ISO and IEC standards
The standards bodies that specify privacy instead of policing it
The regime itself mandates, pilots or funds privacy-preserving technology.
What ISO and IEC standards actually says
Set this against the financial standard-setters and the contrast is sharp. In February 2026 ISO and IEC published guidelines on privacy preservation based on zero-knowledge proofs, meaning there is now an international standard for deploying the primitive that the anti-money-laundering bodies do not mention at all. FATF's July 2026 report on information sharing identifies data protection law as the main obstacle to cooperation and names no privacy-enhancing technology anywhere. ISO's blockchain committee has treated privacy as an engineering problem since 2020, when its technical report on personally identifiable information in distributed ledgers addressed immutability against erasure directly. None of this binds anyone unless a regulator or contract adopts it, which so far none has.
The instruments that matter
- ISO/IEC 27565:2026, 10 February 2026
- guidelines on privacy preservation based on zero-knowledge proofs, a published international standard for deploying the primitive itself
- ISO/TR 23244:2020
- privacy and personally identifiable information protection considerations for blockchain and DLT, covering immutability against erasure and on-chain versus off-chain placement
- ISO 22739:2024
- second edition of the blockchain vocabulary, superseding the 2020 edition
- ISO/IEC 20889:2018
- privacy-enhancing data de-identification terminology and classification of techniques
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- NISTGlobal · The vocabulary that makes privacy claims testable
- BIS Innovation HubGlobal · Central bank prototypes that build privacy on purpose
- Convention 108+Global · The only binding international data protection treaty
- eIDAS 2 and the EU Digital Identity WalletEurope · Digital identity · Regulation (EU) 2024/1183
- US Treasury and the Working GroupAmericas · The first federal endorsement of privacy technology
- Basel Committee, SCO60Global · Bank capital · the sharpest traceability rule anywhere
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.