From the journal

California Digital Financial Assets Law Becomes Fully Operative for Stablecoin Issuers, July 2026

From 1 July 2026, California's Digital Financial Assets Law (DFAL), enacted as AB 39, became fully operative, prohibiting any person from engaging in digital financial asset business activity with California residents unless licensed by the Department of Financial Protection and Innovation. The law places particular obligations on stablecoin issuers, requiring separate DFPI approval of each stablecoin before exchange, transfer, or storage activity can proceed.

2 min read

From 1 July 2026, California's Digital Financial Assets Law (DFAL), enacted as AB 39 and codified in the Financial Code, became fully operative. The law prohibits any person from engaging in digital financial asset business activity with California residents, or representing an ability to do so, unless that person holds a DFAL licence issued by the Department of Financial Protection and Innovation (DFPI) or qualifies for an exemption. Entities that submitted licence applications before 1 July 2026 may continue operating provisionally pending a licensing decision.

DFAL defines 'digital financial asset business activity' in Financial Code Section 3100 et seq. to cover exchange, transfer, storage, and administration of digital financial assets. For stablecoins, Financial Code Section 3302 requires that a covered stablecoin be separately approved by the DFPI Commissioner before a licensed entity may exchange, transfer, or store it; the Commissioner may attach conditions, restrictions, or prohibitions to each stablecoin approval. Covered persons must comply with consumer protection requirements covering customer service standards, disclosure obligations, and financial stability measures.

Crypto exchanges, digital asset custodians, and stablecoin issuers transacting with California users face an immediate licensing obligation. Entities that have not obtained or applied for a DFAL licence and continue to transact with California residents are in violation and subject to DFPI enforcement, including cease-and-desist orders and civil money penalties up to $100,000 per day. Financial institutions seeking to distribute or custody stablecoins for California clients must verify that both the institution and the stablecoin carry DFPI approval before onboarding.

The DFAL licensing regime interacts with federal money transmission rules and federal stablecoin legislation pending in Congress. Entities holding money transmitter licences or federal bank charters may qualify for DFAL exemptions or reciprocity provisions, though the DFPI has not yet published final guidance on all exemption categories. Issuers of payment stablecoins that eventually fall under a federal regime may raise preemption arguments, but federal preemption of DFAL was not established as of 1 July 2026.

Licentium advises digital asset businesses on US state licensing strategy, DFAL compliance, and stablecoin regulatory positioning. For queries on how the DFAL operative date affects your entity, contact us. Work we undertake includes DFAL licence application support, stablecoin approval strategy, digital asset compliance programme design, money transmission law analysis, and crypto regulatory advisory.

Source: California DFPI, Digital Financial Assets Law Frequently Asked Questions (DFPI.ca.gov)

Crypto Regulatory

More from the journal

See all
Illia Prokopiev

Crypto Vaults and Lending Strategies Under U.S. Federal Securities Law

Commissioner Hester M. Peirce’s July 22, 2026 statement does not establish binding law, but it identifies the principal federal securities-law questions raised by crypto vaults and onchain lending strategies. This analysis examines when vault interests, lending claims, receipt tokens, and related service-provider activities may trigger the Securities Act, Exchange Act, Investment Company Act, and Investment Advisers Act.

MiCAR Transitional Regime for CASPs Expires Across the EU, July 2026

On 1 July 2026, the MiCAR transitional period under Article 143(3) of Regulation (EU) 2023/1114 expired across the EU. Former virtual asset service providers operating under national registrations must now hold a MiCAR crypto-asset service provider authorisation or cease providing crypto-asset services. In Luxembourg, the CSSF confirmed that VASP registration under the 2004 AML Law no longer provides a sufficient legal basis for market activity.

EDPB Adopts Final GDPR Guidelines on Blockchain Data Processing, EU, 8 July 2026

On 8 July 2026, the European Data Protection Board adopted the final version of Guidelines 02/2025 on the processing of personal data through blockchain technologies. The guidelines confirm that encrypted and hashed on-chain data remains personal data under the GDPR and that blockchain immutability does not override data subjects' right to erasure under Article 17. Controllers must address architecture choices and data minimisation before any on-chain recording of personal data.