DeFi protocol frontend in Croatia
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Croatia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with the Office for Anti-Money Laundering (USPN / Ured za sprječavanje pranja novca) as a VASP if the frontend exercises control or intermediation over transactions (e.g., fee-taking, routing, key management, screening)
- Compliance with the Croatian Anti-Money Laundering and Terrorist Financing Act (Zakon o sprječavanju pranja novca i financiranja terorizma) transposing AMLD5/AMLD4
- Implement KYC/CDD procedures for users if the frontend qualifies as a VASP (e.g., collects fees, routes transactions, screens users)
- Appoint an AML Compliance Officer
- Establish internal AML/CFT policies, procedures, and a risk assessment methodology
- Report suspicious transactions to the Financial Intelligence Office (USPN)
- Maintain records of customer due diligence and transactions for the statutory period
- Under MiCA (from 30 December 2025): full CASP authorization likely required from HANFA if the frontend provides 'crypto-asset services' — harmonized EU licensing with higher compliance obligations
Key Restrictions
- Must be a legal entity incorporated in Croatia with a registered office if the frontend qualifies as a VASP (e.g., fee-taking, active intermediation, or user screening)
- If the frontend merely provides a purely non-custodial, non-intermediated interface to permissionless smart contracts and takes no fees or control over transactions, it may fall outside the VASP definition — but this is legally untested
- Fee-taking (e.g., swap fees, routing fees) likely triggers VASP classification, making the frontend subject to registration and AML obligations
- Geofencing required for US persons (compliance with US sanctions and securities laws as a practical matter), though no explicit Croatian geofencing rule exists
- Under MiCA (from Dec 30, 2025), any frontend providing 'crypto-asset services' as defined by MiCA will need a full CASP license
Key Risks
- Regulatory ambiguity: it is unclear whether a purely non-custodial, non-fee-taking frontend falls under the current Croatian VASP definition — lack of guidance or enforcement precedent
- If the frontend takes fees or screens users, it is very likely considered a VASP and operating without registration is a criminal/regulatory risk
- MiCA transition risk: from Dec 30, 2025, the regulatory bar rises significantly — frontends that were previously unregulated may need a full CASP license
- HANFA may classify certain DeFi tokens as financial instruments under securities laws, creating dual regulatory exposure
- Enforcement risk: no local Croatian enforcement precedent yet on DeFi frontends specifically, but EU-wide regulatory attention on DeFi is increasing
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Office for Anti-Money Laundering (Ured za sprječavanje pranja novca – USPN): This is the primary authority responsible for supervising the implementation of AML/CFT measures by obliged entities, including VASPs. They maintain the register of VASPs.
Current Regime (Pre-MiCA): Croatia operates a registration regime for VASPs, primarily for AML/CFT supervision. This means entities providing virtual asset services must register with the USPN and comply with AML obligations. It is not a full financial services license in the traditional sense, but an AML registration.
Future Regime (Post-MiCA): From December 30, 2025, MiCA will introduce a harmonized licensing regime across the EU. Entities providing "crypto-asset services" (as defined by MiCA) will require a license from a competent national authority (likely HANFA in Croatia, in coordination with USPN for AML aspects) in one EU member state, which will then allow them to operate across the entire EU ("passporting"). This will replace the national AML registrations for the services covered by MiCA.
Generally, a legal entity incorporated in Croatia is required to apply for registration.
A registered office in Croatia is necessary.
AML/KYC Framework: This is the most critical aspect:
AML/CFT Policies and Procedures: Comprehensive internal rules and procedures for customer due diligence (CDD), enhanced due diligence (EDD), ongoing monitoring, record-keeping, and reporting suspicious transactions.
Risk Assessment: A robust risk assessment methodology for identifying and mitigating money laundering and terrorist financing risks associated with the VASP's operations, customers, products, and geographies.
VASPs are required to register with the Ministry of Finance – Financial Intelligence Office (Ured za sprječavanje pranja novca) as part of their AML/CTF obligations.
This registration requires compliance with the Croatian Anti-Money Laundering and Terrorist Financing Act (Zakon o sprječavanju pranja novca i financiranja terorizma), which transposes EU AML Directives (specifically AMLD5).
Implementing robust KYC/CDD (Know Your Customer/Customer Due Diligence) procedures.
Reporting suspicious activities to the Financial Intelligence Office.
Appointing an AML Officer.
Establishing internal AML policies and procedures.
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1114 (Note: MiCA has a phased implementation, with most provisions for CASPs applying from 30 December 2025).
Croatian Financial Services Supervisory Agency (Hrvatska agencija za nadzor financijskih usluga – HANFA): While USPN handles the AML registration, HANFA, as the financial regulator, may also have a role in interpreting certain crypto-assets as financial instruments under existing securities laws, or in providing guidance, particularly concerning future MiCA implementation.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend operating in/from Croatia is likely regulated as a VASP (requiring USPN registration and full AML compliance) if it takes fees, screens users, or otherwise intermediates transactions; a purely passive, non-fee, non-custodial interface may fall outside the definition, but this is legally untested and carries significant ambiguity risk, with MiCA harmonization raising the bar further from December 2025.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?