Remote VASP serving residents in Spain
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Spain with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASP must register with Banco de España under Law 10/2010 (transposed via Real Decreto-ley 7/2021) and Circular 2/2022 of Banco de España
- MiCA CASP authorization required from CNMV/Banco de España — full licensing process (6–12 months)
- Customer CDD required: establish business relationship, occasional transactions >€1,000, or any suspicion of ML/TF
- Natural persons: verify identity via independent source (national ID/passport), collect full name, DOB, address, national ID number
- Legal persons: verify name, legal form, address, proof of incorporation, directors, legal representatives
- Beneficial ownership identification: identify natural persons owning/controlling ≥25%+1 share or otherwise exercising control
- Gather information on purpose and intended nature of business relationship, typical transaction volumes, types of virtual assets, source of funds/wealth
- Ongoing monitoring: scrutinize transactions for consistency with customer profile, regularly update CDD documentation
- Travel Rule compliance required with EUR 0 threshold (no de minimis exemption under TFR recast)
- Suspicious transaction reporting (ROS) obligations under Law 10/2010 framework
- Report to SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales) as competent FIU
Key Restrictions
- Foreign-incorporated entity without a local office cannot serve Spanish residents — must establish a local entity and obtain CASP authorization under MiCA
- CASP authorization required for custody, exchange, and transfer services — this is a full license, not a mere registration
- All crypto marketing must comply with CNMV Circular 1/2022 — mandatory risk warnings and disclosures
- Prudential requirements (own funds or professional indemnity insurance) apply under MiCA Article 67 for custody services
- Segregation of client crypto-assets from own assets required by MiCA Article 38
- Cannot operate without being on the Banco de España VASP register and holding MiCA CASP authorization
Key Risks
- High enforcement risk for unregistered remote operators — CNMV and Banco de España have publicly warned and fined unregistered entities (e.g., Binance fined for advertising non-compliance; hundreds of 'chiringuitos financieros' publicly warned)
- CNMV maintains a public warning list of unauthorized entities; appearing on this list causes reputational and operational harm
- MiCA introduces comprehensive supervisory framework with significant penalties for operating without authorization
- Biometric/identity data handling risks (see Worldcoin/THF enforcement precedent — €200M+ penalty for data protection violations)
- Travel Rule compliance at EUR 0 threshold imposes heavy operational burden for cross-border transactions
- Regulatory ambiguity during MiCA transition period may create gaps in supervisory expectations
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
CNMV — Securities market, crypto advertising regulation (mandatory risk warnings)
MiCA Regulation (EU) (2023) — CASP authorization, comprehensive crypto regulation
Law 10/2010 (Anti-Money Laundering) (2010) — Pre-MiCA VASP registration with Banco de Espana
VASP: CASP authorization under MiCA via CNMV/Banco de Espana. 6-12 months. Relatively reasonable registration process — attracted crypto firms.
CUSTODY: CASP authorization — custody is a licensed MiCA activity
EXCHANGE: CASP authorization under MiCA; CNMV mandatory risk warnings on all crypto marketing
Ley 10/2010, de 28 de abril, de prevención del blanqueo de capitales y de la financiación del terrorismo (Law 10/2010, of April 28, on the prevention of money laundering and terrorist financing).
Real Decreto-ley 7/2021, de 27 de abril (Royal Decree-Law 7/2021, of April 27): This specific decree transposed significant parts of the 5th AMLD, formally bringing VASPs under the scope of Law 10/2010 and establishing the requirement for their registration with the Bank of Spain.
Circular 2/2022 del Banco de España, de 23 de marzo (Circular 2/2022 of the Bank of Spain, of March 23): This circular specifically regulates the administrative registration of providers of virtual currency exchange services for fiat currency and electronic wallet custody services.
Identification and Verification of the Customer:
Natural Persons: Obtain and verify identity using reliable independent sources (e.g., national ID card, passport). Required data includes full name, date and place of birth, address, and national identification number.
Legal Persons/Entities: Obtain and verify the name, legal form, address, proof of incorporation, articles of association, names of directors, and the legal representative(s).
Identification and Verification of the Customer:
For legal entities, identify any natural person(s) who ultimately own or control 25% plus one share or more of the entity, or who otherwise exercise control.
If no such natural person is identified, identify the natural person(s) who hold the position of senior managing official(s).
Understanding the Purpose and Intended Nature of the Business Relationship:
Ongoing Monitoring of the Business Relationship:
Scrutinizing transactions undertaken throughout the course of the relationship to ensure consistency with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Regularly updating customer information, including CDD documentation.
Carrying out occasional transactions exceeding €1,000 (whether in a single transaction or several linked transactions).
Where there is suspicion of money laundering or terrorist financing.
When there are doubts about the veracity or adequacy of previously obtained customer identification data.
Travel Rule adopted — threshold: EUR 0 (no threshold under TFR recast)
Requirement: Under MiCA, providing "custody and administration of crypto-assets on behalf of clients" will require a full authorization (license) from a national competent authority (in Spain, likely the CNMV - Comisión Nacional del Mercado de Valores, or potentially the Bank of Spain, subject to national implementation laws).
Legal Basis: Regulation (EU) 2023/1114 on Markets in Crypto-assets (MiCA).
Key Provisions: Articles 53-62 of MiCA detail the authorization process and requirements for all CASPs, including those offering custody.
Segregation: They must ensure the segregation of clients' crypto-assets and funds from their own assets, and from the assets of other clients, in their accounting records.
CASPs will be required to hold a minimum amount of own funds or have a professional indemnity insurance policy, or a combination of both.
Entity Targeted: Binance (specifically, Binance Spain S.L.). Violation Type: Non-compliance with the CNMV's Circular 1/2022 on advertising of crypto-assets. The alleged violations included insufficient disclosure of risks, lack of clarity, and inadequate warnings in advertising campaigns. Outcome: Fine imposed and publicly announced. This marked a significant enforcement of Spain's relatively new crypto advertising rules.
Entity Targeted: Numerous (hundreds) of unregistered entities operating in the cryptocurrency and forex markets, often referred to as "chiringuitos financieros" (financial boiler rooms). Specific examples include warnings against companies like Bitget, MEXC Global, and countless smaller, fraudulent-appearing platforms. Violation Type: Offering investment services or products related to crypto assets in Spain without the required authorization or registration with the CNMV. This often includes deceptive advertising practices. Penalty Amount: While not a single "fine," the outcome is a public warning, inclusion on the CNMV's "grey list" (list of unauthorized firms), and potential legal action or blocking of access within Spain. This effectively prohibits their operations in Spain and serves as a public consumer alert. Outcome: Prohibition of unauthorized operations in Spain, public consumer warning, and potential escalation to legal action. This proactive enforcement has been a continuous and significant effort to protect investors.
Legal Basis: Regulation (EU) 2023/1114 on Markets in Crypto-assets (MiCA).
Outcome: Prohibition of unauthorized operations in Spain, public consumer warning, and potential escalation to legal action. This proactive enforcement has been a continuous and significant effort to protect investors.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP may serve Spanish residents only if it establishes a local entity and obtains full MiCA CASP authorization (from CNMV/Banco de España), registers under Law 10/2010 AML framework, and complies with CNMV crypto advertising rules; unregistered remote operation carries high enforcement risk.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?