Two-Way Traffic: Private International Law and the MiCA Review
This post was written by Cayetana Santaolalla Montoya, Associate Professor of Private International Law, Public University of Navarra.
The review of Regulation (EU) 2023/1114 under Articles 140 and 142 is mostly being read as an exercise in supervisory calibration. Which services belong on the list, how asset-referenced tokens should be treated, where the perimeter of decentralised finance runs. In the response I submitted to the Commission’s targeted consultation on 4 August 2026, and in the working paper drawn from it, I argued that several of the hardest questions on that list are not supervisory questions at all. They are conflict of laws questions in regulatory dress.
That claim, on its own, will not surprise readers of this blog. What may be worth discussing is the direction of the traffic.
We are used to saying that regulation leaves private law untouched, and that private international law must then coordinate the national private laws that remain. That is correct, and much of my response says so. But the relationship runs the other way as well. Regulation produces facts. Conflicts rules need facts that third parties can ascertain. A supervisory regime built on authorisation, disclosure and record-keeping manufactures the kind of objective, verifiable connection that our connecting factors have always relied on, and that the on-chain environment otherwise denies us.
So the traffic runs both ways. Private international law lends regulation tests it does not have, and regulation lends private international law facts it cannot otherwise find. Three illustrations follow. The first two run in opposite directions. The third runs in neither, because it concerns a question that both bodies of law have left to whoever drafts the contract.
Reverse solicitation, decided by Pammer
Here the loan runs from private international law to regulation. MiCA inherits from MiFID II an exception for services provided at the client’s own exclusive initiative. In practice the exception is asserted by the provider and assessed largely on the provider’s own account of its conduct. Meanwhile third-country platforms reach European users through app stores, EU-language marketing and paid promotion.
We already have a litigated, objective test for when a trader directs its activity to a Member State. The Court of Justice built it in Pammer and Hotel Alpenhof, and its list of indicia is expressly non-exhaustive: the international nature of the activity, a language or a currency other than those generally used in the trader’s own Member State, a top-level domain other than its own, expenditure on an internet referencing service, the mention of an international clientele. The Court was equally clear about the other side of the line. Mere accessibility of the website in the consumer’s State is not enough on its own, and neither is the use of the trader’s own language or currency.
Availability in a national app store and paid promotion aimed at a national audience belong to the first group, not the second. A storefront is segmented by country, and the provider chooses the countries in which it appears. Payment for placement is expenditure with a purpose. The test accommodates them without being stretched.
What interests me is the borrowing itself. A doctrine developed to protect consumer jurisdiction becomes a regulatory perimeter test. The underlying inquiry is the same in both settings: did this trader reach into this market? Private international law answers it better than supervisory practice does, because it has been answering it under judicial control since 2010.
COMI, supplied by the authorisation
Article 3 of Regulation (EU) 2015/848 presumes the centre of main interests to lie at the registered office, and Eurofood and Interedil tell us that the presumption yields to factors which are objective and ascertainable by third parties. A crypto-asset group is often engineered to have no meaningful seat. Its keys, servers, clients and reserves sit in different States, and the registered office is chosen precisely because it signifies nothing.
The place of MiCA authorisation and effective supervision is exactly the kind of factor the case law asks for. It is public, verifiable, and not adopted for the occasion of the insolvency. A crypto-specific rebuttable presumption anchored there would give the doctrine the objective fact it already demands and cannot currently find.
The conflicts rule does not merely survive regulation. It is made workable by it.
Segregation, taken out of the custodian’s hands
The recent failures were decided by private law, not by technology. In Celsius, the court held in January 2023 that the terms of the Earn programme had transferred title, so those depositors ranked as unsecured creditors, while the separate custody service, which conferred no right of use, left title with the customers. One institution produced both proprietary and merely personal claimants over materially identical assets. In Ruscoe v Cryptopia Ltd (in liquidation) the New Zealand High Court held that the exchange held user assets on trust, so the account-holders were beneficial owners outside the estate. In FTX the terms said that title to customers’ digital assets remained with them at all times, but commingling meant the promise could not be made good, and customers were left asserting claims against an estate rather than identifying assets within it.
The line between a proprietary and a personal claim was therefore drawn by a term the custodian drafted, and, where the term was favourable, by whether the custodian had troubled to keep the assets apart. That is an odd place to leave it.
Two consequences follow, and they operate on different planes. On the substantive plane, EU law should require client-asset segregation and treat the client’s entitlement as excluded from the custodian’s estate, whatever the contract says. On the conflicts plane, that requirement should bind as an overriding mandatory provision within the meaning of Article 9 of the Rome I Regulation, so that a chosen law cannot defeat it in the contractual relationship where the characterisation is in practice decided. Party autonomy belongs to the custody contract. It should not reach the proprietary dimension, which was never the parties’ to allocate.
The connecting factor, and the usual objection
For the proprietary aspects of tokens I propose a free-standing Regulation with a waterfall: the law specified in the token, failing that the law specified in the rules of the system on which it is recorded, failing that the law of the issuer’s establishment and supervision. For the custodial relationship, the connecting factor should be the effective locus of control over the key-management infrastructure through which the asset is accessible.
The standard objection to a control-based factor is that control is a fact, and a fact that may leave no independent trace. It is a serious objection. In self-custody and in permissionless settings I do not think it has been answered.
In regulated custody it has, and the answer is again regulatory. The custodian must maintain, document and disclose the infrastructure through which client assets move. Access logs, signatory records and evidence of approval are supervisory requirements before they are evidence in a dispute. The locus of control is ascertainable because regulation compels it to be ascertainable. The Mauritius custody rules of 2019 already require records of that kind, and MiCA’s record-keeping obligations point the same way.
The substantive counterpart is functional rather than harmonising: uniform legal effects attached to the fact of control, enacted under Article 114 TFEU. Article 345 TFEU is no obstacle, for the reason the Union already relied on in the Financial Collateral and Settlement Finality Directives, both of which confer proprietary and insolvency effects without touching national property law.
Why it matters now
Four things follow: an objective directed-activity test for reverse solicitation, a crypto-specific presumption of the centre of main interests, segregation as an overriding mandatory rule, and a free-standing conflicts Regulation for the proprietary aspects of tokens.
The consultation closes on 30 September 2026, and the Experts’ Group on Digital Tokens of the Hague Conference meets at the Permanent Bureau from 26 to 29 October. The two exercises are usually treated as separate conversations. They are the same conversation, and the Union is in a position to set the standard rather than to receive it.
The full argument is in a working paper, Control, Custody and Conflict of Laws: Private International Law and the Regulation of Crypto-Assets in the European Union (4 August 2026).
All comments welcome, particularly with respect to the control-based connecting factor.

Leave a Reply
Want to join the discussion?Feel free to contribute!