Disclaimer: This chapter was last updated on 29 May 2024 and does not reflect any subsequent developments. The information provided is intended for general informational purposes and should not be construed as legal advice.

1. How is crypto regulated?

2. What are the steps taken by the regulator to adopt MiCAR? 

From 30 June 2024:

The Hungarian legislature has passed Act VII of 2024 on the market in crypto-assets, designating the Central Bank of Hungary (CBH) as the competent authority responsible for ensuring the compliance of crypto-asset service providers with MiCAR. The government and the governor of the CBH are expected to pass detailed rules in the near future.

The Hungarian Act adds new provisions to MiCAR:

  1. Knowledge and experience: natural persons acting on behalf of service providers ‘providing advice on crypto-assets’ must have the necessary knowledge and professional experience to provide such advice, the detailed rules of which will be laid down in an implementing government decree that has not been adopted yet. This new additional provision was the subject of much debate before the law was passed, and the government has decided to set out the details in a separate government decree rather than stipulating detailed rules in the Act.
  2. Complaint handling: the Act contains detailed provisions on the handling of complaints, which may be made in person, by telephone or in writing, and by post or electronic mail. For complaints made by telephone, the provider must record the phone conversation and keep the recording for five years. Complaints must be kept for five years. The language used when handling complaints must be Hungarian (with exceptions).
  3. Consumer protection: the provider must appoint a contact person for consumer protection issues.

DORA Regulation and NIS2 directive for crypto-asset providers

In the Hungarian Act, based on Article 19 of the DORA regulation, the NIS2 directive is applied to crypto-asset providers and issuers of asset-referenced tokens under MiCAR and has stipulated that these entities:

  • must report the significant ICT-related incidents to the NBH and the Hungarian CSIRT under the NIS2 directive; and
  • if they report significant cyber threats to the NBH on a voluntary basis, they must report it in parallel to the Hungarian CSIRT under the NIS2 directive.

Although this is allowed by the DORA, this represents a significant change to the DORA regulation and makes the reporting obligations of crypto-asset service providers more difficult.

3. Are the following activities regulated or unregulated in your jurisdiction? ― Direct sales of tokens by issuers— Exchange (buy/sell) ― Custody (hold) ― Borrowing/lending ― Yield/staking services —Staking on proof of stake consensus mechanisms (please indicate if NFTs are treated differently from fungible cryptoassets for each activity)

4. Can offshore business provide services to local customers on either active solicitation or reverse solicitation basis? 

5. How long would establishing a cryptoasset business/obtaining a license in your jurisdiction take?

6. What would be the approximate overall cost of obtaining a licence?

7. What is the probability (%) of success in obtaining a licence?

8. What other limitations are there in your jurisdiction when looking to set up a cryptoasset business? E.g., Compliance requirements and physical presence