A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.
What Japan actually says
Japan shows the pattern in this section at its clearest: the rule is written against untraceability, never against named assets. The industry body's handling rules have barred members since 2018 from dealing in any crypto asset whose transfer records cannot be traced or are markedly difficult to trace, which is why Monero, Zcash and Dash have been absent from Japanese venues for years without any instrument naming them. Legislation enacted in July 2026 moves crypto trading out of payments law and into the securities framework. Worth being precise about what that does to traceability: the statute bars assets failing user-protection standards, but the criteria, including transfer-record management, are delegated to Cabinet Office Ordinance and have not been written yet.
The instruments that matter
- JVCEA handling rules, Article 4(3), from 30 July 2018
- members must not handle a crypto asset whose transfer records cannot be traced or are markedly difficult to trace; the test is traceability, not the asset's name
- Green List, updated 5 August 2026
- 30 assets, none of them Monero, Zcash or Dash; note this is a widely-handled list rather than the permitted universe, so absence is evidence and not proof of prohibition
- FIEA migration enacted 15 July 2026
- moves crypto trading out of the Payment Services Act into the Financial Instruments and Exchange Act as a product distinct from securities, creates crypto insider trading, and raises the unregistered-operator penalty to ten years
- Amended FIEA Article 43-7
- bars handling assets failing user-protection standards, with the criteria (including transfer-record management) delegated to Cabinet Office Ordinance rather than set in the statute
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- Japan FSA and JVCEAAsia-Pacific · A traceability test, applied by the industry body
- BangladeshAsia-Pacific · Barred through exchange control, not a crypto law
- ChinaAsia-Pacific · Crypto banned, and a state currency designed for anonymity
- IndiaAsia-Pacific · No crypto statute, regulated through AML and tax
- MalaysiaAsia-Pacific · A categorical ban written by definition, not by coin name
- South KoreaAsia-Pacific · Identity-maximalist, and exporting the model
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.