In Portugal, the terminology used to define these assets is not entirely uniform, which contributes to regulatory complexity. For example, the Portuguese regulator traditionally uses the term “virtual assets” rather than “blockchain assets”, whereas EU legislation adopts the term “cryptoassets”, as reflected in Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in cryptoassets (the “MiCA Regulation” or MiCA).
The MiCA Regulation defines a “cryptoasset” as “a digital representation of a value or of a right that is able to be transferred or stored electronically using distributed ledger technology or similar technology”.
At the national level, Law No. 83/2017 of 18 August defines virtual assets as a “digital representation of value that is not necessarily linked to a legally established currency and does not have the legal status of fiat currency, a security or another financial instrument, but which is accepted by natural or legal persons as a means of exchange or investment and may be transferred, stored and traded electronically”.
With respect to stablecoins, Portugal now follows the classifications set out in the MiCA Regulation, which distinguishes between asset-referenced tokens (ARTs) and electronic money tokens (EMTs). Pursuant to Article 3(6) of the MiCA Regulation, ARTs are defined as a “type of cryptoasset that is not an electronic money token and that purports to maintain a stable value by referencing another value or right or a combination thereof, including one or more official currencies”. On the other hand, EMTs are defined as a “type of cryptoasset that purports to maintain a stable value by referencing the value of one official currency”.
With respect to non-fungible tokens (NFTs), Portuguese law does not currently provide for a specific regulatory regime or statutory definition governing the issuance or trading of NFTs, or the operation of NFT platforms/marketplaces. Nevertheless, depending on their specific characteristics, NFTs may hypothetically qualify as securities and, if so, fall within the scope of the Portuguese Securities Code.
While the MiCA Regulation generally excludes NFTs from the definition of cryptoassets, this exclusion does not entirely exempt NFTs from falling under the purview of the MiCA Regulation.
With respect to cryptoassets that qualify as financial instruments, the primary regulatory framework at EU level is Regulation (EU) 2022/858 of the European Parliament and of the Council of 30 May 2022 on a pilot regime for market infrastructures based on distributed ledger technology (the “DLT Pilot Regime”). This Regulation establishes a specific legal framework governing the issuance, trading and settlement of financial instruments that are recorded and transferred using distributed ledger technology.
Portugal implemented the DLT Pilot Regime through Decree-Law No. 66/2023 of 8 August, which transposes into the Portuguese legal order the rules applicable to the use of DLT in the issuance, trading and settlement of financial instruments.
Decree-Law No. 66/2023 of 8 August further sets out, at national level, the key rules governing the implementation of the DLT Pilot Regime in Portugal, in particular by:
- defining how DLT-based systems are integrated into the Portuguese capital markets and adapting certain provisions of the Portuguese Securities Code to reflect the specific features of DLT;
- establishing specific authorisation requirements for entities seeking to operate DLT-based market infrastructures, including registration, trading and settlement systems;
- providing for exemptions from the obligation to register financial instruments in traditional centralised systems where DLT-based infrastructures are used; and
- designating the Portuguese Securities Market Commission (Comissão do Mercado de Valores Mobiliários (CMVM)) as the competent national authority for the authorisation, supervision and oversight of activities carried out under the DLT Pilot Regime.
At EU level, the MiCA Regulation entered into force in June 2023 and became fully applicable in Portugal on 30 December 2024.
Portugal took approximately 30 months to adopt the domestic legislation necessary to implement MiCA. This delay created practical difficulties for entities seeking registration as cryptoasset service providers (CASPs), as well as for entities already licensed in Portugal, since no transitional regime was initially established and the national competent authorities responsible for authorisation and supervision under MiCA had not yet been designated. As a result, a period of regulatory uncertainty and operational stagnation affected the Portuguese blockchain ecosystem.
This situation was addressed with the entry into force of Law No. 69/2025 of 22 December, which implements the MiCA Regulation in Portugal. This legislation represents a decisive step towards the full regulatory harmonisation of cryptoasset markets, bringing clarity after a prolonged period during which market participants lacked certainty as to the competent supervisory authority and applicable authorisation procedures.
Law No. 69/2025 clarifies, in particular, the following key aspects:
- supervisory and regulatory competences are allocated between the Bank of Portugal and the CMVM, depending on the category of cryptoasset and the nature of the services provided;
- the Bank of Portugal is responsible for the supervision of public offerings of ARTs and EMTs, as well as for the prudential supervision of CASPs;
- the CMVM is responsible for the supervision of public offerings of cryptoassets other than ARTs and EMTs, for conduct-of-business supervision of CASPs, and for market abuse matters;
- the Bank of Portugal and the CMVM cooperate in the CASP authorisation process; and
- a grandfathering regime applies, allowing entities registered with the Bank of Portugal under the previous virtual asset service provider (VASP) regime to continue operating until 1 July 2026, or until an authorisation under MiCA is granted or refused, whichever occurs first.
With respect to the key regulatory bodies, Portugal relies on two administrative authorities vested with regulatory, supervisory and sanctioning powers, each acting within its respective area of competence:
- The Bank of Portugal, acting as the Portuguese central bank and a member of the European System of Central Banks under the European Central Bank, is responsible for the supervision of credit institutions, payment institutions, electronic money institutions and, under MiCA, for the prudential supervision and certain authorisation functions relating to CASPs.
- The CMVM, which supervises securities offerings, capital markets and asset management activities in Portugal, is also the competent authority for authorising crowdfunding activities and, where relevant, may request technical opinions from the Bank of Portugal in that context.
There are no types of cryptoassets that are outlawed outright. Nevertheless, there are, strictly speaking, no entirely unregulated tokens in Portugal. In most cases, a given token that does not fall within the scope of MiCA is nevertheless likely to fall within the regulatory scope of the Portuguese Securities Code, where such token is classified as a financial instrument or financial asset, or, alternatively, to become subject to regulation under the DLT Pilot Regime.
In Portugal, electronic money regulated under Decree-Law No. 91/2018 of 12 November, which transposes Directive (EU) 2015/2366 of the European Parliament and of the Council (PSD2) into Portuguese law differs from EMTs introduced by the MiCA Regulation. The former covers electronically stored monetary value issued against funds and supervised by the Bank of Portugal. EMTs, by contrast, are cryptoassets designed to maintain a stable value by reference to a single official currency and are subject to a distinct, harmonised EU regulatory regime under MiCA.
In the current legal landscape, it is likely that all types of tokens, including utility tokens that in the past were less prone to regulation, regardless of their specific features or characteristics, will fall within the scope of existing regulatory frameworks, as the regulatory perimeter in this area continues to expand over time.
As of this date, there are 10 entities registered with the Bank of Portugal to provide services related to virtual assets in Portugal. With regard to applications for authorisation as CASPs under the MiCA Regulation, no entities have yet been registered. This situation may be explained by the fact that Portugal only domesticated the Regulation in December 2025.
Law No. 69/2025 of 22 December 2025 establishes a transitional regime, applicable until 1 July 2026, pursuant to which all entities that were, as at 30 December 2024, registered with the Bank of Portugal to carry out activities involving virtual assets may continue to do so until authorisation is granted or refused under the MiCA Regulation, or until the expiry of the transitional period (whichever occurs first).
At this stage, it is difficult to estimate the length of time required for the assessment and approval of applications by the competent authorities, particularly while the supervisory authorities themselves are adapting to the new procedures and regulatory framework introduced by the MiCA Regulation.
In terms of timing, once the applicant has submitted all documentation required to duly instruct the registration process for assessment by the Bank of Portugal and the CMVM, the applicant must be notified of the final decision (approval or refusal) within 40 business days, and in any event no later than 60 business days from submission. Where authorisation is granted, the applicant has 12 months from the date of the decision to commence its activities.
Portugal has no standalone regime governing the advertising of fintech or cryptoasset products. Advertising is regulated through general consumer protection rules, the Advertising Code, and sector-specific financial legislation.
Under the MiCA Regulation, advertising of cryptoassets must be fair, clear and not misleading and must be consistent with the information disclosed in the MiCA white paper. Issuers of ARTs and EMTs are required to prepare and publish a white paper setting out the terms of the offer and the main risks. CASPs, where not acting as issuers, must ensure their marketing communications are aligned with the applicable white paper.
More generally, advertising addressed to consumers in Portugal is subject to the Advertising Code and the Unfair Commercial Practices Law, which prohibit misleading practices across all media. Advertising of financial products by unauthorised entities is prohibited under Law No. 78/2021 of November 24.
Advertising must generally be provided in Portuguese. Direct electronic marketing of financial products is subject to prior consent and must comply with the EU General Data Protection Regulation (GDPR) and Portuguese e-privacy rules.
In Portugal, the regulatory framework applicable to VASPs and CASPs has evolved significantly with the entry into force of the MiCA Regulation. Prior to MiCA, VASPs were subject to a registration regime with the Bank of Portugal under the anti-money laundering and counter-terrorist financing (AML/CFT) framework set out in Law No. 83/2017 of 18 August. This regime applied to entities with a local presence providing exchange, transfer and custody services in relation to cryptoassets not classified as financial instruments, with supervision limited to AML/CFT purposes.
MiCA introduces a harmonised EU-wide framework applicable to CASPs, complemented by Regulation (EU) No. 2023/1113 on information accompanying transfers of funds and certain cryptoassets (the “Transfer of Funds Regulation”), which introduces the “travel rule” and enhances transaction traceability. Although MiCA does not define ownership or transfer finality, it establishes comprehensive organisational, governance, security and transparency requirements.
Custody is broadly defined in Article 3(1)(17) of the MiCA Regulation as the safekeeping or control of cryptoassets or the means of access to them, including private cryptographic keys. Entities providing custody services must obtain authorisation as CASPs and comply with MiCA’s governance and risk-management requirements.
MiCA does not impose specific technical solutions but requires CASPs to implement robust internal governance arrangements, effective internal controls and appropriate technical and organisational measures to address operational and security risks (Articles 70 and 73, MiCA Regulation), ensure business continuity, and maintain adequate financial resources and, where applicable, professional indemnity insurance.
Pursuant to Article 72 of MiCA, CASPs must safeguard clients’ cryptoassets and ensure strict segregation of client assets from their own assets, maintain accurate records, and protect client assets from creditor claims, including in insolvency. CASPs providing custody services must also comply with conduct-of-business, transparency, reporting and complaints-handling requirements, and cooperate with the competent authorities (the Bank of Portugal or the CMVM, depending on the services provided).
Virtual asset activities in Portugal are subject to the AML/CFT framework established by Law No. 83/2017 of 18 August, as amended. Under this law, VASPs are required to register with the Bank of Portugal before commencing their activities and are treated as obliged entities for AML/CFT purposes.
Registered VASPs must comply with the AML/CFT obligations set out in Law No. 83/2017, as supplemented by sector-specific regulations issued by the Bank of Portugal, including Notice No. 3/2021 and Notice No. 1/2023. These obligations include the appointment of an independent AML/CFT compliance officer and a member of senior management responsible for AML/CFT matters, the implementation of regular staff training, the application of Know-Your-Customer (KYC) and Know-Your-Transaction (KYT) procedures, and the monitoring, suspension and reporting of suspicious transactions to the Bank of Portugal and the Financial Intelligence Unit (Unidade de Informação Financeira (UIF)).
In parallel, the MiCA Regulation reinforces AML/CFT expectations for CASPs, requiring robust customer due diligence, transaction monitoring and enhanced checks in higher-risk situations. Service providers must be able to refuse or terminate relationships where compliance cannot be ensured. Certain customer identification tasks may be outsourced, but overall responsibility remains with the provider.
VASPs and CASPs providing cryptoasset transfer services are also subject to the Transfer of Funds Regulation, which introduces the “travel rule” and requires the collection and transmission of information on the originator and beneficiary of cryptoasset transfers. These obligations apply to both MiCA-authorised CASPs and VASPs operating under the existing national AML/CFT framework.
Finally, under Law No. 83/2017, suspicious cryptoasset transactions or activities must be reported promptly, regardless of value or completion, to the Bank of Portugal and the UIF through the designated reporting channels.
Under Portuguese law, ownership of cryptoassets is not expressly defined by reference to control of a private cryptographic key. In practice, however, possession of the private key is generally regarded as evidence of ownership, as it enables effective control over the asset.
In practice, transfer finality is commonly understood as the point at which a transaction recorded on a distributed ledger becomes irreversible in accordance with the rules of the relevant network.
Although these concepts are not expressly defined in the MiCA Regulation, this Regulation imposes obligations on CASPs relating to transaction security, custody and transparency. This framework is further reinforced by the Transfer of Funds Regulation, which introduces the “travel rule” to ensure the traceability of cryptoasset transfers.
Under Portuguese law, decentralised autonomous organisations (DAOs) are not recognised as a distinct legal form and do not benefit from legal personality as such. Similarly, MiCA does not establish a specific regime for DAOs and expressly excludes cryptoasset services provided in a fully decentralised manner, where no identifiable issuer or service provider can be identified (Recital 22, MiCA).
From a functional perspective, a DAO may be described as an organisational structure implemented through one or more smart contracts deployed on a blockchain, enabling members (typically referred to as tokenholders) to collectively manage and allocate shared resources. Decision-making is generally automated and decentralised, with governance mechanisms embedded in code. Participation in a DAO is usually linked to the ownership of governance or utility tokens, which may be acquired through purchase or granted as a reward, resulting in a limited distinction between ownership and control.
DAOs differ fundamentally from traditional legal entities and business associations recognised under Portuguese law. In particular:
- governance is not exercised by directors or managers, but by tokenholders through decentralised voting or consensus mechanisms implemented via smart contracts;
- the relationships between participants are primarily governed by code-based rules rather than by formal constitutional documents or statutory provisions;
- funding is typically raised through the issuance or allocation of tokens, rather than through conventional equity or debt instruments; and
- DAOs are generally designed to operate on a cross-border basis, which impairs the easy determination of applicable jurisdiction.
In the absence of specific legislative guidance, Portuguese scholars have suggested that DAOs could, by analogy on a case-by-case basis, be assessed under the rules applicable to civil law partnerships, which also apply to unincorporated companies prior to formal incorporation, and are not limited liability entities. This approach is generally viewed as an interim solution, pending legislative clarification as to whether a bespoke legal regime for DAOs should be introduced or whether existing legal forms can adequately accommodate decentralised organisational models.
If DAO structures were to be characterised as civil law partnerships, the practical implications would be significant. In particular, the DAO would not have legal personality, and its members could be exposed to joint and several liability, on a subsidiary basis, for the obligations and liabilities incurred in the course of the DAO’s activities, including tax liabilities.
Portugal does not provide for a bespoke insolvency regime applicable to cryptoassets or CASPs. Accordingly, in the event of insolvency or bankruptcy, cryptoassets are dealt with under the general insolvency framework, primarily the Portuguese Insolvency and Corporate Recovery Code (Código da Insolvência e da Recuperação de Empresas (CIRE)), together with the relevant principles of civil law and applicable EU legislation.
The application of traditional insolvency rules to blockchain-based assets raises a number of practical and legal challenges. In particular, the decentralised and, in many cases, immutable nature of the DLT may make it difficult for insolvency administrators to identify, seize and effectively control cryptoassets recorded on a blockchain, as well as to transfer such assets into the insolvency estate for the benefit of creditors.
In addition, certain insolvency concepts established under Portuguese law are not easily reconciled with blockchain transactions. This includes, for example, the avoidance of transactions carried out by the debtor shortly prior to the opening of insolvency proceedings, which may be technically complex to unwind where transactions are executed on decentralised networks and recorded on immutable ledgers.
Finally, the inherently cross-border character of many cryptoasset transactions may further complicate insolvency proceedings. Issues may arise in relation to the determination of the competent jurisdiction, the recognition of foreign insolvency proceedings and the enforcement of foreign insolvency-related judgments, particularly where assets, counterparties and infrastructure are located across multiple jurisdictions.
Portuguese law does not specifically regulate smart contracts, and there is no binding case law on their enforceability. Their legal effect is therefore assessed under general contract law.
Smart contracts may be legally binding where the general requirements for contract formation are met, including legal capacity, lawful object and mutual consent. As Portuguese law imposes limited formalities, contracts concluded electronically — including through smart contracts — are generally admissible, provided the parties’ intention to be bound is clear. Certain transactions, however, remain subject to mandatory formal requirements that cannot be satisfied by smart contracts alone, notably transfers of real estate.
Even where a smart contract does not qualify as a legally binding contract in itself, it may still be legally relevant as a technical mechanism for the automated performance or execution of contractual obligations arising from an underlying agreement. In such cases, the smart contract functions as an instrument of performance rather than as the legal source of the obligations.
The use of smart contracts also raises several unresolved legal issues under Portuguese law, including the interpretation of code-based contractual terms, the allocation of liability in the event of coding errors or technical vulnerabilities, the treatment of mistakes or defects in consent arising from automated execution, and the determination of the applicable law and jurisdiction in decentralised or cross-border blockchain environments.
In Portugal, victims of crypto fraud have access to criminal and civil remedies. The primary course of action is to file a criminal complaint with the Portuguese Department of Investigation and Criminal Action (DIAP), which may lead to an investigation under the Portuguese Criminal Code for offences such as fraud, computer-related crime, breach of trust or money laundering and terrorism financing. Criminal proceedings allow authorities to seek seizure and freezing of cryptoassets, including wallets or exchange accounts, subject to judicial authorisation and, where necessary, international cooperation mechanisms.
Victims may also seek compensation through civil proceedings, either by joining the criminal case as a civil claimant or by initiating a separate civil action based on tort, unjust enrichment or contractual liability. In certain circumstances, claims may extend to intermediaries or service providers, particularly where failures in compliance or due diligence can be established. Interim measures may be available to prevent dissipation of assets.
In addition, victims may report crypto fraud to regulatory and supervisory authorities such as the Bank of Portugal or the CMVM, particularly in cases involving unauthorised or misleading crypto-related activities. While these authorities do not grant compensation, their involvement may support enforcement actions and facilitate coordination with criminal investigations.
Despite the availability of criminal and civil remedies in Portugal, recovering assets in crypto fraud cases remains challenging due to the pseudonymous and cross-border nature of transactions, difficulties in tracing assets, and the frequent use of self-hosted wallets. Enforcement often depends on international cooperation, which can be slow, and on adapting traditional legal concepts to novel technologies, leading to evidentiary and procedural uncertainty.
For individuals, the tax treatment of cryptoassets depends on the nature of the income and the holding period.
Short term capital gains arising from the disposal of cryptoassets not qualifying as securities are taxable. The taxable gain corresponds to the difference between acquisition and disposal value, determined under the first-in, first-out (FIFO) method, with documented acquisition and disposal costs being deductible. Capital gains are generally taxed at a flat rate of 28% (35% if connected to blacklisted jurisdictions), with an option to aggregate and apply progressive rates. Capital gains (if not connected to blacklisted jurisdictions) from the disposal of cryptoassets held for 365 days or more are not subject to personal income tax (PIT). Taxation is generally deferred until conversion into fiat currency. Transfers between wallets held by the same taxpayer do not trigger taxation.
Crypto-to-crypto exchanges constitute a tax relevant event but do not trigger immediate taxation. The acquisition value of the cryptoassets received is determined by reference to the market value of the assets exchanged.
Income derived from mining, issuance, or transaction validation is classified as business or professional income and taxed under either the simplified regime or the organised accounts regime, liable to progressive marginal rates ranging from 12.5% up to 48%. Remuneration from staking or similar activities qualifies as capital income and is taxed upon disposal where received in cryptoassets.
Individual taxpayers must report taxable cryptoasset income and gains in their annual tax returns.
Portugal has no specific corporate income tax (CIT) regime for cryptoassets. Corporate taxpayers are taxed under the ordinary CIT rules, based on accounting profit. Gains and income from cryptoassets are, in principle, fully taxable, irrespective of holding period. The tax treatment depends on the accounting classification of the cryptoassets (e.g. inventory, intangible assets, or other assets), in accordance with Portuguese accounting standards. Corporate profits are subject to the standard CIT rate of 19% for fiscal year 2026.
In line with EU law and the case law of the Court of Justice of the European Union, transactions involving the exchange of cryptoassets for fiat currency, and vice versa, are generally exempt from VAT. Where cryptoassets are used as payment for goods or services, VAT applies to the underlying good/service by general rules.
The use of blockchain and other DLTs by cryptoasset businesses raises a number of legal challenges, particularly given that existing legal frameworks were not originally designed to accommodate the technical and operational characteristics of decentralised systems. One of the areas where these challenges are most acute is data protection and cybersecurity. One of the main fields where such challenges arise is in data protection.
European data protection rules applicable in Portugal, notably the GDPR and domestic Law No. 58/2019 of 8 August, were conceived for data processing environments based on centralised control by identifiable entities. By contrast, blockchain operates through decentralised architectures involving multiple participants, which complicates the allocation of legal roles and responsibilities, particularly in determining who qualifies as a data controller or processor. Moreover, core features of blockchain technology (such as immutability, transparency and distributed storage) may conflict with fundamental GDPR principles, including purpose limitation, data minimisation, storage limitation and, in particular, the right to erasure (“right to be forgotten”).
To address these challenges, the European Data Protection Board adopted Guidelines 02/2025 on the processing of personal data through blockchain technologies. These guidelines provide a structured compliance framework, emphasising the need to assess the necessity of using blockchain for the intended purposes. They generally discourage the storage of personal data on-chain and recommend the use of off-chain storage combined with privacy-enhancing techniques, such as encryption or hashing, while clarifying that such techniques do not exempt controllers from GDPR obligations, particularly with respect to data subject rights.
In parallel, cryptoasset and fintech participants are subject to cybersecurity and operational resilience requirements under Law No. 46/2018 of 13 August, which transposed Directive (EU) 2016/1148 (the “NIS Directive”) into Portuguese law. These rules require the implementation of appropriate technical and organisational security measures, including encryption, access controls, incident response, disaster recovery and business continuity planning. In addition, Regulation (EU) 2022/2554 (the “Digital Operational Resilience Act” (DORA)) may apply to certain financial entities, imposing further ICT risk management and resilience obligations.
Currently, there is no specific regulatory framework exclusively governing staking activities in Portugal. Depending on their legal and economic characteristics, staking arrangements may nevertheless fall within existing regulatory regimes, including financial, payment or investment-related frameworks, where the structure of the activity or the nature of the services provided so requires.
Similarly, there is no dedicated legal regime applicable to DeFi. Notwithstanding the decentralised nature of certain platforms, regulatory obligations may still arise depending on the specific functions performed, such as custody, exchange, lending or intermediation. DeFi has been identified as an area of increasing regulatory concern at both European and national level. In this context, the Bank of Portugal has published analytical reports highlighting potential financial stability risks and structural vulnerabilities associated with DeFi, while also acknowledging its potential benefits and innovation-driven opportunities.
The regulatory approach to DeFi remains under development and subject to ongoing policy debate, with no definitive framework yet adopted. Current regulatory efforts are primarily focused on consolidating the general cryptoasset regulatory framework and strengthening AML/CFT safeguards. In this regard, the MiCA Regulation expressly excludes from its scope cryptoasset services that are provided in a fully decentralised manner, without any intermediary, although the practical determination of what constitutes “fully decentralised” remains legally complex and fact dependent.
In the absence of specific DeFi or smart contract legislation, general legal principles continue to apply, including civil and, where relevant, banking and financial laws. Smart contracts may be recognised as valid and enforceable contracts under Portuguese civil law, provided that general contractual requirements are met. Consequently, fully decentralised DeFi platforms and DAOs remain outside the current regulatory perimeter, to the extent that effective operational control is genuinely decentralised and no identifiable intermediary or issuer can be established.
As of this date, no new legislative developments have been identified within the Portuguese legal framework in relation to cryptoassets. The developments currently underway are predominantly of a regulatory and prudential nature, based on a case-by-case assessment by the competent authorities, particularly with regard to the definition of technical criteria and the legal framework applicable to the promotion of financial instruments and cryptoassets by digital influencers (“finfluencers”), with a view to establishing a regulatory framework capable of enabling the supervision of social media platforms and the advertising content disseminated therein.
Furthermore, considering that Law No. 69/2025 of 22 December implemented the transitional adaptation period provided for under the MiCA Regulation, it is foreseeable that, during the second half of the year, there will be an increase in regulatory activity by the national supervisory authorities, namely through the issuance of notices, guidelines and regulations by the Bank of Portugal and the CMVM.