Skip to main content
Why non-regulated entities should conduct data collection now (even without legal mandates)

Why non-regulated entities should conduct data collection now (even without legal mandates)

This is some text inside of a div block.
By:
Rabihah Butler,
Rabihah Butler
August 21, 2026
4 min
August 21, 2026
This is some text inside of a div block.

Federal law lets non-regulated businesses skip KYC checks, but ignoring customer verification is a gamble few can afford. By collecting onboarding data, compliance pros can shift this task from a chore to a critical shield for operations and liability

Key insights:

  • Non-regulated entities operate without collection mandates — Retailers, SaaS platforms, and content publishers face no overarching federal requirement to collect identity verification or conduct background checks.
  • Practical and contractual reasons compel data collection anyway — Basic customer information is essential for service delivery, contract enforcement, payment processing, and fraud mitigation.
  • Privacy laws now apply regardless of financial regulation — Even without AML obligations, companies must comply with data privacy rules that govern what they collect and how they protect it.

Banks and fintech companies operate under strict anti-money laundering and know-your-customer requirements, which compel them to verify identities and screen customers against sanctions lists.

Yet, non-regulated entities face no such mandates. A retail business, SaaS company, or content publisher has no federal requirement to collect identity proof or conduct verification. This distinction creates a misleading assumption that non-regulated businesses can safely ignore customer onboarding data. However, that assumption overlooks several critical realities.

Why businesses should collect onboarding data anyway

There are good reasons a business should collect idendity data despite not facing any legal mandates to do so, including:

Protecting business operations

The most straightforward reason non-regulated entities collect customer data is operational necessity. Without it, basic business functions become impossible.

For example, e-commerce retailers require shipping addresses, phone numbers, and email contacts to deliver orders and manage returns. They need customer name and address information for invoicing and billing records. And SaaS platforms need verified email addresses to create accounts, reset passwords, and send billing notifications. They also require a company name and billing address for enterprise contracts.

Further, rideshare apps, delivery services, and marketplaces all collect information on contractors, vendors, and customers to ensure safety and manage liability as well as to facilitate transactions, process payouts, and comply with tax reporting obligations.

These operational requirements exist independently of regulatory mandates. A subscription service cannot renew a customer's membership without contact information, or a marketplace cannot issue 1099 forms or process seller payments without verified bank account data. Customer data collection directly enables these core business functions and customer satisfaction.

Collecting customer data is essential for detecting and preventing fraud.

The alternative to structured on-boarding creates real operational problems. Without standardized collection, customer service teams spend time manually requesting missing information. As a result, returns and billing becomes difficult, payment disputes escalate, and customer satisfaction suffers when basic operational data is incomplete.

Ensuring contractual protection

Collecting customer information serves a critical legal function by ensuring that companies deal with legitimate entities. Identity and contact details establish a contractual foundation essential for enforcing terms of service, collecting unpaid invoices, and managing disputes.

A platform cannot enforce its terms without knowing who violated them or pursue payment recovery without reliable contact information.

Engaging in fraud prevention

Collecting customer data is essential for detecting and preventing fraud. Non-regulated entities face multiple fraud threats that customer information can help mitigate.

Chargeback fraud occurs when customers claim non-receipt or unauthorized transactions and reverse charges through their bank. Contact information and order details allow merchants to respond with delivery proof or signatures. Without this data, merchants lose disputes by default. Refund abuse exploits return policies through repeated purchases of seasonal items or discounted merchandise with immediate refund requests. If the data is collected, then email and payment history can reveal patterns of serial abusers across multiple accounts.

Various fraud crimes such as account takeover fraud, friendly fraud, synthetic identity fraud, and velocity fraud, which involves rapid account creation designed to overwhelm detection systems. Criminal fraud rings create fake accounts to exploit sign-up bonuses and referral programs. Without name, email, and phone verification, platforms may become vulnerable to these coordinated fraud campaigns.

The absence of a federal mandate doesn't erase the business imperative.

Data collected during onboarding — such as email, phone, address, payment method, IP, device information, billing and shipping address matching — creates a verification baseline. Deviations from this baseline trigger fraud alerts. Unusual patterns such as address mismatches, multiple accounts from same IP, impossible geographic velocity, or payment method anomalies all become detectable.

Yet without this foundation of transaction integrity, customer trust, and fraud prevention, many platforms would be operating blind to fraud.

Complying with data privacy rules

Non-regulated entities must comply with privacy laws such as the European Union's General Data Protection Regulation (GDPR) and state-level privacy acts in the United States. These regulations impose requirements on what data companies can collect, how they obtain consent, and what safeguards protect information. Companies must collect only what is necessary, secure proper consent, and implement robust data protection practices.

Moving forward

The absence of a federal mandate doesn't erase the business imperative. In an era in which synthetic identities, account takeover attacks, and data breaches are routine, waiting for regulation to catch up is a strategy built on borrowed time. Operational efficiency, contractual leverage, fraud mitigation, and emerging privacy laws have converged to make customer verification not just prudent, but essential.

Non-regulated entities that approach onboarding strategically gain more than risk reduction. They build defensible operations, strengthen partner relationships, and create audit trails that matter when disputes arise or breaches occur. More importantly, they signal to customers, investors, and insurers that protection isn't an afterthought, it's part of their process.

You can find out more about the challenges of corporate compliance and risk management here

Follow us on social

Have questions?

Get in touch with one of our solutions experts....
Thomson Reuters Institute logo
Why non-regulated entities should conduct data collection now (even without legal mandates)
Federal law lets non-regulated businesses skip KYC checks, but ignoring customer verification is a gamble few can afford. By collecting onboarding data, compliance pros can shift this task from a chore to a critical shield for operations and liability
August 21, 2026
4 min
Corporate Compliance & Risk
Rabihah Butler
Manager for Enterprise content for Risk, Fraud & Government
Thomson Reuters Institute
Headshot of Rabihah Butler
Reputational Risk
Risk Management
US Regulators
Regulatory intelligence
Corporate professionals
10 Global Compliance Concerns for 2026: How the compliance landscape is transforming
"Future of Professionals" report analysis: How AI can help corporate functions align with their organization’s strategy
The banks you don't know you're using: Risks of unregulated banking