DeFi protocol frontend in Democratic Republic of the Congo
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Democratic Republic of the Congo with a local entity, subject to AML obligations and low licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Low
- Last updated
- 2026-07-13
AML Obligations
- General AML/CFT framework applies under Law No. 04/016 of 19 July 2004 — even though no crypto-specific rules exist, adherence to FATF best practices is expected
- Suspicious Transaction Reports (STRs) must be filed with CENAREF (Cellule Nationale de Renseignements Financiers) if the operation handles transactions that could be interpreted as financial activity
- KYC/AML procedures recommended as international best practice, though no crypto-specific thresholds are defined
- If the frontend handles fiat-to-crypto or crypto-to-fiat conversion (via a payment processor or integrated on/off ramp), it may fall under Law No. 20/017 on payment services regulation, bringing full AML/CFT obligations with BCC supervision
Key Restrictions
- Cryptocurrencies are not recognized as legal tender in the DRC — any frontend must clearly disclaim legal-tender status
- BCC has publicly warned against the use of cryptocurrencies (June 2021 and December 2021 communiqués), creating regulatory uncertainty for any crypto-facing service
- Local entity required — any company operating in the DRC must have a registered local presence (office, directors, commercial registry) under general business laws
- If the frontend takes fees (especially in fiat) or processes fiat payments, the BCC may interpret this as a regulated payment service under Law No. 20/017, requiring a BCC authorization
- No specific crypto license exists, so operators operate in a grey area with no formal authorization pathway
Key Risks
- High regulatory ambiguity — the BCC has issued public warnings against cryptocurrencies but has not provided a clear legal framework, creating enforcement risk
- BCC could retroactively interpret fee-taking or fiat-integration as requiring a payment services license, leading to potential penalties or shutdown orders
- No crypto-specific AML regulations means obligations are ambiguous — failure to implement FATF-standard KYC could be used as a basis for enforcement if the regulator changes its stance
- Reputational and PR risk from operating in a jurisdiction where the central bank has publicly cautioned against crypto use
- Pending amendments to Law No. 04/016 (AML/CFT) could introduce new obligations without transition periods
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Virtual-asset activity in the Democratic Republic of the Congo is prohibited, not unregulated: article 22 bis of Loi n° 25/048 du 1er juillet 2025, amending Loi n° 22/068 du 27 décembre 2022, bans virtual-asset activities and virtual-asset service providers outright, so operating a cryptocurrency exchange or a crypto custody business in the country is unlawful rather than merely unlicensed.
General Business Registration: Any entity operating in the DRC, regardless of its specific activity, would need to comply with general business registration requirements (e.g., registering with the Ministry of Commerce, obtaining a tax ID, etc.), but these are not specific to financial services or virtual assets.
A payment processor dealing exclusively in virtual assets may not operate in the Democratic Republic of the Congo at all: article 22 bis of Loi n° 25/048 du 1er juillet 2025 prohibits virtual-asset activities and virtual-asset service providers, so the absence of a dedicated licence reflects a ban rather than a permission.
Loi n° 20/017 du 25 novembre 2020 is the Congolese telecommunications and ICT statute, regulated by ARPTIC, and its own scope article excludes electronic money; payment services in the Democratic Republic of the Congo are governed by Loi n° 18/019 du 9 juillet 2018 relative aux systèmes de paiement et de règlement-titres, and fiat-to-crypto conversion is in any event prohibited by article 22 bis of Loi n° 25/048 du 1er juillet 2025.
Implication: A crypto payment processor that converts fiat to crypto or vice-versa, or handles fiat payments in general, might be interpreted by the BCC as falling under the scope of existing payment services regulation, requiring an authorization from the BCC. This would be decided on a case-by-case basis and is subject to interpretation given the lack of specific definitions for virtual assets within this law.
Crypto-only exchanges and custody businesses have no registration or licensing route in the Democratic Republic of the Congo because article 22 bis of Loi n° 25/048 du 1er juillet 2025 prohibits virtual-asset activities and virtual-asset service providers; the Banque Centrale du Congo is the authority competent to detect and sanction providers operating in breach of that prohibition.
The general AML/CFT framework of the Democratic Republic of the Congo is Loi n° 22/068 du 27 décembre 2022, which replaced Loi n° 04/016 du 19 juillet 2004, as amended by Loi n° 25/048 du 1er juillet 2025; the amending law is crypto-specific, since its article 22 bis prohibits virtual-asset activities and virtual-asset service providers in the country.
The Cellule Nationale des Renseignements Financiers (CENAREF) is the Congolese financial intelligence unit responsible for receiving, analysing and transmitting suspicious transaction reports on money laundering, terrorist financing and proliferation financing, and it is the central and sole structure for that purpose under Loi n° 22/068 du 27 décembre 2022.
Even in the absence of specific crypto regulations, any legitimate financial operation (or one seeking future legitimacy) should adhere to international AML/CFT best practices (e.g., FATF recommendations), including robust KYC procedures, transaction monitoring, and suspicious activity reporting. Failure to do so could lead to future legal issues or blacklisting.
Local Presence: General business laws would require any company operating in the DRC to have a registered local presence (e.g., a local office, local directors, registration with the relevant commercial registries).
Regulator Name: Banque Centrale du Congo (BCC)
The Banque Centrale du Congo's public crypto warnings are its avis au public dated 9 November 2018 against the illegal collection of public savings through a purported cryptocurrency, and its communiqué of 7 July 2020 stating that crypto-assets are neither regulated nor authorised to operate in the DRC; the BCC's own avis index records no June 2021 warning.
Outcome: To inform the public of the risks and to clarify that cryptocurrencies are not recognized as legal tender, aiming to deter their use within the formal financial system. The outcome is public awareness rather than a specific legal penalty.
Loi n° 04/016 du 19 juillet 2004 was replaced by Loi n° 22/068 du 27 décembre 2022 and amended by Loi n° 25/048 du 1er juillet 2025, which is the operative Congolese AML/CFT/CPF statute; instead of extending FATF virtual-asset obligations to VASPs, its Article 22 bis prohibits virtual-asset activities and virtual-asset service providers in the DRC.
The Conseil des ministres adopted the bill amending Loi n° 04/016 du 19 juillet 2004 on 24 December 2021; it was enacted as Loi n° 22/068 du 27 décembre 2022, which replaced Loi n° 04/016, and was itself amended by Loi n° 25/048 du 1er juillet 2025.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — operating a DeFi protocol frontend in the DRC is legally ambiguous due to no specific crypto framework; possible under general business registration if the frontend is purely non-custodial and avoids fiat integration, but fee-taking or fiat processing risks reclassification as a regulated payment service under BCC supervision, and the BCC's public warnings create material enforcement risk.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?