Regulatory framework
A regulated crypto on-ramp doesn't operate in a grey zone — it operates on top of a stack of recent statutes. This page lists every act we rely on, what it does, and how FotifyPay maps to it. All references are public; click through to read the official texts.
1. The European Union — the unified rulebook
1.1 MiCA — Regulation (EU) 2023/1114
The Markets in Crypto-Assets Regulation is the legal foundation of FotifyPay's EU activity. Fully applicable since 30 December 2024, it creates a single licence — the CASP (Crypto-Asset Service Provider) authorisation — passportable across all 27 member states.
What MiCA imposes on us: prudential capital, governance, conduct-of-business rules, complaint handling, conflict-of-interest management, market-abuse prevention, white-paper disclosures for any issued token, and transparency of the order-execution policy. Read the consolidated text on EUR-Lex →
1.2 Transfer of Funds Regulation — Regulation (EU) 2023/1113
The "Travel Rule" for crypto. From 30 December 2024, every transfer must carry originator and beneficiary identification — name, account/wallet address, and (above the threshold) date of birth or customer ID. FotifyPay attaches this data outbound and validates it inbound. Unverified inbound transfers enter a holding state pending counterparty information. Official text →
1.3 The AML Package — AMLR + AMLD6 + AMLA
- Regulation (EU) 2024/1624 (AMLR) — the single, directly-applicable EU AML rulebook. Customer due diligence, beneficial-owner verification, source-of-funds thresholds, recordkeeping. Text →
- Directive (EU) 2024/1640 (AMLD6) — supervisory powers, FIU cooperation, beneficial-owner registers. Text →
- Regulation (EU) 2024/1620 (AMLA) — the EU Anti-Money Laundering Authority, headquartered in Frankfurt, starts direct supervision of the highest-risk entities from 2025. Text →
1.4 PSD2 — Directive (EU) 2015/2366 — Open Banking
The legal foundation of European Open Banking. PSD2 created two regulated services we depend on: AISP (Account Information Service Providers) and PISP (Payment Initiation Service Providers). Strong Customer Authentication (SCA) under RTS 2018/389 is what makes pay-ins by Open Banking both fast and secure. The proposed PSD3 / Payment Services Regulation will extend this further from 2026 onward. Text →
1.5 GDPR — Regulation (EU) 2016/679
The data-protection floor for everything we do with personal data. See our dedicated GDPR page for the operational implementation. Text →
1.6 DORA — Regulation (EU) 2022/2554
The Digital Operational Resilience Act. From 17 January 2025, financial entities must run a documented ICT risk-management framework, classify and report ICT incidents on the regulator's clock, oversee third-party providers, and run regular resilience tests. FotifyPay reports under DORA's incident-reporting taxonomy in parallel with GDPR breach notifications. Text →
1.7 eIDAS 2 — Regulation (EU) 2024/1183
The legal basis of the EU Digital Identity Wallet (EUDI Wallet). We are following the implementing-acts timeline so customers can complete KYC with their wallet once it is widely deployed in their member state. Text →
2. The United Kingdom — Cryptoasset Register & MLR 2017
- Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 (SI 2017/692) — the UK AML rulebook. The FCA operates the Cryptoasset Register under reg. 54A. Only registered firms may legally offer crypto services to UK residents. Text →
- UK Travel Rule — extension of MLR 2017 in force since 1 September 2023. Same originator/beneficiary information requirement as the EU TFR. FCA guidance →
- Financial Services and Markets Act 2023 — the framework that lets HM Treasury extend the regulated activities order to crypto, in stages, throughout 2025–2026. Text →
- Consumer Duty (FCA PS22/9) — for retail customers, we apply the FCA's good-outcomes standard.
3. Canada — PCMLTFA & FINTRAC MSB registration
- PCMLTFA (S.C. 2000, c. 17) — Canada's federal AML statute. Virtual-currency dealers are Money Services Businesses; we hold an MSB registration with FINTRAC. Act → · FINTRAC →
- Travel Rule for virtual currency — applicable since 1 June 2021. Same information set as FATF R.16.
- PIPEDA — the federal private-sector privacy law that governs personal data of Canadian customers. Act →
- Provincial securities law — we do not offer crypto-asset trading platforms (CTPs) under CSA Staff Notices 21-329 / 21-332; we operate strictly as an on-ramp.
4. International standards we follow
- FATF 40 Recommendations — in particular Recommendation 16 (Wire Transfers), the global Travel Rule blueprint. fatf-gafi.org →
- Wolfsberg Principles for correspondent payments where we touch the traditional rails.
- OFAC SDN list — screened against every payout address via the Chainalysis on-chain Sanctions Oracle. OFAC →
- ISO/IEC 27001 — information-security management system. Audit cycle in progress.
5. How each act maps to a FotifyPay control
| Act | FotifyPay control |
|---|---|
| MiCA — Title V (CASP rules) | Authorised CASP licence; conduct & conflict-of-interest policies; complaint-handling SLA |
| TFR (EU 2023/1113) | Travel Rule data attached on every outbound transfer; sunrise-rule holding state on inbound |
| AMLR (EU 2024/1624) | CDD/EDD workflow; PEP & sanctions screening via ComplyAdvantage |
| AMLD6 (EU 2024/1640) | FIU.net access; STR/SAR templates aligned to FIU formats |
| GDPR (EU 2016/679) | Art. 13 notice; DSAR pipeline; DPO; SCC-backed transfers |
| PSD2 + RTS 2018/389 | SCA-compliant Open Banking pay-ins; AISP/PISP partner integration |
| DORA (EU 2022/2554) | ICT risk register; incident-reporting taxonomy; resilience testing cadence |
| UK MLR 2017 | FCA Cryptoasset Register; UK Travel Rule outbound/inbound |
| PCMLTFA + FINTRAC MSB | MSB registration; STRs via F2R; Canada-specific record-keeping |
| FATF R.16 | Travel Rule as the global control fabric across all three jurisdictions |
6. Where to escalate
If you believe we have breached any of the above, write to legal@fotifypay.com first. If unresolved, you may complain to:
- Your national EU competent authority (or the AMLA for direct-supervision entities).
- The UK FCA (for UK customers) at fca.org.uk.
- FINTRAC (for Canadian customers) at fintrac-canafe.gc.ca.
- Your national Data Protection Authority for privacy concerns.
Disclaimer: this page is a customer-facing summary of our regulatory framework. It is accurate as of the "Last updated" date at the top, but regulations evolve. For the binding, authoritative text always refer to the official sources linked above.