DeFi protocol frontend in Luxembourg
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Luxembourg with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with the CSSF as a VASP (Virtual Asset Service Provider) under the Law of 12 November 2004 (AML Law) if the frontend provides 'custodian wallet services' or otherwise falls within the VASP definition.
- CDD obligations: Obtain and verify customer's name, address, date/place of birth, nationality, and unique ID number from reliable independent documents (lu.aml.obtain-and-verify-the-customers, lu.aml.verify-identity-using-reliable-independent).
- For legal entities: Obtain and verify company name, legal form, registered address, articles of association, list of directors, proof of incorporation, and UBO identification (25%+ ownership/control threshold) (lu.aml.legal-entities-companies-foundations-etc, lu.aml.beneficial-ownership-ubo-identify-and).
- Ongoing transaction monitoring: Scrutinize transactions to ensure consistency with customer risk profile; regular review/update of CDD data (lu.aml.scrutinize-transactions-undertaken-throughout-the, lu.aml.regularly-review-and-update-customer).
- Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, and complex/unusually large transactions with no apparent economic purpose (lu.aml.enhanced-due-diligence-edd-required, lu.aml.politically-exposed-persons-peps-their, lu.aml.transactions-involving-high-risk-jurisdictions, lu.aml.complex-or-unusually-large-transactions).
- Suspicious Transaction Reporting (STR) obligations to the CSSF.
- Internal control frameworks and AML/CFT compliance program required under CSSF Circular 22/811 (lu.licensing.cssf-circular-22811-and-previous).
- MiCA regime (Regulation EU 2023/1114) will introduce full authorization requirements and additional prudential obligations including capital or professional indemnity insurance for entities providing custody and administration of crypto-assets (lu.licensing.authorization-not-just-registration-mica, lu.licensing.mica-regulation-eu-20231114-article).
Key Restrictions
- If the frontend takes custody of user assets (e.g., holds private keys), it qualifies as a VASP providing 'custodian wallet services' and must register with the CSSF under the AML Law (lu.licensing.registration-as-a-vasp-entities).
- If the frontend merely acts as a non-custodial interface (no key custody, no fee-taking beyond standard protocol fees), it may fall outside VASP classification — but this is fact-dependent and ambiguous.
- Fee-taking (e.g., frontend fees, swap fees) could increase the risk of classification as a regulated activity under Luxembourg law.
- Geofencing / IP blocking of EU/Luxembourg residents may be necessary to avoid triggering Luxembourg/EU regulatory requirements if the operator does not wish to become a registered VASP.
- Under MiCA (once applicable), a full authorization from the CSSF will be required to provide crypto-asset services across the EU, superseding the current AML registration (lu.licensing.authorization-not-just-registration-mica).
- No explicit exemption exists for DeFi frontends — the analysis turns on whether the operator exercises control or custody.
Key Risks
- Regulatory ambiguity: It is unclear whether a non-custodial DeFi frontend that merely routes users to permissionless smart contracts constitutes a VASP under Luxembourg law, creating legal uncertainty.
- Enforcement risk: CSSF may issue warnings or cease-and-desist orders against unregistered entities operating without proper VASP registration (lu.enforcement.issuing-warnings-for-unregistered-activities, lu.enforcement.ordering-non-compliant-entities-to-cease).
- MiCA transition risk: Current AML registration regime is a baseline; MiCA will impose significantly higher capital/prudential obligations and a full licensing process.
- Lack of clear safe harbor for DeFi: The CSSF has not issued specific guidance on DeFi frontends, increasing the risk of regulatory action if services are deemed to fall within VASP definitions.
- Cross-border risk: If the frontend serves EU residents without proper registration/authorization, it faces enforcement risk not only from the CSSF but potentially other EU member state regulators.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Registration as a VASP: Entities providing "custodian wallet services" (which includes custody of virtual assets on behalf of clients) are considered Virtual Asset Service Providers (VASPs) under Luxembourg law. These VASPs are subject to registration with the CSSF for AML/CFT purposes.
The registration is governed by the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"), which incorporated the EU's 5th AML Directive.
Registration requires the entity to comply with AML/CFT obligations, including customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting, and internal control frameworks.
Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (Loi du 12 novembre 2004 relative à la lutte contre le blanchiment et contre le financement du terrorisme, telle que modifiée): While a specific URL to the consolidated law is hard to pinpoint, it's the primary legal basis. The key amendments are from 2018 and later.
CSSF Circular 22/811 (and previous versions like 20/747 and 21/769 which it consolidates/replaces): This circular provides detailed guidance on AML/CFT obligations for VASPs.
Authorization, not just Registration: MiCA will require firms providing "custody and administration of crypto-assets on behalf of third parties" to obtain a full authorization from a national competent authority (the CSSF in Luxembourg) to operate across the EU. This is a more stringent licensing regime than the current AML registration.
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):
MiCA Regulation (EU) 2023/1114, Article 67 ("Custody and administration of crypto-assets on behalf of third parties"): Specifically, Article 67(1)(b) addresses segregation.
Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"): This is the cornerstone legislation. It was significantly amended by the Law of 25 March 2020 to transpose the 5th AML Directive, explicitly including virtual asset service providers as "professionals" subject to AML/CFT obligations.
CSSF Circular 20/747 (as amended by Circular 22/815): This circular is crucial for VASPs as it consolidates and specifies the AML/CFT professional obligations under the amended AML Law for all entities subject to CSSF supervision, including VASPs. It provides detailed guidance on risk assessment, customer due diligence, internal organisation, and reporting requirements.
Exchange services: Exchanging virtual assets for fiat currencies or other virtual assets.
Custodial wallet providers: Entities that provide services to safeguard private cryptographic keys on behalf of their customers, to hold, store and transfer virtual assets.
Transfer of virtual assets: Services involving the movement of virtual assets between addresses or accounts.
Identification and Verification:
Obtain and verify the customer's name, residential address, date and place of birth, nationality, and a unique identification number (e.g., from a passport or national ID card).
Verify identity using reliable, independent source documents, data, or information (e.g., government-issued photo ID, proof of address utility bill).
Beneficial Ownership (UBO): Identify and take reasonable measures to verify the identity of the beneficial owner(s) (any natural person who directly or indirectly owns or controls 25% or more of the shares or voting rights, or otherwise exercises control over the entity). For trusts or similar legal arrangements, identify the settlors, trustees, beneficiaries, and any other person exercising ultimate control.
Scrutinize transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Regularly review and update customer identification data, especially for high-risk clients.
Enhanced Due Diligence (EDD): Required for situations posing a higher ML/TF risk, including:
Politically Exposed Persons (PEPs), their family members, and close associates.
Transactions involving high-risk jurisdictions.
Complex or unusually large transactions, and all unusual patterns of transactions, that have no apparent economic or lawful purpose.
Issuing warnings for unregistered activities.
Ordering non-compliant entities to cease operations.
Focus on Registration and AML/CFT Compliance:
CSSF VASP Register (Information Page): This page explains the registration requirements and provides access to the list of registered VASPs.
CSSF Circular 23/843 (Relevant for AML/CFT for VASPs):
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — A DeFi protocol frontend operating in/from Luxembourg or serving Luxembourg residents is likely a regulated VASP if it takes custody of user assets (private keys) or charges identifiable fees; it must register with the CSSF under the AML Law and comply with full CDD/AML/CFT obligations, but the status of purely non-custodial interfaces with no fee-taking remains ambiguous.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?