Centralized exchange in Bulgaria
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Bulgaria with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD required under MAMLA: identify and verify natural persons (name, date/place of birth, nationality, address, unique ID) and legal entities (name, legal form, registration number, registered address, authorized representatives) using reliable independent source documents
- Beneficial owner identification: must identify natural persons ultimately owning/controlling ≥25%+1 share or voting rights, or exercising control via other means
- Ongoing monitoring: regular scrutiny of transactions throughout the business relationship to ensure consistency with customer knowledge, business, and risk profile
- PEP screening: identify customers who hold/have held prominent public functions, their family members, or close associates
- High-risk third country enhanced due diligence for customers/beneficial owners from countries identified by EU or FATF as having strategic AML/CFT deficiencies
- Suspicious Transaction Reports (STRs) to SANS (Financial Intelligence Directorate — Bulgaria's FIU)
- Registration with the National Revenue Agency (NRA) for AML/CFT purposes
- Record-keeping: retain customer documents, data, and transaction records for 5 years
- Travel Rule compliance under EU Regulation 2023/1113 (TFR): collect and transmit originator name, crypto-asset account number, address/ID/DOB for natural persons or registration number for legal entities, and beneficiary name and crypto-asset account number for ALL transfers — no de minimis threshold for CASP-to-CASP transfers
- Unhosted wallet transfers over €1,000: must verify ownership/control of the wallet; below €1,000 verification not mandated absent suspicion
- Implement systems to detect missing/incomplete originator or beneficiary information for incoming/outgoing transfers
- GDPR compliance for all data processing related to Travel Rule obligations
Key Restrictions
- Must register with the National Revenue Agency (NRA) as a VASP/CASP under MAMLA and MiCA transposition
- Must obtain authorization as a Crypto-Asset Service Provider (CASP) under the EU MiCA framework (fully applicable from 2026), which replaced the earlier MAMLA-based classification
- Must comply with EU Regulation 2023/1113 (TFR) Travel Rule applicable from 30 December 2024 with no de minimis threshold for CASP-to-CASP transfers
- Local entity (Bulgarian incorporation) is required to register with NRA and be supervised by SANS
- All crypto-asset transfers involving self-hosted (unhosted) wallets are subject to MiCA rules as of 1 July 2025, with verification requirements above €1,000
Key Risks
- Enforcement risk: administrative fines, cessation of non-compliant activities, potential criminal investigations for severe money laundering cases; fines up to BGN 1,000,000+ for legal entities
- Regulatory transition risk: Bulgaria has moved from MAMLA-based VASP classification to MiCA CASP framework — operators may face dual-regime uncertainty during the transition period
- EU sanctions directly applicable — failure to screen against EU sanctions lists carries serious legal consequences
- Travel Rule compliance complexity for unhosted wallet transfers, especially verification of wallet ownership/control above €1,000 threshold
- SANS and NRA have inspection and sanction powers — compliance gaps in CDD, STR, or registration can trigger administrative or criminal liability
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Measures Against Money Laundering Act (MAMLA) (Закон за мерките срещу изпирането на пари - ЗМИП).
This act defines "virtual assets" and "virtual asset service providers" and brings them within the scope of obliged entities. It outlines the specific requirements for customer due diligence, reporting, and record-keeping.
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset are subject to AML/CFT regulation and are treated as financial activities for regulated virtual asset and stablecoin issuers.
In Bulgaria, AML/CFT supervision of VASPs is shared among multiple authorities, with the National Revenue Agency (NRA) as the leading registration and enforcement body, the Financial Supervision Commission (FSC) overseeing crypto-asset service providers within its regulatory perimeter, and DANS-FID retaining a role but no longer the sole or primary supervisor.
Role: This is Bulgaria's Financial Intelligence Unit (FIU). It is the primary recipient of Suspicious Transaction Reports (STRs) and other AML-related information from obliged entities. SANS is responsible for analyzing suspicious activities and disseminating intelligence to law enforcement.
National Revenue Agency (NRA) (Национална агенция за приходите - НАП)
Role: The NRA is responsible for the registration and general supervision of VASPs for AML/CFT purposes. VASPs in Bulgaria are typically required to register with the NRA and demonstrate compliance with AML obligations. The NRA may conduct inspections and impose administrative sanctions for non-compliance.
Bulgarian law now mandates continuous identification and verification of beneficial owners, requiring ongoing monitoring and periodic updates beyond a static registration step.
Natural Persons: Name, date and place of birth, nationality, permanent address, unique identification number (e.g., national ID card, passport number). Identity must be verified using reliable, independent source documents or data (e.g., valid official identification document).
Legal Entities: Company name, legal form, registration number, registered address, and the names of the individuals authorized to represent the company. Verification involves obtaining extracts from commercial registers or similar official documents.
Bulgarian law now mandates continuous identification and verification of beneficial owners, requiring ongoing monitoring and periodic updates beyond a static registration step.
For legal entities, VASPs must identify the natural person(s) who ultimately own or control the customer, typically defined as holding 25% plus one share or more of the voting rights or exercising control via other means. This information must also be verified.
Understanding the Purpose and Intended Nature of the Business Relationship:
VASPs must gather information on why the customer wants to use their services, the expected transaction patterns, and the source of funds/wealth where relevant.
Regular scrutiny of transactions undertaken throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Keeping customer documents, data, and information up-to-date.
Politically Exposed Persons (PEPs): Customers who hold or have held prominent public functions, their family members, or close associates.
High-Risk Third Countries: Transactions involving customers or beneficial owners from countries identified by the EU or FATF as having strategic AML/CFT deficiencies.
Complex, Unusual, Large Transactions, or Unusual Patterns: Transactions that have no apparent economic or lawful purpose.
Adopted: Yes, the principles of the FATF Travel Rule for crypto assets are adopted in Bulgaria through the Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, also known as the amended Transfer of Funds Regulation (TFR). This regulation is directly applicable in all EU member states, including Bulgaria, without the need for national transposition.
The EU Transfer of Funds Regulation as amended by Regulation (EU) 2023/1113 extends the Travel Rule to crypto‑asset transfers, and these requirements have applied in the EU (including Bulgaria) since 30 December 2024.
For crypto-asset transfers between EU Crypto-Asset Service Providers (CASPs) under Regulation (EU) 2023/1113, there is no de minimis threshold: all such transfers, regardless of amount, must include complete originator and beneficiary information. However, the EU framework now distinguishes these CASP‑to‑CASP transfers from transactions involving self‑hosted wallets, for which additional rules apply above €1,000, so any description of the regime should situate the zero‑threshold rule within this broader, MiCA‑aligned CASP/Transfer of Funds Regulation context rather than as a generic VASP rule.
As of July 1, Bulgaria applies MiCA’s strict rules to all crypto transfers, including those involving self-hosted wallets, ending any prior unregulated status.
CASPs must collect originator and beneficiary information for all transfers.
For transfers exceeding €1,000, the CASP must verify that the unhosted wallet is owned or controlled by the originator or beneficiary.
Verification is now mandatory for all unhosted wallets in Bulgaria, regardless of transaction value below €1,000.
Collect and transmit information: Ensure that crypto-asset transfers are accompanied by the following information:
Originator: Name, crypto-asset account number, address (or national ID number/customer ID number), date and place of birth (for natural persons), legal entity registration number (for legal entities).
Beneficiary: Name, crypto-asset account number.
Verify information: Take reasonable steps to verify the accuracy of the information, especially for transfers to/from unhosted wallets above the €1,000 threshold.
Retain records: Keep records of the collected information for a period of five years.
Detect missing information: Implement systems to detect if the required originator or beneficiary information is missing or incomplete for incoming or outgoing transfers.
Data Protection: All data processing must comply with the GDPR (General Data Protection Regulation).
Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc. Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Legal Basis: EU sanctions are typically imposed through Council Decisions and implemented via Council Regulations. These Regulations are directly applicable in all EU Member States without the need for national transposition.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange (order-book with custody) is permissible in Bulgaria but requires registration with the National Revenue Agency as a VASP/CASP under MAMLA, authorization under the EU MiCA framework, a local entity, and full compliance with AML/CFT obligations including CDD, ongoing monitoring, STRs to SANS, and EU Travel Rule (no de minimis threshold for CASP-to-CASP transfers, with verification rules for unhosted wallets above €1,000).
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?