DeFi protocol frontend in Albania
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Albania with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Law No. 119/2019 applies: CDD on all customers (natural persons: identity documents; legal entities: name, legal form, address, proof of incorporation, beneficial ownership).
- Beneficial ownership identification required for all legal-entity customers.
- Purpose-and-nature-of-business-relationship information required.
- Ongoing transaction monitoring throughout the business relationship.
- Risk-based approach: simplified (SDD) for low-risk, enhanced (EDD) for high-risk (PEPs, high-value transactions).
- Suspicious transaction reporting (STR) to the General Directorate for the Prevention of Money Laundering (GDPML) — no minimum monetary threshold; any suspicion must be reported without delay.
- Tipping-off prohibition on disclosing STRs to customers or third parties.
- Record-keeping: at least 5 years after end of business relationship or occasional transaction.
- Internal AML/CFT policies, procedures, and institutional risk assessment required.
- Designated AML/CFT compliance officer at management level required.
- Ongoing staff training programs on AML/CFT obligations required.
Key Restrictions
- Must obtain prior authorization from the FSA (Article 12, Law No. 110/2020) — applicable to any entity offering DLT services, which likely covers DeFi frontends that facilitate virtual asset exchange, transfer, or custody.
- Must be established as a legal entity in Albania.
- Must meet minimum capital requirements set by FSA secondary legislation (Article 13, Law No. 110/2020).
- Must meet governance, fit-and-proper management, and internal control requirements (Article 15).
- Must implement client asset protection measures including segregation, identification, reconciliation (Article 21) — relevant if the frontend handles user assets.
- AML/CDD obligations under Law No. 119/2019 would likely require user screening and geofencing/restriction of unverified users.
- Fee-taking (e.g., swap fees, routing fees) likely triggers classification as a regulated DLT service (exchange between virtual assets), requiring full licensing.
Key Risks
- Regulatory ambiguity: Law No. 110/2020 was designed for centralized DLT service providers and may not cleanly map to permissionless DeFi frontends — no clear safe harbor for 'mere interface' operators.
- Enforcement risk: Albania cooperated in the Thodex extradition (fraud/money laundering), indicating willingness to pursue crypto-related financial crime enforcement.
- If the frontend does not take fees or custody, it may still be captured as 'participation in and provision of financial services related to an issuer's offer/sale of a virtual asset' under the AML law.
- The FSA has broad discretion in secondary legislation — capital requirements and operational rules could be onerous and unpredictable.
- Low regulatory guidance: minimal enforcement precedent or published guidance specific to DeFi frontends in Albania.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law No. 110/2020 "On Financial Markets Based on Distributed Ledger Technology": This is the foundational legal act regulating DLT-based financial markets and virtual assets in Albania. It defines virtual assets, DLT service providers, and sets out licensing and operational requirements.
Authorization from FSA: Any entity intending to offer DLT services, including custody of virtual assets, must obtain prior authorization from the FSA (Article 12).
Legal Form and Capital: Applicants must be established as legal entities in Albania and meet minimum capital requirements, which are determined by secondary legislation issued by the FSA.
Governance and Management: Requirements for sound and prudent management, including "fit and proper" criteria for directors and significant shareholders, robust internal control mechanisms, risk management procedures, and administrative arrangements.
AML/CFT Compliance: Strict adherence to anti-money laundering and combating the financing of terrorism (AML/CFT) regulations, including customer due diligence (CDD), suspicious transaction reporting, and internal AML policies. These are primarily governed by Law No. 111/2019 "On Preventing Money Laundering and Terrorism Financing."
Article 21 (Client Asset Protection): DLT service providers, including custodians, are required to implement measures to protect the virtual assets and funds of their clients. This includes:
Minimum Capital Requirements: DLT service providers must meet minimum initial capital requirements, as determined by the FSA through secondary acts. This capital acts as a buffer against operational risks and potential liabilities.
Regulatory Reference: Articles 12-16 of Law No. 110/2020 and subsequent secondary legislation/regulations issued by the FSA.
Regulatory Reference: Article 13 of Law No. 110/2020 (regarding capital requirements) and Article 15 (regarding internal governance and risk management).
Security Requirements (Article 15): DLT service providers must establish robust internal control mechanisms, including comprehensive IT security measures, to ensure the integrity, confidentiality, and availability of data and assets. This would naturally lead to the adoption of industry best practices for securing private keys, which typically include a significant portion of assets being held in offline (cold) storage.
Law No. 119/2019 "On Preventing Money Laundering and Terrorism Financing" (Ligji Nr. 119/2019 "Për parandalimin e pastrimit të parave dhe financimit të terrorizmit").
Participation in and provision of financial services related to an issuer's offer and/or sale of a virtual asset.
Natural Persons: Identifying and verifying the identity of the customer and any beneficial owner using reliable, independent source documents, data, or information (e.g., identity cards, passports, official residence documents).
Legal Entities: Identifying and verifying the identity of the customer, including its name, legal form, address, proof of incorporation, and powers that regulate and bind the legal person. This also extends to identifying and verifying the identity of the natural persons who hold senior management positions and the beneficial owners.
Beneficial Ownership: Identifying the beneficial owner(s) of the customer and taking reasonable measures to verify their identity, including understanding the ownership and control structure of the customer.
Purpose and Nature of the Business Relationship: Obtaining information on the purpose and intended nature of the business relationship.
Ongoing Monitoring: Conducting ongoing monitoring of the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Risk-Based Approach: Applying CDD measures on a risk-sensitive basis. This means applying simplified CDD (SDD) measures where the risks are lower and enhanced CDD (EDD) measures where the risks are higher (e.g., transactions involving politically exposed persons (PEPs), high-value transactions, or relationships with customers from high-risk jurisdictions).
Reporting Obligation: If a VASP knows, suspects, or has reasonable grounds to suspect that funds are the proceeds of criminal activity, or are related to terrorism financing, it must promptly (without delay) report this to the General Directorate for the Prevention of Money Laundering (GDPML).
No Threshold: There is no minimum monetary threshold for reporting suspicious transactions; any amount can be suspicious.
"Tipping Off": VASPs and their employees are prohibited from "tipping off" the customer or third parties about the fact that a suspicious transaction report has been made or that an investigation is underway.
Period: Records relating to CDD, business relationships, and transactions must be kept for at least five years after the end of the business relationship or after the date of an occasional transaction.
Internal Policies and Procedures: Establish and maintain internal policies, controls, and procedures for AML/CFT compliance, proportionate to their nature and size.
AML Officer: Appoint a designated AML/CFT compliance officer at management level.
Staff Training: Implement ongoing training programs for relevant staff members to ensure they are aware of their AML/CFT obligations, the risks faced by the VASP, and how to identify and report suspicious activities.
Entity Targeted: Faruk Fatih Özer, founder and CEO of the Turkish cryptocurrency exchange Thodex. Violation Type: International fraud, money laundering (related to the collapse of the Thodex exchange, which defrauded hundreds of thousands of users of an estimated $2 billion). The Albanian action related to his illegal entry and residence, and the execution of the international arrest warrant. Penalty Amount (Albania): No specific "penalty amount" was imposed by Albanian authorities on Özer directly for the crypto fraud. The outcome in Albania was his arrest and successful extradition. Outcome: Faruk Fatih Özer was arrested in Vlora, Albania, following an international manhunt. After a period of legal appeals, he was extradited to Turkey, where he faced trial. In Turkey, he was subsequently sentenced to 11,196 years in prison in September 2023 for aggravated fraud, leading a criminal organization, and money laundering.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi frontend serving Albanian residents would likely be treated as a regulated DLT service provider under Law No. 110/2020, requiring full FSA authorization, local incorporation, minimum capital, and comprehensive AML/CFT obligations under Law No. 119/2019, though there is significant regulatory ambiguity on whether a non-custodial, non-fee-taking interface could avoid licensing.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?