Financial Privacy Rules for Crypto: The Gap the GENIUS Act Left Open

Federal crypto policy now surveils issuers and exempts DeFi — with no privacy rule in between
A CoinDesk opinion piece published March 31, 2026 argues that despite a year of real regulatory progress, financial privacy remains the unaddressed frontier in digital asset policy. The author, writing as Yelderman, makes the case in the article that the agencies have coordinated on nearly everything except the question of who gets to see your transaction data.
Here is the part the coverage is missing. The two headline reforms of the past year pull in opposite directions on privacy. The GENIUS Act, signed July 18, 2025 as P.L. 119-27, explicitly subjects stablecoin issuers to the Bank Secrecy Act and directs Treasury to identify surveillance methods for detecting illicit activity. Weeks earlier, Congress had repealed the IRS DeFi Broker Rule under H.J. Res. 25, signed April 10, 2025 as P.L. 119-5, exempting decentralized platforms from Form 1099-DA reporting entirely.
So federal policy is expanding surveillance for regulated issuers while retreating from it for decentralized protocols. That is not a privacy framework. It is a regulatory coin flip that depends entirely on how your product is architected.
The agencies coordinated on classification. They skipped privacy.
The past twelve months produced the clearest crypto market-structure signals in the industry's history. Two of them matter here.
- The SEC–CFTC Memorandum of Understanding. On March 11, 2026, Chairman Paul S. Atkins and CFTC Chairman Michael S. Selig signed an MOU to coordinate on crypto asset regulation, superseding the 2018 version.
- The joint interpretive release. On March 17, 2026, the agencies issued Release No. 33-11412, 91 Fed. Reg. 13714, establishing a five-part taxonomy: digital commodities, digital collectibles, digital tools, stablecoins, and digital securities.
That taxonomy tells a founder which agency governs a token and which disclosure regime attaches. It does not tell anyone what data an issuer must collect, retain, hand over, or protect. Classification answers jurisdiction. It does not answer surveillance.
Why the gap is a market-structure problem, not a privacy footnote
When the rule that governs data collection depends on whether a product is centralized or decentralized, the rulebook itself becomes a design incentive. A stablecoin issuer inherits the full weight of the Bank Secrecy Act. A comparable DeFi protocol, after the H.J. Res. 25 repeal, inherits far less. Capital and engineering talent respond to that asymmetry. The privacy gap is quietly steering how products get built.
The SEC has been signaling this gap for months
This is not a surprise the agencies stumbled into. The SEC's Crypto Task Force, launched January 21, 2025, hosted its sixth public roundtable on Financial Surveillance and Privacy on December 15, 2025, with opening remarks from Chairman Atkins and Commissioner Hester Peirce, per the SEC's own announcement.
The distinction that matters here is between data classification and data governance. The March interpretive release told the market what a token is. The December roundtable was about what happens to the information generated when someone uses it. Those are different questions, and only the first one has been answered.
For an operator, the practical reading is straightforward. The agencies know the privacy question is unresolved. They convened a public forum on it and then shipped classification guidance without it. That sequencing tells you privacy rules are coming, but not soon, and not through the same vehicle. Building today means building against a standard that does not yet exist.
What your leadership team should decide this quarter
The absence of a federal privacy rule does not mean the absence of obligations. It means your obligations depend on your architecture, and you should map that dependency now rather than after examiners do it for you.
Concrete steps
- Classify your own product against the five-part taxonomy first. Determine whether you are issuing a stablecoin, a digital security, a digital commodity, a digital tool, or a collectible under Release No. 33-11412. Your data obligations flow from that answer.
- If you touch stablecoin issuance, treat the Bank Secrecy Act as live today. The GENIUS Act subjected issuers to the BSA on enactment. Do not wait for implementing rules to build your AML and data-retention program.
- If you run a DeFi protocol, do not read the H.J. Res. 25 repeal as permanent relief. The repeal removed one reporting rule. It did not create a privacy right, and future rulemaking or the CLARITY Act could reintroduce obligations.
- Inventory what user data you collect and where it lives. A future federal privacy standard will ask this question. Firms that already have the answer will absorb the rule cheaply.
The board-level question is not whether privacy rules are coming. It is whether your product architecture can survive a rule you cannot yet read. For firms building stablecoin or tokenized products, digital assets counsel can map your current data footprint against both the BSA obligations that already bind issuers and the privacy framework the SEC has signaled is next.
Key takeaways
- Federal crypto policy surveils issuers and exempts DeFi with no rule in between. The GENIUS Act subjected stablecoin issuers to the Bank Secrecy Act while H.J. Res. 25 exempted DeFi platforms from Form 1099-DA reporting.
- Classification is settled; data governance is not. Release No. 33-11412 established a five-part taxonomy on March 17, 2026, but said nothing about what data issuers must collect, retain, or protect.
- The SEC telegraphed the gap. Its Crypto Task Force held a Financial Surveillance and Privacy roundtable on December 15, 2025, then shipped classification guidance without a privacy standard attached.
- Your obligations depend on your architecture. Whether a product is a regulated stablecoin or a decentralized protocol now determines its surveillance burden — making design choices a compliance decision.
- Stablecoin issuers should treat BSA duties as live today. The GENIUS Act imposed those obligations on enactment, July 18, 2025; waiting for implementing rules is not a defensible position.
The rulebook rewards good architecture — build for the rule you cannot read yet
The clearest signal from the past year is that classification came first and privacy will come later, which leaves every digital asset builder designing against a standard that does not exist. That is a solvable problem, but only for firms that map their data obligations to their product architecture before the rule lands.
Firms issuing stablecoins or tokenized products generally need their Bank Secrecy Act program and data-retention practices reviewed against the GENIUS Act framework now, and their architecture stress-tested against the privacy standard the SEC has signaled is next. FinTech Law does that work. If you are building in this space and want your data footprint mapped against both current obligations and the coming privacy rule, contact FinTech Law.
FinTech Law's data privacy counsel team advises on the requirements described above.
This blog post is for informational purposes only and does not constitute legal advice. No attorney-client relationship is formed by reading this content. If you need legal advice, please contact a qualified attorney.