What the regulators actually say.
Confidentiality and compliance are usually described as opposites. Read the instruments and they mostly are not: nearly every rule that looks like a demand for transparency binds a regulated institution to know and disclose specific facts to specific parties, not to publish those facts to the world.
58 entries: the standard-setters and supervisors, the jurisdictions applying them, and explainers on where the two systems genuinely collide. Each entry names the instruments it turns on and links its primary source, so you can check the reading rather than take ours.
Global (18)
- The travel rule binds institutions, not ledgersWhere privacy tech meets the rulebook
The most common objection to confidential transfers is that the travel rule forbids them.
- Erasure against an append-only ledgerWhere privacy tech meets the rulebook
This is the collision that does not dissolve on closer reading.
- Selective disclosure as a compliance primitiveWhere privacy tech meets the rulebook
Supervisory access, external audit and suspicious activity reporting are all bilateral disclosures to a named party under a legal duty.
- Proving where funds did not come fromWhere privacy tech meets the rulebook
The 2023 Privacy Pools paper made a design argument that has held up: instead of hiding everything, let a depositor prove in zero knowledge that their withdrawal belongs to a chosen set of deposits, o…
- Central banks are building confidentiality themselvesWhere privacy tech meets the rulebook
The strongest evidence that public authorities do not equate confidentiality with wrongdoing is that they keep building it.
- Why regulated institutions cannot use a transparent ledgerWhere privacy tech meets the rulebook
The compliance debate usually asks whether institutions are permitted to use confidentiality.
- Sanctions screening on a confidential ledgerWhere privacy tech meets the rulebook
Worth stating plainly rather than glossing: this is the weakest part of the case for confidential ledgers.
- Anonymity is not the same thing as confidentialityWhere privacy tech meets the rulebook
Regulators keep drawing a line that the debate tends to flatten.
- FATFRegulator or standard-setterRestricts anonymity
Nothing else in this section has as much reach. FATF sets standards rather than law, but the mutual evaluation process and the grey list make adoption close to compulsory, which is why the same travel…
- Basel Committee, SCO60Regulator or standard-setterRestricts anonymity
The single most privacy-restrictive sentence in global financial regulation is probably here.
- BIS Innovation HubRegulator or standard-setterBuilds with privacy tech
If you want evidence that the institutions writing the rules do not equate confidentiality with crime, this is where to look.
- OECD CARFRegulator or standard-setterRestricts anonymity
The quiet instrument that will do the most to end pseudonymity at the intermediary layer, and it arrives before the AML rules do.
- IOSCORegulator or standard-setterPrivacy with disclosure
IOSCO pulls in both directions, which makes it more interesting than most.
- Financial Stability BoardRegulator or standard-setterPrivacy with disclosure
Included here mainly to correct a common misattribution. The FSB coordinates national authorities on financial stability, and its 2023 framework is frequently cited in arguments about on-chain surveil…
- Convention 108+Regulator or standard-setterBuilds with privacy tech
The counterweight instrument, and the one that has not arrived.
- Egmont GroupRegulator or standard-setterRestricts anonymity
Rarely discussed in privacy debates about crypto, and structurally one of the more significant bodies in this section.
- NISTRegulator or standard-setterBuilds with privacy tech
A national agency rather than a global one, included because its output gets adopted internationally as reference material and because it does something no financial regulator has.
- ISO and IEC standardsRegulator or standard-setterBuilds with privacy tech
Set this against the financial standard-setters and the contrast is sharp.
Europe (15)
- MiCARegulator or standard-setterPrivacy with disclosure
MiCA carries exactly one operative anonymity rule, and it is narrower than its reputation.
- EU Transfer of Funds RegulationRegulator or standard-setterRestricts anonymity
This, not the privacy-coin headline, is what actually ends unattributed transfers at the EU perimeter.
- EU AMLR Article 79Regulator or standard-setterRestricts anonymity
Reported almost everywhere as an EU ban on privacy coins from 1 July 2027.
- GDPRRegulator or standard-setterBuilds with privacy tech
The law most often described as a problem for blockchain is also the strongest European argument for building with privacy technology.
- EDPB blockchain guidelinesRegulator or standard-setterPrivacy with disclosure
The reference text on how European data protection law lands on a ledger, final since 7 July 2026.
- CJEU on identifiabilityRegulator or standard-setterPrivacy with disclosure
Whether a blockchain address is personal data is not a settled question, and the two European institutions answering it are drifting apart.
- eIDAS 2 and the EU Digital Identity WalletRegulator or standard-setterBuilds with privacy tech
The clearest counterexample to the idea that regulators are uniformly against cryptographic privacy: here EU law names the technology and requires it.
- Digital euroRegulator or standard-setterBuilds with privacy tech
A central bank designing confidentiality into money on purpose is the most direct evidence that European regulators do not equate privacy with illegality.
- EU Data Act, Article 36Regulator or standard-setterPrivacy with disclosure
A useful case of a rule written for one context landing awkwardly on another.
- United KingdomJurisdictionPrivacy with disclosure
The UK has built a full regulatory perimeter without reaching for a single prohibition on privacy technology.
- SwitzerlandJurisdictionRestricts anonymity
A useful corrective to the assumption that a crypto-friendly jurisdiction is permissive about anonymity.
- TurkeyJurisdictionRestricts anonymity
Turkey reaches the same destination as an anonymity ban without ever writing one.
- NorwayJurisdictionPrivacy with disclosure
Norway took the EU rulebook through the EEA route and enforced it promptly, closing its transition window in July 2026 with providers told to wind down.
- UkraineJurisdictionRegime still forming
An unusual case: the virtual assets law passed in February 2022 is recorded in the official register as never having entered into force.
- GeorgiaJurisdictionRestricts anonymity
Across every jurisdiction surveyed for this section, institutional privacy oversight was either strengthening or holding steady.
Americas (8)
- FinCENRegulator or standard-setterRestricts anonymity
Registration, identity verification and suspicious activity reporting for anyone acting as a money transmitter in crypto all originate here, and none of that has loosened.
- GENIUS ActRegulator or standard-setterRestricts anonymity
The most restrictive thing in current US law on this subject, and it is architectural rather than procedural.
- OFAC and Van LoonRegulator or standard-setterPrivacy with disclosure
The most severe action ever taken by a government against privacy tooling, followed by the most significant legal retreat from one.
- The third-party doctrineRegulator or standard-setterRestricts anonymity
Any account of US financial privacy that stops at statutes misses the layer that actually decides things.
- IRS broker reportingRegulator or standard-setterRestricts anonymity
The clearest illustration of the US perimeter split. Custodial reporting arrived exactly as planned and is now in its first year of cost-basis reporting, which means identity, proceeds and acquisition…
- NYDFSRegulator or standard-setterRestricts anonymity
Where federal policy has softened around non-custodial software, New York has not moved at all.
- US Treasury and the Working GroupRegulator or standard-setterBuilds with privacy tech
The most significant shift in this section, and the one most easily overstated.
- United StatesJurisdictionPrivacy with disclosure
The US moved in both directions at once between 2024 and 2026, and the dividing line is custody rather than politics.
Asia-Pacific (8)
- AustraliaJurisdictionPrivacy with disclosure
Australia constrains confidentiality through anti-money-laundering law and not through any coin-specific rule.
- ThailandJurisdictionRestricts anonymity
Thailand is the jurisdiction most often cited as having banned privacy coins, and the claim does not survive reading the instrument.
- IndiaJurisdictionRestricts anonymity
India has no bespoke crypto statute and regulates the sector through anti-money-laundering law and tax instead.
- SingaporeJurisdictionPrivacy with disclosure
The one jurisdiction in this section that declined to exclude anonymity-enhancing assets and chose to price the risk instead.
- Hong Kong SARJurisdictionPrivacy with disclosure
A good illustration of exclusion happening without a rule that mentions the thing being excluded.
- TaiwanJurisdictionRegime still forming
Two things commonly reported about Taiwan are wrong. The VASP Act is not pending; it passed its third reading on 30 June 2026, though commencement still has to be designated and licensing runs on a 21…
- South KoreaJurisdictionRestricts anonymity
The most identity-maximalist regime covered here, and the only one actively trying to export it.
- JapanJurisdictionRestricts anonymity
Japan shows the pattern in this section at its clearest: the rule is written against untraceability, never against named assets.
Middle East & Africa (9)
- IsraelJurisdictionPrivacy with disclosure
Israel splits cleanly along the axis this whole section turns on.
- United Arab EmiratesJurisdictionRestricts anonymity
If you want the counterexample to the pattern running through this section, it is here.
- KenyaJurisdictionRestricts anonymity
Most prohibitions in this section live in rulebooks that a regulator can amend without going back to a legislature.
- GhanaJurisdictionPrivacy with disclosure
Worth citing well beyond Ghana, because a central bank stated plainly in writing what most regimes leave to inference.
- South AfricaJurisdictionRestricts anonymity
The most precisely drafted travel rule in this section, and the one that leaves least room.
- BahrainJurisdictionRestricts anonymity
Bahrain never names a coin, and its rule is broader for it. Licensees may not list assets that facilitate, or may facilitate, obfuscation or concealment of a client or counterparty's identity, and the…
- QatarJurisdictionRestricts anonymity
Qatar reaches exclusion without ever writing a prohibition on anonymity, because its perimeter is drawn as a positive list.
- NigeriaJurisdictionPrivacy with disclosure
Nigeria took the securities route rather than building a bespoke crypto statute, bringing digital assets under the securities regulator through the 2025 Act while the 2022 rules continue to carry the…
- SeychellesJurisdictionPrivacy with disclosure
Seychelles matters here because of how many crypto entities are domiciled in it rather than because of anything it says about confidentiality, and it says nothing.
Compliant by default.
Confidentiality from the public, disclosure to the parties entitled to it. See how the access list works.