DeFi protocol frontend in Bulgaria
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Bulgaria with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with the National Revenue Agency (NRA) as a VASP under the Measures Against Money Laundering Act (MAMLA) — required if the frontend operator falls within the definition of a 'virtual asset service provider'.
- Customer due diligence (CDD) on all users: identify and verify natural persons (name, date/place of birth, nationality, address, national ID/passport number) and legal entities (name, legal form, registration number, address, authorized representatives).
- Beneficial ownership identification using a 25%+1 share threshold for legal entity customers.
- Ongoing transaction monitoring to detect complex, unusual, large transactions or patterns inconsistent with customer profiles.
- Suspicious Transaction Reporting (STRs) to SANS (State Agency for National Security - Financial Intelligence Directorate).
- PEP screening for customers holding prominent public functions, their family members, and close associates.
- High-risk third-country enhanced due diligence for customers from EU/FATF-listed jurisdictions.
- Record-keeping obligations under MAMLA for CDD documents, transaction data, and STR records.
Key Restrictions
- If the frontend operator charges fees (e.g., swap fees, spread, interface fees), it is more likely to be classified as a VASP engaging in 'participation in and provision of financial services related to an issuer's offer and/or sale of a virtual asset' or 'exchange between virtual assets and fiat currencies' / 'exchange between virtual assets', triggering full AML registration and compliance obligations under MAMLA.
- A local legal entity registered in Bulgaria is likely required to register as a VASP with the NRA and to comply with MAMLA obligations.
- Geofencing/region blocking of users from high-risk third countries and sanctioned jurisdictions (EU sanctions are directly applicable) is required.
- If the frontend only provides a non-custodial interface to permissionless smart contracts and does not take custody, process fiat, or charge fees, the classification risk may be lower — but regulatory uncertainty remains and Bulgarian authorities have wide discretion to classify activities.
Key Risks
- Regulatory ambiguity: Bulgarian law does not clearly distinguish between a 'fully decentralized' protocol and the frontend operator interacting with it — MAMLA defines VASP activities broadly, and fee-taking or profit-generating activity may trigger classification.
- Enforcement risk: SANS and NRA can impose administrative fines, cessation orders, and refer matters for criminal investigation for non-compliance with VASP registration and AML obligations.
- EU sanctions risk: Directly applicable EU sanctions regimes require immediate compliance; failure to block sanctioned jurisdictions or individuals carries severe penalties.
- Tax/PR exposure: Even if a frontend operates from outside Bulgaria, serving Bulgarian residents without a local entity and registration may be treated as unlicensed VASP activity.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
While MAMLA historically served as the primary domestic AML/CFT law for VASPs in Bulgaria, the current regulatory framework is transitioning to the EU's MiCA regime. The 'Bulgarian MiCA Act' is being introduced as the new governing law, and VASPs/CASPs now face dual compliance obligations under both MiCA and MAMLA-derived AML/CFT rules (such as CDD), though MAMLA no longer solely dictates the requirements and penalties for VASPs.
This act defines "virtual assets" and "virtual asset service providers" and brings them within the scope of obliged entities. It outlines the specific requirements for customer due diligence, reporting, and record-keeping.
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset are subject to AML/CFT regulation and are treated as financial activities for regulated virtual asset and stablecoin issuers.
In Bulgaria, the State Agency for National Security (SANS) is the primary AML/CFT regulatory body, overseeing VASPs centrally; the Financial Intelligence Directorate under DANS no longer serves as the sole key entity.
National Revenue Agency (NRA) (Национална агенция за приходите - НАП)
In Bulgaria, the identification and verification of the beneficial owner is required under the AML Act, but if no individual beneficial owner can be identified through ownership or control criteria, the law provides that members of senior management are treated as the beneficial owner for registration purposes, so the process is not absolute but includes a fallback.
Natural Persons: Name, date and place of birth, nationality, permanent address, unique identification number (e.g., national ID card, passport number). Identity must be verified using reliable, independent source documents or data (e.g., valid official identification document).
Legal Entities: Company name, legal form, registration number, registered address, and the names of the individuals authorized to represent the company. Verification involves obtaining extracts from commercial registers or similar official documents.
In Bulgaria, the identification and verification of the beneficial owner is required under the AML Act, but if no individual beneficial owner can be identified through ownership or control criteria, the law provides that members of senior management are treated as the beneficial owner for registration purposes, so the process is not absolute but includes a fallback.
For legal entities, VASPs must identify the natural person(s) who ultimately own or control the customer, typically defined as holding 25% plus one share or more of the voting rights or exercising control via other means. This information must also be verified.
Evidence fact bg.aml.understanding-the-purpose-and-intended not found (may have been renamed).
Regular scrutiny of transactions undertaken throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Politically Exposed Persons (PEPs): Customers who hold or have held prominent public functions, their family members, or close associates.
High-Risk Third Countries: Transactions involving customers or beneficial owners from countries identified by the EU or FATF as having strategic AML/CFT deficiencies.
Complex, Unusual, Large Transactions, or Unusual Patterns: Transactions that have no apparent economic or lawful purpose.
Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc. Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Legal Basis: EU sanctions are typically imposed through Council Decisions and implemented via Council Regulations. These Regulations are directly applicable in all EU Member States without the need for national transposition.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend serving Bulgarian residents is likely to be classified as a VASP under MAMLA if it charges fees or exercises any control over the user's interaction with the protocol, requiring NRA registration, full AML/CFT compliance, and a local entity.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?