← Regulations / Luxembourg / Operating Models / DeFi frontend

DeFi protocol frontend in Luxembourg

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Luxembourg with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration with the CSSF as a VASP (Virtual Asset Service Provider) under the Law of 12 November 2004 (AML Law) if the frontend provides 'custodian wallet services' or otherwise falls within the VASP definition.
  • CDD obligations: Obtain and verify customer's name, address, date/place of birth, nationality, and unique ID number from reliable independent documents (lu.aml.obtain-and-verify-the-customers, lu.aml.verify-identity-using-reliable-independent).
  • For legal entities: Obtain and verify company name, legal form, registered address, articles of association, list of directors, proof of incorporation, and UBO identification (25%+ ownership/control threshold) (lu.aml.legal-entities-companies-foundations-etc, lu.aml.beneficial-ownership-ubo-identify-and).
  • Ongoing transaction monitoring: Scrutinize transactions to ensure consistency with customer risk profile; regular review/update of CDD data (lu.aml.scrutinize-transactions-undertaken-throughout-the, lu.aml.regularly-review-and-update-customer).
  • Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, and complex/unusually large transactions with no apparent economic purpose (lu.aml.enhanced-due-diligence-edd-required, lu.aml.politically-exposed-persons-peps-their, lu.aml.transactions-involving-high-risk-jurisdictions, lu.aml.complex-or-unusually-large-transactions).
  • Suspicious Transaction Reporting (STR) obligations to the CSSF.
  • Internal control frameworks and AML/CFT compliance program required under CSSF Circular 22/811 (lu.licensing.cssf-circular-22811-and-previous).
  • MiCA regime (Regulation EU 2023/1114) will introduce full authorization requirements and additional prudential obligations including capital or professional indemnity insurance for entities providing custody and administration of crypto-assets (lu.licensing.authorization-not-just-registration-mica, lu.licensing.mica-regulation-eu-20231114-article).

Key Restrictions

  • If the frontend takes custody of user assets (e.g., holds private keys), it qualifies as a VASP providing 'custodian wallet services' and must register with the CSSF under the AML Law (lu.licensing.registration-as-a-vasp-entities).
  • If the frontend merely acts as a non-custodial interface (no key custody, no fee-taking beyond standard protocol fees), it may fall outside VASP classification — but this is fact-dependent and ambiguous.
  • Fee-taking (e.g., frontend fees, swap fees) could increase the risk of classification as a regulated activity under Luxembourg law.
  • Geofencing / IP blocking of EU/Luxembourg residents may be necessary to avoid triggering Luxembourg/EU regulatory requirements if the operator does not wish to become a registered VASP.
  • Under MiCA (once applicable), a full authorization from the CSSF will be required to provide crypto-asset services across the EU, superseding the current AML registration (lu.licensing.authorization-not-just-registration-mica).
  • No explicit exemption exists for DeFi frontends — the analysis turns on whether the operator exercises control or custody.

Key Risks

  • Regulatory ambiguity: It is unclear whether a non-custodial DeFi frontend that merely routes users to permissionless smart contracts constitutes a VASP under Luxembourg law, creating legal uncertainty.
  • Enforcement risk: CSSF may issue warnings or cease-and-desist orders against unregistered entities operating without proper VASP registration (lu.enforcement.issuing-warnings-for-unregistered-activities, lu.enforcement.ordering-non-compliant-entities-to-cease).
  • MiCA transition risk: Current AML registration regime is a baseline; MiCA will impose significantly higher capital/prudential obligations and a full licensing process.
  • Lack of clear safe harbor for DeFi: The CSSF has not issued specific guidance on DeFi frontends, increasing the risk of regulatory action if services are deemed to fall within VASP definitions.
  • Cross-border risk: If the frontend serves EU residents without proper registration/authorization, it faces enforcement risk not only from the CSSF but potentially other EU member state regulators.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Registration as a VASP: Entities providing "custodian wallet services" (which includes custody of virtual assets on behalf of clients) are considered Virtual Asset Service Providers (VASPs) under Luxembourg law. These VASPs are subject to registration with the CSSF for AML/CFT purposes.

licensing 60% confidence

The registration is governed by the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"), which incorporated the EU's 5th AML Directive.

licensing 60% confidence

Registration requires the entity to comply with AML/CFT obligations, including customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting, and internal control frameworks.

licensing 60% confidence

Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (Loi du 12 novembre 2004 relative à la lutte contre le blanchiment et contre le financement du terrorisme, telle que modifiée): While a specific URL to the consolidated law is hard to pinpoint, it's the primary legal basis. The key amendments are from 2018 and later.

licensing 60% confidence

CSSF Circular 22/811 (and previous versions like 20/747 and 21/769 which it consolidates/replaces): This circular provides detailed guidance on AML/CFT obligations for VASPs.

licensing 60% confidence

Authorization, not just Registration: MiCA will require firms providing "custody and administration of crypto-assets on behalf of third parties" to obtain a full authorization from a national competent authority (the CSSF in Luxembourg) to operate across the EU. This is a more stringent licensing regime than the current AML registration.

licensing 60% confidence

Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):

licensing 60% confidence

MiCA Regulation (EU) 2023/1114, Article 67 ("Custody and administration of crypto-assets on behalf of third parties"): Specifically, Article 67(1)(b) addresses segregation.

aml 60% confidence

Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"): This is the cornerstone legislation. It was significantly amended by the Law of 25 March 2020 to transpose the 5th AML Directive, explicitly including virtual asset service providers as "professionals" subject to AML/CFT obligations.

aml 60% confidence

CSSF Circular 20/747 (as amended by Circular 22/815): This circular is crucial for VASPs as it consolidates and specifies the AML/CFT professional obligations under the amended AML Law for all entities subject to CSSF supervision, including VASPs. It provides detailed guidance on risk assessment, customer due diligence, internal organisation, and reporting requirements.

aml 60% confidence

Exchange services: Exchanging virtual assets for fiat currencies or other virtual assets.

aml 60% confidence

Custodial wallet providers: Entities that provide services to safeguard private cryptographic keys on behalf of their customers, to hold, store and transfer virtual assets.

aml 60% confidence

Transfer of virtual assets: Services involving the movement of virtual assets between addresses or accounts.

aml 60% confidence

Obtain and verify the customer's name, residential address, date and place of birth, nationality, and a unique identification number (e.g., from a passport or national ID card).

aml 60% confidence

Verify identity using reliable, independent source documents, data, or information (e.g., government-issued photo ID, proof of address utility bill).

aml 60% confidence

Beneficial Ownership (UBO): Identify and take reasonable measures to verify the identity of the beneficial owner(s) (any natural person who directly or indirectly owns or controls 25% or more of the shares or voting rights, or otherwise exercises control over the entity). For trusts or similar legal arrangements, identify the settlors, trustees, beneficiaries, and any other person exercising ultimate control.

aml 60% confidence

Scrutinize transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.

aml 60% confidence

Regularly review and update customer identification data, especially for high-risk clients.

aml 60% confidence

Enhanced Due Diligence (EDD): Required for situations posing a higher ML/TF risk, including:

aml 60% confidence

Politically Exposed Persons (PEPs), their family members, and close associates.

aml 60% confidence

Transactions involving high-risk jurisdictions.

aml 60% confidence

Complex or unusually large transactions, and all unusual patterns of transactions, that have no apparent economic or lawful purpose.

enforcement 60% confidence

CSSF VASP Register (Information Page): This page explains the registration requirements and provides access to the list of registered VASPs.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — A DeFi protocol frontend operating in/from Luxembourg or serving Luxembourg residents is likely a regulated VASP if it takes custody of user assets (private keys) or charges identifiable fees; it must register with the CSSF under the AML Law and comply with full CDD/AML/CFT obligations, but the status of purely non-custodial interfaces with no fee-taking remains ambiguous.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?