Centralized exchange in Gibraltar
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Gibraltar with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- AML/CFT/CPF obligations under the Proceeds of Crime Act 2015 (POCA), including customer due diligence (CDD), transaction monitoring, risk assessments, staff training, and appointment of a compliance officer (MLRO registered with GFSC).
- Must submit AML/CFT policies and manuals during the DLT licensing application.
- Sanctions compliance under the Sanctions Act 2019.
- Travel Rule obligations: for virtual asset transfers valued at €1,000 or more, originator VASPs must collect and securely transmit originator and beneficiary information (names and account/wallet details) before or alongside the transaction to counterparty VASPs or relevant financial businesses.
- Ongoing GFSC supervision and compliance with GFSC-issued AML/CFT/CPF guidance.
Key Restrictions
- Must hold a DLT Provider Licence under the Financial Services Act 2019 (FSA), which is mandatory for any business using blockchain/DLT to store, transmit, or trade digital assets.
- Must incorporate under the Companies Act 2014 (updated 2022) and maintain physical presence in Gibraltar (local office, local hires including a manager, 'mind and management' in Gibraltar).
- Authorized capital is not fixed but must demonstrate financial stability — determined case-by-case with business plans showing sufficient resources.
- Principles-based regulation under 10 DLT Principles covering governance, risk management, financial stability, data security, and customer protection.
- No separate crypto-only license exists — the DLT license covers broader blockchain activities and is not a simple registration regime.
- Three-stage application process (Initial Application → Full Application → Final Submissions) with non-refundable fees and ongoing annual fees (e.g., £50,000 for exchanges).
Key Risks
- GFSC has enforcement authority and may revoke licenses or impose sanctions for non-compliance with DLT Principles or AML/CFT obligations.
- Substance requirements (physical office, local employees) create a high operational cost floor for Gibraltar operations.
- Principles-based regime introduces interpretive risk — GFSC assessments of compliance with the 10 DLT Principles may be subjective and change over time.
- Stablecoin-specific rules (e.g., 1:1 reserve requirements) are absent from sources, creating regulatory ambiguity for exchange-listed stablecoins.
- Travel Rule technical implementation challenges — originator VASPs must ensure secure transmission of beneficiary information, which may require technical interoperability with counterparty VASPs.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Financial Services Act 2018 – establishes the 10 key principles for DLT business operations
The DLT Regulations – govern distributed ledger technology providers
Proceeds of Crime Act 2015 – addresses AML/CFT/CPF requirements
Gibraltar Financial Services Commission (GFSC): The main authority, responsible for licensing, supervising, and enforcing rules on DLT firms, virtual asset service providers (VASPs), crypto exchanges, custody services, and trading platforms. It ensures compliance with international standards like FATF, including customer verification and risk management.
Financial Services Act 2019 (FSA): Oversees virtual/digital asset activities, ensuring GFSC compliance for transfers, storage, and management.
DLT Framework (introduced 2018): Pioneering principles-based regulations for DLT operators, covering licensing, governance, and consumer protection; developed from the 2014 Cryptocurrency Working Group.
The regime is principles-based, with 10 core principles covering governance, risk management, financial stability, data security, and customer protection; applicants must demonstrate compliance, including "mind and management" in Gibraltar (e.g., local office and employees).1 2 6
Post-licensing, firms must adhere to AML/CFT/CPF under the Proceeds of Crime Act 2015 ("POCA") and subsidiary rules, including customer due diligence (CDD), transaction monitoring, risk assessments, staff training, and appointing a compliance officer.1 2 6
No separate "crypto-only" license exists; the DLT license covers broader blockchain activities.2
The DLT Provider Licence is mandatory for any business using blockchain or DLT to store, transmit, or trade digital assets, including crypto exchanges, wallet providers, trading platforms, and custodial services; it falls under Section 8 of the FSA and ensures compliance with 9-10 DLT principles focused on transparency, risk management, AML/CFT, and governance.
Requirements include physical presence, qualified management, transparent ownership, and annual fees (e.g., £50,000 for exchanges).
Stage 1 (Initial Application): Submit form, business plan (detailing name, services, address, contact, founders/key persons), and pay non-refundable assessment fee; GFSC reviews viability against DLT principles.
Stage 2 (Full Application): Pay full fee, submit pack with policy manuals on risk management, IT/security, governance, financial crime (AML/CFT), and compliance procedures.
Stage 3 (Final Submissions): Provide conduct-of-business policies, non-financial resources info, and individual application forms for directors, shareholders, and key personnel; GFSC assesses business model, security, and substance.
Authorized capital varies by project specifics and is not fixed; applicants must demonstrate financial stability, often via business plans showing sufficient resources for operations, risk management, and substance in Gibraltar (e.g., real office, local employees, manager).
Substance mandates: Local office, local hires (including a manager), and proof of domestic operations; GFSC verifies the firm is genuinely run from Gibraltar.
Proceeds of Crime Act 2015 (POCA): Core law mandating AML/CFT/CPF obligations for DLT Firms and VASPs, including registration of the Money Laundering Reporting Officer (MLRO) with GFSC.
Financial Services Act 2019 (FSA): Regulates DLT activities (e.g., storing/transmitting value via DLT) as requiring GFSC authorization; non-DLT crypto activities fall under POCA AML regime.
GFSC issues comprehensive AML/CFT/CPF guidance; VASPs must submit policies/manuals during application.
Sanctions Act 2019: Expected compliance for counter-proliferation.
Threshold Amount: The rule applies to transfers of virtual assets valued at €1,000 or more (equivalent to EUR 1000).
Covered VASPs: All activities matching the FATF definition of Virtual Asset Service Providers (VASPs)—including exchanges, digital wallet providers, OTC trading desks, safekeeping/administration of virtual assets, and participation in virtual asset issuance/sales—are regulated and supervised by the GFSC. This covers DLT Providers authorised since 1 January 2018 under the Financial Services (DLT Providers and VAA Providers) Regulations 2020.
Technical Implementation Requirements: Originator VASPs must collect and securely transmit (before or alongside the transaction) originator and beneficiary information—such as names and account/wallet details—for transactions over the threshold involving another VASP or relevant financial business. Beneficiary VASPs must obtain and hold this data. Virtual assets are defined in the amended POCA as digital representations of value for payment/investment, excluding fiat digital representations and certain financial instruments.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange can operate in Gibraltar only under a DLT Provider Licence from the GFSC, requiring local incorporation, physical substance (office + local hires), multi-stage application, AML/CFT/CPF compliance under POCA, and Travel Rule obligations for transfers ≥ €1,000.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?