Centralized exchange in Denmark
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Denmark with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs must register with Finanstilsynet (Danish FSA) and comply with the Money Laundering Act (hvidvaskloven) transposing EU 4th/5th/6th AMLDs.
- Customer identification and verification (KYC) – natural persons: obtain and verify full name, address, date of birth, national ID via reliable independent sources (passport, national ID, driving license with proof of address).
- Customer identification and verification (KYC) – legal entities: obtain and verify entity name, legal form, address, registration number, Articles of Association; identify authorised persons.
- Beneficial ownership identification: identify UBOs of legal entities – any natural person owning or controlling >25% of shares/voting rights or otherwise exercising control; verify via reliable independent sources.
- Purpose and intended nature of the business relationship must be established for all customers.
- Enterprise-wide risk assessment required under § 7 of hvidvaskloven covering customers, products, services, transactions, and geographic areas.
- Enhanced Due Diligence (EDD) required for PEPs, customers from high-risk third countries (EU/FATF list), unusual/complex transactions, and non-face-to-face identification – including senior management approval and source-of-funds/source-of-wealth determination.
- Simplified Due Diligence (SDD) is permitted only in clearly defined low-risk situations, though virtual asset sector is generally considered higher risk.
- Continuous transaction monitoring required under § 13 of hvidvaskloven – scrutiny of transactions consistent with customer knowledge, business, and risk profile; customer information and risk profiles must be kept up-to-date.
- Travel Rule obligations: As a VASP under the EU AML framework transposing 5AMLD, the exchange must implement the FATF Travel Rule for transfers of virtual assets above the applicable threshold – sending VASPs must transmit originator and beneficiary information to receiving VASPs for all transfers (no minimum threshold under MiCA's Transfer of Funds Regulation which applies from Dec 30, 2024).
Key Restrictions
- Must be licensed as a CASP (Crypto-Asset Service Provider) under MiCA, which applies from December 30, 2024 (with Titles III and IV from June 30, 2024), with Finanstilsynet as the competent authority in Denmark.
- Custody segregation: MiCA requires CASPs that hold client crypto-assets to segregate client assets from the operator's own assets, maintain them in separate accounts/wallets, and ensure clients have a direct claim on the assets.
- Market conduct and listing rules: CASPs operating an exchange (trading platform) must publish a detailed crypto-asset admission schedule, ensure fair and orderly trading, prevent market abuse (market manipulation, insider dealing) under MiCA's market abuse provisions, and maintain transparent fee and order-book structures.
- Travel Rule obligations: Under the EU Transfer of Funds Regulation (part of the MiCA/TFR package), VASPs must transmit originator and beneficiary information for all virtual-asset transfers, regardless of amount, from December 30, 2024.
- Issuance of EMTs (e-money tokens) and ARTs (asset-referenced tokens) on the exchange is subject to additional MiCA-specific authorization and reserve requirements – EMT issuance restricted to credit institutions or e-money institutions only.
Key Risks
- MiCA implementation transition risk: The regulatory framework transitions from national AML registration (under hvidvaskloven/5AMLD) to the full MiCA regime from Dec 30, 2024 – operators must ensure a timely and complete transition to avoid regulatory gaps.
- Enforcement precedent: Finanstilsynet has shown willingness to issue public statements and enforce against non-compliant crypto operators; past enforcement actions indicate scrutiny of AML compliance, custody arrangements, and marketing practices.
- Regulatory ambiguity on specific custody segregation requirements under MiCA – further technical standards (RTS) may clarify but create interim uncertainty.
- Market abuse surveillance obligations under MiCA impose significant operational burdens for order-book exchanges, including transaction monitoring for suspicious activity and market manipulation, with potential penalties for non-compliance.
- Travel Rule compliance complexity: The no-threshold requirement under the EU TFR from Dec 30, 2024 imposes significant operational burden for all transfers, including to non-EU counterparties, requiring technology solutions (e.g., TRISA, OpenVASP) that may not be fully mature.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Lov om forebyggende foranstaltninger mod hvidvask og finansiering af terrorisme (hvidvaskloven) – The Money Laundering Act.
This is the core Danish law that transposes the EU's 4th, 5th, and 6th Anti-Money Laundering Directives (AMLDs).
The 5th AMLD (Directive (EU) 2018/843) was particularly significant for bringing virtual asset service providers under the scope of AML/CFT regulations, requiring them to register and comply with the same obligations as traditional financial institutions.
The 6th AMLD (Directive (EU) 2018/1673) primarily harmonises the definition of money laundering offences and associated penalties across member states, indirectly strengthening the overall framework.
Exchange between virtual currencies and fiat currencies.
Natural Persons: Obtain and verify the customer's identity (full name, address, date of birth, national identification number if applicable). Verification must be based on reliable, independent sources (e.g., valid passport, national ID card, driving license combined with proof of address).
Legal Entities: Obtain and verify the entity's name, legal form, address, registration number, and Articles of Association. Identify and verify the identity of the persons who are authorised to act on behalf of the legal entity.
Purpose and Intended Nature of the Business Relationship: Understand the purpose and intended nature of the business relationship or the occasional transaction.
VASPs must identify the ultimate beneficial owner (UBO) of all legal entities and trusts. A UBO is typically any natural person who directly or indirectly owns or controls more than 25% of the shares or voting rights, or otherwise exercises control.
Verification of the UBO's identity is also required, using reliable, independent sources.
VASPs must conduct an enterprise-wide risk assessment (§ 7 of Hvidvaskloven) to identify, assess, and understand the money laundering and terrorist financing risks associated with their customers, products, services, transactions, and geographic areas.
Enhanced Due Diligence (EDD): Required in situations presenting a higher risk of money laundering or terrorist financing. This includes:
Customers who are Politically Exposed Persons (PEPs) or their family members/close associates.
Customers from high-risk third countries (as identified by the EU or FATF).
Situations where the customer is not physically present for identification.
Measures include obtaining senior management approval, taking reasonable measures to establish the source of funds and wealth, and conducting enhanced ongoing monitoring.
Simplified Due Diligence (SDD): Permitted in clearly defined low-risk situations, but these are rare for the virtual asset sector, which is generally considered higher risk.
VASPs must continuously monitor the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship, to ensure that the transactions are consistent with the VASP’s knowledge of the customer, their business, and risk profile (§ 13 of Hvidvaskloven).
Customer information and risk profiles must be kept up-to-date.
E-money Tokens (EMTs): Crypto-assets that aim to maintain a stable value by referencing the value of one official currency (e.g., a EUR-pegged stablecoin).
Asset-Referenced Tokens (ARTs): Crypto-assets that aim to maintain a stable value by referencing any other value or right, or a combination thereof, including one or more official currencies, commodities, or other crypto-assets (e.g., a stablecoin referencing a basket of currencies or gold).
Titles III (ARTs) and IV (EMTs) of MiCA apply from June 30, 2024.
The remaining provisions of MiCA apply from December 30, 2024.
Securities: Stablecoins that qualify as financial instruments (securities) under MiFID II are excluded from MiCA's scope and remain subject to existing securities legislation. However, most common stablecoin designs are unlikely to meet the definition of a transferable security under MiFID II.
EMTs are explicitly classified as a specific type of crypto-asset within MiCA, but their issuance is restricted to entities already authorized as credit institutions or e-money institutions under the E-Money Directive 2009/110/EC (EMD2). MiCA effectively extends and adapts EMD2 rules for EMTs.
Only credit institutions (banks) authorized under the Capital Requirements Directive (CRD IV) or e-money institutions authorized under EMD2 can issue EMTs.
These entities must also notify their competent authority (Finanstilsynet in Denmark) and comply with specific MiCA requirements related to EMTs.
Issuers must be authorized by their competent authority (Finanstilsynet in Denmark) as a "crypto-asset service provider" (CASP) specifically for the issuance of ARTs.
The authorization process requires a detailed application outlining business plans, governance arrangements, operational resilience, and the reserve asset management.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange operating in Denmark must be licensed as a MiCA CASP with Finanstilsynet, comply with full AML/CTF obligations under hvidvaskloven (KYC, CDD, EDD, UBO identification, transaction monitoring), implement custody segregation for client assets, adhere to MiCA market-conduct and market-abuse rules, and comply with the EU Transfer of Funds Regulation (Travel Rule) with no minimum threshold from Dec 30, 2024.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?