← Regulations / Spain / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Spain

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Spain with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Custodial wallet providers are explicitly classified as VASPs under 5th AMLD (EU 2018/843) transposed via Royal Decree-Law 7/2021, requiring full AML/CFT compliance.
  • Registration with Banco de España's VASP registry under Circular 2/2022 is mandatory before commencing operations.
  • Customer Due Diligence (CDD) is required at: establishing a business relationship; occasional transactions exceeding €1,000; any suspicion of ML/TF; and doubts about existing identification data (Law 10/2010, Royal Decree 304/2014).
  • CDD must include: identification/verification of natural persons (reliable independent sources, full name, DOB, address, national ID), legal persons (name, legal form, incorporation docs, directors, representatives), and beneficial owners (25%+1 share threshold).
  • Ongoing monitoring: scrutinize transactions for consistency with client profile, source of funds/wealth where necessary, and regularly update CDD documentation.
  • Obligation to understand the purpose and intended nature of the business relationship, including typical transaction volumes, types of virtual assets, and source of funds/wealth.
  • Suspicious Transaction Reports (STRs) to SEPBLAC (Spain's Financial Intelligence Unit) are required.

Key Restrictions

  • Full MiCA CASP authorization (license) is required for providing 'custody and administration of crypto-assets on behalf of clients' — this covers the custodial wallet/SaaS operator directly.
  • A formal custody agreement must be entered into with each client (Article 38 MiCA).
  • Client crypto-assets and funds must be segregated from the CASP's own assets and from other clients' assets in accounting records.
  • Adequate measures must be taken to ensure client crypto-assets are not available to third-party creditors of the CASP (insolvency protection).
  • A policy on insolvency of the CASP must be established and maintained.
  • Prudential requirements apply: minimum own funds or professional indemnity insurance based on the type of services and risk assessment (Article 67 MiCA); custody is at a higher tier.
  • Robust security arrangements are required (Article 37 MiCA), implying industry best practices such as multi-sig, HSMs, and segregated cold/warm storage even though not explicitly mandated.
  • CNMV mandatory risk warnings are required on all crypto-asset marketing and advertising (Circular 1/2022).
  • The SaaS operator (the CASP), not the white-label client, bears primary regulatory responsibility for custody, AML, and segregation — though the client may have separate obligations.

Key Risks

  • Enforcement precedent: CNMV has actively fined entities (e.g., Binance Spain S.L.) for non-compliance with advertising rules under Circular 1/2022, and has issued hundreds of warnings against unregistered operators ('chiringuitos financieros').
  • MiCA authorization is a multi-month process (6-12 months) and represents a significant step up from Spain's pre-MiCA VASP registration framework.
  • The AEPD (data protection authority) has taken aggressive enforcement action — e.g., the €200M+ fine against Worldcoin/Tools for Humanity — meaning privacy and biometric data risks are acute for wallet operators handling personal data.
  • Ambiguity on allocation of AML responsibilities between the SaaS custodial operator and the white-label client could create compliance gaps if not clearly contracted and supervised.
  • Serving Spanish residents without proper Banco de España registration or MiCA authorization exposes the operator to enforcement prohibition and public consumer warnings.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 40% confidence

Requirement: Under MiCA, providing "custody and administration of crypto-assets on behalf of clients" will require a full authorization (license) from a national competent authority (in Spain, likely the CNMV - Comisión Nacional del Mercado de Valores, or potentially the Bank of Spain, subject to national implementation laws).

custody 40% confidence

Legal Basis: Regulation (EU) 2023/1114 on Markets in Crypto-assets (MiCA).

custody 40% confidence

Key Provisions: Articles 53-62 of MiCA detail the authorization process and requirements for all CASPs, including those offering custody.

custody 40% confidence

Key Provisions (Article 38 - MiCA):

custody 40% confidence

CASPs offering custody must enter into a custody agreement with clients.

custody 40% confidence

They must establish and maintain an internal policy outlining how they safeguard client crypto-assets and funds.

custody 40% confidence

Segregation: They must ensure the segregation of clients' crypto-assets and funds from their own assets, and from the assets of other clients, in their accounting records.

custody 40% confidence

They must take adequate measures to ensure that client crypto-assets are not available to third-party creditors of the CASP.

custody 40% confidence

They must establish a policy on the insolvency of the CASP.

custody 40% confidence

MiCA introduces prudential requirements for CASPs.

custody 40% confidence

Key Provisions (Article 67 - MiCA):

custody 40% confidence

CASPs will be required to hold a minimum amount of own funds or have a professional indemnity insurance policy, or a combination of both.

custody 40% confidence

The amount will depend on the type of services provided and a risk assessment. For "custody and administration of crypto-assets on behalf of clients," this prudential requirement is set at a higher tier than for some other services.

custody 40% confidence

This aims to cover potential liability risks, including operational risks and professional negligence.

custody 40% confidence

While MiCA does not explicitly mandate "cold storage," it places strong emphasis on robust security arrangements, operational resilience, and integrity of systems.

custody 40% confidence

Key Provisions (Article 37 - MiCA): CASPs must "act honestly, fairly and professionally in accordance with the best interests of their clients" and "implement sound administrative arrangements, which ensure the protection of clients' data." Article 38 also requires "robust security arrangements."

custody 40% confidence

The requirement for sound operational and security measures would naturally lead custodians to adopt industry best practices, including sophisticated multi-signature schemes, hardware security modules (HSMs), and segregated "cold" or "warm" storage solutions, even if the specific technology isn't dictated.

custody 40% confidence

Under MiCA, entities authorized to provide "custody and administration of crypto-assets on behalf of clients" will effectively be the "qualified custodians" within the EU regulatory framework.

custody 40% confidence

MiCA sets out detailed requirements for these authorized entities, including:

custody 40% confidence

Prudential requirements (capital/insurance).

custody 40% confidence

Organizational requirements (governance, risk management, internal controls).

custody 40% confidence

Operational requirements (IT systems, security, business continuity).

licensing 80% confidence

CNMV — Securities market, crypto advertising regulation (mandatory risk warnings)

licensing 80% confidence

Banco de Espana — VASP registration, AML/CFT

licensing 20% confidence

MiCA Regulation (EU) (2023) — CASP authorization, comprehensive crypto regulation

licensing 20% confidence

Law 10/2010 (Anti-Money Laundering) (2010) — Pre-MiCA VASP registration with Banco de Espana

licensing 20% confidence

VASP: CASP authorization under MiCA via CNMV/Banco de Espana. 6-12 months. Relatively reasonable registration process — attracted crypto firms.

licensing 20% confidence

CUSTODY: CASP authorization — custody is a licensed MiCA activity

aml 60% confidence

Directive (EU) 2015/849 (4th AMLD): The foundational directive, which brought more entities into scope and strengthened CDD.

aml 60% confidence

Directive (EU) 2018/843 (5th AMLD): Crucially, this directive extended the scope of AML/CFT rules to include virtual asset service providers (VASPs), specifically:

aml 60% confidence

Custodian wallet providers.

aml 60% confidence

Ley 10/2010, de 28 de abril, de prevención del blanqueo de capitales y de la financiación del terrorismo (Law 10/2010, of April 28, on the prevention of money laundering and terrorist financing).

aml 60% confidence

Real Decreto 304/2014, de 5 de mayo, por el que se aprueba el Reglamento de la Ley 10/2010 (Royal Decree 304/2014, of May 5, approving the Regulation of Law 10/2010): This Royal Decree provides detailed rules for the implementation of Law 10/2010. It also has been amended to reflect EU changes.

aml 60% confidence

Real Decreto-ley 7/2021, de 27 de abril (Royal Decree-Law 7/2021, of April 27): This specific decree transposed significant parts of the 5th AMLD, formally bringing VASPs under the scope of Law 10/2010 and establishing the requirement for their registration with the Bank of Spain.

aml 60% confidence

Circular 2/2022 del Banco de España, de 23 de marzo (Circular 2/2022 of the Bank of Spain, of March 23): This circular specifically regulates the administrative registration of providers of virtual currency exchange services for fiat currency and electronic wallet custody services.

aml 60% confidence

Identification and Verification of the Customer:

aml 60% confidence

Natural Persons: Obtain and verify identity using reliable independent sources (e.g., national ID card, passport). Required data includes full name, date and place of birth, address, and national identification number.

aml 60% confidence

Legal Persons/Entities: Obtain and verify the name, legal form, address, proof of incorporation, articles of association, names of directors, and the legal representative(s).

aml 60% confidence

Identification and Verification of the Customer:

aml 60% confidence

For legal entities, identify any natural person(s) who ultimately own or control 25% plus one share or more of the entity, or who otherwise exercise control.

aml 60% confidence

If no such natural person is identified, identify the natural person(s) who hold the position of senior managing official(s).

aml 60% confidence

Understanding the Purpose and Intended Nature of the Business Relationship:

aml 60% confidence

VASPs must gather information about the client's typical transaction volumes, types of virtual assets, and the source of funds/wealth where necessary.

aml 60% confidence

Ongoing Monitoring of the Business Relationship:

aml 60% confidence

Scrutinizing transactions undertaken throughout the course of the relationship to ensure consistency with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.

aml 60% confidence

Regularly updating customer information, including CDD documentation.

aml 60% confidence

When CDD is Required:

aml 60% confidence

Establishing a business relationship.

aml 60% confidence

Carrying out occasional transactions exceeding €1,000 (whether in a single transaction or several linked transactions).

aml 60% confidence

Where there is suspicion of money laundering or terrorist financing.

aml 60% confidence

When there are doubts about the veracity or adequacy of previously obtained customer identification data.

enforcement 50% confidence

Entity Targeted: Binance (specifically, Binance Spain S.L.). Violation Type: Non-compliance with the CNMV's Circular 1/2022 on advertising of crypto-assets. The alleged violations included insufficient disclosure of risks, lack of clarity, and inadequate warnings in advertising campaigns. Outcome: Fine imposed and publicly announced. This marked a significant enforcement of Spain's relatively new crypto advertising rules.

enforcement 50% confidence

Entity Targeted: Tools for Humanity Corp. (the company behind the Worldcoin project). Violation Type: Illicit processing of personal data (especially sensitive biometric data like iris scans), lack of transparency, insufficient information provided to users, and processing of data of minors. Penalty Amount: Precautionary measure imposing an immediate prohibition on the collection and processing of personal data by Worldcoin in Spain. A final fine amount will be determined after a full investigation, potentially reaching up to €20 million for GDPR violations. Outcome: Precautionary measure imposed, requiring Worldcoin to cease all data collection and processing activities in Spain related to its iris scanning. Investigation ongoing. This is a very significant action due to its direct operational impact and the novelty of regulating biometric data in a crypto context.

enforcement 50% confidence

Entity Targeted: Numerous (hundreds) of unregistered entities operating in the cryptocurrency and forex markets, often referred to as "chiringuitos financieros" (financial boiler rooms). Specific examples include warnings against companies like Bitget, MEXC Global, and countless smaller, fraudulent-appearing platforms. Violation Type: Offering investment services or products related to crypto assets in Spain without the required authorization or registration with the CNMV. This often includes deceptive advertising practices. Penalty Amount: While not a single "fine," the outcome is a public warning, inclusion on the CNMV's "grey list" (list of unauthorized firms), and potential legal action or blocking of access within Spain. This effectively prohibits their operations in Spain and serves as a public consumer alert. Outcome: Prohibition of unauthorized operations in Spain, public consumer warning, and potential escalation to legal action. This proactive enforcement has been a continuous and significant effort to protect investors.

enforcement 70% confidence

Legal Basis: Regulation (EU) 2023/1114 on Markets in Crypto-assets (MiCA).

enforcement 50% confidence

Outcome: Prohibition of unauthorized operations in Spain, public consumer warning, and potential escalation to legal action. This proactive enforcement has been a continuous and significant effort to protect investors.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a custodial wallet / SaaS operator providing "custody and administration of crypto-assets on behalf of clients" in Spain requires full MiCA CASP authorization from the CNMV/Banco de España (a high-burden, multi-month licensing process), must comply with strict segregation, prudential, and security requirements under MiCA Articles 37-38 and 67, and bears extensive AML/CFT obligations under Law 10/2010 and Banco de España Circular 2/2022, with the SaaS operator (not the white-label client) holding primary regulatory responsibility for custody and AML.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?