# Brazil

> Brazil (Banco Central do Brasil · CVM · ANPD): A named anonymity rule, and a CBDC that could not solve privacy. Region: Americas. Attribution required: A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Americas
- Subject: A named anonymity rule, and a CBDC that could not solve privacy
- Authority: Banco Central do Brasil · CVM · ANPD
- Stance on on-chain confidentiality: Attribution required. A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.
- Tags: Article 64, anonymity prohibited, self-custody permitted, Drex trilemma
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-brazil

## What it actually says

Brazil holds the two halves of this section's argument in one place. Its listing rule is among the most explicit anywhere, requiring providers to bar assets designed to favour money laundering by facilitating anonymity, while the same framework expressly contemplates a client choosing self-custody and asks only that the provider explain the risks. Then there is Drex. The central bank spent a pilot phase testing zero-knowledge designs precisely to build confidentiality into a state currency, and reported that the approaches which delivered privacy also cost it the visibility and control it judged necessary for its legal obligations. That is the trilemma stated by a central bank from its own experiment rather than argued in the abstract, and it is the most honest public account of the problem we found.

## The instruments that matter

- **Resolutions BCB 519, 520 and 521 of 10 November 2025**: create the virtual asset service provider framework, covering authorisation, operation, and virtual asset services in the foreign exchange market
- **Resolution 520, Article 64**: listing policies must prohibit offering virtual assets with characteristics that favour fraud or crime, expressly including assets designed to favour money laundering and terrorist financing by facilitating anonymity
- **Self-custody expressly permitted**: Article 57 contemplates a client choosing self-custody, with the provider's duty being to explain the necessary security measures rather than to refuse
- **Travel rule with wallet identification**: Article 44 requires originator and beneficiary information including identification of the transaction's virtual asset wallet
- **Drex could not reconcile privacy with oversight**: the central bank tested zero-knowledge approaches including Anonymous Zether and Rayls, and found that stronger anonymisation cost it the visibility and control it considered necessary

## Sources

- [Resolution BCB 520/2025](https://www.legisweb.com.br/legislacao/?id=486181)

## Related entries

- [Bahamas](https://www.sodalabs.xyz/privacy-hub/regulation/jur-bahamas): Issuance of privacy tokens barred, trading not
- [Bermuda](https://www.sodalabs.xyz/privacy-hub/regulation/jur-bermuda): A travel rule with no minimum, reaching self-hosted wallets
- [Mexico](https://www.sodalabs.xyz/privacy-hub/regulation/jur-mexico): Anonymity named as the reason to exclude the asset class
- [Argentina](https://www.sodalabs.xyz/privacy-hub/regulation/jur-argentina): Self-custody providers written out of the regime
- [British Virgin Islands](https://www.sodalabs.xyz/privacy-hub/regulation/jur-british-virgin-islands): Structural confidentiality kept, transactional confidentiality not
- [California](https://www.sodalabs.xyz/privacy-hub/regulation/jur-california): A licensing regime that arrived in July 2026
