Soda Labs

Liechtenstein

Identification unbundled into its own licensed role

JurisdictionEuropeConfidential with disclosure

Confidentiality is workable so long as the regulated firm can identify the parties and disclose on demand. Encrypted amounts are not the thing being restricted.

What Liechtenstein actually says

Liechtenstein made a structural choice worth understanding: rather than requiring every participant to identify counterparties, it turned identification into its own licensed role. An identity service provider is defined as the party who identifies whoever is entitled to dispose of a token and records them in a register, and the corresponding duty is to assign identifiers correctly to the lawful holder and keep customer data securely. That scopes the surveillance function to a nameable actor instead of spreading it everywhere. Technology neutrality is written into the statute's purpose rather than asserted in marketing. Nothing in the text we read restricts anonymity-enhancing assets. Note that the financially regulated activities have since been carved out to the EU regime, leaving this act covering the civil-law and non-EU residue.

The instruments that matter

Token and TT Service Provider Act (TVTG)
the law of 3 October 2019 on tokens and trustworthy technology service providers, published in the national gazette on 2 December 2019
Technology neutrality is a statutory purpose
Article 1 states the aim of creating optimal, innovation-friendly and technology-neutral conditions for services on trustworthy technology systems
Identity as a separate licensed function
Article 2(1)(t) defines an identity service provider as a person who identifies the party entitled to dispose of a token and records them in a register, rather than spreading that duty across every actor
The corresponding duty
Article 17 requires such providers to ensure correct assignment of identifiers to the lawful holder and secure retention of customer data
A guardrail on onward transfer
Article 42 permits transmission of personal data to third-country authorities only where the conditions of Chapter V of the GDPR are met
The EU anti-money-laundering regulation is not incorporated
it remains under examination for the EEA by Liechtenstein, Iceland and Norway, so the EU prohibition on anonymous crypto accounts does not currently bind them

What this means for confidential transactions

Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.

Compliant by default.

See how selective disclosure satisfies a supervisor without publishing your book to the world.