Click the Play button to listen to article

Let's start with a scenario. Meera runs a crypto exchange that is compliant almost everywhere except, awkwardly, in the country where it operates. Her platform is registered with the Financial Intelligence Unit (FIU) under the Prevention of Money Laundering Act, 2002 (PMLA); it deducts 1 per cent TDS on every trade, charges 18 per cent GST on its fees, and files suspicious transaction reports on time.

Yet when her compliance head asks the simplest question in the business, "Which regulator actually governs our product?" there is no clear answer. The same bitcoin can, depending on the law and the activity involved, trigger different legal consequences. A VDA is considered a virtual digital asset for tax purposes and is not recognised as legal tender by the RBI. Depending on its structure and rights, a specific token or arrangement may raise questions under securities law. VDA transactions can also be subject to the PMLA reporting framework, and crypto-assets may be classified as “proceeds of crime” if they meet the statutory requirements under the PMLA.

This is not a drafting error. It is the current, deliberate state of Indian law governing this sector, and mapping it is the single most important exercise for any business touching virtual digital assets (VDAs).

Getting the Basics Right: There Is No Dedicated Crypto Law

India has no single, comprehensive statute that governs cryptocurrency or virtual digital assets (VDAs), nor there is a single lead regulator with general jurisdiction over the sector. Instead, different statutes address different aspects of crypto activity.

Tax law defines VDAs for income-tax purposes, while the PMLA framework expressly brings specified VDA-related activities within India's anti-money-laundering regime. The result is not just about the creation of a legal vacuum, but a fragmented framework in which different institutions regulate, tax, monitor or enforce different aspects of the same activity.

1. RBI regulates money and monetary stability. Its position has remained constant since 2018: crypto is not legal tender, private stablecoins are unacceptable, and the interface between crypto and the banking and payments system must be walled off. The Supreme Court struck down the 2018 banking-ban circular as disproportionate in Internet and Mobile Association of India v. RBI, but granted crypto no legal status, and the RBI has only hardened its line, particularly around monetary stability, financial stability and the exposure of regulated entities to crypto-assets.

2. SEBI regulates securities markets. Not directly as a crypto regulator, but has signalled openness to regulating tokens that behave like securities, the seed of a proposed multi-regulator model in which SEBI handles exchanges and securities-like tokens, the RBI handles cross-border flows, and the Finance Ministry keeps tax policy.

3. The Central Board of Direct Taxes (CBDT) and the Central Board of Indirect Taxes (CBIC) shall tax VDAs as property. This means a flat 30% tax on capital gains plus 1% TDS under Section 393(1), when combined with Section 194 of the 2025 Act. There's also no loss set-off and an 18% GST on platform fees from July 2025.

4. FIU-IND, under the PMLA, treats Exchanges as reporting entities that must register, run KYC and file suspicious transaction reports. By July 2026, 54 VDA service providers were registered, and offshore exchanges such as Binance and KuCoin registered only after being blocked and facing penalties.

5. Enforcement is an entirely separate layer. The ED does not function as a general crypto-market regulator, but it becomes relevant when crypto-related conduct falls within its statutory enforcement jurisdiction under laws such as the PMLA and FEMA. Crypto-assets may therefore become relevant to ED proceedings where the statutory conditions for offences, proceeds of crime or foreign-exchange violations are met.

The Twist Hiding in the Classification

These are not five regulators sharing one market, but are five regulators giving one asset five different legal personalities at once: property for tax, not-money for the RBI, a security only if SEBI chooses to look, a reportable transaction for FIU-IND, proceeds of crime for the ED.

The consequence is regulatory asymmetry: a business can be fully tax-compliant, FIU-registered, and GST-paid, and still be told by the RBI that its activity should be "contained," while SEBI and the Finance Ministry negotiate in public over who will regulate it next.

The Law's Own Confession

So, where does a business stand today? The honest answer was recorded by the government itself in the 36th Report of the Standing Committee on Finance on the Securities Markets Code, 2025. VDAs remain "presently unregulated in India, except for the limited purposes of taxation, prevention of money laundering and reporting." The panel has recommended an interim framework led by SROs, under the oversight of SEBI or RBI, with a clearer VDA classification and phased statutory oversight until a comprehensive law is drafted. But a recommendation is not law, and nothing changes until the Parliament acts.

Why 2025-26 Quietly Changed the Temperature

There's a crucial point to grasp. Even without a dedicated statute, the past 18 months have made crypto compliance a mandatory legal requirement under existing regulations. Starting 1 April 2026, exchanges must directly report transaction-level VDA data to the income tax department. This will incur a daily penalty of ₹200 and a maximum inaccuracy penalty of ₹50,000.

Furthermore, Schedule VDA reporting is mandatory on returns. Additionally, an 18% GST on platform fees has been in effect since July 2025. Operating without applicable PMLA registration and reporting requirements is also a violation. Tax authorities estimate that approximately 39 million Indians held around USD 2.1 billion in crypto by the end of May 2026.

Essentially, the regulatory landscape is being shaped not by a crypto statute but by the tax, Anti-Money Laundering and GST codes, one by one.

What Smarter Businesses Are Already Doing

The first question is to stop asking "is crypto legal?" and start asking "which regulator am I answerable to, and what does that regulator think this token is?" That single reframing resolves most recurring problems. In practice, it means separating the compliance streams: the tax team answers to the CBDT, the AML team to the FIU, the product team to SEBI's securities lens, and the treasury team to the RBI's payments lens.

A single "crypto policy" that mixes them is where enforcement surprises begin.

The Practical Playbook

To navigate the crypto regulatory landscape, businesses need to map out regulators rather than simply trusting their instincts. This involves evaluating every touchpoint, such as trading, custody, staking, lending, stablecoins, token issuance, and cross-border flows. For security-like tokens, SEBI's oversight should apply, while for payment-related activities, the RBI's containment line should be duly considered.

In the realm of regulatory compliance, maintaining distinct streams is crucial, as each governing body requires specific types of evidence. For instance, the Central Board of Direct Taxes (CBDT) demands Tax Deduction and Collection Certificates (TDS) and Schedule VDA submissions. Meanwhile, the Central Board of Indirect Taxes and Customs (CBIC) necessitates Know Your Customer (KYC) procedures, Suspicious Transaction Reports (STRs), and invoices. Additionally, the Reserve Bank of India (RBI) requires dedicated transaction rails to ensure compliance.

To meet the RBI's primary enforcement focus, companies should strategically design their systems to contain payment rails. This involves clearly separating fiat on- and off-ramps from core banking systems. By doing so, businesses can effectively address the RBI's regulatory requirements while maintaining operational efficiency.

Proactively adopting a multi-regulator model by implementing exchange-grade standards, custody segregation, audit trails, grievance redressal, and full disclosures ensures readiness once formal registration regimes open. Additionally, asset classification requires rigorous legal work rather than marketing labels, necessitating written, regulator-by-regulator notes that are updated whenever product features change.

Finally, operators must make declarations actionable by recognising that the Finance Ministry's current position, where crypto remains largely unregulated outside of tax, AML, and reporting, describes an existing regulatory gap rather than a safe harbour.

The Real Question Isn't Whether Crypto Is Legal

So, is crypto "legal" in India? That is the wrong question, and Meera's compliance head now knows it. Trading is not banned; the 2020 Supreme Court ruling keeps the market open. But no statute assigns ownership of this asset class to any single regulator, and the tax, AML, and GST codes already govern it in practice, while the RBI, SEBI, and the Finance Ministry decide who will regulate it next. Until Parliament enacts the law, the safest position is to treat every token as five distinct legal things at once and keep a separate, provable compliance file for each.

India's crypto problem is not that the law says nothing, but that different parts of the law say different things for different purposes, without a single statute explaining how those pieces fit together.

Views are personal.

Tags: