# Anonymity is not the same thing as confidentiality

> Anonymity is not the same thing as confidentiality: Why two privacy designs get treated differently. Region: Global.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Where privacy tech meets the rulebook
- Region: Global
- Subject: Why two privacy designs get treated differently
- Tags: anonymity vs confidentiality, Article 79, our reading, undefined terms
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/why-programmable-confidentiality

## What it actually says

Regulators keep drawing a line that the debate tends to flatten. What the instruments actually turn on is who holds the disclosure lever, not how strong the cryptography is. A protocol with mandatory, protocol-level anonymity leaves a regulated intermediary with no compliant posture at all, because it cannot produce records it has no mechanism to obtain. A design with encrypted state and a disclosure path leaves that intermediary roughly where it sits in conventional finance: data confidential from the public, available to the authorised party. Two caveats we would rather state ourselves. This is our reading of the drafting, not a position any regulator has published. And issuer-retained control is a real centralisation risk, not a free win. The EU's key phrase, increased obfuscation of transactions, is undefined, and AMLA guidance will decide how far it reaches.

## The instruments that matter

- **AMLR Article 79 turns on the account**: it prohibits obliged entities from keeping accounts allowing anonymisation of the holder, or anonymisation or increased obfuscation of transactions
- **The lever, not the cryptography**: protocol-level mandatory anonymity leaves an intermediary with no compliant posture; optional shielding with disclosure keys leaves a workable one
- **This cuts both ways**: issuer-retained disclosure control is itself a centralisation and abuse surface, and encrypted personal data is still personal data

## Sources

- [Regulation (EU) 2024/1624, Article 79](https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng)

## Related entries

- [Central banks are building confidentiality themselves](https://www.sodalabs.xyz/privacy-hub/regulation/why-central-banks-build-privacy): What the people writing the rules do when they design money
- [Erasure against an append-only ledger](https://www.sodalabs.xyz/privacy-hub/regulation/why-erasure): The one collision with no clean answer yet
- [Proving where funds did not come from](https://www.sodalabs.xyz/privacy-hub/regulation/why-privacy-pools): Association sets, and the Tornado Cash aftermath
- [Sanctions screening on a confidential ledger](https://www.sodalabs.xyz/privacy-hub/regulation/why-sanctions-screening): The genuinely open problem
- [Selective disclosure as a compliance primitive](https://www.sodalabs.xyz/privacy-hub/regulation/why-viewing-keys): Bilateral disclosure versus publishing to everyone
- [The travel rule binds institutions, not ledgers](https://www.sodalabs.xyz/privacy-hub/regulation/why-travel-rule): The rule everyone assumes ends on-chain confidentiality
