Most businesses operating in the digital asset space think of compliance as a federal question.
Is the SEC involved? Does the CFTC have jurisdiction? What does FinCEN require?
Those are legitimate questions. But since August 18, 2025, there is a state-level compliance framework that applies to your business if you serve Illinois residents, regardless of where you are headquartered, regardless of whether any federal regulator has touched your business, and regardless of whether you think of yourself as an Illinois company.
It is called the Digital Assets and Consumer Protection Act. It is administered by the Illinois Department of Financial and Professional Regulation. And if your business is engaged in digital asset activity involving Illinois customers, it applies to you right now.
Illinois Governor JB Pritzker signed Senate Bill 1797, enacting the Digital Assets and Consumer Protection Act on August 18, 2025, establishing an Illinois state-level regulatory framework for centralized crypto exchanges with Illinois customers and other digital asset businesses operating in the state. DACPA is administered and enforced by the Illinois Department of Financial and Professional Regulation.
This is the foundational compliance layer that every Illinois digital asset business needs to understand. And with the new Digital Asset Tax Act now signed into law on top of it, the two frameworks run simultaneously, each with its own registration obligations, each with its own penalty structure.
What DACPA Actually Is
DACPA is Illinois’s answer to a simple problem: for years, Illinois consumers had no meaningful state-level protection when dealing with crypto exchanges, digital asset custodians, or crypto kiosks. They were operating in a regulatory gap between federal agencies that either lacked jurisdiction or lacked resources to act.
Illinois consumers lost significant amounts to crypto-related fraud, which provided the core justification for regulatory action. The political framing was explicit. Governor Pritzker’s press release stated that while the federal government was letting the crypto industry shape its own policy, Illinois was implementing common-sense protections for investors and consumers.
DACPA treats digital asset businesses more like traditional financial institutions, requiring capital standards, consumer disclosures, and operational safeguards. It focuses on companies that act as intermediaries, particularly those that hold custody of user assets or offer services to Illinois residents. Its extraterritorial scope puts pressure on businesses to assess state-by-state exposure when planning market entry or expansion.
That extraterritorial scope is the provision most businesses miss. You do not need an Illinois office. You do not need Illinois employees. You need Illinois customers and activity that falls within the statute’s definition of digital asset business activity.
Who DACPA Covers
The statute defines covered activity broadly. DACPA applies to any person or entity engaged in, or holding itself out as being able to engage in, digital asset business activity with or on behalf of an Illinois resident. Even if you have no Illinois presence at all, you still need to comply with DACPA if you are conducting business with Illinois residents.
The definition of digital asset business activity encompasses exchanging, transferring, or storing digital assets, digital asset administration, and any additional activities designated through Illinois Department of Financial and Professional Regulation rulemaking.
That last piece matters more than most people realize. IDFPR has broad authority to expand the definition of covered activity through rulemaking with relatively few statutory limitations. The scope of what DACPA covers is not fully fixed. It can grow.
Businesses most clearly in scope include:
Centralized crypto exchanges that allow Illinois residents to buy, sell, or trade digital assets. Digital asset custodians that hold assets on behalf of customers. Crypto brokers and liquidity providers that handle customer assets. Fintech companies embedding crypto into non-crypto services where the crypto component involves custody or transfer. Wallet providers that hold custody of customer keys or funds. Digital asset kiosk operators, which are covered separately under the companion Digital Asset Kiosk Act but subject to IDFPR oversight under the same administrative structure.
Not every crypto-related activity falls under DACPA. The law was written to avoid unnecessary friction for developers, infrastructure providers, or non-financial use cases. DACPA does not apply to peer-to-peer transactions between individuals conducted through decentralized exchanges where no party holds custody or controls the transaction flow. If your platform is fully decentralized and non-custodial, you are likely outside DACPA’s reach. But partial decentralization, such as admin control over keys or trade routing, may trigger compliance.
The exemptions for merchant transactions and personal use also matter. If your business accepts crypto as payment for goods or services without acting as a financial intermediary, your DACPA analysis is different from a platform that holds, transfers, or trades crypto on behalf of customers. That line needs to be drawn carefully with legal counsel, not assumed.
The Key Compliance Milestones
DACPA did not create a single deadline. It created a phased compliance timeline that is still unfolding.
DACPA creates critical compliance milestones: customer disclosure and custody protections must be implemented by January 1, 2027, while full licensing requirements take effect July 1, 2027.
The IDFPR may prescribe rules that take effect at an earlier date, but not before January 1, 2026. Rules have been in development since the law was signed, and the rulemaking process is ongoing. This is not a static framework. It is a living regulatory structure that is being built in real time.
What this means practically is that compliance is not a single event you prepare for and check off. It is a program you build now, maintain through the rulemaking process, and update as IDFPR issues final rules.
The businesses that engage early, build their compliance infrastructure ahead of the deadlines, and participate in the rulemaking process where possible are in a fundamentally different position than the ones that wait for final rules to be published and then scramble to catch up.
What DACPA Actually Requires You to Do
The substantive compliance obligations under DACPA are significant. They are not filing a form and paying a fee. They reflect the law’s intent to bring digital asset businesses under a regulatory framework comparable to traditional financial institutions.
Digital asset businesses and exchanges must implement, update, and enforce written compliance policies and procedures for addressing critical risks, including cybersecurity, business continuity, and anti-money laundering. DACPA also requires digital asset businesses to hold adequate financial resources and provide detailed disclosures to customers.
The disclosure obligations for covered exchanges are particularly specific. Before a covered exchange lists or offers a digital asset for the benefit of Illinois residents, the exchange must certify that it has identified the risk that the digital asset would be deemed a security by federal or state regulators, provided written disclosure relating to conflicts of interest of the covered exchange and the digital asset, and conducted a comprehensive risk assessment designed to ensure consumers are adequately protected.
That pre-listing certification requirement is something most platforms have never built a process for. Building it after you have already listed assets is significantly more complicated than building it before.
DACPA gives IDFPR significant enforcement power. IDFPR can subpoena documents and witnesses, examine the books and records of every covered person, entity, affiliate or service provider, and impose fees, fines, and civil penalties of up to $25,000 for each day of violation or each act or omission in violation, not to exceed $75,000 per day.
Those are not token penalties. For a platform with meaningful transaction volume, a sustained period of non-compliance can generate liability that exceeds the cost of building a compliance program by a significant multiple.
The Kiosk Act: A Separate Compliance Layer
If your business operates crypto kiosks, commonly known as Bitcoin ATMs, in Illinois, the companion Digital Asset Kiosk Act imposes its own set of obligations, administered by IDFPR alongside DACPA.
The Digital Asset Kiosk Act limits losses to fraud by capping daily transactions at kiosks at $2,500 for new customers and $10,500 for existing customers. It also reduces excessive transaction fees by setting limits on fees at kiosks at the greater of $5 or 18% of the digital assets involved in the transaction, and provides refund protections for victims of scams by requiring digital asset kiosk operators to provide full refunds to customers who request a refund within 30 days after the last transaction if they are victims of fraud.
These are operational requirements that go directly to how your machines are configured, how your customer onboarding works, and what your refund processing infrastructure looks like. Most kiosk operators who existed before the law passed have not fully rebuilt their systems to comply.
The Kiosk Act enforcement is already active. IDFPR sent industry notifications to kiosk operators when the law was signed. If you operate kiosks in Illinois and have not reviewed your operations against the Kiosk Act’s requirements, that review needs to happen immediately.
The Rulemaking Process and Why It Matters to Your Business
One of the most important and least understood aspects of DACPA is that the full scope of what it requires is still being determined.
DACPA leaves room for the details of its implementation to be ironed out through the rulemaking process, in which digital asset businesses can and should participate. Two entities are responsible for the rulemaking process: IDFPR and the Joint Committee on Administrative Rules. IDFPR has broad authority to shape the scope of DACPA through administrative rules.
The rulemaking process is where the specific definitions, thresholds, and procedural requirements get filled in. It is also where industry participants have the opportunity to shape how the law is applied in practice.
By engaging early with IDFPR and the rulemaking process, businesses can shape the scope of DACPA. Digital asset businesses should regularly communicate with IDFPR and engage at all levels, including with IDFPR, JCAR staff, and JCAR members of the Illinois legislature.
For most small and mid-size digital asset businesses, direct engagement with IDFPR and JCAR is not something they can manage alone. An attorney who understands both the regulatory process and the specific legal obligations under DACPA is not a luxury in this environment. It is a practical necessity.
The DACPA and Digital Asset Tax Act Together
If you have been following Illinois crypto regulation, you are now looking at two overlapping frameworks.
DACPA, signed August 2025, establishes the registration, licensing, disclosure, custody, and compliance framework. It is the consumer protection layer. Full licensing takes effect July 1, 2027. Customer disclosure and custody protections must be in place by January 1, 2027.
The Digital Asset Tax Act, signed June 16, 2026, imposes a 0.2% privilege tax on every exchange, transfer, or storage transaction involving Illinois residents or businesses generating $100,000 or more annually from Illinois digital asset activity. It takes effect January 1, 2027.
These two laws are not alternatives. They are additive. A business subject to both must register under DACPA and build the compliance infrastructure it requires, and separately register as a withholding agent under the tax law and build the tax calculation and remittance infrastructure that law requires.
If you have only been thinking about one of these laws, you have incomplete compliance exposure on your radar.
What Businesses Need to Be Doing Right Now
The compliance timeline is not theoretical. It is running.
The first thing every business with Illinois customer exposure needs to do is determine definitively whether DACPA applies to its specific activities. The statute’s coverage language is broad and the exemptions are specific. That determination requires a careful legal analysis of what your business does, not a general reading of the statute.
If DACPA applies, the next step is building the written compliance program the law requires. Cybersecurity policies, business continuity plans, anti-money laundering procedures, customer disclosure frameworks, and capital adequacy documentation are not things that can be assembled in a week before a deadline.
If your business lists digital assets for Illinois residents, the pre-listing certification process needs to be built now, not after your next listing decision.
If you operate kiosks, your transaction caps, fee structures, and refund procedures need to be reviewed against the Kiosk Act requirements immediately.
And if you have not registered with IDFPR or engaged with the rulemaking process, both of those should be on your agenda before full licensing requirements take effect July 1, 2027.
The businesses that are in the best position when enforcement becomes fully operational are the ones that treated DACPA as a real compliance obligation from the day it was signed, not as a future problem to be addressed when final rules are published.
The Enforcement Question
There is no indication that IDFPR currently has the resources, capabilities, or digital asset industry domain expertise to administer or enforce DACPA effectively. That observation, made by Foley and Lardner shortly after the law was signed, reflects a legitimate question about enforcement capacity.
But enforcement capacity is not a compliance strategy. Agencies build capacity. Resources get allocated. Staff gets hired. And enforcement actions, when they do come, tend to fall hardest on businesses that made no effort to comply, kept no documentation, and cannot demonstrate good faith.
The penalty structure under DACPA is steep enough that a single sustained enforcement action against an unprepared business could be existential. The cost of building a compliance program is a fraction of that exposure. The math is not complicated.
About George Bellas
George Bellas Partner, Bellas and Wachowski businessattorneychicago.com
George Bellas is a Chicago business attorney with decades of experience helping Illinois businesses navigate complex regulatory environments and emerging legal frameworks. As digital asset regulation in Illinois has moved from a general concept to a specific, enforceable set of obligations, the businesses that come through this period without significant legal exposure are the ones that got ahead of it early with experienced counsel.
If your business has exposure under DACPA, has not yet analyzed its compliance obligations under the Digital Asset Tax Act, or has questions about what Illinois crypto law requires of your specific operations, George Bellas is available for a consultation.
Call 800.825.9260 or visit bellas-wachowski.com. The deadlines are fixed. The rulemaking is ongoing. The time to understand where you stand is now.
Chicago Business Attorney Blog

