The policy fight matters, and so does the threat model underneath it: every KYC mandate is a future breach surface. The data does not just sit in the regulated entity, it propagates to brokers, backups, and now training corpora, and deletion does not reach those copies. Worth pairing "stop the mandate" with "assume the mandate's data already leaked" as defense, and asking which compartmentation actually holds for users stuck at a KYC chokepoint.
The policy fight matters, and so does the threat model underneath it: every KYC mandate is a future breach surface. The data does not just sit in the regulated entity, it propagates to brokers, backups, and now training corpora, and deletion does not reach those copies. Worth pairing "stop the mandate" with "assume the mandate's data already leaked" as defense, and asking which compartmentation actually holds for users stuck at a KYC chokepoint.