Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.
What United Kingdom actually says
The UK has built a full regulatory perimeter without reaching for a single prohibition on privacy technology. There is no ban on anonymity-enhancing assets and no bar on transfers to unhosted wallets; firms are expected to document a risk-based approach, and transfers into jurisdictions that have not implemented the travel rule call for enhanced assessment rather than refusal. Two things are worth noting on the other side of the ledger. The FCA runs a permanent digital sandbox offering hundreds of synthetic, anonymised and pseudonymised datasets, cooperating with the data protection regulator. And the digital pound design carries an unusually direct commitment that neither the Bank nor the Government would have access to users' personal data.
The instruments that matter
- FSMA (Cryptoassets) Regulations 2026, made 4 February 2026
- brings dealing, arranging, trading platforms, custody, qualifying stablecoin issuance and staking arrangement into the regulated perimeter
- FCA final rules, 30 June 2026
- the authorisation gateway opens 30 September 2026, applications run to 28 February 2027, and the regime bites 25 October 2027
- Travel rule since 1 September 2023
- under Part 7A of the Money Laundering Regulations 2017; transfers to non-implementing jurisdictions require enhanced assessment rather than automatic refusal
- Digital pound privacy commitment
- neither the Bank nor Government would access users' personal data; payment interface providers do the identity work and anonymise before the core ledger
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- SingaporeAsia-Pacific · Regulates anonymity by risk assessment, not prohibition
- AustraliaAsia-Pacific · Travel rule without a threshold, no coin ban
- NorwayEurope · MiCA via the EEA, with a privacy-innovation sandbox
- CJEU on identifiabilityEurope · Case law · is a wallet address personal data
- EDPB blockchain guidelinesEurope · Data protection guidance · Guidelines 02/2025
- EU Data Act, Article 36Europe · Smart contract requirements · Regulation (EU) 2023/2854
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.