← Regulations / Bulgaria / Operating Models / DeFi frontend

DeFi protocol frontend in Bulgaria

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Bulgaria with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration with the National Revenue Agency (NRA) as a VASP under the Measures Against Money Laundering Act (MAMLA) — required if the frontend operator falls within the definition of a 'virtual asset service provider'.
  • Customer due diligence (CDD) on all users: identify and verify natural persons (name, date/place of birth, nationality, address, national ID/passport number) and legal entities (name, legal form, registration number, address, authorized representatives).
  • Beneficial ownership identification using a 25%+1 share threshold for legal entity customers.
  • Ongoing transaction monitoring to detect complex, unusual, large transactions or patterns inconsistent with customer profiles.
  • Suspicious Transaction Reporting (STRs) to SANS (State Agency for National Security - Financial Intelligence Directorate).
  • PEP screening for customers holding prominent public functions, their family members, and close associates.
  • High-risk third-country enhanced due diligence for customers from EU/FATF-listed jurisdictions.
  • Record-keeping obligations under MAMLA for CDD documents, transaction data, and STR records.

Key Restrictions

  • If the frontend operator charges fees (e.g., swap fees, spread, interface fees), it is more likely to be classified as a VASP engaging in 'participation in and provision of financial services related to an issuer's offer and/or sale of a virtual asset' or 'exchange between virtual assets and fiat currencies' / 'exchange between virtual assets', triggering full AML registration and compliance obligations under MAMLA.
  • A local legal entity registered in Bulgaria is likely required to register as a VASP with the NRA and to comply with MAMLA obligations.
  • Geofencing/region blocking of users from high-risk third countries and sanctioned jurisdictions (EU sanctions are directly applicable) is required.
  • If the frontend only provides a non-custodial interface to permissionless smart contracts and does not take custody, process fiat, or charge fees, the classification risk may be lower — but regulatory uncertainty remains and Bulgarian authorities have wide discretion to classify activities.

Key Risks

  • Regulatory ambiguity: Bulgarian law does not clearly distinguish between a 'fully decentralized' protocol and the frontend operator interacting with it — MAMLA defines VASP activities broadly, and fee-taking or profit-generating activity may trigger classification.
  • Enforcement risk: SANS and NRA can impose administrative fines, cessation orders, and refer matters for criminal investigation for non-compliance with VASP registration and AML obligations.
  • EU sanctions risk: Directly applicable EU sanctions regimes require immediate compliance; failure to block sanctioned jurisdictions or individuals carries severe penalties.
  • Tax/PR exposure: Even if a frontend operates from outside Bulgaria, serving Bulgarian residents without a local entity and registration may be treated as unlicensed VASP activity.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

aml 95% confidence

Measures Against Money Laundering Act (MAMLA) (Закон за мерките срещу изпирането на пари - ЗМИП).

aml 95% confidence

This act defines "virtual assets" and "virtual asset service providers" and brings them within the scope of obliged entities. It outlines the specific requirements for customer due diligence, reporting, and record-keeping.

aml 95% confidence

Exchange between virtual assets and fiat currencies.

aml 100% confidence

Exchange between one or more forms of virtual assets.

aml 90% confidence

Transfer of virtual assets.

aml 90% confidence

Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.

aml 78% confidence

Participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset are subject to AML/CFT regulation and are treated as financial activities for regulated virtual asset and stablecoin issuers.

aml 90% confidence

In Bulgaria, AML/CFT supervision of VASPs is shared among multiple authorities, with the National Revenue Agency (NRA) as the leading registration and enforcement body, the Financial Supervision Commission (FSC) overseeing crypto-asset service providers within its regulatory perimeter, and DANS-FID retaining a role but no longer the sole or primary supervisor.

aml 90% confidence

National Revenue Agency (NRA) (Национална агенция за приходите - НАП)

aml 90% confidence

Bulgarian law now mandates continuous identification and verification of beneficial owners, requiring ongoing monitoring and periodic updates beyond a static registration step.

aml 80% confidence

Natural Persons: Name, date and place of birth, nationality, permanent address, unique identification number (e.g., national ID card, passport number). Identity must be verified using reliable, independent source documents or data (e.g., valid official identification document).

aml 80% confidence

Legal Entities: Company name, legal form, registration number, registered address, and the names of the individuals authorized to represent the company. Verification involves obtaining extracts from commercial registers or similar official documents.

aml 90% confidence

Bulgarian law now mandates continuous identification and verification of beneficial owners, requiring ongoing monitoring and periodic updates beyond a static registration step.

aml 95% confidence

For legal entities, VASPs must identify the natural person(s) who ultimately own or control the customer, typically defined as holding 25% plus one share or more of the voting rights or exercising control via other means. This information must also be verified.

aml 88% confidence

Understanding the Purpose and Intended Nature of the Business Relationship:

aml 83% confidence

Regular scrutiny of transactions undertaken throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.

aml 95% confidence

Politically Exposed Persons (PEPs): Customers who hold or have held prominent public functions, their family members, or close associates.

aml 95% confidence

High-Risk Third Countries: Transactions involving customers or beneficial owners from countries identified by the EU or FATF as having strategic AML/CFT deficiencies.

aml 95% confidence

Complex, Unusual, Large Transactions, or Unusual Patterns: Transactions that have no apparent economic or lawful purpose.

enforcement 98% confidence

Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc. Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.

enforcement 70% confidence

Legal Basis: EU sanctions are typically imposed through Council Decisions and implemented via Council Regulations. These Regulations are directly applicable in all EU Member States without the need for national transposition.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a DeFi protocol frontend serving Bulgarian residents is likely to be classified as a VASP under MAMLA if it charges fees or exercises any control over the user's interaction with the protocol, requiring NRA registration, full AML/CFT compliance, and a local entity.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?