Soda Labs

Netherlands

The wallet verification demand that was abandoned

JurisdictionEuropeConfidential with disclosure

Confidentiality is workable so long as the regulated firm can identify the parties and disclose on demand. Encrypted amounts are not the thing being restricted.

What Netherlands actually says

The Netherlands ran the most aggressive self-hosted wallet identification demand in Europe and then gave it up, which makes it the most instructive European case in this section. Providers had to verify the address on every transfer to or from an external wallet, in practice by asking customers to photograph their wallet or sign a message. Worth being precise, because the headlines were not: the court did not annul the requirement. It gave the regulator six weeks to justify it properly. The regulator then accepted the challenge was well founded, revoked the requirement and stopped collecting screenshots. A supervisor reversing itself on proportionality grounds is rare enough to be worth citing wherever the unhosted wallet question comes up.

The instruments that matter

The central bank's address verification requirement
providers had to verify the wallet address on every transaction to or from an external wallet, in practice by collecting a customer screenshot or a signature over the receiving address
Challenged as disproportionate
the exchange argued the requirement had no technical merit and violated customer privacy, putting its complaints to the court in March 2021
The court did not strike it down
the judge gave the central bank six weeks to review and re-justify its address verification policy rather than annulling it
The regulator then withdrew it
the central bank accepted the challenge was right, revoked the requirement and stopped asking for wallet screenshots

What this means for confidential transactions

Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.

Compliant by default.

See how selective disclosure satisfies a supervisor without publishing your book to the world.