Custodial wallet / SaaS in Portugal
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Portugal with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Full compliance with Law No. 83/2017 (Anti-Money Laundering Law) and FATF standards is mandatory (pt.aml.full-compliance-with-law-no).
- KYC procedures: identify and verify client identity, understand business relationships, and document beneficial ownership in a Central Register (pt.aml.kyc-procedures-identify-and-verify).
- Ongoing transaction monitoring and regular reporting to Unidade de Informação Financeira (UIF) (pt.aml.ongoing-transaction-monitoring-and-regular).
- Internal compliance programs including risk assessments, internal policies, and staff training (pt.aml.internal-compliance-programs-including-risk).
- Compliance with restrictive measures approved by the UN or EU (pt.aml.compliance-with-restrictive-measures-approved).
- CASPs must collect, retain, and share Travel Rule data (originator/beneficiary details) under TFR (pt.aml.casps-must-collect-retain-and).
- For transactions involving self-hosted wallets, CASPs must request proof of ownership/control for amounts ≥ EUR 1,000 (pt.aml.for-transactions-involving-self-hosted-wallets).
- Enhanced measures for self-hosted wallets: data collection/retention plus verification for ≥ EUR 1,000 (pt.aml.enhanced-measures-for-self-hosted-wallets).
- Data verification, recordkeeping, security measures, and alignment with TFR for AML/CFT (immediate/secure sharing) (pt.aml.requirements-include-data-verification-recordkeeping).
- Annual IRS declaration of crypto assets required (pt.aml.february-2024-bill-mandates-annual).
- Compliance with restrictive measures approved by the UN or EU (pt.aml.compliance-with-restrictive-measures-approved).
Key Restrictions
- Custodial wallet / SaaS operators must obtain MiCA authorization as a CASP (crypto-asset service provider) under Law No. 69/2025, effective July 2026 (pt.aml.law-no-692025-december-2025).
- Custodial services (storage of crypto-assets and encrypted keys) is a specifically licensable activity in Portugal (pt.licensing.custodial-services-storage-of-crypto-assets).
- VASPs already registered with BdP by December 30, 2024 can operate under transitional MiCA rules until June 30, 2026; after that, full MiCA authorization is required (pt.aml.portuguese-aml-law-governs-vasp).
- Banco de Portugal (BdP) registers VASPs and supervises AML/CFT; handles MiCA authorization applications for CASPs starting July 2026 (pt.aml.banco-de-portugal-bdp-bank).
- CMVM determines whether crypto-assets qualify as financial instruments, which could impose securities-level custody rules (pt.aml.comisso-do-mercado-de-valores).
- Law No. 69/2025 treats CASPs as financial entities under AML rules (pt.aml.law-no-692025-december-2025).
- No general de minimis threshold for transfers other than the EUR 1,000 self-hosted wallet threshold (pt.aml.no-general-de-minimis-threshold).
Key Risks
- Ongoing MiCA implementation creates regulatory transition risk: current VASP registration regime shifts to full CASP authorization by July 2026, with potential gaps in interim clarity.
- CMVM may classify certain custodied assets as financial instruments, triggering securities-level custody requirements beyond standard VASP rules (pt.aml.comisso-do-mercado-de-valores).
- Travel Rule compliance (TFR) with GDPR creates practical data-sharing challenges, especially for cross-border SaaS operations (pt.aml.no-specific-protocols-eg-interoperability).
- 28% tax on crypto gains held <365 days (Lei n.º 24-D/2022) may create tax reporting complexity for white-label clients (pt.aml.lei-n-24-d2022-state-budget).
- Enforcement activity exists: Eurojust coordinated a €100M+ crypto fraud operation in September 2025 involving Portugal (pt.enforcement.september-2025-eurojust-coordinated-an).
- SaaS operator may bear AML program responsibility for white-labeled services, but liability allocation between SaaS provider and white-label client is not explicitly defined under Portuguese law.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Custodial services (storage of crypto-assets and encrypted keys)
Full compliance with Law No. 83/2017 (Anti-Money Laundering Law) and FATF standards is mandatory
KYC procedures: Identify and verify client identity, understand the nature of business relationships, and document beneficial ownership information in a Central Register
Ongoing transaction monitoring and regular reporting to Unidade de Informação Financeira (UIF)
Internal compliance programs including risk assessments, internal policies, and staff training
Compliance with restrictive measures approved by the UN or EU
Banco de Portugal (BdP, Bank of Portugal): Registers virtual asset service providers (VASPs) and supervises AML/CFT compliance; handles MiCA authorization applications for crypto-asset service providers (CASPs) starting July 2026.
Comissão do Mercado de Valores Mobiliários (CMVM, Portuguese Securities Market Commission): Determines if crypto-assets qualify as financial instruments; shares MiCA supervision with BdP.
Law No. 69/2025 (December 2025): Incorporates MiCA and Transfer of Funds Regulation (TFR) into national law; treats CASPs as financial entities under AML rules; effective July 2026.
Law No. 70/2025 (January 2026): Further implements TFR alongside MiCA.
Portuguese AML Law: Governs VASP registration; VASPs registered by December 30, 2024, can operate under transitional MiCA rules until June 30, 2026.
Applies to Crypto-Asset Service Providers (CASPs), formally integrated into Portugal's AML regime.
Banco de Portugal (BdP) supervises compliance for CASPs and payment service providers; registered CASPs can operate under MiCA transitional rules until July 1, 2026.
CASPs must collect, retain, and share Travel Rule data (e.g., originator/beneficiary details for unique transfer identification) for transparency in transfers.
For transactions involving self-hosted wallets, CASPs must request proof of ownership/control for amounts of EUR 1,000 or more (per TFR Chapter III, Section 1, Article 1(5)).
Enhanced measures for self-hosted wallets when a regulated entity is involved: data collection/retention by originating CASP, plus verification for ≥EUR 1,000.
Requirements include data verification, recordkeeping, security measures, and alignment with TFR for AML/CFT (e.g., immediate/secure sharing).
No general de minimis threshold is explicitly detailed for all transfers beyond this; it aligns with FATF's recommended EUR 1,000 limit, though countries vary implementation.
No specific protocols (e.g., interoperability solutions) mandated beyond TFR; challenges like GDPR and tech fragmentation noted globally.
Lei n.º 24-D/2022 (State Budget Law, effective January 1, 2023): Introduced 28% tax on crypto gains held <365 days; long-term gains (>365 days) tax-free unless involving tax havens or security tokens.
February 2024 bill: Mandates annual IRS declaration of crypto assets.
September 2025: Eurojust coordinated an operation halting a cryptocurrency investment fraud exceeding 100 million euros across Europe, resulting in five arrests including the alleged main perpetrator.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers can operate in Portugal but must register as VASPs with Banco de Portugal (current regime) and transition to full MiCA CASP authorization by July 2026, with comprehensive AML/CFT obligations including KYC, Travel Rule compliance, transaction monitoring, and potential reclassification by CMVM if custodied assets are deemed financial instruments.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?