DeFi protocol frontend in Netherlands
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Netherlands with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- KYC (customer identification and verification) required under WWFT if the frontend qualifies as a CASP providing exchange or custody services
- Transaction monitoring obligations under WWFT for crypto service providers registered with DNB
- Suspicious transaction reporting (unusual transactions) to DNB under WWFT
- Fit-and-proper tests for UBOs and management required for CASP authorization
- MiCA CASP authorization requires comprehensive AML/CFT policies, business plans, and ongoing supervision by DNB/AFM
Key Restrictions
- DeFi frontends that provide exchange or custody services (e.g., via integrated swap or bridging features) likely constitute CASP activities under MiCA and require a MiCA license from AFM/DNB
- Pre-MiCA DNB registration had ~90% rejection rate, indicating very high bar for compliance; post-transition (June 30, 2025) only licensed entities can operate
- Fee-taking (e.g., interface fees, routing fees) strengthens the case that the frontend is providing a regulated crypto-asset service as an 'operator' or 'intermediary' rather than merely displaying information
- Geofencing (blocking NL/IPs) may reduce regulatory exposure if the frontend does not actively solicit NL residents, but risk remains if services are available to residents
- If the frontend does not take custody of user funds or execute trades (pure informational aggregator), the CASP classification is less clear, but DNB/AFM may still assert jurisdiction over any intermediation activity
Key Risks
- Strict enforcement precedent: DNB has fined unregistered platforms (e.g., Binance, Coinbase) for operating without registration
- AMBIGUITY: It is not fully resolved whether a non-custodial DeFi frontend with no fee-taking qualifies as a CASP — regulator may take expansive view
- Transitional period ended June 30, 2025 — operating without a MiCA license post-transition carries enforcement risk including fines and criminal liability under WWFT
- UBO integrity screening is rigorous and many applicants (especially international crypto firms) were rejected pre-MiCA; similar scrutiny expected under MiCA
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
DNB — VASP registration (~90% rejection rate pre-MiCA), AML/CFT supervision
MiCA Regulation (EU) (2023) — CASP authorization, comprehensive crypto regulation
WWFT (Anti-Money Laundering and Anti-Terrorist Financing Act) (2018) — Pre-MiCA VASP AML registration with DNB — rigorous WWFT compliance
VASP: CASP authorization under MiCA via DNB/AFM. Pre-MiCA DNB registration had ~90% rejection rate. Substantial UBO integrity screening. Several exchanges withdrew from Netherlands.
CUSTODY: CASP authorization — custody is a licensed MiCA activity
EXCHANGE: CASP authorization under MiCA; rigorous UBO integrity screening
AFM: Licenses and supervises crypto-asset service providers under MiCAR; opened its digital portal for MiCAR license applications as of April 22, 2024
DNB: Maintains the register of crypto service providers and oversees AML/CFT compliance under the Wwft
Comprehensive: Regulated via Dutch implementation of EU rules (e.g., 5AMLD and MiCA) rather than standalone national laws; covers AML/CTF, licensing, and supervision without prohibiting crypto.
Applies to crypto exchanges, custodian wallet providers, and CASPs; stablecoins and unbacked cryptos (e.g., Bitcoin) have specific oversight.
Transitional period ended June 30, 2025: Existing CASPs could operate under prior rules while applying for MiCA licenses; only licensed entities allowed post-transition.
De Nederlandsche Bank (DNB): Central bank; handles AML/CTF registration for crypto service providers (exchanges, custodians), monitors compliance, supervises stablecoin issuers under MiCA, and enforces Wwft/Sanctions Act. Requires fit-and-proper tests, business plans, and policies for registration.
Dutch Authority for the Financial Markets (AFM): Supervises conduct, handles MiCA license applications/notifications for CASPs (opened portal April 22, 2024), and applies Financial Supervision Act (Wft) if crypto qualifies as financial instruments.
Wwft (Dutch Money Laundering and Anti-Terrorist Financing Act): Implements 5AMLD (effective May 21, 2020); mandates DNB registration for exchanges and custodian wallets, with KYC, transaction monitoring, and suspicious activity reporting. Non-compliance risks fines/imprisonment.
Markets in Crypto-Assets Regulation (MiCA/MiCAR): EU-wide (enacted 2024, licenses effective December 30, 2024); AFM processes applications, promotes transparency; DNB focuses on stablecoins.
Strict enforcement: Fines on unregistered platforms (e.g., Binance, Coinbase).
Legal and encouraged with oversight: Trading/owning crypto permitted; providers must register with DNB (pre-MiCA) or obtain AFM MiCA licenses post-2025. AFM advises new providers to apply directly for MiCA rather than DNB registration.
AFM MiCA portal: Referenced in CMS guide (applications since April 2024).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — DeFi protocol frontends operating in/for the Netherlands likely require MiCA CASP authorization from AFM/DNB if they provide exchange, custody, or intermediation services (especially if fee-taking), with high licensing burden, rigorous UBO screening, and significant enforcement risk for unlicensed operation post-June 2025 transition deadline.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?