Summary
- Reuters-reviewed documents show Binance supplied Russian investigators with personal and transaction data later used in a terrorism-financing case against a Russian IT specialist.
- The customer holds a Bulgarian residency permit, although it has not been established whether he was registered with Binance as an EU customer and therefore covered by GDPR for the disclosure.
- The case exposes the difficulty global technology and financial platforms face when law-enforcement demands collide with privacy rules, sanctions, and conflicting national legal systems.
Binance supplied Russian investigators with personal and transaction information about a cryptocurrency customer whose donations to Ukrainian causes were later used as evidence in a terrorism-financing case, according to law-enforcement documents reviewed by Reuters. The disclosure raises a difficult cross-border data question because the customer, Russian IT specialist Yuri Belenkiy, holds a Bulgarian residency permit, while Binance had publicly announced that it was leaving Russia in 2023.
The documents show that Russia’s Investigative Committee requested information about cryptocurrency transfers made by Belenkiy and that Binance responded with material including transaction records and identifying data. Russian authorities subsequently cited transactions made through the exchange as evidence in proceedings against him after alleging that he had sent more than $700 to Ukrainian military-linked fundraising efforts between January 2023 and March 2024.
Belenkiy was detained in September 2025 and is awaiting trial in Russia. The information sent in response to investigators included his date of birth, address, telephone and passport details, as well as copies of his Russian passport and Bulgarian residency permit, Reuters reported. Binance said it cooperates with lawful law-enforcement requests subject to applicable legal, privacy, and regulatory requirements while declining to discuss the details of an individual confidential request.
It has not been established whether Belenkiy was registered with Binance as an EU resident, which would be material to assessing how European data protection rules applied to the disclosure. His Bulgarian residency permit creates an obvious European connection, but residency documentation alone does not prove how his Binance account was classified or which legal entity controlled the relevant customer data. Reuters said Belenkiy’s lawyer did not respond when asked whether the account was registered to him as a Bulgarian resident.
Law-enforcement requests cross regulatory borders
Large digital platforms routinely receive demands for customer information from police, prosecutors, tax authorities, and intelligence agencies, but those requests become more difficult when the user, service provider, data controller, and requesting authority sit in different legal systems. Compliance with a request that appears valid under one country’s law may still create obligations under privacy, sanctions, or human-rights rules elsewhere, particularly where data is being transferred into a jurisdiction that the EU does not recognise as providing equivalent personal-data protections.
The Binance case makes that conflict unusually visible because the company announced in September 2023 that it was selling its Russian business and described continued operation in the country as incompatible with its compliance strategy. The documents seen by Reuters nevertheless show Russian investigators later receiving responses associated with an email address used for law-enforcement communications, while Binance maintains that financial institutions still have obligations to respond appropriately to legitimate requests from authorities.
European data law does not create a simple prohibition on every international disclosure, but transfers outside the European Economic Area are governed by conditions intended to maintain protection when personal information crosses borders. Russia does not benefit from an EU adequacy decision, and any assessment of this case would depend on matters including which Binance entity controlled the data, whether Belenkiy fell within the relevant European regime, the legal basis for disclosure, and the mechanism under which information was transferred. None of those questions has yet been resolved publicly by a regulator.
Reuters approached the European Data Protection Board, which said enforcement questions fall to national supervisory authorities, while Bulgaria’s Commission for Personal Data Protection did not respond to questions about whether data-protection rules had been breached. A significant gap therefore remains between the facts visible in the Russian case file and the legal assessment required before concluding that Binance violated European law.
Platform exits do not end data obligations
The issue extends beyond cryptocurrency because multinational technology companies often retain data, contractual relationships, historic account records, or legal obligations in countries after reducing commercial operations there. Leaving a market can end sales, staffing, or revenue-generating activity without instantly removing years of customer information or the possibility that authorities will seek access to it. Companies therefore need policies for dealing with requests from jurisdictions where their commercial presence has changed but their historical data footprint has not.
Geopolitical conflict makes those decisions harder still because information that appears routine in a financial-compliance context can have very different consequences when transferred into a criminal investigation connected with war, political opposition, or organisations designated differently across jurisdictions. Russia classifies the Azov formation involved in the case as a terrorist organisation, while the broader legal and political treatment of Ukrainian military fundraising is plainly different across Europe. A platform responding to an information request can consequently become part of a legal process whose assumptions are not shared by the jurisdiction where the customer lives.
The documents examined so far concern Belenkiy’s case, and Reuters could not determine whether other Binance customers who donated to Ukrainian causes were identified through similar requests. Broad conclusions remain premature, although the case already shows why cross-border disclosure controls have become a governance issue rather than a back-office compliance task. Global platforms need to know not only whether an authority has asked correctly for information, but which entity holds it, which privacy regime applies to the person concerned, what restrictions govern its transfer, and what foreseeable consequences follow once the data leaves their systems.












