Remote VASP serving residents in Denmark
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Denmark with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Registration as a VASP with Finanstilsynet (the Danish FSA) is required under the Money Laundering Act (Hvidvaskloven), which transposes EU 4th-6th AMLDs including 5AMLD coverage of VASPs.
- Customer due diligence (CDD): identify and verify identity of natural persons (name, address, DOB, national ID) and legal entities (name, legal form, address, registration number, articles, authorized persons).
- Beneficial ownership identification: identify and verify UBOs (≥25% ownership/control) of legal entities and trusts.
- Enterprise-wide risk assessment required under § 7 of Hvidvaskloven covering customers, products, services, transactions, and geographies.
- Enhanced Due Diligence (EDD) required for PEPs, high-risk third-country customers, unusual/complex transactions, and non-face-to-face onboarding.
- Simplified Due Diligence (SDD) rarely available for the virtual asset sector, which is generally treated as higher risk.
- Continuous transaction monitoring under § 13 of Hvidvaskloven to ensure transactions match customer knowledge and risk profile.
- Suspicious transaction reporting (STR) obligations to the Danish Financial Intelligence Unit.
- Records retention obligations under AML rules.
Key Restrictions
- Must be authorized as a crypto-asset service provider (CASP) by Finanstilsynet under MiCA, which took effect from December 30, 2024 (with Titles III/IV on ARTs and EMTs from June 30, 2024).
- Cross-border service to Danish residents without a local entity and authorization is not permitted — a non-EU operator must establish an EU/EEA entity to obtain MiCA authorization and passport into Denmark.
- EMT issuance restricted to credit institutions or e-money institutions; ARTs require specific CASP authorization for issuance.
- Purely algorithmic stablecoins without robust reserves are effectively prohibited under MiCA.
- No exemption for foreign-incorporated entities serving residents remotely — the activity triggers Danish/MiCA licensing requirements.
Key Risks
- Unlicensed remote operation targeting Danish residents carries high enforcement risk — Finanstilsynet has the power to issue cease-and-desist orders, public warnings, and coordinate with EU competent authorities under MiCA.
- Binance-style enforcement precedent: unlicensed cross-border VASPs targeting EU residents have faced coordinated regulatory action across EU member states.
- Reclassification risk: if an offered crypto-asset qualifies as a financial instrument (MiFID II), additional securities laws may apply beyond VASP/CASP licensing.
- Tax and PR exposure: operating without Danish registration may attract negative attention from consumers, media, and regulators.
- Ambiguity around the precise scope of 'other services related to virtual assets' under Danish AML law could expand obligations unexpectedly.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Lov om forebyggende foranstaltninger mod hvidvask og finansiering af terrorisme (hvidvaskloven) – The Money Laundering Act.
This is the core Danish law that transposes the EU's 4th, 5th, and 6th Anti-Money Laundering Directives (AMLDs).
The 5th AMLD (Directive (EU) 2018/843) was particularly significant for bringing virtual asset service providers under the scope of AML/CFT regulations, requiring them to register and comply with the same obligations as traditional financial institutions.
Exchange between virtual currencies and fiat currencies.
Natural Persons: Obtain and verify the customer's identity (full name, address, date of birth, national identification number if applicable). Verification must be based on reliable, independent sources (e.g., valid passport, national ID card, driving license combined with proof of address).
Legal Entities: Obtain and verify the entity's name, legal form, address, registration number, and Articles of Association. Identify and verify the identity of the persons who are authorised to act on behalf of the legal entity.
Purpose and Intended Nature of the Business Relationship: Understand the purpose and intended nature of the business relationship or the occasional transaction.
VASPs must identify the ultimate beneficial owner (UBO) of all legal entities and trusts. A UBO is typically any natural person who directly or indirectly owns or controls more than 25% of the shares or voting rights, or otherwise exercises control.
Verification of the UBO's identity is also required, using reliable, independent sources.
VASPs must conduct an enterprise-wide risk assessment (§ 7 of Hvidvaskloven) to identify, assess, and understand the money laundering and terrorist financing risks associated with their customers, products, services, transactions, and geographic areas.
Enhanced Due Diligence (EDD): Required in situations presenting a higher risk of money laundering or terrorist financing. This includes:
Customers who are Politically Exposed Persons (PEPs) or their family members/close associates.
Customers from high-risk third countries (as identified by the EU or FATF).
Situations where the customer is not physically present for identification.
Measures include obtaining senior management approval, taking reasonable measures to establish the source of funds and wealth, and conducting enhanced ongoing monitoring.
Simplified Due Diligence (SDD): Permitted in clearly defined low-risk situations, but these are rare for the virtual asset sector, which is generally considered higher risk.
VASPs must continuously monitor the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship, to ensure that the transactions are consistent with the VASP’s knowledge of the customer, their business, and risk profile (§ 13 of Hvidvaskloven).
Customer information and risk profiles must be kept up-to-date.
The remaining provisions of MiCA apply from December 30, 2024.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Danish residents must be established as an EU/EEA entity authorized as a CASP under MiCA (with Finanstilsynet as competent authority), comply fully with the Danish Money Laundering Act (Hvidvaskloven) AML obligations, and cannot serve residents from a non-EU jurisdiction without local incorporation and licensing.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?