Custodial wallet / SaaS in Greece
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Greece with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with the Hellenic Capital Market Commission (HCMC) under Law 4557/2018 (as amended by Laws 4734/2020, 4816/2021, 4991/2022) as a 'Provider of Services of Virtual Assets' — specifically a Custody Provider offering custodian wallet services.
- Appoint an AML Compliance Officer (and potentially a Deputy).
- Conduct Customer Due Diligence (CDD) on all customers — natural persons (full name, DOB, nationality, address, ID number) and legal entities (name, registered office, directors, beneficial owners >25%).
- Apply Enhanced Due Diligence (EDD) for PEPs, high-risk third countries, complex/unusual transactions, non-face-to-face situations.
- Screen customers against EU/UN sanctions lists.
- Monitor transactions and report suspicious activities to the Hellenic Financial Intelligence Unit (FIU).
- Maintain records of CDD data and transaction records sufficient to reconstruct individual transactions.
- Implement the Travel Rule (per Law 4991/2022 transposing EU Regulation on info accompanying transfers of funds and certain crypto-assets).
- Regular staff training on AML/CFT.
- Conduct ongoing monitoring of transactions and periodic review of CDD information.
Key Restrictions
- VASP must be incorporated in Greece and have its management and operational base within the country (gr.licensing.while-not-explicitly-always-requiring).
- No specific minimum capital requirements as a strict numeric threshold, but the HCMC assesses financial soundness as part of registration (gr.licensing.the-national-aml-regime-does).
- Fit & proper requirements apply to management, key personnel, and significant shareholders.
Key Risks
- Enforcement risk: Greek authorities have actively pursued crypto-related fraud and money laundering cases, including organized 'boiler room' schemes and fraudulent investment platforms (gr.enforcement.entity-targeted-a-large-international, gr.enforcement.entity-targeted-individuals-involved-in).
- Regulatory ambiguity: No dedicated crypto custody law beyond the AML registration framework — capital adequacy, segregation, insurance, and proof-of-reserves rules are not explicitly codified for VASPs.
- Sanctions/travel rule compliance is a growing focus under Law 4991/2022 and may create technical burdens for SaaS/white-label models where the SaaS operator and client may have shared AML responsibilities.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law 4557/2018 (as amended), which transposed the EU's 5th Anti-Money Laundering Directive (AMLD5) and 6th Anti-Money Laundering Directive (AMLD6) into national law. This law defines "providers of services of virtual assets" and mandates their registration.
HCMC Decision No. 2/902/10.03.2021 (and subsequent amendments), which provides further details on the registration process and ongoing obligations.
Custody Providers: Providers that offer custodian wallet services, holding, storing, and transferring virtual assets or private cryptographic keys on behalf of customers.
Establish and implement robust AML/CFT policies, procedures, and internal controls in line with national and EU requirements.
Conduct customer due diligence (CDD) and enhanced due diligence (EDD) where necessary.
Monitor transactions for suspicious activities and report them to the Hellenic Financial Intelligence Unit (FIU).
Appoint an AML Compliance Officer and potentially a Deputy AML Compliance Officer.
Regular staff training on AML/CFT.
Fit & Proper Requirements:
Management and key personnel must demonstrate integrity, competence, and absence of criminal records.
While not explicitly always requiring a physical office, the VASP must be incorporated in Greece and have its management and operational base within the country to effectively comply with Greek AML/CFT laws and HCMC supervision.
The national AML regime does not impose specific initial capital requirements as stringent as a licensing regime. However, VASPs are expected to have adequate financial resources to operate responsibly and comply with their obligations. The HCMC will assess the financial soundness as part of the registration.
Hellenic Capital Market Commission (HCMC) - Virtual Assets Page:
Law 4557/2018 (Government Gazette A' 139/30.07.2018): This is the primary Greek AML/CFT law, transposing the Fourth AML Directive (EU 2015/849). It established the general framework for obliged entities.
Law 4734/2020 (Government Gazette A' 199/08.10.2020): This crucial law amended Law 4557/2018 to transpose the Fifth AML Directive (5AMLD) into Greek law. It explicitly expanded the scope of obliged entities to include:
Providers of custodial wallet services (holding, storing, and transferring virtual currencies on behalf of customers).
Law 4816/2021 (Government Gazette A' 118/09.07.2021): This law further amended Law 4557/2018, primarily to transpose aspects of the Sixth Anti-Money Laundering Directive (6AMLD) concerning the criminalization of money laundering offenses.
Law 4991/2022 (Government Gazette A' 214/11.11.2022): This law made further amendments to Law 4557/2018, primarily to incorporate the changes from the EU Regulation on information accompanying transfers of funds and certain crypto-assets (Travel Rule).
Legal Entities: Obtain and verify the entity's name, legal form, address of registered office, company registration number, and the names of the directors. Crucially, they must identify and verify the Beneficial Owner(s) (BOs) – any natural person who ultimately owns or controls more than 25% of the entity, directly or indirectly, or exercises control through other means.
Regularly review transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Enhanced Due Diligence (EDD): Required for higher-risk situations, such as:
Entity Targeted: A large international organized crime group operating "boiler rooms" (call centers) that defrauded investors across Europe, including Greece, using fake cryptocurrency investments. Violation Type: Investment fraud, aggravated fraud, money laundering, participation in a criminal organization. Outcome: Multiple arrests (at least 15 in Greece, others internationally), dismantling of call centers, freezing of assets. Criminal proceedings are ongoing.
Entity Targeted: Individuals involved in a fraudulent scheme that lured victims into investing in fake cryptocurrency platforms. Violation Type: Fraud, money laundering, establishment/participation in a criminal organization. Outcome: Arrests, ongoing investigations and criminal proceedings.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS providers may operate in Greece but must register with the HCMC as a VASP (custody provider) under Law 4557/2018, maintain a local incorporated entity with management in Greece, comply with full AML/CFT obligations (CDD, EDD, Travel Rule, suspicious activity reporting to FIU), and pass fit & proper checks, though no specific custody-specific capital, segregation, insurance, or proof-of-reserves rules are codified in the AML registration framework.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?