# Mexico

> Mexico (Banco de México · CNBV · UIF): Anonymity named as the reason to exclude the asset class. Region: Americas. Attribution required: A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Americas
- Subject: Anonymity named as the reason to exclude the asset class
- Authority: Banco de México · CNBV · UIF
- Stance on on-chain confidentiality: Attribution required. A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.
- Tags: anonymity as rationale, bank perimeter exclusion, whitelist, regulator independence lost
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-mexico

## What it actually says

Mexico states the reasoning that most regulators leave implicit. Its central bank says plainly that offering virtual asset services to the public through financial institutions is not advisable, and lists the anonymity those assets provide in transactions among the reasons. That is anonymity named as the ground for keeping an entire asset class outside the regulated banking perimeter, rather than as a factor to be managed within it. Note what it is not: no named asset is prohibited, and exchange houses may continue to serve clients who bear the risk themselves. The other development worth flagging sits on the data protection side, where the independent regulator was abolished and its private-sector functions moved into a government ministry.

## The instruments that matter

- **The central bank's stated position**: it considers that providing virtual asset services to the general public through financial institutions is not advisable, identifying the anonymity such assets provide in transactions as a core reason
- **Internal use only, with permission**: financial institutions may use distributed ledgers or virtual assets for internal operations with prior central bank authorisation, provided the risks do not reach end consumers
- **Fintech Law authorisation**: institutions may operate only with virtual assets previously authorised by the central bank, which is a whitelist in substance
- **The data protection regulator was abolished**: a constitutional reform ended the independent transparency and data protection institute, moving private-sector data protection competence into an executive ministry

## Sources

- [Banco de México regulatory actions on virtual assets](https://www.banxico.org.mx/sistemas-de-pago/6--acciones-regulatorias-po.html)

## Related entries

- [Bahamas](https://www.sodalabs.xyz/privacy-hub/regulation/jur-bahamas): Issuance of privacy tokens barred, trading not
- [Bermuda](https://www.sodalabs.xyz/privacy-hub/regulation/jur-bermuda): A travel rule with no minimum, reaching self-hosted wallets
- [Brazil](https://www.sodalabs.xyz/privacy-hub/regulation/jur-brazil): A named anonymity rule, and a CBDC that could not solve privacy
- [Kuwait](https://www.sodalabs.xyz/privacy-hub/regulation/jur-kuwait): A ban whose stated reason is anonymity itself
- [Argentina](https://www.sodalabs.xyz/privacy-hub/regulation/jur-argentina): Self-custody providers written out of the regime
- [British Virgin Islands](https://www.sodalabs.xyz/privacy-hub/regulation/jur-british-virgin-islands): Structural confidentiality kept, transactional confidentiality not
