What the regulators actually say.
Confidentiality and compliance are usually described as opposites. Read the instruments and they mostly are not: nearly every rule that looks like a demand for transparency binds a regulated institution to know and disclose specific facts to specific parties, not to publish those facts to the world.
107 entries: the standard-setters and supervisors, the jurisdictions applying them, and explainers on where the two systems genuinely collide. Each entry names the instruments it turns on and links its primary source, so you can check the reading rather than take ours.
Global (18)
- The travel rule binds institutions, not ledgersWhere privacy tech meets the rulebook
The most common objection to confidential transfers is that the travel rule forbids them.
- Erasure against an append-only ledgerWhere privacy tech meets the rulebook
This is the collision that does not dissolve on closer reading.
- Selective disclosure as a compliance primitiveWhere privacy tech meets the rulebook
Supervisory access, external audit and suspicious activity reporting are all bilateral disclosures to a named party under a legal duty.
- Proving where funds did not come fromWhere privacy tech meets the rulebook
The 2023 Privacy Pools paper made a design argument that has held up: instead of hiding everything, let a depositor prove in zero knowledge that their withdrawal belongs to a chosen set of deposits, o…
- Central banks are building confidentiality themselvesWhere privacy tech meets the rulebook
The strongest evidence that public authorities do not equate confidentiality with wrongdoing is that they keep building it.
- Why regulated institutions cannot use a transparent ledgerWhere privacy tech meets the rulebook
The compliance debate usually asks whether institutions are permitted to use confidentiality.
- Sanctions screening on a confidential ledgerWhere privacy tech meets the rulebook
Worth stating plainly rather than glossing: this is the weakest part of the case for confidential ledgers.
- Anonymity is not the same thing as confidentialityWhere privacy tech meets the rulebook
Regulators keep drawing a line that the debate tends to flatten.
- FATFRegulator or standard-setterAttribution required
Nothing else in this section has as much reach. FATF sets standards rather than law, but the mutual evaluation process and the grey list make adoption close to compulsory, which is why the same travel…
- OECD CARFRegulator or standard-setterAttribution required
The quiet instrument that will do the most to end pseudonymity at the intermediary layer, and it arrives before the AML rules do.
- Basel Committee, SCO60Regulator or standard-setterAttribution required
The single most privacy-restrictive sentence in global financial regulation is probably here.
- Financial Stability BoardRegulator or standard-setterConfidential with disclosure
Included here mainly to correct a common misattribution. The FSB coordinates national authorities on financial stability, and its 2023 framework is frequently cited in arguments about on-chain surveil…
- IOSCORegulator or standard-setterConfidential with disclosure
IOSCO pulls in both directions, which makes it more interesting than most.
- BIS Innovation HubRegulator or standard-setterBuilds with privacy tech
If you want evidence that the institutions writing the rules do not equate confidentiality with crime, this is where to look.
- Convention 108+Regulator or standard-setterBuilds with privacy tech
The counterweight instrument, and the one that has not arrived.
- Egmont GroupRegulator or standard-setterAttribution required
Rarely discussed in privacy debates about crypto, and structurally one of the more significant bodies in this section.
- ISO and IEC standardsRegulator or standard-setterBuilds with privacy tech
Set this against the financial standard-setters and the contrast is sharp.
- NISTRegulator or standard-setterBuilds with privacy tech
A national agency rather than a global one, included because its output gets adopted internationally as reference material and because it does something no financial regulator has.
Europe (34)
- MiCARegulator or standard-setterConfidential with disclosure
MiCA carries exactly one operative anonymity rule, and it is narrower than its reputation.
- EU Transfer of Funds RegulationRegulator or standard-setterAttribution required
This, not the privacy-coin headline, is what actually ends unattributed transfers at the EU perimeter.
- EU AMLR Article 79Regulator or standard-setterAttribution required
Reported almost everywhere as an EU ban on privacy coins from 1 July 2027.
- GDPRRegulator or standard-setterBuilds with privacy tech
The law most often described as a problem for blockchain is also the strongest European argument for building with privacy technology.
- EDPB blockchain guidelinesRegulator or standard-setterConfidential with disclosure
The reference text on how European data protection law lands on a ledger, final since 7 July 2026.
- Digital euroRegulator or standard-setterBuilds with privacy tech
A central bank designing confidentiality into money on purpose is the most direct evidence that European regulators do not equate privacy with illegality.
- eIDAS 2 and the EU Digital Identity WalletRegulator or standard-setterBuilds with privacy tech
The clearest counterexample to the idea that regulators are uniformly against cryptographic privacy: here EU law names the technology and requires it.
- CJEU on identifiabilityRegulator or standard-setterConfidential with disclosure
Whether a blockchain address is personal data is not a settled question, and the two European institutions answering it are drifting apart.
- EU Data Act, Article 36Regulator or standard-setterConfidential with disclosure
A useful case of a rule written for one context landing awkwardly on another.
- United KingdomJurisdictionConfidential with disclosure
The UK has built a full regulatory perimeter without reaching for a single prohibition on privacy technology.
- SwitzerlandJurisdictionAttribution required
A useful corrective to the assumption that a crypto-friendly jurisdiction is permissive about anonymity.
- TurkeyJurisdictionAttribution required
Turkey reaches the same destination as an anonymity ban without ever writing one.
- NorwayJurisdictionConfidential with disclosure
Norway took the EU rulebook through the EEA route and enforced it promptly, closing its transition window in July 2026 with providers told to wind down.
- UkraineJurisdictionRegime still forming
An unusual case: the virtual assets law passed in February 2022 is recorded in the official register as never having entered into force.
- GeorgiaJurisdictionAttribution required
Across every jurisdiction surveyed for this section, institutional privacy oversight was either strengthening or holding steady.
- RussiaJurisdictionAttribution required
Russia has the most direct on-chain deanonymisation mandate found anywhere in this section.
- FranceJurisdictionConfidential with disclosure
France pulls harder in both directions than any other member state.
- GermanyJurisdictionConfidential with disclosure
Germany's divergence runs in two directions and neither is about coins.
- LiechtensteinJurisdictionConfidential with disclosure
Liechtenstein made a structural choice worth understanding: rather than requiring every participant to identify counterparties, it turned identification into its own licensed role.
- IcelandJurisdictionConfidential with disclosure
Iceland is worth a card mainly for what it reveals about the EEA route into EU financial law.
- NetherlandsJurisdictionConfidential with disclosure
The Netherlands ran the most aggressive self-hosted wallet identification demand in Europe and then gave it up, which makes it the most instructive European case in this section.
- PolandJurisdictionRegime still forming
Poland is the exception that shows how the EU framework behaves when a member state cannot implement it.
- IrelandJurisdictionBuilds with privacy tech
Ireland adds nothing of its own to the EU rules on crypto confidentiality, and that is worth saying plainly rather than inventing local colour.
- SpainJurisdictionConfidential with disclosure
Spain's national contribution sits on the marketing side rather than the confidentiality side, and it got there first.
- ItalyJurisdictionConfidential with disclosure
Italy's national addition was a reporting channel rather than a prohibition, and it went further than the European baseline in an unusual direction.
- PortugalJurisdictionConfidential with disclosure
Portugal's distinctive contribution came from its data protection authority rather than its financial regulators, and it addresses a question the financial rules do not reach.
- EstoniaJurisdictionConfidential with disclosure
Estonia mattered to this market out of proportion to its size, because for a few years it issued more crypto authorisations than anywhere else in Europe.
- LithuaniaJurisdictionConfidential with disclosure
Lithuania took the same route as Estonia and reached a similar destination by a different instrument.
- BelgiumJurisdictionConfidential with disclosure
Belgium adds no national layer on confidentiality, and that is worth stating plainly rather than manufacturing local colour.
- AustriaJurisdictionConfidential with disclosure
Austria's only real distinguishing feature in this area is timing.
- LuxembourgJurisdictionConfidential with disclosure
Luxembourg carries weight here because of what is domiciled in it rather than because of any national rule on confidentiality.
- SwedenJurisdictionConfidential with disclosure
Sweden has a reputation for hostility to crypto that is worth separating into its parts.
- DenmarkJurisdictionConfidential with disclosure
Denmark is a useful reminder that the financial supervisor is not always the body that matters most for privacy.
- CzechiaJurisdictionConfidential with disclosure
Czechia is one of the member states that put crypto supervision inside the central bank rather than with a separate markets authority, which matters more for how firms experience the process than for…
Americas (19)
- GENIUS ActRegulator or standard-setterAttribution required
The most restrictive thing in current US law on this subject, and it is architectural rather than procedural.
- OFAC and Van LoonRegulator or standard-setterConfidential with disclosure
The most severe action ever taken by a government against privacy tooling, followed by the most significant legal retreat from one.
- FinCENRegulator or standard-setterAttribution required
Registration, identity verification and suspicious activity reporting for anyone acting as a money transmitter in crypto all originate here, and none of that has loosened.
- NYDFSRegulator or standard-setterAttribution required
Where federal policy has softened around non-custodial software, New York has not moved at all.
- IRS broker reportingRegulator or standard-setterAttribution required
The clearest illustration of the US perimeter split. Custodial reporting arrived exactly as planned and is now in its first year of cost-basis reporting, which means identity, proceeds and acquisition…
- US Treasury and the Working GroupRegulator or standard-setterBuilds with privacy tech
The most significant shift in this section, and the one most easily overstated.
- The third-party doctrineRegulator or standard-setterAttribution required
Any account of US financial privacy that stops at statutes misses the layer that actually decides things.
- United StatesJurisdictionConfidential with disclosure
The US moved in both directions at once between 2024 and 2026, and the dividing line is custody rather than politics.
- CanadaJurisdictionConfidential with disclosure
Canada is the clearest case in this section of an outcome that looks like a ban and is not one.
- BrazilJurisdictionAttribution required
Brazil holds the two halves of this section's argument in one place.
- MexicoJurisdictionAttribution required
Mexico states the reasoning that most regulators leave implicit.
- ArgentinaJurisdictionConfidential with disclosure
Argentina drew its perimeter in the place this section keeps arguing is the right one.
- BahamasJurisdictionAttribution required
The Bahamas holds the sharpest contradiction in this section, and both halves are deliberate.
- BermudaJurisdictionAttribution required
Bermuda restricts no asset by name and still runs the most comprehensive transaction surveillance requirement found in the Americas.
- Cayman IslandsJurisdictionConfidential with disclosure
Cayman matters because so many funds and token issuers are structured through it, and the finding is a set of absences rather than rules.
- British Virgin IslandsJurisdictionConfidential with disclosure
The British Virgin Islands is a useful illustration that confidentiality is not one thing.
- WyomingJurisdictionBuilds with privacy tech
Wyoming is the clearest example in the United States of a legislature building around self-custody rather than treating it as a gap.
- CaliforniaJurisdictionConfidential with disclosure
California is the counterweight to Wyoming within the same country, and the contrast is instructive because neither state legislates about anonymity at all.
- TexasJurisdictionBuilds with privacy tech
Texas belongs in this section for what it does not do. Non-stablecoin cryptocurrency does not require a money transmitter licence there, which leaves a large share of activity outside the perimeter th…
Asia-Pacific (18)
- Monetary Authority of SingaporeRegulator or standard-setterConfidential with disclosure
Worth reading closely because it is the road not taken elsewhere.
- Hong Kong SFCRegulator or standard-setterConfidential with disclosure
A useful case study in how a market gets closed without a rule that mentions the thing being closed out.
- Japan FSA and JVCEARegulator or standard-setterAttribution required
Japan is the clearest example of a rule written against untraceability rather than against named assets, and of that rule being applied by an industry body rather than a regulator.
- APGRegulator or standard-setterAttribution required
Standards do not travel by themselves, and this is the machinery that moves them across Asia.
- AustraliaJurisdictionConfidential with disclosure
Australia constrains confidentiality through anti-money-laundering law and not through any coin-specific rule.
- ThailandJurisdictionAttribution required
Thailand is the jurisdiction most often cited as having banned privacy coins, and the claim does not survive reading the instrument.
- IndiaJurisdictionAttribution required
India has no bespoke crypto statute and regulates the sector through anti-money-laundering law and tax instead.
- SingaporeJurisdictionConfidential with disclosure
The one jurisdiction in this section that declined to exclude anonymity-enhancing assets and chose to price the risk instead.
- Hong Kong SARJurisdictionConfidential with disclosure
A good illustration of exclusion happening without a rule that mentions the thing being excluded.
- TaiwanJurisdictionRegime still forming
Two things commonly reported about Taiwan are wrong. The VASP Act is not pending; it passed its third reading on 30 June 2026, though commencement still has to be designated and licensing runs on a 21…
- South KoreaJurisdictionAttribution required
The most identity-maximalist regime covered here, and the only one actively trying to export it.
- JapanJurisdictionAttribution required
Japan shows the pattern in this section at its clearest: the rule is written against untraceability, never against named assets.
- ChinaJurisdictionAttribution required
Two things are true here at once, and most coverage reports only the first.
- KazakhstanJurisdictionConfidential with disclosure
Worth correcting a claim that circulates about Kazakhstan: the law does not establish a state system watching digital asset transactions.
- MalaysiaJurisdictionAttribution required
The most explicit categorical ban in the Asia-Pacific set, and notable for how it is drafted.
- PhilippinesJurisdictionConfidential with disclosure
Read in full, the circular contains no provision on privacy coins, mixers or tumblers, and no express treatment of self-hosted wallets.
- BangladeshJurisdictionAttribution required
Bangladesh is a useful reminder that a country does not need a crypto statute to prohibit crypto.
- Sri LankaJurisdictionRegime still forming
Sri Lanka occupies the position a lot of countries were in five years ago and few still are: crypto is neither licensed nor forbidden.
Middle East & Africa (18)
- VARARegulator or standard-setterAttribution required
Most regimes reach anonymity-enhanced assets sideways, through listing criteria, liquidity gates or traceability tests.
- DFSA and ADGM FSRARegulator or standard-setterAttribution required
The two financial free zones inside the UAE regulate separately from Dubai's virtual assets authority, and they went a step further than it did.
- MENAFATFRegulator or standard-setterAttribution required
The regional counterpart to the Asian body, and the reason the Gulf entries in this section rhyme with one another.
- IsraelJurisdictionConfidential with disclosure
Israel splits cleanly along the axis this whole section turns on.
- United Arab EmiratesJurisdictionAttribution required
If you want the counterexample to the pattern running through this section, it is here.
- KenyaJurisdictionAttribution required
Most prohibitions in this section live in rulebooks that a regulator can amend without going back to a legislature.
- GhanaJurisdictionConfidential with disclosure
Worth citing well beyond Ghana, because a central bank stated plainly in writing what most regimes leave to inference.
- South AfricaJurisdictionAttribution required
The most precisely drafted travel rule in this section, and the one that leaves least room.
- BahrainJurisdictionAttribution required
Bahrain never names a coin, and its rule is broader for it. Licensees may not list assets that facilitate, or may facilitate, obfuscation or concealment of a client or counterparty's identity, and the…
- QatarJurisdictionAttribution required
Qatar reaches exclusion without ever writing a prohibition on anonymity, because its perimeter is drawn as a positive list.
- NigeriaJurisdictionConfidential with disclosure
Nigeria took the securities route rather than building a bespoke crypto statute, bringing digital assets under the securities regulator through the 2025 Act while the 2022 rules continue to carry the…
- SeychellesJurisdictionConfidential with disclosure
Seychelles matters here because of how many crypto entities are domiciled in it rather than because of anything it says about confidentiality, and it says nothing.
- OmanJurisdictionAttribution required
Most rules in this section reach assets, and a few reach tools.
- RwandaJurisdictionConfidential with disclosure
Rwanda uses a technique worth understanding because it is different from a ban.
- MauritiusJurisdictionConfidential with disclosure
Mauritius matters here out of proportion to its size, because a great many crypto entities are domiciled in it.
- KuwaitJurisdictionAttribution required
Kuwait is worth including precisely because its regulators said the quiet part out loud.
- EgyptJurisdictionAttribution required
Egypt inverts the usual shape of an entry in this section. There is no crypto privacy regime to describe because there is no lawful crypto activity: the banking law requires central bank approval to i…
- MoroccoJurisdictionRegime still forming
Morocco is moving from prohibition toward a framework, and the direction is genuinely liberalising after years in which crypto activity sat outside the exchange control rules.
Compliant by default.
Confidentiality from the public, disclosure to the parties entitled to it. See how the access list works.