Security and resilience obligations attaching to digital assets, and the awkward places where distributed ledgers meet data protection law.

What we track

MiCA

EU. Authorisation, custody and operational requirements for crypto-asset service providers.

DORA for crypto-asset firms

EU. Where resilience obligations apply to firms authorised under MiCA, on the same terms as banks.

Blockchain and GDPR

EU. Data protection authority guidance on applying privacy law to immutable records.

Travel rule

International. Information requirements on transfers, and how they are being supervised in practice.

Custody and key management

All jurisdictions. Supervisory expectations for holding assets on behalf of clients.

Tokenised finance

EU, UK and Singapore. Where traditional institutions are bringing this exposure inside the regulated perimeter.

Who is in scope

Crypto-asset service providers, through MiCA authorisation and everything that follows it. Custody, exchange, transfer, advice and portfolio management each have their own conditions.

Traditional financial institutions are arriving through tokenisation and settlement projects, and they bring DORA and their existing supervisory relationship with them. Any organisation holding client assets in this form meets custody expectations regardless of how it describes itself.

Where the deadlines fall

Authorisation windows and transitional regimes, which vary by member state and which have already closed in several. Once authorised, the dates become DORA dates: register submissions, testing cycles and incident classification.

Where organisations get caught

Immutability against erasure. A ledger designed so that records cannot be changed sits badly with a legal right to have records corrected or deleted. Data protection authorities have now published a settled view, and architecture decided before that guidance may need revisiting.

Key management is the whole control set. Custody obligations reduce, in practice, to whether you can evidence who could move an asset and under what approval. That is an identity and access problem wearing a different label, and it is assessed with the seriousness of a banking control.

Dual regime. A firm authorised under MiCA is usually also in scope for DORA. Teams that planned for one and not the other find the resilience obligations heavier than the authorisation ones.

Questions worth asking now

  • Are we in scope under MiCA, and does that pull us into DORA as well?
  • Who can move an asset, under what approval, and can we prove it after the fact?
  • Does any personal data reach a ledger we cannot amend?
  • What is our key ceremony, and when was it last observed by someone independent?
  • If a key were compromised, what is the recovery path and has it been tested?
  • Which of our tokenisation projects assumed this was outside financial regulation?

Related domains

Operational resilience covers the DORA obligations that follow authorisation. Data security and privacy covers the immutability problem. Quantum security and PQC covers the cryptography underneath all of it.

All sixteen domains and how the Radar works.