DeFi protocol frontend in Poland
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Poland with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Register as a VASP with GIIF (Ministry of Finance) under the Polish AML Act before commencing operations.
- Implement Customer Due Diligence (CDD) procedures — identify and verify identity of clients, beneficial owners, and understand purpose of business relationships.
- Conduct ongoing monitoring of client relationships and transactions to detect suspicious activities.
- Implement transaction monitoring systems to screen for unusual patterns or threshold-based triggers.
- Report suspicious transactions and activities to GIIF (General Inspector of Financial Information).
- Maintain records of client identification data and transactions for at least 5 years.
- Appoint a designated AML Officer (Compliance Officer) responsible for AML/CTF compliance.
- Develop and implement internal AML/CTF procedures and a risk assessment specific to the business.
- Provide regular AML/CTF training for relevant employees.
- Screen clients and beneficial owners against sanctions lists.
- If fee-taking is involved, the frontend likely constitutes a 'virtual currency exchange service' (exchanging one virtual currency for another) or an intermediary in such activity, triggering full VASP registration and AML obligations.
Key Restrictions
- Must be a Polish legal entity (e.g., sp. z o.o. or S.A.) to register as a VASP.
- At least one management board member must reside in Poland or hold Polish citizenship.
- Management board members and beneficial owners must meet fit-and-proper criteria (no criminal record for intentional financial crimes).
- Proof of knowledge and experience in virtual currencies is required for registration.
- Geofencing (region restriction) and/or KYC screening likely required — the Polish AML Act's CDD obligations apply to VASPs, which this frontend likely constitutes if it takes fees or intermediates transactions.
- Under MiCA (from Dec 30, 2024), a full CASP license from KNF will replace the current registration, with capital requirements of €50k–€150k depending on services.
Key Risks
- Regulatory ambiguity: A purely non-custodial frontend that does not take fees and merely provides UI to permissionless contracts may argue it is not a VASP — but Polish AML definitions are broad and this position has not been tested in enforcement.
- Fee-taking (e.g., swap fees, frontend fees) strongly shifts classification toward 'virtual currency exchange service' under Polish law, triggering mandatory registration.
- MiCA transition risk: After Dec 30, 2024, current AML registration may be insufficient; a full KNF authorization with capital requirements will be needed, potentially disrupting operations.
- Enforcement risk: GIIF or KNF could classify non-compliant frontends as unregistered VASPs, leading to fines or criminal liability.
- Sanctions screening obligations apply; failure to restrict sanctioned jurisdictions (e.g., RF/irredentist regions) could result in EU sanctions enforcement.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Polish AML Act (current consolidated text, in Polish): Ustawa z dnia 1 marca 2018 r. o przeciwdziałaniu praniu pieniędzy oraz finansowaniu terroryzmu. You can find the consolidated text on the Polish government's legislative information system (ISAP) at: https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU20180000723
GIIF (Ministry of Finance page regarding Virtual Currencies - in Polish): https://www.gov.pl/web/finanse/dzialalnosc-w-zakresie-walut-wirtualnych (This page provides information on the register and requirements).
Virtual currency exchange service: This includes exchanging virtual currencies for fiat currencies and vice-versa, as well as exchanging one virtual currency for another. This category explicitly covers exchanges.
Current (Registration): Poland operates a registration regime for VASPs under its AML Act. This means entities must register their activities with GIIF and comply with AML/CTF obligations. It is not a full "licensing" regime in the sense of prudential supervision (e.g., capital adequacy, operational risk, consumer protection oversight by KNF) like banks or investment firms currently face. The focus is purely on preventing money laundering and terrorist financing.
The applicant must be a Polish legal entity (e.g., Spółka z ograniczoną odpowiedzialnością - limited liability company, or Spółka akcyjna - joint-stock company).
At least one individual from the management board of the Polish legal entity must have their residence in Poland or possess a Polish citizenship.
AML Officer: Appoint a designated individual responsible for AML/CTF compliance (AML Officer or Compliance Officer).
Customer Due Diligence (CDD): Implement procedures for identifying and verifying the identity of clients, including beneficial owners, and understanding the purpose and nature of business relationships. This involves collecting identity documents, verifying data, and screening against sanctions lists.
Ongoing Monitoring: Conduct ongoing monitoring of client relationships and transactions to detect suspicious activities.
Transaction Monitoring: Implement systems to monitor transactions for unusual patterns or thresholds.
Reporting: Report suspicious transactions and activities to GIIF.
Record-keeping: Maintain records of client identification data and transactions for at least 5 years.
Training: Provide regular AML/CTF training for relevant employees.
Internal AML/CTF Procedures: Develop and implement robust internal anti-money laundering and counter-terrorist financing procedures, including a risk assessment specific to the business and its clients.
Fit & Proper Criteria (Management/Owners):
Individuals intending to perform activities in the field of virtual currencies, as well as members of the management board and beneficial owners, must:
Requirement: Entities providing services related to virtual currencies, including "holding virtual currencies, including offering services to their users that consist of maintaining virtual currency instruments or access keys on their behalf," are considered Virtual Asset Service Providers (VASPs). These entities are obliged to register in the Register of Activities in the Field of Virtual Currencies (Rejestr Działalności w Zakresie Walut Wirtualnych).
Conditions for Registration:
Individuals involved in management or ownership must not have been convicted of specific financial crimes or money laundering offenses.
Proof of knowledge and experience in the field of virtual currencies (e.g., certificate of completion of training, professional experience) is required.
Regulatory Body: The register is maintained by the Minister of Finance.
Current Status: The current Polish AML Act does not explicitly mandate specific rules for the segregation of client assets for virtual currency custodians. While good practice and general commercial law principles might suggest segregation, there is no direct regulatory requirement specific to crypto custody in the current AML framework.
Requirement: MiCA explicitly mandates the segregation of client crypto-assets and funds. Article 67 specifies that CASPs providing custody services must:
Titles II, V-XII (covering other crypto-assets and crypto-asset service providers, including custody) apply from 30 December 2024.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — A DeFi protocol frontend that takes fees or intermediates virtual currency transactions likely constitutes a Virtual Asset Service Provider (VASP) under Polish AML law, requiring registration with GIIF, a local Polish legal entity, and comprehensive AML/KYC obligations; purely non-custodial UI-only frontends with no fee-taking face regulatory ambiguity, and full MiCA licensing (with capital requirements) will apply from December 2024.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?