Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.
What Norway actually says
Norway took the EU rulebook through the EEA route and enforced it promptly, closing its transition window in July 2026 with providers told to wind down. That means the zero-threshold travel rule applies here as it does inside the union. The counterweight is unusual and worth knowing about: the Norwegian data protection authority has run a regulatory sandbox for privacy-enhancing innovation since 2020, and in 2024 ran a joint track with the financial supervisor. Few jurisdictions have both regulators in the same room on this question. Norges Bank concluded that a central bank digital currency is not currently warranted and closed its exploration phase in March 2026, so no retail privacy design question arises.
The instruments that matter
- Lov om kryptoeiendeler, in force 1 July 2025
- gives MiCA effect through the EEA Agreement following Joint Committee Decision No. 41/2025 of 20 February 2025
- Travel rule extended to crypto
- simultaneous amendments to the anti-money-laundering act implemented the EU Transfer of Funds Regulation, with no de minimis
- Transition closed 1 July 2026
- unauthorised providers must stop onboarding and wind down
- Datatilsynet regulatory sandbox
- running since 2020 explicitly for privacy-enhancing innovation, including a joint track with the financial supervisor in 2024
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- EU Transfer of Funds RegulationEurope · Travel rule · Regulation (EU) 2023/1113
- United KingdomEurope · Risk-based, with an explicit central bank no-access pledge
- CJEU on identifiabilityEurope · Case law · is a wallet address personal data
- EDPB blockchain guidelinesEurope · Data protection guidance · Guidelines 02/2025
- EU Data Act, Article 36Europe · Smart contract requirements · Regulation (EU) 2023/2854
- GeorgiaEurope · The one place where privacy oversight went backwards
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.