Soda Labs

DFSA and ADGM FSRA

The regulators that went after the tools, not just the assets

Regulator or standard-setterMiddle East & AfricaAttribution required

A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.

What DFSA and ADGM FSRA actually says

The two financial free zones inside the UAE regulate separately from Dubai's virtual assets authority, and they went a step further than it did. Where most instruments in this section reach assets, the DIFC rulebook reaches the tool: it bars the use of a privacy device, meaning mixers and tumblers, in or from the zone. Abu Dhabi's regulator put the prohibition on privacy tokens into its rules in June 2025 and separately refuses simplified customer due diligence for virtual assets on the ground that clients and transactions are pseudonymous. Anyone structuring in the UAE is dealing with three distinct perimeters, not one.

The instruments that matter

DFSA GEN 3A, in force 12 January 2026
prohibits regulated activity in privacy tokens and bars the use of a privacy device, meaning mixers and tumblers, in or from the DIFC
Firm-led token screening
the DFSA abolished its list of recognised tokens, so firms must determine on a reasoned and documented basis whether each token meets the criteria
ADGM FSRA amendments, 10 June 2025
enshrine in rules the prohibition on using privacy tokens within ADGM, alongside a streamlined acceptance process for other assets
No simplified due diligence
the FSRA declines simplified customer due diligence for virtual asset activity, citing the pseudonymity of clients and transactions

What this means for confidential transactions

Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.

Compliant by default.

See how selective disclosure satisfies a supervisor without publishing your book to the world.