DeFi protocol frontend in Greece
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Greece with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Full CDD/EDD under Law 4557/2018 — identify and verify natural persons (full name, date of birth, nationality, address, ID) and legal entities (name, registered office, directors, beneficial owners >25%)
- Ongoing transaction monitoring — review transactions for consistency with customer risk profile; maintain records sufficient to reconstruct each transaction (dates, amounts, asset type, sender, recipient)
- Sanctions screening against EU and UN sanctions lists
- Suspicious transaction reporting (STR) to the Hellenic Financial Intelligence Unit (FIU)
- Appointment of an AML Compliance Officer (and deputy if required)
- Regular staff AML/CFT training
- Travel Rule compliance under Law 4991/2022 (EU funds transfer regulation) — collect and transmit sender/recipient information for virtual asset transfers
- EDD required for PEPs, high-risk third countries, complex/unusual large transactions, non-face-to-face relationships
- Record-keeping: CDD documents and transaction records must be retained for statutory periods (typically 5 years under Greek AML law)
Key Restrictions
- The frontend operator must be incorporated in Greece with management and operational base in the country (HCMC requirement — not just a VASP registration; a local legal entity is needed)
- The operator must register with the Hellenic Capital Market Commission (HCMC) and be entered into the Register of Providers of Services of Virtual Assets
- Management and key personnel must pass fit & proper requirements (integrity, competence, no criminal record); significant shareholders may also be assessed
- The operator must have adequate financial resources (HCMC assesses financial soundness — no strict minimum capital but must show capability)
- Must establish and implement robust AML/CFT policies, procedures, and internal controls documented and submitted to HCMC
- If the frontend only provides non-custodial access to permissionless smart contracts (no exchange, no custody, no transfer execution by the operator), it may fall outside the defined VASP categories — significant regulatory ambiguity exists
- Fee-taking from users (e.g., front-end fees, swap surcharges) likely triggers classification as a VASP engaged in 'exchange services' or 'participation in financial services related to virtual assets', bringing the operator squarely within the regulated scope
Key Risks
- Regulatory ambiguity: The Greek VASP definition (Law 4734/2020 / 5AMLD transposition) covers exchange services, custodial wallets, and transfer services. A pure non-custodial frontend that does not custody assets or execute transfers may argue it is not a VASP — but this has not been tested in Greek enforcement, creating risk
- If the protocol is sufficiently decentralized and the frontend merely displays data without taking fees, Greek regulators may not consider it a VASP. However, any fee extraction by the frontend operator (e.g., 0.1% swap fee) likely triggers VASP classification
- Enforcement precedent in Greece focuses on fraud and money laundering by bad actors — not on clarifying the boundary of decentralized frontends. No specific enforcement action has been taken against a DeFi frontend yet
- MiCA (EU-wide Markets in Crypto-Assets Regulation) will soon supersede parts of the national regime; frontend operators may face a new classification under MiCA for 'crypto-asset services' regardless of decentralization arguments
- Operator must geofence US persons and comply with separate US securities/AML law if accessible from the US; Greek law does not mandate US geofencing but practical risk exposure requires it
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law 4557/2018 (as amended), which transposed the EU's 5th Anti-Money Laundering Directive (AMLD5) and 6th Anti-Money Laundering Directive (AMLD6) into national law. This law defines "providers of services of virtual assets" and mandates their registration.
HCMC Decision No. 2/902/10.03.2021 (and subsequent amendments), which provides further details on the registration process and ongoing obligations.
Exchanges: Providers engaged in the exchange between virtual assets and fiat currencies, or between one or more virtual assets.
Custody Providers: Providers that offer custodian wallet services, holding, storing, and transferring virtual assets or private cryptographic keys on behalf of customers.
Transfer Services: Services enabling the transfer of virtual assets.
Other VASP Activities: Participation in and provision of financial services related to an issuer’s offer and/or sale of virtual assets, and providing virtual asset safekeeping and administration services.
Establish and implement robust AML/CFT policies, procedures, and internal controls in line with national and EU requirements.
Conduct customer due diligence (CDD) and enhanced due diligence (EDD) where necessary.
Monitor transactions for suspicious activities and report them to the Hellenic Financial Intelligence Unit (FIU).
Appoint an AML Compliance Officer and potentially a Deputy AML Compliance Officer.
Regular staff training on AML/CFT.
Fit & Proper Requirements:
Management and key personnel must demonstrate integrity, competence, and absence of criminal records.
While not explicitly always requiring a physical office, the VASP must be incorporated in Greece and have its management and operational base within the country to effectively comply with Greek AML/CFT laws and HCMC supervision.
The national AML regime does not impose specific initial capital requirements as stringent as a licensing regime. However, VASPs are expected to have adequate financial resources to operate responsibly and comply with their obligations. The HCMC will assess the financial soundness as part of the registration.
Hellenic Capital Market Commission (HCMC) - Virtual Assets Page:
Law 4557/2018 (Government Gazette A' 139/30.07.2018): This is the primary Greek AML/CFT law, transposing the Fourth AML Directive (EU 2015/849). It established the general framework for obliged entities.
Law 4734/2020 (Government Gazette A' 199/08.10.2020): This crucial law amended Law 4557/2018 to transpose the Fifth AML Directive (5AMLD) into Greek law. It explicitly expanded the scope of obliged entities to include:
Providers engaged in exchange services between virtual currencies and fiat currencies.
Providers of custodial wallet services (holding, storing, and transferring virtual currencies on behalf of customers).
Any other virtual asset service providers as defined by the Financial Action Task Force (FATF) recommendations and subsequent EU legislation.
Law 4991/2022 (Government Gazette A' 214/11.11.2022): This law made further amendments to Law 4557/2018, primarily to incorporate the changes from the EU Regulation on information accompanying transfers of funds and certain crypto-assets (Travel Rule).
Natural Persons: Obtain and verify the customer's full name, date of birth, place of birth, nationality, permanent address, and unique identification number (e.g., ID card, passport number). Verification must be done using reliable, independent source documents or data (e.g., government-issued photo ID, proof of address).
Legal Entities: Obtain and verify the entity's name, legal form, address of registered office, company registration number, and the names of the directors. Crucially, they must identify and verify the Beneficial Owner(s) (BOs) – any natural person who ultimately owns or controls more than 25% of the entity, directly or indirectly, or exercises control through other means.
Understanding the Purpose and Intended Nature of the Business Relationship: VASPs must understand why the customer is using their services and the expected pattern of transactions.
Regularly review transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Enhanced Due Diligence (EDD): Required for higher-risk situations, such as:
Business relationships with Politically Exposed Persons (PEPs) or their family members/close associates.
Complex, unusually large transactions or unusual patterns of transactions that have no apparent economic or lawful purpose.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend that charges fees or facilitates exchange of virtual assets for Greek residents is treated as a VASP under Law 4557/2018, requiring HCMC registration, a local Greek entity, full AML/CFT program (CDD, monitoring, STR, Travel Rule), fit & proper management, and ongoing supervision; pure non-custodial, non-fee-taking frontends face regulatory ambiguity as the Greek VASP definitions may not clearly capture them.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?