← Regulations / Denmark / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Denmark

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Denmark with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • VASPs (including custodian wallet providers) must register as CASPs under MiCA and comply with the Danish hvidvaskloven (Money Laundering Act) transposing EU 4th/5th/6th AMLDs — dk.aml.lov-om-forebyggende-foranstaltninger-mod, dk.aml.this-is-the-core-danish, dk.aml.the-5th-amld-directive-eu, dk.aml.the-6th-amld-directive-eu
  • Custodian wallet providers are explicitly captured as obligated entities — dk.aml.are-custodian-wallet-providers
  • Customer identification and verification (KYC) for natural and legal persons, including name, address, DOB, registration details, using reliable independent sources — dk.aml.identification-and-verification-of-the, dk.aml.natural-persons-obtain-and-verify, dk.aml.legal-entities-obtain-and-verify
  • Purpose-and-intended-nature-of-business-relationship assessment required — dk.aml.purpose-and-intended-nature-of
  • UBO identification required (25%+ ownership/control threshold) — dk.aml.identification-of-beneficial-owners, dk.aml.vasps-must-identify-the-ultimate, dk.aml.verification-of-the-ubos-identity
  • Enterprise-wide risk assessment required under § 7 of hvidvaskloven — dk.aml.vasps-must-conduct-an-enterprise-wide
  • Enhanced Due Diligence (EDD) required for PEPs, high-risk third countries, unusual transactions, and non-face-to-face onboarding — dk.aml.customers-who-are-politically-exposed, dk.aml.customers-from-high-risk-third-countries, dk.aml.unusual-or-complex-transactions, dk.aml.situations-where-the-customer-is, dk.aml.measures-include-obtaining-senior-management
  • Simplified Due Diligence (SDD) rarely available for virtual asset sector (generally considered higher risk) — dk.aml.simplified-due-diligence-sdd-permitted
  • Continuous transaction monitoring and ongoing due diligence under § 13 of hvidvaskloven — dk.aml.vasps-must-continuously-monitor-the, dk.aml.customer-information-and-risk-profiles
  • Exchange between fiat and virtual currencies, exchange between virtual currencies, and other services related to virtual assets are all covered activities — dk.aml.exchange-between-virtual-currencies-and, dk.aml.exchange-between-one-or-more, dk.aml.provide-other-services-related-to

Key Restrictions

  • Must be licensed as a CASP (crypto-asset service provider) under MiCA with authorization from Finanstilsynet (Danish FSA) — dk.enforcement.issuers-must-be-authorized-by, dk.enforcement.the-authorization-process-requires-a
  • If the custodian wallet holds EMTs (e-money tokens), the issuer of those tokens must be a credit institution or e-money institution — dk.enforcement.only-credit-institutions-banks-authorized — but this applies to the token issuer, not necessarily the wallet SaaS provider itself
  • Full MiCA provisions apply from December 30, 2024 for most crypto-asset services, with Titles III/IV (ARTs/EMTs) applying from June 30, 2024 — dk.enforcement.titles-iii-arts-and-iv, dk.enforcement.the-remaining-provisions-of-mica
  • EMT holders have a statutory redemption right (1:1 at par) — dk.enforcement.holders-of-emts-have-the — may affect wallet design if the SaaS provider also issues EMTs
  • Reserve assets for stablecoin-related services must be segregated in accounts with credit institutions and invested only in highly liquid low-risk assets — dk.enforcement.the-reserve-assets-must-be, dk.enforcement.they-must-be-invested-only
  • SaaS provider and white-label client likely share AML responsibility; provider must conduct enterprise-wide risk assessment covering its full platform — dk.aml.vasps-must-conduct-an-enterprise-wide

Key Risks

  • Regulatory ambiguity around allocation of AML obligations between SaaS custodian-wallet provider and white-label client — unclear if each white-label client needs separate CASP authorization or can rely on the SaaS provider's license
  • 155 additional facts omitted from input may contain material details on custody-specific requirements (segregation, insurance, proof-of-reserves) — incomplete source coverage
  • MiCA transitional periods create compliance risk if operator launches before full applicability (Dec 30, 2024)
  • Purely algorithmic stablecoins (no robust reserves) are effectively prohibited under MiCA — dk.enforcement.algorithmic-stablecoins-without-robust-reserves — restricts certain product designs

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

aml 40% confidence

Lov om forebyggende foranstaltninger mod hvidvask og finansiering af terrorisme (hvidvaskloven) – The Money Laundering Act.

aml 40% confidence

This is the core Danish law that transposes the EU's 4th, 5th, and 6th Anti-Money Laundering Directives (AMLDs).

aml 40% confidence

The 5th AMLD (Directive (EU) 2018/843) was particularly significant for bringing virtual asset service providers under the scope of AML/CFT regulations, requiring them to register and comply with the same obligations as traditional financial institutions.

aml 40% confidence

The 6th AMLD (Directive (EU) 2018/1673) primarily harmonises the definition of money laundering offences and associated penalties across member states, indirectly strengthening the overall framework.

aml 40% confidence

Exchange between virtual currencies and fiat currencies.

aml 40% confidence

Exchange between one or more virtual currencies.

aml 40% confidence

Are custodian wallet providers.

aml 40% confidence

Provide other services related to virtual assets.

aml 40% confidence

Identification and Verification of the Customer:

aml 40% confidence

Natural Persons: Obtain and verify the customer's identity (full name, address, date of birth, national identification number if applicable). Verification must be based on reliable, independent sources (e.g., valid passport, national ID card, driving license combined with proof of address).

aml 40% confidence

Legal Entities: Obtain and verify the entity's name, legal form, address, registration number, and Articles of Association. Identify and verify the identity of the persons who are authorised to act on behalf of the legal entity.

aml 40% confidence

Purpose and Intended Nature of the Business Relationship: Understand the purpose and intended nature of the business relationship or the occasional transaction.

aml 40% confidence

Identification of Beneficial Owners:

aml 40% confidence

VASPs must identify the ultimate beneficial owner (UBO) of all legal entities and trusts. A UBO is typically any natural person who directly or indirectly owns or controls more than 25% of the shares or voting rights, or otherwise exercises control.

aml 40% confidence

Verification of the UBO's identity is also required, using reliable, independent sources.

aml 40% confidence

VASPs must conduct an enterprise-wide risk assessment (§ 7 of Hvidvaskloven) to identify, assess, and understand the money laundering and terrorist financing risks associated with their customers, products, services, transactions, and geographic areas.

aml 40% confidence

Enhanced Due Diligence (EDD): Required in situations presenting a higher risk of money laundering or terrorist financing. This includes:

aml 40% confidence

Customers who are Politically Exposed Persons (PEPs) or their family members/close associates.

aml 40% confidence

Customers from high-risk third countries (as identified by the EU or FATF).

aml 40% confidence

Unusual or complex transactions.

aml 40% confidence

Situations where the customer is not physically present for identification.

aml 40% confidence

Measures include obtaining senior management approval, taking reasonable measures to establish the source of funds and wealth, and conducting enhanced ongoing monitoring.

aml 40% confidence

Simplified Due Diligence (SDD): Permitted in clearly defined low-risk situations, but these are rare for the virtual asset sector, which is generally considered higher risk.

aml 40% confidence

VASPs must continuously monitor the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship, to ensure that the transactions are consistent with the VASP’s knowledge of the customer, their business, and risk profile (§ 13 of Hvidvaskloven).

aml 40% confidence

Customer information and risk profiles must be kept up-to-date.

enforcement 60% confidence

Only credit institutions (banks) authorized under the Capital Requirements Directive (CRD IV) or e-money institutions authorized under EMD2 can issue EMTs.

enforcement 60% confidence

The reserve assets must be held in segregated accounts with credit institutions.

enforcement 60% confidence

They must be invested only in highly liquid, low-risk assets and in a manner that ensures stability and sufficient liquidity.

enforcement 60% confidence

Issuers must be authorized by their competent authority (Finanstilsynet in Denmark) as a "crypto-asset service provider" (CASP) specifically for the issuance of ARTs.

enforcement 60% confidence

The authorization process requires a detailed application outlining business plans, governance arrangements, operational resilience, and the reserve asset management.

enforcement 60% confidence

Holders of EMTs have the right to redeem them at par value (1:1) for the underlying official currency at any time, free of charge (with exceptions for fees for non-active users, similar to e-money).

enforcement 60% confidence

Algorithmic Stablecoins (without robust reserves): MiCA effectively prohibits purely algorithmic stablecoins that do not maintain a stable value through reserves (see section 5 below).

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
low

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a custodial wallet / SaaS provider can operate in Denmark but must be authorized as a CASP under MiCA by Finanstilsynet, comply with the full AML framework under the Danish Money Laundering Act (hvidvaskloven), and faces significant ambiguity on how AML obligations split between SaaS provider and white-label clients; key facts on specific custody rules (asset segregation, insurance, proof-of-reserves) were omitted from the source material, limiting confidence.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?