A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.
What Mexico actually says
Mexico states the reasoning that most regulators leave implicit. Its central bank says plainly that offering virtual asset services to the public through financial institutions is not advisable, and lists the anonymity those assets provide in transactions among the reasons. That is anonymity named as the ground for keeping an entire asset class outside the regulated banking perimeter, rather than as a factor to be managed within it. Note what it is not: no named asset is prohibited, and exchange houses may continue to serve clients who bear the risk themselves. The other development worth flagging sits on the data protection side, where the independent regulator was abolished and its private-sector functions moved into a government ministry.
The instruments that matter
- The central bank's stated position
- it considers that providing virtual asset services to the general public through financial institutions is not advisable, identifying the anonymity such assets provide in transactions as a core reason
- Internal use only, with permission
- financial institutions may use distributed ledgers or virtual assets for internal operations with prior central bank authorisation, provided the risks do not reach end consumers
- Fintech Law authorisation
- institutions may operate only with virtual assets previously authorised by the central bank, which is a whitelist in substance
- The data protection regulator was abolished
- a constitutional reform ended the independent transparency and data protection institute, moving private-sector data protection competence into an executive ministry
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- BahamasAmericas · Issuance of privacy tokens barred, trading not
- BermudaAmericas · A travel rule with no minimum, reaching self-hosted wallets
- BrazilAmericas · A named anonymity rule, and a CBDC that could not solve privacy
- KuwaitMiddle East & Africa · A ban whose stated reason is anonymity itself
- ArgentinaAmericas · Self-custody providers written out of the regime
- British Virgin IslandsAmericas · Structural confidentiality kept, transactional confidentiality not
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.