Soda Labs

United Arab Emirates

The most explicit prohibition anywhere in this section

JurisdictionMiddle East & AfricaRestricts anonymity

Anonymity-enhancing assets or unattributed transfers are barred outright, or barred for regulated firms.

What United Arab Emirates actually says

If you want the counterexample to the pattern running through this section, it is here. Almost everywhere else, exclusion happens through listing rules, whitelists or traceability tests that never mention anonymity. Dubai's regulator simply writes it down: issuance of anonymity-enhanced cryptocurrencies, and every activity related to them, is prohibited in the Emirate. The financial free zones go further in a different direction, with the DIFC barring not only privacy tokens but the use of a privacy device (mixers and tumblers) as a category of tool. Four separate regulators operate here with different perimeters, which matters when structuring. Self-custody survives everywhere; the central bank's Digital Dirham is designed so that no personally identifiable information sits on the ledger.

The instruments that matter

VARA Regulations 2023, Part II Section C
states that the issuance of anonymity-enhanced cryptocurrencies and all virtual asset activities related to them are prohibited in the Emirate; the clearest named ban found in any jurisdiction here
DFSA GEN 3A, in force 12 January 2026
prohibits regulated activity in privacy tokens and bars the use of a privacy device, meaning mixers and tumblers, in or from the DIFC
ADGM FSRA amendments, 10 June 2025
enshrine in rules the prohibition on using privacy tokens within ADGM, and the FSRA refuses simplified customer due diligence for virtual assets citing pseudonymity
VARA travel rule above AED 3,500
unhosted wallets are not banned; providers must document how they handle non-obliged entities and anonymity-enhanced transactions

What this means for confidential transactions

Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.

Compliant by default.

See how selective disclosure satisfies a supervisor without publishing your book to the world.