Crypto ATM / kiosk operator in Slovakia
Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.
Crypto ATM is conditionally permitted in Slovakia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration as an obliged entity under Act No. 297/2008 Coll. (AML Act) — no dedicated VASP license currently, but AML registration with FIU/Ministry of Interior is required.
- Customer Due Diligence (CDD): Identify and verify natural persons (full name, DOB, place of birth, permanent address, nationality, identity document type/number, issuing authority) and legal entities (company name, registered address, registration number, directors/management, authority verification).
- Beneficial Ownership identification: Identify and verify natural persons ultimately owning/controlling >25% of the customer.
- Ongoing transaction monitoring: Continuously scrutinize transactions throughout the business relationship to ensure consistency with customer risk profile.
- Suspicious Activity Reporting (SAR): Report any transaction, attempted transaction, or activity where there are reasonable grounds to suspect proceeds of crime or terrorist financing — reports must be submitted promptly/immediately upon suspicion.
- Enhanced Due Diligence (EDD) required for: PEPs and their family/associates, high-risk jurisdictions (FATF/EC listed), complex or unusually large transactions, new/developing technologies (including virtual assets), non-face-to-face business relationships.
- Source of Funds (SoF) and Source of Wealth (SoW) measures required for high-risk relationships or transactions.
- Internal risk management systems and policies must be implemented by obliged entities.
- From December 30, 2024: MiCA takes effect — mandatory CASP authorization required from NBS, with application demonstrating organizational, operational, and prudential compliance, plus strict segregation of client assets.
Key Restrictions
- No dedicated crypto ATM/kiosk license currently exists — operator must register as an obliged entity under the AML Act (Act No. 297/2008 Coll.).
- From December 30, 2024, a mandatory CASP authorization from NBS (National Bank of Slovakia) will be required under MiCA, with application, capital, and organizational requirements.
- No specific cold storage mandate exists under current law, but robust security measures are expected.
- No specific insurance/bonding mandates for crypto custody under current Slovak law.
- Non-face-to-face business relationships (standard for ATMs) trigger enhanced due diligence obligations.
- Cash-in / cash-out operations likely trigger the 'high-cash AML risk profile' and associated EDD requirements.
Key Risks
- No dedicated crypto licensing regime until MiCA applies (Dec 30, 2024) — regulatory ambiguity for ATM operators regarding what constitutes a financial service vs. an AML-only obliged entity.
- High enforcement risk: NBS issues frequent warnings about unlicensed crypto services; NAKA (National Criminal Agency) actively pursues crypto-related fraud and money laundering cases with seizures of assets.
- Cash-intensive model attracts elevated scrutiny under AML Act — cash transaction thresholds and cash reporting obligations are not explicitly defined for crypto ATMs in the provided facts, creating compliance uncertainty.
- MiCA transition period risk: operators set up under current AML-only regime may need to re-authorize as CASPs by Dec 30, 2024, with potentially different capital and governance requirements.
- Non-face-to-face CDD for ATM users is inherently high-risk under Slovak AML rules, potentially requiring additional verification measures beyond what a kiosk can easily provide.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Registration, not a dedicated license: Currently, there isn't a specific "crypto custody license" in the traditional financial sense. However, entities providing services related to virtual assets, including custodian wallet providers, are considered "obliged entities" under Slovak AML law.
AML Obligations: This means they must comply with AML/CFT requirements, such as customer due diligence (CDD), transaction monitoring, suspicious activity reporting (SARs), and implementing internal risk management systems.
National Legislation: These obligations stem from Act No. 297/2008 Coll. on measures against the legalization of proceeds of crime and the financing of terrorism (Zákon č. 297/2008 Z. z. o ochrane pred legalizáciou príjmov z trestnej činnosti a o ochrane pred financovaním terorizmu). This Act has been amended multiple times to transpose the 4th, 5th, and 6th EU AML Directives.
Competent Authorities: For AML purposes, the Financial Intelligence Unit (FIU) within the Ministry of Interior is key, but the National Bank of Slovakia (Národná banka Slovenska - NBS) supervises financial institutions, which could include certain crypto-related activities if deemed financial services.
Act No. 297/2008 Coll. (AML Act): Link to Slov-Lex, the Slovak legislative database (in Slovak) (Search for the consolidated version to include amendments).
National Bank of Slovakia (NBS) general information on Virtual Assets (in Slovak): https://www.nbs.sk/sk/dohlad-nad-financnym-trhom/dohlad-nad-virtualnymi-aktivami (This page confirms the application of AML rules and highlights upcoming MiCA).
Insurance/Bonding Requirements (Current):
None specific to crypto custody: There are no national insurance or bonding mandates specifically for crypto custody providers under current Slovak law.
Cold Storage Mandates (Current):
No specific mandate: Slovak law does not currently mandate the use of cold storage for crypto assets. Custodians are expected to implement robust security measures, but the specific technology is not prescribed.
Publication: MiCA was published in the Official Journal of the European Union on June 9, 2023.
All other titles, including those related to CASPs and custody, will apply from December 30, 2024.
Mandatory Authorization: Under MiCA (Title V), any entity providing "custody and administration of crypto-assets on behalf of clients" (Article 68) will be considered a Crypto-Asset Service Provider (CASP) and will need to be authorized by the national competent authority. In Slovakia, this will most likely be the National Bank of Slovakia (NBS).
Application Process: CASPs will need to apply for authorization, demonstrating compliance with various organizational, operational, and prudential requirements.
Segregation of Client Assets Rules (Current):
Strict Segregation Mandate: MiCA explicitly requires CASPs providing custody services to:
Act No. 297/2008 Coll. on Protection Against Legalisation of Proceeds of Crime and Against Financing of Terrorism (AML Act): This is the primary legislation in Slovakia governing AML/CFT. It has been amended multiple times, most notably by Act No. 397/2019 Coll., which transposed the 5AMLD and extended its scope to virtual assets and VASPs.
Virtual currency exchange services: Providers exchanging virtual currencies for fiat currencies, or vice versa, or between one or more forms of virtual assets.
Custodian wallet providers: Entities that provide services to safeguard private cryptographic keys on behalf of their customers, to hold, store, and transfer virtual assets.
Providers of other services related to virtual assets: This can be broadly interpreted to include other services like issuance, transfer, or administration of virtual assets.
Identification of the Customer and Verification of Identity:
Natural Persons: Full name, date of birth, place of birth, permanent address, nationality, type and number of identity document, and the issuing authority. Identity must be verified using reliable, independent sources (e.g., government-issued ID).
Legal Entities: Company name, registered address, registration number, identification of directors/management, and verification of their authority.
Identification of the Ultimate Beneficial Owner (UBO):
Identify the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted. This usually means individuals holding 25% or more of the shares/voting rights, or otherwise exercising control.
Understanding the Purpose and Nature of the Business Relationship/Transaction:
Continuously scrutinize transactions throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Politically Exposed Persons (PEPs): Customers who are or have been entrusted with prominent public functions, their family members, or close associates.
High-risk jurisdictions: Customers or transactions involving countries identified as having strategic AML/CFT deficiencies by FATF or the European Commission.
Complex or unusually large transactions: Or transactions with an unusual pattern, without an apparent economic or lawful purpose.
New or developing technologies: Including virtual assets, where the risks may not be fully understood.
Non-face-to-face business relationships: Where there is no physical meeting with the customer.
Source of Funds (SoF) and Source of Wealth (SoW): VASPs must take reasonable measures to establish the source of funds and wealth involved in high-risk relationships or transactions.
Obligation to Report: Any transaction, attempted transaction, or activity where the VASP suspects or has reasonable grounds to suspect that funds are proceeds of criminal activity or are linked to terrorist financing.
Timing: Reports must be submitted promptly, usually immediately, once a suspicion arises.
Regulator Name: National Criminal Agency (NAKA) – specifically the National Unit for Combating Financial Crime.
Entity Targeted: An organized criminal group involving multiple individuals suspected of operating a sophisticated investment fraud scheme and subsequent money laundering using cryptocurrencies. Violation Type: Investment fraud, money laundering, unauthorized business activities, establishment, masterminding, and support of a criminal group. The scheme involved luring victims into fake crypto investment platforms.
Seizure of assets: During the operation, authorities seized financial assets, movable property, and real estate worth approximately €15 million. This includes accounts, cryptocurrencies, and other assets believed to be proceeds of crime.
Regulator Name: National Bank of Slovakia (Národná banka Slovenska - NBS).
Evidence fact sk.enforcement.nbs-has-issued-numerous not found (may have been renamed).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — Crypto ATM/kiosk operators may operate in Slovakia, but only if registered as obliged entities under Act No. 297/2008 Coll. (AML Act) and compliant with full CDD/EDD/SAR obligations, with mandatory MiCA CASP authorization from NBS required from December 30, 2024.
Questions this verdict aims to answer
- What money-transmitter / kiosk-specific license is required?
- What cash-transaction reporting thresholds apply?
- What enhanced-KYC obligations attach to cash-in / cash-out?