
A crypto ad compliance dossier is not a folder you assemble the night before submission. It's the fire extinguisher you hope you never need, kept by the door where everyone can find it, not buried in a cupboard three staff changes deep. That distinction matters more than it sounds, because most projects only discover which category they built the day the reviewer asks a question nobody can answer.
Here's the uncomfortable bit. Most crypto marketing teams treat compliance documentation as a one-off chore: gather the license, screenshot the disclaimer, zip it up, submit, forget. Six months later the account gets flagged, the license has quietly lapsed, the person who saved the files left in March, and nobody can find the original disclosure copy. Our crypto Google Ads work runs into this constantly — not because projects are careless, but because nobody built the dossier to survive contact with a review that arrives whenever it arrives, not on a schedule anyone chose. This piece is about building the version that doesn't fall apart the moment its builder stops checking on it.
What a Dossier Is—and Is Not
A compliance dossier is a review-ready evidence system, not a magic trick. It's a set of documents, indexed and dated, that prove who you are, what you're selling, where you're licensed to sell it, and how you handle the data you collect.
It is not a way to dress up a non-compliant product so it photographs well. That distinction is worth stating plainly, because a lot of checklists floating around online blur it without meaning to. A dossier doesn't make an unlicensed exchange licensed. It doesn't retroactively make a claim true that wasn't true when someone wrote the ad copy.
What it does is let you prove, fast and specifically, the things that are already true about your project. That's the entire job a reviewer is doing anyway, and later an appeals officer too — they are trying to establish facts, not vibes.
Google's own policy for cryptocurrency products already requires certification before certain categories can run ads at all, and increasingly asks advertisers to hold and present their own evidence rather than leaning on a one-time application reviewed once and forgotten. A dossier is the internal system built to match that expectation, and it's the operating assumption behind every account we run in a certified category across multiple markets.
The Core Folders

Organize the dossier into eight folders, not one. A single "compliance" directory is a graveyard — everything goes in, nothing comes back out, and you find that out the day it matters.
- Entity — incorporation documents, ownership structure, the legal name that actually appears on your licenses
- Product — what the product does, in plain language, matched to how it's actually described in ad copy
- Licensing — every license or registration held, by jurisdiction and regulator
- Geography — which markets you're licensed to advertise in, and which you deliberately exclude
- Destination — the specific landing pages your ads point to, versioned
- Claim — every substantive claim made in an ad, mapped to its evidence
- Privacy. Consent flow, data fields collected, vendors, retention
- Approval. Prior platform decisions, correspondence, and appeal outcomes
Licensing deserves its own spotlight because it's the folder that moves without you touching it. Under Google's MiCA-linked update, advertisers targeting the EEA with exchanges or wallets need a Crypto-Asset Service Provider license and other local requirements sorted before Google will certify them there. A bar that looked completely different a year earlier.
A licensing folder untouched since launch day is almost certainly wrong by now. Nobody finds that out until the review does, and that is a genuinely bad way to learn it.
Create an Evidence Index
Every document inside the dossier needs five fields attached, or it's just a pile of PDFs with no way to know which ones still apply. Owner, source URL, expiration or review date, which platforms it's relevant to, and a change history. That's the skeleton the whole dossier hangs on.
Here's an example of how the index should look:
| Document | Owner | Source | Review Date | Platforms | Last Changed |
| CASP License (EEA) | Legal lead | Regulator portal | Quarterly | Google, Meta | 2026-08 |
| Entity registration | Ops lead | Companies registry | Annual | All | 2026-01 |
| Landing page v4 | Marketing lead | CMS | Per campaign | 2026-09 | |
| Privacy policy v3 | Legal lead | Website | Per policy change | All | 2026-06 |
The "owner" column isn't bureaucracy for its own sake, it's the difference between a five-minute answer and a five-day scramble. When a reviewer or an appeals officer asks a pointed question, someone in the building needs to answer it before lunch, not reconstruct a paper trail from a former colleague's inbox. That's the same pattern we see across Google Ads suspension appeals. The accounts that recover fastest already know exactly where the license lives.
Add a Landing-page and Claims Register
Every claim your ads make needs to be mapped to two things: the evidence that substantiates it, and the exact version of the landing page it points to. This is the part almost every public checklist skips entirely, and it's usually the part that actually breaks a review.
A reviewer doesn't judge your ad copy floating in isolation. They follow the ad through to the destination and check whether the two agree with each other. If your ad says "regulated in the UK" and the landing page a reviewer clicks through to was quietly edited last month to remove that line, the mismatch reads as either carelessness or deception to a trust and safety team.
Neither reading gets you a fast pass.
Build the register as a plain table: claim, evidence source, destination URL, and destination version at time of publication. Landing pages get redesigned, disclaimers get shortened for a new market, and nobody remembers which claim belonged to which version unless it's written down somewhere a human can find it.
Document Tracking Responsibly
Tracking documentation belongs in the dossier alongside licensing, not off to one side as a legal afterthought bolted on at the end. Record the consent flow itself, the specific data fields collected, every vendor with access to that data, retention periods, and the controls a user has to withdraw or amend their consent.
Under GDPR's Article 7(1), simply claiming that consent was obtained isn't enough during an inspection. Organizations are expected to hold a record of who consented, when, and by what method, including the exact policy version shown at the moment of collection.
That's a much higher bar than most teams assume, and it's the one folder almost none of the public dossier checklists mention at all. Practically, this means your consent logs need timestamps and policy version numbers, not a checkbox that just says "consent: yes."
If your ad platform requires a pixel or a conversion API integration, that vendor relationship belongs in the same index as your license. Same owner field, same review date, same discipline.
Maintain the Review Pack
A dossier that isn't maintained decays faster than one that was never built, because it hands you false confidence right up until the moment it costs you. Set a periodic check, quarterly is a reasonable default, and build in triggers that force an update outside that schedule regardless: a new product feature, a new domain, entry into a new market, or a change to the offer itself.
The EEA's licensing shift is a useful case study in why this matters. A license that was entirely sufficient for running ads in an EEA market one year can lapse the following year without a single thing changing about the advertiser's product. Purely because the regulatory floor moved under it while everyone was looking elsewhere.
Google's crypto ad policy does allow advertisers to appeal a decision directly from their account when they believe an ad was flagged in error, and compliant ads can run again once the review confirms compliance. An appeal backed by a maintained dossier is a fundamentally different conversation with a reviewer than a scramble to reconstruct one from scratch under pressure.
Nobody at Coinpresso is going to hand you a number for how many days that shaves off a review, because we don't have one and neither does anyone else being straight with you. Outcomes vary by platform, product category and market, and anyone quoting a fixed figure is guessing out loud.
It's also worth knowing the shape of what you're actually dealing with, platform by platform. Meta requires advertisers seeking to promote crypto trading platforms or blockchain-based products to submit a recognized regulatory license and obtain written permission through its Authorizations and Verifications process. Trade press has reported this functions as a tiered system that varies by regulator and jurisdiction rather than a single flat gate, though that nuance isn't spelled out in Meta's own published policy text, so treat it as a useful heads-up rather than settled fact.
Treating Google certification and Meta authorization as the same document with two different logos stapled on is the kind of shortcut that gets caught, usually at the worst possible moment.
None of this guarantees an outcome, and anyone telling you otherwise is selling something. A dossier supports clarity; it does not obscure ownership, product scope, geography or tracking practice, and it cannot make a platform approve something it has genuine grounds to reject. Review your legal documentation and privacy controls with qualified counsel, not a marketing agency's blog post.
Conclusion
Build the dossier as a living index, not a submission folder, and the difference shows up the first time you need it under genuine pressure rather than on your own schedule. Here's a minimal starting template:
- Entity: registration documents, ownership chart, authorized signatories
- Product: one-paragraph plain-language description matched to ad copy
- Licensing: license or registration per jurisdiction, issuing regulator, expiry date
- Geography: markets included, markets deliberately excluded, reasoning
- Destination: landing page URL, version number, last review date
- Claim: claim text, evidence source, linked destination version
- Privacy: consent flow, data fields, vendor list, retention schedule
- Approval: platform decisions, correspondence, appeal history
Every row gets an owner and a review date attached to it. That's the whole system laid bare: eight folders, five fields each, checked on a schedule instead of assembled in a crisis at 11pm the night before a resubmission. This is also the groundwork our crypto PPC team asks new accounts to have in place before a single dollar goes into a live campaign.
The fire extinguisher only works if it's still where you left it, charged and in date. Build the dossier now, index it properly, and the next platform review becomes a conversation instead of a fire drill. Make compliance evidence usable before a reviewer ever asks for it. Contact Coinpresso to structure an ad compliance dossier around your product, your markets, and your campaign destinations.
FAQs
What belongs in a crypto advertising compliance dossier?
Eight categories, at minimum: entity, product, licensing, geography, destination, claims, privacy, and prior approvals. Each document needs an owner and a review date attached, not just a place in a folder, or it becomes stale evidence nobody trusts. Our Web3 marketing work treats this as the baseline before any paid spend goes live.
Should the dossier include licensing documents?
Yes, and they should sit in their own folder because they change faster than anything else in the dossier. Regulatory shifts, like the EEA's move toward CASP licensing, can make a document insufficient without your product changing at all, so a license folder needs a review date, not a one-time upload.
How should tracking be documented?
Record the consent flow, exact data fields collected, every vendor with access, retention periods, and user controls, alongside the same ownership and review fields as your licensing folder. GDPR's consent-logging requirement means a checkbox alone won't hold up under inspection; you need timestamps and the policy version shown at collection.
Can a dossier guarantee approval?
No. A dossier supports clarity and speeds up how quickly a reviewer can verify what's already true, but it cannot make a platform approve a product with genuine grounds for rejection. Treat any claim to the contrary, from any agency, as marketing rather than fact.
Who owns the dossier internally?
No single department should own the whole thing, because compliance evidence touches legal, product, and marketing at once. Assign an owner per folder instead — legal for entity and licensing, marketing for destination and claims — and review the full structure together on a set schedule. Our case studies page has examples of how that kind of cross-functional structure holds up once an account is live.































