← Malta

Chapter 647

In short

This law establishes a framework for crypto-assets, including asset-referenced tokens, e-money tokens, and other crypto-assets, and sets requirements for crypto-asset service providers. Its main goal is to implement the relevant provisions of the MiCA Regulation (EU) 2023/1114.

What it regulates

Who it concerns

Key points

Legal text
Obsah (12)Article 4Article 3Article 2Article 47Article 34Article 21Article 23Article 48Article 61Article 6Article 60Article 63

ACT AN ACT to provide for the establishment

a framework for the requirements applicable to

fers to the public and admission to trading on a trading platform

asset-referenced tokens, e-money tokens, other cryptoassets, and the requirements applicable to crypto-asset service providers. 30th June, 2024 ACT XXXVI

2024, as amended by Act XI

2025. ARRANGEMENT

THE ACT Articles Part I Preliminary 1-4 Part II Crypto-assets other than Asset-Referenced Tokens or E-Money Tokens 5-8 Part III Asset-Referenced Tokens 9 - 21 Part IV E-Money Tokens 22 - 25 Part V Crypto-Asset Service Providers 26 - 34 Part VI Prevention and Prohibition

Market Abuse 35 - 36 Part VII Regulatory and Investigative Powers 37 - 48 Part VIII Appeals,

fences and Confidentiality 49 - 53 Part IX Cooperation with Other Authorities 54 - 57 Part X Transitory Provisions Part XI Amendments to the Banking Act Part XII Amendments to the Virtual Financial Assets Act 59 - 61 62-64 PART I PRELIMINARY 1.

(1)Assets Act. The short title

this Act is the Markets in Crypto-

(2)The principal scope

this Act is to implement the relevant provisions

Regulation (EU) 2023/1114

the European Parliament and

the Council

31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No. 1093/2010 and (EU) No. 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937, and it shall be interpreted and applied accordingly. Short title and scope. Interpretation. MARKETS IN CRYPTO-ASSETS 2.

(1)In this Act, unless the context otherwise requires: "AIFs" shall have the same meaning as that assigned to it in paragraph (a)

Article 4

(1)

Directive 2011/61/EU;       "alternative investment fund manager" shall have the same meaning as that assigned to it in point

(48)

Article 3

(1)

the MiCA Regulation and shall include investment services licence holders licensed in accordance with the Investment Services Act to carry out the investment service referred to in item 4

the First Schedule

the said Act in relation to AIFs; "asset-referenced token" shall have the same meaning as that assigned to it in point

(6)

Article 3

(1)

the MiCA Regulation; "binding legal instruments" means any directly applicable measures, including but not limited to, any implementing technical standards, regulatory technical standards or similar measures, issued in accordance with European Union legislation;  "Central Bank" means the Central Bank

Malta as defined in the Central Bank

Malta Act; "central securities depository" shall have the same meaning as that assigned to it in point

(1)

Article 2

(1)

Regulation (EU) No. 909/2014;   "competent authority" means the Malta Financial Services Authority established by the Malta Financial Services Authority Act; "credit institution" shall have the same meaning as that assigned to it in point

(28)

Article 3

(1)

the MiCA Regulation; "crypto-asset" shall have the same meaning as that assigned to it in point

(5)

Article 3

(1)

the MiCA Regulation; "crypto-asset service" shall have the same meaning as that assigned to it in point

(16)

Article 3

(1)

the MiCA Regulation; "crypto-asset service provider" shall have the same meaning as that assigned to it in point

(15)

Article 3

(1)

the MiCA Regulation; "Directive 2009/65/EC" means Directive 2009/65/EC

the European Parliament and

the Council

13 July 2009 on MARKETS IN CRYPTO-ASSETS the coordination

laws, regulations and administrative provisions relating to undertakings for collective investment in transferable securities (UCITS), as may be amended from time to time, and includes any binding legal instruments, guidelines and other measures that have been or may be issued thereunder; "Directive 2011/61/EU" means Directive 2011/61/EU

the European Parliament and

the Council

8 June 2011 on Alternative Investment Fund Managers and amending Directives 2003/41/EC and 2009/65/EC and Regulations (EC) No. 1060/2009 and (EU) No. 1095/2010, as may be amended from time to time, and includes any binding legal instruments, guidelines and other measures that have been or may be issued thereunder; "Directive 2013/34/EU" means Directive 2013/34/EU

the European Parliament and

the Council

26 June 2013 on the annual financial statements, consolidated financial statements and related reports

certain types

undertakings, amending Directive 2006/43/EC

the European Parliament and

the Council and repealing Council Directives 78/660/ EEC and 83/349/EEC, as may be amended from time to time, and includes any binding legal instruments, guidelines and other measures that have been or may be issued thereunder; "Directive 2014/65/EU" means Directive 2014/65/EU

the European Parliament and

the Council

15 May 2014 on markets in financial instruments and amending Directive 2002/92/EC and Directive 2011/61/EU, as may be amended from time to time, and includes any binding legal instruments, guidelines and other measures that have been or may be issued thereunder; "Directive (EU) 2015/849" means Directive (EU) 2015/ 849

the European Parliament and

the Council

20 May 2015 on the prevention

the use

the financial system for the purposes

money laundering or terrorist financing, amending Regulation (EU) No. 648/2012

the European Parliament and

the Council, and repealing Directive 2005/ 60/EC

the European Parliament and

the Council and Commission Directive 2006/70/EC, as may be amended from time to time, and includes any implementing measures, implementing technical standards, regulatory technical standards, guidelines and similar measures that have been or may be issued thereunder; "Directive (EU) 2015/2366" means Directive (EU) 2015/2366

the European Parliament and

the Council

25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/ EU and Regulation (EU) No. 1093/2010, and repealing MARKETS IN CRYPTO-ASSETS Directive 2007/64/EC, as may be amended from time to time, and includes any binding legal instruments, guidelines and other measures that have been or may be issued thereunder; "EBA" means the European Banking Authority established by Regulation (EU) No. 1093/2010; "European Central Bank" or "ECB" means the European Central Bank established by the Treaty on the Functioning

the European Union;       "electronic money institution" shall have the same meaning as that assigned to it in point

(43)

Article 3

(1)

the MiCA Regulation and shall include financial institutions authorised to issue electronic money in accordance with the Financial Institutions Act; "electronic money token" or "e-money token" shall have the same meaning as that assigned to it in point

(7)

Article 3

(1)

the MiCA Regulation; "ESMA" means the European Securities and Markets Authority established by Regulation (EU) No. 1095/2010; "European regulatory authority" means a body or bodies designated by a Member State other than Malta in accordance with Article 93

(1)

the MiCA Regulation for the purpose

carrying out the functions and duties provided for under the said Regulation;    "Financial Intelligence Analysis Unit" means the Financial Intelligence Analysis Unit as established by article 15

the Prevention

Money Laundering Act; "GDPR" means Regulation (EU) 2016/679

the European Parliament and

the Council

27 April 2016 on the protection

natural persons with regard to the processing

personal data and on the free movement

such data, and repealing Directive 95/46/EC (General Data Protection Regulation), as may be amended from time to time, and includes any binding legal instruments, guidelines and other measures that have been, or may be issued thereunder; "home Member State" shall have the same meaning as that assigned to it in point

(33)

Article 3

(1)

the MiCA Regulation; "host Member State" shall have the same meaning as that assigned to it in point

(34)

Article 3

(1)

the MiCA Regulation; MARKETS IN CRYPTO-ASSETS "investment firm" shall have the same meaning as that assigned to it in point

(29)

Article 3

(1)

the MiCA Regulation and shall include investment services licence holders licensed in accordance with the Investment Services Act to carry out any

the investment services referred to in items 1 to 4, 6 to 9 and 11

the First Schedule

the said Act in relation to an instrument as defined in the Investment Services Act;      "issuer" shall have the same meaning as that assigned to it in point

(10)

Article 3

(1)

the MiCA Regulation; "market operator" shall have the same meaning as that assigned to it in point

(18)

Article 4

(1)

Directive 2014/ 65/EU and shall include investment services licence holders licensed in accordance with the Investment Services Act to carry out the investment services referred to in item 9

the First Schedule

the said Act in relation to an instrument as defined in the Investment Services Act; "MiCA Regulation" means Regulation (EU) 2023/1114

the European Parliament and

the Council

31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No. 1093/2010 and (EU) No. 1095/2010 and Directives 2013/ 36/EU and (EU) 2019/1937, as may be amended from time to time, and includes any binding legal instruments, guidelines and other measures that have been or may be issued thereunder; "Minister" means the Minister responsible for the regulation

financial services; "

feror" shall have the same meaning as that assigned to it in point

(13)

Article 3

(1)

the MiCA Regulation; "qualified investor" shall have the same meaning as that assigned to it in point

(30)

Article 3

(1)

the MiCA Regulation; "Regulation (EU) No. 1093/2010" means Regulation (EU) No. 1093/2010

the European Parliament and

the Council

24 November 2010 establishing a European Supervisory Authority (European Banking Authority), amending Decision No. 716/2009/EC and repealing Commission Decision 2009/78/EC, as may be amended from time to time, and includes any binding legal instruments, guidelines and other measures that have been or may be issued thereunder; "Regulation (EU) No. 1095/2010" means Regulation (EU) No. 1095/2010

the European Parliament and

the Council

24 November 2010 establishing a European      MARKETS IN CRYPTO-ASSETS Supervisory Authority (European Securities and Markets Authority), amending Decision No. 716/2009/EC and repealing Commission Decision 2009/77/EC, as may be amended from time to time, and includes any binding legal instruments, guidelines and other measures that have been or may be issued thereunder; "Regulation (EU) No. 909/2014" means Regulation (EU) No. 909/2014

the European Parliament and

the Council

23 July 2014 on improving securities settlement in the European Union and on central securities depositories and amending Directives 98/26/EC and 2014/65/EU and Regulation (EU) No. 236/2012, as may be amended from time to time, and includes any binding legal instruments, guidelines and other measures that have been or may be issued thereunder; "Rules" refers to Rules which may be issued by the competent authority in accordance with this Act;  "UCITS" shall have the same meaning as that assigned to it in article 2

(1)

the Investment Services Act;      "UCITS management company" shall have the same meaning as that assigned to it in point

(47)

Article 3

(1)

the MiCA Regulation and shall include investment services licence holders licensed in accordance with the Investment Services Act to carry out the investment service referred to in item 4

the First Schedule

the said Act in relation to UCITS in the form

common funds or

investment companies.

(2)Unless the context otherwise requires, the words used in this Act which are not defined herein shall have the same meaning as assigned to them in the MiCA Regulation.
(3)In this Act, and in any regulations made thereunder, where there are any conflicts between the English and the Maltese texts, the English text shall prevail.
(4)In the event that there is any conflict between this Act and the provisions

the MiCA Regulation, the provisions

the MiCA Regulation shall prevail. Applicability. 3.

(1)The provisions

this Act and any regulations made, or Rules issued thereunder shall not apply to: (a) persons who provide crypto-asset services exclusively for their parent companies, for their own subsidiaries or for other subsidiaries

their parent companies; (b) a liquidator or an administrator acting in the course

an insolvency procedure, except for the purposes

Article 47

the MiCA Regulation and article 21; MARKETS IN CRYPTO-ASSETS (c) the ECB, central banks

the Member States when acting in their capacity as monetary authorities, or other public authorities

the Member States; (

  1. d)the subsidiaries; European Investment Bank and its (
  2. e)the European Financial Stability Facility and the European Stability Mechanism; and (
  3. f)public international organisations.

(2)The provisions

this Act and any regulations made, or Rules issued thereunder shall not apply to crypto-assets that are unique and not fungible with other crypto-assets.

(3)The provisions

this Act and any regulations made, or Rules issued thereunder shall not apply to crypto-assets that qualify as one or more

the following: (

  1. a)financial instruments; (
  2. b)deposits, including structured deposits; (
  3. c)funds, except if they qualify as e-money tokens; (
  4. d)securitisation positions in the context

a securitisation as defined in Article 2, point

(1),

Regulation (EU) 2017/2402; (e) non-life or life insurance products falling within the classes

insurance listed in Annexes I and II to Directive 2009/138/EC

the European Parliament and

the Council

25 November 2009 on the taking-up and pursuit

the business

Insurance and Reinsurance (Solvency II) or reinsurance and retrocession contracts referred to in such Directive; (f) pension products that under national law are recognised as having the primary purpose

providing the investor with an income in retirement and that entitle the investor to certain benefits; (g)

ficially recognised occupational pension schemes falling within the scope

Directive (EU) 2016/2341

the European Parliament and

the Council

14 December 2016 on the activities and supervision

institutions for occupational retirement provision (IORPs) or Directive 2009/ 138/EC

the European Parliament and

the Council

25 November 2009 on the taking-up and pursuit

the business

Insurance and Reinsurance; (

  1. h)individual pension products for which a financial MARKETS IN CRYPTO-ASSETS contribution from the employer is required by national law and where the employer or the employee has no choice as to the pension product or provider; (
  2. i)a pan-European Personal Pension Product as defined in point 2

Article 2

Regulation (EU) 2019/1238

the European Parliament and

the Council

20 June 2019 on a pan-European Personal Pension Product (PEPP); and (j) social security schemes covered by Regulation (EC) No. 883/2004

the European Parliament and

the Council

29 April 2004 on the coordination

social security systems and Regulation (EC) No. 987/2009

the European Parliament and

the Council

16 September 2009 laying down the procedure for implementing Regulation (EC) No. 883/2004 on the coordination

social security systems. The competent authority. 4.

(1)The competent authority shall carry out its functions under this Act and in particular shall ensure compliance with the provisions

the MiCA Regulation, this Act and any regulations made, and Rules issued thereunder.

(2)The competent authority shall also carry out the functions and duties as competent authority for all purposes

the MiCA Regulation. PART II CRYPTO-ASSETS OTHER THAN ASSET-REFERENCED TOKENS OR E-MONEY TOKENS Approval

crypto-asset white papers and market communications is not required. 5. The competent authority shall not require the prior approval

crypto-asset white papers drawn up by persons intending to make an

fer to the public or seeking admission to trading

crypto-assets other than asset-referenced tokens or e-money tokens in the European Union, nor

any marketing communications relating thereto, before their respective publication. Notification

the crypto-asset white paper. 6.

(1)The provisions

this article shall only apply where Malta is the home Member State.

(2)

ferors, persons seeking admission to trading, or operators

trading platforms for crypto-assets other than asset-referenced tokens or e-money tokens shall notify their crypto-asset white paper to the competent authority.

(3)

ferors and persons seeking admission to trading

cryptoassets other than asset-referenced tokens or e-money tokens shall, together with the notification referred to in sub-article

(2), provide the competent authority with a list

the host Member States, if any, where they intend to

fer their crypto-assets to the public, or intend to seek admission to trading and they shall inform the competent authority

the starting date

the intended

fer to the public or intended MARKETS IN CRYPTO-ASSETS admission to trading and

any change to that date: Provided that the competent authority shall notify the single point

contact

the host Member States

the intended

fer to the public or the intended admission to trading and communicate to that single point

contact the corresponding crypto-asset white paper within five

(5)working days

receipt

the list

host Member States referred to in this sub-article.

(4)The notification

the crypto-asset white paper referred to in sub-article

(2)shall be accompanied by an explanation

why the crypto-asset described in the crypto-asset white paper should not be considered to be: (a) a crypto-asset excluded from the scope

the MiCA Regulation, this Act and any regulations made, and Rules issued thereunder pursuant to Article 2

(4)

the MiCA Regulation and article 3

(3)

this Act; (

  1. b)an e-money token; or (
  2. c)an asset-referenced token.

(5)The notification and explanation referred to in sub-articles
(2)and
(4)respectively shall be notified to the competent authority at least twenty
(20)working days before the date

publication

the crypto-asset white paper. 7.

(1)Where Malta is the home Member State or the host Member State, marketing communications shall upon request, be notified to the competent authority when addressing prospective holders

crypto-assets other than asset-referenced tokens or e-money tokens in Malta. Marketing communications.

(2)When marketing communications are disseminated in Malta, the competent authority shall have the power to assess their compliance with Article 7
(1)

the MiCA Regulation in respect

those marketing communications. 8.

(1)The provisions

this article shall only apply where Malta is the home Member State.

(2)Where for each twelve
(12)month period starting from the beginning

the initial

fer to the public, the total consideration

an

fer to the public

a crypto-asset, other than an asset-referenced token or e-money token, in the European Union exceeds one million euro (€1,000,000), the

feror shall send a notification to the competent authority containing a description

the

fer and explaining why the

fer is exempt from the provisions

Title II

the MiCA Regulation and Part II

this Act pursuant to paragraph (d)

Article 4

(3)

the MiCA Regulation: Notification

exemption. MARKETS IN CRYPTO-ASSETS Provided that for the purposes

this sub-article, a "cryptoasset, other than an asset-referenced token or e-money token" means a crypto-asset, other than an asset-referenced token or e-money token, which grants its holder the right to use it only in exchange for goods and services in a limited network

merchants with contractual arrangements with the

feror.

(3)Based on the notification referred to in sub-article
(2), the competent authority shall take a duly justified decision where it considers that the activity does not qualify for an exemption as a limited network in a c c o r d a n c e w i t h Article 4
(3)(d)

the MiCA Regulation, and shall inform the

feror accordingly. PART III ASSET-REFRENCED TOKENS Authorisation to

fer assetreferenced tokens to the public or seek their admission to trading. 9.

(1)A person shall not make an

fer to the public, or seek the admission to trading

an asset-referenced token in Malta, unless that person is the issuer

that asset-referenced token and is: (a) a legal person or other undertaking that is established in the European Union and has been authorised in accordance with Article 21

the MiCA Regulation by the competent authority

its home Member State; or (b) a credit institution that complies with Article 17

the MiCA Regulation: Provided that for the purposes

paragraph (a), other undertakings may issue asset-referenced tokens only if their legal form ensures a level

protection for third parties’ interests equivalent to that afforded by legal persons and if they are subject to equivalent prudential supervision appropriate to their legal form.

(2)Notwithstanding the provisions

sub-article

(1), upon the written consent

the issuer

an asset-referenced token, other persons may

fer to the public or seek the admission to trading

that asset-referenced token: Provided that the persons referred to in this sub-article shall comply with Articles 27, 29 and 40

the MiCA Regulation and article 16.

(3)where: The provisions

sub-articles

(1)and
(2)shall not apply (a) over a period

twelve

(12)months, calculated at the end

each calendar day, the average outstanding value

the asset-referenced token issued by an issuer never exceeds five million euro (€5,000,000), or the equivalent amount in another

ficial currency, and the issuer is not linked MARKETS IN CRYPTO-ASSETS to a network

other exempt issuers; or (b) the

fer to the public

the asset-referenced token is addressed solely to qualified investors and the assetreferenced token can only be held by such qualified investors: Provided that where this sub-article applies, issuers

assetreferenced tokens shall draw up a crypto-asset white paper as provided for in Article 19

the MiCA Regulation and notify such cryptoasset white paper, and upon request, any marketing communications to the competent authority where Malta is the home Member State. 10.

(1)For the purposes

this article, "credit institution" means a credit institution which is licensed as such under the Banking Act.

(2)An asset-referenced token issued by a credit institution may be

fered to the public or admitted to trading if the credit institution: (a) draws up a crypto-asset white paper as referred to in Article 19

the MiCA Regulation for the asset-referenced token, submits such crypto-asset white paper for approval by the competent authority

its home Member State in accordance with the procedure set out in the regulatory technical standards adopted pursuant to Article 17

(8)

the MiCA Regulation, and has the crypto-asset white paper approved by the competent authority; and (b) notifies the competent authority, at least ninety

(90)working days before issuing the asset-referenced token for the first time, by providing it with the following information: (i) a programme

operations, setting out the business model that the credit institution intends to follow; (ii) a legal opinion that the asset-referenced token does not qualify as either a crypto-asset excluded from the scope

the MiCA Regulation, this Act and any regulations made, and Rules issued thereunder pursuant to Article 2

(4)

the MiCA Regulation and article 3

(3)

this Act; (iii) a detailed description

the governance arrangements referred to in Article 34

(1)

the MiCA Regulation; (iv) the policies and procedures listed in the first sub-paragraph

Article 34

(5)

the MiCA Regulation; (v) a description

the contractual Requirements for credit institutions to

fer assetreferenced tokens to the public or seek their admission to trading.  MARKETS IN CRYPTO-ASSETS arrangements with third-party entities as referred to in the second sub- paragraph

Article 34

(5)

the MiCA Regulation; (vi) a description

the business continuity policy referred to in Article 34

(9)

the MiCA Regulation; (vii) a description

the internal control mechanisms and risk management procedures referred to in Article 34

(10)

the MiCA Regulation; and (viii) a description

the systems and procedures in place to safeguard the availability, authenticity, integrity and confidentiality

data referred to in Article 34

(11)

the MiCA Regulation.

(3)Notwithstanding the provisions

sub-article

(2), a credit institution that has previously notified the competent authority in accordance with sub-article
(2)(b), when issuing another assetreferenced token, shall not be required to submit any information that was previously submitted by it to the competent authority where such information would be identical: Provided that when submitting the information listed in subarticle
(2)(b), the credit institution shall expressly confirm that any information not resubmitted in accordance with this sub-article is still up-to-date.
(4)When receiving a notification as referred to in sub-article
(2)(b), the competent authority shall, within twenty
(20)working days

receipt

the information listed in the said sub-article, assess whether the information required under that paragraph has been provided.

(5)Where the competent authority concludes, following the assessment carried out in accordance with sub-article
(4), that a notification is not complete because some information is missing, it shall immediately inform the notifying credit institution thereof and set a deadline by which that credit institution is required to provide the missing information: Provided that the deadline for providing any missing information shall not exceed twenty
(20)working days from the date

the request and, until the expiry

such deadline, the period set out in sub-article

(2)(b) shall be suspended.
(6)Without prejudice to the provisions

sub-article

(5), any further request by the competent authority for completion or clarification

the information provided in terms

this article shall be at its discretion but shall not result in a suspension

the period set out MARKETS IN CRYPTO-ASSETS in sub-article

(2)(b).
(7)The credit institution shall not make an

fer to the public or seek the admission to trading

the asset-referenced token as long as the notification referred to in sub-article

(2)(b) is incomplete.
(8)The competent authority shall communicate to the ECB without delay the complete information received under sub-article
(2)and, where the credit institution is established in a Member State whose

ficial currency is not the euro or where an

ficial currency

a Member State that is not the euro is referenced by the assetreferenced token, also to the Central Bank.

(9)The ECB and, where applicable, the Central Bank shall within twenty
(20)working days

receipt

the complete information in accordance with sub-article

(8), issue an opinion on that information and transmit that opinion to the competent authority.
(10)The competent authority shall require the credit institution not to

fer to the public or seek the admission to trading

the assetreferenced token in cases where the ECB or, where applicable, the Central Bank, give a negative opinion on the grounds

a risk posed to the smooth operation

payment systems, monetary policy transmission or monetary sovereignty. 11.

(1)The provisions

this article shall only apply when Malta is the home Member State.

(2)Legal persons or other undertakings that intend to

fer to the public or seek the admission to trading

asset-referenced tokens shall submit their application for an authorisation as referred to in article 9 to the competent authority.

(3)Without prejudice to Article 18
(6)and
(7)

the MICA Regulation, the application referred to in sub-article

(2)shall contain all

the following information: (a) the address

the applicant; (b) the legal entity identifier

the applicant; (c) the articles

association

the applicant, where applicable; (d) a programme

operations, setting out the business model that the applicant intends to follow; (e) a legal opinion that the asset-referenced token does not qualify as either

the following: (i) a crypto-asset excluded from the scope

the MiCA Regulation, this Act and any regulations Application for authorisation. MARKETS IN CRYPTO-ASSETS made, and Rules issued thereunder pursuant to Article 2

(4)

the MiCA Regulation and article 3

(3)

this Act; or (

  1. ii)an e-money token; (
  2. f)a detailed description

the applicant’s governance arrangements as referred to in Article 34

(1)

the MiCA Regulation; (g) where cooperation arrangements with specific crypto-asset service providers exist, a description

their internal control mechanisms and procedures to ensure compliance with the obligations in relation to the prevention

money laundering and terrorist financing under Directive (EU) 2015/849; (h) the identity

the members

the management body

the applicant; (

  1. i)proof that the persons referred to in paragraph (
  2. h)are

sufficiently good repute and possess the appropriate knowledge, skills and experience to manage the applicant; (j) proof that any shareholder or member, whether direct or indirect, that has a qualifying holding in the applicant is

sufficiently good repute; (k) a crypto-asset white paper as referred to in Article 19

the MiCA Regulation; (l) the policies and procedures referred to in the first sub-paragraph

Article 34

(5)

the MiCA Regulation; (m) a description

the contractual arrangements with the third-party entities as referred to in the second subparagraph

Article 34

(5)

the MiCA Regulation; (n) a description

the applicant’s business continuity policy referred to in Article 34

(9)

the MiCA Regulation; (o) a description

the internal control mechanisms and risk management procedures referred to in Article 34

(10)

the MiCA Regulation; (p) a description

the systems and procedures in place to safeguard the availability, authenticity, integrity and confidentiality

data as referred to in Article 34

(11)

the MiCA Regulation; (q) a description

the applicant’s complaints- MARKETS IN CRYPTO-ASSETS handling procedures as referred to in Article 31

the MiCA Regulation; and (r) where applicable, a list

host Member States where the applicant intends to

fer the asset-referenced token to the public or intends to seek admission to trading

the asset- referenced token.

(4)For the purposes

sub-article

(3)(i) and (j), the applicant shall provide proof

all

the following: (a) for all members

the management body, the absence

a criminal record in respect

convictions or the absence

penalties imposed under the applicable commercial law, insolvency law and financial services law, or in relation to anti-money laundering and counter-terrorist financing, to fraud or to professional liability; (b) that the members

the management body

the applicant

the asset-referenced token collectively possess the appropriate knowledge, skills and experience to manage the issuer

the asset-referenced token and that such persons are required to commit sufficient time to perform their duties; and (c) for all shareholders and members, whether direct or indirect, that have qualifying holdings in the applicant, the absence

a criminal record in respect

convictions and the absence

penalties imposed under the applicable commercial law, insolvency law and financial services law, or in relation to anti-money laundering and counter-terrorist financing, to fraud or to professional liability.

(5)Notwithstanding the provisions

sub-article

(3), issuers that have already been authorised in respect

one

(1)asset-referenced token shall not be required to submit, for the purposes

authorisation in respect

another asset-referenced token, any information that was previously submitted by them to the competent authority where such information would be identical: Provided that when submitting the information listed in subarticle

(3), the issuer shall expressly confirm that any information not resubmitted is still up to date.
(6)The competent authority shall promptly, and in any event within two
(2)working days

receipt

an application referred to in sub-article

(2), acknowledge receipt thereof in writing to the applicant.
(7)The competent authority shall, within twenty-five
(25)working days

receipt

the application referred to in sub-article

(2), assess whether that application, including the crypto-asset white paper referred to in Article 19

the MiCA Regulation, comprises all MARKETS IN CRYPTO-ASSETS

the required information and it shall immediately notify the applicant whether the application, including the crypto-asset white paper, is missing required information: Provided that where the application, including the cryptoasset white paper, is not complete, the competent authority shall set a deadline by which the applicant is to provide any missing information.

(8)The competent authority shall, within sixty
(60)working days

receipt

a complete application, assess whether the applicant complies with the requirements

Title III

the MiCA Regulation and the provisions

this Part, and prepare a fully reasoned draft decision granting or refusing authorisation to

fer asset-referenced tokens to the public or seek their admission to trading: Provided that, within the period referred to in this subarticle, the competent authority may request from the applicant any information on the application, including on the crypto-asset white paper referred in Article 19

the MiCA Regulation: Provided further that for the purposes

the assessment to be carried out in accordance with this sub-article, the competent authority may cooperate with competent authorities for anti-money laundering and counter-terrorist financing, financial intelligence units or other public bodies.

(9)The assessment periods referred to in sub-articles
(7)and
(8)shall be suspended for the period between the date

request for missing information by the competent authority and the receipt by the said competent authority

a response from the applicant: Provided that the suspension referred to in this sub-article shall not exceed twenty

(20)working days.
(10)Without prejudice to the provisions

sub-article

(9), any further requests by the competent authority for completion or clarification

the information provided in terms

this article shall be at its discretion but shall not result in a suspension

the assessment periods set out in sub-articles

(7)and
(8).
(11)The competent authority shall, after the period referred to in sub-article
(8), transmit its draft decision as referred to in the said sub-article and the relative application to the EBA, ESMA and the ECB: Provided that where an

ficial currency

a Member State that is not the euro is referenced by the asset-referenced token, the competent authority shall also transmit its draft decision and the application to the central bank

such Member State.

(12)The opinion to be issued by the EBA and ESMA MARKETS IN CRYPTO-ASSETS respectively, at the request

the competent authority, as regards their evaluation

the legal opinion referred to in Article 18

(2)(e)

the MiCA Regulation and sub-article

(3)(e), shall be transmitted to the competent authority within twenty
(20)working days

receipt

the draft decision referred to in sub-article

(8)and the relative application.
(13)The opinion to be issued by the ECB or, where applicable, the central bank referred to in sub-article
(11)as regards its evaluation

the risks that issuing such asset-referenced token might pose to financial stability, the smooth operation

payment systems, monetary policy transmission and monetary sovereignty, in accordance with Article 21

(5)

the MiCA Regulation, shall be transmitted to the competent authority within twenty

(20)working days

receipt

the draft decision referred to in sub-article

(8)and the relative application.
(14)Without prejudice to the provisions

sub-article

(11), the opinions referred to in sub-articles
(12)and
(13)shall be non-binding: Provided that the competent authority shall duly consider the opinions referred to in this sub-article.
(15)The competent authority shall, within twenty-five
(25)working days

receipt

the opinions referred to in sub-articles

(12)and
(13), take a fully reasoned decision to grant or refuse to grant to the applicant authorisation to

fer asset-referenced tokens to the public or seek their admission to trading and, within five

(5)working days

taking such decision, notify it to the applicant: Provided that where an applicant is authorised, its cryptoasset white paper shall be deemed to be approved.

(16)In granting an authorisation under this article, the competent authority may subject the issuer

an asset-referenced token to such conditions as it may deem appropriate and having granted such an authorisation, it may from time to time, vary or revoke any condition so imposed or impose new conditions. 12.

(1)The competent authority shall refuse to grant authorisation under Article 21

the MiCA Regulation and article 11, to

fer asset-referenced tokens to the public or seek their admission to trading where there are objective and demonstrable grounds that: (a) the management body

the applicant may pose a threat to its effective, sound and prudent management and business continuity and to the adequate consideration

the interest

its clients and the integrity

the market; (b) members

the management body

the applicant do not meet the criteria set out in Article 34

(2)

the MiCA Regulation; (c) shareholders and members, whether direct or Refusal

the authorisation. MARKETS IN CRYPTO-ASSETS indirect,

the applicant that have qualifying holdings who do not meet the criteria

sufficiently good repute set out in Article 34

(4)

the MiCA Regulation; (d) the applicant fails to meet or is likely to fail to meet any

the requirements

Title III

the MiCA Regulation or the provisions

this Part; and, or (e) the applicant’s business model may pose a serious threat to market integrity, financial stability, the smooth operation

payment systems, or exposes the issuer or the sector to serious risks

money laundering and terrorist financing.

(2)The competent authority shall also refuse to grant authorisation under Article 21

the MiCA Regulation and article 11 to

fer asset-referenced tokens to the public or seek their admission to trading if the ECB or, where applicable, the central bank referred to in article 11

(11)gives a negative opinion under Article 20
(5)

the MiCA Regulation and article 12

(13)on the grounds

a risk posed to the smooth operation

payment systems, monetary poli cy transmission, or monetary sovereignty. Withdrawal

the authorisation. 13.

(1)The competent authority shall withdraw an authorisation granted under Article 21

the MiCA Regulation and article 11 to an issuer

an asset-referenced token in any

the following situations: (a) the issuer has ceased to engage in business for six

(6)consecutive months, or has not used its authorisation for twelve
(12)consecutive months; (b) the issuer has obtained its authorisation by irregular means, such as by making false statements in the application for authorisation referred to in Article 18

the MiCA Regulation and article 11 or in any crypto-asset white paper modified in accordance with Article 25

the MiCA Regulation and article 15; (

  1. c)the issuer no longer meets the conditions under which the authorisation was granted; (
  2. d)the issuer has seriously infringed the provisions

Title III

the MiCA Regulation and, or the provisions

this Part; (

  1. e)the issuer has been subject to a redemption plan; (
  2. f)the issuer has expressly renounced authorisation or has decided to cease operations; and, or (
  3. g)its the issuer’s activity poses a serious threat to MARKETS IN CRYPTO-ASSETS market integrity, financial stability, the smooth operation

payment systems, or exposes the issuer, or the sector to serious risks

money laundering and terrorist financing: Provided that the issuer

the asset-referenced token authorised under Article 21

the MiCA Regulation and article 11 shall notify the competent authority

any

the situations referred to in paragraphs (e) and (f)

this sub-article.

(2)Without prejudice to sub-articles
(1)and
(3), the competent authority shall withdraw an authorisation granted under Article 21

the MiCA Regulation and article 11 to an issuer

an asset-referenced token when the ECB or, where applicable, the central bank referred to in article 11

(11)issue an opinion that the asset-referenced token poses a serious threat to the smooth operation

payment systems, monetary policy transmission or monetary sovereignty.

(3)Without prejudice to sub-articles
(1)and
(2), the competent authority shall withdraw an authorisation granted under Article 21

the MiCA Regulation and article 11 to an issuer

an asset-referenced token where it is

the opinion that the situations referred to in Article 24

(4)

the MiCA Regulation affect the good repute

the members

the management body

that issuer, or the good repute

any shareholders or members, whether direct or indirect,

the issuer that have qualifying holdings, or if there is an indication

a failure

the governance arrangements, or internal control mechanisms as referred to in Article 34

the MiCA Regulation: Provided that when an authorisation is withdrawn in terms

this sub-article, the issuer

the asset-referenced token shall implement the procedure under Article 47

the MiCA Regulation and article 21. 14.

(1)Where the competent authority proposes to: (a) refuse an application for authorisation submitted to the competent authority in accordance with the provisions

Article 21

the MiCA Regulation and article 11, or to withdraw the authorisation granted to an issuer

an assetreferenced token under the said provisions; or (b) vary any condition to which an authorisation granted under Article 21

the MiCA Regulation and article 11 is subject, or impose a condition thereon, it shall give the applicant or the issuer

an asset-referenced token, as applicable, notice in writing

its intention to do so, while setting out the reasons for the decision it proposes to take.

(2)Every notice given under sub-article
(1)shall state that the recipient

such notice may, within a reasonable period after the Notice

proposed refusal, variation, or withdrawal

an authorisation. MARKETS IN CRYPTO-ASSETS service thereof as may be stated in the notice, make representations in writing to the competent authority in which he gives the reasons why the proposed decision should not be taken, and the competent authority shall consider any representation so made before reaching a final decision.

(3)Subject to the provisions

Article 21

the MiCA Regulation and article 11, the competent authority shall as soon as practicable notify its final decision in writing to any

the persons to whom notice is to be given under sub-article

(1). Modification

published cryptoassets white papers for assetreferenced tokens. 15.

(1)The provisions

this article shall only apply when Malta is the home Member State.

(2)Issuers

asset-referenced tokens shall notify the competent authority

any intended change

their business model likely to have a significant influence on the purchase decision

any holders or prospective holders

asset-referenced tokens, which occurs after the authorisation pursuant to Article 21

the MiCA Regulation and article 11, or after the approval

the crypto-asset white paper pursuant to Article 17

the MiCA Regulation and article 10, as well as in the context

Article 23

the MiCA Regulation: Provided that the competent authority shall be notified

the intended changes referred to in this sub-article at least thirty

(30)working days before the said changes take effect.
(3)The changes referred to in sub-article
(2)shall include, amongst others, any material modifications to: (
  1. a)the governance arrangements, including reporting lines to the management body and risk management framework; (
  2. b)the reserve assets and the custody

the reserve assets; (c) the rights granted to the holders

assetreferenced tokens; (

  1. d)the mechanism through referenced token is issued and redeemed; which an asset- (
  2. e)the protocols for validating the transactions in asset- referenced tokens; (
  3. f)the functioning

issuers’ proprietary distributed ledger technology, where the asset-referenced tokens are issued, transferred and stored using such a distributed ledger technology; (g) the mechanisms to ensure the liquidity

assetreferenced tokens, including the liquidity management policy MARKETS IN CRYPTO-ASSETS and procedures for issuers

significant asset-referenced tokens referred to in Article 45

the MiCA Regulation; (h) the arrangements with third-party entities, including for managing the reserve assets and the investment

the reserve, for the custody

reserve assets, and where applicable, for the distribution

the asset-referenced tokens to the public; (

  1. i)the complaints handling procedures; and, or (
  2. j)the money laundering and terrorist financing risk assessment and general policies and procedures related thereto.

(4)Where any intended change as referred to in sub-article
(2)has been notified to the competent authority, the issuer

an assetreferenced token shall draw up a draft modified crypto-asset white paper and shall ensure that the order

the information appearing therein is consistent with that

the original crypto-asset white paper.

(5)The issuer

the asset-referenced token shall notify the draft modified crypto-asset white paper referred to in sub-article

(4)to the competent authority and the competent authority shall electronically acknowledge receipt

the said white paper as soon as possible, but in any case not later than five

(5)working days from receipt thereof.
(6)The competent authority shall grant approval

, or refuse to approve, the draft modified crypto-asset white paper referred to in sub-article

(4)within thirty
(30)working days

acknowledgement

receipt thereof in accordance with sub-article

(5): Provided that during the examination

the draft modified crypto-asset white paper, the competent authority may request any additional information, explanations or justifications concerning the said white paper and, when the competent authority makes such request, the time limit referred to in this sub-article shall only commence when the competent authority has received the requested additional information. 16.

(1)The competent authority shall not require the prior approval

marketing communications relating to an

fer to the public

an asset-referenced token, or to the admission to trading

such asset-referenced token, before their publication. Marketing communications.

(2)Marketing communications as referred to in sub-article
(1)shall, upon request, be notified to the competent authority. 17. Where the issuer

an asset-referenced token, being a credit institution licensed under the Banking Act or a legal person or other undertaking authorised under Article 21

the MiCA Regulation and article 11, decides to discontinue the provision

its services and Discontinuation

services and activities.  MARKETS IN CRYPTO-ASSETS activities, including by discontinuing the issue

such asset-referenced token, it shall submit a plan to the competent authority for approval

such discontinuation. Assessment

proposed acquisitions

issuers

assetreferenced tokens.    18.

(1)For the purposes

this article: (a) "proposed acquirer" means any natural or legal persons or such persons acting in concert who intend to acquire, directly or indirectly, a qualifying holding in an issuer

an asset-referenced token; and (b) "issuer

an asset-referenced token" means an issuer

an asset-referenced token which is a credit institution licensed under the Banking Act or a legal person or other undertaking authorised under Article 21

the MiCA Regulation and article 11.

(2)Any natural or legal persons or such persons acting in concert who intend to acquire, directly or indirectly, a qualifying holding in an issuer

an asset-referenced token or to increase, directly or indirectly, such a qualifying holding so that the proportion

the voting rights or

the capital held would reach or exceed twenty per cent (20%), thirty per cent (30%) or fifty per cent (50%), or so that the issuer

the asset-referenced token would become its subsidiary, shall notify the competent authority

such issuer in writing, indicating the size

the intended holding and the information required by the regulatory technical standards adopted by the European Commission in conformity with Article 42

(4)

the MiCA Regulation.

(3)Any natural or legal person who has taken a decision to dispose, directly or indirectly,

a qualifying holding in an issuer

an asset-referenced token shall, prior to disposing

such holding, notify in writing the competent authority

its decision and indicate the size

such holding: Provided that any such person as referred to in this subarticle shall also notify the competent authority when it has taken a decision to reduce a qualifying holding so that the proportion

the voting rights or

the capital held would fall below ten per cent (10%), twenty per cent (20%), thirty per cent (30%) or fifty per cent (50%), or so that the issuer

the asset-referenced token would cease to be such person’s subsidiary.

(4)The competent authority shall, immediately and in any event within two
(2)working days following receipt

a notification pursuant to sub-article

(2), acknowledge receipt thereof in writing: Provided that when acknowledging receipt

the notification provided in accordance with this sub-article, the competent authority shall inform the proposed acquirer

the date

MARKETS IN CRYPTO-ASSETS expiry

the assessment period determined in accordance with subarticle

(5).
(5)The competent authority shall assess the proposed acquisition referred to in sub-article
(2)and the information required pursuant to the regulatory technical standards adopted by the European Commission in conformity with Article 42
(4)

the MiCA Regulation, within sixty

(60)working days

the date

the written acknowledgement

receipt referred to in sub-article

(4).
(6)When performing the assessment referred to in sub-article
(5), the competent authority may request from the proposed acquirer any additional information that is necessary to complete such assessment: Provided that such requests shall be made in writing and shall specify the additional information needed: Provided further that such requests shall be made before the assessment is finalised, and in any case not later than fifty
(50)working days from the date

the written acknowledgement

receipt referred to in sub-article

(4).
(7)The competent authority shall suspend the assessment period referred to in sub-article
(5)until it has received the additional information referred to in sub-article
(6): Provided that the suspension referred to in this sub-article shall not exceed twenty
(20)working days: Provided further that the competent authority may extend the suspension referred to in this sub-article by up to thirty
(30)working days if the proposed acquirer is situated outside the European Union or regulated in accordance with the law

a third country.

(8)Without prejudice to the provisions

sub-article

(7), any further requests by the competent authority for additional information or for clarification

the information received shall not result in a suspension

the assessment period set out in sub-article

(5).
(9)Where the competent authority, upon completion

the assessment referred to in sub-article

(5), decides to oppose the proposed acquisition referred to in sub-article
(2), it shall notify the proposed acquirer

its decisions, and provide the reasons for its decision, within two

(2)working days, and in any event before the date referred to in sub-article
(5)as extended, where applicable, in accordance with the provisions

this article.

(10)Where the competent authority does not oppose the proposed acquisition referred to in sub-article
(2)before the date referred to in sub-article
(5)as extended, where applicable, in MARKETS IN CRYPTO-ASSETS accordance with the provisions

this article, the proposed acquisition shall be deemed to be approved.

(11)The competent authority may set a maximum period for the conclusion

the proposed acquisition referred to in sub-article

(2), and extend that maximum period when appropriate. Refusal

proposed acquisitions

issuers

assetreferenced tokens. 19.

(1)When performing the assessment referred to in Article 41
(4)

the MiCA Regulation and article 18

(5), the competent authority shall appraise the suitability

the proposed acquirer and the financial soundness

the proposed acquisition referred to in Article 41

(1)

the MiCA Regulation and article 18

(2)on the basis

all

the following criteria: (a) the reputation

the proposed acquirer; (b) the reputation, knowledge, skills and experience

any person who shall direct the business

the issuer

the asset-referenced token as a result

the proposed acquisition; (c) the financial soundness

the proposed acquirer, in particular in relation to the type

business envisaged and pursued in respect

the issuer

the asset-referenced token in which the acquisition is proposed; (d) whether the issuer

the asset-referenced token shall be able to comply and continue to comply with the provisions

Title III

the MiCA Regulation and this Part; and      (e) whether there are reasonable grounds to suspect that, in connection with the proposed acquisition, money laundering or the funding

terrorism within the meaning

article 2

(1)

the Prevention

Money Laundering Act is being or has been committed or attempted, or that the proposed acquisition could increase the risk thereof.

(2)The competent authority may oppose the proposed acquisition referred to in Article 41
(1)

the MiCA Regulation and article 18

(2)where there are reasonable grounds for doing so based on the criteria set out in sub-article
(1), or where the information provided in accordance with Article 41
(4)

the MiCA Regulation and article 18

(5)is incomplete or false.
(3)The competent authority shall not examine the proposed acquisition referred to in Article 41
(1)

the MiCA Regulation and article 18

(2)in terms

the economic needs

the market. Notification

the recovery plan.  20.

(1)For the purposes

this article, "issuer

an assetreferenced token" means an issuer

an asset-referenced token which is a credit institution licensed under the Banking Act or a legal person MARKETS IN CRYPTO-ASSETS or other undertaking authorised under Article 21

the MiCA Regulation and article 11.

(2)The issuer

an asset-referenced token shall notify the recovery plan drawn up in accordance with Article 46

(1)

the MiCA Regulation to the competent authority within six

(6)months

the date

authorisation pursuant to Article 21

the MiCA Regulation and article 11 or within

(6)six months

the date

approval

the crypto-asset white paper pursuant to Article 17

the MiCA Regulation and article 10.

(3)The competent authority shall require amendments to the recovery plan referred to in sub-article
(2)where necessary to ensure its proper implementation and shall notify its decision requesting those amendments to the issuer

the asset-referenced token within forty

(40)working days

the date

notification

such plan.

(4)The decision

the competent authority referred to in subarticle

(3)shall be implemented by the issuer

the asset-referenced token within forty

(40)working days

the date

notification

such decision.

(5)The issuer

the asset-referenced token shall regularly review and update the recovery plan.

(6)Where the issuer

the asset-referenced token fails to comply with the requirements applicable to the reserve

assets as referred to in Chapter 3

Title III

the MiCA Regulation or, due to a rapidly deteriorating financial condition, is likely in the near future to not be able to comply with such requirements, the competent authority, in order to ensure compliance with the applicable requirements, shall have the power to require the said issuer to implement one or more

the arrangements or measures set out in the r e c o v e r y p l a n o r t o u p d a t e su c h a r e co v e r y p l a n w h en t h e circumstances are different from the assumptions set out in the initial recovery plan and implement one or more

the arrangements or measures set out in the updated plan within a specific time frame.

(7)In the circumstances referred to in sub-article
(6), the competent authority shall have the power to temporarily suspend the redemption

asset-referenced tokens, provided that the suspension is justified while having regard to the interests

the holders

assetreferenced tokens and financial stability. 21.

(1)For the purposes

this article, "issuer

an assetreferenced token" means an issuer

an asset-referenced token which is a credit institution licensed under the Banking Act or a legal person or other undertaking authorised under Article 21

the MiCA Regulation and article 11.

(2)The issuer

an asset-referenced token shall notify the Notification

the redemption plan.  MARKETS IN CRYPTO-ASSETS redemption plan drawn up in accordance with Article 47

(1)and
(2)

the MiCA Regulation to the competent authority within six

(6)months

the date

authorisation pursuant to Article 21

the MiCA Regulation and article 11 or within six

(6)months

the date

approval

the crypto-asset white paper pursuant to Article 17

the MiCA Regulation and article 10.

(3)The competent authority shall require amendments to the redemption plan referred to in sub-article
(2)where necessary, to ensure its proper implementation and shall notify its decision requesting those amendments to the issuer

the asset-referenced token within forty

(40)working days

the date

notification

such plan.

(4)The decision

the competent authority referred to in subarticle

(3)shall be implemented by the issuer

the asset-referenced token within forty

(40)working days

the date

notification

the said decision.

(5)The issuer

the asset-referenced token shall regularly review and update the redemption plan. PART IV E-MONEY TOKENS No approval

crypto-asset white papers for e-money tokens and marketing communications required. 22. The competent authority shall neither require prior approval

crypto-asset white papers for e-money tokens, nor

any marketing communications relating thereto, before their respective publication. Notification by issuers

e- money tokens. Cap. 371.  23.

(1)For the purposes

this article, "issuers

e-money tokens" means issuers

e-money tokens which are licensed as a credit institution under the Banking Act or as a financial institution authorised to issue electronic money under the Financial Institutions Act.

(2)Issuers

e-money tokens shall, at least forty

(40)working days before the date on which they intend to

fer to the public such e-money tokens or seek their admission to trading, notify the competent authority

that intention.

(3)Issuers

e-money tokens shall notify their crypto-asset white paper to the competent authority at least twenty

(20)working days before the date

its publication.

(4)Issuers

e-money tokens shall, together with the notification

the crypto-asset white paper referred to in sub-article

(3), provide the competent authority with the information referred to in Article 109
(4)

the MiCA Regulation.

(5)Without prejudice to the provisions

sub-article

(3), where MARKETS IN CRYPTO-ASSETS the provisions

Article 48

(5)

the MiCA Regulation apply, the issuers

e-money tokens shall draw up a crypto-asset white paper and notify such crypto-asset white paper to the competent authority in accordance with Article 51

the said Regulation and sub-articles

(3)and
(4).
(6)Marketing communications relating to an

fer to the public

an e-money token, or to the admission to trading

such e-money token shall, upon request, be notified to the competent authority. 24.

(1)For the purposes

this article, "issuer

an e-money token" means an issuer

an e-money token which is licensed as a credit institution under the Banking Act or as a financial institution authorised to issue electronic money under the Financial Institutions Act.

(2)The issuer

an e-money token shall notify the recovery plan drawn up in accordance with Article 46

(1)

the MiCA Regulation, as applicable pursuant to Article 55

the said Regulation, to the competent authority within six

(6)months

the date

the

fer to the public or admission to trading

the e-money token.

(3)The competent authority shall require amendments to the recovery plan referred to in sub-article
(2)where necessary to ensure its proper implementation and shall notify its decision requesting those amendments to the issuer

an e-money token within forty

(40)working days

the date

notification

such plan.

(4)The decision

the competent authority referred to in subarticle

(3)shall be implemented by the issuer

the e-money token within forty

(40)working days

the date

notification

such decision.

(5)The issuer

the e-money token shall regularly review and update the recovery plan.

(6)Where the issuer

an e-money token fails to comply with the applicable requirements under the MiCA Regulation or, due to a rapidly deteriorating financial condition, is likely in the near future to not be able to comply with those requirements, the competent authority in order to ensure compliance with the applicable requirements, shall have the power to require the said issuer to implement one or more

the arrangements or measures set out in the recovery plan, or to update such a recovery plan when the circumstances are different from the assumptions set out in the initial recovery plan and implement one or more

the arrangements or measures set out in the updated plan within a specific time frame.

(7)In the circumstances referred to in sub-article
(6), the competent authority shall have the power to temporarily suspend the redemption

e-money tokens, provided that the suspension is Notification

the recovery plan.  Cap. 371.  MARKETS IN CRYPTO-ASSETS justified while having regard to the interests

the holders

e-money tokens and financial stability. Notification

the redemption plan.  Cap. 371.  25.

(1)For the purposes

this article, "issuer

an e-money token" means an issuer

an e-money token which is licensed as a credit institution under the Banking Act or as a financial institution authorised to issue electronic money under the Financial Institutions Act.

(2)The issuer

an e-money token shall notify the redemption plan drawn up in accordance with Article 47

(1)and
(2)

the MiCA Regulation, as applicable pursuant to Article 55

the said Regulation, to the competent authority within six

(6)months

the date

the

fer to the public or admission to trading

the e-money token.

(3)The competent authority shall require amendments to the redemption plan referred to in sub-article
(2)where necessary to ensure its proper implementation and shall notify its decision requesting those amendments to the issuer

the e-money token within forty

(40)working days

the date

notification

such plan.

(4)The decision

the competent authority referred to in subarticle

(3)shall be implemented by the issuer

the e-money token within forty

(40)working days

the date

notification

such decision.

(5)The issuer

the e-money token shall regularly review and update the redemption plan. PART V CRYPTO-ASSET SERVICE PROVIDERS Authorisation

crypto-asset service providers. 26.

(1)Without prejudice to the provisions

Article 61

the MiCA Regulation, a person shall not provide crypto-asset services in Malta unless that person is: (a) a legal person or other undertaking that has been authorised to act as a crypto-asset service provider in accordance with Article 63

the MiCA Regulation; or (b) a credit institution, central securities depository, investment firm, market operator, electronic money institution, UCITS management company, or an alternative investment fund manager that is allowed to provide crypto-asset services pursuant to Article 60

the MiCA Regulation.

(2)Without prejudice to sub-article
(1), crypto-asset service providers shall be allowed to provide crypto-asset services in Malta either through the right

establishment, including through a branch, or through the freedom to provide services: Provided that where Malta is the host Member State, crypto- MARKETS IN CRYPTO-ASSETS asset service providers that provide crypto-asset services in Malta shall not be required to have a physical presence in Malta. 27.

(1)The provisions

this article shall only apply where Malta is the home Member State.

(2)A credit institution may provide crypto-asset services if it notifies the information referred to in sub-article
(9)to the competent authority at least forty
(40)working days before providing such services for the first time.
(3)A central securities depository authorised under Regulation (EU) No. 909/2014 shall only provide the custody and administration

crypto-assets on behalf

clients if it notifies the information referred to in sub-article

(9)to the competent authority at least forty
(40)working days before providing such service for the first time: Provided that for the purposes

this sub-article, the provision

the custody and administration

crypto-assets on behalf

clients shall be deemed equivalent to providing, maintaining or operating securities accounts in relation to the settlement service referred to in point

(3)

Section B

the Annex to Regulation (EU) No. 909/2014.

(4)An investment firm may provide crypto-asset services in the European Union equivalent to the investment services and activities for which it is specifically authorised under Directive 2014/ 65/EU if it notifies to the competent authority the information referred to in sub-article
(9)at least forty
(40)working days before providing such services for the first time: Provided that for the purposes

this sub-article: (a) the provision

the custody and administration

crypto-assets on behalf

clients shall be deemed equivalent to the ancillary service as referred to in point

(1)

Section B

Annex I to Directive 2014/65/EU; (b) the operation

a trading platform for cryptoassets shall be deemed equivalent to the operation

a multilateral trading facility and operation

an organised trading facility as referred to in points

(8)and
(9)respectively,

Section A

Annex I to Directive 2014/65/EU; (c) the exchange

crypto-assets for funds and other crypto-assets shall be deemed equivalent to dealing on own account as referred to in point

(3)

Section A

Annex I to Directive 2014/65/EU; (d) the execution

orders for crypto-assets on behalf

clients shall be deemed equivalent to the execution

orders on behalf

clients as referred to in point

(2)

Section A

Provision

crypto-asset services by certain financial entities. MARKETS IN CRYPTO-ASSETS Annex I to Directive 2014/65/EU; (e) the placing

crypto-assets is deemed equivalent to the underwriting or placing

financial instruments on a firm commitment basis and placing

financial instruments without a firm commitment basis as referred to in points

(6)and
(7)respectively,

Section A

Annex I to Directive 2014/65/EU; (f) the reception and transmission

orders for crypto- assets on behalf

clients shall be deemed equivalent to the reception and transmission

orders in relation to one or more financial instruments as referred to in point

(1)

Section A

Annex I to Directive 2014/65/EU; (g) providing advice on crypto-assets shall be deemed equivalent to investment advice as referred to in point

(5)

Section A

Annex I to Directive 2014/65/EU; and (h) providing portfolio management on crypto-assets shall be deemed equivalent to management

investments as referred to in point

(4)

Section A

Annex I to Directive 2014/65/EU.

(5)An electronic money institution authorised in accordance with Directive 2009/110/EC shall only provide the custody and administration

crypto-assets on behalf

clients and transfer services for crypto-assets on behalf

clients with regard to the emoney tokens it issues, if it notifies the competent authority w i t h the information referred to in sub-article

(9)at least forty
(40)working days before providing those services for the first time.
(6)A UCITS management company or an alternative investment fund manager may provide crypto-asset services equivalent to the management

portfolios

investment and non-core services for which it is authorised i n a c c o r d a n c e w i t h Directive 2009/65/ EC or Directive 2011/61/EU if it notifies the competent authority with the information referred to in sub-article

(9)at least forty
(40)working days before providing those services for the first time: Provided that for the purposes

this sub-article: (a) the reception and transmission

orders for crypto- assets on behalf

clients shall be deemed equivalent to the reception and transmission

orders in relation to financial instruments as referred to in point (b)(iii)

Article 6

(4)

Directive 2011/61/EU; (b) providing advice on crypto-assets shall be deemed equivalent to investment advice as referred to in point (b)(i)

Article 6

(4)

Directive 2011/61/EU and in point (b)(i)

Article 6

(3)

Directive 2009/65/EC; MARKETS IN CRYPTO-ASSETS (c) providing portfolio management on crypto-assets shall be deemed equivalent to the services as referred to in point (a)

Article 6

(4)

Directive 2011/61/EU and in point (a)

Article 6

(3)

Directive 2009/65/EC.

(7)A market operator authorised in accordance with Directive 2014/65/EU may operate a trading platform for crypto-assets if it notifies the competent authority with the information referred to in sub-article
(9)at least forty
(40)working days before providing such services for the first time.
(8)Notwithstanding the provisions

sub-articles

(2)to
(7), the entities referred to in the said sub-articles shall not be required to submit any information referred to in sub-article
(9)that was previously submitted by them to the competent authority where such information would be identical: Provided that when submitting the information referred to in sub-article
(9), the entities referred to in sub-articles
(2)to
(7)shall expressly state that any information that was submitted previously is still up-to-date.
(9)Without prejudice to the provisions

Article 60

(13)and
(14)

the MiCA Regulation, for the purposes

sub-articles

(2)to
(7)the following information shall be notified to the competent authority: (a) a programme

operations setting out the types

crypto-asset services that the applicant intends to provide, including where and how those services are to be marketed; (b) a description

: (i) the internal control mechanisms, policies and procedures to ensure compliance with the provisions

national law transposing Directive (EU) 2015/849; (ii) the risk assessment framework for the management

money laundering and terrorist financing risks; and (iii) the business continuity plan; (c) the technical documentation

the ICT systems and security arrangements, and a description thereof in nontechnical language; (d) a description

the procedure for the segregation

clients’ crypto-assets and funds; (e) a description

the custody and administration policy, where it is intended to provide custody and MARKETS IN CRYPTO-ASSETS administration

crypto-assets on behalf

clients; (f) a description

the operating rules

the trading platform and

the procedures and system to detect market abuse, where it is intended to operate a trading platform for crypto-assets; (g) a description

the non-discriminatory commercial policy governing the relationship with clients as well as a description

the methodology for determining the price

the crypto-assets they propose to exchange for funds or other crypto-assets, where it is intended to exchange cryptoassets for funds or other crypto-assets; (h) a description

the execution policy, where it is intended to execute orders for crypto-assets on behalf

clients; (i) evidence that the natural persons giving advice on behalf

the applicant or managing portfolios on behalf

the applicant have the necessary knowledge and expertise to fulfil their obligations, where it is intended to provide advice on crypto-assets or provide portfolio management on cryptoassets; (

  1. j)whether the crypto-asset service relates to assetreferenced tokens, e-money tokens or other crypto-assets; and (
  2. k)information on the manner in which such transfer services shall be provided, where it is intended to provide transfer services for crypto-assets on behalf

clients.

(10)The competent authority shall, within twenty
(20)working days

receipt

such notification as referred to in sub-articles

(2)to
(7), assess whether all required information has been provided.
(11)Where the competent authority concludes that a notification as referred to in sub-articles
(2)to
(7)is not complete, it shall immediately inform the notifying entity thereof and set a deadline by which that entity is required to provide the missing information: Provided that the deadline for providing any missing information shall not exceed twenty
(20)working days from the date

the request and, until the expiry

the said deadline, each period as set out in sub-articles

(2)to
(7)shall be suspended: Provided further that the crypto-asset service provider shall not begin providing the crypto-asset services as long as the notification referred to in sub-articles
(2)to
(7)is incomplete.
(12)Without prejudice to sub-article
(11), any further request by the competent authority for completion or clarification

the information provided in terms

this article, shall be at its discretion MARKETS IN CRYPTO-ASSETS but shall not result in a suspension

the period set out in sub-articles

(2)to
(7). 28.
(1)The provisions

this article shall only apply where Malta is the home Member State.

(2)Legal persons or other undertakings that intend to provide crypto-asset services shall submit their application for an authorisation to act as a crypto-asset service provider to the competent authority.
(3)The application referred to in sub-article
(2)shall contain all

the following information: (a) the name, including the legal name and any other commercial name used, the legal entity identifier

the applicant, the website operated by such applicant, a contact email address, a contact telephone number and its physical address; (b) the legal nature

the applicant; (c) the articles

association

the applicant, where applicable; (d) a programme

operations, setting out the types

crypto-asset services that the applicant intends to provide, including where and how those services are to be marketed; (e) proof that the applicant meets the requirements for prudential safeguards set out in Article 67

the MiCA Regulation; (f) a description

the applicant’s governance arrangements; (g) proof that members

the management body

the applicant are

sufficiently good repute and possess the appropriate knowledge, skills and experience to manage such provider; (h) the identity

any shareholders and members, whether direct or indirect, that have qualifying holdings in the applicant and the amounts

those holdings, as well as proof that those persons are

sufficiently good repute; (i) a description

the applicant’s internal control mechanisms, policies and procedures to identify, assess and manage risks, including money laundering and terrorist financing risks, and business continuity plan; (j) the technical documentation

the ICT systems and security arrangements, and a description thereof in non- Application for authorisation. MARKETS IN CRYPTO-ASSETS technical language; (k) a description

the procedure for the segregation

clients’ crypto-assets and funds; (l) a description

the applicant’s complaintshandling procedures; (m) where the applicant intends to provide custody and administration

crypto-assets on behalf

clients, a description

the custody and administration policy; (n) where the applicant intends to operate a trading platform for crypto-assets, a description

the operating rules

the trading platform and

the procedure and system to detect market abuse; (o) where the applicant intends to exchange cryptoassets for funds or other crypto-assets, a description

the commercial policy, which shall be non-discriminatory, governing the relationship with clients as well as a description

the methodology for determining the price

the cryptoassets that the applicant crypto-asset service provider proposes to exchange for funds or other crypto-assets; (p) where the applicant intends to execute orders for crypto-assets on behalf

clients, a description

the execution policy; (q) where the applicant intends to provide advice on crypto-assets or portfolio management

crypto-assets, proof that the natural persons giving advice on behalf

the applicant crypto-asset service provider or managing portfolios on behalf

the applicant have the necessary knowledge and expertise to fulfil their obligations; (r) where the applicant intends to provide transfer services for crypto-assets on behalf

clients, information on the manner in which such transfer services shall be provided; and (s) the type

crypto-asset to which the cryptoasset service relates: Provided that for the purposes

paragraphs (g) and (h), an applicant shall provide proof

all

the following: (a) for all members

the management body

the applicant, the absence

a criminal record in respect

convictions and the absence

penalties imposed in accordance with the applicable commercial law, insolvency law and financial services law, or in relation to anti-money laundering MARKETS IN CRYPTO-ASSETS and counter-terrorist financing, to fraud or to professional liability; (b) that the members

the management body

the applicant collectively possess the appropriate knowledge, skills and experience to manage the crypto-asset service provider and that such persons are required to commit sufficient time to perform their duties; and (c) for all shareholders and members, whether direct or indirect, that have qualifying holdings in the applicant, the absence

a criminal record in respect

convictions or the absence

penalties imposed in accordance with the applicable commercial law, insolvency law and financial services law, or in relation to anti-money laundering and counter-terrorist financing, to fraud or to professional liability.

(4)Notwithstanding the provisions

sub-articles

(2)and
(3), the competent authority shall not require an applicant to provide any information referred to in sub-article
(3)that it has already received under the respective authorisation procedures in accordance with the Financial Institutions Act or the Investment Services Act, or pursuant to national law applicable to crypto-asset services prior to 29 June 2023, provided that such previously submitted information or documents are still up-to-date.
(5)The competent authority shall immediately, and in any event within five
(5)working days

receipt

an application referred to in sub-article

(2), acknowledge receipt thereof in writing to the applicant.
(6)The competent authority shall, within twenty-five
(25)working days

receipt

an application referred to in sub-article

(2), assess whether that application is complete by verifying that the information referred to in sub-article
(3)has been submitted: Provided that where the application is not complete, the competent authority shall set a deadline by which the applicant shall provide any missing information.
(7)The competent authority may refuse to review an application referred to in sub-article
(2)when such application remains incomplete after the expiry

the deadline set by it in accordance with sub-article

(6).
(8)Once an application is complete, the competent authority shall immediately notify the applicant thereof.
(9)The competent authority shall, within forty
(40)working days from the date

receipt

a complete application, assess whether the applicant complies with the requirements

Title V

the MiCA Regulation and the provisions

this Part, and shall take a fully       Cap. 376  MARKETS IN CRYPTO-ASSETS reasoned decision granting or refusing an authorisation to act as a crypto-asset service provider: Provided that the competent authority shall notify the applicant

its decision within five

(5)working days

the date

such decision: Provided further that the assessment referred to in this subarticle shall take into account the nature, scale and complexity

the crypto-asset services that the applicant intends to provide.

(10)The competent authority may, during the assessment period provided for in sub-article
(9), and not later than the twentieth (20th) working day

the said period, request any further information that is necessary to complete the assessment referred to in sub-article

(6): Provided that such request shall be made in writing to the applicant and shall specify the additional information needed.
(11)The assessment period referred to in sub-article
(9)shall be suspended for the period between the date

request for missing information by the competent authority and the receipt by it

a response thereto from the applicant: Provided that suspension referred to in this sub-article shall not exceed twenty

(20)working days.
(12)Without prejudice to the provisions

sub-article

(11), any further requests by the competent authority for completion or clarification

the information provided in terms

this article, shall be at its discretion but shall not result in a suspension

the assessment period set out in sub-article

(9).
(13)In granting an authorisation under this article, the competent authority may impose on the crypto-asset service provider such conditions as it may deem appropriate and, wh en having granted such an authorisation it may, from time to time, vary or revoke any condition so imposed or impose new conditions.
(14)An authorisation granted i n ac co r d a n c e w i t h Article 63

the MiCA Regulation and this article shall specify the crypto-asset services that the crypto-asset service provider, to which such authorisation was granted, is authorised to provide.

(15)Where a crypto-asset service provider to which an authorisation was granted under Article 63

the MiCA Regulation and this article intends to provide crypto-asset services additional to those which it is authorised to provide, it shall submit a request to the competent authority for an extension

the authorisation granted to it, by complementing and updating the information referred to in Article 62

the MiCA Regulation and this article: MARKETS IN CRYPTO-ASSETS Provided that the request for extension shall be processed in accordance with Article 63

the MiCA Regulation and this article. 29.

(1)Where an applicant operates establishments or relies on third parties established in high-risk third countries identified pursuant to Article 9

Directive (EU) 2015/849, the competent authority shall ensure that the applicant complies with the provisions

regulations 12

(2), 6
(3)and 6
(4)

the Prevention

Money Laundering and Funding

Terrorism Regulations before granting or refusing an authorisation to act as a crypto-asset service provider in accordance with the provisions

the MiCA Regulation and this Act. Refusal

authorisation.        S.L. 373.01.

(2)Before granting or refusing an authorisation to act as a crypto-asset service provider in accordance with the provisions

the MiCA Regulation and this Act, the competent authority shall ensure that the applicant complies with the provisions

regulation 11

(10)and
(12)

the Prevention

Money Laundering and Funding

Terrorism Regulations, where applicable.        S.L. 373.01.

(3)The competent authority shall refuse to grant an authorisation under Article 63

the MiCA Regulation and article 28 where there are objective and demonstrable grounds that: (a) the management body

the applicant poses a threat to its effective, sound and prudent management and business continuity, and to the adequate consideration

the interest

its clients and the integrity

the market, or exposes the applicant to a serious risk

money laundering or terrorist financing; (b) the members

the management body

the applicant do not meet the criteria set out in Article 68

(1)

the MiCA Regulation; (c) the shareholders or members, whether direct or indirect, that have qualifying holdings in the applicant do not meet the criteria

sufficiently good repute set out in Article 68

(2)

the MiCA Regulation; and, or (d) the applicant fails to meet or is likely to fail to meet any

the requirements

Title V

the MiCA Regulation and this Part.

(4)Without prejudice to the provisions

sub-article

(3), the competent authority shall also refuse to grant an authorisation under Article 63

the MiCA Regulation and article 28 where: (a) there exist close links between the applicant and other natural or legal persons and the said links prevent the effective exercise

their supervisory functions; and, or (b) the laws, regulations or administrative provisions MARKETS IN CRYPTO-ASSETS

a third country governing one or more natural or legal persons with which the applicant has close links, or any difficulties involved in their enforcement, prevent the effective exercise

its supervisory functions. Withdrawal

authorisation. 30.

(1)The competent authority shall withdraw an authorisation granted to a crypto-asset service provider under Article 63

the MiCA Regulation and article 28 in any

the following situations: (a) the crypto-asset service provider has not used its authorisation within twelve

(12)months

the date

the authorisation; (

  1. b)the crypto-asset service provider has expressly renounced its authorisation; (
  2. c)the crypto-asset service provider has not provided crypto-asset services for nine

(9)consecutive months; (
  1. d)the crypto-asset service provider has obtained its authorisation by irregular means, such as by making false statements in its application for authorisation; (
  2. e)the crypto-asset service provider no longer meets the conditions under which the authorisation was granted and has not taken the remedial action requested by the competent authority within the specified time frame; (
  3. f)the crypto-asset service provider fails to have in place effective systems, procedures and arrangements to detect and prevent money laundering and terrorist financing in accordance with Directive (EU) 2015/849 as transposed in national law; and, or (
  4. g)the crypto-asset service provider has seriously infringed the provisions

the MiCA Regulation, this Act and, or any regulations made and, o r Rules issued thereunder, including the provisions relating to the protection

holders

crypto-assets or

clients

crypto-asset service providers, or market integrity.

(2)Without prejudice to the provisions

sub-article

(1), the competent authority may withdraw an authorisation granted to a crypto-asset service provider under Article 63

the MiCA Regulation and article 28 in any

the following situations: (a) the crypto-asset service provider has infringed the provisions

national law transposing Directive (EU) 2015/ 849; and, or (b) the crypto-asset service provider has lost its MARKETS IN CRYPTO-ASSETS authorisation as a payment institution or its authorisation as an electronic money institution, and such crypto-asset service provider has failed to remedy the situation within forty

(40)calendar days.
(3)Without prejudice to the provisions

sub-articles

(1)and
(2), the competent authority may limit the withdrawal

an authorisation granted to a crypto-asset service provider under Article 63

the MiCA Regulation and article 28 to a particular crypto-asset service. 31.

(1)Where the competent authority proposes to: (a) refuse an application for authorisation submitted to the competent authority in accordance with Article 62

the MiCA Regulation and article 28 or to withdraw the authorisation granted to a crypto-asset service provider under Article 63

the MiCA Regulation and article 28; or Notice

proposed refusal, variation, or withdrawal

an authorisation. (b) vary any condition to which an authorisation granted under Article 63

the MiCA Regulation and article 28 is subject to or to impose a condition thereon, it shall give the applicant or the issuer

an asset-referenced token, as applicable, notice in writing

its intention to do so, while setting out the reasons for the decision it proposes to take.

(2)Every notice given under sub-article
(1)shall state that the recipient

the notice may, within such reasonable period after the service thereof as may be stated in the notice, make representations in writing to the competent authority giving reasons why the proposed decision should not be taken, and the competent authority shall consider any representation so made before arriving at a final decision.

(3)Subject to the provisions

Article 63

the MiCA Regulation and article 28, the competent authority shall as soon as practicable notify its final decision in writing to any

the persons to whom notice is to be given under sub-article

(1). 32.
(1)Where Malta is the home Member State, a cryptoasset service provider that intends to provide crypto-asset services in a Member State other than Malta shall submit the following information to the competent authority: (a) a list

the Member States in which the cryptoasset service provider intends to provide crypto-asset services; (

  1. b)the crypto-asset services that the crypto-asset service provider intends to provide on a cross-border basis; (
  2. c)the starting date

the intended provision

the crypto-asset services; and Cross-border provision

crypto-asset services. MARKETS IN CRYPTO-ASSETS (d) a list

all other activities provided by the cryptoasset service provider not covered by the MiCA Regulation and this Act.

(2)The competent authority shall, within ten
(10)working days

rec eipt

the information re ferred to in sub-article

(1), communicate the said information to the single points

contact

the host Member States, to ESMA and to the EBA.

(3)The competent authority shall inform the crypto-asset service provider concerned

the communication referred to in subarticle

(2)without delay.
(4)The crypto-asset service provider may begin to provide crypto-asset services in a Member State other than Malta from the date

receipt

the communication referred to in sub-article

(3)or at the latest from the fifteenth (15th) calendar day after having submitted the information referred to in sub-article
(1). Assessment

proposed acquisitions

crypto-asset service providers.      Cap.

  1.  Cap.
  2.   Cap.
  3.    33.

(1)For the purposes

this article: (

  1. a)"proposed acquirer" means any natural or legal persons or such persons acting in concert who intend to acquire, directly or indirectly, a qualifying holding in a crypto-asset service provider; and (
  2. b)"crypto-asset service provider" means a legal person or other undertaking authorised under Article 63

the MiCA Regulation and article 28, a credit institution licensed under the Banking Act, a central securities depository authorised under the Financial Markets Act, a financial institution authorised to issue electronic money under the Financial Institutions Act, or a person licensed as an investment services licence holder under the Investment Services Act.

(2)Any natural or legal persons or such persons acting in concert who intend to acquire, directly or indirectly, a qualifying holding in a crypto-asset service provider or to increase, directly or indirectly, such a qualifying holding so that the proportion

the voting rights or

the capital held would reach or exceed twenty per cent (20%), thirty per cent (30%) or fifty per cent (50%), or so that the crypto-asset provider would become its subsidiary, shall notify the competent authority thereof in writing, indicating the size

the intended holding and the information required by the regulatory technical standards adopted by the European Commission in accordance with Article 42

(4)

the MiCA Regulation.

(3)Any natural or legal person who has taken a decision to dispose, directly or indirectly,

a qualifying holding in a cryptoasset service provider shall, prior to disposing

such holding, notify in writing the competent authority

its decision and indicate the size MARKETS IN CRYPTO-ASSETS

such holding: Provided that any such person as referred to in this subarticle shall also notify the competent authority where it has taken a decision to reduce a qualifying holding so that the proportion

the voting rights or

the capital held would fall below ten per cent (10%), twenty per cent (20%), thirty per cent (30%), or fifty per cent (50%), or so that the crypto-asset service provider would cease to be that person’s subsidiary.

(4)The competent authority shall, promptly and in any event within two
(2)working days following receipt

a notification in accordance with sub-article

(2), acknowledge receipt thereof in writing: Provided that when acknowledging receipt

the notification provided in accordance with this sub-article, the competent authority shall inform the proposed acquirer

the date

expiry

the assessment period determined in accordance with the provisions

sub-article

(5).
(5)The competent authority shall assess the proposed acquisition referred to in sub-article
(2)and the information required pursuant to the regulatory technical standards adopted by the European Commission in accordance with Article 84
(4)

the MiCA Regulation, within sixty

(60)working days

the date

the written acknowledgement

receipt referred to in sub-article

(4).
(6)When performing the assessment referred to in sub-article
(5), the competent authority may request from the proposed acquirer any additional information that is necessary to complete that assessment: Provided that such requests shall be made in writing and shall specify the additional information needed: Provided further that such requests shall be made before the assessment is finalised, and in any case no later than fifty
(50)working days from the date

the written acknowledgement

receipt referred to in sub-article

(4).
(7)The competent authority shall suspend the assessment period referred to in sub-article
(5)until it has received the additional information referred to in sub-article
(6): Provided that the suspension referred to in this sub-article shall not exceed twenty
(20)working days: Provided further that the competent authority may extend the suspension referred to in this sub-article by up to thirty
(30)working days if the proposed acquirer is situated outside the European MARKETS IN CRYPTO-ASSETS Union or regulated under the law

a third country.

(8)Without prejudice to the provisions

sub-article

(7), any further requests by the competent authority for additional information or for clarification

the information received shall not result in a suspension

the assessment period set out in sub-article

(5).
(9)Where the competent authority, upon completion

the assessment referred to in sub-article

(5), decides to oppose the proposed acquisition referred to in sub-article
(2), it shall notify the proposed acquirer

its decisions, and provide the reasons for its decision, within two

(2)working days, and in any event before the date referred to in sub-article
(5)as extended, where applicable, in accordance with the provisions

this article.

(10)Where the competent authority does not oppose the proposed acquisition referred to in sub-article
(2)before the date referred to in sub-article
(5)as extended, where applicable, in accordance with the provisions

this article, the proposed acquisition shall be deemed to be approved.

(11)The competent authority may set a maximum period for the conclusion

the proposed acquisition referred to in sub-article

(2)and extend such maximum period where appropriate. Refusal

proposed acquisitions

crypto-asset service providers. 34.

(1)When performing the assessment referred to in Article 83
(4)

the MiCA Regulation and article 33

(5), the competent authority shall appraise the suitability

the proposed acquirer and the financial soundness

the proposed acquisition referred to in Article 83

(1)

the MiCA Regulation and article 33

(2)against all

the following criteria: (a) the reputation

the proposed acquirer; (b) the reputation, knowledge, skills and experience

any person who is to direct the business

the crypto-asset provider as a result

the proposed acquisition; (c) the financial soundness

the proposed acquirer, in particular in relation to the type

business envisaged and pursued in respect

the crypto-asset service provider in which the acquisition is proposed; (d) whether the crypto-asset service provider will be able to comply and continue to comply with the provisions

Title V

the MiCA Regulation and this Part; and      (e) whether there are reasonable grounds to suspect that, in connection with the proposed acquisition, money laundering or the funding

terrorism within the meaning

article 2

(1)

the Prevention

Money Laundering Act is being or has been committed or attempted, or that the proposed MARKETS IN CRYPTO-ASSETS acquisition could increase the risk thereof.

(2)The competent authority may oppose the proposed acquisition referred to in Article 83
(1)

the MiCA Regulation and article 33

(2)where there are reasonable grounds for doing so based on the criteria set out in sub-article
(1)or where the information provided in accordance with Article 83
(4)

the MiCA Regulation and article 33

(5)is incomplete or false.
(3)The competent authority shall not examine the proposed acquisition referred to in Article 83
(1)

the MiCA Regulation and article 33

(2)in terms

the economic needs

the market. PART VI PREVENTION AND PROHIBITION

MARKET ABUSE 35.

(1)Issuers,

ferors and persons seeking admission to trading shall inform the public as soon as possible

inside information referred to in Article 87

the MiCA Regulation that directly concerns them, in a manner that enables fast access as well as complete, correct and timely assessment

the information by the public: Provided that issuers,

ferors and persons seeking admission to trading shall not combine the disclosure

inside information to the public with the marketing

their activities: Provided further that issuers,

ferors and persons seeking admission to trading shall post and maintain on their website, for a period

at least five

(5)years, all inside information that they are required to disclose publicly.
(2)Issuers,

ferors and persons seeking admission to trading may, on their own responsibility, delay disclosure to the public

inside information referred to in Article 87

the MiCA Regulation provided that all

the following conditions are met: (a) immediate disclosure is likely to prejudice the legitimate interests

the issuers,

ferors or persons seeking admission to trading; (b) public; and delay

disclosure is not likely to mislead the (c) issuers,

ferors or persons seeking admission to trading are able to ensure the confidentiality

such information.

(3)Where an issuer,

feror or a person seeking admission to trading has delayed the disclosure

inside information in accordance with sub-article

(2), it shall inform the competent authority that disclosure

the information was delayed and shall provide a written Public disclosure

inside information. MARKETS IN CRYPTO-ASSETS explanation

how the conditions set out in sub-article

(2)were met, immediately after the information is disclosed to the public.
(4)The provisions

this article shall only apply: (a) with respect to issuers,

ferors and persons seeking admission to trading

crypto-assets other than assetreferenced tokens or e-money tokens when Malta is the home Member State;    (b) with respect to issuers,

ferors and persons seeking admission to trading

asset-referenced tokens being credit institutions licensed as such under the Banking Act or persons authorised under Article 21

the MiCA Regulation and article 11; and    Cap. 371.   (c) with respect to issuers,

ferors and persons seeking admission to trading

e-money tokens being credit institutions licensed as such under the Banking Act or financial institutions authorised to issue electronic money under the Financial Institutions Act. Prevention and detection

market abuse. 36.

(1)Any person professionally arranging or executing t r a n sa c t i o n s i n cr y p t o - a ss e t s s h a l l h a v e i n p l a c e e ff e c t i v e arrangements, systems and procedures to prevent and detect market abuse.
(2)Any such person as referred to in sub-article
(1)having its registered

fice or its head

fice in Malta, or if it is a branch situated in Malta, shall be subject to any applicable notification requirements established in national law, including this Act and any regulations made and Rules issued thereunder, and shall without delay report to the competent authority any reasonable suspicion regarding an order or transaction, including any cancellation or modification thereof, and other aspects

the functioning

the distributed ledger technology suc h a s t he c ons e ns us m e ch a ni sm , whe re th e r e m i ght e xis t circumstances indicating that market abuse has been committed, is being committed or is likely to be committed.

(3)When receiving a report

suspicious orders or transactions in accordance with sub-article

(2), the competent authority shall transmit such information immediately to the competent authorities

the trading platforms concerned. PART VII REGULATORY AND INVESTIGATIVE POWERS Powers

the Minister. 37.

(1)The Minister, acting on the advice

the competent authority, may make regulations to give effect to the provisions

this Act, and without prejudice to the generality

the foregoing may, by such regulations, in particular, do any

the following: MARKETS IN CRYPTO-ASSETS (a) provide for and regulate the payment by any person or body, as the case may be,

authorisation or other fees and such other charges payable to the competent authority in respect

any matter provided for, by or under the MiCA Regulation, this Act and any regulations made, and Rules issued thereunder, including the fees and charges in respect

any permission, licence, authorisation, exemption or other benefit, as well as any fees and charges in respect

the competent authority’s regulatory, supervisory or investigative functions under the MiCA Regulation, this Act and any regulations made, and Rules issued thereunder, as may be prescribed; (b) exempt any person, service or activity from any one or more

the provisions

the MiCA Regulation and, or this Act, subject to such variations, additions, adaptations and modifications as may be prescribed and subject to such conditions or other requirements, including other forms

authorisation and notification procedures, as may be prescribed; (c) transpose, implement and give effect to the provisions and requirements

the MiCA Regulation; (d) transpose, implement and give effect to the provisions and requirements

European Union Directives, European Union Regulations and any other legislative measures

the European Union requiring transposition and, or implementation, as they may be amended from time to time, including any implementing measures that have been, or may be issued thereunder and relating to authorised persons and others as may be specified therein. Regulations made under this paragraph, and strictly related to transpositions or implementations as aforesaid, may provide that any provision

this Act or

any other law shall not apply to matters falling under such regulations, and that insofar as any

the provisions

the regulations are inconsistent with the provisions

this Act or

any other law, such provisions in any such regulations shall prevail; (e) assign powers and functions to the competent authority for the purposes

the MiCA Regulation and this Act, and provide for the exercise

such powers and the performance

such functions; (f) provide for the establishment and imposition

administrative penalties and other administrative measures that the competent authority may impose on crypto-asset service providers, issuers,

ferors, persons seeking admission to trading and any other persons as may be specified therein; MARKETS IN CRYPTO-ASSETS (g) prescribe that a breach

any regulations made under this Act may amount to a criminal

fence as may be specified, and such regulations may impose punishments in respect

any breach, consisting

a fine (multa) not exceeding five million euro (€5,000,000) or imprisonment for a term not exceeding six

(6)years or both such fine and imprisonment in the case

a natural person; and a fine (multa) not exceeding fifteen million euro (€15,000,000) in the case

a legal person; and a higher fine (multa) may be imposed on such natural or legal person, as the case may be, where deemed necessary or appropriate for any breach or failure

compliance with any European Union Directive or European Union Regulation or with any regulations made under this article to transpose or to give effect to any European Union Directive or European Union Regulation; (h) prescribe anything which may be prescribed; and (i) provide for any matter incidental to, connected with any

the above stipulated paragraphs. or

(2)Regulations made under this article may be made subject to such exemptions or conditions as may be specified therein, may make different provision for different cases, circumstances or purposes and may give to the competent authority such powers and, or functions

adaptation

the regulations as may also be so specified.

(3)Where regulations have been made in terms

this article, the competent authority may issue Rules for the better carrying out and implementation

the provisions

any regulations made in accordance with this Act.

(4)Regulations made under this Act and any amendment or revocation

such regulations, may be published in the English language only.

(5)The exercise

any

the powers assigned under this article shall be subject to any obligations or rights arising from Malta’s international commitments. Powers to issue Rules. 38.

(1)The competent authority may, from time to time, issue, publish, amend or revoke Rules which shall be binding on all persons authorised by it or falling under its regulatory or supervisory functions, or any other persons, as may be specified therein.
(2)Without prejudice to the generality

sub-article

(1), Rules issued by the competent authority may: (a) lay down additional requirements and conditions in relation to persons authorised by it, seeking its approval, or falling under the regulatory or supervisory functions

the MARKETS IN CRYPTO-ASSETS competent authority, their activities, the conduct

their business, their relations with customers, the public and other parties, their responsibilities to the competent authority, reporting requirements, financial and other resources and related requirements, and any other matters as the competent authority may consider appropriate; (

  1. b)provide for the statements and notices that shall be made or given for any purposes in regard to which the competent authority exercises supervisory or regulatory functions and the form and contents thereof; (
  2. c)prescribe the information that such persons are to submit to the competent authority; (
  3. d)transpose, implement and give effect to the provisions and requirements

the MiCA Regulation; (e) transpose, implement and give effect to the provisions and requirements

European Union legislation and any other legislative measures

the European Union requiring transposition and, or implementation, as they may be amended from time to time, including any implementing measures that have been, or may be issued thereunder and relating to authorised persons and others as may be specified therein; and, or (f) regulate any matter that is incidental to, or connected with any

the matters mentioned above as the competent authority may consider appropriate in the performance

its functions.

(3)Rules may be made subject to such exemptions or conditions as may be specified therein, may make different provision for different cases, circumstances or purposes and may give to the competent authority such powers

adaptation

the Rules as may also be so specified. 39.

(1)Without prejudice to any other powers conferred to the competent authority by this Act or by any other law, the competent authority may, whenever it deems necessary, give by notice in writing such directives as it may deem appropriate in the circumstances, and any person to whom the notice is given shall observe, comply with and otherwise give effect to any such directive within the time and in the manner stated in the directive or subsequent directives: Provided that the competent authority may give any such directive even when an authorised person, for whatever reason, ceases to be so authorised in accordance with this Act: Provided further that any directive given in accordance Power to issue directives. MARKETS IN CRYPTO-ASSETS with this article shall, unless the competent authority otherwise directs, continue to apply even when an authorised person, for whatever reason, ceases to be so authorised in accordance with this Act.
(2)The power to issue directives under this article shall also include the power to vary, alter, add to or withdraw any directive, as well as the power to issue subsequent new directives.
(3)Where the competent authority is satisfied that the circumstances so warrant, it may at any time make public any directive it has given in accordance with this article. Power to require information. 40.
(1)The competent authority may, at any time and by notice in writing, require the persons referred to in sub-article
(2)to do all or any

the following: (

  1. a)to furnish to the competent authority, at such time and place and in such form as it may specify, such information and, or documentation as it may require, including the power to require existing telephone and data traffic records; (
  2. b)to furnish to the competent authority any information and, or documentation as it may require verified in such manner as it may specify; (
  3. c)to appear before the competent authority, or before a person appointed by it, at such time and place as it may specify, to reply to questions and provide such information and, or documentation as it may require; and, or (
  4. d)to provide the competent authority any assistance which it may require and which that person is reasonably able to provide.

(2)The following persons may be required by the competent authority to provide information, documentation and, or assistance as specified in sub-article
(1): (a) crypto-asset service providers, issuers,

ferors and persons seeking admission to trading; (

  1. b)the natural and, or legal persons that control any person referred to in paragraph (
  2. a)or are controlled by such person, both in the past and present, as well as past and present directors, managers, auditors,

ficers and other employees

such person, and any third party providing a service to such person; (c) any person who is successively involved in the transmission

orders or conduct

the operations concerned, as well as their principals; and, or MARKETS IN CRYPTO-ASSETS (d) any other person who appears to be in possession

any relevant information.

(3)A natural or legal person making information available to the competent authority in accordance with this article shall not be considered to be infringing any restriction on disclosure

information imposed by contract or by any legislative, regulatory or administrative provision, and shall not be subject to liability

any kind related to the provision

such information and, or documentation.

(4)The competent authority may require, make and, or retain copies

any document furnished, provided or to which it has access in accordance with this article.

(5)Where the person required to provide information and, or documentation under this article does not have the relevant information and, or documentation, such person shall disclose to the competent authority where, to the best

his knowledge, that information and, or documentation can be found, and the competent authority may require any person, whether indicated as aforesaid or otherwise, who appears to the said authority to be in possession

such information and, or documentation to provide it as requested.

(6)A declaration made, and documentation provided, in accordance with any requirement under this article may be used in evidence against the person making the declaration or providing the documentation as well as against any person to whom they relate.
(7)The provisions

this article shall not apply to information and, or documentation which is privileged in accordance with the provisions

article 642

the Criminal Code.   

(8)Where the competent authority has appointed a representative under sub-article
(1)(c), such person shall, for the purposes

carrying out his functions under his appointment, have all the powers and functions conferred on the competent authority by this article and a requirement imposed by such person shall be deemed to be and have the same force and effect as a requirement imposed by the competent authority. 41.

(1)The competent authority may, whenever it deems it necessary or expedient, appoint an inspector to investigate and report on the affairs

any persons referred to in article 40

(2).
(2)An inspector appointed under sub-article
(1): (a) may, if he deems it necessary or expedient for the purposes

an investigation, investigate the affairs

any person mentioned in sub-article

(1); (b) shall have and may exercise all the powers conferred on the competent authority by article 40, and any Powers to appoint inspectors. MARKETS IN CRYPTO-ASSETS requirement imposed by the said inspector shall be deemed to be and have the same force and effect as a requirement

the competent authority; and (c) may, and if so directed by the competent authority shall, prepare and submit interim reports and, on the conclusion

the investigation, a final report to the competent authority.

(3)In appointing an inspector under sub-article
(1), the competent authority may direct that the investigation shall be carried out within such time and shall be limited to such specific or general matters as the competent authority may deem fit.   
(4)For the purposes

this article, the inspectors may include an advocate, a person authorised to carry out the profession

accountant or auditor in accordance with the Accountancy Profession Act, or a person considered by the competent authority as possessing suitable expertise to exercise such function.

(5)The competent authority shall have the power to order that all expenses

, and incidental to an investigation carried out in accordance with this article shall be paid by the persons referred to in sub-article

(1). Right

entry. 42.

(1)Any

ficer, employee or agent

the competent authority, on producing evidence

his authority, if required, shall have the power to enter any premises, other than the private residences

natural persons, occupied by a person on whom a notice has been served in accordance with article 40 or whose affairs are being investigated in accordance with article 41, for the purpose

obtaining therefrom the information or documents required by such notice, or for the purpose

carrying out on-site inspections or investigations, and

exercising any

the powers conferred by the said articles: Provided that the right

entry under this sub-article shall also apply to private residences

natural persons where such entry is necessary for the competent authority to fulfil its duties under Title VI

the MiCA Regulation and Part VI.

(2)Where any

ficer, employee or agent

the competent authority has cause to believe that if the notice referred to in article 40 were to be served, it would not be complied with, or that any documents to which it may relate would be removed, tampered with or destroyed, such

ficer, employee or agent shall have the power, on producing evidence

his authority, if required, to enter any premises in accordance with sub-article

(1)for the purpose

obtaining any information or documents specified in the authority, being information or documents that may have been required in accordance to such notice as referred to in article 40. MARKETS IN CRYPTO-ASSETS

(3)For the purposes

any action taken in accordance with the provisions

this article, the competent authority may request the assistance

the Commissioner

Police, who may for such purpose exercise such powers as are vested in him by law. 43.

(1)Without prejudice to any other power conferred upon it by the MiCA Regulation, this Act or any other law, the competent authority shall have the following powers: (a) to suspend, or to require a crypto-asset service provider to suspend the provision

crypto-asset services for a maximum

thirty

(30)consecutive working days on any single occasion where there are reasonable grounds for suspecting any

the provisions

the MiCA Regul

🔗 Għas-sors uffiċjali

AI explanation based on the official legal text. Indicative, not a substitute for legal advice.