🌉 FotifyPay
Home How it works Security Regulation Partners FAQ
Sign in Buy crypto
Home How it works Security Regulation Partners FAQ
Sign in Buy crypto

Legal

  • Privacy policy
  • Terms of service
  • GDPR — your rights
  • AML / KYC policy
  • Cookies
  • Regulatory framework

Questions? legal@fotifypay.com

FotifyPay · Legal

Regulatory framework

Version: v2.0 Last updated: 2026-05-17 Applies to: EU · UK · CA

A regulated crypto on-ramp doesn't operate in a grey zone — it operates on top of a stack of recent statutes. This page lists every act we rely on, what it does, and how FotifyPay maps to it. All references are public; click through to read the official texts.

1. The European Union — the unified rulebook

1.1 MiCA — Regulation (EU) 2023/1114

The Markets in Crypto-Assets Regulation is the legal foundation of FotifyPay's EU activity. Fully applicable since 30 December 2024, it creates a single licence — the CASP (Crypto-Asset Service Provider) authorisation — passportable across all 27 member states.

What MiCA imposes on us: prudential capital, governance, conduct-of-business rules, complaint handling, conflict-of-interest management, market-abuse prevention, white-paper disclosures for any issued token, and transparency of the order-execution policy. Read the consolidated text on EUR-Lex →

1.2 Transfer of Funds Regulation — Regulation (EU) 2023/1113

The "Travel Rule" for crypto. From 30 December 2024, every transfer must carry originator and beneficiary identification — name, account/wallet address, and (above the threshold) date of birth or customer ID. FotifyPay attaches this data outbound and validates it inbound. Unverified inbound transfers enter a holding state pending counterparty information. Official text →

1.3 The AML Package — AMLR + AMLD6 + AMLA

  • Regulation (EU) 2024/1624 (AMLR) — the single, directly-applicable EU AML rulebook. Customer due diligence, beneficial-owner verification, source-of-funds thresholds, recordkeeping. Text →
  • Directive (EU) 2024/1640 (AMLD6) — supervisory powers, FIU cooperation, beneficial-owner registers. Text →
  • Regulation (EU) 2024/1620 (AMLA) — the EU Anti-Money Laundering Authority, headquartered in Frankfurt, starts direct supervision of the highest-risk entities from 2025. Text →

1.4 PSD2 — Directive (EU) 2015/2366 — Open Banking

The legal foundation of European Open Banking. PSD2 created two regulated services we depend on: AISP (Account Information Service Providers) and PISP (Payment Initiation Service Providers). Strong Customer Authentication (SCA) under RTS 2018/389 is what makes pay-ins by Open Banking both fast and secure. The proposed PSD3 / Payment Services Regulation will extend this further from 2026 onward. Text →

1.5 GDPR — Regulation (EU) 2016/679

The data-protection floor for everything we do with personal data. See our dedicated GDPR page for the operational implementation. Text →

1.6 DORA — Regulation (EU) 2022/2554

The Digital Operational Resilience Act. From 17 January 2025, financial entities must run a documented ICT risk-management framework, classify and report ICT incidents on the regulator's clock, oversee third-party providers, and run regular resilience tests. FotifyPay reports under DORA's incident-reporting taxonomy in parallel with GDPR breach notifications. Text →

1.7 eIDAS 2 — Regulation (EU) 2024/1183

The legal basis of the EU Digital Identity Wallet (EUDI Wallet). We are following the implementing-acts timeline so customers can complete KYC with their wallet once it is widely deployed in their member state. Text →

2. The United Kingdom — Cryptoasset Register & MLR 2017

  • Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 (SI 2017/692) — the UK AML rulebook. The FCA operates the Cryptoasset Register under reg. 54A. Only registered firms may legally offer crypto services to UK residents. Text →
  • UK Travel Rule — extension of MLR 2017 in force since 1 September 2023. Same originator/beneficiary information requirement as the EU TFR. FCA guidance →
  • Financial Services and Markets Act 2023 — the framework that lets HM Treasury extend the regulated activities order to crypto, in stages, throughout 2025–2026. Text →
  • Consumer Duty (FCA PS22/9) — for retail customers, we apply the FCA's good-outcomes standard.

3. Canada — PCMLTFA & FINTRAC MSB registration

  • PCMLTFA (S.C. 2000, c. 17) — Canada's federal AML statute. Virtual-currency dealers are Money Services Businesses; we hold an MSB registration with FINTRAC. Act → · FINTRAC →
  • Travel Rule for virtual currency — applicable since 1 June 2021. Same information set as FATF R.16.
  • PIPEDA — the federal private-sector privacy law that governs personal data of Canadian customers. Act →
  • Provincial securities law — we do not offer crypto-asset trading platforms (CTPs) under CSA Staff Notices 21-329 / 21-332; we operate strictly as an on-ramp.

4. International standards we follow

  • FATF 40 Recommendations — in particular Recommendation 16 (Wire Transfers), the global Travel Rule blueprint. fatf-gafi.org →
  • Wolfsberg Principles for correspondent payments where we touch the traditional rails.
  • OFAC SDN list — screened against every payout address via the Chainalysis on-chain Sanctions Oracle. OFAC →
  • ISO/IEC 27001 — information-security management system. Audit cycle in progress.

5. How each act maps to a FotifyPay control

ActFotifyPay control
MiCA — Title V (CASP rules)Authorised CASP licence; conduct & conflict-of-interest policies; complaint-handling SLA
TFR (EU 2023/1113)Travel Rule data attached on every outbound transfer; sunrise-rule holding state on inbound
AMLR (EU 2024/1624)CDD/EDD workflow; PEP & sanctions screening via ComplyAdvantage
AMLD6 (EU 2024/1640)FIU.net access; STR/SAR templates aligned to FIU formats
GDPR (EU 2016/679)Art. 13 notice; DSAR pipeline; DPO; SCC-backed transfers
PSD2 + RTS 2018/389SCA-compliant Open Banking pay-ins; AISP/PISP partner integration
DORA (EU 2022/2554)ICT risk register; incident-reporting taxonomy; resilience testing cadence
UK MLR 2017FCA Cryptoasset Register; UK Travel Rule outbound/inbound
PCMLTFA + FINTRAC MSBMSB registration; STRs via F2R; Canada-specific record-keeping
FATF R.16Travel Rule as the global control fabric across all three jurisdictions

6. Where to escalate

If you believe we have breached any of the above, write to legal@fotifypay.com first. If unresolved, you may complain to:

  • Your national EU competent authority (or the AMLA for direct-supervision entities).
  • The UK FCA (for UK customers) at fca.org.uk.
  • FINTRAC (for Canadian customers) at fintrac-canafe.gc.ca.
  • Your national Data Protection Authority for privacy concerns.
Disclaimer: this page is a customer-facing summary of our regulatory framework. It is accurate as of the "Last updated" date at the top, but regulations evolve. For the binding, authoritative text always refer to the official sources linked above.

This document is part of FotifyPay's binding legal framework. If a translated version differs from the English original, the English text prevails. For complaints, contact legal@fotifypay.com — or escalate to the regulator listed on our Regulatory framework page.

🌉 FotifyPay

A calmer on-ramp to crypto

Buy Bitcoin, Ethereum and USDT with EUR, CAD or GBP — through Open Banking or card. Built for the EU, UK and Canada.

Product

  • Home
  • How it works
  • Security
  • Loyalty
  • Rates
  • FAQ

Partner

  • Affiliate program
  • APM partnerships
  • Open Banking providers
  • Large-client pricing

Legal

  • Privacy policy
  • Terms of service
  • GDPR — your rights
  • AML / KYC policy
  • Cookies
  • Regulatory framework

Contact

  • support@fotifypay.com
  • legal@fotifypay.com
  • partners@fotifypay.com
  • Telegram support

FotifyPay © 2026 — FCA reg. №928910 · FINTRAC MSB · MiCA CASP · GDPR compliant

Not investment advice. Crypto assets are volatile and not covered by deposit-protection schemes. Past performance is no guarantee of future results.