Centralized exchange in Poland
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Poland with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with GIIF (Minister of Finance) under the Polish AML Act (Ustawa z dnia 1 marca 2018 r.) before commencing operations.
- Customer Due Diligence (CDD) — identify and verify identity of clients and beneficial owners, screen against sanctions lists.
- Ongoing monitoring of client relationships and transactions for suspicious activity.
- Transaction monitoring systems to detect unusual patterns or thresholds.
- Suspicious Transaction Reports (STRs) to GIIF.
- Record-keeping of client identification data and transactions for at least 5 years.
- Appoint a designated AML Officer (Compliance Officer).
- Develop and implement internal AML/CTF procedures, including a business-specific risk assessment.
- Provide regular AML/CTF training for all relevant employees.
- Travel Rule obligations apply on withdrawals — under the current AML Act and future MiCA framework (Article 67), transfers of crypto-assets must be accompanied by originator and beneficiary information.
Key Restrictions
- Must be a Polish legal entity (e.g., Sp. z o.o. or S.A.) with at least one management board member residing in Poland or holding Polish citizenship.
- Management board members and beneficial owners must meet fit-and-proper criteria (no criminal record for intentional financial crimes).
- Proof of knowledge and experience in virtual currencies required for registration.
- No specific minimum capital requirement currently, but MiCA will introduce capital requirements of €50,000–€150,000 from December 2024.
- MiCA will require segregation of client crypto-assets and funds (Article 67) — a separate agreement with clients and operational segregation must be in place.
- Under MiCA, CASPs must obtain authorization from the KNF (Polish Financial Supervision Authority) and obtain passportable EU license.
- Custody services must comply with MiCA's operational, IT security, and business continuity requirements.
Key Risks
- Current Polish AML Act does not explicitly mandate segregation of client assets for VASPs — regulatory gap exposes operators to civil liability if client assets are not segregated in practice.
- No specific definition of a 'qualified custodian' under current Polish law for virtual assets — ambiguity in custody standards until MiCA fully applies.
- Transition period from current GIIF registration regime to MiCA authorization with KNF may create regulatory uncertainty and dual-compliance burden.
- Enforcement precedent under the current AML Act is limited — sanctions risk for non-compliance with registration obligations.
- Failure to comply with Travel Rule obligations (originator/beneficiary data for crypto transfers) could result in sanctions from GIIF.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Current (Registration): Poland operates a registration regime for VASPs under its AML Act. This means entities must register their activities with GIIF and comply with AML/CTF obligations. It is not a full "licensing" regime in the sense of prudential supervision (e.g., capital adequacy, operational risk, consumer protection oversight by KNF) like banks or investment firms currently face. The focus is purely on preventing money laundering and terrorist financing.
Legal Entity / Local Presence:
The applicant must be a Polish legal entity (e.g., Spółka z ograniczoną odpowiedzialnością - limited liability company, or Spółka akcyjna - joint-stock company).
At least one individual from the management board of the Polish legal entity must have their residence in Poland or possess a Polish citizenship.
Fit & Proper Criteria (Management/Owners):
Internal AML/CTF Procedures: Develop and implement robust internal anti-money laundering and counter-terrorist financing procedures, including a risk assessment specific to the business and its clients.
AML Officer: Appoint a designated individual responsible for AML/CTF compliance (AML Officer or Compliance Officer).
Customer Due Diligence (CDD): Implement procedures for identifying and verifying the identity of clients, including beneficial owners, and understanding the purpose and nature of business relationships. This involves collecting identity documents, verifying data, and screening against sanctions lists.
Ongoing Monitoring: Conduct ongoing monitoring of client relationships and transactions to detect suspicious activities.
Transaction Monitoring: Implement systems to monitor transactions for unusual patterns or thresholds.
Reporting: Report suspicious transactions and activities to GIIF.
Record-keeping: Maintain records of client identification data and transactions for at least 5 years.
Training: Provide regular AML/CTF training for relevant employees.
Under the current Polish AML Act, there are NO specific minimum capital requirements solely for VASP registration. This is a significant difference from traditional financial licenses.
Future MiCA Impact: MiCA will introduce capital requirements for Crypto-Asset Service Providers (CASPs), ranging from €50,000 to €150,000 depending on the type of services provided.
Virtual currency exchange service: This includes exchanging virtual currencies for fiat currencies and vice-versa, as well as exchanging one virtual currency for another. This category explicitly covers exchanges.
Virtual currency safekeeping wallet service: This refers to the provision of services for safeguarding private cryptographic keys on behalf of clients, to hold, store, and transfer virtual currencies. This explicitly covers custody providers.
Requirement: Entities providing services related to virtual currencies, including "holding virtual currencies, including offering services to their users that consist of maintaining virtual currency instruments or access keys on their behalf," are considered Virtual Asset Service Providers (VASPs). These entities are obliged to register in the Register of Activities in the Field of Virtual Currencies (Rejestr Działalności w Zakresie Walut Wirtualnych).
Regulatory Body: The register is maintained by the Minister of Finance.
Purpose: This registration primarily serves AML/CFT purposes, ensuring that service providers implement appropriate customer due diligence (KYC), transaction monitoring, and suspicious activity reporting measures. It is not a comprehensive prudential license.
Current Status: The current Polish AML Act does not explicitly mandate specific rules for the segregation of client assets for virtual currency custodians. While good practice and general commercial law principles might suggest segregation, there is no direct regulatory requirement specific to crypto custody in the current AML framework.
Current Status: There is no specific definition of a "qualified custodian" for virtual assets within current Polish law. The AML Act focuses on identifying and registering VASPs for AML/CFT purposes, not on their operational qualifications or prudential standards as custodians.
Requirement: Under MiCA, entities wishing to provide custody and administration of crypto-assets will need to obtain an authorization from their competent national authority (likely the Polish Financial Supervision Authority – KNF). This authorization will be passportable across the EU.
Requirement: MiCA explicitly mandates the segregation of client crypto-assets and funds. Article 67 specifies that CASPs providing custody services must:
Enter into an agreement with clients for the custody of crypto-assets.
Having a minimum initial capital (Article 60).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange is permitted in Poland under the current GIIF registration regime for VASPs, but must be structured as a Polish legal entity with a resident manager, comply with extensive AML/CTF obligations including Travel Rule data transmission, and prepare for the transition to MiCA authorization under KNF supervision with capital requirements and mandatory client asset segregation from December 2024.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?