# United Kingdom

> United Kingdom (FCA · Bank of England · Information Commissioner): Risk-based, with an explicit central bank no-access pledge. Region: Europe. Privacy with disclosure: Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Europe
- Subject: Risk-based, with an explicit central bank no-access pledge
- Authority: FCA · Bank of England · Information Commissioner
- Stance on on-chain confidentiality: Privacy with disclosure. Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.
- Tags: risk-based, no privacy coin ban, digital sandbox, digital pound
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-united-kingdom

## What it actually says

The UK has built a full regulatory perimeter without reaching for a single prohibition on privacy technology. There is no ban on anonymity-enhancing assets and no bar on transfers to unhosted wallets; firms are expected to document a risk-based approach, and transfers into jurisdictions that have not implemented the travel rule call for enhanced assessment rather than refusal. Two things are worth noting on the other side of the ledger. The FCA runs a permanent digital sandbox offering hundreds of synthetic, anonymised and pseudonymised datasets, cooperating with the data protection regulator. And the digital pound design carries an unusually direct commitment that neither the Bank nor the Government would have access to users' personal data.

## The instruments that matter

- **FSMA (Cryptoassets) Regulations 2026, made 4 February 2026**: brings dealing, arranging, trading platforms, custody, qualifying stablecoin issuance and staking arrangement into the regulated perimeter
- **FCA final rules, 30 June 2026**: the authorisation gateway opens 30 September 2026, applications run to 28 February 2027, and the regime bites 25 October 2027
- **Travel rule since 1 September 2023**: under Part 7A of the Money Laundering Regulations 2017; transfers to non-implementing jurisdictions require enhanced assessment rather than automatic refusal
- **Digital pound privacy commitment**: neither the Bank nor Government would access users' personal data; payment interface providers do the identity work and anonymise before the core ledger

## Sources

- [FCA new cryptoasset regime](https://www.fca.org.uk/firms/new-regime-cryptoasset-regulation)
- [Bank of England digital pound](https://www.bankofengland.co.uk/the-digital-pound)

## Related entries

- [Singapore](https://www.sodalabs.xyz/privacy-hub/regulation/jur-singapore): Regulates anonymity by risk assessment, not prohibition
- [Australia](https://www.sodalabs.xyz/privacy-hub/regulation/jur-australia): Travel rule without a threshold, no coin ban
- [Norway](https://www.sodalabs.xyz/privacy-hub/regulation/jur-norway): MiCA via the EEA, with a privacy-innovation sandbox
- [CJEU on identifiability](https://www.sodalabs.xyz/privacy-hub/regulation/reg-cjeu-identifiability): Case law · is a wallet address personal data
- [EDPB blockchain guidelines](https://www.sodalabs.xyz/privacy-hub/regulation/reg-edpb-blockchain): Data protection guidance · Guidelines 02/2025
- [EU Data Act, Article 36](https://www.sodalabs.xyz/privacy-hub/regulation/reg-eu-data-act): Smart contract requirements · Regulation (EU) 2023/2854
