DeFi protocol frontend in Guinea-Bissau
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Guinea-Bissau with a local entity, subject to AML obligations and low licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Low
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD) — identification and verification of identity (natural persons: name, address, date of birth, nationality, unique identification number; legal persons: name, legal form, address, directors, beneficial owners) — required under Law No. 7/2014 and UEMOA Directive No. 003/2021/CM/UEMOA
- Beneficial ownership identification — for legal persons, understanding ownership and control structure, identifying the ultimate beneficial owner (UBO)
- Purpose-and-nature assessment — understanding the purpose and intended nature of the business relationship or transaction
- Ongoing transaction monitoring — scrutiny of transactions throughout the business relationship to ensure consistency with the customer's profile
- Record-keeping — maintain customer identification data, transaction records (including travel-rule information), analysis of complex/unusual transactions, and copies of STRs for applicable retention periods
- Risk-based approach — apply Simplified CDD (SCDD) for lower-risk situations and Enhanced CDD (EDD) for higher-risk situations (PEPs, high-risk jurisdictions, complex/unusual transactions, new technologies)
- Suspicious Transaction Reporting (STR) — report any suspicious or attempted transaction, regardless of amount, to the Unidade de Informação Financeira (UIF — Financial Intelligence Unit of Guinea-Bissau)
- No tipping-off — prohibition on disclosing to the customer or any third party that an STR has been or will be filed
- Travel Rule obligations — sender and recipient information must be recorded for virtual asset transfers, per FATF Recommendation 15 as transposed via UEMOA Directive No. 003/2021/CM/UEMOA
Key Restrictions
- No specific crypto or VASP licensing framework exists — the operator cannot obtain a license tailored to DeFi frontend activities
- BCEAO has issued public warnings against cryptocurrencies and generally prohibits unauthorized payment/crypto services by non-licensed entities
- If the frontend involves fee-taking, it may be reclassified as a financial service requiring a traditional financial license (e.g., e-money, payment services, financial intermediation) from the BCEAO — this is a significant grey-area risk
- Any entity operating in Guinea-Bissau must incorporate locally with a registered office under general business registration laws
- UEMOA Directive No. 003/2021/CM/UEMOA transposes FATF Recommendation 15 on virtual assets — VASPs (potentially including DeFi frontends) must comply with AML/CFT obligations even absent specific crypto licensing
- The BCEAO's stance that cryptocurrencies are not recognized as legal tender or regulated financial instruments creates an ambiguous legal environment for any crypto-touching service
Key Risks
- Regulatory uncertainty — no specific crypto laws exist but BCEAO warnings suggest active hostility; future regulation (possibly retroactive) is a material risk
- Fee-taking risk — if the frontend charges fees (swap fees, routing fees), it risks being classified as an unauthorized financial or payment service under BCEAO rules, carrying enforcement exposure
- Enforcement risk — the FIU (UIF) and Central Bank could scrutinize any entity handling financial flows under general AML/CFT provisions, even without specific VASP rules
- Travel Rule compliance ambiguity — FATF Recommendation 15 transposed via UEMOA Directive applies to VASPs, but it is unclear how it applies to non-custodial DeFi frontends; compliance expectations are unclear
- GIABA mutual evaluation risk — Guinea-Bissau's AML/CFT framework deficiencies regarding virtual assets may lead to increased enforcement pressure or sudden regulatory changes
- Operational grey area — operating a DeFi frontend without explicit legal clarity exposes the operator to potential shutdown orders or reputational damage
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Absence of Specific Crypto Laws: There are no explicit laws or regulations defining virtual assets, outlining VASP licensing categories, setting specific capital requirements for crypto firms, or mandating a particular application process for crypto businesses.
Central Bank Stance: Like many central banks in the absence of specific legislation, the Banco Central da Guiné-Bissau (Central Bank of Guinea-Bissau) is more likely to have issued warnings regarding the risks associated with cryptocurrencies rather than establishing a regulatory framework for them. These warnings typically highlight price volatility, lack of consumer protection, and potential for illicit use. (Unfortunately, direct links to specific public warnings are often hard to find without deep local search capabilities in Portuguese).
General Business Registration: Any entity wishing to operate in Guinea-Bissau, including a business that might involve virtual assets, would still need to comply with general company registration laws and obtain standard business licenses from the relevant government ministries (e.g., Ministry of Economy and Finance, Ministry of Justice) for its operational activities, irrespective of whether those activities involve virtual assets.
Neither (for Crypto-Specific Activities): Since there's no specific regulatory framework for virtual assets, there is no designated "registration regime" or "licensing regime" for crypto activities.
None Specifically for Crypto: There are no specific "Virtual Asset Exchange License," "Crypto Custody License," or "Crypto Payment Processor License" available or required in Guinea-Bissau.
Traditional Financial Licenses (Potential Overlap/Future): If a VASP's activities were deemed to fall under the scope of traditional financial services (e.g., money remittance, e-money issuance, or general financial intermediation), then relevant licenses for those traditional activities might be required. However, without specific legal clarity on how virtual assets are classified in relation to existing financial laws, this remains ambiguous. It's more likely that traditional financial services licenses would not implicitly cover virtual asset activities without explicit legislative amendment.
AML/KYC: This is the most likely area where some implicit obligation might arise. Guinea-Bissau is a member of the Inter-Governmental Action Group against Money Laundering in West Africa (GIABA), an FATF-style regional body. This means it is committed to implementing FATF Recommendations, including Recommendation 15 on New Technologies, which requires countries to regulate Virtual Asset Service Providers (VASPs) for AML/CFT purposes.
Current Situation: While Guinea-Bissau has general Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) laws, it's not clear whether these laws explicitly designate VASPs as "reporting entities" or "financial institutions" that must adhere to AML/KYC obligations (e.g., customer due diligence, suspicious transaction reporting).
Financial Intelligence Unit (FIU): Guinea-Bissau has an FIU (Unidade de Informação Financeira - UIF). If a virtual asset business were identified as conducting financial activities that could facilitate money laundering, it might eventually fall under the purview of the general AML/CFT law and the FIU's supervision.
Local Presence: Any company operating in Guinea-Bissau would generally require a registered local office and compliance with local business registration requirements.
General AML/CFT Law: Guinea-Bissau is expected to have legislation aligned with international AML/CFT standards. The most recent comprehensive law would be:
Law No. 5/2023 of April 28, 2023, on the Prevention and Combat of Money Laundering, Terrorist Financing, and Proliferation Financing.
Central Bank of Guinea-Bissau (Banco Central da Guiné-Bissau): This is the primary financial regulator. Any future crypto-related regulations would likely emanate from here.
Law No. 7/2014 of 30th May 2014 on the Prevention and Combat of Money Laundering and Terrorist Financing: This is the overarching national AML/CFT law. It defines reporting entities, establishes the Financial Intelligence Unit (FIU), and outlines general obligations.
UEMOA Directive No. 003/2021/CM/UEMOA relating to the fight against money laundering and terrorist financing in the UEMOA Member States: This critical regional directive, adopted in 2021, incorporates the revised FATF Recommendations, including specific provisions for virtual assets (FATF Recommendation 15). It mandates member states (including Guinea-Bissau) to apply AML/CFT measures to VASPs and to supervise or monitor them. National legislation and regulations are expected to be updated to reflect this directive.
Purpose and Nature of the Business Relationship: Understanding the purpose and intended nature of the business relationship or transaction.
Conducting ongoing monitoring of the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP’s knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Risk-Based Approach: Applying CDD measures based on a risk assessment. This means:
Report Suspicious Transactions: Report any transaction (or attempted transaction), regardless of its amount, that they suspect may involve money laundering or terrorist financing. This includes transactions related to virtual assets.
Reporting Body: Reports must be submitted to the national Financial Intelligence Unit (FIU).
Unidade de Informação Financeira (UIF) - Financial Intelligence Unit of Guinea-Bissau:
Implication of BCEAO Stance: Any entity seeking to offer financial services, including what might be construed as digital asset custody, would generally need a license from the BCEAO and/or national financial authorities. However, the BCEAO's stance against recognizing cryptocurrencies means that such a license specifically for crypto custody is not available or granted. Unlicensed provision of financial services is generally illegal.
Central Bank of West African States (BCEAO) Official Website:
BCEAO Communiqués on Cryptocurrencies (Example - French):
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend can operate in Guinea-Bissau only in a high-risk grey area: no specific crypto licensing exists, but general AML/CFT obligations (including FATF Recommendation 15 via UEMOA Directive) may apply; fee-taking risks reclassification as an unauthorized financial service under BCEAO rules; local incorporation is required for any entity presence, and the BCEAO's anti-crypto stance creates material enforcement exposure.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?