← Regulations / Slovakia / Operating Models / DeFi frontend

DeFi protocol frontend in Slovakia

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Slovakia with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration as an obliged entity under Act No. 297/2008 Coll. (AML Act) — any entity providing services related to virtual assets must register/notify and comply with AML/CFT requirements.
  • Customer Due Diligence (CDD): Identification and verification of natural persons (full name, date of birth, place of birth, permanent address, nationality, type and number of identity document) and legal entities (company name, registered address, registration number, directors/management).
  • UBO identification: Identify any natural person(s) owning 25%+ or otherwise controlling the customer.
  • Ongoing transaction monitoring: Continuously scrutinize transactions throughout the business relationship and keep customer information up-to-date.
  • Suspicious Activity Reporting (SAR): Report any transaction, attempted transaction, or activity where there are reasonable grounds to suspect proceeds of crime or terrorist financing — reports must be submitted promptly (immediately once suspicion arises).
  • Enhanced due diligence (EDD) required for: PEPs, high-risk jurisdictions (FATF/EU-identified), complex/unusually large transactions, new technologies including virtual assets, non-face-to-face business relationships.
  • Source of Funds (SoF) and Source of Wealth (SoW) measures required for high-risk relationships or transactions.
  • Competent authorities: FIU within the Ministry of Interior (for AML), and NBS (National Bank of Slovakia) supervises financial institutions — activities deemed financial services may fall under NBS supervision.
  • Under MiCA (from December 30, 2024): mandatory authorization as a CASP by NBS, with organizational, operational, and prudential requirements.

Key Restrictions

  • If the frontend takes fees or exercises any control over user funds/transactions (e.g., routing through a proprietary smart contract), it may be classified as providing 'services related to virtual assets' under the AML Act and become a fully regulated obliged entity.
  • Even if fully non-custodial and fee-less, the frontend may still fall within 'providers of other services related to virtual assets' — a broadly interpretable category under Slovak AML law (Act No. 297/2008 Coll.).
  • Geofencing/region restrictions for US persons or other high-risk jurisdictions may be required as part of AML risk-based approach, though no explicit statutory geofencing mandate exists in current Slovak law.
  • No specific 'crypto custody license' exists today — only AML registration as an obliged entity — but MiCA authorization (CASP) will be mandatory from December 30, 2024 for any service involving custody or administration of crypto-assets.
  • Under MiCA, strict client agreement and segregation mandates apply for custody-related activities (Article 68).
  • Passporting is available once authorized as a CASP in Slovakia (for EU-wide operations).

Key Risks

  • Regulatory ambiguity: 'Providers of other services related to virtual assets' is broadly defined and could be interpreted to include frontend interfaces — leading to unexpected enforcement for non-registered operators.
  • Enforcement precedent: NAKA (National Criminal Agency) has conducted large-scale crypto-related raids and seizures (e.g., €15M seizure in Dec 2023) targeting unlicensed crypto operations and fraud — showing active criminal enforcement.
  • NBS has issued repeated public warnings (2021-2023) about unlicensed financial services and crypto risks, signaling active scrutiny of unregistered operators.
  • MiCA transition risk: Entities that are compliant under current AML-only regime may need significant operational changes to meet full CASP authorization requirements by December 30, 2024.
  • If the frontend is deemed to provide investment services or financial advice, it could require full NBS authorization under investment services regulations, not just AML registration.
  • International cooperation (Europol, Eurojust) is commonly used — cross-border enforcement risk is real even if the operator is remote.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Registration, not a dedicated license: Currently, there isn't a specific "crypto custody license" in the traditional financial sense. However, entities providing services related to virtual assets, including custodian wallet providers, are considered "obliged entities" under Slovak AML law.

licensing 60% confidence

AML Obligations: This means they must comply with AML/CFT requirements, such as customer due diligence (CDD), transaction monitoring, suspicious activity reporting (SARs), and implementing internal risk management systems.

licensing 60% confidence

National Legislation: These obligations stem from Act No. 297/2008 Coll. on measures against the legalization of proceeds of crime and the financing of terrorism (Zákon č. 297/2008 Z. z. o ochrane pred legalizáciou príjmov z trestnej činnosti a o ochrane pred financovaním terorizmu). This Act has been amended multiple times to transpose the 4th, 5th, and 6th EU AML Directives.

licensing 60% confidence

Competent Authorities: For AML purposes, the Financial Intelligence Unit (FIU) within the Ministry of Interior is key, but the National Bank of Slovakia (Národná banka Slovenska - NBS) supervises financial institutions, which could include certain crypto-related activities if deemed financial services.

aml 60% confidence

Act No. 297/2008 Coll. on Protection Against Legalisation of Proceeds of Crime and Against Financing of Terrorism (AML Act): This is the primary legislation in Slovakia governing AML/CFT. It has been amended multiple times, most notably by Act No. 397/2019 Coll., which transposed the 5AMLD and extended its scope to virtual assets and VASPs.

aml 60% confidence

Providers of other services related to virtual assets: This can be broadly interpreted to include other services like issuance, transfer, or administration of virtual assets.

aml 60% confidence

Identification of the Customer and Verification of Identity:

aml 60% confidence

Obligation to Report: Any transaction, attempted transaction, or activity where the VASP suspects or has reasonable grounds to suspect that funds are proceeds of criminal activity or are linked to terrorist financing.

aml 60% confidence

Source of Funds (SoF) and Source of Wealth (SoW): VASPs must take reasonable measures to establish the source of funds and wealth involved in high-risk relationships or transactions.

aml 60% confidence

High-risk jurisdictions: Customers or transactions involving countries identified as having strategic AML/CFT deficiencies by FATF or the European Commission.

aml 60% confidence

Politically Exposed Persons (PEPs): Customers who are or have been entrusted with prominent public functions, their family members, or close associates.

aml 60% confidence

Non-face-to-face business relationships: Where there is no physical meeting with the customer.

licensing 60% confidence

Mandatory Authorization: Under MiCA (Title V), any entity providing "custody and administration of crypto-assets on behalf of clients" (Article 68) will be considered a Crypto-Asset Service Provider (CASP) and will need to be authorized by the national competent authority. In Slovakia, this will most likely be the National Bank of Slovakia (NBS).

licensing 60% confidence

All other titles, including those related to CASPs and custody, will apply from December 30, 2024.

licensing 60% confidence

Application Process: CASPs will need to apply for authorization, demonstrating compliance with various organizational, operational, and prudential requirements.

enforcement 60% confidence

Entity Targeted: An organized criminal group involving multiple individuals suspected of operating a sophisticated investment fraud scheme and subsequent money laundering using cryptocurrencies. Violation Type: Investment fraud, money laundering, unauthorized business activities, establishment, masterminding, and support of a criminal group. The scheme involved luring victims into fake crypto investment platforms.

enforcement 60% confidence

Seizure of assets: During the operation, authorities seized financial assets, movable property, and real estate worth approximately €15 million. This includes accounts, cryptocurrencies, and other assets believed to be proceeds of crime.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a DeFi protocol frontend is likely a regulated obliged entity under Slovakia's AML Act (Act No. 297/2008 Coll.) as a "provider of other services related to virtual assets," requiring AML registration, CDD/KYC, transaction monitoring, and SAR filing; fee-taking or any custody-adjacent activity increases the likelihood of classification as a full virtual asset service provider, and MiCA CASP authorization will become mandatory by December 30, 2024.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?