DeFi protocol frontend in Qatar
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is not permitted in Qatar.
Verdict Details
- Permitted
- no
- Local entity required
- No
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD required under Law No. 20 of 2019 — obtain and verify name, permanent address, date of birth, nationality, official ID (QID/passport) for natural persons
- Beneficial ownership identification required for any legal person owning 25% or more
- Source of funds and source of wealth information required for high-risk customers or transactions
- Ongoing monitoring of business relationships and transactions for unusual or suspicious activity
- PEP screening and enhanced due diligence (EDD) required
- Sanctions screening against UNSC sanctions lists required
- STRs must be filed with the Qatar Financial Information Unit (QFIU) — no tipping-off permitted
- Record retention: minimum 5 years from date of transaction or end of business relationship, whichever is later
- Cross-border virtual asset transfers attract EDD obligations
- EDD for new technologies or business practices — likely covers DeFi interaction models
Key Restrictions
- QFCRA FSRU Rule 2.1.3(1) prohibits a Firm from undertaking any Financial Service or other activity relating to a Virtual Asset — a DeFi frontend facilitating swaps, trades, or transfers of virtual assets would fall within this prohibition
- The QFCRA Glossary defines 'Virtual Asset' broadly — covers any digital representation of value that can be digitally traded or transferred, used for payment or investment purposes, excluding only digital fiat, securities, and other already-regulated financial assets
- No dedicated VASP licensing framework exists — there is no path to lawfully obtain a license for this activity within QFC or under QCB
- The prohibition applies to QFC firms; operating from outside the QFC without a QFC presence does not avoid the virtual-asset activity restriction under Qatari law if serving residents
Key Risks
- Qatar has maintained a restrictive stance on direct retail crypto activities — enforcement risk for any operator serving Qatari residents
- Law No. 20 of 2019 brings virtual assets within the AML/CFT framework even while licensing is absent — operators could face criminal exposure for unlicensed financial services and AML violations simultaneously
- QCB has been exploring a wholesale CBDC but has given no indication of permitting private crypto intermediaries
- No grandfathering or transitional provisions exist for existing crypto service providers
- Any fee-taking (e.g., frontend swap fees, routing fees) could constitute a 'Financial Service' relating to a Virtual Asset, bringing the operator squarely within the QFCRA prohibition
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
QFCRA Financial Services Rulebook (FSRU) and General Rules (GENU):
Rule 2.1.3(1) of the FSRU states: "A Firm must not undertake a Financial Service or other activity relating to a Virtual Asset."
The QFCRA Glossary defines "Virtual Asset" broadly as "any digital representation of value that can be digitally traded or transferred and used for payment or investment purposes, but does not include digital representations of fiat currencies, securities and other financial assets that are already covered by the QFCRA’s regulatory framework."
Current Status: There are no specific licenses for dedicated cryptocurrency custody businesses in Qatar. This is because the QFCRA prohibits firms from engaging in activities related to Virtual Assets, as detailed above.
Exceptions/Nuances: The prohibition explicitly excludes "digital representations of fiat currencies, securities and other financial assets that are already covered by the QFCRA’s regulatory framework." This means that if a tokenized security (e.g., a security issued on a blockchain) is regulated as a traditional security under QFCRA rules, then a licensed firm within the QFC could potentially custody such a tokenized security under its existing securities custody license. However, this is distinct from general cryptocurrency custody.
Law No. (20) of 2019 on Combating Money Laundering and Terrorist Financing: This is the foundational law establishing the AML/CFT framework, defining offenses, obligations for reporting entities, and the powers of regulatory and law enforcement bodies. It aligns Qatar's framework with the latest FATF Recommendations.
Qatar Financial Centre Regulatory Authority (QFCRA) Rulebook: For entities licensed within the Qatar Financial Centre (QFC), the QFCRA Rulebook, particularly its AML/CFT Rulebook, provides specific and comprehensive requirements. The QFC has been more explicit in classifying and regulating virtual asset activities.
Identification and Verification of Customers:
Natural Persons: Obtain and verify the customer's name, permanent address, date of birth, nationality, and official identification document number (e.g., QID, passport).
Beneficial Ownership Identification: Identify and verify the identity of the beneficial owner(s) – any natural person(s) who ultimately own or control 25% or more of the legal person, or on whose behalf a transaction is being conducted.
Source of Funds and Source of Wealth: For high-risk customers or transactions, obtain information on the source of funds (where the funds came from for a specific transaction) and the source of wealth (the overall economic activity that generates the customer's total net worth). This is particularly crucial in the virtual asset space.
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring for unusual or suspicious activities.
Politically Exposed Persons (PEPs): Implement procedures to determine if a customer or beneficial owner is a PEP. Apply enhanced due diligence (EDD) measures to PEPs, their family members, and close associates.
Sanctions Screening: Screen customers and transactions against national and international sanctions lists (e.g., UNSC sanctions).
Enhanced Due Diligence (EDD): Apply EDD for higher-risk scenarios, which often include:
Cross-border virtual asset transfers.
New technologies or business practices.
Report Suspicious Activity: Immediately report any transaction, attempted transaction, or funds where there are reasonable grounds to suspect that they are linked to money laundering or terrorist financing.
Reporting Body: All STRs must be submitted to the Qatar Financial Information Unit (QFIU).
Duration: Records must be maintained for a minimum of five (5) years from the date of the transaction or the end of the business relationship, whichever is later.
Legal Basis: Qatar implements UN Security Council Resolutions through its domestic legal framework, primarily Law No. 20 of 2019 on Combating Money Laundering and Terrorist Financing. This law mandates compliance with UN sanctions, including the freezing of funds and assets of designated individuals and entities.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Not permitted — QFCRA FSRU Rule 2.1.3(1) prohibits any firm from undertaking a Financial Service or other activity relating to a Virtual Asset; there is no dedicated VASP licensing framework in Qatar, and a DeFi frontend facilitating virtual-asset swaps or transfers would fall squarely within the prohibition, with no available license or exemption path.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?