DeFi protocol frontend in Finland
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Finland with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Registration as a virtual currency provider (VCP) with FIN-FSA is required if the frontend takes custody of or facilitates exchange/transfer of virtual currencies — this includes fee-taking via smart contract interaction where the operator controls or handles private keys.
- Customer due diligence (CDD) is required under the Act on Virtual Currency Providers (572/2019), including identity verification, risk assessment, and ongoing monitoring.
- Internal control mechanisms and AML/CTF risk assessments must be documented and maintained — deficiencies in these areas have led to enforcement actions (Tesseract Finance Oy public warning, Coinmotion Oy public reprimand).
- Suspicious Transaction Reports (STRs) must be filed with the Financial Intelligence Unit (FIU) at the National Bureau of Investigation.
- The management (CEO and at least one board member) must be located in Finland.
- Professional indemnity insurance is required — no specific minimum share capital requirement under Finnish law.
Key Restrictions
- The operator must be a Finnish limited liability company (osakeyhtiö) or a branch of an EEA-incorporated company.
- If the frontend merely provides a non-custodial interface to permissionless smart contracts without taking custody of user funds or facilitating exchange/transfer (e.g., pure UI/aggregator with no fee on transfer), it may fall outside the VCP definition — but this is legally unsettled and high-risk.
- Taking any fee tied to the exchange, transfer, or custody of virtual currencies likely triggers VCP registration requirements.
- Geofencing/region-blocking is not explicitly mandated by Finnish law but is effectively required if the operator cannot comply with EU-wide MiCA obligations across the European Economic Area.
- Under MiCA rollout: 2024-2025 gradual rollout affecting broader categories; full enforcement from 2026.
Key Risks
- Regulatory ambiguity: It is unclear whether a purely non-custodial frontend that does not take fees from the transaction itself qualifies as a 'virtual currency provider' under the Act on Virtual Currency Providers (572/2019). Finnish enforcement actions (Tesseract, Coinmotion) have focused on custodial and exchange services, not pure frontends.
- Enforcement precedent: FIN-FSA issued a public warning to Tesseract Finance Oy for operating without proper registration and for AML deficiencies, showing active enforcement even for non-traditional structures.
- MiCA transition risk: The regime is in progressive rollout (2023-2026) — obligations may expand to cover frontends even more clearly by 2026.
- If the frontend is deemed a VCP and fails to register, penalties include public warnings/reprimands and mandatory corrective measures; monetary fines may apply in serious cases.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Financial Supervisory Authority (FIN-FSA): The primary regulator responsible for authorizing and supervising all crypto-asset service providers, ensuring compliance with anti-money laundering (AML), consumer protection standards, and operational requirements.
Financial Intelligence Unit (FIU): Operates within the National Bureau of Investigation to receive and investigate suspicious transaction reports from crypto service providers, focusing on preventing money laundering and terrorist financing.
Issuance of licenses for providers offering stablecoins and other crypto assets.
2024-2025: Gradual rollout affecting broader categories of crypto service providers.
2026: Full enforcement across all covered activities.
Mandatory transparency disclosures regarding the nature, risks, and costs associated with crypto assets.
Requirements for clear terms of use and accessible customer support mechanisms.
Technology Upgrades: Invest in systems that support real-time transaction monitoring, KYC/AML checks, and data reporting capabilities as stipulated by MiCA.
Providing services for exchanging virtual currency and fiat currency: This covers entities facilitating the purchase or sale of virtual currencies using traditional currencies (e.g., EUR, USD).
Providing custodial wallet services: This refers to services where an entity holds, stores, or transfers virtual currencies or private cryptographic keys on behalf of customers.
Exchanges: Both exchanges offering fiat-to-crypto and crypto-to-crypto trading services are clearly defined as "virtual currency providers" and require registration with the FIN-FSA.
Custody Providers: Entities providing "custodial wallet services" are also explicitly defined as "virtual currency providers" and require registration with the FIN-FSA. This includes services where the private keys are held by the provider on behalf of the client.
Payment Processors: This depends on the nature of the service:
The applicant must be a Finnish limited liability company (osakeyhtiö) or a branch of a limited liability company incorporated in an EEA country.
The management of the applicant must be located in Finland. This includes the CEO and at least one other member of the board of directors.
Capital Requirements (Professional Indemnity Insurance):
Regulator Name: Financial Supervisory Authority (FIN-FSA)
Entity Targeted: Tesseract Finance Oy (now operating as Stableton). Violation Type: Providing virtual currency services without proper registration for a period, and deficiencies in internal control mechanisms, risk assessment, and customer due diligence processes for Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF). Penalty Amount: Public warning (julkinen varoitus). While not a monetary fine, it's a formal and significant disciplinary measure by the FIN-FSA, obliging the company to rectify its shortcomings. Outcome: The company was required to implement corrective measures to comply with the Virtual Currency Providers Act and AML/CTF obligations. The public warning serves as a significant mark on the company's regulatory record.
Entity Targeted: Coinmotion Oy (a registered virtual currency provider in Finland). Violation Type: Deficiencies in compliance with Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) obligations, specifically regarding customer due diligence, risk assessment, and internal control. The FIN-FSA found that Coinmotion's practices did not fully meet the requirements of the Act on Virtual Currency Providers and the Anti-Money Laundering Act. Penalty Amount: Public reprimand (julkinen huomautus). Similar to the public warning, this is a formal, non-monetary disciplinary action, indicating serious shortcomings that required immediate correction. Outcome: Coinmotion Oy was instructed to rectify the identified deficiencies in its AML/CTF processes to ensure full compliance with regulatory requirements.
Legal Basis: The primary legal framework is the Act on Virtual Currency Providers (572/2019), which came into force in Finland on May 1, 2019. This Act places virtual asset service providers (VASPs) under the supervision of the Finnish Financial Supervisory Authority (FIN-FSA) and subjects them to AML/CFT obligations akin to traditional financial institutions.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend that takes custody, facilitates exchange/transfer of virtual currencies, or takes fees from such activities likely requires registration as a virtual currency provider with FIN-FSA under the Act on Virtual Currency Providers (572/2019); however, purely non-custodial frontends with no fee-taking occupy a legally ambiguous space with limited enforcement precedent, creating material regulatory risk.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?