SODALABS

The on-chain privacy landscape, mapped.

A living map of the teams and technologies building on-chain confidentiality, across FHE, MPC, garbled circuits, ZK, and TEE, and where each approach fits.

BlockchainPrivacyReportQ3 2026FHE · MPC · ZK · TEE

The Quarterly Blockchain Privacy Report.

Market map

Who’s building what.

Soda LabsBuilt on SodaEveryone else· Click any card to read the full entry

Privacy projects.

Teams building confidentiality for blockchains, across the four technology families. Strengths and documented limits, with sources.

Bubble
by Soda Labs
Soda Labs

Bubble integrations.

Where Soda Bubble already plugs in: wallets, token standards, and vaults. Each one has a page explaining how the integration works.

Wallets
Soda Bubble support
Soda Bubble support
Soda Bubble support
Soda Bubble support
Soda Bubble support
Standards
Soda Bubble support
Soda Bubble support
Soda Bubble support
Soda Bubble support
Soda Bubble support
Vaults & platforms
Soda Bubble support
Soda Bubble support

Privacy on different chains.

Where each network stands on confidentiality: privacy built into the protocol, privacy provided by others, and where Soda Bubble is live. Highlighted cards are networks Bubble runs on today.

One correction worth making up front: a ZK rollup is not a private chain. Validity proofs there serve scaling, and rollups publish their state data precisely so anyone can reproduce it. Transparency is a security requirement of the design, not an unfinished privacy feature.

Bubble privacy enabled
Bubble privacy enabled
Bubble privacy enabled
Bubble privacy enabled
Soda privacy enabled

Privacy-enabled tokens.

Stablecoin issuers, DeFi protocols, tokenization platforms and asset managers, and how far each has actually got with confidentiality. Most of the market is still at the start of this list, which is the point.

The landscape as we read it · claims about other projects carry sources · corrections welcome on any card

Privacy and the rulebook

What the regulators actually say.

Confidentiality and compliance are usually described as opposites. Read the instruments and they mostly are not. What supervisors demand, almost everywhere, is attribution: that a regulated firm can identify the parties and disclose on request. That is a different requirement from publishing amounts to the world, and almost nothing in these rules asks for the second. The distinction decides what is actually buildable. This section works through where the two systems genuinely collide, where they fit together once the obligation is read precisely, and what is still unresolved.

Every entry has a page of its own, with the full reading and its primary sources: all 107 regulation entries, by jurisdiction.

StanceAttribution requiredConfidential with disclosureBuilds with privacy techRegime still forming· Click any card for the instruments and sources behind it
01 / 03 · The recurring questions (8)

Where privacy and the rulebook actually meet.

The questions that come up in every jurisdiction: what the travel rule really demands of a confidential transfer, whether an immutable ledger can honour a deletion request, and what regulators have said about viewing keys and selective disclosure.

The rule everyone assumes ends on-chain confidentiality

The most common objection to confidential transfers is that the travel rule forbids them. Read the standard and it does not. Recommendation 16 obliges the institution to obtain, hold and transmit originator and beneficiary details to the counterparty institution. Nothing requires that data to be written into the transaction, and in practice it never is: compliant systems move an IVMS101 payload over a separate channel while value settles on chain. On a transparent chain the names are already off-chain. Making the value leg confidential changes neither the duty nor the ability to discharge it. What stays genuinely hard is the other side: due diligence toward self-hosted wallets, where there is no counterparty institution to message, and the sunrise problem of uneven adoption between jurisdictions.

Read more
The one collision with no clean answer yet

This is the collision that does not dissolve on closer reading. European regulators treat a public key as personal data wherever it can identify someone, and are explicit that encryption does not take data outside the rules, nor does hashing. Against that sits an append-only ledger. The EDPB's answer is architectural rather than doctrinal: keep personal data off chain, and design so that on-chain data can be rendered effectively anonymous when erasure is requested. It concedes this is technically demanding while insisting technical impossibility is no defence. Destroying a decryption key is treated as making data unintelligible rather than erased. Commitments fare better, since deleting the original and its witness leaves something genuinely useless behind. No supervisor or court has yet tested either in a contested case.

Read more
Bilateral disclosure versus publishing to everyone

Supervisory access, external audit and suspicious activity reporting are all bilateral disclosures to a named party under a legal duty. Public-ledger transparency is something else entirely: universal, unauthorised disclosure to everyone, permanently. No other part of the financial system is asked for the second in order to satisfy the first. Viewing keys are the oldest worked example, letting a holder share visibility of shielded activity without surrendering the ability to spend, and they are already used for exchange deposit detection and custodian-to-auditor disclosure. Threshold decryption generalises this to a quorum. Two honest caveats. We found no regulator that has endorsed the pattern in guidance, so this is an argument from structure rather than from authority. And viewing keys are blunt: per address, retrospective and prospective at once, with no revocation once shared.

Read more
Association sets, and the Tornado Cash aftermath

The 2023 Privacy Pools paper made a design argument that has held up: instead of hiding everything, let a depositor prove in zero knowledge that their withdrawal belongs to a chosen set of deposits, or does not belong to a flagged one. Honest users dissociate from illicit funds without revealing which deposit is theirs, and the policy judgement moves to an identifiable, contestable curator rather than sitting in the protocol. A mainnet implementation launched in 2025. The contrast with Tornado Cash is instructive rather than settled: the Fifth Circuit held in November 2024 that OFAC had exceeded its authority because nobody controls an immutable contract, and the sanction was lifted in March 2025. The criminal case against Roman Storm is a separate matter and remains live, so treat anything you read about it as provisional.

Read more
What the people writing the rules do when they design money

The strongest evidence that public authorities do not equate confidentiality with wrongdoing is that they keep building it. The BIS Innovation Hub's Tourbillon prototypes, developed with the Swiss National Bank, were designed around payer anonymity: a consumer pays without revealing personal information to the merchant, to the banks or to the central bank, while the payee remains identified to their own bank. The BIS presents this as compatible with anti-money-laundering aims rather than in tension with them, precisely because the receiving side stays legible. The Bank of England has run comparable work on offline digital pound payments. Read together with the digital euro's offline design, the pattern is consistent: asymmetric privacy, where the party being paid is known and the party paying is not, is a design regulators actively pursue.

Read more
The demand side, which is usually left out of the debate

The compliance debate usually asks whether institutions are permitted to use confidentiality. The prior question is whether they can function without it. An institution operating on a fully transparent ledger publishes its order flow, inviting anyone to trade ahead of it; its counterparty set and exposures; its treasury positions; its payroll; and its clients' commercial terms. Where counterparties are people, it also publishes personal data that data protection law obliges it to minimise. No regulator asks for any of this. Public visibility is a property of the ledger, not a supervisory requirement, and the two are constantly confused. The revealed preference shows up in architecture: institutional settlement has concentrated on permissioned networks whose main selling point is that only the transacting parties see the trade.

Read more
The genuinely open problem

Worth stating plainly rather than glossing: this is the weakest part of the case for confidential ledgers. Sanctions liability under the US regime attaches without knowledge or intent, so any design that leaves a regulated intermediary unable to determine whether it dealt with a designated party hands that intermediary unmanaged legal risk. That mechanism, more than any explicit prohibition, is what drives delisting. The architectural answer is that screening does not require public amounts and parties, only that somebody with the duty can screen: at the on-ramp and off-ramp where identity already exists, inside the state machine as issuer policy, or through authorised disclosure. The unsolved parts are real. Designations are retroactive while proofs are historical, and a shielded transfer between two self-custodied parties has no intermediary at all. We found no regulator guidance and no enforcement precedent on any of it.

Read more
Why two privacy designs get treated differently

Regulators keep drawing a line that the debate tends to flatten. What the instruments actually turn on is who holds the disclosure lever, not how strong the cryptography is. A protocol with mandatory, protocol-level anonymity leaves a regulated intermediary with no compliant posture at all, because it cannot produce records it has no mechanism to obtain. A design with encrypted state and a disclosure path leaves that intermediary roughly where it sits in conventional finance: data confidential from the public, available to the authorised party. Two caveats we would rather state ourselves. This is our reading of the drafting, not a position any regulator has published. And issuer-retained control is a real centralisation risk, not a free win. The EU's key phrase, increased obfuscation of transactions, is undefined, and AMLA guidance will decide how far it reaches.

Read more
Filter the two directories below
Region
Stance
02 / 03 · Standard-setters (33)

Standard-setters and regulators.

The bodies whose rules travel across borders. Most set standards that national supervisors then write into law, which is why the same few instruments turn up in every jurisdiction below.

European Union · ESMA
Europe
Confidential with disclosure
Market licensing · Regulation (EU) 2023/1114

MiCA carries exactly one operative anonymity rule, and it is narrower than its reputation. Article 76(3) requires a trading platform's operating rules to prevent admission of crypto-assets with an inbuilt anonymisation function, unless the platform can identify the holders and their transaction history. It binds trading venues only: custody, transfer, exchange and execution are untouched, no coin is named, and "inbuilt anonymisation function" is left undefined. ESMA has issued no guidance interpreting it, so national competent authorities apply it with varying strictness, which is where listing fragmentation across the bloc comes from. Titles III and IV applied from 30 June 2024, the CASP regime from 30 December 2024, and national grandfathering closed for good on 1 July 2026.

Read more
Financial Action Task Force
Attribution required
The source of almost every travel rule on earth

Nothing else in this section has as much reach. FATF sets standards rather than law, but the mutual evaluation process and the grey list make adoption close to compulsory, which is why the same travel rule appears in every jurisdiction below. Recommendation 15 brought virtual assets into scope in 2018, and its interpretive note carries the transfer threshold. The July 2026 targeted update found peer-to-peer transfers through self-hosted wallets treated as high risk in 88% of responding jurisdictions. Two things cut the other way and are usually missed: the 2025 revision of Recommendation 16 is not applied directly to virtual asset providers, and FATF's own July 2026 report on information sharing concludes that data protection law, not technology, is the main barrier to cooperation.

Read more
European Union · EBA
Europe
Attribution required
Travel rule · Regulation (EU) 2023/1113

This, not the privacy-coin headline, is what actually ends unattributed transfers at the EU perimeter. The recast travel rule attaches originator and beneficiary name, address and account identifier to every crypto transfer between providers, with no de minimis threshold at all, where the fiat regime it recasts has one. Above EUR 1,000 to or from a self-hosted address, the provider must take adequate measures to establish that its own customer owns or controls that address. Self-hosted wallets are not banned and peer-to-peer transfers between two of them sit outside the regulation entirely. Applicable since 30 December 2024, operationalised by EBA guidelines that specify the data fields, it is the reason EU exchanges now ask who owns the withdrawal address.

Read more
US Congress · Treasury · FinCEN · OFAC
Americas
Attribution required
Stablecoins · censorability as a licensing precondition

The most restrictive thing in current US law on this subject, and it is architectural rather than procedural. A payment stablecoin may only be issued if the issuer has the technological capability to comply with any lawful order, and a lawful order is defined as one requiring it to seize, freeze, burn or prevent transfer. In other words the ability to censor is a precondition of the licence, designed into the token rather than imposed on the operator afterwards. Foreign issuers face the same test or lose access to US secondary trading. There are narrow counterweights: the word privacy appears once, requiring FinCEN to weigh privacy risks in what it collects, and the implementing proposal does not require issuers to monitor secondary market activity.

Read more
European Union · AMLA · national FIUs
Europe
Attribution required
Anti-money laundering · Regulation (EU) 2024/1624

Reported almost everywhere as an EU ban on privacy coins from 1 July 2027. Two things are wrong with that. The date is 10 July 2027, when the AMLR begins to apply. And the prohibition binds obliged entities, not people: banks, financial institutions and licensed crypto providers may not keep anonymous accounts, or accounts that anonymise the holder or obfuscate transactions including through anonymity-enhancing coins. It creates no offence for holding or spending such an asset, outlaws no protocol, and leaves self-custody standing, which the recitals treat as a risk factor to be assessed rather than something barred. What it does mean is that regulated European venues will almost certainly drop support. How far it reaches assets with optional privacy will be settled by AMLA guidance, not by this text.

Read more
MAS
Asia-Pacific
Confidential with disclosure
The regulator that priced the risk instead of banning it

Worth reading closely because it is the road not taken elsewhere. Faced with the same assets that Dubai and Malaysia prohibited outright, Singapore's regulator chose enhanced obligations instead, and said so in Parliament: privacy coins, privacy wallets and mixers are to be risk-assessed and monitored, not barred. Firms are told to pay special attention to technologies that favour anonymity, which is a supervisory expectation rather than a listing rule. MAS has also observed that most licensed providers decline to offer such assets anyway, which is the market making a commercial choice rather than the regulator making it for them. The transfer rules are strict in the other direction, with no minimum value at all.

Read more
Dubai Virtual Assets Regulatory Authority
Middle East & Africa
Attribution required
The most explicit prohibition in any rulebook

Most regimes reach anonymity-enhanced assets sideways, through listing criteria, liquidity gates or traceability tests. Dubai's regulator simply writes it down: issuance of such assets, and every activity related to them, is prohibited in the Emirate. That makes VARA the clearest counterexample to the pattern running through this section, and it is quoted far beyond the UAE precisely because so few instruments are this direct. Two things temper it. The prohibition binds licensed activity in Dubai rather than individuals, and self-custody survives: providers must document how they handle transfers involving unhosted wallets, which is a diligence obligation and not a ban.

Read more
US Treasury · Office of Foreign Assets Control
Americas
Confidential with disclosure
Sanctions · where the law found a limit

The most severe action ever taken by a government against privacy tooling, followed by the most significant legal retreat from one. Sanctioning Tornado Cash in 2022 meant that touching a set of immutable contracts became a strict-liability violation, with no intent requirement. The Fifth Circuit held that unlawful in November 2024 on a narrow but durable ground: property under the statute means something someone can own or control, and nobody can own an immutable contract. Treasury delisted in March 2025. Read the limits carefully before drawing comfort from it. The holding binds one circuit, it says nothing about mutable or upgradeable contracts, and OFAC's appetite for designating people and addresses is undiminished.

Read more
US Treasury · Financial Crimes Enforcement Network
Americas
Attribution required
Bank Secrecy Act · the deepest US constraint

Registration, identity verification and suspicious activity reporting for anyone acting as a money transmitter in crypto all originate here, and none of that has loosened. What has changed is the perimeter around it. The two most aggressive proposals aimed at self-custody were both withdrawn: the 2020 unhosted wallet rule in 2024, and the plan to lower the cross-border transfer threshold to USD 250 in 2025. The 2019 guidance also still distinguishes providing an anonymising service from publishing anonymising software, which matters a great deal to developers. The open question is the 2023 proposal to treat mixing as a class of transactions of primary money laundering concern. Nearly three years on it is neither finalised nor abandoned.

Read more
03 / 03 · Jurisdictions (66)

Jurisdiction by jurisdiction.

Where each country actually stands: the financial supervisor, the data protection authority, and whether the two pull in the same direction. Stance reflects what the rules say about confidentiality, not how welcoming the country is to crypto generally.

Europe(25)
Finanzmarktaufsicht
Confidential with disclosure
EU baseline, with an early transition close

Austria's only real distinguishing feature in this area is timing. It was among the member states that chose a short grandfathering window, closing the door on national-regime operators near the end of 2025 rather than running to the outer limit the following July. On the substance of confidentiality it adds nothing: the FMA authorises and supervises, and the operative rules are the European ones. We located no Austrian provision on anonymity-enhancing assets or transfers to self-hosted wallets. Firms that missed the earlier deadline had to be authorised or stop, which made Austria one of the tighter places to be caught mid-transition.

Read more
FSMA · National Bank of Belgium
Confidential with disclosure
EU baseline, with no national layer on confidentiality

Belgium adds no national layer on confidentiality, and that is worth stating plainly rather than manufacturing local colour. The authority to deal with is the FSMA, working alongside the National Bank on prudential questions, and the rules that actually bite are the European ones covered elsewhere in this section: identity attached to every transfer regardless of size, and from July 2027 a bar on regulated firms keeping accounts that anonymise the holder. Nothing Belgian restricts anonymity-enhancing assets or self-hosted wallets. For anyone mapping obligations, that means the Belgian answer is the European answer.

Read more
Česká národní banka
Confidential with disclosure
EU baseline, supervised by the central bank

Czechia is one of the member states that put crypto supervision inside the central bank rather than with a separate markets authority, which matters more for how firms experience the process than for what the rules say. On confidentiality it adds nothing to the European position: we located no Czech instrument restricting anonymity-enhancing assets or self-hosted wallets. The operative constraints are the ones described in the European entries in this section, and the practical question for anyone operating here is the authorisation process at the central bank rather than any distinctively Czech rule about how private a transaction may be.

Read more
Finanstilsynet · Skattestyrelsen
Confidential with disclosure
EU baseline, with tax as the historic pressure point

Denmark is a useful reminder that the financial supervisor is not always the body that matters most for privacy. Its crypto framework is the European one, administered by Finanstilsynet, with no national rule on anonymity-enhancing assets or self-hosted wallets that we could locate. The pressure historically came from the tax side, where the administration has obtained transaction and identity data covering the customer bases of domestic exchanges in bulk rather than case by case. That is a different mechanism from anything in the financial rulebook, and it is the one worth checking in any jurisdiction: what the revenue authority can compel often exceeds what the market supervisor asks for.

Read more
Finantsinspektsioon
Confidential with disclosure
The licence cull that reshaped the European market

Estonia mattered to this market out of proportion to its size, because for a few years it issued more crypto authorisations than anywhere else in Europe. The 2022 amendments ended that: capital requirements, real local presence, a compliance officer and fit and proper testing of owners took the register from over fourteen hundred licences to roughly a hundred. Worth being precise about what that was and was not. It was a gate on who may operate, not a rule about what operators may offer. We found no Estonian instrument touching anonymity-enhancing assets or self-hosted wallets, so on confidentiality the European baseline governs here as it does elsewhere.

Read more
AMF · ACPR · CNIL
Confidential with disclosure
Hardest against anonymity, most literate about privacy tech

France pulls harder in both directions than any other member state. On one side it legislated against transactional anonymity earlier and more explicitly than the EU baseline required: providers may not hold anonymous accounts, identification is required before any occasional transaction with no minimum value, and anonymous electronic money cannot be used to buy digital assets. On the other, its data protection regulator produced the most technically literate guidance any European authority has published on building compliant chains. The 2018 analysis ranks cryptographic techniques in order of preference and states that a perfectly hiding commitment, once its witness is destroyed, ceases to be personal data at all. That is a regulator describing how to do this properly rather than warning people off.

Read more
National Bank of Georgia · State Audit Office
Attribution required
The one place where privacy oversight went backwards

Across every jurisdiction surveyed for this section, institutional privacy oversight was either strengthening or holding steady. Georgia is the exception. Its independent data protection authority was liquidated in March 2026 and the function folded into the State Audit Office, which removes the separation that made the supervisor independent in the first place. On the financial side the picture is restrictive but conventional: providers have registered with the central bank since mid-2023, and using virtual assets for payment is barred by the organic law governing the central bank. Peer-to-peer trading with one's own funds stays outside the regime. We found no instrument addressing anonymity-enhancing assets either way.

Read more
BaFin · Bundesbank · BfDI and the Länder authorities
Confidential with disclosure
A national custody licence, and secrecy for tokenised securities

Germany's divergence runs in two directions and neither is about coins. It built a national licence for crypto custody before the EU had one, and that licence survives alongside the European regime without carrying a passport. But it drew the line at self-custody in unusually clear terms: holding your own assets is not the licensed activity, because you are not doing it for anyone else. Less discussed, and more interesting for this section, is the confidentiality rule for tokenised securities. A holder's identity and address may be disclosed from the register only on a special legitimate interest, weighed against their data protection interests. That is confidentiality by default in a securities register, with no equivalent in EU law. Germany's data protection authorities, notably, have published nothing at all on blockchain.

Read more
Seðlabanki Íslands · EFTA Surveillance Authority · Persónuvernd
Confidential with disclosure
MiCA a year late, the travel rule not yet switched on

Iceland is worth a card mainly for what it reveals about the EEA route into EU financial law. It adopted the European crypto framework a full year behind the union, shifting the internal dates forward so the transitional architecture still worked. More consequentially, the two instruments that matter most for confidentiality have arrived at different speeds. The travel rule was incorporated into the EEA agreement in June 2025 but the government's own database still records implementation as not begun, so the obligation exists in principle without national machinery. The EU anti-money-laundering regulation, which carries the 2027 prohibition on anonymous accounts, has not been incorporated at all. For now the binding rule here is the narrower trading-platform test.

Read more
Central Bank of Ireland · Data Protection Commission
Builds with privacy tech
A central bank piloting zero-knowledge KYC

Ireland adds nothing of its own to the EU rules on crypto confidentiality, and that is worth saying plainly rather than inventing local colour. What makes it worth a card is the opposite move. Its central bank ran its first innovation sandbox specifically on financial crime, and one of the seven projects put zero-knowledge proofs to work inside the compliance process itself: verifying a customer's name and address in real time against authoritative national datasets without revealing or transferring the underlying data. That is a supervisor hosting a live pilot of exactly the technique this section argues is compatible with regulation, inside the very programme aimed at money laundering. Very few of the accommodating signals elsewhere in this section are that concrete.

Read more
CONSOB · Banca d'Italia · Garante per la protezione dei dati personali
Confidential with disclosure
Customer-level reporting to a public registrar

Italy's national addition was a reporting channel rather than a prohibition, and it went further than the European baseline in an unusual direction. Providers registered in the special section had to transmit, every quarter, identification data for each customer together with summary data on that customer's overall activity in Italy. That is customer-level reporting to a registrar, on a fixed cycle, with no suspicion trigger and no transaction threshold. Nothing comparable exists in the EU rules the framework sat on top of. On the questions this section is otherwise about, Italy is quiet: we found no restriction on anonymity-enhancing assets and no national rule on self-hosted wallets.

Read more
Finanzmarktaufsicht
Confidential with disclosure
Identification unbundled into its own licensed role

Liechtenstein made a structural choice worth understanding: rather than requiring every participant to identify counterparties, it turned identification into its own licensed role. An identity service provider is defined as the party who identifies whoever is entitled to dispose of a token and records them in a register, and the corresponding duty is to assign identifiers correctly to the lawful holder and keep customer data securely. That scopes the surveillance function to a nameable actor instead of spreading it everywhere. Technology neutrality is written into the statute's purpose rather than asserted in marketing. Nothing in the text we read restricts anonymity-enhancing assets. Note that the financially regulated activities have since been carved out to the EU regime, leaving this act covering the civil-law and non-EU residue.

Read more
Bank of Lithuania
Confidential with disclosure
Capital requirements used as a filter

Lithuania took the same route as Estonia and reached a similar destination by a different instrument. Rather than testing substance and ownership, it raised the capital floor to EUR 125,000 and struck off everyone who had not met it by the end of 2022. Firms lost the right to operate from the first day of 2023. Like Estonia's, this was a filter on who may hold a licence rather than a rule about confidentiality, and we located nothing in Lithuanian law addressing anonymity-enhancing assets or self-hosted wallets. Supervision now sits with the central bank, which is a slightly unusual choice among member states.

Read more
Commission de Surveillance du Secteur Financier
Confidential with disclosure
EU baseline, seen through a fund domicile

Luxembourg carries weight here because of what is domiciled in it rather than because of any national rule on confidentiality. It is one of Europe's main fund jurisdictions, so the questions that arise are institutional: what a regulated fund may hold, through which custodian, and what diligence the manager must do on the assets themselves. Those duties tend to bite on provenance and on who controls the keys rather than on whether amounts are public. On the narrower question this section asks, we located no Luxembourg instrument restricting anonymity-enhancing assets or self-hosted wallets, so the European baseline governs.

Read more
AFM · De Nederlandsche Bank · Autoriteit Persoonsgegevens
Confidential with disclosure
The wallet verification demand that was abandoned

The Netherlands ran the most aggressive self-hosted wallet identification demand in Europe and then gave it up, which makes it the most instructive European case in this section. Providers had to verify the address on every transfer to or from an external wallet, in practice by asking customers to photograph their wallet or sign a message. Worth being precise, because the headlines were not: the court did not annul the requirement. It gave the regulator six weeks to justify it properly. The regulator then accepted the challenge was well founded, revoked the requirement and stopped collecting screenshots. A supervisor reversing itself on proportionality grounds is rare enough to be worth citing wherever the unhosted wallet question comes up.

Read more
Finanstilsynet · Norges Bank · Datatilsynet
Confidential with disclosure
MiCA via the EEA, with a privacy-innovation sandbox

Norway took the EU rulebook through the EEA route and enforced it promptly, closing its transition window in July 2026 with providers told to wind down. That means the zero-threshold travel rule applies here as it does inside the union. The counterweight is unusual and worth knowing about: the Norwegian data protection authority has run a regulatory sandbox for privacy-enhancing innovation since 2020, and in 2024 ran a joint track with the financial supervisor. Few jurisdictions have both regulators in the same room on this question. Norges Bank concluded that a central bank digital currency is not currently warranted and closed its exploration phase in March 2026, so no retail privacy design question arises.

Read more
KNF · GIIF
Regime still forming
The one EU state with no functioning licensing regime

Poland is the exception that shows how the EU framework behaves when a member state cannot implement it. Three presidential vetoes have blocked the national act, so no authority has been designated to licence providers. Meanwhile the European deadline passed regardless: since July 2026, serving the Polish market without authorisation breaches Union law, and the only lawful route in is cross-border activity by firms licensed elsewhere. Around two thousand registered operators are caught between the two. The substance of the dispute is directly relevant here, because the objections concerned how long a regulator may freeze accounts and block domains without a court, which is the supervisory-power question underneath most privacy arguments.

Read more
CMVM · Banco de Portugal · CNPD
Confidential with disclosure
A data regulator stopping biometrics bought with tokens

Portugal's distinctive contribution came from its data protection authority rather than its financial regulators, and it addresses a question the financial rules do not reach. When an identity system offered crypto tokens in exchange for iris scans, the authority suspended collection of biometric data across Portuguese territory as an urgent measure, citing collection from minors without parental authorisation, inadequate information, and no way to delete data or withdraw consent. The detail that matters here is the absence of any age check while people joined specifically to receive tokens. It is a regulator treating payment for biometric data as the problem, which is the mirror image of most debates in this section, where the worry is that transactions reveal too much rather than that identity is being bought.

Read more
Bank of Russia · Federal Tax Service · Rosfinmonitoring
Attribution required
Wallet addresses reported to the state by statute

Russia has the most direct on-chain deanonymisation mandate found anywhere in this section. Miners must report the address identifier itself, mining pool included, to the tax authority, which passes it to the financial intelligence body and the central bank without any suspicion trigger. That is wallet-address disclosure written into statute rather than inferred from analytics. The digital rouble points the same way. Accounts sit not at a bank but on the central bank's own platform, with banks acting as front ends, so the issuer is positioned to see every transaction. The central bank's promise is precise and worth reading closely: the data carries the same bank secrecy as an ordinary account and will not exceed what cashless payments already reveal. That is confidentiality from third parties, not from the state.

Read more
CNMV · Banco de España · AEPD
Confidential with disclosure
First in the EU to regulate how crypto is advertised

Spain's national contribution sits on the marketing side rather than the confidentiality side, and it got there first. Its advertising circular, in force since February 2022, was the earliest crypto advertising regulation published in any EU member state: it compels a specific risk warning and requires campaigns aimed at more than a hundred thousand people to be notified to the regulator ten business days in advance. That is a rule about how crypto is sold, not how privately it can be held. On the questions this section is actually about, Spain adds nothing to the European baseline, and we found no Spanish instrument restricting anonymity-enhancing assets or transfers to self-hosted wallets.

Read more
Finansinspektionen
Confidential with disclosure
EU baseline, with a hawkish supervisory tone

Sweden has a reputation for hostility to crypto that is worth separating into its parts. Its supervisors have been openly sceptical about crypto as an investment and about its energy use, and that scepticism is real. But it is a view about an asset class, not a rule about confidentiality, and the two get conflated constantly. We located no Swedish instrument restricting anonymity-enhancing assets or transfers to self-hosted wallets. What applies is the European framework, supervised by Finansinspektionen. Anyone reading Swedish policy statements as a privacy position is reading across a gap that the instruments themselves do not close.

Read more
FINMA · Federal Data Protection and Information Commissioner
Attribution required
Crypto-friendly and strict on anonymity at once

A useful corrective to the assumption that a crypto-friendly jurisdiction is permissive about anonymity. The two are unrelated, and Switzerland proves it. Nothing in Swiss law bans privacy coins, and the regulator treats anonymity as a risk factor rather than a prohibited property. But since 2019 supervised institutions have only been able to move tokens to an external wallet where that wallet belongs to their own identity-verified customer, with ownership demonstrated by technical proof. There is no minimum value and no carve-out for unregulated wallets, which makes it stricter than both the FATF standard and the EU rule that followed. The practical effect is that regulated Swiss venues are closed to anonymous self-custody, by supervisory practice rather than statute.

Read more
Capital Markets Board · MASAK · KVKK
Attribution required
Caps, delays and a compelled purpose description

Turkey reaches the same destination as an anonymity ban without ever writing one. No primary instrument prohibiting anonymity-enhancing tokens was found. What exists instead is a stack of operational controls that make routine confidentiality impractical at licensed venues: value caps on transfers, doubled only if the full travel rule dataset is collected, a mandatory waiting period before withdrawal, a declaration requirement for anything touching an unhosted wallet, and a compelled free-text description of what every transfer is for. Each measure is individually defensible as anti-fraud policy. Together they amount to a regime where a licensed Turkish venue cannot process a transfer it does not have a stated reason for.

Read more
NSSMC · National Bank of Ukraine · Ombudsman
Regime still forming
The law that passed and never commenced

An unusual case: the virtual assets law passed in February 2022 is recorded in the official register as never having entered into force. With no operative licensing regime, there is no in-force restriction on anonymity-enhancing assets and no constraint on unhosted wallets, not as a policy choice, but because the machinery was never switched on. A MiCA-based replacement passed first reading in 2025 and would change that quickly. The detail worth carrying forward is the central bank's e-hryvnia design note, which states plainly that the regulator will not have any personal information. Explicit commitments of that kind from a central bank are rare enough to be worth citing wherever they appear.

Read more
FCA · Bank of England · Information Commissioner
Confidential with disclosure
Risk-based, with an explicit central bank no-access pledge

The UK has built a full regulatory perimeter without reaching for a single prohibition on privacy technology. There is no ban on anonymity-enhancing assets and no bar on transfers to unhosted wallets; firms are expected to document a risk-based approach, and transfers into jurisdictions that have not implemented the travel rule call for enhanced assessment rather than refusal. Two things are worth noting on the other side of the ledger. The FCA runs a permanent digital sandbox offering hundreds of synthetic, anonymised and pseudonymised datasets, cooperating with the data protection regulator. And the digital pound design carries an unusually direct commitment that neither the Bank nor the Government would have access to users' personal data.

Read more
Americas(12)
CNV · Unidad de Información Financiera · AAIP
Confidential with disclosure
Self-custody providers written out of the regime

Argentina drew its perimeter in the place this section keeps arguing is the right one. Providers of self-custody wallets are exempt from the registration regime by the resolution's opening article, which is the most explicit carve-out for non-custodial software we found anywhere in the Americas. What the rules do restrict is the service rather than the asset: registered providers must not offer mechanisms designed to hinder identification of where a transaction came from and where it went. No coin is named. Read together, the two provisions describe a coherent position: the regulator claims authority over intermediaries that obscure flows, and disclaims it over software that merely lets people hold their own keys.

Read more
Securities Commission of The Bahamas · Central Bank
Attribution required
Issuance of privacy tokens barred, trading not

The Bahamas holds the sharpest contradiction in this section, and both halves are deliberate. Its 2024 act bars issuers from offering privacy tokens for sale in or from the jurisdiction, and makes the provision of anonymity-enhancing services a regulated activity. The nuance almost always dropped in reporting is that the bar is on issuance: trading and exchange of such tokens is not prohibited, so long as the business can meet its obligations while doing it. Meanwhile the country's own central bank digital currency ships a tier that requires no identification at all below modest limits. A state that will not let you issue a private token will let you hold its own money without giving your name.

Read more
Bermuda Monetary Authority · Privacy Commissioner
Attribution required
A travel rule with no minimum, reaching self-hosted wallets

Bermuda restricts no asset by name and still runs the most comprehensive transaction surveillance requirement found in the Americas. There is no minimum value: every virtual asset transfer carries originator and beneficiary information. More unusually, the obligation expressly reaches transfers to self-hosted wallets, where most regimes either carve out an exemption or say nothing at all. Set against that, the regulator has published no position whatsoever on anonymity-enhancing assets, mixers or tumblers, treating everything under the single heading of digital assets. It is a clean illustration of the pattern running through this section: the binding constraint on confidentiality is the transfer rule, not a list of forbidden coins.

Read more
Banco Central do Brasil · CVM · ANPD
Attribution required
A named anonymity rule, and a CBDC that could not solve privacy

Brazil holds the two halves of this section's argument in one place. Its listing rule is among the most explicit anywhere, requiring providers to bar assets designed to favour money laundering by facilitating anonymity, while the same framework expressly contemplates a client choosing self-custody and asks only that the provider explain the risks. Then there is Drex. The central bank spent a pilot phase testing zero-knowledge designs precisely to build confidentiality into a state currency, and reported that the approaches which delivered privacy also cost it the visibility and control it judged necessary for its legal obligations. That is the trilemma stated by a central bank from its own experiment rather than argued in the abstract, and it is the most honest public account of the problem we found.

Read more
BVI Financial Services Commission · Information Commissioner
Confidential with disclosure
Structural confidentiality kept, transactional confidentiality not

The British Virgin Islands is a useful illustration that confidentiality is not one thing. At the level of corporate structure it deliberately preserves it: beneficial ownership information is filed with the regulator but not publicly disclosed, which is a policy choice other jurisdictions have abandoned under pressure. At the level of transactions it does the opposite, applying a travel rule from a thousand dollars and extending automatic exchange of information to crypto businesses. We located no position either way on anonymity-enhancing assets. So the entity behind a structure can stay out of public view while its transfers are reported, which is close to the inverse of how a public blockchain behaves.

Read more
Department of Financial Protection and Innovation
Confidential with disclosure
A licensing regime that arrived in July 2026

California is the counterweight to Wyoming within the same country, and the contrast is instructive because neither state legislates about anonymity at all. California built a licensing regime for digital asset businesses that took effect at the start of July 2026, and the confidentiality consequences follow from the licence rather than from any rule naming an asset: a licensed business keeps records and identifies customers. That is the pattern this whole section keeps finding. Where a state or country reaches for a licence, identity obligations arrive with it; where it does not, the question is usually left unanswered rather than decided in either direction.

Read more
FINTRAC · Canadian Securities Administrators · Privacy Commissioner
Confidential with disclosure
Delistings without a rule that names the assets

Canada is the clearest case in this section of an outcome that looks like a ban and is not one. Anonymity-enhancing assets have largely disappeared from Canadian platforms, and yet across the securities administrators and the financial intelligence unit we found no instrument that names them or prohibits them as a class. The mechanism appears to be the combination of know-your-product duties on platforms and a travel rule that makes an untraceable transfer above CAD 1,000 impossible to comply with. One large exchange's own delisting notice attributes the decision to recent compliance requirements in Canada without citing a single rule. Read that carefully: it is a compliance judgement by a private firm, not a prohibition, and the distinction matters when people cite Canada as precedent.

Read more
Cayman Islands Monetary Authority · Ombudsman
Confidential with disclosure
A mature regime that never addresses confidentiality

Cayman matters because so many funds and token issuers are structured through it, and the finding is a set of absences rather than rules. The licensing framework is mature and the travel rule has applied since 2022, with a second licensing phase for trading platforms and custodians since April 2025. But across the regulator's own provider guidance and its dedicated travel rule page, there is no position on anonymity-enhancing assets, nothing on transfers to self-hosted wallets, and no stated monetary threshold for the transfer obligation. For a jurisdiction of this importance to the industry, that silence is itself the useful information: the questions this section is about have not been answered here.

Read more
Banco de México · CNBV · UIF
Attribution required
Anonymity named as the reason to exclude the asset class

Mexico states the reasoning that most regulators leave implicit. Its central bank says plainly that offering virtual asset services to the public through financial institutions is not advisable, and lists the anonymity those assets provide in transactions among the reasons. That is anonymity named as the ground for keeping an entire asset class outside the regulated banking perimeter, rather than as a factor to be managed within it. Note what it is not: no named asset is prohibited, and exchange houses may continue to serve clients who bear the risk themselves. The other development worth flagging sits on the data protection side, where the independent regulator was abolished and its private-sector functions moved into a government ministry.

Read more
Texas Department of Banking · State Securities Board
Builds with privacy tech
No licence for non-stablecoin crypto

Texas belongs in this section for what it does not do. Non-stablecoin cryptocurrency does not require a money transmitter licence there, which leaves a large share of activity outside the perimeter that elsewhere carries customer identification and record-keeping duties with it. Legislative energy has gone into stablecoins instead, including proposals for a commodity-backed state token. As with the other American states covered here, nothing in Texan law addresses anonymity-enhancing assets or self-hosted wallets. The federal layer still applies in full, so the practical position is a light state regime sitting under the Bank Secrecy Act rather than an absence of rules.

Read more
Treasury · FinCEN · OFAC · SEC · CFTC · IRS · state regulators
Confidential with disclosure
Split by perimeter, not by ideology

The US moved in both directions at once between 2024 and 2026, and the dividing line is custody rather than politics. Where an intermediary holds customer assets, identity obligations expanded: broker reporting went live on schedule, the travel rule is unchanged, and stablecoin issuers must now be able to freeze and seize. Where software is non-custodial, the direction reversed: the unhosted wallet proposal was withdrawn, the DeFi broker rule was repealed by Congress and cannot be reissued without new legislation, and a derivatives regulator declined to treat self-custodial wallet software as an intermediary. Executive Order 14178 states protection of self-custody and uncensored transacting as policy. Almost none of this is settled law: the market structure bill has still not passed.

Read more
Wyoming Division of Banking · Secretary of State
Builds with privacy tech
Property law written for self-custody

Wyoming is the clearest example in the United States of a legislature building around self-custody rather than treating it as a gap. Classifying digital assets as property under the commercial code sounds technical and is not: it gives a holder a defined legal interest in an asset they control directly, rather than leaving the question to be answered by whoever holds it for them. Declining to require a money transmitter licence for standalone virtual currency keeps non-custodial activity outside the perimeter that elsewhere drags identity collection along with it. The state has since issued its own stable token, which makes it both regulator and issuer.

Read more
Asia-Pacific(14)
AUSTRAC · ASIC · OAIC
Confidential with disclosure
Travel rule without a threshold, no coin ban

Australia constrains confidentiality through anti-money-laundering law and not through any coin-specific rule. No Australian instrument prohibits anonymity-enhancing assets; AUSTRAC lists privacy coins, tumblers and mixers among its suspicious activity indicators, and delistings to date have been commercial and bank-driven rather than mandated. The travel rule that starts applying to virtual asset transfers on 1 July 2026 has no minimum value at all, which is stricter than most peers. Transfers to self-hosted wallets are handled as their own category rather than exempted: the sending institution must collect and verify payer information and collect payee and tracing information, with reporting on transfers to unverified self-hosted wallets starting in 2029. Retail CBDC was set aside after Project Acacia, so the retail privacy design question never arose here.

Read more
Bangladesh Bank
Attribution required
Barred through exchange control, not a crypto law

Bangladesh is a useful reminder that a country does not need a crypto statute to prohibit crypto. The bar here runs through exchange control: because virtual currencies are not currency within the meaning of the 1947 foreign exchange law, dealing in them is not an approved transaction, and the central bank's 2022 circular states plainly that such transactions and any facilitation of them are not permitted. Breach is cognizable under the same 1947 Act. There is no licensing path and no state digital currency offering an alternative, so the practical effect is that residents transact on fully identified bank and mobile money rails. Confidentiality is not restricted here so much as the entire asset class is.

Read more
People's Bank of China · CSRC · NFRA · SAFE
Attribution required
Crypto banned, and a state currency designed for anonymity

Two things are true here at once, and most coverage reports only the first. Decentralised crypto is prohibited, and the prohibition was renewed in February 2026 by an eight-agency notice that replaced the 2021 one and extended the perimeter to offshore RMB-pegged stablecoins and domestic tokenisation of real-world assets. Then the same central bank built a retail currency around deliberate anonymity. Its own paper sets the principle as anonymity for small amounts and traceability for large amounts in accordance with the law, and confirms the lowest wallet tier opens on a phone number alone, capped at CNY 2,000, with telecom operators barred from disclosing the identity behind that number even to the central bank. The limits are structural: this anonymity is administered, capped and revocable, not cryptographic.

Read more
SFC · HKMA · Privacy Commissioner for Personal Data
Confidential with disclosure
Retail exclusion by liquidity gate, not by anonymity rule

A good illustration of exclusion happening without a rule that mentions the thing being excluded. Hong Kong's platform guidelines say nothing about privacy coins, anonymity or mixers anywhere in the text. What they require is that any token offered to retail clients be an eligible large-cap virtual asset, present in at least two acceptable indices from two different providers. Monero and Zcash fail that liquidity test, so they are absent from retail without any policy against confidentiality ever being stated. The wider posture is expansionist on tokenisation and stablecoins, with the first licences granted in April 2026. The June 2025 policy statement setting the digital asset strategy is similarly silent: privacy is not argued against, it is simply never raised.

Read more
FIU-IND · RBI · CBDT · Data Protection Board
Attribution required
No crypto statute, regulated through AML and tax

India has no bespoke crypto statute and regulates the sector through anti-money-laundering law and tax instead. Providers became reporting entities under the PMLA in March 2023, and FIU-IND has enforced that perimeter hard against offshore exchanges, issuing show-cause notices to nine of them in December 2023 and following with penalties and URL blocking. We found no Indian instrument restricting privacy coins, so the pressure on confidentiality is indirect: a 1% withholding on transfers creates a transaction-level trail as a matter of tax design, and the 30% flat rate pushes activity onto fully identified venues. The retail e-rupee pilot is the counterweight, its stated design leaving small-value transactions untraced once issued to a wallet, with disclosure expected on larger sums.

Read more
FSA · JVCEA · Personal Information Protection Commission
Attribution required
Untraceability barred by self-regulation, now moving into ordinance

Japan shows the pattern in this section at its clearest: the rule is written against untraceability, never against named assets. The industry body's handling rules have barred members since 2018 from dealing in any crypto asset whose transfer records cannot be traced or are markedly difficult to trace, which is why Monero, Zcash and Dash have been absent from Japanese venues for years without any instrument naming them. Legislation enacted in July 2026 moves crypto trading out of payments law and into the securities framework. Worth being precise about what that does to traceability: the statute bars assets failing user-protection standards, but the criteria, including transfer-record management, are delegated to Cabinet Office Ordinance and have not been written yet.

Read more
National Bank of Kazakhstan · ARDFM · AFSA in the AIFC
Confidential with disclosure
Surveillance tooling required of operators, not run by the state

Worth correcting a claim that circulates about Kazakhstan: the law does not establish a state system watching digital asset transactions. It requires each licensed operator to run its own analysis and control system, built to the National Bank's specification, which is a mandated chain-analytics obligation rather than centralised surveillance. The teeth are in the identification rule. Operators must hold information sufficient to identify both sender and recipient, and a transfer with incomplete information is suspended and then refused. Unsecured digital assets remain legal but are stripped of status as a means of payment or a financial instrument. A second, separate track exists inside the Astana financial centre under its own regulator, whose terms we could not verify.

Read more
Securities Commission Malaysia
Attribution required
A categorical ban written by definition, not by coin name

The most explicit categorical ban in the Asia-Pacific set, and notable for how it is drafted. Malaysia does not list forbidden coins. It prohibits exchange operators from permitting a privacy token to be offered for trading, then defines a privacy token by purpose: one intended to enhance user anonymity and transaction confidentiality. That catches the technique wherever it appears, including designs that did not exist when the rule was written, and it applies regardless of whether an asset is otherwise reputable. The same revision liberalised elsewhere, moving listing decisions to the exchange's own board under documented criteria. So Malaysia loosened its grip on what may be listed while tightening it specifically around confidentiality.

Read more
Bangko Sentral ng Pilipinas · SEC
Confidential with disclosure
Every transfer is a cross-border wire, inside a closed chain

Read in full, the circular contains no provision on privacy coins, mixers or tumblers, and no express treatment of self-hosted wallets. What makes the Philippines restrictive in practice is structural instead. Every virtual asset transfer is treated as a cross-border wire transfer, so the travel rule applies to flows other regimes would consider domestic, and providers may deal only inside what the circular calls an unbroken chain of regulated entities. That closes the perimeter around self-custody without ever legislating against it. Worth noting the clause that cuts the other way, because it is rare: providers are expressly obliged to keep the identity data they collect confidential and to prevent unauthorised disclosure. The obligation is to know, not to publish.

Read more
MAS · PDPC
Confidential with disclosure
Regulates anonymity by risk assessment, not prohibition

The one jurisdiction in this section that declined to exclude anonymity-enhancing assets and chose to price the risk instead. MAS set the position in Parliament in October 2022: privacy coins, privacy wallets and mixers attract enhanced obligations rather than prohibition. The notice requires providers to risk-assess such tokens before dealing and to pay special attention to technologies favouring anonymity, and MAS has observed that most licensed firms simply choose not to offer them anyway. That restraint sits alongside a travel rule with no minimum value and a deliberately narrow licensing door. COSMIC is worth noting for what it shows about the underlying logic: Singapore legislated a carve-out from bank secrecy so banks could share data privately with each other, not publicly.

Read more
FSC · FSS · KoFIU · PIPC
Attribution required
Identity-maximalist, and exporting the model

The most identity-maximalist regime covered here, and the only one actively trying to export it. Untraceable assets have been barred from Korean platforms since 2021, layered on top of a real-name bank account requirement that makes the won on-ramp a chokepoint. The August 2026 amendments go further than anything else in this section: the travel rule threshold is abolished outright so it applies to transfers of any size, and transfers to personal wallets are permitted only where the destination is low-risk or the two ends are confirmed to be the same person, with outright prohibition where the counterparty is high-risk. Accommodation exists but sits entirely on the institutional access axis (corporate accounts, tokenised securities) and not on confidentiality.

Read more
Central Bank of Sri Lanka · Financial Intelligence Unit
Regime still forming
Unregulated rather than prohibited

Sri Lanka occupies the position a lot of countries were in five years ago and few still are: crypto is neither licensed nor forbidden. The central bank has said it has authorised nobody to operate schemes involving virtual currencies and approved no token offering, and has warned about the risks, but it has not prohibited holding or trading. That leaves no privacy position to describe, because there is no regime to have one. It also leaves users without the protections a licensing regime brings. Movement toward registration of providers with the financial intelligence unit has been proposed rather than enacted, so the vacuum is the current state rather than a settled policy.

Read more
Financial Supervisory Commission
Regime still forming
The travel rule that has never come into force

Two things commonly reported about Taiwan are wrong. The VASP Act is not pending; it passed its third reading on 30 June 2026, though commencement still has to be designated and licensing runs on a 21-month tail after that. And the travel rule, often described as operative with an NT$30,000 threshold, has never been in force at all. The provision has carried a deferred effective date since 2021, and the regulator confirmed in writing in August 2026 that it has still not been implemented, setting out a phased plan starting with domestic transfers in October 2026. There is no named privacy-coin prohibition. For now Taiwan is the outlier: a registration regime in force, and the transfer-identity machinery still switched off.

Read more
SEC Thailand · Bank of Thailand · AMLO · PDPC
Attribution required
Closed by whitelist, not by prohibition

Thailand is the jurisdiction most often cited as having banned privacy coins, and the claim does not survive reading the instrument. Notification No. Kor Thor. 18/2564 prohibits four categories (meme tokens, fan tokens, NFTs and exchange-issued tokens) and stops there. Anonymity is never mentioned. The exclusion is real but it works through market architecture instead: exchanges may list only what the SEC has approved, the approved list is short, and anonymity-enhancing assets simply never reach it. Combined with the ban on using digital assets for payment since April 2022 and the 2025 extension of the perimeter to offshore operators targeting Thai users, the practical result is closed access rather than illegal holding. The distinction matters, and almost every secondary source erases it.

Read more
Middle East & Africa(15)
Central Bank of Bahrain · Personal Data Protection Authority
Attribution required
A listing test written against effects, not asset names

Bahrain never names a coin, and its rule is broader for it. Licensees may not list assets that facilitate, or may facilitate, obfuscation or concealment of a client or counterparty's identity, and the phrase may facilitate does a great deal of work, since it reaches capability rather than demonstrated use. The second limb is arguably more consequential: a licensee may only list assets it actually has the monitoring capability to supervise, which makes listing contingent on the state of analytics tooling rather than on any judgement about the asset. Together they are a cleaner statement of the real mechanism than most explicit bans, because they explain what regulators are actually protecting: their own ability to see.

Read more
Central Bank of Egypt · Personal Data Protection Center
Attribution required
Crypto barred, so data protection is the live constraint

Egypt inverts the usual shape of an entry in this section. There is no crypto privacy regime to describe because there is no lawful crypto activity: the banking law requires central bank approval to issue, trade or promote cryptocurrencies, and no approval has ever been granted. What is live instead is data protection. The 2020 personal data law sat without executive regulations for years and finally received them in 2025, turning it into a working supervisory regime with licensing requirements attached, including for cross-border transfers of personal data. For any firm handling Egyptian personal data, that transfer licence is the real compliance surface, and the grace period closes at the end of October 2026.

Read more
Bank of Ghana · SEC · Financial Intelligence Centre
Confidential with disclosure
The regulator that put self-custody in writing

Worth citing well beyond Ghana, because a central bank stated plainly in writing what most regimes leave to inference. Its FAQ says that neither the regulatory authorities nor the government will control private wallets or individual transactions, and that the law regulates service providers rather than personal ownership of digital assets. That is the custodial-perimeter principle running through this entire section, expressed by a regulator rather than argued by an industry. Ghana moved from prohibition to licensing inside a year, splitting supervision between the central bank and the securities regulator by activity. The cedi remains sole legal tender, and pricing or paying wages in virtual assets is not permitted.

Read more
ISA · Capital Market Authority · IMPA · Privacy Protection Authority
Confidential with disclosure
Light on-chain, heavy on data protection

Israel splits cleanly along the axis this whole section turns on. On chain, the constraint is light: no instrument restricts anonymity-enhancing assets or transfers to self-hosted wallets, and those questions fall under ordinary anti-money-laundering supervision rather than any dedicated rule. Off chain, the regime got considerably heavier a year ago. Amendment 13 to the Protection of Privacy Law came into force in August 2025, requiring privacy protection officers, widening the definition of sensitive data, and giving the regulator administrative orders and fines with real weight behind them. For a firm handling personal data alongside on-chain activity, the binding compliance burden here comes from the data protection side, not the financial one.

Read more
Capital Markets Authority · Central Bank of Kenya · Data Protection Commissioner
Attribution required
The ban written into primary legislation, not a rulebook

Most prohibitions in this section live in rulebooks that a regulator can amend without going back to a legislature. Kenya's does not. The 2025 Act puts the restriction in primary law: a service provider may not undertake mixer or tumbler services, or anonymity-enhancing services, with the latter defined broadly enough to reach any transaction whose effect or intention is to conceal information. Breach is a criminal offence. That drafting choice matters more than its content, because it sets a much higher bar for reversal than the Gulf rulebooks that reach a similar result. Note also what the definition catches: it turns on effect, not on the name of an asset, so it is technique-neutral by design.

Read more
Capital Markets Authority · Central Bank of Kuwait
Attribution required
A ban whose stated reason is anonymity itself

Kuwait is worth including precisely because its regulators said the quiet part out loud. The prohibition covers payment use, investment recognition, provider licensing and mining, and the stated reason is not volatility or consumer protection but anonymity: the central bank's warning is that the anonymous nature of crypto transactions creates room for illegal use. That makes it one of the few places where confidentiality is the explicit basis for excluding an entire asset class rather than a secondary concern. The consequence for this section is a useful caution. Kuwait has no travel rule and no privacy-coin rule, but that silence reflects the absence of any licensable activity, not tolerance.

Read more
Financial Services Commission
Confidential with disclosure
A mature licensing regime that never mentions anonymity

Mauritius matters here out of proportion to its size, because a great many crypto entities are domiciled in it. Its regime is mature rather than minimal: a licensing act in force since 2022, five distinct licence classes with capital requirements, and seven detailed rules covering everything from custody to cybersecurity. What it does not contain, anywhere we could find across the act, the rules and independent reviews of both, is any restriction on anonymity-enhancing assets, mixers or self-hosted wallets. That silence is the finding. It is not a considered permission and should not be read as one, but it does make Mauritius the most accommodating jurisdiction in the region on confidentiality, purely by not having addressed it.

Read more
Bank Al-Maghrib · AMMC · Office des Changes
Regime still forming
Liberalising in direction, with a ten-year retention sting

Morocco is moving from prohibition toward a framework, and the direction is genuinely liberalising after years in which crypto activity sat outside the exchange control rules. The detail worth attention is not the licensing but the retention. The draft would require providers to keep transaction data for ten years, which is longer than most regimes in this section and creates a large standing pool of transaction-level records regardless of any suspicion. Issuance of fiat-indexed tokens would be reserved to approved banks. Decentralised finance is left out of scope entirely. As of mid-2026 the central bank reported progress but no firm date for submission to parliament, so none of this is law yet.

Read more
SEC · Central Bank of Nigeria · Data Protection Commission
Confidential with disclosure
Securities-first, with banking access restored

Nigeria took the securities route rather than building a bespoke crypto statute, bringing digital assets under the securities regulator through the 2025 Act while the 2022 rules continue to carry the operational detail. The more consequential shift for anyone actually operating there was the central bank reversing its 2021 banking restriction in December 2023, which restored the account access that had pushed activity into informal channels. On confidentiality specifically, the file is empty in both directions: we found no instrument restricting anonymity-enhancing assets, mixers or self-hosted wallets, and equally nothing protecting them. Read that as an unwritten question rather than as permission.

Read more
Financial Services Authority · Central Bank of Oman
Attribution required
The only rule found that names privacy wallets

Most rules in this section reach assets, and a few reach tools. Oman's drafting reaches further than any other we found. The registration decision already bars virtual assets that conceal the identity of the originator or the nature of the transaction, which is broad on its own. The consultation framework then extends the intent to tumblers, mixers and, unusually, privacy-enhanced wallets, and targets concealment of the holder and beneficial owner rather than only the counterparties to a transfer. That last move matters: a rule aimed at who owns an asset catches designs that a transfer-focused rule would miss. We could not confirm whether the wider framework has been finalised, so treat the registration decision as the operative instrument.

Read more
QFC Regulatory Authority · Qatar Central Bank
Attribution required
Exclusion by perimeter rather than prohibition

Qatar reaches exclusion without ever writing a prohibition on anonymity, because its perimeter is drawn as a positive list. Only permitted tokens may be issued or traded: assets anchored to a verified real-world asset or legal right, passing a defined validation and tokenisation process. Cryptocurrencies and stablecoins are outside that definition entirely, so anonymity-enhancing assets never come up for consideration. What Qatar is building instead is a tokenisation regime with real property rights attached, recognised in its own courts, supported by an incubator. It is worth reading as a statement of what a regulator wants from a ledger: verified claims on identified things, not bearer instruments.

Read more
Capital Market Authority · National Bank of Rwanda
Confidential with disclosure
Anonymity defined out of the regime rather than banned

Rwanda uses a technique worth understanding because it is different from a ban. Rather than prohibiting anonymity-enhanced assets, the law writes them out of the definition of a virtual asset altogether, alongside NFTs, algorithmic stablecoins and central bank digital currencies. The effect is that no licensed provider can deal in them, because they are not the thing the licence covers. Whether dealing in them is otherwise lawful is left unanswered, which is a meaningfully different position from prohibition. More surprising is the treatment of mixers: operating one without authorisation is an offence, and the drafting implies such services could in principle be authorised. Very few regimes anywhere treat mixing as licensable rather than forbidden.

Read more
Financial Services Authority
Confidential with disclosure
No anonymity rule, but the offshore route is closing

Seychelles matters here because of how many crypto entities are domiciled in it rather than because of anything it says about confidentiality, and it says nothing. No located instrument restricts anonymity-enhancing assets. What changed is the plumbing around that silence. The 2024 Act arrived with an unusually complete set of regulations, and the regulator paired them with substance requirements and guidance on what counts as operating in or from Seychelles. That combination closes the structure anonymity-tolerant venues have historically relied on: registering in a jurisdiction with no privacy rules while serving users everywhere else. The absence of a prohibition is becoming less useful than it looks.

Read more
FSCA · Financial Intelligence Centre · Information Regulator
Attribution required
A travel rule that starts at any value above zero

The most precisely drafted travel rule in this section, and the one that leaves least room. Where other regimes debate where to set a minimum, South Africa defined a qualifying transfer as any crypto asset transfer above zero, then used its R5,000 line to reduce how much data is required rather than whether the rule applies at all. Providers must refuse to execute where they cannot comply. Self-custody is treated the way most of the world treats it (a risk category requiring documented policy, not a prohibition), and 2026 guidance singles out peer-to-peer and wallet-to-wallet transfers as higher risk. The tightening arrived alongside the country's exit from the FATF grey list in October 2025, which is the usual pattern.

Read more
VARA · DFSA · ADGM FSRA · CBUAE
Attribution required
The most explicit prohibition anywhere in this section

If you want the counterexample to the pattern running through this section, it is here. Almost everywhere else, exclusion happens through listing rules, whitelists or traceability tests that never mention anonymity. Dubai's regulator simply writes it down: issuance of anonymity-enhanced cryptocurrencies, and every activity related to them, is prohibited in the Emirate. The financial free zones go further in a different direction, with the DIFC barring not only privacy tokens but the use of a privacy device (mixers and tumblers) as a category of tool. Four separate regulators operate here with different perimeters, which matters when structuring. Self-custody survives everywhere; the central bank's Digital Dirham is designed so that no personally identifiable information sits on the ledger.

Read more

Not legal advice · rules change faster than pages do · every card carries its primary source, corrections welcome

How Soda Bubble compares.

Every cell links its primary source on hover. Methodology and per-claim sources: technology taxonomy. Last updated August 11, 2026.

A practical comparison of garbled-circuit MPC used by Soda Bubble network versus FHE used in Zama network.

CapabilitySoda Bubble (GC-MPC)FHE (Zama and others)
Encryption
Encrypted amounts (arguments)YesYes
Encrypted addresses (anonymity support)YesNo
Encryption typeBattle-tested AESTFHE
Encryption adoptionAES: the worldwide standard (internet, banking, government)Early: no large-scale production deployments yet
Performance
LatencyNear zero – HTTPS equivalentHigh latency – requires expensive client-side ZK proofs
Computation speedFast: near-native circuit evaluationSlow: encrypted operations take orders of magnitude longer
Throughput500 cTPS sustained, 750 peak (measured end-to-end)20 tx/s in production (vendor-published, CPU)
Cost per transferEssentially $0 ($0.14 per million transfers, measured)A ~$10,000/month GPU operator before the first transfer
Performant on CPUYesNo, relies on GPU or ASIC
Compliance & compatibility
Full EVM/SVM compatibilityYesNo (doesn't support 256-bit and hash operations)

Detailed capability comparison: see the Privacy Hub taxonomy for a neutral summary.

Go deeper.

Compare the technologies side by side, or read the research behind them.