What Binance actually handed over
Yuri Belenkiy, a 49-year-old IT specialist, sent just over 700 US dollars in cryptocurrency between January 2023 and March 2024 to wallets linked to Ukraine's military, including a group Russia designates as a terrorist organization, after exiled Kremlin critic Arkady Babchenko publicized the appeal. Russian investigators detained Belenkiy in September 2025 and formally charged him on October 13, 2025. According to case files and correspondence reviewed by Reuters, the evidence against him traces back to Binance: after Russian law enforcement wrote to the exchange's compliance address for Russian and Belarusian requests, Binance replied at least twice with a data file confirming the transfer, plus Belenkiy's date of birth, home address, phone number, passport number, a copy of his Russian passport, and a copy of his Bulgarian residency permit.
Binance's own comment on the record, given to reporters this week, does not dispute that it answered the request. It says only that it "cooperates with lawful information requests from law enforcement globally, subject to applicable legal, privacy and regulatory requirements," and that it runs its own internal assessment of whether a request is suitable before releasing anything. It declined to discuss the Belenkiy case specifically or to say whether the disclosure might have breached European data protection rules.
The exit that was never a data wall
Binance has told users and regulators since September 2023 that it withdrew from the Russian market: no local entity, no local licensing, no local product. That framing did real work for the exchange's reputation with Western regulators watching sanctions compliance. But an exit like that is a licensing and business decision, not a promise that the request-answering pipeline for that jurisdiction shuts down too. The correspondence Reuters reviewed shows Russian investigators still had a working channel into Binance's compliance team more than a year after the stated exit, and that channel still produced a full personal-data file on request.
That gap matters beyond this one case. Any global platform that formally withdraws from a market can keep a compliance mailbox open to that market's authorities indefinitely, because nothing in an exit announcement obligates it to stop answering. For a user, the practical protection was never the exit headline - it was whatever internal judgment call the platform's compliance team makes on each individual request, a process invisible to the person whose data is on the other end of it.
A GDPR rule with no one currently enforcing it
The legal theory here is straightforward. If Belenkiy was registered with Binance as a resident of Bulgaria, an EU member state, his personal data falls under GDPR. Russia is not on the EU's list of countries offering an adequate level of data protection, so transferring his file there without a valid legal basis such as a court order or a mutual legal assistance request would breach the regulation. Legal specialists who reviewed the case for reporters this week made the same point: a mere email request from foreign investigators is not the standard GDPR sets for moving an EU resident's passport data into a country with no data protection agreement with the bloc.
What is missing is anyone actually testing that theory. Binance will not confirm Belenkiy's registered residency. His lawyer would not confirm it either when asked. The European Data Protection Board has stayed out, saying enforcement sits with national authorities, not with it. As of publication, no single national data protection authority - not Bulgaria's, not any other member state's - has said it opened a file on this case. The rule that should have stopped this transfer is real. The body that would enforce it against a global exchange, in this specific case, does not currently exist.
Read next: Ireland Cancels Its EUR1 Billion Microsoft Tender | PSN's EUR231M Loan Bets on a Still-Loss-Making Cloud



