# DFSA and ADGM FSRA

> DFSA and ADGM FSRA (Dubai Financial Services Authority · Abu Dhabi Global Market): The regulators that went after the tools, not just the assets. Region: Middle East & Africa. Attribution required: A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Regulator or standard-setter
- Region: Middle East & Africa
- Subject: The regulators that went after the tools, not just the assets
- Authority: Dubai Financial Services Authority · Abu Dhabi Global Market
- Stance on on-chain confidentiality: Attribution required. A regulated firm must be able to attribute activity to an identified person, and assets or accounts that make that impossible are barred at the licensed perimeter. This is a rule about attribution, not about whether amounts are public.
- Tags: privacy devices, mixers barred, firm-led screening, financial free zones
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/reg-uae-free-zones

## What it actually says

The two financial free zones inside the UAE regulate separately from Dubai's virtual assets authority, and they went a step further than it did. Where most instruments in this section reach assets, the DIFC rulebook reaches the tool: it bars the use of a privacy device, meaning mixers and tumblers, in or from the zone. Abu Dhabi's regulator put the prohibition on privacy tokens into its rules in June 2025 and separately refuses simplified customer due diligence for virtual assets on the ground that clients and transactions are pseudonymous. Anyone structuring in the UAE is dealing with three distinct perimeters, not one.

## The instruments that matter

- **DFSA GEN 3A, in force 12 January 2026**: prohibits regulated activity in privacy tokens and bars the use of a privacy device, meaning mixers and tumblers, in or from the DIFC
- **Firm-led token screening**: the DFSA abolished its list of recognised tokens, so firms must determine on a reasoned and documented basis whether each token meets the criteria
- **ADGM FSRA amendments, 10 June 2025**: enshrine in rules the prohibition on using privacy tokens within ADGM, alongside a streamlined acceptance process for other assets
- **No simplified due diligence**: the FSRA declines simplified customer due diligence for virtual asset activity, citing the pseudonymity of clients and transactions

## Sources

- [ADGM FSRA framework amendments](https://www.adgm.com/media/announcements/adgm-fsra-implements-amendments-to-its-digital-asset-regulatory-framework)

## Related entries

- [United Arab Emirates](https://www.sodalabs.xyz/privacy-hub/regulation/jur-uae): The most explicit prohibition anywhere in this section
- [MENAFATF](https://www.sodalabs.xyz/privacy-hub/regulation/reg-menafatf): The same machinery, across the Gulf and North Africa
- [VARA](https://www.sodalabs.xyz/privacy-hub/regulation/reg-vara): The most explicit prohibition in any rulebook
- [Bahrain](https://www.sodalabs.xyz/privacy-hub/regulation/jur-bahrain): A listing test written against effects, not asset names
- [Egypt](https://www.sodalabs.xyz/privacy-hub/regulation/jur-egypt): Crypto barred, so data protection is the live constraint
- [Kenya](https://www.sodalabs.xyz/privacy-hub/regulation/jur-kenya): The ban written into primary legislation, not a rulebook
