A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.
What Turkey actually says
Turkey reaches the same destination as an anonymity ban without ever writing one. No primary instrument prohibiting anonymity-enhancing tokens was found. What exists instead is a stack of operational controls that make routine confidentiality impractical at licensed venues: value caps on transfers, doubled only if the full travel rule dataset is collected, a mandatory waiting period before withdrawal, a declaration requirement for anything touching an unhosted wallet, and a compelled free-text description of what every transfer is for. Each measure is individually defensible as anti-fraud policy. Together they amount to a regime where a licensed Turkish venue cannot process a transfer it does not have a stated reason for.
The instruments that matter
- Law No. 7518, July 2024
- places crypto service provider licensing with the Capital Markets Board, with establishment and capital rules set by communiqués published 13 March 2025
- Travel rule from 25 February 2025
- expanded originator data above TRY 15,000; transfers to or from unhosted wallets require a customer declaration, and transfers with unresolved information gaps are returned or rejected
- Communiqués 28 and 29, June 2025
- stablecoin transfer caps of USD 3,000 daily and USD 50,000 monthly, doubled where full travel rule data is collected, with higher caps for other crypto assets
- Withdrawal delays and purpose text
- a 48-hour delay on withdrawals, 72 hours on the first, plus a minimum 20-character description of every transfer's purpose
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- GeorgiaEurope · The one place where privacy oversight went backwards
- RussiaEurope · Wallet addresses reported to the state by statute
- SwitzerlandEurope · Crypto-friendly and strict on anonymity at once
- AustriaEurope · EU baseline, with an early transition close
- BelgiumEurope · EU baseline, with no national layer on confidentiality
- CzechiaEurope · EU baseline, supervised by the central bank
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.