Confidentiality is workable so long as the regulated firm can identify the parties and disclose on demand. Encrypted amounts are not the thing being restricted.
What Kazakhstan actually says
Worth correcting a claim that circulates about Kazakhstan: the law does not establish a state system watching digital asset transactions. It requires each licensed operator to run its own analysis and control system, built to the National Bank's specification, which is a mandated chain-analytics obligation rather than centralised surveillance. The teeth are in the identification rule. Operators must hold information sufficient to identify both sender and recipient, and a transfer with incomplete information is suspended and then refused. Unsecured digital assets remain legal but are stripped of status as a means of payment or a financial instrument. A second, separate track exists inside the Astana financial centre under its own regulator, whose terms we could not verify.
The instruments that matter
- Law No. 193-VII of 6 February 2023 on digital assets
- the National Bank licenses and oversees operators of unsecured digital asset exchanges and digital financial asset platforms
- System for the analysis and control of operations
- defined in the law as a platform or service for monitoring digital asset operations, tracking them and detecting suspicious activity; operators must implement one to National Bank specification
- A duty on operators, not a state platform
- the obligation was added by a 2026 amendment and is closer to a mandated chain-analytics requirement than to centralised state surveillance
- Identification blocks the transfer
- operators must collect sender and recipient information sufficient to identify them; transfers with incomplete information are suspended for at least 48 hours and refused if not remedied
- Personal data must stay in country
- Article 12 of the 2013 personal data law requires storage in a database located on Kazakh territory, which constrains offshore custody and analytics
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- AustraliaAsia-Pacific · Travel rule without a threshold, no coin ban
- Hong Kong SARAsia-Pacific · Retail exclusion by liquidity gate, not by anonymity rule
- PhilippinesAsia-Pacific · Every transfer is a cross-border wire, inside a closed chain
- SingaporeAsia-Pacific · Regulates anonymity by risk assessment, not prohibition
- BangladeshAsia-Pacific · Barred through exchange control, not a crypto law
- ChinaAsia-Pacific · Crypto banned, and a state currency designed for anonymity
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.