Crypto-funded debit card in Albania
A card program where customer fiat balances are funded from crypto holdings, typically through an off-ramp at point of sale or top-up.
Crypto debit card is conditionally permitted in Albania with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD on natural persons: identify and verify using reliable source documents (ID cards, passports, official residence documents) — Law No. 119/2019
- CDD on legal entities: identify name, legal form, address, proof of incorporation, senior management and beneficial owners — Law No. 119/2019
- Beneficial ownership identification: identify and verify beneficial owners, including ownership and control structure — Law No. 119/2019
- Purpose and nature of business relationship: obtain information on intended purpose — Law No. 119/2019
- Ongoing monitoring: scrutinise transactions throughout the relationship to ensure consistency with customer risk profile — Law No. 119/2019
- Risk-based approach: apply simplified or enhanced CDD based on risk (e.g. PEPs, high-value transactions) — Law No. 119/2019
- Suspicious transaction reporting: report promptly (no minimum threshold) to the General Directorate for the Prevention of Money Laundering (GDPML) — Law No. 119/2019
- Record-keeping: maintain CDD and transaction records for at least 5 years after end of relationship — Law No. 119/2019
- Internal policies: maintain AML/CFT policies, controls and procedures proportionate to size — Law No. 119/2019
- AML officer: appoint a designated compliance officer at management level — Law No. 119/2019
- Staff training: implement ongoing AML/CFT training programs — Law No. 119/2019
- Risk assessment: conduct institutional ML/TF risk assessments — Law No. 119/2019
- No tipping off: prohibition on informing customers about STRs or investigations — Law No. 119/2019
Key Restrictions
- Must obtain prior authorization (license) from the Financial Supervisory Authority (AMF) under Law No. 110/2020 — Articles 12-16
- Must be established as a legal entity in Albania (local incorporation required)
- Must meet minimum capital requirements set by the FSA via secondary legislation — Article 13
- Must implement client asset protection measures including segregation of client virtual assets/funds from proprietary assets — Article 21
- Crypto-to-fiat conversion (off-ramp) is a regulated DLT service requiring AMF authorization under Law No. 110/2020
- If the stablecoin component meets the definition of e-money under Law No. 9918/2008, additional e-money regulation and Bank of Albania oversight may apply
- No specific debit-card / e-money licence framework identified under Albanian law — card issuance likely relies on a foreign BIN sponsor or partner bank
- Fit-and-proper requirements for directors and significant shareholders must be satisfied
Key Risks
- Law No. 110/2020 has reportedly resulted in zero licensed companies in practice, creating substantial regulatory ambiguity and practical unlicensability
- No licensed precedent for a crypto-funded debit card exists in Albania — regulatory interpretation is untested
- Stablecoin classification gap: Law No. 110/2020 does not differentiate stablecoins by backing; potential dual regulation under e-money law (Bank of Albania) and DLT law (AMF) creates jurisdictional risk
- No specific payment-services or e-money framework for card issuance means reliance on foreign BIN sponsors, which may raise supervisory questions
- Enforcement precedent is thin — only known case relates to international fraud/money laundering (Thodex case), not local crypto debit cards
- Tax obligations: 15% capital gains tax on crypto-to-fiat disposals and 20% VAT on service fees must be operationalised — unclear reporting infrastructure
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law No. 110/2020 "On Financial Markets Based on Distributed Ledger Technology": This is the foundational legal act regulating DLT-based financial markets and virtual assets in Albania. It defines virtual assets, DLT service providers, and sets out licensing and operational requirements.
Authorization from FSA: Any entity intending to offer DLT services, including custody of virtual assets, must obtain prior authorization from the FSA (Article 12).
Legal Form and Capital: Applicants must be established as legal entities in Albania and meet minimum capital requirements, which are determined by secondary legislation issued by the FSA.
Minimum Capital Requirements: DLT service providers must meet minimum initial capital requirements, as determined by the FSA through secondary acts. This capital acts as a buffer against operational risks and potential liabilities.
Governance and Management: Requirements for sound and prudent management, including "fit and proper" criteria for directors and significant shareholders, robust internal control mechanisms, risk management procedures, and administrative arrangements.
Operational Capacity: Adequate technical and human resources to perform the intended services securely and efficiently. This implicitly covers aspects like cybersecurity, data protection, and operational resilience.
Article 21 (Client Asset Protection): DLT service providers, including custodians, are required to implement measures to protect the virtual assets and funds of their clients. This includes:
Segregation: Maintaining separate accounts for client virtual assets and funds from their own proprietary assets. This is a fundamental principle to ensure that client assets are not subject to claims from the DLT service provider's creditors in case of insolvency.
Regulatory Reference: Articles 12-16 of Law No. 110/2020 and subsequent secondary legislation/regulations issued by the FSA.
Regulatory Reference: Article 13 of Law No. 110/2020 (regarding capital requirements) and Article 15 (regarding internal governance and risk management).
Law No. 119/2019 "On Preventing Money Laundering and Terrorism Financing" (Ligji Nr. 119/2019 "Për parandalimin e pastrimit të parave dhe financimit të terrorizmit").
Natural Persons: Identifying and verifying the identity of the customer and any beneficial owner using reliable, independent source documents, data, or information (e.g., identity cards, passports, official residence documents).
Legal Entities: Identifying and verifying the identity of the customer, including its name, legal form, address, proof of incorporation, and powers that regulate and bind the legal person. This also extends to identifying and verifying the identity of the natural persons who hold senior management positions and the beneficial owners.
Beneficial Ownership: Identifying the beneficial owner(s) of the customer and taking reasonable measures to verify their identity, including understanding the ownership and control structure of the customer.
Purpose and Nature of the Business Relationship: Obtaining information on the purpose and intended nature of the business relationship.
Ongoing Monitoring: Conducting ongoing monitoring of the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Risk-Based Approach: Applying CDD measures on a risk-sensitive basis. This means applying simplified CDD (SDD) measures where the risks are lower and enhanced CDD (EDD) measures where the risks are higher (e.g., transactions involving politically exposed persons (PEPs), high-value transactions, or relationships with customers from high-risk jurisdictions).
Reporting Obligation: If a VASP knows, suspects, or has reasonable grounds to suspect that funds are the proceeds of criminal activity, or are related to terrorism financing, it must promptly (without delay) report this to the General Directorate for the Prevention of Money Laundering (GDPML).
No Threshold: There is no minimum monetary threshold for reporting suspicious transactions; any amount can be suspicious.
"Tipping Off": VASPs and their employees are prohibited from "tipping off" the customer or third parties about the fact that a suspicious transaction report has been made or that an investigation is underway.
Period: Records relating to CDD, business relationships, and transactions must be kept for at least five years after the end of the business relationship or after the date of an occasional transaction.
Internal Policies and Procedures: Establish and maintain internal policies, controls, and procedures for AML/CFT compliance, proportionate to their nature and size.
AML Officer: Appoint a designated AML/CFT compliance officer at management level.
Staff Training: Implement ongoing training programs for relevant staff members to ensure they are aware of their AML/CFT obligations, the risks faced by the VASP, and how to identify and report suspicious activities.
Risk Assessment: Conduct institutional risk assessments to identify, assess, and understand the money laundering and terrorism financing risks to which they are exposed.
Law No. 110/2020 defines "virtual assets" broadly as a digital representation of value that can be digitally traded or transferred and used for payment or investment purposes. It does not explicitly differentiate between stablecoins and other virtual assets based on their backing mechanism.
E-money: If a stablecoin meets the definition of e-money under Law No. 9918/2008 (i.e., electronically stored monetary value, representing a claim on the issuer, issued on receipt of funds for the purpose of making payment transactions), it would be subject to that regulation. The Bank of Albania would supervise this.
Stablecoins are classified into distinct regulatory categories across major jurisdictions: EU's MiCA regulates 'e-money tokens' (pegged to single fiat) and 'asset-referenced tokens'; US SEC guidance states 'Covered Stablecoins' (USD-pegged, fully reserved) are not securities; UK regulates 'payment stablecoins' and 'fiat-backed stablecoins'. Classification depends on structure, peg, reserves, and marketing.
Law No. 110/2020 does not specifically differentiate between collateralized and algorithmic stablecoins, but the overall Albanian regulatory framework (including Law No. 66/2020) now differentiates them.
Tax Rate (Individuals): For individuals, capital gains from the sale of shares, financial instruments, and other assets are subject to a 15% flat rate under the Law on Income Tax. It is widely understood that gains from virtual assets would fall under this category.
Tax Rate (Businesses): If a business deals with virtual assets, any gains from their disposal would be included in the company's taxable profit and subject to the Corporate Income Tax rate of 15% (or 0% for small businesses meeting specific criteria).
Fees charged by virtual asset service providers (e.g., exchanges, wallet providers) for services like trading fees, platform usage, custodial services, or brokerage services are generally considered subject to standard VAT rates (currently 20%).
Exchange of Crypto for Fiat or Other Crypto: The direct exchange of traditional currency for virtual currency and vice-versa, or virtual currency for virtual currency, is generally considered a supply of financial services and is likely exempt from VAT. This aligns with the European Court of Justice ruling in Skatteverket v David Hedqvist (C‑264/14), which found that Bitcoin exchanges are exempt from VAT under the "transactions concerning currency, bank notes and coins used as legal tender" provision.
Entity Targeted: Faruk Fatih Özer, founder and CEO of the Turkish cryptocurrency exchange Thodex. Violation Type: International fraud, money laundering (related to the collapse of the Thodex exchange, which defrauded hundreds of thousands of users of an estimated $2 billion). The Albanian action related to his illegal entry and residence, and the execution of the international arrest warrant. Penalty Amount (Albania): No specific "penalty amount" was imposed by Albanian authorities on Özer directly for the crypto fraud. The outcome in Albania was his arrest and successful extradition. Outcome: Faruk Fatih Özer was arrested in Vlora, Albania, following an international manhunt. After a period of legal appeals, he was extradited to Turkey, where he faced trial. In Turkey, he was subsequently sentenced to 11,196 years in prison in September 2023 for aggravated fraud, leading a criminal organization, and money laundering.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a crypto-funded debit card operation is theoretically permissible under Albania's DLT framework (Law No. 110/2020) via an AMF license, but the framework has resulted in zero licensed entities in practice, the card-issuance/e-money licence pathway is unclear, and the operator would need a local entity, AMF authorization, full AML/CFT compliance under Law No. 119/2019, and likely a foreign BIN sponsor for card issuance, all in a highly ambiguous regulatory environment.
Questions this verdict aims to answer
- What e-money / payment-institution license is required?
- How is the crypto-to-fiat conversion regulated?
- What KYC and AML obligations apply to cardholders?
- What partner-bank or BIN-sponsor arrangements are required?