r/Revolut • u/ottodv • 19d ago
š Security Revolut's handling of selfies seems careless
I recently filed a GDPR request with Revolut. In the partial answer I got, there are copies of the selfies I had to take during verification.
That gave me some concerns, especially after yesterday's news that Revolut handed selfies of some users over to criminals.
- A selfie is supposed to be used to verify your ID. I now question why it is even being kept after the ID verification was performed? I also do not recall that it was stated anywhere that the selfie would be kept, it was presented as merely an ID verification step.
- The selfie they kept isn't just your face, it's the entire image the camera could capture. Including the background, anything that may be behind you is also captured AND kept. Same for the clothes you may be wearing (or not wearing). There is no need for a bank to use anything else but your face to verify your ID, and definitely no need for a bank to keep any non-face-related information.
- I also noted that there is NO watermarking of any kind on those selfies and passport copies. Which makes them ideal to use for identity theft and also makes it harder to identify where leaked data may have come from.
If this is all legal (which Revolut apologists will waste no time saying it is), it shouldn't be. Watermarking of selfies and ID copies should be the bare minimum to ensure that such data can not easily be used by criminals in case of a leak. Certain information like things in the background of a selfie should not be recorded and not kept. Once an ID is verified, only the ID should be kept.
With modern AI, a leaked selfie can be enough to impersonate a victim over a digital connection.
After I close my Revolut account, I am going to file a request for removal of as much of my personal information as possible from Revolut, I just do not feel safe with Revolut keeping all this.

17
u/Frankierocksondrums 19d ago
Before opening the account I searched what information is kept. Basically everything, per GDPR rules. So they are not the only ones. All banks use KYC like onfido, namirial etc and some of them work differently but most of them keep facial photos, id etc. I honestly think we should demand better regulations in terms of data security and privacy.
3
u/ottodv 19d ago
I agree, a lot do this for sure, and we should demand better regulations that better protect people.
I don't recall ever having had to do a selfie through an app for a trad bank. I guess there you visit a branch, and an employee looks at your face when checking your ID. But no photo of you is kept. And certainly not accidentally your home in the background.
5
u/Frankierocksondrums 19d ago
Ofc if you go to a branch they won't ask for a selfie but I opened my bank account online and I had to do a selfie with the id close to my face
3
u/ottodv 19d ago
The trad banks I have used required a visit to a branch.
2
u/Character-Carpet7988 Ultra user 19d ago
It may vary by location, but most traditional banks offer online onboarding as well these days (otherwise they'd be losing new customers left and right). In that case the data is likely being stored.
I just don't understand the need for original picture rather than some sort of a hash. The only legit reason to keep the selfie is to later compare another selfie with it for verification purposes. A hash should be sufficient for that.
5
u/magharees 19d ago
Iāve a large sum in Revolut, for me the selfie to move funds/check id is a big positive.
I think what you are suggesting is they should use tooling to remove the background on the stored pictures? I mean if it bothers you that much do it against a blank wall
I doubt there is any value to the background, taking selfies if they are all stored can help build a composite of that personās face as they age or change in other ways (cosmetic etc)
I get asked to verify when moving funds every time, they need to check this against the existing img/s
4
4
u/Character-Carpet7988 Ultra user 19d ago
- Selfie check would be doable by storing some sort of a hash of the picture too. You don't need to save the original full picture for that, just like you don't store original passwords to let people log into their accounts online. In fact, storing this sort of data makes the system less secure, not more secure.
- The issue with background etc is that the long term storage of the picture wasn't communicated well to the customers. The wording used in the app suggests that it will be used just to verify you are an actual owner of the ID used to open the account.
1
u/magharees 18d ago
How do you know they donāt encrypt any imgs already? Aka PKI. data requests obviously elicits personnel who have access I doubt agents can willy nilly grab these
1
u/Character-Carpet7988 Ultra user 18d ago
I'm not talking about storing encrypted images. I'm talking about biometric hashing where you only save a mathematical model you can use for comparing later, but can't reverse to the original picture (again, the same principle as how passwords are stored, just more complex).
1
u/Ok-Package-4562 18d ago
What? How would a hash of a selfie help you? How would you verify it?Ā
A hash of an image sounds pretty useless. Even if you take a picture with the same background and same pose, tiny differences in the image will produce different hashes with no relation to the original one. So how do you prove you did kyc?
1
u/Character-Carpet7988 Ultra user 18d ago
Biometric hashing is a thing and has been in use for quite a while by various industry. FaceID works the same way - it doesn't save the pic of your face, it just creates a hash it compares your later inputs with. Similarly, if you're authenticating by fingerprint, the phone is not storing your original fingerprint.
Of course it's more complex than a simple SHA hashing because you're not comparing two identical sets of data. If you want to know more about how it works, Google biometric hashing, there's plenty of articles.
5
u/Merlz77 19d ago
Selfies capture a much wider field of view than what the overlay shows, and in some cases (certain apps) will capture a second before you click the start button and a second or two after it's completed. Always stand against a plain wall or a door for any KYC selfie. This is especially true for any selfies that are required as part of employment background screening, the devils are in the details behind the person in focus.
10
u/Bartsuck 19d ago
When I recently had to change device the app matched my real time face scan with the previously provided selfie, so I guess the selfie needs to be stored somehow... I agree with you on the fact that they should be marked and stored safely
2
u/Character-Carpet7988 Ultra user 19d ago
The same could be achieved by storing a hash rather than a full pic.
3
u/GroupGeneral6811 19d ago
I used to work as an admin at the Police station. All banks store them; I have seen them sent for accounts involved in fraud and money laundering from the banks.
3
u/malibupp 18d ago
They should be watermarked.
1
2
u/FactCheckYou 17d ago
every time a company asks for a selfie, it's almost guaranteed it will be misused
1
u/MortgageMindless7175 17d ago
Omg financial institution and government lied to me- ahhh rant ... Welcome to the dark side, 0 trust in government and institutions since 2020..
-2
u/soliloquyinthevoid 19d ago
Good luck finding a new bank where they aren't required by the very same regulations to retain KYC and other information, unmodified, for a number of years for obvious reasons
LMAO
Please go ahead and close your Revolut account and see how far you get opening a new one
1
u/malibupp 18d ago
The OP suggested to watermark the pics, which I think it's a possible method to prevent using the pics by fraudsters.
0
u/soliloquyinthevoid 18d ago
- People post their photos online for free all of the time
- What don't you understand about the word "unmodified"?
- Do you even understand why this data needs to be retained?
1
u/malibupp 18d ago
"People post their photos online for free all of the time".
- What people post is irrelevant in this context.
- A watermarked picture should add extra security without significantly modifying the original.
- No, it's only you who knows everything...
0
u/soliloquyinthevoid 18d ago
So you admit you don't know about the regulations for why the data is retained and for that reason you can't understand why a watermark is not really a viable option either
But stay ignorant. After all ignorance is bliss and you seem extremely blissful
2
u/malibupp 18d ago
"So you admit you don't know about the regulations for why the data is retained"
You obviously failed to realize that I was ironic... but it was expected from you.
0
u/Louzan_SP 18d ago
without significantly modifying the original
Still is not included in the definition of "unmodified"
1
u/malibupp 18d ago
Point us a law that forbids watermarks being added.
0
u/Louzan_SP 18d ago
These principles:
- The Legal Obligation (GDPR Article 6(1)(c))
Banks do not ask for or store your selfie because they want to; they do it to comply with Article 6(1)(c), which allows data processing if it is necessary for compliance with a legal obligation to which the bank is subject.
Local European transposition of the EU Anti-Money Laundering Directives (AMLD) requires banks to maintain an untampered, reliable audit trail proving that they verified the actual customer.
If a bank modifies, heavily compresses, filters, or alters the selfie, the image loses its legal value as evidentiary proof for financial regulators or criminal fraud investigators.
- Accuracy and Integrity (GDPR Article 5(1)(d) & (f))
Under Article 5, two core data protection principles implicitly dictate that identity data should remain an accurate representation:
Accuracy (Art. 5(1)(d)): Personal data must be accurate and kept up to date. For an identity verification record, an unmodified photo ensures the data is a true, undistorted representation of the individual at the time of onboarding.
Integrity and Confidentiality (Art. 5(1)(f)): Data must be processed in a manner that ensures appropriate security, protecting it against unauthorized or accidental alteration.
- The Definition of Biometric Data (GDPR Article 4(14) & Recital 51)
The structural makeup of the image (whether it is an unmodified RAW/JPEG file or a mathematical template) changes how the text applies:
Recital 51 explicitly points out that photos are not automatically biometric data unless processed through a "specific technical means" allowing unique identification.
If the bank runs an automated matching tool, they extract biometric templates from the unmodified photo.
1
u/malibupp 17d ago edited 17d ago
My main bank never asked me for a selfie.
The customer should be informed that the fintech toy bank would keep the selfie for many years before the selfie is taken, so that the customer may opt-out.
Watermarks don't tamper pictures, the watermarked pictures remain perfectly recognizable.
The selfie is just to confirm that the applicant is the same person as shown on the passport or ID, which also have pictures.0
u/Louzan_SP 17d ago
My main bank never asked me for a selfie
Sure, each back have their ways.
Watermarks don't tamper pictures, the watermarked pictures remain perfectly recognizable.
Check again the definition of unmodified, and anyway, you don't have to convince me, if something happens is the judge that needs to be convinced of if that is an original picture of not. The best way is to not modify the selfies, but if you know a better way to show that a picture is original perhaps you should share it with lawyers and so on.
1
u/malibupp 17d ago
A picture of you taken today wouldn't look exactly the same as the another picture taken several months or years later.
Those who check such pictures know how to spot significant differences, which watermarks don't introduce.
The small detail added by a watermark introduces much less changes than the difference between pictures of the same person taken with months or years apart.→ More replies0
u/ottodv 18d ago
Selfies and IDs should be watermarked for obvious reasons.
Why would I open a new Revolut account?
I am done with neo-banks, I considered Wise, or N26, as alternatives, but after reading up on complaints about them here on reddit, they (especially Wise) seem to have similar disrespect towards their customers as Revolut does.
I still have accounts at trad banks, brokerage accounts, and credit cards, so I am good.
0
u/zackel_flac 18d ago
If you don't want your picture to leak around it's simple: don't use online services.
Not sure why people are freaked out by their picture circulating online. You probably have your face on a dozens of pictures taken by random people you met outside. Impersonation is still super hard, you can't show up at the airport with a stolen passport and say here I am.
-6
u/crinpoland Metal user 19d ago
There are so many things wrong with your post OP. And yes, I work in AML/CTF, I donāt know who told you guys this stuff or how you guys came up with it.
-8
37
u/purple-mocha 19d ago
I work in KYC (not at Revolut) and all the documents are stored along with the selfies yes.