0tokens

Apply for AI Grants India

Financial support for innovators building the future of AI in India.

Apply now

Chat · crypto regulatory norms india

Crypto Regulatory Norms India: 2026 Guide

  1. aigi

    India’s crypto regulatory norms are best understood as a layered compliance framework—not as a single law that either legalises or bans cryptocurrency. Virtual digital assets (VDAs), including crypto tokens and certain NFTs, are subject to income-tax rules and, in relevant cases, anti-money-laundering obligations. At the same time, the Reserve Bank of India (RBI) continues to warn users about financial, consumer and monetary risks, while the regulatory position for different crypto activities can depend on their facts and business model.

    For Indian founders, exchanges, custodians, Web3 companies and investors, the practical question is not simply whether crypto is “legal.” It is whether a specific activity triggers tax, reporting, customer-due-diligence, data-protection, securities, payments or foreign-exchange obligations.

    What Are the Crypto Regulatory Norms in India?

    India currently regulates crypto primarily through a combination of:

    • Income-tax provisions governing VDAs;
    • Prevention of Money-Laundering Act (PMLA) obligations for specified crypto businesses;
    • Financial Intelligence Unit–India (FIU-IND) registration and reporting requirements;
    • RBI directions and risk warnings concerning payment systems, foreign exchange and financial stability;
    • Securities-market rules, where a token or arrangement has characteristics of a security or investment product;
    • Consumer protection, cybersecurity and data-protection requirements; and
    • Company, accounting, contract and cross-border laws applicable to the operating entity.

    This means compliance must be assessed activity by activity. A non-custodial software developer may have a different risk profile from a custodial exchange, while a token issuer offering returns may face different questions from a company selling digital collectibles.

    Are Cryptocurrencies Legal in India?

    Cryptocurrencies are not recognised as legal tender in India. The Indian rupee remains the country’s sovereign currency and the authorised means of payment under the applicable monetary framework. However, the absence of legal-tender status does not automatically mean every possession or transaction involving a digital asset is prohibited.

    Crypto businesses operate in a legally sensitive environment. The government has introduced a tax regime for VDAs, and specified service providers must comply with PMLA requirements. These measures create compliance obligations but should not be interpreted as a blanket government endorsement of crypto products.

    Founders should avoid marketing language that describes crypto as “government-approved,” “risk-free,” or equivalent to bank deposits. Communications should clearly explain volatility, liquidity risk, technology risk, counterparty risk, fraud risk and the absence of deposit insurance unless a specific protection legally applies.

    VDA Taxation Under Indian Income-Tax Rules

    India’s tax framework for VDAs is one of the most important crypto regulatory norms for users and businesses.

    Tax on VDA gains

    Under Section 115BBH of the Income-tax Act, income from the transfer of a VDA is generally taxed at a 30% rate, subject to the statutory rules and applicable surcharge and cess. The framework is designed to apply to gains from transfers and does not operate like a conventional capital-gains regime with broad deductions.

    Important practical points include:

    • The tax rate applies to income from transfer of VDAs under the relevant provisions.
    • Expenses other than the permitted cost of acquisition are generally not deductible for computing such income.
    • Loss from a VDA transfer generally cannot be set off against income from another VDA or other heads of income under the specific regime.
    • The treatment of particular tokens, rewards, mining receipts, staking income, airdrops and DeFi activity can depend on the facts and the applicable tax interpretation.

    Tax treatment should be reviewed with a qualified Indian tax professional, especially where transactions involve derivatives, offshore platforms, liquidity pools, token compensation or cross-border settlements.

    Tax deducted at source under Section 194S

    Section 194S generally requires 1% tax deducted at source (TDS) on consideration paid for the transfer of a VDA, subject to statutory conditions and thresholds. The operational responsibility can differ depending on whether the transaction occurs through an exchange, broker, peer-to-peer arrangement or other intermediary.

    Platforms should design transaction systems to determine:

    • Whether the asset falls within the VDA definition;
    • Who is responsible for deducting and depositing TDS;
    • Whether the transaction is in cash, kind or a combination;
    • How TDS is handled for non-resident counterparties;
    • How refunds, cancellations and failed transactions are treated; and
    • How users receive records and tax documentation.

    Poor TDS logic can create reconciliation problems, customer disputes and penalties. Exchanges should maintain an auditable trail linking orders, fills, wallet movements, fees, consideration and tax deductions.

    Business accounting and GST questions

    Crypto businesses must separately analyse corporate income tax, withholding obligations, Goods and Services Tax (GST), transfer-pricing rules and accounting treatment. GST treatment may depend on the precise service supplied—such as brokerage, exchange access, custody, software, advertising or consulting—and should not be assumed solely from the fact that crypto is involved.

    PMLA, FIU-IND Registration and AML Compliance

    A major development in India’s crypto regulatory norms is the extension of anti-money-laundering obligations to specified virtual digital asset service providers. In-scope activities can include services involving exchange between VDAs and fiat currencies, exchange between one or more VDAs, transfer of VDAs, safekeeping or administration of VDAs, and financial services connected with an issuer’s offer or sale of a VDA, depending on the applicable notification and facts.

    An in-scope business should assess whether it is a reporting entity under the PMLA framework. Where required, the business must register with FIU-IND and build a compliance programme rather than treating registration as a one-time formality.

    Core AML controls for crypto businesses

    A credible AML and counter-terrorist-financing programme should include:

    • Board-approved AML and customer-acceptance policies;
    • Customer identification and verification procedures;
    • Beneficial-owner identification for companies, trusts and partnerships;
    • Risk-based customer classification;
    • Sanctions and politically exposed person screening;
    • Wallet and blockchain transaction monitoring;
    • Suspicious transaction identification and reporting;
    • Record retention and retrieval controls;
    • Enhanced due diligence for high-risk customers and jurisdictions;
    • Staff training and compliance testing; and
    • Appointment of responsible compliance personnel.

    Crypto-specific monitoring should account for mixers, rapid chain-hopping, privacy-enhancing tools, darknet exposure, ransomware indicators, sanctioned addresses, unusual velocity and inconsistent source-of-funds explanations. A simple bank-style transaction-monitoring rulebook may not identify on-chain typologies effectively.

    KYC, Customer Due Diligence and Travel Rule Readiness

    KYC is not merely an onboarding screen. Platforms should be able to understand who the customer is, who ultimately owns or controls an entity, why the account is being used and whether activity matches the stated risk profile.

    A sound onboarding process can include:

    1. Identity and address verification using reliable documents or approved digital methods;
    2. Beneficial-owner checks for non-individual customers;
    3. PEP, sanctions and adverse-media screening;
    4. Source-of-funds or source-of-wealth checks for higher-risk accounts;
    5. Device, IP, geolocation and behavioural-risk signals where lawful and proportionate;
    6. Wallet screening before deposits and withdrawals; and
    7. Periodic refresh of customer information.

    Businesses handling transfers between virtual-asset service providers should also evaluate applicable Travel Rule expectations and maintain processes for transmitting and receiving originator and beneficiary information. The exact technical implementation should be aligned with current FIU-IND requirements and the business’s transaction flows.

    RBI Position, Payments and Foreign Exchange

    The RBI has repeatedly highlighted risks associated with private cryptocurrencies, including monetary, financial-stability, consumer-protection, operational and cybersecurity concerns. Crypto platforms must therefore distinguish between providing access to a digital-asset service and offering a regulated payment product.

    Businesses should not assume that accepting crypto automatically permits settlement in foreign currency, operation of a payment system or movement of funds across borders. Cross-border structures may involve the Foreign Exchange Management Act (FEMA), rules for overseas investment, import-export documentation, authorised-dealer bank requirements, pricing and reporting obligations.

    Key questions include:

    • Is the company receiving customer money or only providing software?
    • Are fiat balances pooled, safeguarded or transferred?
    • Does the product function like a wallet, payment instrument or remittance service?
    • Are Indian residents dealing with an offshore entity?
    • Are founders using overseas subsidiaries or foreign bank accounts?
    • Does a token sale involve Indian residents and cross-border consideration?

    These questions should be answered before launch, not after a bank, regulator or compliance partner raises them.

    Securities-Law and Token-Classification Risk

    India does not provide a universal public classification saying every crypto token is either a security or a commodity. A token’s legal treatment may depend on its rights, economic substance, marketing, governance, expected returns and the surrounding arrangement.

    A token may create heightened securities-law risk if it represents ownership, debt, profit participation, pooled investment exposure, or an expectation that returns will primarily result from the efforts of a promoter or manager. Tokenised shares, investment contracts, structured products and fractionalised assets require especially careful analysis.

    Before issuing or listing a token, founders should prepare a legal memorandum covering:

    • Token rights and restrictions;
    • Issuer and promoter obligations;
    • Governance and control;
    • Distribution and marketing strategy;
    • Investor eligibility and geography;
    • Secondary-market arrangements;
    • Custody and settlement;
    • Disclosures and risk factors; and
    • Potential securities, payment, foreign-exchange and tax consequences.

    A technical white paper is not a substitute for a legal disclosure document or regulatory analysis.

    Data Protection, Cybersecurity and Consumer Protection

    Crypto firms hold highly sensitive information: identity documents, financial data, wallet addresses, device identifiers, transaction histories and sometimes biometric or video-verification data. They should implement privacy and security controls appropriate to the risks and comply with applicable Indian data-protection requirements, including the Digital Personal Data Protection framework as operational rules and guidance develop.

    Minimum controls should include:

    • Clear privacy notices and lawful processing purposes;
    • Data minimisation and retention schedules;
    • Role-based access and privileged-account controls;
    • Encryption in transit and at rest;
    • Hardware-security and key-management procedures;
    • Multi-factor authentication;
    • Withdrawal risk controls and address whitelisting where appropriate;
    • Independent penetration testing;
    • Incident response and breach escalation;
    • Vendor and cloud-security due diligence; and
    • Business continuity and disaster recovery testing.

    Customer terms should explain custody arrangements, withdrawal limits, forks, outages, liquidation, loss of private keys, fees, dispute resolution and the circumstances in which an account may be frozen.

    Compliance Checklist for Indian Crypto Startups

    Before launching a crypto product in India, founders should complete the following checklist:

    • Define the exact product and customer journey;
    • Map every flow of fiat, tokens, custody and personal data;
    • Determine whether the business is an FIU-IND reporting entity;
    • Complete PMLA registration if required;
    • Build KYC, AML, sanctions and transaction-monitoring controls;
    • Design Section 194S TDS and tax-record workflows;
    • Assess GST and corporate-tax treatment;
    • Review token classification and securities exposure;
    • Check RBI, payments and FEMA implications;
    • Establish custody, key-management and wallet-screening controls;
    • Draft customer agreements, risk disclosures and privacy notices;
    • Appoint compliance and information-security owners; and
    • Document regulatory assumptions and review them as rules change.

    Do not rely solely on a foreign legal opinion. A global platform operating with Indian customers, Indian employees, Indian marketing or Indian payment rails can create India-specific exposure.

    Common Compliance Mistakes

    The most frequent mistakes are operational rather than technical. Startups often launch with a polished app but no defensible answer to who controls customer assets, how suspicious activity is escalated or how tax records are generated.

    Avoid these errors:

    • Treating tax compliance as a complete regulatory strategy;
    • Assuming decentralised branding eliminates legal responsibility;
    • Using a generic KYC vendor without risk-based oversight;
    • Allowing withdrawals without wallet and sanctions screening;
    • Marketing guaranteed yields or assured returns;
    • Mixing customer and treasury assets without clear controls;
    • Ignoring Indian residents while operating from an offshore entity;
    • Failing to preserve transaction and decision logs; and
    • Waiting for a regulator, bank or investor to identify compliance gaps.

    FAQ: Crypto Regulatory Norms India

    Is crypto banned in India?

    India has not created a blanket prohibition on every crypto activity, but cryptocurrencies are not legal tender. Tax, AML, consumer, foreign-exchange and other obligations may apply depending on the activity.

    Do crypto exchanges need FIU-IND registration?

    An exchange or other virtual-asset service provider may need to register with FIU-IND if its activities fall within the notified PMLA reporting-entity categories. The determination should be made from the actual business model.

    What is the crypto tax rate in India?

    Income from VDA transfers is generally subject to the statutory 30% tax regime, with applicable surcharge and cess. A 1% TDS rule may also apply to consideration for VDA transfers, subject to conditions and thresholds.

    Can Indian startups issue tokens?

    Token issuance is legally and commercially sensitive. The startup should analyse securities, tax, AML, consumer, data, payments and FEMA implications before offering tokens to Indian or overseas users.

    Does using an offshore company avoid Indian compliance?

    Not necessarily. Indian customers, employees, marketing, payment flows, management or business operations can create India-related legal and tax exposure. Offshore incorporation is not a substitute for a jurisdictional analysis.

    How often should crypto compliance policies be reviewed?

    Review policies at least annually and whenever the product, token, custody model, customer geography, applicable law or regulator guidance changes. High-risk businesses should use more frequent testing and monitoring.

    Apply for AI Grants India

    Building compliance, risk intelligence or trustworthy blockchain infrastructure for India’s emerging digital-asset ecosystem? Apply to AI Grants India for support, visibility and opportunities designed for Indian AI founders.

    Last updated 19 September 2026

AIGI may be inaccurate. Replies seeded from the guide above.