# Crypto privacy regulation, by jurisdiction

> What the rulebook actually says about confidentiality on public blockchains,
> read from the instruments themselves rather than from summaries of them.

Confidentiality and compliance are usually described as opposites. Read the
instruments and they mostly are not: nearly every rule that looks like a demand
for transparency binds a regulated institution to know and disclose specific
facts to specific parties, not to publish those facts to the world.

Part of the Soda Labs Privacy Hub: https://www.sodalabs.xyz/privacy-hub
Human-readable version of this page: https://www.sodalabs.xyz/privacy-hub/regulation
Every entry below also exists as markdown at <entry-url>.md

## 58 entries

### Global (18)

- [The travel rule binds institutions, not ledgers](https://www.sodalabs.xyz/privacy-hub/regulation/why-travel-rule): The most common objection to confidential transfers is that the travel rule forbids them.
- [Erasure against an append-only ledger](https://www.sodalabs.xyz/privacy-hub/regulation/why-erasure): This is the collision that does not dissolve on closer reading.
- [Selective disclosure as a compliance primitive](https://www.sodalabs.xyz/privacy-hub/regulation/why-viewing-keys): Supervisory access, external audit and suspicious activity reporting are all bilateral disclosures to a named party under a legal duty.
- [Proving where funds did not come from](https://www.sodalabs.xyz/privacy-hub/regulation/why-privacy-pools): The 2023 Privacy Pools paper made a design argument that has held up: instead of hiding everything, let a depositor prove in zero knowledge that their withdrawal belongs to a chose…
- [Central banks are building confidentiality themselves](https://www.sodalabs.xyz/privacy-hub/regulation/why-central-banks-build-privacy): The strongest evidence that public authorities do not equate confidentiality with wrongdoing is that they keep building it.
- [Why regulated institutions cannot use a transparent ledger](https://www.sodalabs.xyz/privacy-hub/regulation/why-institutions-need-it): The compliance debate usually asks whether institutions are permitted to use confidentiality.
- [Sanctions screening on a confidential ledger](https://www.sodalabs.xyz/privacy-hub/regulation/why-sanctions-screening): Worth stating plainly rather than glossing: this is the weakest part of the case for confidential ledgers.
- [Anonymity is not the same thing as confidentiality](https://www.sodalabs.xyz/privacy-hub/regulation/why-programmable-confidentiality): Regulators keep drawing a line that the debate tends to flatten.
- [FATF](https://www.sodalabs.xyz/privacy-hub/regulation/reg-fatf) [Restricts anonymity]: Nothing else in this section has as much reach. FATF sets standards rather than law, but the mutual evaluation process and the grey list make adoption close to compulsory, which is…
- [Basel Committee, SCO60](https://www.sodalabs.xyz/privacy-hub/regulation/reg-basel-sco60) [Restricts anonymity]: The single most privacy-restrictive sentence in global financial regulation is probably here.
- [BIS Innovation Hub](https://www.sodalabs.xyz/privacy-hub/regulation/reg-bis-innovation-hub) [Builds with privacy tech]: If you want evidence that the institutions writing the rules do not equate confidentiality with crime, this is where to look.
- [OECD CARF](https://www.sodalabs.xyz/privacy-hub/regulation/reg-oecd-carf) [Restricts anonymity]: The quiet instrument that will do the most to end pseudonymity at the intermediary layer, and it arrives before the AML rules do.
- [IOSCO](https://www.sodalabs.xyz/privacy-hub/regulation/reg-iosco) [Privacy with disclosure]: IOSCO pulls in both directions, which makes it more interesting than most.
- [Financial Stability Board](https://www.sodalabs.xyz/privacy-hub/regulation/reg-fsb) [Privacy with disclosure]: Included here mainly to correct a common misattribution. The FSB coordinates national authorities on financial stability, and its 2023 framework is frequently cited in arguments ab…
- [Convention 108+](https://www.sodalabs.xyz/privacy-hub/regulation/reg-convention-108) [Builds with privacy tech]: The counterweight instrument, and the one that has not arrived.
- [Egmont Group](https://www.sodalabs.xyz/privacy-hub/regulation/reg-egmont) [Restricts anonymity]: Rarely discussed in privacy debates about crypto, and structurally one of the more significant bodies in this section.
- [NIST](https://www.sodalabs.xyz/privacy-hub/regulation/reg-nist) [Builds with privacy tech]: A national agency rather than a global one, included because its output gets adopted internationally as reference material and because it does something no financial regulator has.
- [ISO and IEC standards](https://www.sodalabs.xyz/privacy-hub/regulation/reg-iso) [Builds with privacy tech]: Set this against the financial standard-setters and the contrast is sharp.

### Europe (15)

- [MiCA](https://www.sodalabs.xyz/privacy-hub/regulation/reg-mica) [Privacy with disclosure]: MiCA carries exactly one operative anonymity rule, and it is narrower than its reputation.
- [EU Transfer of Funds Regulation](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eu-travel-rule) [Restricts anonymity]: This, not the privacy-coin headline, is what actually ends unattributed transfers at the EU perimeter.
- [EU AMLR Article 79](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eu-amlr) [Restricts anonymity]: Reported almost everywhere as an EU ban on privacy coins from 1 July 2027.
- [GDPR](https://www.sodalabs.xyz/privacy-hub/regulation/reg-gdpr) [Builds with privacy tech]: The law most often described as a problem for blockchain is also the strongest European argument for building with privacy technology.
- [EDPB blockchain guidelines](https://www.sodalabs.xyz/privacy-hub/regulation/reg-edpb-blockchain) [Privacy with disclosure]: The reference text on how European data protection law lands on a ledger, final since 7 July 2026.
- [CJEU on identifiability](https://www.sodalabs.xyz/privacy-hub/regulation/reg-cjeu-identifiability) [Privacy with disclosure]: Whether a blockchain address is personal data is not a settled question, and the two European institutions answering it are drifting apart.
- [eIDAS 2 and the EU Digital Identity Wallet](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eidas2) [Builds with privacy tech]: The clearest counterexample to the idea that regulators are uniformly against cryptographic privacy: here EU law names the technology and requires it.
- [Digital euro](https://www.sodalabs.xyz/privacy-hub/regulation/reg-digital-euro) [Builds with privacy tech]: A central bank designing confidentiality into money on purpose is the most direct evidence that European regulators do not equate privacy with illegality.
- [EU Data Act, Article 36](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eu-data-act) [Privacy with disclosure]: A useful case of a rule written for one context landing awkwardly on another.
- [United Kingdom](https://www.sodalabs.xyz/privacy-hub/regulation/jur-united-kingdom) [Privacy with disclosure]: The UK has built a full regulatory perimeter without reaching for a single prohibition on privacy technology.
- [Switzerland](https://www.sodalabs.xyz/privacy-hub/regulation/jur-switzerland) [Restricts anonymity]: A useful corrective to the assumption that a crypto-friendly jurisdiction is permissive about anonymity.
- [Turkey](https://www.sodalabs.xyz/privacy-hub/regulation/jur-turkey) [Restricts anonymity]: Turkey reaches the same destination as an anonymity ban without ever writing one.
- [Norway](https://www.sodalabs.xyz/privacy-hub/regulation/jur-norway) [Privacy with disclosure]: Norway took the EU rulebook through the EEA route and enforced it promptly, closing its transition window in July 2026 with providers told to wind down.
- [Ukraine](https://www.sodalabs.xyz/privacy-hub/regulation/jur-ukraine) [Regime still forming]: An unusual case: the virtual assets law passed in February 2022 is recorded in the official register as never having entered into force.
- [Georgia](https://www.sodalabs.xyz/privacy-hub/regulation/jur-georgia) [Restricts anonymity]: Across every jurisdiction surveyed for this section, institutional privacy oversight was either strengthening or holding steady.

### Americas (8)

- [FinCEN](https://www.sodalabs.xyz/privacy-hub/regulation/reg-fincen) [Restricts anonymity]: Registration, identity verification and suspicious activity reporting for anyone acting as a money transmitter in crypto all originate here, and none of that has loosened.
- [GENIUS Act](https://www.sodalabs.xyz/privacy-hub/regulation/reg-genius-act) [Restricts anonymity]: The most restrictive thing in current US law on this subject, and it is architectural rather than procedural.
- [OFAC and Van Loon](https://www.sodalabs.xyz/privacy-hub/regulation/reg-ofac) [Privacy with disclosure]: The most severe action ever taken by a government against privacy tooling, followed by the most significant legal retreat from one.
- [The third-party doctrine](https://www.sodalabs.xyz/privacy-hub/regulation/reg-third-party-doctrine) [Restricts anonymity]: Any account of US financial privacy that stops at statutes misses the layer that actually decides things.
- [IRS broker reporting](https://www.sodalabs.xyz/privacy-hub/regulation/reg-irs-broker-reporting) [Restricts anonymity]: The clearest illustration of the US perimeter split. Custodial reporting arrived exactly as planned and is now in its first year of cost-basis reporting, which means identity, proc…
- [NYDFS](https://www.sodalabs.xyz/privacy-hub/regulation/reg-nydfs) [Restricts anonymity]: Where federal policy has softened around non-custodial software, New York has not moved at all.
- [US Treasury and the Working Group](https://www.sodalabs.xyz/privacy-hub/regulation/reg-us-treasury-pwg) [Builds with privacy tech]: The most significant shift in this section, and the one most easily overstated.
- [United States](https://www.sodalabs.xyz/privacy-hub/regulation/jur-united-states) [Privacy with disclosure]: The US moved in both directions at once between 2024 and 2026, and the dividing line is custody rather than politics.

### Asia-Pacific (8)

- [Australia](https://www.sodalabs.xyz/privacy-hub/regulation/jur-australia) [Privacy with disclosure]: Australia constrains confidentiality through anti-money-laundering law and not through any coin-specific rule.
- [Thailand](https://www.sodalabs.xyz/privacy-hub/regulation/jur-thailand) [Restricts anonymity]: Thailand is the jurisdiction most often cited as having banned privacy coins, and the claim does not survive reading the instrument.
- [India](https://www.sodalabs.xyz/privacy-hub/regulation/jur-india) [Restricts anonymity]: India has no bespoke crypto statute and regulates the sector through anti-money-laundering law and tax instead.
- [Singapore](https://www.sodalabs.xyz/privacy-hub/regulation/jur-singapore) [Privacy with disclosure]: The one jurisdiction in this section that declined to exclude anonymity-enhancing assets and chose to price the risk instead.
- [Hong Kong SAR](https://www.sodalabs.xyz/privacy-hub/regulation/jur-hong-kong) [Privacy with disclosure]: A good illustration of exclusion happening without a rule that mentions the thing being excluded.
- [Taiwan](https://www.sodalabs.xyz/privacy-hub/regulation/jur-taiwan) [Regime still forming]: Two things commonly reported about Taiwan are wrong. The VASP Act is not pending; it passed its third reading on 30 June 2026, though commencement still has to be designated and li…
- [South Korea](https://www.sodalabs.xyz/privacy-hub/regulation/jur-south-korea) [Restricts anonymity]: The most identity-maximalist regime covered here, and the only one actively trying to export it.
- [Japan](https://www.sodalabs.xyz/privacy-hub/regulation/jur-japan) [Restricts anonymity]: Japan shows the pattern in this section at its clearest: the rule is written against untraceability, never against named assets.

### Middle East & Africa (9)

- [Israel](https://www.sodalabs.xyz/privacy-hub/regulation/jur-israel) [Privacy with disclosure]: Israel splits cleanly along the axis this whole section turns on.
- [United Arab Emirates](https://www.sodalabs.xyz/privacy-hub/regulation/jur-uae) [Restricts anonymity]: If you want the counterexample to the pattern running through this section, it is here.
- [Kenya](https://www.sodalabs.xyz/privacy-hub/regulation/jur-kenya) [Restricts anonymity]: Most prohibitions in this section live in rulebooks that a regulator can amend without going back to a legislature.
- [Ghana](https://www.sodalabs.xyz/privacy-hub/regulation/jur-ghana) [Privacy with disclosure]: Worth citing well beyond Ghana, because a central bank stated plainly in writing what most regimes leave to inference.
- [South Africa](https://www.sodalabs.xyz/privacy-hub/regulation/jur-south-africa) [Restricts anonymity]: The most precisely drafted travel rule in this section, and the one that leaves least room.
- [Bahrain](https://www.sodalabs.xyz/privacy-hub/regulation/jur-bahrain) [Restricts anonymity]: Bahrain never names a coin, and its rule is broader for it. Licensees may not list assets that facilitate, or may facilitate, obfuscation or concealment of a client or counterparty…
- [Qatar](https://www.sodalabs.xyz/privacy-hub/regulation/jur-qatar) [Restricts anonymity]: Qatar reaches exclusion without ever writing a prohibition on anonymity, because its perimeter is drawn as a positive list.
- [Nigeria](https://www.sodalabs.xyz/privacy-hub/regulation/jur-nigeria) [Privacy with disclosure]: Nigeria took the securities route rather than building a bespoke crypto statute, bringing digital assets under the securities regulator through the 2025 Act while the 2022 rules co…
- [Seychelles](https://www.sodalabs.xyz/privacy-hub/regulation/jur-seychelles) [Privacy with disclosure]: Seychelles matters here because of how many crypto entities are domiciled in it rather than because of anything it says about confidentiality, and it says nothing.
