Crypto-funded debit card in Germany
A card program where customer fiat balances are funded from crypto holdings, typically through an off-ramp at point of sale or top-up.
Crypto debit card is conditionally permitted in Germany with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer identification and KYC verification required under GwG (German Money Laundering Act)
- Transaction monitoring and AML/CFT compliance per GwG, supervised by BaFin
- Travel rule compliance under KryptoWTransferV — originator/beneficiary data must be transmitted for crypto transfers
- Suspicious transaction reporting (STRs) to BaFin/FIU under GwG
- Ongoing due diligence and record-keeping obligations for all cardholder transactions
Key Restrictions
- Customer fiat balances must be held in a safeguarded e-money account — likely requiring an e-money license (ZAG license) or partnership with a licensed e-money institution
- Crypto-to-fiat conversion at point of sale requires either a CASP authorization under MiCA (EUR 150,000 minimum capital for exchange services) or a licensed partner
- A German legal entity (GmbH or AG) is required for the operator or at minimum for the CASP-licensed entity
- Must secure a partner bank or BIN sponsor (e.g. Mastercard/Visa issuer) licensed in Germany or passported under PSD2
- Crypto custody (if operator holds keys) requires Kryptoverwahrgeschaeft license under KWG with EUR 125,000 minimum capital
- Customer asset segregation required — client and proprietary crypto assets must be separated
- IT security requirements per BAIT (BaFin IT Guidance) and DORA apply
Key Risks
- Complex multi-license requirement — likely needs both a CASP (MiCA) and an e-money / payment institution license (ZAG), which BaFin processes slowly (6–12 months)
- Ambiguity on whether the on-chain/off-ramp conversion is an 'exchange service' under MiCA or a payment service under PSD2 — both regimes may apply
- Consumer crypto taxation at point-of-sale spends may create reporting friction (short-term gains are taxable at personal rates if held <12 months)
- BaFin's thorough supervisory approach imposes ongoing operational burden (BAIT, capital adequacy reporting, outsourcing oversight for BIN-sponsor)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
BaFin — CASP authorization (MiCA), crypto custody licensing (Kryptoverwahrgeschaeft) — pioneer since Jan 2020, ~40 entities hold/applied
Kreditwesengesetz (KWG) — Banking Act (2020) — Crypto custody license (Kryptoverwahrgeschaeft) — EUR 125,000 minimum
VASP: CASP authorization under MiCA via BaFin. Pre-MiCA crypto custody license also in effect. BaFin 12-month transition period. 6-12 months (BaFin known for thoroughness/slower processing). Requires detailed business plans and IT security concepts (BAIT/DORA).
CUSTODY: Crypto custody license (Kryptoverwahrgeschaeft) under KWG — EUR 125,000 minimum capital. ~40 entities hold or have applied.
EXCHANGE: CASP authorization under MiCA — EUR 150,000 minimum capital for trading platforms
German Banking Act (KWG): Since January 2020, crypto custody has been regulated as a financial service requiring a BaFin license.
Markets in Crypto-Assets Regulation (MiCAR): Applies EU-wide as of the end of 2024, establishing harmonized licensing requirements for crypto-asset service providers throughout the EU.
Exchange services (conversion between fiat and crypto, or between different crypto assets)
Establishing a German legal entity (GmbH, AG, or bank) with proper corporate governance
Customer asset segregation: Complete separation of client and proprietary crypto assets required.
IT security procedures: Per BAIT (BaFin Guidance on IT Requirements), including encryption, access controls, and incident response.
AML/CFT compliance: Full adherence to the German Money Laundering Act (GwG) with customer identification and transaction monitoring.
Know Your Customer (KYC): Verification of all transaction parties' identities.
GwG (Money Laundering Act): Core national law incorporating EU AML Directives (e.g., AMLD5), covering obliged entities like CASPs for ML/TF prevention.
KWG (Banking Act): Requires BaFin licensing (section 32) for crypto custody business, exchange services, and related financial activities.
KMAG (Crypto Markets Supervision Act): Implements MiCAR domestically, granting BaFin powers for CASP licensing, supervision, and public warnings.
KryptoWTransferV (Crypto Asset Transfer Regulation): Enforces the EU "travel rule" for crypto transfers, requiring originator/beneficiary identification.
Fit-and-proper requirements: At least one managing director must be reliable, sufficiently qualified, and experienced in crypto custody business.
Professional liability insurance: Minimum €1,000,000 covering custody service operation risks.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a crypto-funded debit card program in Germany requires a complex multi-license structure (CASP authorization under MiCA for crypto-to-fiat exchange + either a ZAG e-money license or partnership with a licensed e-money institution for fiat card issuance), a German legal entity, BaFin supervision, full GwG AML/KYC obligations including travel rule compliance, and a BIN-sponsor/bank partner licensed in Germany or passported under PSD2.
Questions this verdict aims to answer
- What e-money / payment-institution license is required?
- How is the crypto-to-fiat conversion regulated?
- What KYC and AML obligations apply to cardholders?
- What partner-bank or BIN-sponsor arrangements are required?