Confidentiality is workable so long as the regulated firm can identify the parties and disclose on demand. Encrypted amounts are not the thing being restricted.
What Australia actually says
Australia constrains confidentiality through anti-money-laundering law and not through any coin-specific rule. No Australian instrument prohibits anonymity-enhancing assets; AUSTRAC lists privacy coins, tumblers and mixers among its suspicious activity indicators, and delistings to date have been commercial and bank-driven rather than mandated. The travel rule that starts applying to virtual asset transfers on 1 July 2026 has no minimum value at all, which is stricter than most peers. Transfers to self-hosted wallets are handled as their own category rather than exempted: the sending institution must collect and verify payer information and collect payee and tracing information, with reporting on transfers to unverified self-hosted wallets starting in 2029. Retail CBDC was set aside after Project Acacia, so the retail privacy design question never arose here.
The instruments that matter
- AML/CTF Amendment Act 2024
- commences for existing reporting entities 31 March 2026 and for tranche 2 entities 1 July 2026, widening virtual asset services to exchange, custody, transfer and sale
- Travel rule from 1 July 2026 for virtual assets
- applies to every virtual asset transfer regardless of value; there is no de minimis
- Self-hosted wallets handled separately
- an ordering institution transferring to a self-hosted wallet must collect and verify payer information and collect payee and tracing information; reporting on transfers to unverified self-hosted wallets starts 31 March 2029
- ASIC INFO 225, updated 29 October 2025
- 18 worked examples plus a sector-wide no-action position on licensing until 30 June 2026
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- SingaporeAsia-Pacific · Regulates anonymity by risk assessment, not prohibition
- Hong Kong SARAsia-Pacific · Retail exclusion by liquidity gate, not by anonymity rule
- KazakhstanAsia-Pacific · Surveillance tooling required of operators, not run by the state
- PhilippinesAsia-Pacific · Every transfer is a cross-border wire, inside a closed chain
- United KingdomEurope · Risk-based, with an explicit central bank no-access pledge
- BangladeshAsia-Pacific · Barred through exchange control, not a crypto law
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.