Soda Labs

Portugal

A data regulator stopping biometrics bought with tokens

JurisdictionEuropeConfidential with disclosure

Confidentiality is workable so long as the regulated firm can identify the parties and disclose on demand. Encrypted amounts are not the thing being restricted.

What Portugal actually says

Portugal's distinctive contribution came from its data protection authority rather than its financial regulators, and it addresses a question the financial rules do not reach. When an identity system offered crypto tokens in exchange for iris scans, the authority suspended collection of biometric data across Portuguese territory as an urgent measure, citing collection from minors without parental authorisation, inadequate information, and no way to delete data or withdraw consent. The detail that matters here is the absence of any age check while people joined specifically to receive tokens. It is a regulator treating payment for biometric data as the problem, which is the mirror image of most debates in this section, where the worry is that transactions reveal too much rather than that identity is being bought.

The instruments that matter

CNPD suspension of Worldcoin, 26 March 2024
suspended collection of iris, eye and face biometric data in Portuguese territory to safeguard the fundamental right to personal data protection, especially for minors
An urgent provisional measure
imposed for 90 days to allow the authority to conclude its investigation and issue a final decision, and maintained on review in July 2024
What prompted it
numerous complaints reporting collection from minors without parental authorisation, deficient information to data subjects, and inability to delete data or withdraw consent
The crypto link is the point
the authority noted there was no age verification mechanism despite a significant influx of people, including minors, joining to receive tokens

What this means for confidential transactions

Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.

Compliant by default.

See how selective disclosure satisfies a supervisor without publishing your book to the world.