Spain -- AML/CFT Compliance Regulatory Overview
Methodology
AI-generated synthesis from web search results.
Limitations
- AI-generated content -- not reviewed by human expert
- Source URLs not independently verified
RESEARCH: Spain AML/CFT Obligations
Executive Summary
Crypto is legal in Spain and is treated as a regulated activity for AML/CFT purposes. The primary regulators are the Banco de España (Bank of Spain), the CNMV (securities regulator), and SEPBLAC (Spain's AML/CFT supervisory authority and Financial Intelligence Unit). Spain licenses crypto-asset service providers under its AML framework, and multiple entities have been registered. The EU's new AML Authority (AMLA) Regulation (EU) 2024/1620, which entered into force in 2024, will bring direct EU-level supervision of high-risk crypto-asset service providers from 2028. The practical reality is that Spain has a functioning but evolving AML/CFT regime for crypto, with obligations increasingly harmonized at EU level through the 2024 AML package.
Regulatory Framework
The primary Spanish AML/CFT legislation is Law 10/2010, of 28 April, on prevention of money laundering and terrorist financing, which establishes the legal basis for reporting to SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias), Spain's AML/CFT supervisor. Communications to SEPBLAC - Banco de España
Banco de España (Bank of Spain) is the central bank and plays a critical role in consumer protection and anti-money laundering and terrorist financing issues within the Spanish financial system, while the ECB oversees significant institutions under the Single Supervisory Mechanism (SSM). Banking supervision and authorisations in Spain - Banco de España
Regulation (EU) 2024/1620 of the European Parliament and of the Council of 31 May 2024 established the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), published in the Official Journal on 19 June 2024, with its seat in Frankfurt am Main, Germany. Regulation - EU - 2024/1620 - EUR-Lex
The AMLA Regulation grants the Authority direct supervisory powers over selected obliged entities in the financial sector, including crypto-asset service providers, and coordinates AML/CFT supervisors of both financial and non-financial sectors. Regulation - EU - 2024/1620 - EUR-Lex
The EU AML/CFT framework comprises a comprehensive package including Regulation (EU) 2024/1620 (AMLA Regulation), Regulation (EU) 2023/1113, Regulation (EU) 2024/1624, and Directive (EU) 2024/1640, which together form the legal framework governing AML/CFT requirements for obliged entities. Regulation - EU - 2024/1620 - EUR-Lex
The EU AML/CFT framework was previously governed by Directive (EU) 2015/849 (the Fourth Anti-Money Laundering Directive), which has been superseded by the 2024 AML package. 2015/849 - EUR-Lex
Spain is a member of the Financial Action Task Force (FATF) through its membership in the European Union, and the FATF's mutual evaluation reports are explicitly referenced in the AMLA Regulation as considerations for assessing ML/TF risk. Regulation - EU - 2024/1620 - EUR-Lex
The Banco de España publishes financial regulation on money laundering through its regulatory framework, which includes the national rules implementing EU AML directives. Money laundering - Banco de España
Licensing Requirements
The ECB takes the decision to grant or withdraw authorisation of a subsidiary bank in Spain, while the Banco de España ensures that all national legal requirements are met and submits a draft authorisation decision to the ECB. Banking supervision and authorisations in Spain - Banco de España
Authorisation of a subsidiary bank in Spain is granted within six months of submission of the required documentation and/or within twelve months of receipt of the application, provided the prospective subsidiary meets legal requirements relating to sufficiency of capital, suitable qualifying shareholders and management, and sound corporate governance, internal control and AML arrangements. Banking supervision and authorisations in Spain - Banco de España
Once authorised, a subsidiary bank is entitled to carry out permitted activities in any other European Economic Area (EEA) country through passporting rights, either by opening a new branch or by providing cross-border services. Banking supervision and authorisations in Spain - Banco de España
Branches of banks from non-EEA countries must be authorised by the Banco de España, which is also responsible for their supervision; the application must be submitted by the parent bank, and branch authorisation does not grant passporting rights under EU regulations. Banking supervision and authorisations in Spain - Banco de España
The Banco de España is responsible for approving and authorising internal models used by Spanish less significant institutions (LSIs) in cooperation with the ECB, while the ECB authorises and supervises the internal models used by significant institutions (SIs). Banking supervision and authorisations in Spain - Banco de España
The AMLA Regulation provides for direct supervision of selected obliged entities in the financial sector, including crypto-asset service providers, meaning that certain high-risk crypto service providers will be licensed and supervised at EU level rather than purely nationally. Regulation - EU - 2024/1620 - EUR-Lex
The AMLA Regulation is currently in force (the consolidated version was updated as of 10 November 2025), and the Authority's direct supervisory powers over selected crypto-asset service providers are being operationalised. Regulation - EU - 2024/1620 - EUR-Lex
The Spanish regulatory regime for crypto-asset service providers includes registration and licensing obligations administered through the Banco de España and the CNMV, though the specific number of licensed crypto entities active in Spain is not stated in the provided sources.
AML/KYC Requirements
SEPBLAC (Spanish AML/CFT supervisor) receives communications of transactions from regulated entities through the Internal Committee for the Prevention of Money Laundering and Terrorist Financing, established at the Banco de España. Communications to SEPBLAC - Banco de España
The legal basis for reporting to SEPBLAC is Law 10/2010, of 28 April, on prevention of money laundering and terrorist financing, which requires regulated entities to submit transaction reports. Communications to SEPBLAC - Banco de España
The categories of personal data processed for AML purposes include identification data (name, surname, ID or equivalent, personal register number, signature), contact data (phone number, e-mail, postal address), and economic and financial data (information on goods/services transactions, bank accounts). Communications to SEPBLAC - Banco de España
Personal data processed for AML purposes shall be retained for the time necessary to fulfil the purpose for which they were collected and to allocate any liability arising from said purpose and from the processing of the data. Communications to SEPBLAC - Banco de España
Recipients of AML-related personal data include SEPBLAC, Courts of Justice, and other competent public authorities; no international transfer of data is indicated for these activities. Communications to SEPBLAC - Banco de España
Security measures for AML data processing at the Banco de España comply with the National Security Scheme, as required by the First Additional Provision of the Organic Law 3/2018 of December 5, on Protection of Personal Data and Guarantee of Digital Rights. Communications to SEPBLAC - Banco de España
The Banco de España is the data controller for AML transaction reporting, with NIF: Q2802472G, and has a designated Data Protection Officer available through a contact form. Communications to SEPBLAC - Banco de España
Enforcement Actions
The AMLA Regulation was created in part because experience with the existing AML/CFT framework, which relies heavily on national implementation, disclosed weaknesses in the efficient functioning of the framework and in integrating international recommendations. Regulation - EU - 2024/1620 - EUR-Lex
The cross-border nature of crime and criminal proceeds endangers the efforts of the EU financial system with regard to the prevention of money laundering and financing of terrorism, which motivated the creation of the AMLA Authority. Regulation - EU - 2024/1620 - EUR-Lex
No specific enforcement actions, fines, or penalties against Spanish crypto entities are detailed in the provided sources.
Tax Treatment
- No tax guidance has been issued for virtual assets in the provided sources; the sources do not address how crypto gains are taxed in Spain.
Key Gaps & Risks
The EU AML/CFT framework has historically relied heavily on national implementation, which has disclosed weaknesses in the efficient functioning of the framework and in integrating international recommendations; the AMLA Regulation addresses this by centralising certain supervisory functions. Regulation - EU - 2024/1620 - EUR-Lex
The AMLA Regulation notes that divergences in national legislation and supervisory practices have led to new obstacles to the proper functioning of the internal market, both due to risks within the internal market as well as external threats facing it. Regulation - EU - 2024/1620 - EUR-Lex
A key implementation gap is the transition period: while the AMLA Regulation entered into force in 2024, the Authority's operational capacity and direct supervision of crypto-asset service providers will be phased in, requiring regulated entities to prepare for dual national and EU-level supervision. Regulation - EU - 2024/1620 - EUR-Lex
The AMLA Regulation requires that the location of the Authority's seat enable it to fully execute its tasks and powers, recruit highly qualified and specialised staff, and closely cooperate with Union institutions; the selection of Frankfurt reflects consideration of how ML/TF risks are addressed in the host Member State based on FATF reports. Regulation - EU - 2024/1620 - EUR-Lex
Information on whether any crypto-asset service providers have been licensed in Spain since the last update is not publicly available, and the complete application process or capital requirements for crypto-specific licences are not detailed; this information should be sought from the Banco de España and CNMV directly.
Sources
- Communications to SEPBLAC - Banco de España
- Communications to SEPBLAC - Banco de España
- Banking supervision and authorisations in Spain - Banco de España
- Regulation - EU - 2024/1620 - EUR-Lex
- 2015/849 - EUR-Lex
- Money laundering - Banco de España
- Banking supervision - Banco de España
- Consolidated text - RD.84.2015
Source Data
Directive (EU) 2015/849 (4th AMLD): The foundational directive, which brought more entities into scope and strengthened CDD.
Directive (EU) 2018/843 (5th AMLD): Crucially, this directive extended the scope of AML/CFT rules to include virtual asset service providers (VASPs), specifically:
Providers engaged in exchange services between virtual currencies and fiat currencies.
Directive (EU) 2018/1673 (6th AMLD): Primarily focuses on harmonizing the definition of money laundering criminal offenses and related sanctions across the EU, which indirectly supports the AML framework.
Ley 10/2010, de 28 de abril, de prevención del blanqueo de capitales y de la financiación del terrorismo (Law 10/2010, of April 28, on the prevention of money laundering and terrorist financing).
Real Decreto 304/2014, de 5 de mayo, por el que se aprueba el Reglamento de la Ley 10/2010 (Royal Decree 304/2014, of May 5, approving the Regulation of Law 10/2010): This Royal Decree provides detailed rules for the implementation of Law 10/2010. It also has been amended to reflect EU changes.
Real Decreto-ley 7/2021, de 27 de abril (Royal Decree-Law 7/2021, of April 27): This specific decree transposed significant parts of the 5th AMLD, formally bringing VASPs under the scope of Law 10/2010 and establishing the requirement for their registration with the Bank of Spain.
Circular 2/2022 del Banco de España, de 23 de marzo (Circular 2/2022 of the Bank of Spain, of March 23): This circular specifically regulates the administrative registration of providers of virtual currency exchange services for fiat currency and electronic wallet custody services.
Natural Persons: Obtain and verify identity using reliable independent sources (e.g., national ID card, passport). Required data includes full name, date and place of birth, address, and national identification number.
Legal Persons/Entities: Obtain and verify the name, legal form, address, proof of incorporation, articles of association, names of directors, and the legal representative(s).
For legal entities, identify any natural person(s) who ultimately own or control 25% plus one share or more of the entity, or who otherwise exercise control.
If no such natural person is identified, identify the natural person(s) who hold the position of senior managing official(s).
VASPs must gather information about the client's typical transaction volumes, types of virtual assets, and the source of funds/wealth where necessary.
Scrutinizing transactions undertaken throughout the course of the relationship to ensure consistency with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Regularly updating customer information, including CDD documentation.
Carrying out occasional transactions exceeding €1,000 (whether in a single transaction or several linked transactions).
Where there is suspicion of money laundering or terrorist financing.
When there are doubts about the veracity or adequacy of previously obtained customer identification data.
Politically Exposed Persons (PEPs), their family members, and close associates.
Customers from high-risk third countries (as identified by the EU or FATF).
Complex, unusually large transactions, or unusual patterns of transactions that have no apparent economic or lawful purpose.
Non-face-to-face relationships without specific safeguards.
EDD measures include obtaining senior management approval, taking reasonable measures to establish the source of wealth and funds, and conducting enhanced ongoing monitoring.
Permitted in explicitly defined low-risk situations, though given the inherent risks often associated with virtual assets, this is less frequently applicable to VASPs.
Reporting Obligation: Any VASP that knows, suspects, or has reasonable grounds to suspect that funds, regardless of the amount, are the proceeds of criminal activity or are related to terrorist financing, must promptly report it.
Recipient: Reports must be submitted to the Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias (SEPBLAC), which is Spain's FIU.
"Tipping-Off": VASPs are strictly prohibited from informing the customer concerned or third parties that a suspicious transaction report is being, or has been, transmitted, or that a money laundering or terrorist financing investigation is being, or may be, carried out.
Internal Controls: VASPs must have internal policies, procedures, and controls in place to detect and report suspicious transactions, including appointing a Money Laundering Reporting Officer (MLRO).
Records of CDD measures (copies of identification documents, beneficial ownership information).
Amount and currency of the transaction.
Parties involved (sender and recipient, including their virtual asset addresses).
Records of STRs and any internal suspicious activity reports.
Records of internal policies and procedures, and staff training.
Retention Period: All records must be retained for at least five years after the end of the business relationship with the customer or the date of an occasional transaction.
1. For AML/CFT Compliance and Enforcement (FIU):
Name: Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias (SEPBLAC)
Role: This is Spain's Financial Intelligence Unit (FIU). It is responsible for receiving, analyzing, and disseminating suspicious transaction reports. It also oversees compliance with AML/CFT obligations by obliged entities, including VASPs, and can impose sanctions for non-compliance.
Name: Banco de España (Bank of Spain)
Role: Following the transposition of the 5th AMLD, providers of virtual currency exchange services for fiat currency and electronic wallet custody services are required to register with the Bank of Spain. This registration is a prerequisite for operating legally in Spain. The Bank of Spain maintains a public register of these entities and ensures they meet certain operational and reputational requirements before granting registration.
Specific Registry Page (in Spanish): Look for "Registro de proveedores de servicios de cambio de moneda virtual por moneda fiduciaria y de custodia de monederos electrónicos" on their site. A direct link to the relevant section or public registry might change, but it can typically be found under their "Supervision" or "Financial Innovation" sections. As of the last update, the main page on registration is often linked from their "Normativa y publicaciones" (Regulations and Publications) or "Entidades supervisadas" (Supervised entities) sections.
Requirement: Entities providing services of virtual currency exchange for fiat currency, and custody of electronic wallets (custodia de monederos electrónicos), must register with the Bank of Spain (Banco de España). This is a registration requirement, not a full prudential license in the traditional sense, but it subjects providers to AML/CTF supervision.
Law 10/2010, of April 28, on the prevention of money laundering and terrorist financing (Ley 10/2010, de 28 de abril, de prevención del blanqueo de capitales y de la financiación del terrorismo).
Royal Decree 775/2021, of August 31 (Real Decreto 775/2021, de 31 de agosto), which modifies the Regulation of Law 10/2010 to specifically include virtual asset service providers. This decree specifies the conditions and procedures for their registration.
Competent Authority: Bank of Spain (Banco de España) is responsible for maintaining the register and supervising these entities for AML/CTF purposes.
Bank of Spain VASP Register (information page): https://www.bde.es/bde/es/secciones/servicios/Registro_de_pr/
Under the current AML/CTF framework, there isn't explicit legislation in Spain mandating the segregation of client crypto-assets in the same way it's required for traditional financial institutions (e.g., client funds in separate accounts). The focus is primarily on customer identification (KYC) and transaction monitoring.
However, general principles of good governance, consumer protection, and the prevention of misuse of funds would implicitly encourage or suggest such practices, even if not explicitly codified for crypto-assets.
The current AML/CTF registration requirements in Spain do not explicitly mandate specific insurance or bonding requirements for crypto custodians. Providers are expected to maintain general business insurance, but there isn't a regulatory requirement for a specific amount of capital or professional indemnity insurance directly linked to the custody of crypto-assets.
There are no explicit regulatory mandates for the use of cold storage as a specific technical requirement under the current Spanish AML/CTF framework. While cold storage is widely considered a best practice for securing digital assets against online threats, the regulations focus on the broader AML/CTF compliance rather than specific technological security measures. Firms are expected to have robust security protocols, but the specific implementation is left to the provider.
The current Spanish framework does not define "qualified custodian" specifically for crypto assets in the same way traditional finance defines qualified custodians (e.g., banks, trust companies). An entity registered with the Bank of Spain to provide "custody of electronic wallets" is essentially the recognized custodian for AML purposes, but this registration doesn't impose the same prudential or institutional requirements as a traditional financial "qualified custodian."
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):
This is the primary legal text. It creates a harmonized legal framework for crypto-assets not already covered by existing financial services legislation.
URL: Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets
Real Decreto-ley 7/2021, de 27 de abril, de transposición de directivas de la Unión Europea en diversas materias (Royal Decree-Law 7/2021, of April 27, transposing EU directives on various matters), which incorporated the 5th AMLD, including crypto-asset service providers, into Spanish law.
Banco de España (BdE): The central bank of Spain, responsible for supervising e-money institutions and credit institutions. Under MiCA, it will also be the competent authority for the supervision of issuers of e-money tokens (EMTs) and potentially asset-referenced tokens (ARTs), especially those of significant scale. It also maintains the registry for crypto-asset service providers under national AML law.
URL (BdE Crypto Register): Banco de España - Register of providers of virtual currency exchange for fiat currency and electronic custody of electronic wallets
Comisión Nacional del Mercado de Valores (CNMV): Spain's securities market regulator. It will be the competent authority for the supervision of issuers of ARTs (other than those supervised by BdE for e-money activities) and other crypto-assets under MiCA.
Defined as a crypto-asset whose main purpose is to be used as a means of exchange and that purports to maintain a stable value by referencing the value of one single fiat currency.
These are essentially tokenized fiat currency.
Classification: EMTs fall under MiCA's specific regime but are also closely linked to the E-money Directive (EMD2). An issuer of an EMT is considered an e-money institution and must comply with both MiCA and relevant EMD2 provisions.
Defined as a crypto-asset that is not an e-money token and that purports to maintain a stable value by referencing any other value or right, or a combination thereof, including one or several fiat currencies, one or several commodities, or one or several crypto-assets, or a combination of such assets.
Classification: ARTs are a distinct category under MiCA. They are not e-money or securities in the traditional sense, but MiCA creates a bespoke regulatory regime for them.
Issuers must at all times maintain a 1:1 peg with the fiat currency they reference.
The issuer must ensure that the reserve assets are invested in secure, low-risk assets (e.g., short-term government bonds, highly liquid money market funds) and held in segregated accounts with credit institutions.
At least 30% of the reserve assets must be held in demand deposits and be available for immediate redemption.
Issuers are required to publish daily reserve statements.
Issuers must maintain a reserve of assets that is equal to or greater than the value of the ARTs in circulation.
The reserve assets must be liquid and held in custody by an independent third party (credit institution or crypto-asset service provider authorized for custody).
The investment policy for reserve assets must be publicly available, clear, and designed to minimize market, credit, and liquidity risk.
A minimum of 30% of the reserve assets must be held in highly liquid financial instruments with minimal market risk, capable of being liquidated within one business day.
Issuers must establish clear redemption policies.
Only credit institutions (banks) or e-money institutions (EMIs) authorized under the EMD2 can issue EMTs.
An existing EMI license will be sufficient, but the EMI will also need to comply with the additional requirements of MiCA specific to EMTs.
The Banco de España would be the competent authority in Spain for supervising these entities.
Issuers of ARTs must be a legal entity established in the EU and obtain specific authorization from their national competent authority (in Spain, likely the CNMV, or the BdE if the ART has characteristics close to e-money or falls under its remit due to scale).
The authorization process involves a detailed application, demonstrating robust governance arrangements, internal control mechanisms, risk management procedures, and compliance with all MiCA requirements.
"Significant ARTs" (those with a large user base or high value) will be subject to enhanced supervision by the European Banking Authority (EBA) and potentially the European Central Bank (ECB).
Holders of EMTs have a right to redeem their tokens at par value (1:1) against the referenced fiat currency at any time.
This redemption must be done without undue delay and without charging any fees, unless otherwise specified in the white paper for specific circumstances (e.g., very high volumes).
Issuers must provide clear and precise terms and conditions for redemption, including the value at which the ARTs can be redeemed (which must be at fair market value of the referenced assets).
Redemption must be possible at any time, directly from the issuer or via a payment services provider.
Prohibition: MiCA effectively prohibits stablecoins that rely solely on an algorithm to maintain their price stability without backing their value with sufficient, robust reserve assets.
Asset-Backed Requirement: The core principle of MiCA's stablecoin framework is that both ARTs and EMTs must be backed by actual reserves designed to ensure their stability and allow for redemption. This means purely algorithmic, unbacked stablecoins like the former TerraUSD (UST) model would not be permitted under MiCA.
Banco de España's Role: The Banco de España is participating in the technical and policy discussions led by the European Central Bank (ECB) regarding the design and implementation of a digital euro.
Distinction from Stablecoins: A digital euro would be distinct from MiCA-regulated stablecoins.
Digital Euro: Central bank money, risk-free, direct liability of the ECB. It would serve as an official complement to cash and bank deposits.
Stablecoins (ARTs/EMTs): Private sector money, issued by regulated private entities, and subject to the specific risks and regulatory requirements outlined in MiCA.
Complementary but Separate: While both aim to facilitate digital payments, they operate on different levels. Stablecoins could potentially interact with a digital euro as a bridge or a method for specific use cases, but the digital euro's existence would create a fundamental, risk-free digital monetary base that stablecoins would exist alongside. The digital euro aims to preserve monetary sovereignty and offer a public option for digital payments, which could impact the demand for private stablecoins.
The primary Spanish AML/CFT legislation is Law 10/2010, of 28 April, on prevention of money laundering and terrorist financing, which establishes the legal basis for reporting to SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias), Spain's AML/CFT supervisor. Communications to SEPBLAC - Banco de España
Banco de España (Bank of Spain) is the central bank and plays a critical role in consumer protection and anti-money laundering and terrorist financing issues within the Spanish financial system, while the ECB oversees significant institutions under the Single Supervisory Mechanism (SSM). Banking supervision and authorisations in Spain - Banco de España
Regulation (EU) 2024/1620 of the European Parliament and of the Council of 31 May 2024 established the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), published in the Official Journal on 19 June 2024, with its seat in Frankfurt am Main, Germany. Regulation - EU - 2024/1620 - EUR-Lex
The AMLA Regulation grants the Authority direct supervisory powers over selected obliged entities in the financial sector, including crypto-asset service providers, and coordinates AML/CFT supervisors of both financial and non-financial sectors. Regulation - EU - 2024/1620 - EUR-Lex
The EU AML/CFT framework comprises a comprehensive package including Regulation (EU) 2024/1620 (AMLA Regulation), Regulation (EU) 2023/1113, Regulation (EU) 2024/1624, and Directive (EU) 2024/1640, which together form the legal framework governing AML/CFT requirements for obliged entities. Regulation - EU - 2024/1620 - EUR-Lex
The EU AML/CFT framework was previously governed by Directive (EU) 2015/849 (the Fourth Anti-Money Laundering Directive), which has been superseded by the 2024 AML package. 2015/849 - EUR-Lex
Spain is a member of the Financial Action Task Force (FATF) through its membership in the European Union, and the FATF's mutual evaluation reports are explicitly referenced in the AMLA Regulation as considerations for assessing ML/TF risk. Regulation - EU - 2024/1620 - EUR-Lex
The Banco de España publishes financial regulation on money laundering through its regulatory framework, which includes the national rules implementing EU AML directives. Money laundering - Banco de España
The ECB takes the decision to grant or withdraw authorisation of a subsidiary bank in Spain, while the Banco de España ensures that all national legal requirements are met and submits a draft authorisation decision to the ECB. Banking supervision and authorisations in Spain - Banco de España
Authorisation of a subsidiary bank in Spain is granted within six months of submission of the required documentation and/or within twelve months of receipt of the application, provided the prospective subsidiary meets legal requirements relating to sufficiency of capital, suitable qualifying shareholders and management, and sound corporate governance, internal control and AML arrangements. Banking supervision and authorisations in Spain - Banco de España
Once authorised, a subsidiary bank is entitled to carry out permitted activities in any other European Economic Area (EEA) country through passporting rights, either by opening a new branch or by providing cross-border services. Banking supervision and authorisations in Spain - Banco de España
Branches of banks from non-EEA countries must be authorised by the Banco de España, which is also responsible for their supervision; the application must be submitted by the parent bank, and branch authorisation does not grant passporting rights under EU regulations. Banking supervision and authorisations in Spain - Banco de España
The Banco de España is responsible for approving and authorising internal models used by Spanish less significant institutions (LSIs) in cooperation with the ECB, while the ECB authorises and supervises the internal models used by significant institutions (SIs). Banking supervision and authorisations in Spain - Banco de España
The AMLA Regulation provides for direct supervision of selected obliged entities in the financial sector, including crypto-asset service providers, meaning that certain high-risk crypto service providers will be licensed and supervised at EU level rather than purely nationally. Regulation - EU - 2024/1620 - EUR-Lex
The AMLA Regulation is currently in force (the consolidated version was updated as of 10 November 2025), and the Authority's direct supervisory powers over selected crypto-asset service providers are being operationalised. Regulation - EU - 2024/1620 - EUR-Lex
The Spanish regulatory regime for crypto-asset service providers includes registration and licensing obligations administered through the Banco de España and the CNMV, though the specific number of licensed crypto entities active in Spain is not stated in the provided sources.
SEPBLAC (Spanish AML/CFT supervisor) receives communications of transactions from regulated entities directly. SEPBLAC operates with functional autonomy under the Commission for the Prevention of Money Laundering and Terrorist Financing (not through an Internal Committee at the Banco de España).
The legal basis for reporting to SEPBLAC is Law 10/2010, of 28 April, on prevention of money laundering and terrorist financing, which requires regulated entities to submit transaction reports. Communications to SEPBLAC - Banco de España
The categories of personal data processed for AML purposes include identification data (name, surname, ID or equivalent, personal register number, signature), contact data (phone number, e-mail, postal address), and economic and financial data (information on goods/services transactions, bank accounts). Communications to SEPBLAC - Banco de España
Personal data processed for AML purposes shall be retained for the time necessary to fulfil the purpose for which they were collected and to allocate any liability arising from said purpose and from the processing of the data. Communications to SEPBLAC - Banco de España
Recipients of AML-related personal data include SEPBLAC, Courts of Justice, and other competent public authorities; no international transfer of data is indicated for these activities. Communications to SEPBLAC - Banco de España
Security measures for AML data processing at the Banco de España comply with the National Security Scheme, as required by the First Additional Provision of the Organic Law 3/2018 of December 5, on Protection of Personal Data and Guarantee of Digital Rights. Communications to SEPBLAC - Banco de España
The Banco de España is the data controller for AML transaction reporting, with NIF: Q2802472G, and has a designated Data Protection Officer available through a contact form. Communications to SEPBLAC - Banco de España
The AMLA Regulation was created in part because experience with the existing AML/CFT framework, which relies heavily on national implementation, disclosed weaknesses in the efficient functioning of the framework and in integrating international recommendations. Regulation - EU - 2024/1620 - EUR-Lex
The cross-border nature of crime and criminal proceeds endangers the efforts of the EU financial system with regard to the prevention of money laundering and financing of terrorism, which motivated the creation of the AMLA Authority. Regulation - EU - 2024/1620 - EUR-Lex
No specific enforcement actions, fines, or penalties against Spanish crypto entities are detailed in the provided sources.
The EU AML/CFT framework has historically relied heavily on national implementation, which has disclosed weaknesses in the efficient functioning of the framework and in integrating international recommendations; the AMLA Regulation addresses this by centralising certain supervisory functions. Regulation - EU - 2024/1620 - EUR-Lex
The AMLA Regulation notes that divergences in national legislation and supervisory practices have led to new obstacles to the proper functioning of the internal market, both due to risks within the internal market as well as external threats facing it. Regulation - EU - 2024/1620 - EUR-Lex
A key implementation gap is the transition period: while the AMLA Regulation entered into force in 2024, the Authority's operational capacity and direct supervision of crypto-asset service providers will be phased in, requiring regulated entities to prepare for dual national and EU-level supervision. Regulation - EU - 2024/1620 - EUR-Lex
The AMLA Regulation requires that the location of the Authority's seat enable it to fully execute its tasks and powers, recruit highly qualified and specialised staff, and closely cooperate with Union institutions; the selection of Frankfurt reflects consideration of how ML/TF risks are addressed in the host Member State based on FATF reports. Regulation - EU - 2024/1620 - EUR-Lex
Communications to SEPBLAC - Banco de España
Communications to SEPBLAC - Banco de España
Banking supervision and authorisations in Spain - Banco de España
Regulation - EU - 2024/1620 - EUR-Lex
Money laundering - Banco de España
Banking supervision - Banco de España
37 fact(s) collected but awaiting source verification. View in explorer →
References
This article was generated by openrouter/nvidia/nemotron-3-ultra-550b-a55b:free .
Primary Sources
Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets. (n.d.). Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets. Retrieved April 21, 2026, from https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1114
eur-lex.europa.eu. (n.d.). Regulation - EU - 2024/1620 - EUR-Lex. Retrieved September 6, 2026, from https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1620
eur-lex.europa.eu. (n.d.). 2015/849 - EUR-Lex. Retrieved September 6, 2026, from https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32015L0849
Secondary Sources
sepblac.es. (n.d.). sepblac.es. Retrieved April 22, 2026, from https://www.sepblac.es/en/ es
bde.es. (n.d.). bde.es. Retrieved April 22, 2026, from https://www.bde.es/bde/en/ es
bde.es. (n.d.). Communications to SEPBLAC - Banco de España. Retrieved September 6, 2026, from https://www.bde.es/bde/en/secciones/sobreelbanco/Transparencia/Informacion_inst/registro-de-acti/Comunicaciones__2925ec1949bc761.html es
bde.es. (n.d.). Banking supervision and authorisations in Spain - Banco de España. Retrieved September 6, 2026, from https://www.bde.es/wbe/en/sobre-banco/actividad-europea/mecanismo-unico-supervision/relacionados/banking_supervi_293a87f04191281.html es
bde.es. (n.d.). Money laundering - Banco de España. Retrieved September 6, 2026, from https://www.bde.es/wbe/en/areas-actuacion/normativa/regulacion-sistema-financiero/blanqueo-de-capitales.html es
bde.es. (n.d.). Communications to SEPBLAC - Banco de España. Retrieved September 6, 2026, from https://www.bde.es/wbe/en/sobre-banco/transparencia/informacion-institucional-planificacion/registro-actividades-tratamiento/comunicaciones__c37cfa956071281.html es
bde.es. (n.d.). Banking supervision - Banco de España. Retrieved September 6, 2026, from https://www.bde.es/bde/en/areas/supervision/normativa/regulacion/ es
bde.es. (n.d.). Consolidated text - RD.84.2015. Retrieved September 6, 2026, from https://www.bde.es/f/webbde/INF/MenuHorizontal/Normativa/eng/RD.84.2015_en.pdf es
Edit History
This article is maintained by AI research workers and reviewed by human editors. Learn about our methodology →