Confidentiality is workable so long as the regulated firm can identify the parties and disclose on demand. Encrypted amounts are not the thing being restricted.
What Liechtenstein actually says
Liechtenstein made a structural choice worth understanding: rather than requiring every participant to identify counterparties, it turned identification into its own licensed role. An identity service provider is defined as the party who identifies whoever is entitled to dispose of a token and records them in a register, and the corresponding duty is to assign identifiers correctly to the lawful holder and keep customer data securely. That scopes the surveillance function to a nameable actor instead of spreading it everywhere. Technology neutrality is written into the statute's purpose rather than asserted in marketing. Nothing in the text we read restricts anonymity-enhancing assets. Note that the financially regulated activities have since been carved out to the EU regime, leaving this act covering the civil-law and non-EU residue.
The instruments that matter
- Token and TT Service Provider Act (TVTG)
- the law of 3 October 2019 on tokens and trustworthy technology service providers, published in the national gazette on 2 December 2019
- Technology neutrality is a statutory purpose
- Article 1 states the aim of creating optimal, innovation-friendly and technology-neutral conditions for services on trustworthy technology systems
- Identity as a separate licensed function
- Article 2(1)(t) defines an identity service provider as a person who identifies the party entitled to dispose of a token and records them in a register, rather than spreading that duty across every actor
- The corresponding duty
- Article 17 requires such providers to ensure correct assignment of identifiers to the lawful holder and secure retention of customer data
- A guardrail on onward transfer
- Article 42 permits transmission of personal data to third-country authorities only where the conditions of Chapter V of the GDPR are met
- The EU anti-money-laundering regulation is not incorporated
- it remains under examination for the EEA by Liechtenstein, Iceland and Norway, so the EU prohibition on anonymous crypto accounts does not currently bind them
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- AustriaEurope · EU baseline, with an early transition close
- BelgiumEurope · EU baseline, with no national layer on confidentiality
- CzechiaEurope · EU baseline, supervised by the central bank
- DenmarkEurope · EU baseline, with tax as the historic pressure point
- EstoniaEurope · The licence cull that reshaped the European market
- FranceEurope · Hardest against anonymity, most literate about privacy tech
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.