← Regulations / Germany / Operating Models / Crypto debit card

Crypto-funded debit card in Germany

A card program where customer fiat balances are funded from crypto holdings, typically through an off-ramp at point of sale or top-up.

Conditional AI-Generated · Unreviewed

Crypto debit card is conditionally permitted in Germany with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Customer identification and KYC verification required under GwG (German Money Laundering Act)
  • Transaction monitoring and AML/CFT compliance per GwG, supervised by BaFin
  • Travel rule compliance under KryptoWTransferV — originator/beneficiary data must be transmitted for crypto transfers
  • Suspicious transaction reporting (STRs) to BaFin/FIU under GwG
  • Ongoing due diligence and record-keeping obligations for all cardholder transactions

Key Restrictions

  • Customer fiat balances must be held in a safeguarded e-money account — likely requiring an e-money license (ZAG license) or partnership with a licensed e-money institution
  • Crypto-to-fiat conversion at point of sale requires either a CASP authorization under MiCA (EUR 150,000 minimum capital for exchange services) or a licensed partner
  • A German legal entity (GmbH or AG) is required for the operator or at minimum for the CASP-licensed entity
  • Must secure a partner bank or BIN sponsor (e.g. Mastercard/Visa issuer) licensed in Germany or passported under PSD2
  • Crypto custody (if operator holds keys) requires Kryptoverwahrgeschaeft license under KWG with EUR 125,000 minimum capital
  • Customer asset segregation required — client and proprietary crypto assets must be separated
  • IT security requirements per BAIT (BaFin IT Guidance) and DORA apply

Key Risks

  • Complex multi-license requirement — likely needs both a CASP (MiCA) and an e-money / payment institution license (ZAG), which BaFin processes slowly (6–12 months)
  • Ambiguity on whether the on-chain/off-ramp conversion is an 'exchange service' under MiCA or a payment service under PSD2 — both regimes may apply
  • Consumer crypto taxation at point-of-sale spends may create reporting friction (short-term gains are taxable at personal rates if held <12 months)
  • BaFin's thorough supervisory approach imposes ongoing operational burden (BAIT, capital adequacy reporting, outsourcing oversight for BIN-sponsor)

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 40% confidence

BaFin — CASP authorization (MiCA), crypto custody licensing (Kryptoverwahrgeschaeft) — pioneer since Jan 2020, ~40 entities hold/applied

licensing 20% confidence

Kreditwesengesetz (KWG) — Banking Act (2020) — Crypto custody license (Kryptoverwahrgeschaeft) — EUR 125,000 minimum

licensing 20% confidence

VASP: CASP authorization under MiCA via BaFin. Pre-MiCA crypto custody license also in effect. BaFin 12-month transition period. 6-12 months (BaFin known for thoroughness/slower processing). Requires detailed business plans and IT security concepts (BAIT/DORA).

licensing 20% confidence

CUSTODY: Crypto custody license (Kryptoverwahrgeschaeft) under KWG — EUR 125,000 minimum capital. ~40 entities hold or have applied.

licensing 20% confidence

EXCHANGE: CASP authorization under MiCA — EUR 150,000 minimum capital for trading platforms

licensing 20% confidence

German Banking Act (KWG): Since January 2020, crypto custody has been regulated as a financial service requiring a BaFin license.

licensing 20% confidence

Markets in Crypto-Assets Regulation (MiCAR): Applies EU-wide as of the end of 2024, establishing harmonized licensing requirements for crypto-asset service providers throughout the EU.

licensing 20% confidence

Exchange services (conversion between fiat and crypto, or between different crypto assets)

licensing 20% confidence

Establishing a German legal entity (GmbH, AG, or bank) with proper corporate governance

licensing 20% confidence

Customer asset segregation: Complete separation of client and proprietary crypto assets required.

licensing 20% confidence

IT security procedures: Per BAIT (BaFin Guidance on IT Requirements), including encryption, access controls, and incident response.

licensing 20% confidence

AML/CFT compliance: Full adherence to the German Money Laundering Act (GwG) with customer identification and transaction monitoring.

licensing 20% confidence

Know Your Customer (KYC): Verification of all transaction parties' identities.

aml 40% confidence

GwG (Money Laundering Act): Core national law incorporating EU AML Directives (e.g., AMLD5), covering obliged entities like CASPs for ML/TF prevention.

aml 40% confidence

KWG (Banking Act): Requires BaFin licensing (section 32) for crypto custody business, exchange services, and related financial activities.

aml 40% confidence

KMAG (Crypto Markets Supervision Act): Implements MiCAR domestically, granting BaFin powers for CASP licensing, supervision, and public warnings.

aml 40% confidence

KryptoWTransferV (Crypto Asset Transfer Regulation): Enforces the EU "travel rule" for crypto transfers, requiring originator/beneficiary identification.

licensing 20% confidence

Fit-and-proper requirements: At least one managing director must be reliable, sufficiently qualified, and experienced in crypto custody business.

licensing 20% confidence

Professional liability insurance: Minimum €1,000,000 covering custody service operation risks.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a crypto-funded debit card program in Germany requires a complex multi-license structure (CASP authorization under MiCA for crypto-to-fiat exchange + either a ZAG e-money license or partnership with a licensed e-money institution for fiat card issuance), a German legal entity, BaFin supervision, full GwG AML/KYC obligations including travel rule compliance, and a BIN-sponsor/bank partner licensed in Germany or passported under PSD2.

Questions this verdict aims to answer

  • What e-money / payment-institution license is required?
  • How is the crypto-to-fiat conversion regulated?
  • What KYC and AML obligations apply to cardholders?
  • What partner-bank or BIN-sponsor arrangements are required?