FAQ: How will new Estonian draft legislation affect virtual assets and crypto?

On December 23, Estonian government approved draft legislation that tightens regulation of virtual asset service providers, or VASPs. This page contains answers to frequently asked questions on the new legislative proposals.

The bill - which now has to pass through Parliament and is planned to enter into full force in the first half of 2022 - brings regulation of VASPs more in line with e-money institutions and payment service providers but does not directly affect customers or individuals who use private wallets from owning crypto. However, Estonian VASPs are not allowed to provide anonymous services and must identify their clients.

The regulation builds further on the general prohibition for Estonian VASPs to open anonymous virtual accounts, a rule that came to force in summer 2020 after license applications boomed and risks for financial crime sharply spiked. The rules are not applied to customers, but to VASPs who conduct activities for or on behalf of a natural or legal person as a permanent business.

This means that the legislation does not contain any measures to ban customers from owning and trading virtual assets and does not in any way require customers to share their private keys to wallets. The regulation does not affect individuals who own virtual currency through a private wallet not provided by a VASP.

However, accounts opened with Estonian VASPs cannot be anonymous and Estonian VASPs should treat anonymous services as higher risk – and apply real time transaction monitoring solutions, to spot and, if necessary, notify suspicious activities to the FIU. Reducing anonymity does not mean that personal data collected by the service provider will become public.
 

FAQ

Starting from 2019, Estonia conducted its second National Risk Assessment (NRA), a two-year survey based on methodology developed by the World Bank that mapped potential risks and vulnerabilities related to money laundering and financing of terrorism. The risk assessment concluded that significant risks were associated with licensed virtual asset service providers, including risks for abuse and financial crime.

The Estonian Financial Intelligence Unit (FIU) started licensing virtual asset service providers (VASPs) in 2017. Requirements for obtaining a license were lenient and allowed companies who are not connected to or do not operate in Estonia to be licensed. License applications quickly boomed – in 2017, four licenses were issued, in 2018, the number increased to 599 and by 2019 it had risen to 1234. Many of these companies had no direct connection to Estonia, which made effective supervision unfeasible.

In 2020, regulations were tightened, mainly by restricting VASPs from opening anonymous accounts and wallets – and required the VASP to apply the "know your client" principle the same way as banks and payment service providers do.  Know-your-client and customer due diligence are required from financial services providers all across the world and it has significantly reduced the risk of financial crime.

The 2020 amendments only temporarily reduced the inflow of new applications, partially due to a new emerging industry which registered and licensed dormant VASPs en masse for purposes of resale to third parties not connected to Estonia. Therefore, the new rules could not be implemented in practice, carrying risks of abuse to the Estonian business environment and to companies and customers acting in good faith.

Many of the companies carrying an Estonian license had no connection to the country. Meanwhile risks had begun to materialize as attention from international regulators and other countries was caught. For example, between August 2020 and August 2021, entities licensed in Estonia for virtual asset services had a combined turnover of 18.5 billion euros (FIU estimate). For comparison, the GDP of Estonia (in 2015 prices) was 23.68 billion euros in 2020. This in combination with other risk factors started to pose a significant risk, including to the Estonian business environment and legitimate actors.

The new proposed amendments require an Estonian-licensed VASP to either operate in Estonia or to have a demonstrable connection to Estonia. Resale of licenses will be restricted and capital requirements for VASPs will be increased to ensure that licensed entities will be active and able to fulfill their obligations (i.e to reduce the economic appeal of keeping VASP license “dormant” for future use or re-sale purposes).

Estonia will also be one of the first jurisdictions to fully comply with the technical guidance of FATF, an international standards body for AML/CFT, on virtual assets and virtual asset service providers.
 

No. The new rules do not directly apply to customers or private wallets not set up through an Estonian virtual asset service provider (VASP). The regulation applies to VASPs who conduct activities for or on behalf of a natural or legal person as a permanent business, as VASPs are obliged entities under the Anti-Money Laundering Act of Estonia.

This means that the legislation does not contain any measures to ban customers from owning and trading virtual assets and does not in any way require customers to share their private keys to wallets. Individuals can still freely use non-custodial wallets.

However, accounts opened with Estonian VASPs cannot be anonymous and Estonian VASPs cannot offer anonymous accounts or wallets. This means that an Estonian VASP must verify the identity of the person (individual or company) behind an account and, if a transaction is initiated or received through a VASP, to share and link this information with the transaction.

This is an application of the FATF Travel Rule, initially designed for banks and payment providers. This also means that due regard on safeguarding customer data and data protection issues is given.

The regulation also takes into account that not all jurisdictions have yet implemented the rule for virtual asset services, nor do all wallets or transactions inherently have a proper counterparty to receive the information; therefore, the amendments allow for transactions with VASPs and with un-hosted wallets, if real-time risk analysis is performed on each transaction. This falls in line with the general goal of the travel rule – to ensure that all transactions are monitored in accordance with the risk and to enable adequate collection and, if necessary, sharing of information and cooperation with law enforcement authorities.

FATF, the international standards body for AML/CFT, has designed a “travel rule” that requires financial institutions to identify participants in a transaction. Both the initiating and receiving party must be identified and the information must be shared between their payment processors and linked to the transaction – i.e, identifying information travels along with the transaction to decrease the risk for financial crime. Historically, the travel rule has been applied to banks and payment services, but new FATF guidance recommends extending it to virtual asset services.

With the amendments Estonia makes significant progress in the adaption of international standards and FATF guidance. Over 50 other countries have reported to FATF they have implemented the revised FATF standards for VASPs.

VASPs are required to follow the travel rule, which means that customers must be identified and the data passed along. The regulation also takes into account that not all jurisdictions have yet implemented the rule for virtual asset services, nor do all wallets or transactions inherently have a proper counterparty to receive the information; therefore, the amendments allow for transactions with VASPs and with un-hosted wallets, if real-time risk analysis is performed on each transaction. This falls in line with the general goal of the travel rule – to ensure that all transactions are monitored in accordance with the risk and to enable adequate collection and, if necessary, sharing of information and cooperation with law enforcement authorities.

The application of travel rule does not mean a ban on anonymous crypto transactions. The regulation does not apply to customers and individuals, who are still allowed to own a private wallet and to use non-VASPs, as well as VASPs in other jurisdictions. There are no provisions that require all Estonians to use non-custodial wallets or VASP services. However, Estonian accounts opened with Estonian VASPs cannot be anonymous and Estonian VASPs cannot offer anonymous accounts or wallets.

The main reason why rules originally designed for banks and payment providers are extended to virtual assets (including crypto) is that virtual asset transactions are analogous to transfers of non-virtual assets – they are used for transferring value by, for example, paying for goods or services. The travel rule was designed to reduce abuse of the financial system for nefarious purposes like money laundering, fraud or other financial crime. The intent behind extending this rule to virtual assets is to reduce this risk.

The data collected and passed along with the transaction is as follows.

For natural persons (individuals):

  • Full name;
  • Payment account, virtual asset wallet identifier or, if not applicable, a unique identifier of the transaction;
  • Personal identification code (if available) – an Estonian unique personal identification system that derives from the date of birth;
  • Date of birth, if no personal identification code is available;
  • Place of birth, if no personal identification code is available;
  • Name and number of their identity document (passport, ID card);
  • Residential address.

For legal persons (companies, NGOs, etc):

  • Full legal/business name;
  • Payment account, virtual asset wallet identifier or, if not applicable, a unique identifier of the transaction;
  • Estonian registry code; if not applicable, a registry or identification code of the resident country;
  • Address where business is conducted.

The collection and storage of personal data must adhere to the General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act meaning that it has to be ensured that the data transmitted are not disclosed in an unauthorized manner.

No. The regulation does not apply to customers and individuals, who are still allowed to own a private wallet and to use non-VASPs, as well as VASPs in other jurisdictions. There are no provisions that require all Estonians to use non-custodial wallets or VASP services.

However, VASPs (as service providers) are required to identify their clients and pass their information along with the transaction. This also means that accounts opened with Estonian VASPs cannot be anonymous and Estonian VASPs cannot offer anonymous accounts or wallets.

If a VASP breaches the requirements, they risk revocation of their license and a fine of up to 300 fine units (one fine unit equals 4 euros) for a natural person (i.e a VASP director or other natural person that can be held liable for the actions of a VASP) and a fine of up to 400 000 euros for a legal person (i.e the legal person holding the license of a VASP or providing VA services).

The main reason why rules originally designed for banks and payment providers are extended to virtual assets (including crypto) is that virtual asset transactions are analogous to transfers of non-virtual assets – they are used for transferring value by, for example, paying for goods or services. The travel rule was designed to reduce abuse of the financial system for nefarious purposes like money laundering, fraud or other financial crime. The intent behind extending this rule to virtual assets is to reduce this risk.

The new legislation will directly adopt the definitions of virtual asset service providers provided by FATF, the international standards body for AML/CFT, in its Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers, which can be found at the FATF website.

The new definition of a virtual asset service provider includes virtual asset (virtual currency) transfer services and services related to issuing virtual assets. Among others, this includes virtual asset brokerages, order-to-book exchanges and other intermediaries as well as platforms facilitating ICOs - however, not necessarily entities who conduct an ICO. All the different services are included under the term VASP.'

Decentralized applications (dApps) can fall under the new definition depending on whether users have a business relationship - including relationships established by smart contracts - with the owners, developers or managers of a decentralized application. Developers, owners or other persons who benefit monetarily from such applications could also be considered obliged entities as VASPs.

None of these services will be banned, but entities who wish to provide such services in Estonia must comply with AML/CFT rules.

Share capital of a VASP must be a minimum of 125 000 euros for wallet services, exchanges, and ICO and similar platforms; for transfer services, the minimum is 350 000 euros. Previously, the floor was 12 000 euros. The license fee is increased to 10 000 euros, up from 3300 euros. Additionally, a supervision fee will apply starting from April 2022 in the amount of 1% of share capital and 0.035% of all transactions for virtual asset transfer services.

The requirements have been increased to ensure that only companies who are active can apply for a license and to discourage registering dormant entities for purposes of resale.

To obtain a VASP license, the entity must provide financial information on assets and an overview of income, as well as information of beneficial owners and the management board. Members of the management board must have completed higher education and have at least two years of professional work experience. Members of the management board may not hold board positions in more than two Estonian VASPs. Members of the board must also have an impeccable reputation and necessary experience, as determined by the FIU.

Furthermore, a business plan for the first two years must be submitted, including a description of the nature of the business and its structure. The applicant must also submit a risk assessment and documentation of risk appetite. Applicants must be audited (both a financial and risk-based audit must be conducted on a regular basis). The applicant must also give a detailed overview on the technologies used in providing services.

Under the proposed legislation, only companies who operate in Estonia or are connected to Estonia can apply for a license to operate as a VASP, to ensure effective supervision and reduce the risk of international financial crime. The FIU can decline to license an entity if this requirement is not met. Licensed entities cannot be resold before two years of operations.
The new requirements are more closely in line with rules applying to banks and payment service providers and comply with FATF recommendations.
 

The proposals are tech-agnostic. We regulate services provided, not specific technologies. The aim is to regulate VASPs insofar as they perform the same functions as a financial service would.

The Money-Laundering Act, including new proposals, concerns services that could in principle be used for money laundering or financing of terrorism - i.e services that allow finances to both enter and leave (to start and receive transactions). The goal is to reduce the risk that such services are used for money laundering or other types of financial crime.

Service providers are persons who are able to influence the terms under which the service is provided - for example, persons who can decide whether to continue providing the service or not. Technical developers are generally not considered to be service providers.

However, if it is difficult to identify the service provider - for example, if the service is decentralized - several indicators must be taken into account to identify who has the largest amount of control over the terms of the service. One such indicator is to find out who benefits monetarily from providing the service.

Please also see the Ministry of Finance press release on new proposed regulation here.

If you have any questions, please contact the press / comms office at [email protected].

Last updated: 04.01.2022

search block image