Centralized exchange in Slovakia
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Slovakia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Register as an obliged entity under Act No. 297/2008 Coll. (AML Act) with the Slovak FIU/Ministry of Interior.
- Perform customer due diligence (CDD): identify and verify customers (natural persons: full name, DOB, place of birth, address, nationality, ID details; legal entities: company name, registered address, registration number, directors/management).
- Identify and verify Ultimate Beneficial Owners (UBOs) — natural persons owning ≥25% or controlling the customer.
- Understand the purpose and nature of the business relationship; gather information on expected transaction activity.
- Continuously monitor transactions throughout the relationship and keep customer information up to date.
- Apply enhanced due diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusually large transactions, new technologies (including virtual assets), and non-face-to-face relationships.
- Establish Source of Funds (SoF) and Source of Wealth (SoW) for high-risk relationships.
- Report suspicious transactions/activities promptly to the FIU (immediately upon suspicion).
- Maintain internal AML/CFT risk management systems, policies, and procedures.
- From December 30, 2024 (MiCA effective date): obtain authorization as a CASP under MiCA Title V from the NBS, requiring organizational, operational, and prudential compliance.
- From MiCA date: comply with strict client-asset segregation rules under MiCA Article 68 — enter into a client agreement specifying duties, ownership rights, and segregation of client crypto-assets from the CASP's own assets.
- From MiCA date: travel-rule obligations under FATF Recommendation 16 / EU TFR implementer — collect and transmit originator and beneficiary information on transfers (including to/from unhosted wallets where applicable).
Key Restrictions
- No dedicated crypto-custody license exists pre-MiCA; operators rely on AML registration as obliged entities, which creates regulatory ambiguity.
- Pre-MiCA: no explicit cold-storage mandate, no specific custody segregation rules, no qualified-custodian definition for crypto — operators must design their own security and segregation frameworks.
- From December 30, 2024: mandatory CASP authorization under MiCA (Title V) applies, requiring a full application to the NBS with capital, governance, and operational requirements.
- MiCA requires strict segregation of client crypto-assets from the CASP's own assets, via the client agreement and operational safeguards.
- From MiCA date: EU-wide passporting available once authorized in Slovakia.
Key Risks
- Enforcement risk: NAKA (National Criminal Agency) actively investigates and prosecutes crypto-related fraud and money laundering, with criminal charges and asset seizures reaching €15M in recent operations.
- NBS issues frequent public warnings against unlicensed or fraudulent crypto operators and has signaled readiness to enforce the upcoming MiCA regime strictly.
- Pre-MiCA regulatory gap: lack of a specific crypto-custody license means operators may face uncertainty about whether their activities require additional financial-services authorizations (e.g., investment services licensing) — NBS warnings suggest risk of enforcement for unlicensed activities.
- Travel-rule compliance is required under the AML Act transposing 5AMLD/6AMLD; post-MiCA, the EU Travel of Funds Regulation will apply, requiring technical solutions for information transmission on transfers.
- Reputational and PR risk: given high-profile crypto fraud enforcement actions and consumer warnings, any compliance failure could trigger criminal investigation and significant reputational damage.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Custodial License Requirements (Current - AML Focus):
Registration, not a dedicated license: Currently, there isn't a specific "crypto custody license" in the traditional financial sense. However, entities providing services related to virtual assets, including custodian wallet providers, are considered "obliged entities" under Slovak AML law.
AML Obligations: This means they must comply with AML/CFT requirements, such as customer due diligence (CDD), transaction monitoring, suspicious activity reporting (SARs), and implementing internal risk management systems.
National Legislation: These obligations stem from Act No. 297/2008 Coll. on measures against the legalization of proceeds of crime and the financing of terrorism (Zákon č. 297/2008 Z. z. o ochrane pred legalizáciou príjmov z trestnej činnosti a o ochrane pred financovaním terorizmu). This Act has been amended multiple times to transpose the 4th, 5th, and 6th EU AML Directives.
Competent Authorities: For AML purposes, the Financial Intelligence Unit (FIU) within the Ministry of Interior is key, but the National Bank of Slovakia (Národná banka Slovenska - NBS) supervises financial institutions, which could include certain crypto-related activities if deemed financial services.
Act No. 297/2008 Coll. (AML Act): Link to Slov-Lex, the Slovak legislative database (in Slovak) (Search for the consolidated version to include amendments).
National Bank of Slovakia (NBS) general information on Virtual Assets (in Slovak): https://www.nbs.sk/sk/dohlad-nad-financnym-trhom/dohlad-nad-virtualnymi-aktivami (This page confirms the application of AML rules and highlights upcoming MiCA).
Segregation of Client Assets Rules (Current):
Insurance/Bonding Requirements (Current):
None specific to crypto custody: There are no national insurance or bonding mandates specifically for crypto custody providers under current Slovak law.
Cold Storage Mandates (Current):
No specific mandate: Slovak law does not currently mandate the use of cold storage for crypto assets. Custodians are expected to implement robust security measures, but the specific technology is not prescribed.
Qualified Custodian Definitions (Current):
Not explicitly defined for crypto: The concept of a "qualified custodian" as a specifically regulated entity for crypto assets does not exist under current Slovak law. Entities performing custody are primarily defined by their AML obligations.
Publication: MiCA was published in the Official Journal of the European Union on June 9, 2023.
Titles III (asset-referenced tokens) and IV (e-money tokens) will apply from June 30, 2024.
All other titles, including those related to CASPs and custody, will apply from December 30, 2024.
MiCA Text (Official Journal of the European Union): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1114
Custodial License Requirements (Future - MiCA):
Mandatory Authorization: Under MiCA (Title V), any entity providing "custody and administration of crypto-assets on behalf of clients" (Article 68) will be considered a Crypto-Asset Service Provider (CASP) and will need to be authorized by the national competent authority. In Slovakia, this will most likely be the National Bank of Slovakia (NBS).
Application Process: CASPs will need to apply for authorization, demonstrating compliance with various organizational, operational, and prudential requirements.
Passporting: Once authorized in Slovakia, a CASP can "passport" its services across the entire EU.
Strict Segregation Mandate: MiCA explicitly requires CASPs providing custody services to:
"Enter into a client agreement to specify their duties and responsibilities, and to ensure that clients’ rights are clearly established, including those relating to the ownership of the crypto-assets." (Article 68(2)(b))
Act No. 297/2008 Coll. on Protection Against Legalisation of Proceeds of Crime and Against Financing of Terrorism (AML Act): This is the primary legislation in Slovakia governing AML/CFT. It has been amended multiple times, most notably by Act No. 397/2019 Coll., which transposed the 5AMLD and extended its scope to virtual assets and VASPs.
Directive (EU) 2018/843 (5th Anti-Money Laundering Directive - 5AMLD): This directive extended AML/CFT obligations to VASPs for the first time.
Virtual currency exchange services: Providers exchanging virtual currencies for fiat currencies, or vice versa, or between one or more forms of virtual assets.
Custodian wallet providers: Entities that provide services to safeguard private cryptographic keys on behalf of their customers, to hold, store, and transfer virtual assets.
Providers of other services related to virtual assets: This can be broadly interpreted to include other services like issuance, transfer, or administration of virtual assets.
Identification of the Customer and Verification of Identity:
Natural Persons: Full name, date of birth, place of birth, permanent address, nationality, type and number of identity document, and the issuing authority. Identity must be verified using reliable, independent sources (e.g., government-issued ID).
Legal Entities: Company name, registered address, registration number, identification of directors/management, and verification of their authority.
Identification of the Ultimate Beneficial Owner (UBO):
Identify the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted. This usually means individuals holding 25% or more of the shares/voting rights, or otherwise exercising control.
Understanding the Purpose and Nature of the Business Relationship/Transaction:
Gather information about the reason for the customer seeking services from the VASP and the expected nature of their activity.
Continuously scrutinize transactions throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Politically Exposed Persons (PEPs): Customers who are or have been entrusted with prominent public functions, their family members, or close associates.
High-risk jurisdictions: Customers or transactions involving countries identified as having strategic AML/CFT deficiencies by FATF or the European Commission.
Complex or unusually large transactions: Or transactions with an unusual pattern, without an apparent economic or lawful purpose.
New or developing technologies: Including virtual assets, where the risks may not be fully understood.
Non-face-to-face business relationships: Where there is no physical meeting with the customer.
Source of Funds (SoF) and Source of Wealth (SoW): VASPs must take reasonable measures to establish the source of funds and wealth involved in high-risk relationships or transactions.
Obligation to Report: Any transaction, attempted transaction, or activity where the VASP suspects or has reasonable grounds to suspect that funds are proceeds of criminal activity or are linked to terrorist financing.
Timing: Reports must be submitted promptly, usually immediately, once a suspicion arises.
Regulator Name: National Criminal Agency (NAKA) – specifically the National Unit for Combating Financial Crime.
Entity Targeted: An organized criminal group involving multiple individuals suspected of operating a sophisticated investment fraud scheme and subsequent money laundering using cryptocurrencies. Violation Type: Investment fraud, money laundering, unauthorized business activities, establishment, masterminding, and support of a criminal group. The scheme involved luring victims into fake crypto investment platforms.
Criminal charges filed against multiple individuals.
Seizure of assets: During the operation, authorities seized financial assets, movable property, and real estate worth approximately €15 million. This includes accounts, cryptocurrencies, and other assets believed to be proceeds of crime.
Date: Raids and arrests occurred in late 2023 (e.g., December 2023), with investigations ongoing since prior to that.
Outcome: Multiple individuals arrested and charged. Assets seized. Criminal proceedings are ongoing. This represents one of the largest financial crime operations in Slovakia involving cryptocurrencies.
Regulator Name: National Bank of Slovakia (Národná banka Slovenska - NBS).
Entity Targeted: General public, but implicitly targets any unlicensed entities or scammers operating without proper authorization or misrepresenting their services. Violation Type: Operating without required licenses (e.g., for investment services or financial advisory), offering fraudulent investment opportunities, misrepresentation of crypto products, or not adhering to AML/CFT obligations (though the latter is harder for the NBS to enforce directly against unlicensed foreign entities). Penalty Amount: No direct monetary penalty specified for the warning itself. The "penalty" is more in the form of reputational damage for entities named (if any) and increased public awareness leading to fewer victims.
Date: NBS has issued numerous warnings throughout the last 3 years, for example:
September 2023: Warning about financial services without NBS authorization.
May 2022: General warning regarding cryptocurrency risks.
March 2021: Warning against specific entities offering unlicensed services.
Outcome: Increased public awareness, reduced risk for consumers (if warnings are heeded), and a clear signal from the regulator regarding unauthorized activities. These warnings often precede or accompany police investigations.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange (custodial VASP) is permitted in Slovakia but must register as an AML obliged entity under Act No. 297/2008 Coll. pre-MiCA, and from December 30, 2024, must obtain full CASP authorization from the NBS under MiCA (Title V), with strict client-asset segregation, travel-rule compliance, and ongoing AML/CFT obligations.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?