• PL
  • EN
  • Proud Member of Alliott Global Alliance — Chambers Top Ranked Global 2023
    Woloszanski & Partners

    Legal support for cryptocurrency and blockchain firms

    We advise on setting up cryptocurrency companies, implementing legal requirements and legal auditing their activity
    Chambers Contributor — Global Practice Guides 2026, Blockchain & Crypto-Assets
    Home Legal solutions Cryptocurrency firms
    We stand on the side of innovation
    At Wołoszański & Partners, we assist innovative companies in achieving safe development in the new technology market. We explain the intricate cryptocurrency regulations in simple, clear and coherent language to help you adapt to them wisely. We remove legal obstacles so that you can fully focus on the implementation of your project.

    Our services

    Our legal services for cryptocurrency firms

    End-to-end support at every stage — from token classification and licensing to ongoing compliance, tax and disputes. Below are the areas in which we guide our clients.

    01

    Regulatory analysis and token classification

    We determine whether your activity and tokens fall under MiCA, under financial-instrument rules, or outside those regimes — and what other laws (e.g. payments, consumer, AML, tax) may nevertheless apply. This is the foundation for every further decision.

    02

    CASP licensing and EU passporting

    We guide you through obtaining a CASP authorisation in a chosen EU member state and passporting services into Poland, with the full application file.

    03

    White paper and disclosure duties

    We prepare the crypto-asset white paper and other MiCA disclosure duties, including marketing communications that meet the requirements.

    04

    AML/CFT programme and the Travel Rule

    We implement KYC/KYT procedures, risk assessment, reporting and the transfer-of-data obligation (Regulation (EU) 2023/1113).

    05

    Crypto taxation and DAC8

    Tax treatment of the business and its transactions, plus the new reporting duties under the DAC8 directive.

    06

    DORA and ICT operational resilience

    ICT risk management, contracts with ICT providers and incident-response procedures in line with DORA.

    07

    Contracts and terms of service

    Terms of service, custody, staking and listing agreements and B2B contracts — tailored to the crypto-asset market.

    08

    Data protection (GDPR)

    GDPR compliance for data processing in a blockchain and KYC environment, including controller and processor roles and on-chain data.

    09

    Sanctions and market abuse

    Compliance with the sanctions regime and MiCA market-abuse rules for crypto-assets admitted to trading or for which admission has been requested.

    10

    DeFi, DAO and tokenisation

    Legal classification of DeFi protocols and DAOs, smart contracts and the tokenisation of real-world assets (RWA).

    11

    Restructuring and redomiciliation

    An orderly move or conversion of the business to a jurisdiction with a functioning CASP regime, while managing business continuity to the extent legally achievable.

    12

    Disputes and representation before authorities

    Representation in supervisory, tax and court proceedings and in disputes with counterparties and clients.

    Our cryptocurrency experts

    Our experts are known for their success and acumen in handling particularly complex cases for international clients.

    Łukasz Kudela

    Łukasz Kudela

    Cryptocurrency Project Manager · Attorney-at-law

    Łukasz has cooperated with 47 foreign law firms and has extensive experience in conducting analyses and preparing legal opinions for cryptocurrency companies, including global exchanges. He has a thorough command of the applicable conditions and regulations on local and foreign markets.

    Contact Łukasz Click the card for the full profile ›
    Michał Wołoszański

    Michał Wołoszański

    Managing Partner · INSEAD Global Executive MBA · Attorney-at-law

    Michał, with a particular focus on intellectual property, combines professional experience and legal education with a passion for new technologies and business. He identifies the risks of a transaction and of the venture’s subsequent operation, and proposes the right legal solutions.

    Contact Michał Click the card for the full profile ›
    Karolina Dębiec

    Karolina Dębiec

    Lawyer · Key Projects Coordinator

    Karolina is a specialist in legal research, focusing on labour and corporate law. Her background includes a role as a research lawyer at a global corporation, advising both private and public organisations. She is currently involved in the development of intricate compliance systems, and works in both Polish and English.

    Contact Karolina Click the card for the full profile ›

    Regulatory compliance

    Comprehensive compliance for the digital-asset market

    We guide cryptocurrency businesses through the full regulatory landscape — from MiCA implementation and CASP licensing to AML/CFT obligations, taxation and operational resilience. Below are the areas in which we support our clients.

    01

    MiCA & CASP licensing

    Implementation of the MiCA Regulation, obtaining CASP authorisation, white-paper requirements, and the EMT/ART (stablecoin) token regime.

    02

    AML/CFT & VASP register

    Anti-money-laundering procedures, registration of virtual-currency activity, and the duties of an Approved AML & Sanctions Officer.

    03

    Travel Rule

    Compliance with EU Regulation 2023/1113 — transmitting originator and beneficiary information on transfers of crypto-assets.

    04

    Taxation & DAC8

    Taxation of virtual currencies (19%), the new DAC8 reporting obligations, and cross-border reporting.

    05

    DORA & operational resilience

    Implementation of the Digital Operational Resilience Act for financial-market entities and their ICT providers.

    06

    DeFi, DAO & tokenisation

    Legal classification of DeFi protocols and DAOs, smart contracts, the regulatory sandbox, and asset tokenisation.

    Frequently asked questions

    Does my cryptocurrency firm need a CASP licence?

    As a rule, yes — if you provide a service listed in MiCA professionally in the EU and no exclusion or Article 60 notification route for an already-regulated financial entity applies. The MiCA regulation has applied since 30 December 2024, and on 1 July 2026 the transitional period ended for firms that had been operating under national registers. From that date, carrying on a MiCA-covered activity — for example an exchange, a bureau de change, custody (a custodial wallet), a trading platform, order execution or advice on crypto-assets — requires an authorisation as a crypto-asset service provider (CASP).

    Not every crypto-related activity is a CASP service, however. We help you establish whether your business model falls within the catalogue of MiCA-covered services at all and, if so, which service category applies and what capital, organisational and disclosure requirements come with it.

    Operating without the required authorisation after the end of the transitional period exposes the firm to supervisory sanctions and the risk of losing the ability to serve clients in the EU. That is why the first step is always a sound legal classification of your activity.

    Can I obtain a CASP licence in Poland today?

    In practice, no — Poland currently has no authority that issues CASP authorisations. The MiCA regulation applies directly, but granting authorisations requires a national act that designates a supervisory authority and a licensing procedure. Successive versions of the crypto-asset market act have been vetoed by the President (including on 1 December 2025, 12 February 2026 and 11 June 2026); no version has entered into force and the legislative process is still ongoing.

    As a result, in its position of 10 February 2026 the Polish Financial Supervision Authority (KNF) stated that, until an authority is designated by statute, it can neither open nor conduct proceedings to grant a CASP authorisation. The 1 July 2026 deadline, moreover, cannot be moved by a national decision or by the KNF alone.

    This does not mean that lawful crypto activity in Poland is impossible. The realistic route today is to obtain a CASP licence in another EU member state and serve clients in Poland under the passporting mechanism. We advise on which jurisdictions are currently the most predictable and how to build a MiCA-compliant structure.

    What does the end of the MiCA transitional period on 1 July 2026 mean for me?

    From 1 July 2026, the previous national register regimes — in Poland, entry in the register of virtual-currency activity — no longer entitle a firm to provide MiCA-covered services. Firms that did not obtain a CASP authorisation have, as a rule, lost the right to continue providing those services within the EU.

    An unauthorised provider may not continue MiCA-covered services while awaiting authorisation. In line with ESMA statements of 17 April and 23 June 2026, it should immediately stop onboarding new EU clients and implement an orderly wind-down or migration of existing relationships. The strategic decision is therefore between obtaining a CASP authorisation in another EU member state and passporting it into Poland, narrowing the activity to services not covered by MiCA, or ending or moving the business in an orderly way.

    Each of these options carries different regulatory, tax and contractual consequences — including towards clients, banks and counterparties. We help choose the option that fits the scale and model of the firm and carry it out lawfully and with business continuity preserved.

    How does a CASP licence differ from entry in the VASP register?

    Entry in the register of virtual-currency activity (the VASP register kept in Poland) is the previous, national register regime based mainly on anti-money-laundering obligations. It was essentially an administrative entry rather than an authorisation to conduct regulated financial activity.

    A CASP licence under MiCA is a full regulatory authorisation, uniform across the EU. It comes with capital requirements, requirements on corporate governance, risk management, the holding and safeguarding of client funds, disclosure duties and prudential supervision — going considerably further than a mere register entry.

    Moving from a VASP entry to a CASP authorisation is therefore not a simple change of form but a qualitative change in the compliance model. We support the gap analysis between the current state and CASP requirements and the preparation of the full application file.

    How can I obtain a CASP licence in another EU state and passport it into Poland?

    Under the single-market principle, a provider that has obtained a CASP authorisation in one member state may provide services across the EU — including in Poland — under a passport, without a separate authorisation in each country. This is the main realistic route today for firms that want to serve Polish clients in line with MiCA.

    The process involves choosing a jurisdiction with a predictable and efficient supervisory practice, setting up or adapting an entity there and preparing the CASP application file (including prudential safeguards, governance, AML, ICT and service-specific policies); any issuance documentation, including a white paper where the project requires one, is prepared separately. Once authorised, the passport notification is submitted to the home-state competent authority, which transmits it to the Polish single point of contact and to ESMA and EBA.

    We advise on the choice of jurisdiction, the structure and the coordination with local advisers, so that the model is MiCA-compliant while remaining efficient for tax and operations. We pay attention to genuine business substance — an address in another state alone is not enough.

    What AML/CFT obligations does a cryptocurrency firm have?

    Crypto-asset service providers (CASPs) and other entities identified by the applicable AML rules are obliged institutions — though not every crypto-related business is one. This means, among other things, applying financial-security measures (customer identification and verification — KYC), ongoing transaction monitoring, reporting and appointing persons responsible for AML. An entity subject to the Polish AML Act makes its reports to the General Inspector of Financial Information; in a cross-border structure the competent authority and reporting channel must be determined separately.

    On top of that comes the Travel Rule — the obligation to transmit information on the originator and the beneficiary when transferring crypto-assets, arising from Regulation (EU) 2023/1113. Firms must also apply measures against sanctions risk and screen counterparties against sanctions lists.

    We implement complete AML/CFT programmes scaled to the business: internal procedures, a risk assessment, KYC/KYT paths, Travel Rule documentation and team training. A well-designed AML programme is today not only a legal requirement but also a condition for working with banks and partners.

    What is the Travel Rule and whom does it apply to?

    The Travel Rule is the obligation to transmit, together with a transfer of crypto-assets, information identifying the originator and the beneficiary, so that crypto-asset transactions are as transparent as traditional transfers. In the EU it is governed by Regulation (EU) 2023/1113 (the recast Transfer of Funds Regulation), which has applied since 30 December 2024.

    The duties differ depending on whether the CASP acts for the originator or the beneficiary of a transfer. Where a self-hosted address is involved, the relevant CASP must obtain and hold the required information and, for a transfer exceeding EUR 1,000, take appropriate measures to assess whether the address is owned or controlled by its client. A person-to-person transfer without CASP involvement is outside the Regulation.

    Implementing the Travel Rule requires technical solutions (integration with tools for exchanging data between providers), procedures for handling missing data and consistency with AML and GDPR policy. We help design and document the whole process in line with the requirements.

    How are cryptocurrencies taxed in Poland and what is DAC8?

    In Poland, income from the disposal of virtual currencies for consideration is taxed at 19% (as income from monetary capital), and costs are settled under special rules. The tax classification of specific events — for example staking, crypto-to-crypto exchanges, remuneration in tokens or business activity — can nonetheless be complex and calls for individual analysis.

    A new element is DAC8 (Council Directive (EU) 2023/2226), which Poland implemented through the Act of 13 February 2026. Due-diligence and data-collection duties cover transactions from 1 January 2026, and reporting crypto-asset service providers must submit their first information, for 2026, to the Head of the National Revenue Administration by 30 June 2027. The category of a reporting provider is not the same as holding a CASP authorisation.

    We advise both firms (reporting obligations, procedures for collecting client data) and on structuring transactions, so that settlements are lawful and resilient to disputes with the tax authorities.

    Does MiCA cover NFTs?

    As a rule, no — MiCA excludes from its scope non-fungible tokens (NFTs) that are genuinely unique and non-interchangeable, for example representing a specific work of art or a collectible. The exclusion is not automatic, however, and does not depend on the name "NFT" alone.

    If tokens are issued in large, fungible series, are fractional in nature, or perform a function similar to other crypto-assets (for example an investment instrument or a means of payment), they may fall under MiCA or, if they qualify as financial instruments, under the applicable capital-markets rules instead of MiCA. What decides is the actual function and economic features of the token, not its label.

    Every NFT project therefore requires an individual legal assessment: classification of the token, analysis of the issuance and secondary-trading model and the resulting obligations. We help carry out this assessment before a project launches, to avoid an unexpected regulatory classification.

    What is DORA and does it apply to cryptocurrency firms?

    Yes — crypto-asset service providers authorised under MiCA and issuers of asset-referenced tokens (ARTs) are covered by the DORA regulation (the Digital Operational Resilience Act), which has applied since 17 January 2025; it does not automatically cover every business engaged in crypto-related activity. DORA imposes requirements on digital operational resilience: ICT risk management, reporting of major incidents, resilience testing and oversight of third-party ICT service providers.

    For a crypto firm this means putting the security and business-continuity area in order: ICT risk-management policies, a register of ICT providers, contractual clauses with providers (including cloud providers) and incident-response procedures.

    DORA requirements dovetail with MiCA and AML obligations, so it is best to implement them coherently rather than in isolation. We help map the requirements onto real processes in the firm, prepare the documentation and contractual clauses and ready the organisation for any supervisory questions.

    How does MiCA treat stablecoins (ART and EMT tokens)?

    MiCA distinguishes two special categories of stable-value crypto-assets: asset-referenced tokens (ART) and e-money tokens (EMT). The rules on these tokens applied earlier than the CASP regime — from 30 June 2024 — and provide for separate, stricter requirements.

    An ART issuer generally requires MiCA authorisation (subject to statutory exemptions), publishes a white paper and must maintain a reserve of assets; an ART is redeemed at the market value of the referenced assets or through delivery of those assets. An EMT, by contrast, must generally be issued by a credit institution or an e-money institution and is redeemable at any time at par value. Tokens designated as significant — under MiCA criteria and procedure — are subject to additional prudential requirements.

    If you plan to issue or trade in a stablecoin, the proper classification of the token and the choice of a MiCA-compliant model are key. We advise on the issuance structure, the documentation and the reserve requirements, and on admitting the token to trading.

    How do we start working with the firm?

    We start with a regulatory analysis of your activity: we establish whether and which services are covered by MiCA, how your tokens are classified and which obligations (CASP, AML, the Travel Rule, DORA, taxes) already apply to you. The result is a clear map of risks and compliance gaps together with priorities.

    On that basis we propose a strategy: the licensing route (most often a CASP licence in a chosen EU state and passporting into Poland), the scope of AML and DORA implementation, the tax model and a timeline. We then move to delivery — documentation, applications, procedures and contracts — and support the firm in day-to-day matters and in contacts with the authorities.

    We work across disciplines: we combine financial-markets law, AML, tax and technology law. As a result you receive one coherent advice rather than scattered opinions. You can book a first conversation and an initial assessment of your situation through the contact form.

    Legal position: July 2026. The crypto-asset market is changing rapidly — following the end of the MiCA transitional period (1 July 2026) and given the absence of a national crypto-asset market act in Poland, the rules and supervisory practice may change. The information above is general in nature and does not constitute legal advice.