No spam - just the latest insights!
Join over 30,000 industry professionals who subscribe for free
Subscribe for free!
We'll never share your information or send you spam
Dr. Michael Huertas is a partner and the global and European Financial Services Legal Leader at PwC Legal. Michael advises financial services firms, crypto-asset service providers and issuers, as well as multinational corporations, on a wide range of cross-border banking and finance, capital markets, structured finance and derivatives transactions, as well as complex financial regulatory, supervisory and enforcement matters. He is qualified and practises as a solicitor advocate (England and Wales), solicitor (Ireland) and as a Rechtsanwalt/attorney-at-law (Germany). Michael frequently speaks at conferences and publishes on global financial regulatory issues.
Dr. Hagen Weiss is a lawyer and former Federal Government Director and – with a PhD in DLT systems theory – specializes in the law of crypto assets. He is one of the leading lawyers in the field of digital finance and crypto assets – particularly in matters relating to DLT and blockchain in connection with financial institutions and technology companies, as well as issues relating to the German eWpG, the Markets in Crypto Assets Regulation (MiCAR), the EU DLT pilot program, and decentralized finance (DeFi). As a federal official, he has contributed significantly to the regulatory and legal framework for crypto assets in Germany, at the European and international level. In addition, he has been involved with the underlying technology for many years and is familiar with its actual technological features and developments. Having worked as a civil servant for federal authorities and the Federal Ministry of Finance, Hagen Weiss also has extensive knowledge and experience in advising on strategic regulatory decisions.
Germany’s universal banking model enables existing market participants to integrate crypto-asset services-spanning deposit-taking, custody, brokerage, issuance, and payments-under a single supervisory dialogue. The Electronic Securities Act (Gesetz über elektronische Wertpapiere, “eWpG”) has materially reduced friction for on-chain issuance and lifecycle management of bonds and, increasingly, shares, catalysing tokenisation pilots across treasury, securitisation, and fund units. Concurrently, the EU’s Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114, “MiCAR”) establishes a uniform perimeter for Crypto-Asset Service Providers (“CASPs”)-entities authorised to provide one or more crypto-asset services to clients on a professional basis. This framework draws fintech and crypto-native players into an EU-passportable regime, challenging banks on speed and product breadth while narrowing perceived regulatory arbitrage. Strategic partnerships are prevalent, including bank-led white-labelling for crypto custody and brokerage, and fintech-led tokenisation platforms serving banks. Balance sheet treatment and capital remain practical constraints: banks must manage Basel prudential classification for crypto-exposures alongside expectations on operational risk, third-party risk, and outsourcing.
Germany operates within an EU-first framework, where directly applicable regulations establish minimum harmonisation and national transposition plays a smaller role than under earlier directives. MiCAR now governs the issuance and public offering of crypto-assets, including asset-referenced tokens (“ARTs”)-crypto-assets that purport to maintain a stable value by referencing another value or right, or a combination thereof, including one or more official currencies-and e-money tokens (“EMTs”), which purport to maintain a stable value by referencing a single official currency. MiCAR also governs CASP authorisation for services including custody, trading, exchange, execution, placing, advice, and portfolio management. The EU’s Transfer of Funds Regulation (Regulation (EU) 2023/1113, “TFR”) extends ‘travel rule’ requirements to crypto-asset transfers, ensuring originator and beneficiary information accompanies transactions. The Distributed Ledger Technology Pilot Regime (Regulation (EU) 2022/858, the “DLT Pilot Regime”) provides exemptions allowing market infrastructures to admit and settle tokenised financial instruments within defined limits. In parallel, the Digital Operational Resilience Act (Regulation (EU) 2022/2554, “DORA”) overlays ICT risk and third-party risk management across financial institutions, including CASPs where captured by their regulated status.
At the national level, the Banking Act (Kreditwesengesetz, “KWG”), Securities Trading Act (Wertpapierhandelsgesetz, “WpHG”), and the securities prospectus and markets in financial instruments frameworks apply on a functional basis. The Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht, “BaFin”) continues to characterise many tokens as financial instruments or securities depending on their rights and transferability, applying the prospectus regime, market abuse prohibitions, and the Markets in Financial Instruments Directive (Directive 2014/65/EU, “MiFID II”) conduct rules accordingly. The Payment Services Supervision Act (Zahlungsdiensteaufsichtsgesetz, “ZAG”) governs e-money issuance and payment services, and is critical where business models intertwine fiat rails with crypto. The eWpG provides the legal basis for electronic and crypto-registered securities, embedding duties for register keepers and establishing liability and conflict of law rules. Anti-money laundering and countering the financing of terrorism (“AML/CFT”) obligations are governed by the Anti- Money Laundering Act (Geldwäschegesetz, “GwG”), which already captures crypto custody and exchange services and is now integrated with EU-level travel rule obligations.
Banks offering crypto-asset services typically integrate those activities into their existing licences, subject to prior notification and supervisory review of the business case, risk controls, and outsourcing arrangements. For standalone providers, CASP authorisation is the primary route, with transitional arrangements available only for entities that were operating under national law within defined timelines. The authorisation process requires robust governance, fit-and-proper management, and safeguarding of clients’ crypto-assets and funds. It also mandates organisational separation between proprietary and client activities, conflict-of-interest management, custody controls, outsourcing oversight, market abuse monitoring, and transparent fee and risk disclosures. Although MiCAR is not a capital regime akin to the Capital Requirements Regulation and Capital Requirements Directive (together, “CRR/CRD”), national competent authorities (“NCAs”)- the authorities designated by each EU Member State to supervise MiCAR compliance-expect adequate own funds calibrated to operational and custody risks. For ART and EMT issuers, NCAs expect reserves, investment policies, and redemption mechanisms aligned to the stabilisation design.
Conduct requirements have tightened, particularly for retail-facing promotions. Disclosures must be fair, clear, and not misleading. Risk factors should address volatility, technology and operational risks, and legal and regulatory uncertainties. Order handling, best execution, inducement rules, and product governance expectations apply by analogy where crypto-assets qualify as financial instruments. Under MiCAR, CASPs must manage conflicts of interest, prevent the misuse of inside information, and implement effective market surveillance for admitted trading pairs on their platforms.
MiCAR draws a sharp line between ARTs, EMTs, and other crypto-assets. ARTs, which reference one or several assets, face stringent obligations covering white papers, governance, reserves, redemption, and ongoing disclosure, with additional layers for significant ARTs designated at EU level by the European Banking Authority (“EBA”). EMTs are treated as a species of e-money, requiring authorisation as an electronic money institution (“EMI”) or credit institution and adherence to par value redemption and safeguarding rules. Other crypto-assets may be publicly offered or admitted to trading on a platform, subject to an approved crypto-asset white paper, with liability attaching for inaccuracies and omissions. In Germany, consumer protection overlays and BaFin’s scrutiny of stabilisation mechanics, reserve management conflicts, and retail marketing have proven decisive in review outcomes.
Tokenised securities remain within the traditional securities perimeter. Where a token embodies a transferable security within the meaning of MiFID II and the Prospectus Regulation (Regulation (EU) 2017/1129), issuers must comply with the securities prospectus regime and, if applicable, ongoing disclosure and market abuse laws. While the eWpG facilitates the issuance of electronic securities via central registers or crypto-securities registers on distributed ledger technology (“DLT”)-a technology enabling the distributed operation and use of electronic ledgers-it does not displace these underlying securities law obligations. Issuers must weigh the DLT Pilot Regime for market infrastructure access against private DLT venues and bilateral arrangements for issuance and lifecycle management.
Germany’s AML/CFT framework applies with full scope to banks and CASPs, encompassing customer due diligence, transaction monitoring, sanctions screening, and suspicious activity reporting. The travel rule now extends to crypto-asset transfers, requiring collection and transmission of originator and beneficiary information, with specific handling for unhosted wallets (also known as self-custodied or non-custodial wallets)-wallets where the user retains direct control of the private cryptographic keys rather than entrusting them to a third party. Firms must implement risk-based controls, including enhanced due diligence for higher-risk geographies and products, and robust screening for sanctioned persons and blocked wallet addresses. DORA mandates ICT risk governance, incident reporting, resilience testing, and third-party risk oversight, requiring both CASPs and banks to align their cloud and custody technology stacks with EU resilience expectations.
Supervisory focus has shifted from permissibility to performance. Expected enforcement priorities include: unlicensed activity under MiCAR or national law; inadequate asset segregation and custody controls; shortcomings in stablecoin reserve management and disclosure; misleading marketing to retail clients; inadequate market surveillance; and failures in travel rule implementation and sanctions screening. The liability regime under white papers and securities prospectuses is likely to drive private actions following significant price dislocations or operational failures. Register keeper liability under the eWpG-including for erroneous or untimely entries in crypto-securities registers-is an emerging vector for claims as tokenised issuance scales.
Key inflection points include: the end of MiCAR’s transitional periods for legacy national operators; the maturation of European Securities and Markets Authority (“ESMA”) and EBA Level 2 standards (the delegated and implementing acts that supplement the primary legislative framework); the growing use of tokenised collateral and settlement assets by banks; and further expansion of the eWpG’s scope and market uptake for shares and fund units. Banks that industrialise digital issuance and custody-integrating on-chain corporate actions, collateral mobility, and programmable payments-are well-positioned to capture treasury and capital markets flows. Policy debates on the prudential classification of crypto-exposures, the treatment of staking and lending, and possible extensions of market abuse and short-selling rules to a broader class of crypto-assets will shape the next regulatory phase.
The intersection of crypto-asset services with the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) is increasingly significant, particularly given that personal data may be processed on public and immutable blockchains. CASPs must assess their roles as data controllers or processors, especially in relation to customer onboarding, transaction monitoring, and decentralised finance (“DeFi”) front-ends-DeFi referring to financial services delivered via smart contracts on public blockchains without traditional intermediaries. Key challenges include applying the right to erasure (‘right to be forgotten’) in the context of blockchain’s immutability, managing cross-border data transfers, and implementing privacy by design. The European Data Protection Board (“EDPB”) has issued guidance on blockchain and GDPR, but practical compliance remains complex, especially for permissionless networks. Firms must also consider the interplay with DORA and ICT risk management, ensuring data protection is embedded within operational resilience frameworks.
While MiCAR and general consumer protection law require effective complaints handling, mechanisms for consumer redress in the crypto-asset sector are still evolving. Retail clients must have access to transparent and timely complaint procedures, with clear escalation paths to alternative dispute resolution (“ADR”) bodies where appropriate. Critical issues include the enforceability of smart contracts-self-executing code deployed on a blockchain that automatically performs agreed actions when specified conditions are met-and the availability of legal recourse following protocol failures, hacks, or mis-selling. CASPs should ensure contractual terms address dispute resolution and that consumers are informed of their rights and remedies. The practicalities of pursuing claims remain a developing area, especially where decentralised protocols or decentralised autonomous organisations (“DAOs”)-blockchain-based entities governed by encoded rules and token-holder voting rather than traditional corporate structures-are involved. Questions around jurisdiction, applicable law, and the identification of responsible parties persist.
The regulatory landscape for digital assets is shaped not only by MiCAR, DORA, and the DLT Pilot Regime, but also by the broader EU Digital Finance Package. The Digital Finance Strategy sets out the EU’s vision for a competitive and innovative digital financial sector, while DORA is closely linked to the NIS2 Directive (Directive (EU) 2022/2555) on cybersecurity. The proposed European Single Access Point (“ESAP”) will provide a centralised platform for accessing financial and sustainability data, thereby facilitating transparency and regulatory reporting. Firms should monitor these developments to ensure holistic compliance and leverage synergies across regulatory initiatives.
Translating regulatory requirements into practice presents a range of operational challenges. Market infrastructure providers-such as central securities depositories (“CSDs”), entities that operate securities settlement systems and provide initial recording and central maintenance of securities accounts, and custodians-must upgrade systems to support large-scale tokenisation and DLT integration. Legacy IT systems may require significant adaptation to interface with blockchain networks, raising issues of interoperability, data integrity, and cyber risk. The insurance market for digital asset risks remains nascent, with limited availability and high premiums for coverage against theft, hacking, or operational failures. Compliance teams also face a skills gap and resource constraints, necessitating investment in training and recruitment to meet new regulatory expectations.
Supervisory authorities in Germany and across the EU are increasingly active in monitoring compliance with crypto-asset regulations. Recent enforcement actions have focused on unlicensed activities, inadequate AML controls, and misleading marketing. BaFin and other regulators are enhancing cross-border cooperation through joint investigations and information sharing, particularly in relation to DeFi and cross-jurisdictional service provision. Firms should expect a proactive supervisory approach, with particular focus on governance, risk management, and consumer protection.
To foster responsible innovation, both Germany and the EU have established regulatory sandboxes and innovation hubs. These initiatives provide a controlled environment for testing novel business models, products, and technologies under regulatory supervision. The DLT Pilot Regime itself functions as a form of sandbox for market infrastructure, while BaFin’s TechQuartier and the European Forum for Innovation Facilitators (“EFIF”) offer additional support. Participation in these programmes can provide regulatory clarity and facilitate constructive engagement with supervisors.
Interoperability between DLT networks, custodians, and market infrastructures is essential for the scalability and efficiency of tokenised markets. The EU is supporting the development of industry standards and technical protocols through the European Blockchain Services Infrastructure (“EBSI”) and standard-setting bodies such as the International Organization for Standardization (“ISO”) and the European Committee for Standardization (Comité Européen de Normalisation, “CEN”). Harmonisation of messaging standards, identity frameworks, and settlement processes will be critical to achieving seamless cross-border operations and reducing operational risk.
The potential introduction of a digital euro by the European Central Bank (“ECB”) and other public sector digital asset initiatives could profoundly impact the competitive landscape and regulatory priorities. A digital euro, as a central bank digital currency (“CBDC”), would provide a risk-free, programmable settlement asset, potentially reshaping payment systems and the role of private stablecoins. Public sector pilots and consultations are ongoing; market participants should monitor developments closely to assess strategic and compliance implications.
Environmental, social, and governance (“ESG”) factors are gaining prominence in financial regulation, and crypto-asset markets are no exception. The environmental impact of blockchain infrastructure—particularly energy-intensive proof-of-work consensus mechanisms—has attracted significant regulatory and public scrutiny. Firms may be required to disclose the sustainability profile of their products, including carbon footprint and energy usage, in line with the EU’s Sustainable Finance Disclosure Regulation (Regulation (EU) 2019/2088, “SFDR”) and forthcoming ESG reporting standards under the Corporate Sustainability Reporting Directive (Directive (EU) 2022/2464, “CSRD”). Social and governance considerations-such as inclusivity, transparency, and the robustness of AML controls-are also increasingly relevant to supervisory assessments. Integrating ESG criteria into tokenised products and services is becoming both a competitive differentiator and a regulatory imperative, as investors and counterparties demand greater transparency on the sustainability characteristics of digital asset offerings.
Emerging case law and judicial trends in Germany and the EU are beginning to shape the legal landscape for crypto-assets, smart contracts, and DAOs. German courts have addressed issues such as the legal classification of tokens, the enforceability of smart contracts, and liability for protocol failures or fraudulent schemes. While jurisprudence remains limited, early decisions suggest a pragmatic approach: courts focus on substance over form, applying existing legal principles—including contract, tort, and insolvency law—to novel technologies. Questions of jurisdiction and applicable law are particularly acute where decentralised protocols operate across borders or where the identity of responsible parties is unclear. Ongoing litigation, regulatory guidance, and academic commentary will continue to clarify the rights and obligations of market participants. Firms should monitor these developments to inform their risk management and contractual frameworks.
While the EU and Germany are at the forefront of crypto-asset regulation, significant differences remain compared to other major jurisdictions. The United Kingdom, having departed from the EU, is developing its own regulatory framework for crypto-assets, with proposals focusing on stablecoins, custody, and trading platforms, though the pace and scope of reform remain subject to ongoing consultation. The United States continues to operate a fragmented regime, with overlapping federal and state authority and ongoing debates over the classification of tokens as securities or commodities. Switzerland and Singapore have established themselves as innovation-friendly jurisdictions with clear licensing pathways for digital asset businesses, while maintaining robust AML and prudential standards. Firms operating internationally must navigate these divergences, ensuring compliance with local requirements and monitoring developments in global standard-setting forums such as the Financial Stability Board (“FSB”) and the International Organization of Securities Commissions (“IOSCO”). The evolving international landscape creates both challenges— regulatory fragmentation and compliance burden—and opportunities for jurisdictions and firms that can offer regulatory certainty and cross-border interoperability.