The Price of a Payout: Twitch Wants Your Official ID
Twitch is introducing mandatory ID verification for streamers who want to receive payouts. If you’re earning money on the platform, you will now have to verify your identity. On its face, this isn’t controversial. Financial compliance rules, fraud prevention, and tax regulations often require platforms to verify the identity of the people they pay.
The friction starts with how this verification is handled. Twitch is reportedly using Persona, an identity verification company, to process these checks. That detail matters because the company has recently faced scrutiny over security concerns and vulnerabilities.
To be clear, verifying identity before sending money isn’t inherently unreasonable. If a platform is paying you, it needs to know you’re a real person and not committing any type of fraud. But when verification involves uploading government-issued ID documents, trust becomes central. And trust is fragile.
The Persona Problem
Persona is an age and identity verification provider used by multiple major platforms. Recently, however, the company has been under the spotlight due to security concerns and reports of vulnerabilities.
When a company handles sensitive data like passports, driver’s licenses, and facial scans, even minor weaknesses can have serious consequences. For streamers, this isn’t theoretical. This is your legal identity. Your address. Your birth date. Potentially biometric information. Once submitted, it lives somewhere in a system you have no real control over.
Even if Twitch itself is secure, outsourcing verification to a third party means your data travels beyond one ecosystem. The concern isn’t that verification exists. The concern is whether due diligence is being done at the speed required when handling highly sensitive personal information. Creators are being told that if they want access to their income, they must comply. That shifts the power dynamic quickly.
Bigger Than Twitch
This is part of a broader trend. Across the internet and the world, countless platforms are increasingly requiring identity verification. Sometimes it’s for age assurance. Sometimes it is for payouts. Sometimes it is for regulatory compliance. Each individual step can be justified.
Taken together, they create an online environment where anonymity becomes harder to maintain, and personal data becomes more concentrated in centralized verification systems. What worries me most is how quickly these systems are rolled out.
Compliance deadlines approach. Laws tighten. Platforms partner with verification vendors. Users are told to upload documents or lose access to features. There’s rarely public transparency about vendor vetting processes. Independent audit information is rarely presented to users in plain language.
We are expected to trust that it has been handled. Maybe it has. Maybe it hasn’t. But when verification becomes mandatory to access earned income, skepticism is healthy. Streamers are not criminals. They’re creators trying to get paid for their work. Many are small independent earners without legal teams or cybersecurity advisors.
And they’re now being asked to submit highly sensitive documents to a third party that has recently faced security questions. That deserves scrutiny.
Rushing Toward Verification Culture
I understand why platforms move in this direction. Regulators are demanding accountability. Financial systems have always demanded traceability. Fraud is real. But there’s a difference between implementing safeguards thoughtfully and rushing to deploy verification systems simply to check a compliance box.
When companies partner with vendors that have faced security issues, users deserve transparency. What were the risks? Were they resolved? Has the system been independently audited? How is data stored? For how long? Who has access?
Those questions aren’t anti-compliance. They’re pro-safety. The internet increasingly asks users to surrender more identity data in exchange for participation. The least platforms can do is demonstrate that this data is being handled with the highest possible standard of care.
Twitch’s new rule may be legally sound. But legality isn’t the same as digital safety. If the future of online work requires handing over government ID at every turn, then platforms have a responsibility to ensure that the companies processing that data are beyond reproach. Getting paid should not mean gambling with your identity.
Be part of the resistance, quietly.
Get Mysterium VPN

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
