Main Takeaways

  • Given the prominence of data in today’s digital society, the critical role of data protection extends to almost every aspect of Binance’s global operations, providing a foundational governance layer upon which other business functions are built.

  • Working in the background, Binance’s Data Protection team helps foster the basis of user trust by upholding users’ privacy rights and empowering them to take ownership of the data they share with us.

  • In 2023, our Data Protection team handled over 22,000 privacy-related inquiries and proudly received five security certifications worldwide.

Personal data has become an indispensable part of our digital society, shaping organizational behavior and driving the economy. Given this prominence, users interacting with our platform must have confidence that we are properly handling their data; it is what provides the basis of their relationship with us. Working behind the scenes, Binance’s Data Protection team lays the groundwork for this foundation of user trust. If you wanted to get a copy of your data on our platform or delete it, the team would be your key point of contact.

As digital sentinels of our ecosystem, the Data Protection team remains committed to upholding the sanctity of personal data that users entrust to us. Aligned with Web3 principles of openness and transparency, the team plays a crucial role in Binance’s mission of enhancing financial freedom safely and securely by putting users’ interests first.

An Integrated Network

Dedicated to safeguarding user data, Binance’s Data Protection team is composed of two core parts: the Data Protection Office (DPO) and the Data Protection Counsel (DPC). The DPO handles the governance of the data privacy and protection program at Binance, while the DPC offers legal guidance for this program. Supporting these core teams, there are volunteer “Privacy Champions” distributed across different units of the company – employees who have undergone data privacy training and are enthusiastic about promoting best data protection practices in their respective business units. This integrated network ensures all Binance employees understand and adhere to our data principles.

The Data Protection team’s key responsibilities encompass a broad range of tasks grounded in upholding privacy principles. These include ensuring regulatory compliance, developing internal governance policies, assessing and mitigating data risks, training employees, managing data access, and handling data subject rights requests. Crucial to these responsibilities is the “privacy-by-design” framework, a principle incorporating privacy considerations into the design phase of products and services from the beginning. Another key principle is data minimization, which limits the collection and processing of data to only the minimal amount necessary, thereby decreasing the risk of privacy violations or data breaches.

While only a single team, the role of the Data Protection team reaches across the company, integrated into the backend of almost every facet of Binance’s global operations. As Murilo from the DPO team comments, “Data protection is not only about privacy. We need to understand the core activities and issues of each business unit and user base. Since most data-driven operations involve the use of personal data, it requires a cross-functional effort.”

A global mission

A global industry leader operating in numerous countries around the world, Binance employs the highest standards to ensure its users’ personal data is protected. We follow the stringent guidelines set by the EU’s General Data Protection Regulation (GDPR). Largely acknowledged as the gold standard in data protection regulation, our adherence to GDPR ensures we observe the highest levels of data security and privacy.

However, Binance’s data protection initiatives are more than compliance-driven; they are integral to our user-focused mission. By fostering trust with our users and empowering them to take control of their personal data, we support our global mission of enhancing financial freedom in today’s rapidly digitizing world.

“Our commitment to data privacy isn’t just a regulatory requirement but a strategic asset, supporting Binance’s mission of enhancing financial accessibility globally by building trust with our users and empowering them.” – Murilo, DPO team

In 2023 alone, the Data Protection team successfully handled over 22,000 privacy-related inquiries from users, employees, authorities, and other stakeholders. More than 9,800 of these were data subject rights requests. In recognition of the robustness of our data privacy protocols, the team proudly received five coveted privacy certifications globally – a testament to the quality of their work. They were also instrumental in ensuring all Binance employees received data protection training.

Championing Privacy on All Fronts

The Data Protection team’s governance of data privacy matters influences almost every aspect of our business. Coordinating with the rest of the company in such matters would be impossible without the support of Privacy Champions. Dispersed across various business units, these dedicated individuals are entrusted with promoting and enhancing our internal privacy culture. Privacy Champions help embed privacy as a core value across the organization, not just ticking boxes for compliance but integrating it into all fronts of our global operations.

Each Privacy Champion undergoes comprehensive training, gaining an in-depth understanding of Binance’s privacy policies and practices. Armed with this knowledge, they spread our proactive privacy measures across the company by sharing this wisdom with their colleagues. Moreover, they serve as the Data Protection team’s eyes and ears on the ground, identifying potential privacy risks, escalating any privacy-related matters in their units, and upholding our data protection standards across the company. Last year, the team onboarded 45 new Privacy Champions, demonstrating the importance of collaboration in our ecosystem.

Customer Service

The Customer Service (CS) team plays a pivotal role in handling user data, which necessitates a deep understanding of our data protection frameworks. To equip our CS agents with the necessary knowledge and skills, the team’s dedicated Privacy Champions provide comprehensive educational resources. Through these initiatives, they help ensure that every customer interaction reflects Binance’s commitment to upholding their privacy rights. In 2023, the CS Privacy Champions trained over 2,000 CS agents, enabling them to handle user data with the utmost diligence. 

“We strive to ensure every member is well-equipped, assisting in our sessions, information gathering, and the co-creation of training programs. It is precisely this richness of collaboration and shared mission that defines our team in the most quintessential sense.” – Chloe, CS Privacy Champion

Security

Security and privacy often go hand-in-hand, especially when developing new products and services. Hence, the Security team’s Privacy Champions are essential for incorporating data privacy principles into the design phase. Beyond the day-to-day coordination of our Security and Data Protection teams to handle potential privacy or security concerns, this collaboration helps weave data privacy into the fabric of every initiative Binance undertakes.

Here, the privacy-by-design framework offers an actionable approach that integrates privacy considerations into the design and operation of business practices, offerings, and systems. It improves upon traditional reactive measures, proactively promoting privacy as an integral feature from the beginning. While it can be difficult to incorporate at times, the coordination between the Security and Data Protection teams helps streamline this process. By implementing the privacy-by-design framework, Binance is able to keep privacy considerations at the forefront when innovating.

“Incorporating privacy-by-design frameworks into the security development lifecycle (SDL) helps foster a strong link between security and privacy, thus creating more resilient and trustworthy applications.” – SS, Security Privacy Champion

Web3: A New Frontier

The essence of data protection lies in upholding the fundamental right to privacy. As we move into the next phase of our digital era, where data is increasingly being incorporated into society, openness and transparency in data handling will only become more critical. A key development here has been the rise of Web3 and its principles of decentralization, offering a future where ownership is back in the hands of users.

Aligned with this vision, Binance’s Data Protection team is confident in building a sustainable future for the industry. As Ezgi from the DPC team shares, “We are in a time where we can influence how our personal data is used and govern how personal data should be protected. I am really happy and passionate to be a part of this great era of privacy.” Rémi from the DPO team adds, “My favorite part of the job is helping people. I joined Binance because contributing to the ecosystem and being part of this journey was an opportunity I couldn’t pass up.”

Dynamic challenges

Web3’s principles of openness and transparency play a dual role, fostering user trust and promoting more accountable practices by organizations. The all-encompassing nature of these duties can present unique challenges for the Data Protection team as they must constantly consider the multifaceted aspects of data privacy across different regions and industries. Many team members say that the hardest part of the job is keeping up with the rapidly changing regulatory environment, not only in data privacy but also in related areas such as finance, security, and technology, all of which directly impact their work.

Operating in such a landscape requires a collaborative and dynamic team culture, and many members praise their colleagues for fostering such a proactive work environment. As Hannah from the DPC team states, “No big decisions are made without considering all views, and we are encouraged to give each other feedback. I appreciate the independence of the role, which results from our trust in each other and our self-motivated nature.”

Binance Privacy Portal

For Data Privacy Day 2024, we unveiled our Binance Privacy Portal, a testament to our mission of empowering users. Born out of a desire to improve the user experience in the Web3 space, the portal provides a more comprehensive, intuitive, and engaging resource to demystify data privacy. Here, users can learn how we handle their data, exercise their privacy rights, and contact our DPO team for extra support.

We welcome our users to explore this new resource and continue their journey of digital empowerment with Binance. As Murilo says, “Our objective here transcends mere legal compliance. We strive to empower our users, enabling them to feel confident and in control of their data within our app.” The Binance Privacy Portal would have been impossible without the initiative of the Data Protection team, demonstrating their commitment to ensuring that users feel secure, supported, and truly in control of their data.

Empowering Digital Trust

In the rapidly evolving digital ecosystem, data protection has emerged as a crucial pillar, shaping business interactions, establishing digital trust, and supporting sustainable growth. Beyond legal compliance, the essence of data protection lies in maintaining an ethical and responsible use of data, which can range from simple, tangible tasks (such as the appropriate handling of hard-copy data on a piece of paper) to the nebulous and complex (as with developing new software using AI-driven decision-making algorithms).

This fundamental principle of data protection is not only about shielding information; respecting user rights and preferences is equally important. It’s about ensuring not just the security of personal data but also the appropriate use of such information, holding fast to the user’s rights and liberties relating to privacy. It aims to establish a digital environment where users feel secure and fully in control of their data, fostering their trust and ultimately creating an ongoing, mutually beneficial relationship with any institution.

“I believe data protection is an essential part of the operations of every company, business, and individual. I take pride in safeguarding not only Binance’s interests but also the data of our partners, users, employees, visitors, and more every day.” – Shermayne, DPO team

The role of the Data Protection team isn’t simply foundational; it’s transformational. They steer the direction of our operational areas, ensuring that ethical data handling underpins every interaction, from our customer service to our technical product design. Beyond ensuring compliance, this team embodies the deeper philosophy of data privacy — respecting users’ rights, maintaining their preferences, and solidifying their trust in Binance. Thus, the team supports Binance’s vision of a user-centric, transparency-led world of digital finance.

Further Reading