Crypto ATM / kiosk operator in Denmark
Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.
Crypto ATM is conditionally permitted in Denmark with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Register as a VASP with Finanstilsynet (the Danish FSA) under the hvidvaskloven (Money Laundering Act), which transposes 4th/5th/6th AMLDs (dk.aml.this-is-the-core-danish, dk.aml.the-5th-amld-directive-eu, dk.aml.the-6th-amld-directive-eu)
- Conduct enterprise-wide risk assessment under § 7 of hvidvaskloven (dk.aml.vasps-must-conduct-an-enterprise-wide)
- Customer identification and verification: obtain full name, address, DOB, national ID number (natural persons) from reliable independent sources (e.g. passport, national ID) — dk.aml.natural-persons-obtain-and-verify
- Legal entity customers: verify name, legal form, address, registration number, articles of association, and authorised representatives — dk.aml.legal-entities-obtain-and-verify
- Identify and verify UBOs (any natural person owning/controlling >25% of shares/voting rights) — dk.aml.identification-of-beneficial-owners, dk.aml.vasps-must-identify-the-ultimate, dk.aml.verification-of-the-ubos-identity
- Determine purpose and intended nature of the business relationship — dk.aml.purpose-and-intended-nature-of
- Enhanced Due Diligence (EDD) required for PEPs, high-risk third-country customers, unusual/complex transactions, and non-face-to-face identification — dk.aml.enhanced-due-diligence-edd-required, dk.aml.customers-who-are-politically-exposed, dk.aml.customers-from-high-risk-third-countries, dk.aml.unusual-or-complex-transactions, dk.aml.situations-where-the-customer-is
- EDD measures include senior management approval, source of funds/wealth determination, enhanced ongoing monitoring — dk.aml.measures-include-obtaining-senior-management
- Continuous transaction monitoring under § 13 of hvidvaskloven to ensure transactions match customer risk profile — dk.aml.vasps-must-continuously-monitor-the
- Keep customer information and risk profiles up-to-date — dk.aml.customer-information-and-risk-profiles
- Simplified Due Diligence is rarely available for crypto/VASP sector which is generally considered higher risk — dk.aml.simplified-due-diligence-sdd-permitted
Key Restrictions
- Must register as a VASP/crypto-asset service provider with Finanstilsynet — the Danish financial supervisory authority (implied by all AML provisions referencing the Danish transposition of AMLDs)
- As a cash-intensive business, the operator falls under the 'exchange between virtual currencies and fiat currencies' definition of a VASP under Danish AML law (dk.aml.exchange-between-virtual-currencies-and)
- MiCA Title III (ARTs) and Title IV (EMTs) provisions apply from June 30, 2024; remaining MiCA provisions apply from December 30, 2024 — stablecoin-related kiosk offerings face additional restrictions (dk.enforcement.the-remaining-provisions-of-mica, dk.enforcement.titles-iii-arts-and-iv)
- No specific cash-transaction reporting threshold visible in the provided facts — cash-intensive kiosk model likely triggers EDD obligations as high-risk per the VASP classification
Key Risks
- Cash-intensive nature of crypto ATMs creates inherently higher ML/TF risk profile, likely triggering mandatory EDD for every cash transaction
- Non-face-to-face transactions (if kiosk lacks live video verification) would trigger EDD requirements under Danish law (dk.aml.situations-where-the-customer-is)
- Enforcement risk from Finanstilsynet for failure to maintain adequate customer identification and transaction monitoring at kiosk locations
- Provided facts do not specify a cash-transaction reporting threshold (e.g., EUR 10,000 equivalent) — this creates ambiguity on when CTR obligations apply
- MiCA transition periods (June/Dec 2024) may impose additional authorization requirements that could affect existing kiosk operations
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Lov om forebyggende foranstaltninger mod hvidvask og finansiering af terrorisme (hvidvaskloven) – The Money Laundering Act.
This is the core Danish law that transposes the EU's 4th, 5th, and 6th Anti-Money Laundering Directives (AMLDs).
The 5th AMLD (Directive (EU) 2018/843) was particularly significant for bringing virtual asset service providers under the scope of AML/CFT regulations, requiring them to register and comply with the same obligations as traditional financial institutions.
The 6th AMLD (Directive (EU) 2018/1673) primarily harmonises the definition of money laundering offences and associated penalties across member states, indirectly strengthening the overall framework.
Exchange between virtual currencies and fiat currencies.
Natural Persons: Obtain and verify the customer's identity (full name, address, date of birth, national identification number if applicable). Verification must be based on reliable, independent sources (e.g., valid passport, national ID card, driving license combined with proof of address).
Legal Entities: Obtain and verify the entity's name, legal form, address, registration number, and Articles of Association. Identify and verify the identity of the persons who are authorised to act on behalf of the legal entity.
Purpose and Intended Nature of the Business Relationship: Understand the purpose and intended nature of the business relationship or the occasional transaction.
VASPs must identify the ultimate beneficial owner (UBO) of all legal entities and trusts. A UBO is typically any natural person who directly or indirectly owns or controls more than 25% of the shares or voting rights, or otherwise exercises control.
Verification of the UBO's identity is also required, using reliable, independent sources.
VASPs must conduct an enterprise-wide risk assessment (§ 7 of Hvidvaskloven) to identify, assess, and understand the money laundering and terrorist financing risks associated with their customers, products, services, transactions, and geographic areas.
Enhanced Due Diligence (EDD): Required in situations presenting a higher risk of money laundering or terrorist financing. This includes:
Customers who are Politically Exposed Persons (PEPs) or their family members/close associates.
Customers from high-risk third countries (as identified by the EU or FATF).
Situations where the customer is not physically present for identification.
Measures include obtaining senior management approval, taking reasonable measures to establish the source of funds and wealth, and conducting enhanced ongoing monitoring.
Simplified Due Diligence (SDD): Permitted in clearly defined low-risk situations, but these are rare for the virtual asset sector, which is generally considered higher risk.
VASPs must continuously monitor the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship, to ensure that the transactions are consistent with the VASP’s knowledge of the customer, their business, and risk profile (§ 13 of Hvidvaskloven).
Customer information and risk profiles must be kept up-to-date.
Titles III (ARTs) and IV (EMTs) of MiCA apply from June 30, 2024.
The remaining provisions of MiCA apply from December 30, 2024.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — Crypto ATM/kiosk operators in Denmark must register as VASPs with Finanstilsynet, comply with full CDD/EDD/transaction monitoring under the hvidvaskloven (transposing EU 4th-6th AMLDs), and meet MiCA authorization requirements from 2024; however, the provided facts lack a specific cash-transaction reporting threshold and detailed kiosk-specific licensing regime, creating some ambiguity.
Questions this verdict aims to answer
- What money-transmitter / kiosk-specific license is required?
- What cash-transaction reporting thresholds apply?
- What enhanced-KYC obligations attach to cash-in / cash-out?