Centralized exchange in Germany
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Germany with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Full AML/CFT compliance under the German Money Laundering Act (GwG) — customer identification and transaction monitoring required
- Travel-rule compliance under KryptoWTransferV (Crypto Asset Transfer Regulation): originator and beneficiary identification must accompany all crypto transfers (no de minimis threshold — EUR 0)
- KYC: Verification of all transaction parties' identities required
- Ongoing CDD / transaction monitoring obligations under GwG
- Sanctions screening under Criminal Code (StGB) and applicable EU sanctions regimes
- Supervision by BaFin for all AML obligations
Key Restrictions
- Must establish a German legal entity (GmbH, AG, or bank) with proper corporate governance
- Customer asset segregation: complete separation of client and proprietary crypto assets required
- Professional liability insurance of minimum €1,000,000 covering custody service operation risks
- IT security procedures must comply with BAIT (BaFin Guidance on IT Requirements), including encryption, access controls, and incident response
- Fit-and-proper requirements: at least one managing director must be reliable, sufficiently qualified, and experienced in crypto custody business
- Capital adequacy: €125,000 minimum for custody (Kryptoverwahrgeschaeft) or €150,000 minimum for exchange/trading platform authorization under MiCA CASP
Key Risks
- BaFin is known for thoroughness and slower processing — licensing timeline may be 6-12 months or more
- Regulatory overlap: Pre-MiCA crypto custody license (KWG) and MiCA CASP authorization both apply; transition period may create ambiguity
- Non-compliance with KryptoWTransferV travel-rule obligations (EUR 0 threshold) creates enforcement risk — no small-transaction exemption
- IT security and BAIT/DORA compliance expectations are high and actively enforced
- Conservative BaFin enforcement posture — precedent of enforcement actions against unlicensed operators
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
BaFin — CASP authorization (MiCA), crypto custody licensing (Kryptoverwahrgeschaeft) — pioneer since Jan 2020, ~40 entities hold/applied
MiCA Regulation (EU) (2023) — CASP authorization, comprehensive crypto regulation
Kreditwesengesetz (KWG) — Banking Act (2020) — Crypto custody license (Kryptoverwahrgeschaeft) — EUR 125,000 minimum
VASP: CASP authorization under MiCA via BaFin. Pre-MiCA crypto custody license also in effect. BaFin 12-month transition period. 6-12 months (BaFin known for thoroughness/slower processing). Requires detailed business plans and IT security concepts (BAIT/DORA).
CUSTODY: Crypto custody license (Kryptoverwahrgeschaeft) under KWG — EUR 125,000 minimum capital. ~40 entities hold or have applied.
EXCHANGE: CASP authorization under MiCA — EUR 150,000 minimum capital for trading platforms
Federal Financial Supervisory Authority (BaFin): Germany's primary financial regulator responsible for licensing and supervising all crypto-asset service providers, including exchanges and custodians. BaFin enforces compliance with national laws and EU regulations, focusing on consumer protection and anti-money laundering measures.
German Banking Act (KWG): Since January 2020, crypto custody has been regulated as a financial service requiring a BaFin license.
Markets in Crypto-Assets Regulation (MiCAR): Applies EU-wide as of the end of 2024, establishing harmonized licensing requirements for crypto-asset service providers throughout the EU.
Safekeeping, administration, and safeguarding of crypto assets or private keys
Operation of trading platforms (cryptocurrency exchanges)
Exchange services (conversion between fiat and crypto, or between different crypto assets)
Fit-and-proper requirements: At least one managing director must be reliable, sufficiently qualified, and experienced in crypto custody business.
Professional liability insurance: Minimum €1,000,000 covering custody service operation risks.
IT security procedures: Per BAIT (BaFin Guidance on IT Requirements), including encryption, access controls, and incident response.
Customer asset segregation: Complete separation of client and proprietary crypto assets required.
AML/CFT compliance: Full adherence to the German Money Laundering Act (GwG) with customer identification and transaction monitoring.
Know Your Customer (KYC): Verification of all transaction parties' identities.
Establishing a German legal entity (GmbH, AG, or bank) with proper corporate governance
Preparing a comprehensive business plan describing crypto custody offerings, technology platform, and security procedures
Documenting capital adequacy with €125,000 minimum through bank accounts and audited financial statements
GwG (Money Laundering Act): Core national law incorporating EU AML Directives (e.g., AMLD5), covering obliged entities like CASPs for ML/TF prevention.
KWG (Banking Act): Requires BaFin licensing (section 32) for crypto custody business, exchange services, and related financial activities.
KMAG (Crypto Markets Supervision Act): Implements MiCAR domestically, granting BaFin powers for CASP licensing, supervision, and public warnings.
KryptoWTransferV (Crypto Asset Transfer Regulation): Enforces the EU "travel rule" for crypto transfers, requiring originator/beneficiary identification.
Travel Rule adopted — threshold: EUR 0 (no threshold under TFR recast)
§3 KryptoTransferV mandates sharing: originator's account (e.g., public key), beneficiary's name and account (e.g., public key).
Based on EU Regulation 2015/847, prohibiting unaccompanied client/recipient info transmission.
Crypto Securities Transfer Regulation (KryptoTransferV): Primary law, detailed in German Federal Ministry of Finance draft (English translation via DeepL).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange (order-book with custody) may operate in Germany only after obtaining a BaFin CASP authorization under MiCA (or the existing KWG crypto custody license during transition), with a local German entity, minimum capital of €125,000–€150,000, full customer asset segregation, €1M professional liability insurance, BAIT-compliant IT security, and zero-threshold travel-rule compliance under KryptoWTransferV.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?