Centralized exchange in Spain
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Spain with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASP must register with Banco de España under Law 10/2010 (via Royal Decree-Law 7/2021) and obtain full CASP authorization under MiCA (via CNMV/Banco de España).
- Customer CDD required: verify identity with reliable independent sources (national ID/passport for natural persons; incorporation docs for legal entities).
- Beneficial owner identification for any natural person owning ≥25%+1 share or otherwise controlling the entity.
- CDD triggered at: (a) establishing business relationship, (b) occasional transactions >€1,000 (single or linked), (c) suspicion of ML/TF, (d) doubts about prior CDD data.
- Ongoing monitoring: scrutinize transactions for consistency with customer profile and risk; regularly update CDD documentation.
- Travel Rule: EUR 0 threshold applies (no threshold under TFR recast) — all qualifying transfers must comply with travel-rule data transmission requirements.
- Suspicious transaction reporting (STR) obligations under Law 10/2010 and related regulation.
- Record-keeping obligations for CDD documents and transaction records (typically 5 years post-relationship under EU standards).
Key Restrictions
- Full CASP authorization required — custody of client crypto-assets is a licensed MiCA activity (Articles 53-62 MiCA).
- Custody segregation mandatory: client crypto-assets and funds must be segregated from CASP's own assets and from other clients' assets in accounting records.
- Measures must be taken to ensure client crypto-assets are not available to third-party creditors of the CASP.
- Custody agreement required with each client (Article 38 MiCA).
- Prudential requirements apply: minimum own funds or professional indemnity insurance (Article 67 MiCA); amount depends on service type and risk assessment.
- CNMV mandatory risk warnings on all crypto marketing/advertising (Circular 1/2022 on crypto-asset advertising).
- Local entity incorporation required for CASP authorization under MiCA as an EU-authorised entity.
Key Risks
- Enforcement precedent: CNMV has fined Binance Spain for non-compliance with crypto advertising rules (Circular 1/2022).
- Aggressive enforcement against unregistered entities — hundreds of 'chiringuitos financieros' warned/prohibited (e.g. Bitget, MEXC Global).
- AEPD enforcement: Tools for Humanity (Worldcoin) fined for illicit processing of biometric data — signals privacy regulator scrutiny for novel crypto models.
- Transition period: MiCA implementation is ongoing; operators must manage the shift from pre-MiCA Banco de España registration to full CASP authorization.
- Travel-rule compliance at EUR 0 threshold imposes heavy data transmission burden on all withdrawals/transfers.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
CNMV — Securities market, crypto advertising regulation (mandatory risk warnings)
MiCA Regulation (EU) (2023) — CASP authorization, comprehensive crypto regulation
Law 10/2010 (Anti-Money Laundering) (2010) — Pre-MiCA VASP registration with Banco de Espana
VASP: CASP authorization under MiCA via CNMV/Banco de Espana. 6-12 months. Relatively reasonable registration process — attracted crypto firms.
CUSTODY: CASP authorization — custody is a licensed MiCA activity
EXCHANGE: CASP authorization under MiCA; CNMV mandatory risk warnings on all crypto marketing
Requirement: Under MiCA, providing "custody and administration of crypto-assets on behalf of clients" will require a full authorization (license) from a national competent authority (in Spain, likely the CNMV - Comisión Nacional del Mercado de Valores, or potentially the Bank of Spain, subject to national implementation laws).
Legal Basis: Regulation (EU) 2023/1114 on Markets in Crypto-assets (MiCA).
Key Provisions: Articles 53-62 of MiCA detail the authorization process and requirements for all CASPs, including those offering custody.
MiCA explicitly mandates robust rules for safeguarding client crypto-assets.
CASPs offering custody must enter into a custody agreement with clients.
They must establish and maintain an internal policy outlining how they safeguard client crypto-assets and funds.
Segregation: They must ensure the segregation of clients' crypto-assets and funds from their own assets, and from the assets of other clients, in their accounting records.
They must take adequate measures to ensure that client crypto-assets are not available to third-party creditors of the CASP.
They must establish a policy on the insolvency of the CASP.
MiCA introduces prudential requirements for CASPs.
CASPs will be required to hold a minimum amount of own funds or have a professional indemnity insurance policy, or a combination of both.
The amount will depend on the type of services provided and a risk assessment. For "custody and administration of crypto-assets on behalf of clients," this prudential requirement is set at a higher tier than for some other services.
Key Provisions (Article 37 - MiCA): CASPs must "act honestly, fairly and professionally in accordance with the best interests of their clients" and "implement sound administrative arrangements, which ensure the protection of clients' data." Article 38 also requires "robust security arrangements."
Prudential requirements (capital/insurance).
Organizational requirements (governance, risk management, internal controls).
Operational requirements (IT systems, security, business continuity).
Directive (EU) 2015/849 (4th AMLD): The foundational directive, which brought more entities into scope and strengthened CDD.
Directive (EU) 2018/843 (5th AMLD): Crucially, this directive extended the scope of AML/CFT rules to include virtual asset service providers (VASPs), specifically:
Providers engaged in exchange services between virtual currencies and fiat currencies.
Directive (EU) 2018/1673 (6th AMLD): Primarily focuses on harmonizing the definition of money laundering criminal offenses and related sanctions across the EU, which indirectly supports the AML framework.
Ley 10/2010, de 28 de abril, de prevención del blanqueo de capitales y de la financiación del terrorismo (Law 10/2010, of April 28, on the prevention of money laundering and terrorist financing).
Real Decreto 304/2014, de 5 de mayo, por el que se aprueba el Reglamento de la Ley 10/2010 (Royal Decree 304/2014, of May 5, approving the Regulation of Law 10/2010): This Royal Decree provides detailed rules for the implementation of Law 10/2010. It also has been amended to reflect EU changes.
Real Decreto-ley 7/2021, de 27 de abril (Royal Decree-Law 7/2021, of April 27): This specific decree transposed significant parts of the 5th AMLD, formally bringing VASPs under the scope of Law 10/2010 and establishing the requirement for their registration with the Bank of Spain.
Circular 2/2022 del Banco de España, de 23 de marzo (Circular 2/2022 of the Bank of Spain, of March 23): This circular specifically regulates the administrative registration of providers of virtual currency exchange services for fiat currency and electronic wallet custody services.
Identification and Verification of the Customer:
Natural Persons: Obtain and verify identity using reliable independent sources (e.g., national ID card, passport). Required data includes full name, date and place of birth, address, and national identification number.
Legal Persons/Entities: Obtain and verify the name, legal form, address, proof of incorporation, articles of association, names of directors, and the legal representative(s).
Identification and Verification of the Customer:
For legal entities, identify any natural person(s) who ultimately own or control 25% plus one share or more of the entity, or who otherwise exercise control.
If no such natural person is identified, identify the natural person(s) who hold the position of senior managing official(s).
Understanding the Purpose and Intended Nature of the Business Relationship:
VASPs must gather information about the client's typical transaction volumes, types of virtual assets, and the source of funds/wealth where necessary.
Ongoing Monitoring of the Business Relationship:
Scrutinizing transactions undertaken throughout the course of the relationship to ensure consistency with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Regularly updating customer information, including CDD documentation.
Establishing a business relationship.
Carrying out occasional transactions exceeding €1,000 (whether in a single transaction or several linked transactions).
Where there is suspicion of money laundering or terrorist financing.
When there are doubts about the veracity or adequacy of previously obtained customer identification data.
Travel Rule adopted — threshold: EUR 0 (no threshold under TFR recast)
Entity Targeted: Binance (specifically, Binance Spain S.L.). Violation Type: Non-compliance with the CNMV's Circular 1/2022 on advertising of crypto-assets. The alleged violations included insufficient disclosure of risks, lack of clarity, and inadequate warnings in advertising campaigns. Outcome: Fine imposed and publicly announced. This marked a significant enforcement of Spain's relatively new crypto advertising rules.
Entity Targeted: Tools for Humanity Corp. (the company behind the Worldcoin project). Violation Type: Illicit processing of personal data (especially sensitive biometric data like iris scans), lack of transparency, insufficient information provided to users, and processing of data of minors. Penalty Amount: Precautionary measure imposing an immediate prohibition on the collection and processing of personal data by Worldcoin in Spain. A final fine amount will be determined after a full investigation, potentially reaching up to €20 million for GDPR violations. Outcome: Precautionary measure imposed, requiring Worldcoin to cease all data collection and processing activities in Spain related to its iris scanning. Investigation ongoing. This is a very significant action due to its direct operational impact and the novelty of regulating biometric data in a crypto context.
Entity Targeted: Numerous (hundreds) of unregistered entities operating in the cryptocurrency and forex markets, often referred to as "chiringuitos financieros" (financial boiler rooms). Specific examples include warnings against companies like Bitget, MEXC Global, and countless smaller, fraudulent-appearing platforms. Violation Type: Offering investment services or products related to crypto assets in Spain without the required authorization or registration with the CNMV. This often includes deceptive advertising practices. Penalty Amount: While not a single "fine," the outcome is a public warning, inclusion on the CNMV's "grey list" (list of unauthorized firms), and potential legal action or blocking of access within Spain. This effectively prohibits their operations in Spain and serves as a public consumer alert. Outcome: Prohibition of unauthorized operations in Spain, public consumer warning, and potential escalation to legal action. This proactive enforcement has been a continuous and significant effort to protect investors.
Outcome: Fine imposed and publicly announced. This marked a significant enforcement of Spain's relatively new crypto advertising rules.
Outcome: Prohibition of unauthorized operations in Spain, public consumer warning, and potential escalation to legal action. This proactive enforcement has been a continuous and significant effort to protect investors.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange can operate in Spain but must obtain full MiCA CASP authorization (via CNMV/Banco de España), comply with strict custody segregation and prudential requirements (Articles 37-38, 53-62, 67 MiCA), implement AML/CFT controls under Law 10/2010 and Circular 2/2022, and comply with a zero-threshold travel rule under the TFR recast.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?