# IOSCO

> IOSCO (International Organization of Securities Commissions): Securities regulation · the one body that calls transparency a risk. Region: Global. Privacy with disclosure: Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Regulator or standard-setter
- Region: Global
- Subject: Securities regulation · the one body that calls transparency a risk
- Authority: International Organization of Securities Commissions
- Stance on on-chain confidentiality: Privacy with disclosure. Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.
- Tags: securities, tokenisation, pseudonymity, GDPR conflict
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/reg-iosco

## What it actually says

IOSCO pulls in both directions, which makes it more interesting than most. Its DeFi work treats pseudonymity as an obstacle, citing participants who use multiple addresses to obfuscate activity, and answers by identifying responsible persons. But its November 2025 tokenisation report is the only text from a financial standard-setter that names over-transparency as a risk in its own right. It records an inherent conundrum between data privacy and transparency, warns that ledger immutability could cause unintended user confidentiality breaches and collide with requirements such as the GDPR right to be forgotten, and notes that visible transaction flows can worsen a redemption run. That is a securities regulator arguing that too much publicity is a market-integrity problem, not just a privacy one.

## The instruments that matter

- **Policy Recommendations for Crypto and Digital Asset Markets, FR11/2023**: 18 recommendations on conflicts, custody, market abuse, disclosure and cross-border cooperation, followed by nine DeFi recommendations in December 2023
- **Tokenization of Financial Assets, FR/17/25, November 2025**: records an inherent conundrum between data privacy and transparency, and cites GDPR erasure conflicts directly
- **Thematic review FR/13/25, 16 October 2025**: assessed 20 jurisdictions; information sharing under the MMoU and EMMoU is largely limited to enforcement

## Sources

- [Policy recommendations for crypto and digital asset markets](https://www.iosco.org/library/pubdocs/pdf/IOSCOPD747.pdf)
- [Tokenization of financial assets, FR/17/25](https://www.iosco.org/library/pubdocs/pdf/IOSCOPD813.pdf)

## Related entries

- [Financial Stability Board](https://www.sodalabs.xyz/privacy-hub/regulation/reg-fsb): Financial stability · and explicitly not the privacy body
- [Basel Committee, SCO60](https://www.sodalabs.xyz/privacy-hub/regulation/reg-basel-sco60): Bank capital · the sharpest traceability rule anywhere
- [BIS Innovation Hub](https://www.sodalabs.xyz/privacy-hub/regulation/reg-bis-innovation-hub): Central bank prototypes that build privacy on purpose
- [Convention 108+](https://www.sodalabs.xyz/privacy-hub/regulation/reg-convention-108): The only binding international data protection treaty
- [Egmont Group](https://www.sodalabs.xyz/privacy-hub/regulation/reg-egmont): How financial intelligence crosses borders
- [FATF](https://www.sodalabs.xyz/privacy-hub/regulation/reg-fatf): The source of almost every travel rule on earth
