DeFi protocol frontend in Bulgaria
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Bulgaria with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with the National Revenue Agency (NRA) as a VASP under the Measures Against Money Laundering Act (MAMLA) — required if the frontend operator falls within the definition of a 'virtual asset service provider'.
- Customer due diligence (CDD) on all users: identify and verify natural persons (name, date/place of birth, nationality, address, national ID/passport number) and legal entities (name, legal form, registration number, address, authorized representatives).
- Beneficial ownership identification using a 25%+1 share threshold for legal entity customers.
- Ongoing transaction monitoring to detect complex, unusual, large transactions or patterns inconsistent with customer profiles.
- Suspicious Transaction Reporting (STRs) to SANS (State Agency for National Security - Financial Intelligence Directorate).
- PEP screening for customers holding prominent public functions, their family members, and close associates.
- High-risk third-country enhanced due diligence for customers from EU/FATF-listed jurisdictions.
- Record-keeping obligations under MAMLA for CDD documents, transaction data, and STR records.
Key Restrictions
- If the frontend operator charges fees (e.g., swap fees, spread, interface fees), it is more likely to be classified as a VASP engaging in 'participation in and provision of financial services related to an issuer's offer and/or sale of a virtual asset' or 'exchange between virtual assets and fiat currencies' / 'exchange between virtual assets', triggering full AML registration and compliance obligations under MAMLA.
- A local legal entity registered in Bulgaria is likely required to register as a VASP with the NRA and to comply with MAMLA obligations.
- Geofencing/region blocking of users from high-risk third countries and sanctioned jurisdictions (EU sanctions are directly applicable) is required.
- If the frontend only provides a non-custodial interface to permissionless smart contracts and does not take custody, process fiat, or charge fees, the classification risk may be lower — but regulatory uncertainty remains and Bulgarian authorities have wide discretion to classify activities.
Key Risks
- Regulatory ambiguity: Bulgarian law does not clearly distinguish between a 'fully decentralized' protocol and the frontend operator interacting with it — MAMLA defines VASP activities broadly, and fee-taking or profit-generating activity may trigger classification.
- Enforcement risk: SANS and NRA can impose administrative fines, cessation orders, and refer matters for criminal investigation for non-compliance with VASP registration and AML obligations.
- EU sanctions risk: Directly applicable EU sanctions regimes require immediate compliance; failure to block sanctioned jurisdictions or individuals carries severe penalties.
- Tax/PR exposure: Even if a frontend operates from outside Bulgaria, serving Bulgarian residents without a local entity and registration may be treated as unlicensed VASP activity.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Measures Against Money Laundering Act (MAMLA) (Закон за мерките срещу изпирането на пари - ЗМИП).
This act defines "virtual assets" and "virtual asset service providers" and brings them within the scope of obliged entities. It outlines the specific requirements for customer due diligence, reporting, and record-keeping.
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset are subject to AML/CFT regulation and are treated as financial activities for regulated virtual asset and stablecoin issuers.
In Bulgaria, AML/CFT supervision of VASPs is shared among multiple authorities, with the National Revenue Agency (NRA) as the leading registration and enforcement body, the Financial Supervision Commission (FSC) overseeing crypto-asset service providers within its regulatory perimeter, and DANS-FID retaining a role but no longer the sole or primary supervisor.
National Revenue Agency (NRA) (Национална агенция за приходите - НАП)
Bulgarian law now mandates continuous identification and verification of beneficial owners, requiring ongoing monitoring and periodic updates beyond a static registration step.
Natural Persons: Name, date and place of birth, nationality, permanent address, unique identification number (e.g., national ID card, passport number). Identity must be verified using reliable, independent source documents or data (e.g., valid official identification document).
Legal Entities: Company name, legal form, registration number, registered address, and the names of the individuals authorized to represent the company. Verification involves obtaining extracts from commercial registers or similar official documents.
Bulgarian law now mandates continuous identification and verification of beneficial owners, requiring ongoing monitoring and periodic updates beyond a static registration step.
For legal entities, VASPs must identify the natural person(s) who ultimately own or control the customer, typically defined as holding 25% plus one share or more of the voting rights or exercising control via other means. This information must also be verified.
Understanding the Purpose and Intended Nature of the Business Relationship:
Regular scrutiny of transactions undertaken throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Politically Exposed Persons (PEPs): Customers who hold or have held prominent public functions, their family members, or close associates.
High-Risk Third Countries: Transactions involving customers or beneficial owners from countries identified by the EU or FATF as having strategic AML/CFT deficiencies.
Complex, Unusual, Large Transactions, or Unusual Patterns: Transactions that have no apparent economic or lawful purpose.
Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc. Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Legal Basis: EU sanctions are typically imposed through Council Decisions and implemented via Council Regulations. These Regulations are directly applicable in all EU Member States without the need for national transposition.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend serving Bulgarian residents is likely to be classified as a VASP under MAMLA if it charges fees or exercises any control over the user's interaction with the protocol, requiring NRA registration, full AML/CFT compliance, and a local entity.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?