← Regulations / Spain / Operating Models / On-shore VASP

On-shore VASP in Spain

Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.

Conditional AI-Generated · Unreviewed

On-shore VASP is conditionally permitted in Spain with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration with Banco de España (pre-MiCA) and/or CASP authorization under MiCA
  • CDD required: identity verification (national ID/passport for natural persons; incorporation docs for legal entities)
  • CDD triggered on establishing a business relationship, occasional transactions >€1,000, suspicion of ML/TF, or doubts about existing data
  • Beneficial owner identification at 25%+1 share threshold
  • Ongoing transaction monitoring and regular CDD updates
  • Travel Rule obligation under TFR recast — EUR 0 threshold (no minimum)
  • Suspicious transaction reporting (ROS) to SEPBLAC (Spain's FIU)
  • Internal policies and risk assessment per Law 10/2010, Royal Decree 304/2014, Circular 2/2022
  • Record-keeping obligations per AML framework

Key Restrictions

  • Must obtain CASP authorization under MiCA via CNMV/Banco de España (6–12 month process)
  • Must be locally incorporated as a Spanish entity
  • Custody services require a specific CASP license with prudential capital/insurance requirements (Art. 67 MiCA)
  • Mandatory CNMV risk warnings on all crypto advertising per Circular 1/2022
  • Client crypto-assets must be segregated and protected from third-party creditors
  • CASP must enter into a custody agreement with clients (Art. 38 MiCA)
  • Prudential own funds or professional indemnity insurance required for custody services

Key Risks

  • Aggressive enforcement history — Binance fined for advertising violations; hundreds of unregistered entities warned by CNMV
  • Worldcoin/Tools for Humanity penalized heavily (€250M) for biometric data processing — signals high privacy/regulatory bar
  • Tax reporting burden on operators: Form 172 for domestic clients, Form 721 for overseas holdings, progressive capital gains tax 19–28%
  • MiCA implementation timeline and national discretion may create transitional uncertainty
  • CASP prudential requirements (capital/insurance) represent a step up from pre-MiCA registration-only regime

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 80% confidence

CNMV — Securities market, crypto advertising regulation (mandatory risk warnings)

licensing 80% confidence

Banco de Espana — VASP registration, AML/CFT

licensing 20% confidence

MiCA Regulation (EU) (2023) — CASP authorization, comprehensive crypto regulation

licensing 20% confidence

Law 10/2010 (Anti-Money Laundering) (2010) — Pre-MiCA VASP registration with Banco de Espana

licensing 20% confidence

VASP: CASP authorization under MiCA via CNMV/Banco de Espana. 6-12 months. Relatively reasonable registration process — attracted crypto firms.

licensing 20% confidence

CUSTODY: CASP authorization — custody is a licensed MiCA activity

licensing 20% confidence

EXCHANGE: CASP authorization under MiCA; CNMV mandatory risk warnings on all crypto marketing

aml 60% confidence

Identification and Verification of the Customer:

aml 60% confidence

Natural Persons: Obtain and verify identity using reliable independent sources (e.g., national ID card, passport). Required data includes full name, date and place of birth, address, and national identification number.

aml 60% confidence

Legal Persons/Entities: Obtain and verify the name, legal form, address, proof of incorporation, articles of association, names of directors, and the legal representative(s).

aml 60% confidence

Carrying out occasional transactions exceeding €1,000 (whether in a single transaction or several linked transactions).

aml 60% confidence

Identification and Verification of the Customer:

aml 60% confidence

For legal entities, identify any natural person(s) who ultimately own or control 25% plus one share or more of the entity, or who otherwise exercise control.

aml 60% confidence

If no such natural person is identified, identify the natural person(s) who hold the position of senior managing official(s).

aml 60% confidence

Understanding the Purpose and Intended Nature of the Business Relationship:

aml 60% confidence

Ongoing Monitoring of the Business Relationship:

aml 60% confidence

When CDD is Required:

aml 60% confidence

Establishing a business relationship.

aml 60% confidence

Where there is suspicion of money laundering or terrorist financing.

aml 60% confidence

When there are doubts about the veracity or adequacy of previously obtained customer identification data.

custody 40% confidence

Requirement: Under MiCA, providing "custody and administration of crypto-assets on behalf of clients" will require a full authorization (license) from a national competent authority (in Spain, likely the CNMV - Comisión Nacional del Mercado de Valores, or potentially the Bank of Spain, subject to national implementation laws).

custody 40% confidence

Key Provisions: Articles 53-62 of MiCA detail the authorization process and requirements for all CASPs, including those offering custody.

custody 40% confidence

CASPs offering custody must enter into a custody agreement with clients.

custody 40% confidence

Segregation: They must ensure the segregation of clients' crypto-assets and funds from their own assets, and from the assets of other clients, in their accounting records.

custody 40% confidence

MiCA introduces prudential requirements for CASPs.

custody 40% confidence

Key Provisions (Article 67 - MiCA):

travel-rule 20% confidence

Travel Rule adopted — threshold: EUR 0 (no threshold under TFR recast)

enforcement 50% confidence

Entity Targeted: Binance (specifically, Binance Spain S.L.). Violation Type: Non-compliance with the CNMV's Circular 1/2022 on advertising of crypto-assets. The alleged violations included insufficient disclosure of risks, lack of clarity, and inadequate warnings in advertising campaigns. Outcome: Fine imposed and publicly announced. This marked a significant enforcement of Spain's relatively new crypto advertising rules.

enforcement 50% confidence

Entity Targeted: Tools for Humanity Corp. (the company behind the Worldcoin project). Violation Type: Illicit processing of personal data (especially sensitive biometric data like iris scans), lack of transparency, insufficient information provided to users, and processing of data of minors. Penalty Amount: Precautionary measure imposing an immediate prohibition on the collection and processing of personal data by Worldcoin in Spain. A final fine amount will be determined after a full investigation, potentially reaching up to €20 million for GDPR violations. Outcome: Precautionary measure imposed, requiring Worldcoin to cease all data collection and processing activities in Spain related to its iris scanning. Investigation ongoing. This is a very significant action due to its direct operational impact and the novelty of regulating biometric data in a crypto context.

enforcement 50% confidence

Entity Targeted: Numerous (hundreds) of unregistered entities operating in the cryptocurrency and forex markets, often referred to as "chiringuitos financieros" (financial boiler rooms). Specific examples include warnings against companies like Bitget, MEXC Global, and countless smaller, fraudulent-appearing platforms. Violation Type: Offering investment services or products related to crypto assets in Spain without the required authorization or registration with the CNMV. This often includes deceptive advertising practices. Penalty Amount: While not a single "fine," the outcome is a public warning, inclusion on the CNMV's "grey list" (list of unauthorized firms), and potential legal action or blocking of access within Spain. This effectively prohibits their operations in Spain and serves as a public consumer alert. Outcome: Prohibition of unauthorized operations in Spain, public consumer warning, and potential escalation to legal action. This proactive enforcement has been a continuous and significant effort to protect investors.

tax 60% confidence

Tax Rates (Base del Ahorro - Savings Income): Capital gains from virtual assets are integrated into the "savings income" tax base and are subject to progressive rates:

tax 60% confidence

Modelo 100 (Annual Personal Income Tax Declaration): All capital gains, losses, and income from cryptocurrency activities must be declared in the annual IRPF form.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a locally-incorporated on-shore VASP is permitted in Spain under MiCA CASP authorization (CNMV/Banco de España), requiring full licensing (6–12 months), robust AML obligations (including CDD at €1,000 threshold, Travel Rule at EUR 0), prudential requirements for custody, and mandatory compliance with advertising rules, with active enforcement precedent.

Questions this verdict aims to answer

  • What license(s) are required to operate locally?
  • What capital, governance, and reporting obligations apply?
  • What is the application process and timeline?