Crypto ATM / kiosk operator in Czech Republic
Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.
Crypto ATM is conditionally permitted in Czech Republic with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- KYC identity verification required under Act No. 253/2008 Coll. (AML Act) — natural persons: full name, date/place of birth, permanent address, nationality; legal entities: company name, registered office, IČO, statutory representatives
- Beneficial owner identification required for legal entities and trusts (any natural person holding >25% ownership or control)
- Verification must use reliable independent sources (government-issued ID, company registration documents); non-face-to-face relationships require enhanced verification measures
- Ongoing transaction monitoring to ensure consistency with customer profile, risk profile, and source of funds
- Enhanced Due Diligence (EDD) required for PEPs, high-risk customers, and complex/unusual transactions
- Source of funds/wealth must be established for higher-risk customers or transactions
- Cash-transaction reporting threshold under AML Act applies (obliged entities must report suspicious transactions to FAÚ regardless of amount; specific cash transaction reporting thresholds under Czech AML law apply)
- FAÚ (Financial Analytical Office) is the AML/CFT supervisor and suspicious transaction reporter
- Travel Rule obligations under EU regulatory framework (applicable to transfers of virtual assets between VASPs)
- Regular reviews of customer information and risk assessments required
Key Restrictions
- Must be registered as a trade license (živnostenské oprávnění) under the Trade Licensing Act for 'Provision of services relating to virtual assets' (changed from minimal regulation to specific licensing under MiCA framework effective 2025)
- As of April 1, 2025 and July 1, 2025, the Trade Licensing Act amendments further tighten the regulatory framework for VASPs
- EU MiCA Regulation now applies, including comprehensive licensing requirements for crypto service providers covering fiat-crypto exchange (relevant to ATM/kiosk cash-in/cash-out)
- Non-face-to-face business relationships (inherent in ATM/kiosk model) trigger enhanced verification measures — must have mechanisms for remote identity verification at the kiosk
- Must be an obliged entity registered with FAÚ and subject to AML Act obligations
- Local entity incorporation required — FAÚ and ČNB supervise Czech-registered entities
Key Risks
- High AML risk profile of cash-intensive crypto ATM operations makes this a target for FAÚ enforcement and fines for compliance failures
- Non-face-to-face customer onboarding at kiosks creates inherent enhanced-KYC compliance challenge — failure to implement adequate remote verification is a common compliance gap
- EU Travel Rule obligations create operational complexity for cash-to-crypto transfers (must capture and transmit originator/beneficiary information)
- ČNB regularly issues warnings against unlicensed or non-compliant crypto operators — public reputational risk
- Czech police (NCOZ) and EPPO involvement in major crypto crime cases shows active criminal enforcement pathway beyond administrative sanctions
- Ambiguity around whether the kiosk operator is treated as a 'payment service' versus a 'VASP' — distinct regulatory regimes could apply
- Cash transaction reporting obligations (under AML Act) may not have a specific kiosk-delineated threshold — must report suspicious transactions regardless of amount
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
VASP Activities (Virtual Assets Only): For services exclusively involving virtual assets (e.g., crypto-to-crypto exchange, crypto custody), the Czech Republic requires registration as a trade license (živnostenské oprávnění) under the Trade Licensing Act, specifically for "Provision of services related to virtual assets." This is generally considered a "free trade" (volná živnost).
Act No. 253/2008 Coll., on Certain Measures Against Legalisation of Proceeds of Crime and Financing of Terrorism (the "AML Act"): This is the primary national law transposing the EU AML directives. It was amended to include VASPs as obliged entities.
Act No. 455/1991 Coll., the Trade Licensing Act, was amended effective April 1, 2025, and further amendments will take effect July 1, 2025, affecting the regulatory framework for virtual asset service providers under Czech AML law.
Virtual Asset Exchange Services, defined as providing services for the exchange between virtual assets and fiat currencies or between one or more forms of virtual assets, are no longer subject to minimal regulation but now require specific licenses and adherence to the comprehensive EU MiCA Regulation in Czechia.
Natural Persons: Full name, date and place of birth, permanent address, nationality.
Legal Entities: Company name, registered office address, identification number (IČO), and details of their statutory representatives.
Beneficial Owner (BO): For legal entities and trusts, VASPs must identify and verify the beneficial owner(s) – i.e., the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted. This typically involves identifying any natural person holding more than 25% of the shares or voting rights, or otherwise exercising control.
Information must be verified using reliable, independent sources (e.g., valid government-issued identification documents for individuals like passports or ID cards; official company registration documents for legal entities).
For non-face-to-face relationships, enhanced verification measures are required.
Understanding the Purpose and Intended Nature of the Business Relationship:
VASPs must continuously monitor the business relationship and transactions to ensure they are consistent with their knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Regular reviews of customer information and risk assessments must be conducted.
Regulator Name: Financial Analytical Office (FAÚ) of the Ministry of Finance.
Regulator Name: Czech National Bank (ČNB).
AML/CFT fines by the FAÚ for failures in compliance, which can apply to any "obliged entity," including crypto service providers. However, large, publicly detailed fines against prominent crypto platforms are not as common as in some other countries.
Consumer protection in Czechia has evolved beyond simple warnings to include dynamic legal development, active enforcement, and stricter regulatory obligations under laws like the Cybersecurity Act.
While the Fifth Anti-Money Laundering Directive (EU 2018/843) (5AMLD) initially brought virtual asset service providers under AML/CFT scope in Czechia, the framework has evolved with newer EU regulations (e.g., MiCA, Travel Rule, upcoming AMLR/AMLD legislation by 2025) now also being relevant and superseding aspects of previous directives.
The legal framework for money laundering harmonization in Czechia is now governed by Directive (EU) 2024/1640, which replaced the earlier Sixth Anti-Money Laundering Directive (EU 2018/1673).
Entity Targeted: Various obliged entities, including (but not limited to) payment institutions, banks, and potentially smaller crypto service providers. Specific names and detailed violations for smaller crypto firms are not always publicly disclosed unless the fine is exceptionally large or the case is particularly egregious. Violation Type: Failure to comply with anti-money laundering and counter-terrorist financing (AML/CFT) obligations (e.g., insufficient customer due diligence, inadequate risk assessment, failure to report suspicious transactions). Penalty Amount: Varies significantly depending on the severity and scale of the violation. Fines can range from tens of thousands CZK to millions CZK. FAÚ annually publishes statistics on fines but not always specific details for each entity unless it's a high-profile case. Outcome: Improved AML compliance among obliged entities, deterrence of future violations.
Legal Basis: Act No. 253/2008 Coll., on Selected Measures Against Legitimisation of Proceeds of Crime and Financing of Terrorism (AML Act).
The FSA has the authority to impose fines and suspend licenses for non-compliance with regulatory requirements related to digital asset securities. Recent enforcement actions have targeted issuers failing to meet transparency obligations. Basic Information | Ministry of Finance CR
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — Crypto ATM/kiosk operators may operate in Czechia if registered as a VASP trade license under the Trade Licensing Act, registered as an obliged entity with the FAÚ, and fully compliant with Act No. 253/2008 Coll. AML obligations including KYC, EDD, suspicious transaction reporting, and Travel Rule, with enhanced measures for non-face-to-face (kiosk) customer relationships.
Questions this verdict aims to answer
- What money-transmitter / kiosk-specific license is required?
- What cash-transaction reporting thresholds apply?
- What enhanced-KYC obligations attach to cash-in / cash-out?