DeFi protocol frontend in Latvia
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Latvia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Must register as a VASP with the Financial Intelligence Unit (FIU) of Latvia if the frontend qualifies as a virtual asset service provider (e.g., by taking fees, facilitating exchanges, or providing custodial elements)
- Implement a full AML/CTPF Internal Control System (ICS) including risk assessment, client due diligence (CDD), enhanced due diligence (EDD), transaction monitoring, suspicious transaction reporting to the FIU, record-keeping (5 years), and regular AML training for employees
- Appoint a board member or employee as the designated AML Officer responsible for AML/CTPF compliance
- Conduct customer due diligence (CDD) and ongoing monitoring of business relationships
- Report suspicious transactions to the FIU
- Ensure fitness and propriety of management and beneficial owners (background checks required)
- From MiCA applicability (30 Dec 2024): transition to a full CASP license with prudential safeguards (capital requirements), specific custody/safekeeping rules if holding client assets, and IT/security arrangements
Key Restrictions
- Operator must be a legal entity registered in Latvia (typically an SIA – Limited Liability Company)
- Operator must have its registered office in Latvia
- If the frontend merely provides a non-custodial interface to permissionless smart contracts without taking custody of or exchanging virtual assets, it may fall outside the VASP definition — but fee-taking (e.g., frontend swap fees) likely triggers VASP classification as providing exchange services
- Geofencing of US persons and other sanctioned jurisdictions is expected as a practical risk-control measure, though not explicitly codified for DeFi frontends in Latvian law
- Under MiCA (from Dec 2024), a full license will be required for CASP activities; frontends facilitating exchanges will need authorization from the Bank of Latvia
Key Risks
- Regulatory ambiguity: Latvia's current VASP definition is focused on exchange, custody, and wallet services — a pure, non-custodial, fee-less DeFi frontend may not clearly fit the definition, creating legal uncertainty
- Enforcement risk: If the frontend collects fees (even via smart-contract routing), the FIU may classify it as an unregistered exchange service, exposing the operator to penalties or registration withdrawal
- MiCA transition risk: From 30 Dec 2024, the regime shifts from AML registration to full CASP licensing, raising the bar significantly for DeFi frontends
- Reputational/PR risk: Operating without a clear legal opinion in a small EU jurisdiction like Latvia may attract supervisory scrutiny as part of broader EU DeFi enforcement
- Geofencing gaps: If no user screening is implemented, the operator may be facilitating unregistered crypto services to EU residents in breach of MiCA
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Financial Intelligence Unit (FIU) of Latvia (Finanšu izlūkošanas dienests - FID): The primary authority responsible for registering and supervising VASPs for AML/CTPF compliance.
Specific VASP section: https://www.fid.gov.lv/uzraudziba/virtualo-asentu-pakalpojumu-sniedzeji (Note: Primarily in Latvian, use a translation tool.)
Current Regime (Pre-MiCA): Registration. Latvia requires entities engaged in virtual asset services to register with the FIU. This registration is primarily an AML/CTPF compliance obligation, meaning the focus is on preventing money laundering and terrorist financing, rather than prudential supervision (e.g., capital adequacy for consumer protection, market integrity, etc., which is typical of a full licensing regime).
Future Regime (Post-MiCA): Licensing. Once MiCA fully applies to VASPs (expected December 2024), Latvia will transition to a comprehensive licensing regime under MiCA. This will involve more stringent requirements, including prudential safeguards, operational resilience, and specific disclosures, and will likely be overseen by the Bank of Latvia (FCMC).
Exchanges (Virtual Asset Exchange Service Providers):
The applicant must be a legal entity registered in Latvia (typically a Limited Liability Company – SIA).
The company must have its registered office in Latvia.
AML/CTPF Internal Control System (ICS):
This is the core requirement. The company must establish a robust internal control system for AML/CTPF compliance, including:
Risk Assessment: A comprehensive assessment of the company's money laundering and terrorism financing risks.
Client Due Diligence (CDD) and Enhanced Due Diligence (EDD): Procedures for identifying and verifying clients, beneficial owners, and monitoring business relationships.
Transaction Monitoring: Systems for monitoring transactions for suspicious activities.
Reporting: Procedures for reporting suspicious transactions to the FIU.
Record-keeping: Maintaining records for a specified period (typically 5 years).
Training: Regular AML/CTPF training for employees.
Appointed AML Officer:
The company must appoint a board member or an employee (who reports directly to the board) as the responsible person for AML/CTPF compliance (the AML Officer).
Requirement: Entities providing services of custodial wallet providers (which includes safekeeping or administration of virtual assets or instruments enabling control over virtual assets on behalf of clients) are considered Virtual Asset Service Providers (VASPs). They are required to register with the Latvian Financial Intelligence Unit (FID).
Process: The registration involves demonstrating compliance with AML/CTF requirements, including:
Developing and implementing robust internal control systems.
Appointing a responsible person for AML/CTF compliance.
Conducting customer due diligence (CDD) and ongoing monitoring.
Reporting suspicious transactions.
Ensuring the fitness and propriety of management and beneficial owners.
Law on the Prevention of Money Laundering and Terrorism Financing (AML/CFT Law) (Nozagoto noziedzīgi iegūtu līdzekļu legalizācijas un terorisma finansēšanas novēršanas likums): This is the primary law regulating AML/CFT, which also covers sanctions compliance for obligated entities, including VASPs.
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):
The remaining provisions, including those for custody of other crypto-assets, apply from 30 December 2024.
Penalty Amount: Varies depending on the severity of the violation, ranging from warnings and administrative measures to significant fines. However, publicly reported large fines against pure crypto businesses are scarce. Outcome: Remedial actions required, potential fines, or in severe cases, withdrawal of registration/license.
Outcome: Remedial actions required, potential fines, or in severe cases, withdrawal of registration/license.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend operating in/from Latvia is likely a regulated VASP if it takes fees or facilitates exchanges, requiring FIU registration, a local Latvian entity (SIA), a full AML/CTPF program, and an AML officer; from December 2024 the regime transitions to a full MiCA CASP license with higher prudential requirements and Bank of Latvia supervision.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?