← Regulations / Croatia / Operating Models / DeFi frontend

DeFi protocol frontend in Croatia

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Croatia with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration with the Office for Anti-Money Laundering (USPN / Ured za sprječavanje pranja novca) as a VASP if the frontend exercises control or intermediation over transactions (e.g., fee-taking, routing, key management, screening)
  • Compliance with the Croatian Anti-Money Laundering and Terrorist Financing Act (Zakon o sprječavanju pranja novca i financiranja terorizma) transposing AMLD5/AMLD4
  • Implement KYC/CDD procedures for users if the frontend qualifies as a VASP (e.g., collects fees, routes transactions, screens users)
  • Appoint an AML Compliance Officer
  • Establish internal AML/CFT policies, procedures, and a risk assessment methodology
  • Report suspicious transactions to the Financial Intelligence Office (USPN)
  • Maintain records of customer due diligence and transactions for the statutory period
  • Under MiCA (from 30 December 2025): full CASP authorization likely required from HANFA if the frontend provides 'crypto-asset services' — harmonized EU licensing with higher compliance obligations

Key Restrictions

  • Must be a legal entity incorporated in Croatia with a registered office if the frontend qualifies as a VASP (e.g., fee-taking, active intermediation, or user screening)
  • If the frontend merely provides a purely non-custodial, non-intermediated interface to permissionless smart contracts and takes no fees or control over transactions, it may fall outside the VASP definition — but this is legally untested
  • Fee-taking (e.g., swap fees, routing fees) likely triggers VASP classification, making the frontend subject to registration and AML obligations
  • Geofencing required for US persons (compliance with US sanctions and securities laws as a practical matter), though no explicit Croatian geofencing rule exists
  • Under MiCA (from Dec 30, 2025), any frontend providing 'crypto-asset services' as defined by MiCA will need a full CASP license

Key Risks

  • Regulatory ambiguity: it is unclear whether a purely non-custodial, non-fee-taking frontend falls under the current Croatian VASP definition — lack of guidance or enforcement precedent
  • If the frontend takes fees or screens users, it is very likely considered a VASP and operating without registration is a criminal/regulatory risk
  • MiCA transition risk: from Dec 30, 2025, the regulatory bar rises significantly — frontends that were previously unregulated may need a full CASP license
  • HANFA may classify certain DeFi tokens as financial instruments under securities laws, creating dual regulatory exposure
  • Enforcement risk: no local Croatian enforcement precedent yet on DeFi frontends specifically, but EU-wide regulatory attention on DeFi is increasing

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Office for Anti-Money Laundering (Ured za sprječavanje pranja novca – USPN): This is the primary authority responsible for supervising the implementation of AML/CFT measures by obliged entities, including VASPs. They maintain the register of VASPs.

licensing 60% confidence

Current Regime (Pre-MiCA): Croatia operates a registration regime for VASPs, primarily for AML/CFT supervision. This means entities providing virtual asset services must register with the USPN and comply with AML obligations. It is not a full financial services license in the traditional sense, but an AML registration.

licensing 60% confidence

Future Regime (Post-MiCA): From December 30, 2025, MiCA will introduce a harmonized licensing regime across the EU. Entities providing "crypto-asset services" (as defined by MiCA) will require a license from a competent national authority (likely HANFA in Croatia, in coordination with USPN for AML aspects) in one EU member state, which will then allow them to operate across the entire EU ("passporting"). This will replace the national AML registrations for the services covered by MiCA.

licensing 60% confidence

Generally, a legal entity incorporated in Croatia is required to apply for registration.

licensing 60% confidence

A registered office in Croatia is necessary.

licensing 60% confidence

AML/KYC Framework: This is the most critical aspect:

licensing 60% confidence

AML/CFT Policies and Procedures: Comprehensive internal rules and procedures for customer due diligence (CDD), enhanced due diligence (EDD), ongoing monitoring, record-keeping, and reporting suspicious transactions.

licensing 60% confidence

Risk Assessment: A robust risk assessment methodology for identifying and mitigating money laundering and terrorist financing risks associated with the VASP's operations, customers, products, and geographies.

aml 60% confidence

VASPs are required to register with the Ministry of Finance – Financial Intelligence Office (Ured za sprječavanje pranja novca) as part of their AML/CTF obligations.

aml 60% confidence

This registration requires compliance with the Croatian Anti-Money Laundering and Terrorist Financing Act (Zakon o sprječavanju pranja novca i financiranja terorizma), which transposes EU AML Directives (specifically AMLD5).

aml 60% confidence

Implementing robust KYC/CDD (Know Your Customer/Customer Due Diligence) procedures.

aml 60% confidence

Reporting suspicious activities to the Financial Intelligence Office.

aml 60% confidence

Establishing internal AML policies and procedures.

licensing 60% confidence

Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1114 (Note: MiCA has a phased implementation, with most provisions for CASPs applying from 30 December 2025).

licensing 60% confidence

Croatian Financial Services Supervisory Agency (Hrvatska agencija za nadzor financijskih usluga – HANFA): While USPN handles the AML registration, HANFA, as the financial regulator, may also have a role in interpreting certain crypto-assets as financial instruments under existing securities laws, or in providing guidance, particularly concerning future MiCA implementation.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a DeFi protocol frontend operating in/from Croatia is likely regulated as a VASP (requiring USPN registration and full AML compliance) if it takes fees, screens users, or otherwise intermediates transactions; a purely passive, non-fee, non-custodial interface may fall outside the definition, but this is legally untested and carries significant ambiguity risk, with MiCA harmonization raising the bar further from December 2025.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?