DeFi protocol frontend in Spain
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Spain with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD required when establishing a business relationship (es.aml.when-cdd-is-required)
- CDD required for occasional transactions exceeding €1,000 (es.aml.carrying-out-occasional-transactions-exceeding)
- CDD required where there is suspicion of ML/TF (es.aml.where-there-is-suspicion-of)
- Natural person identification: full name, DOB, address, national ID number from reliable independent sources (es.aml.natural-persons-obtain-and-verify)
- Legal entity identification: name, legal form, address, proof of incorporation, articles, directors, legal rep (es.aml.legal-personsentities-obtain-and-verify)
- Beneficial owner identification: natural person(s) owning/controlling 25%+1 share or otherwise exercising control (es.aml.for-legal-entities-identify-any)
- If no BO identified, identify senior managing official(s) (es.aml.if-no-such-natural-person)
- Gather information on typical transaction volumes, types of virtual assets, source of funds/wealth (es.aml.understanding-the-purpose-and-intended)
- Ongoing monitoring: scrutinize transactions for consistency with customer profile, regularly update CDD (es.aml.ongoing-monitoring-of-the-business)
- Registration with Banco de España as a VASP under Law 10/2010, transposed via Royal Decree-Law 7/2021 (es.aml.real-decreto-ley-72021-de-27)
- Compliance with Circular 2/2022 of Banco de España on VASP registration requirements (es.aml.circular-22022-del-banco-de)
- Suspicious transaction reporting obligations under Law 10/2010 and Royal Decree 304/2014 (es.aml.ley-102010-de-28-de, es.aml.real-decreto-3042014-de-5)
Key Restrictions
- Frontend must obtain CASP authorization under MiCA if it provides services involving custody, exchange, or execution of orders on behalf of clients (es.licensing.vasp, es.licensing.custody, es.licensing.exchange)
- A local entity (Spain-inc.) is required for CASP registration with CNMV/Banco de España under MiCA (es.licensing.vasp)
- All crypto marketing/advertising must include mandatory CNMV risk warnings per Circular 1/2022 (es.licensing.regulator-cnmv)
- If the frontend merely provides a non-custodial interface to permissionless smart contracts without taking custody, executing orders, or intermediating exchange, it may fall outside CASP scope — but ES regulators may still assert jurisdiction under MiCA's broader definitions
- Any fee-taking (e.g. frontend fees, swap fees, routing fees) is likely to trigger classification as a 'crypto-asset service provider' under MiCA, since receipt of remuneration for intermediating transactions is a hallmark of CASP services
Key Risks
- High enforcement risk from CNMV for unregistered operators — CNMV actively issues warnings against unregistered crypto entities ('chiringuitos financieros') including major platforms (es.enforcement.entity-targeted-numerous-hundreds-of)
- Binance Spain was fined for non-compliance with CNMV advertising rules, setting precedent that frontend marketing falls under CNMV oversight (es.enforcement.entity-targeted-binance-specifically-binance)
- MiCA's definition of 'execution of orders on behalf of clients' and 'placing of crypto-assets' could capture frontend operators that route or aggregate user orders, even if no custody is taken
- Tools for Humanity (Worldcoin) enforcement shows Spanish authorities apply strict data protection standards to crypto-related projects (es.enforcement.entity-targeted-tools-for-humanity)
- Structuring the frontend as 'pure non-custodial interface' to avoid CASP scope is legally uncertain — ES regulators may apply look-through analysis to economic substance
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
CNMV — Securities market, crypto advertising regulation (mandatory risk warnings)
Evidence fact es.licensing.regulator-banco-de-espania not found (may have been renamed).
MiCA Regulation (EU) (2023) — CASP authorization, comprehensive crypto regulation
Law 10/2010 (Anti-Money Laundering) (2010) — Pre-MiCA VASP registration with Banco de Espana
VASP: CASP authorization under MiCA via CNMV/Banco de Espana. 6-12 months. Relatively reasonable registration process — attracted crypto firms.
CUSTODY: CASP authorization — custody is a licensed MiCA activity
EXCHANGE: CASP authorization under MiCA; CNMV mandatory risk warnings on all crypto marketing
Directive (EU) 2015/849 (4th AMLD): The foundational directive, which brought more entities into scope and strengthened CDD.
Directive (EU) 2018/843 (5th AMLD): Crucially, this directive extended the scope of AML/CFT rules to include virtual asset service providers (VASPs), specifically:
Providers engaged in exchange services between virtual currencies and fiat currencies.
Directive (EU) 2018/1673 (6th AMLD): Primarily focuses on harmonizing the definition of money laundering criminal offenses and related sanctions across the EU, which indirectly supports the AML framework.
Ley 10/2010, de 28 de abril, de prevención del blanqueo de capitales y de la financiación del terrorismo (Law 10/2010, of April 28, on the prevention of money laundering and terrorist financing).
Real Decreto 304/2014, de 5 de mayo, por el que se aprueba el Reglamento de la Ley 10/2010 (Royal Decree 304/2014, of May 5, approving the Regulation of Law 10/2010): This Royal Decree provides detailed rules for the implementation of Law 10/2010. It also has been amended to reflect EU changes.
Real Decreto-ley 7/2021, de 27 de abril (Royal Decree-Law 7/2021, of April 27): This specific decree transposed significant parts of the 5th AMLD, formally bringing VASPs under the scope of Law 10/2010 and establishing the requirement for their registration with the Bank of Spain.
Circular 2/2022 del Banco de España, de 23 de marzo (Circular 2/2022 of the Bank of Spain, of March 23): This circular specifically regulates the administrative registration of providers of virtual currency exchange services for fiat currency and electronic wallet custody services.
Natural Persons: Obtain and verify identity using reliable independent sources (e.g., national ID card, passport). Required data includes full name, date and place of birth, address, and national identification number.
Legal Persons/Entities: Obtain and verify the name, legal form, address, proof of incorporation, articles of association, names of directors, and the legal representative(s).
For legal entities, identify any natural person(s) who ultimately own or control 25% plus one share or more of the entity, or who otherwise exercise control.
If no such natural person is identified, identify the natural person(s) who hold the position of senior managing official(s).
Understanding the Purpose and Intended Nature of the Business Relationship:
Ongoing Monitoring of the Business Relationship:
Carrying out occasional transactions exceeding €1,000 (whether in a single transaction or several linked transactions).
Where there is suspicion of money laundering or terrorist financing.
Entity Targeted: Binance (specifically, Binance Spain S.L.). Violation Type: Non-compliance with the CNMV's Circular 1/2022 on advertising of crypto-assets. The alleged violations included insufficient disclosure of risks, lack of clarity, and inadequate warnings in advertising campaigns. Outcome: Fine imposed and publicly announced. This marked a significant enforcement of Spain's relatively new crypto advertising rules.
Entity Targeted: Tools for Humanity Corp. (the company behind the Worldcoin project). Violation Type: Illicit processing of personal data (especially sensitive biometric data like iris scans), lack of transparency, insufficient information provided to users, and processing of data of minors. Penalty Amount: Precautionary measure imposing an immediate prohibition on the collection and processing of personal data by Worldcoin in Spain. A final fine amount will be determined after a full investigation, potentially reaching up to €20 million for GDPR violations. Outcome: Precautionary measure imposed, requiring Worldcoin to cease all data collection and processing activities in Spain related to its iris scanning. Investigation ongoing. This is a very significant action due to its direct operational impact and the novelty of regulating biometric data in a crypto context.
Entity Targeted: Numerous (hundreds) of unregistered entities operating in the cryptocurrency and forex markets, often referred to as "chiringuitos financieros" (financial boiler rooms). Specific examples include warnings against companies like Bitget, MEXC Global, and countless smaller, fraudulent-appearing platforms. Violation Type: Offering investment services or products related to crypto assets in Spain without the required authorization or registration with the CNMV. This often includes deceptive advertising practices. Penalty Amount: While not a single "fine," the outcome is a public warning, inclusion on the CNMV's "grey list" (list of unauthorized firms), and potential legal action or blocking of access within Spain. This effectively prohibits their operations in Spain and serves as a public consumer alert. Outcome: Prohibition of unauthorized operations in Spain, public consumer warning, and potential escalation to legal action. This proactive enforcement has been a continuous and significant effort to protect investors.
Outcome: Fine imposed and publicly announced. This marked a significant enforcement of Spain's relatively new crypto advertising rules.
Outcome: Prohibition of unauthorized operations in Spain, public consumer warning, and potential escalation to legal action. This proactive enforcement has been a continuous and significant effort to protect investors.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi frontend operating in/into Spain will likely require CASP authorization under MiCA (a high-burden licensing process with local entity requirement) if it takes any fee or intermediates user orders, and must comply with Banco de España AML registration, CDD/transaction monitoring obligations, and CNMV advertising risk-warning rules, though purely non-custodial, fee-free interfaces may fall outside scope subject to regulatory interpretation risk.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?