# United Arab Emirates

> United Arab Emirates (VARA · DFSA · ADGM FSRA · CBUAE): The most explicit prohibition anywhere in this section. Region: Middle East & Africa. Restricts anonymity: Anonymity-enhancing assets or unattributed transfers are barred outright, or barred for regulated firms.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Middle East & Africa
- Subject: The most explicit prohibition anywhere in this section
- Authority: VARA · DFSA · ADGM FSRA · CBUAE
- Stance on on-chain confidentiality: Restricts anonymity. Anonymity-enhancing assets or unattributed transfers are barred outright, or barred for regulated firms.
- Tags: explicit ban, privacy devices, four regulators, Digital Dirham
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-uae

## What it actually says

If you want the counterexample to the pattern running through this section, it is here. Almost everywhere else, exclusion happens through listing rules, whitelists or traceability tests that never mention anonymity. Dubai's regulator simply writes it down: issuance of anonymity-enhanced cryptocurrencies, and every activity related to them, is prohibited in the Emirate. The financial free zones go further in a different direction, with the DIFC barring not only privacy tokens but the use of a privacy device (mixers and tumblers) as a category of tool. Four separate regulators operate here with different perimeters, which matters when structuring. Self-custody survives everywhere; the central bank's Digital Dirham is designed so that no personally identifiable information sits on the ledger.

## The instruments that matter

- **VARA Regulations 2023, Part II Section C**: states that the issuance of anonymity-enhanced cryptocurrencies and all virtual asset activities related to them are prohibited in the Emirate; the clearest named ban found in any jurisdiction here
- **DFSA GEN 3A, in force 12 January 2026**: prohibits regulated activity in privacy tokens and bars the use of a privacy device, meaning mixers and tumblers, in or from the DIFC
- **ADGM FSRA amendments, 10 June 2025**: enshrine in rules the prohibition on using privacy tokens within ADGM, and the FSRA refuses simplified customer due diligence for virtual assets citing pseudonymity
- **VARA travel rule above AED 3,500**: unhosted wallets are not banned; providers must document how they handle non-obliged entities and anonymity-enhanced transactions

## Sources

- [VARA rulebook, prohibited virtual assets](https://rulebooks.vara.ae/rulebook/c-prohibited-virtual-assets)
- [VARA rulebook, FATF travel rule](https://rulebooks.vara.ae/rulebook/g-fatf-travel-rule)
- [CBUAE Digital Dirham policy paper](https://www.centralbank.ae/media/lczb23l4/cbdc-short-report_july.pdf)

## Related entries

- [Bahrain](https://www.sodalabs.xyz/privacy-hub/regulation/jur-bahrain): A listing test written against effects, not asset names
- [Kenya](https://www.sodalabs.xyz/privacy-hub/regulation/jur-kenya): The ban written into primary legislation, not a rulebook
- [Qatar](https://www.sodalabs.xyz/privacy-hub/regulation/jur-qatar): Exclusion by perimeter rather than prohibition
- [South Africa](https://www.sodalabs.xyz/privacy-hub/regulation/jur-south-africa): A travel rule that starts at any value above zero
- [Ghana](https://www.sodalabs.xyz/privacy-hub/regulation/jur-ghana): The regulator that put self-custody in writing
- [Israel](https://www.sodalabs.xyz/privacy-hub/regulation/jur-israel): Light on-chain, heavy on data protection
