

The "simplest" option is the adequacy decisions by the European Commission: for those countries, it is understood that they offer an equivalent level of protection and the transfer is assimilated to a transfer within the EU.

However, Russia does not have an adequacy decision. Therefore, personal data cannot be transferred to Russia invoking Art. 45: one must resort to the safeguards of Art. 46 or, as a last resort, the exceptions of Art. 49.

3. Appropriate safeguards (Art. 46 GDPR)

When there is no adequacy, the general rule is that transfer can only occur if the data exporter establishes one of the "appropriate safeguards" provided by the GDPR, which must always be accompanied by enforceable rights and effective remedies for the affected individuals. Among them:

  • Standard Contractual Clauses (SCC) approved by the European Commission between the EU data exporter and the importer in Russia. These are the most common mechanism.
  • Binding Corporate Rules (BCR) for multinational corporate groups, approved by the competent supervisory authority.
  • Ad hoc contractual clauses or codes of conduct and certification mechanisms with enforceable commitments, subject to approval by the data protection authority.

Following the CJEU jurisprudence (such as the Schrems II ruling), the use of SCC or other safeguards requires conducting a transfer impact assessment: it is necessary to analyze whether the legislation and practices of the destination country (for example, powers of Russian authorities to access data) practically allow respecting the required level of protection. If not, supplementary technical, organizational, or contractual measures must be added (strong encryption with key management in the EU, robust pseudonymization, access limitations, etc.). If, even so, an essentially equivalent level cannot be ensured, the transfer should not be made based on Art. 46.

4. Exceptions or "derogations" (Art. 49 GDPR)

If there is no adequacy decision nor is it possible to implement appropriate safeguards, the GDPR provides a series of exceptions, which must be interpreted restrictively and not as a usual route. Among them:

  • Explicit consent of the data subject, informed of the possible risks of the transfer to a country without an adequate level.
  • Transfer necessary for the performance of a contract between the data subject and the controller (for example, a travel booking involving services in Russia) or for pre-contractual measures at the data subject's request.
  • Transfers necessary for important reasons of public interest recognized in EU or Member State law.
  • Transfers necessary for the exercise or defense of legal claims.
  • Transfers necessary to protect vital interests of the person or others when the person cannot give consent.

Additionally, the GDPR allows, in strictly limited cases, non-repetitive transfers concerning a limited number of data subjects based on compelling legitimate interests of the controller, with safeguards and prior detailed balancing (Art. 49.1, second paragraph).

5. Responsibility, documentation, and transparency

The controller in the EU must be able to demonstrate compliance with the GDPR ("accountability"). In the context of transfers to Russia, this implies, among other things:

  • Documenting the legal basis of the transfer (adequacy decision, safeguards under Art. 46, or exception under Art. 49).
  • Reflecting the transfer in the record of processing activities.
  • Informing data subjects, in the privacy policy, of the existence of the transfer, the destination country, and the applied safeguards or, if applicable, the associated risks.
  • Periodically reviewing the legal and technical conditions of the destination country and updating measures if circumstances change.

In summary, to transfer personal data to Russia under the GDPR, except for rare exceptions, it is necessary to implement appropriate safeguards (mainly SCC or BCR), assess the impact of Russian legislation on effective data protection, and, if necessary, implement enhanced technical and organizational measures. If it is not possible to achieve an essentially equivalent level of protection, the transfer could only exceptionally and limitedly rely on one of the derogations of Art. 49, or not be carried out at all.

What are the competencies of the Russian Investigative Committee in cases of terrorism financing?

Based on the sources accessible in this investigation — mainly Spanish and European institutional documentation and political and judicial press — no direct, detailed, and verifiable description has been found of the competencies of the Investigative Committee of the Russian Federation specifically regarding terrorism financing, nor of its concrete legal basis or formal coordination with the Russian Prosecutor's Office or the FSB. The consulted sources focus on the Spanish and European systems and, when mentioning Russia, do so only as an external threat or international actor, without entering into its internal procedural architecture.

Consequently, it is not possible, with the information available in this trace, to provide a reliable enumeration of:

  • The Russian legal provisions that grant competence to the Investigative Committee over terrorism financing acts (for example, which articles of the Penal or Procedural Code are reserved for it).
  • The exact distribution of functions among this Committee, the Prosecutor's Office, and the FSB in these types of cases.
  • The material or hierarchical limits of its actions (what it investigates directly, what it refers to other bodies, what thresholds of severity or territoriality are required, etc.).

What the sources do allow is to contextualize, by comparison, what it usually implies for a state body to have competence over terrorism financing investigation, because this pattern repeats in systems like the Spanish or the European Union:

1. Typical scope of competencies in terrorism financing

In the models described in the consulted documentation (Spain, EU), the bodies responsible for these crimes usually assume:

  • Direction of the criminal investigation on financing acts: opening proceedings, coordinating searches, seizing documents and devices, etc.
  • Specialized financial analysis of fund flows, bank accounts, cross-border movements, and corporate structures, usually in coordination with:
    • Financial intelligence units (in Spain, for example, SEPBLAC is cited in the press as a key actor in money laundering and terrorism financing).
    • Specialized police and intelligence services, which provide operational capacity and information gathering.
  • Preparation of the criminal case for possible prosecution: drafting reports, expert opinions, chains of custody of evidence, etc., which then support the accusation before the courts.
  • International cooperation in investigations affecting multiple countries, common in terrorism financing, through mutual legal assistance, information exchange, and participation in police or fiscal networks.
2. Typical relationship with prosecutors and security services

Also comparatively, the available documentation on Spain and the EU shows a recurring division of roles among:

  • Prosecutor's Office: holder of criminal action, which drives the procedure, legally qualifies the facts, and decides whether to prosecute and for which crimes. In notes about Spain, for example, it is explained how the Prosecutor's Office directs complex investigations on terrorism, genocide, or large economic networks.
  • Investigative bodies or judicial police: carry out fieldwork, investigative diligences, and reconstruction of facts, under the direction of the judge or prosecutor, depending on the procedural model.
  • Intelligence or internal security services: provide prior information and threat monitoring capabilities; in many countries, their focus is more on prevention and national security protection than on procedural instruction in the strict sense.

With this comparative pattern, it can be inferred, only at a very general level, that a body like the Russian Investigative Committee, when involved in terrorism and terrorism financing, will likely concentrate on:

  • Criminal instruction of the facts (interrogations, searches, evidence analysis).
  • Coordination with security and intelligence services to exploit operational information.
  • Preparation of a probative file that other bodies (courts, prosecution) will use at trial phase.

However, emphasizing the essential: the concrete details of how this is articulated in Russia — which articles of its legislation regulate it, what competence thresholds the Investigative Committee has versus the Prosecutor's Office or the FSB, what margin of discretion or hierarchy exists among them — do not appear in the consulted sources and therefore cannot be described here without speculation.

If you need a precise legal analysis of Russian law (for example, citing specific articles of the Penal or Procedural Code or the law of the Investigative Committee itself), the most prudent would be to consult directly:

  • The official version of the federal law on the Investigative Committee of the Russian Federation.
  • The Penal Code and the Criminal Procedure Code of Russia, in the chapters on terrorism (including financing).
  • Doctrinal commentaries or Russian law manuals detailing the division of functions among the Committee, Prosecutor's Office, and FSB.

What measures have other cryptocurrency platforms adopted in response to similar requests from foreign authorities?

In recent years, major cryptocurrency platforms and other crypto service providers have had to adapt their operations to requirements from foreign regulators. The measures adopted focus on four main blocks: stopping onboarding new clients, restricting or closing services, strengthening KYC/AML controls, and organizing orderly exits from certain markets, with client migration plans.

Orderly closure and market exit after MiCA (ESMA and CNMV)

The most systematic case in Europe is the application of the MiCA Regulation. The European Securities and Markets Authority (ESMA) has set out what is expected from unauthorized crypto-asset service providers at the end of the transitional period:

  • Stop onboarding new EU clients: unauthorized CASPs "must immediately stop onboarding new EU clients, refrain from initiating new relationships or accounts with them, and cease advertising and client acquisition activities" (ESMA statement 06/23/2026).
  • Limit operations to settlement: they may only provide services necessary to sell or transfer crypto-assets, reassign assets, or close positions. Custody is maintained only "for the strictly necessary period" to complete the orderly exit.
  • Intensive client information: it is required to communicate "clearly, quickly, and repeatedly" the liquidation plans, deadlines to unwind positions, and client protection requirements.
  • Maintenance of AML/CFT controls: throughout the process, effective anti-money laundering and counter-terrorism financing controls must be maintained, including customer due diligence, transaction monitoring, and sanctions list checks.

The CNMV transposes these guidelines to Spain. In its communication of 06/15/2026 on the end of the MiCA transitional period, it requires unauthorized providers to:

  • Have an effective migration plan that allows clients to move their crypto-assets to other addresses and their funds to cash accounts.
  • Set a reasonable deadline for investors to withdraw funds and, once expired, be able to transfer assets to authorized entities, informing those affected.
  • Communicate "clearly and continuously" in advance about the situation and migration plan.
Practical example: Binance in the European Union

Economic press reports a clear example of how a major platform has applied these requirements. According to Demócrata (06/26/2026), Binance began sending emails to its EU users warning that it would stop offering certain services at the end of the MiCA transitional period, having not obtained ESMA authorization in time:

  • It informed about the procedure to withdraw funds and asked users to stay alert for new notifications.
  • It committed to "minimize disruptions" and assured that "all user funds remain safe" while reorganizing its regulatory structure in the EU.
  • It communicated the withdrawal of a license application in Greece and its intention to start the procedure in another Member State, meanwhile assuming the closure of part of its services in the single market.

That is, the reaction combines: temporary renunciation to fully operate in a market, mass communication to clients, withdrawal windows for funds, and geographic restructuring to seek an alternative license.

Restrictions on risk profiles and strengthening KYC (Coinbase/CB Payments case)

Another response to regulatory demands has been to tighten the treatment of certain risk profiles. The UK Financial Conduct Authority (FCA) sanctioned CB Payments Limited (CBPL), part of the Coinbase group, for failing to comply with a requirement that prohibited it from serving high-risk clients (FCA note 07/25/2024).

In this case:

  • The company had accepted a voluntary requirement (VREQ) that prevented it from onboarding new high-risk clients while strengthening its financial crime control framework.
  • Despite this, it onboarded more than 13,000 high-risk clients, leading the FCA to impose a fine of 3.5 million pounds and emphasize the need for robust KYC/AML controls.

This type of case shows that, under regulatory pressure, platforms are forced to:

  • Segment clientele by risk and block or limit access for certain profiles.
  • Review and strengthen processes of identification, monitoring, and due diligence.
Common trends

From these actions by ESMA, CNMV, FCA, and examples like Binance or CBPL/Coinbase, a relatively homogeneous pattern is observed in the measures crypto platforms adopt in response to foreign regulator requests:

  • Ceasing onboarding of new clients in jurisdictions where they lack a license or are under investigation.
  • Limiting services to mere settlement and withdrawal of existing positions.
  • Client migration plans to authorized entities, with defined deadlines and procedures.
  • Strengthening KYC/AML and, where applicable, selective blocking of high-risk clients.
  • Geographic reconfiguration of licenses and corporate structures to continue operating in certain markets under new rules.

Overall, the typical response combines operational measures (blocks, closures, migrations) with a significant increase in identification and control obligations over users.

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

What type of information did Binance provide to the Russian authorities about Yuri Belenkiy?

Question 1 of 3

Why is Yuri Belenkiy accused by the Russian authorities?

Question 2 of 3

Which European regulation is mentioned in the news regarding personal data protection?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?