← Regulations / Bulgaria / Operating Models / CEX

Centralized exchange in Bulgaria

Order-book exchange that takes custody of user assets and matches trades between users.

Conditional AI-Generated · Unreviewed

CEX is conditionally permitted in Bulgaria with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • CDD required under MAMLA: identify and verify natural persons (name, date/place of birth, nationality, address, unique ID) and legal entities (name, legal form, registration number, registered address, authorized representatives) using reliable independent source documents
  • Beneficial owner identification: must identify natural persons ultimately owning/controlling ≥25%+1 share or voting rights, or exercising control via other means
  • Ongoing monitoring: regular scrutiny of transactions throughout the business relationship to ensure consistency with customer knowledge, business, and risk profile
  • PEP screening: identify customers who hold/have held prominent public functions, their family members, or close associates
  • High-risk third country enhanced due diligence for customers/beneficial owners from countries identified by EU or FATF as having strategic AML/CFT deficiencies
  • Suspicious Transaction Reports (STRs) to SANS (Financial Intelligence Directorate — Bulgaria's FIU)
  • Registration with the National Revenue Agency (NRA) for AML/CFT purposes
  • Record-keeping: retain customer documents, data, and transaction records for 5 years
  • Travel Rule compliance under EU Regulation 2023/1113 (TFR): collect and transmit originator name, crypto-asset account number, address/ID/DOB for natural persons or registration number for legal entities, and beneficiary name and crypto-asset account number for ALL transfers — no de minimis threshold for CASP-to-CASP transfers
  • Unhosted wallet transfers over €1,000: must verify ownership/control of the wallet; below €1,000 verification not mandated absent suspicion
  • Implement systems to detect missing/incomplete originator or beneficiary information for incoming/outgoing transfers
  • GDPR compliance for all data processing related to Travel Rule obligations

Key Restrictions

  • Must register with the National Revenue Agency (NRA) as a VASP/CASP under MAMLA and MiCA transposition
  • Must obtain authorization as a Crypto-Asset Service Provider (CASP) under the EU MiCA framework (fully applicable from 2026), which replaced the earlier MAMLA-based classification
  • Must comply with EU Regulation 2023/1113 (TFR) Travel Rule applicable from 30 December 2024 with no de minimis threshold for CASP-to-CASP transfers
  • Local entity (Bulgarian incorporation) is required to register with NRA and be supervised by SANS
  • All crypto-asset transfers involving self-hosted (unhosted) wallets are subject to MiCA rules as of 1 July 2025, with verification requirements above €1,000

Key Risks

  • Enforcement risk: administrative fines, cessation of non-compliant activities, potential criminal investigations for severe money laundering cases; fines up to BGN 1,000,000+ for legal entities
  • Regulatory transition risk: Bulgaria has moved from MAMLA-based VASP classification to MiCA CASP framework — operators may face dual-regime uncertainty during the transition period
  • EU sanctions directly applicable — failure to screen against EU sanctions lists carries serious legal consequences
  • Travel Rule compliance complexity for unhosted wallet transfers, especially verification of wallet ownership/control above €1,000 threshold
  • SANS and NRA have inspection and sanction powers — compliance gaps in CDD, STR, or registration can trigger administrative or criminal liability

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

aml 95% confidence

Measures Against Money Laundering Act (MAMLA) (Закон за мерките срещу изпирането на пари - ЗМИП).

aml 95% confidence

This act defines "virtual assets" and "virtual asset service providers" and brings them within the scope of obliged entities. It outlines the specific requirements for customer due diligence, reporting, and record-keeping.

aml 95% confidence

Exchange between virtual assets and fiat currencies.

aml 100% confidence

Exchange between one or more forms of virtual assets.

aml 90% confidence

Transfer of virtual assets.

aml 90% confidence

Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.

aml 78% confidence

Participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset are subject to AML/CFT regulation and are treated as financial activities for regulated virtual asset and stablecoin issuers.

aml 90% confidence

In Bulgaria, AML/CFT supervision of VASPs is shared among multiple authorities, with the National Revenue Agency (NRA) as the leading registration and enforcement body, the Financial Supervision Commission (FSC) overseeing crypto-asset service providers within its regulatory perimeter, and DANS-FID retaining a role but no longer the sole or primary supervisor.

aml 90% confidence

Role: This is Bulgaria's Financial Intelligence Unit (FIU). It is the primary recipient of Suspicious Transaction Reports (STRs) and other AML-related information from obliged entities. SANS is responsible for analyzing suspicious activities and disseminating intelligence to law enforcement.

aml 90% confidence

National Revenue Agency (NRA) (Национална агенция за приходите - НАП)

aml 80% confidence

Role: The NRA is responsible for the registration and general supervision of VASPs for AML/CFT purposes. VASPs in Bulgaria are typically required to register with the NRA and demonstrate compliance with AML obligations. The NRA may conduct inspections and impose administrative sanctions for non-compliance.

aml 90% confidence

Bulgarian law now mandates continuous identification and verification of beneficial owners, requiring ongoing monitoring and periodic updates beyond a static registration step.

aml 80% confidence

Natural Persons: Name, date and place of birth, nationality, permanent address, unique identification number (e.g., national ID card, passport number). Identity must be verified using reliable, independent source documents or data (e.g., valid official identification document).

aml 80% confidence

Legal Entities: Company name, legal form, registration number, registered address, and the names of the individuals authorized to represent the company. Verification involves obtaining extracts from commercial registers or similar official documents.

aml 90% confidence

Bulgarian law now mandates continuous identification and verification of beneficial owners, requiring ongoing monitoring and periodic updates beyond a static registration step.

aml 95% confidence

For legal entities, VASPs must identify the natural person(s) who ultimately own or control the customer, typically defined as holding 25% plus one share or more of the voting rights or exercising control via other means. This information must also be verified.

aml 88% confidence

Understanding the Purpose and Intended Nature of the Business Relationship:

aml 82% confidence

VASPs must gather information on why the customer wants to use their services, the expected transaction patterns, and the source of funds/wealth where relevant.

aml 83% confidence

Regular scrutiny of transactions undertaken throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.

aml 100% confidence

Keeping customer documents, data, and information up-to-date.

aml 95% confidence

Politically Exposed Persons (PEPs): Customers who hold or have held prominent public functions, their family members, or close associates.

aml 95% confidence

High-Risk Third Countries: Transactions involving customers or beneficial owners from countries identified by the EU or FATF as having strategic AML/CFT deficiencies.

aml 95% confidence

Complex, Unusual, Large Transactions, or Unusual Patterns: Transactions that have no apparent economic or lawful purpose.

travel-rule 95% confidence

Adopted: Yes, the principles of the FATF Travel Rule for crypto assets are adopted in Bulgaria through the Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, also known as the amended Transfer of Funds Regulation (TFR). This regulation is directly applicable in all EU member states, including Bulgaria, without the need for national transposition.

travel-rule 84% confidence

The EU Transfer of Funds Regulation as amended by Regulation (EU) 2023/1113 extends the Travel Rule to crypto‑asset transfers, and these requirements have applied in the EU (including Bulgaria) since 30 December 2024.

travel-rule 86% confidence

For crypto-asset transfers between EU Crypto-Asset Service Providers (CASPs) under Regulation (EU) 2023/1113, there is no de minimis threshold: all such transfers, regardless of amount, must include complete originator and beneficiary information. However, the EU framework now distinguishes these CASP‑to‑CASP transfers from transactions involving self‑hosted wallets, for which additional rules apply above €1,000, so any description of the regime should situate the zero‑threshold rule within this broader, MiCA‑aligned CASP/Transfer of Funds Regulation context rather than as a generic VASP rule.

travel-rule 90% confidence

As of July 1, Bulgaria applies MiCA’s strict rules to all crypto transfers, including those involving self-hosted wallets, ending any prior unregulated status.

travel-rule 80% confidence

CASPs must collect originator and beneficiary information for all transfers.

travel-rule 100% confidence

For transfers exceeding €1,000, the CASP must verify that the unhosted wallet is owned or controlled by the originator or beneficiary.

travel-rule 95% confidence

Verification is now mandatory for all unhosted wallets in Bulgaria, regardless of transaction value below €1,000.

travel-rule 90% confidence

Collect and transmit information: Ensure that crypto-asset transfers are accompanied by the following information:

travel-rule 90% confidence

Originator: Name, crypto-asset account number, address (or national ID number/customer ID number), date and place of birth (for natural persons), legal entity registration number (for legal entities).

travel-rule 95% confidence

Beneficiary: Name, crypto-asset account number.

travel-rule 95% confidence

Verify information: Take reasonable steps to verify the accuracy of the information, especially for transfers to/from unhosted wallets above the €1,000 threshold.

travel-rule 90% confidence

Retain records: Keep records of the collected information for a period of five years.

travel-rule 90% confidence

Detect missing information: Implement systems to detect if the required originator or beneficiary information is missing or incomplete for incoming or outgoing transfers.

travel-rule 100% confidence

Data Protection: All data processing must comply with the GDPR (General Data Protection Regulation).

enforcement 98% confidence

Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc. Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.

enforcement 70% confidence

Legal Basis: EU sanctions are typically imposed through Council Decisions and implemented via Council Regulations. These Regulations are directly applicable in all EU Member States without the need for national transposition.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a centralized exchange (order-book with custody) is permissible in Bulgaria but requires registration with the National Revenue Agency as a VASP/CASP under MAMLA, authorization under the EU MiCA framework, a local entity, and full compliance with AML/CFT obligations including CDD, ongoing monitoring, STRs to SANS, and EU Travel Rule (no de minimis threshold for CASP-to-CASP transfers, with verification rules for unhosted wallets above €1,000).

Questions this verdict aims to answer

  • What exchange / VASP license applies?
  • What custody segregation rules apply to user assets?
  • What market-conduct and listing rules apply?
  • What travel-rule obligations apply on withdrawals?