DeFi protocol frontend in Denmark
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Denmark with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration as a VASP / CASP with Finanstilsynet (Derivative of EU 5th AMLD transposed via Hvidvaskloven) if the frontend exercises control, takes custody, or charges fees such that it is deemed to be 'providing services related to virtual assets'.
- Customer due diligence obligations: verify identity (full name, address, DOB) using reliable independent sources (valid passport, national ID) for natural persons.
- For legal entities: verify name, legal form, address, registration number, articles of association, and authorized representatives.
- Identify and verify ultimate beneficial owners (UBOs) where ownership/control exceeds 25%.
- Conduct enterprise-wide risk assessment under §7 of Hvidvaskloven covering customers, products, services, transactions, and geographic areas.
- Enhanced Due Diligence (EDD) required for PEPs, customers from high-risk third countries, unusual/complex transactions, and non-face-to-face identification.
- Continuous transaction monitoring under §13 of Hvidvaskloven to ensure consistency with customer risk profile.
- Ongoing obligation to keep customer information and risk profiles up-to-date.
- Simplified Due Diligence (SDD) rarely available for virtual asset sector — generally considered higher risk.
Key Restrictions
- If the frontend merely provides an interface to permissionless smart contracts without taking custody, charging fees, or exercising control — it may fall outside regulated VASP/CASP scope, but this is legally untested and risky.
- Fee-taking (e.g., frontend fee, swap fee, interface fee) likely triggers classification as 'providing services related to virtual assets' under Hvidvaskloven, bringing full AML/KYC obligations.
- Geofencing to block Danish residents is a potential risk-mitigation strategy to avoid triggering Danish regulatory nexus, but does not guarantee non-applicability of EU/MiCA rules.
- MiCA applies from December 30, 2024 (general provisions) — if the frontend involves self-custodial wallets and no intermediary function, classification remains ambiguous.
- If the frontend is deemed a crypto-asset service provider (CASP) under MiCA, authorization with Finanstilsynet is required, including detailed application on governance, operational resilience, and business plans.
Key Risks
- Regulatory ambiguity: no clear Danish precedent on whether a non-custodial, fee-taking frontend to a DeFi protocol is a regulated VASP/CASP activity.
- Enforcement risk: Finanstilsynet may take the view that any frontend that charges fees and targets Danish users is 'providing services related to virtual assets' and must comply with AML registration.
- MiCA implementation: as of the transition period, national rules (Hvidvaskloven) still govern VASP definitions; post-MiCA, the CASP definition may capture frontends more clearly.
- No safe harbor for 'non-custodial' frontends in current Danish/EU regulation — unlike pure protocol developers, the frontend operator has a commercial nexus.
- Exposure to fines and criminal liability for operating without required AML registration if Finanstilsynet classifies the activity as regulated.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Lov om forebyggende foranstaltninger mod hvidvask og finansiering af terrorisme (hvidvaskloven) – The Money Laundering Act.
This is the core Danish law that transposes the EU's 4th, 5th, and 6th Anti-Money Laundering Directives (AMLDs).
The 5th AMLD (Directive (EU) 2018/843) was particularly significant for bringing virtual asset service providers under the scope of AML/CFT regulations, requiring them to register and comply with the same obligations as traditional financial institutions.
Exchange between virtual currencies and fiat currencies.
Natural Persons: Obtain and verify the customer's identity (full name, address, date of birth, national identification number if applicable). Verification must be based on reliable, independent sources (e.g., valid passport, national ID card, driving license combined with proof of address).
Legal Entities: Obtain and verify the entity's name, legal form, address, registration number, and Articles of Association. Identify and verify the identity of the persons who are authorised to act on behalf of the legal entity.
Purpose and Intended Nature of the Business Relationship: Understand the purpose and intended nature of the business relationship or the occasional transaction.
VASPs must identify the ultimate beneficial owner (UBO) of all legal entities and trusts. A UBO is typically any natural person who directly or indirectly owns or controls more than 25% of the shares or voting rights, or otherwise exercises control.
Verification of the UBO's identity is also required, using reliable, independent sources.
VASPs must conduct an enterprise-wide risk assessment (§ 7 of Hvidvaskloven) to identify, assess, and understand the money laundering and terrorist financing risks associated with their customers, products, services, transactions, and geographic areas.
Enhanced Due Diligence (EDD): Required in situations presenting a higher risk of money laundering or terrorist financing. This includes:
Customers who are Politically Exposed Persons (PEPs) or their family members/close associates.
Customers from high-risk third countries (as identified by the EU or FATF).
Situations where the customer is not physically present for identification.
Measures include obtaining senior management approval, taking reasonable measures to establish the source of funds and wealth, and conducting enhanced ongoing monitoring.
Simplified Due Diligence (SDD): Permitted in clearly defined low-risk situations, but these are rare for the virtual asset sector, which is generally considered higher risk.
VASPs must continuously monitor the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship, to ensure that the transactions are consistent with the VASP’s knowledge of the customer, their business, and risk profile (§ 13 of Hvidvaskloven).
Customer information and risk profiles must be kept up-to-date.
The remaining provisions of MiCA apply from December 30, 2024.
Titles III (ARTs) and IV (EMTs) of MiCA apply from June 30, 2024.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — DeFi frontends that charge fees or exercise control over user interactions likely constitute regulated VASP/CASP activity requiring AML registration with Finanstilsynet and full KYC/CDD obligations, but the non-custodial, protocol-interface nature creates significant legal ambiguity with no clear Danish precedent.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?