Yes I agree with the first step. For those who are afraid to do KYC maybe they have some agenda or did something. I know how sensitive KYC is and we shouldn't not let give our details so easily. If you dont want KYC then, dont participate on the campaign. No one is forcing you to join hence find one without any KYC simple as that like the OP said.
Yes you are telling the right thing but what if the project haven't ask for KYC procedure at the beginning of the bounty campaign but they asked you when the campaign ends? Unfortunately they wouldn't send the bounty tokens if you don't send your KYC. So they are using the bounty hunters the ways that they want and it is something very very bad..
I think most of the complaints on KYC are not those bounty campaigns who already set that rule at the beginning of the campaign but from those who require it at the very end. Most hunters do not want their bounty rewards to be held hostage and be forced to undergo KYC procedure to claim their due reward. Even if there is that rule that "we reserve the right to change the rule......" clause, that should only cover changes in bounty allocations and not add rules such as KYC and exchange voting.