NFT project legal structuring in Germany (BaFin)
On paper, an NFT project looks straightforward: mint tokens, build a community, launch a marketplace. In practice, a German-law analysis can reclassify those tokens as financial instruments overnight – triggering BaFin (Bundesanstalt für Finanzdienstleistungsaufsicht) authorisation requirements, prospectus obligations and AML registration duties that most project founders do not anticipate until a bank account is closed or a cease-and-desist letter arrives. The legal question is not whether NFTs are "real" assets. It is whether the specific rights embedded in your tokens bring them within the scope of Germany's regulatory perimeter – and what corporate, contractual and compliance architecture you need before you go live. This guide works through that analysis step by step, from token classification to entity selection, banking and the cross-border reality of selling to German users from outside the EU.
NFT project legal structuring in Germany turns on a single prior question: does your token constitute a financial instrument or crypto-asset under the applicable German and EU regulatory regime? The answer determines whether BaFin supervision applies, which licence category is relevant, and how the entity, smart-contract and commercial terms must be configured. Under MiCA (Markets in Crypto-Assets Regulation) – now the operative EU framework – and the German implementing rules, classification is a substance-over-label exercise. A "utility" tag in a whitepaper does not settle the question.
The sections below follow the sequence a project team should work through: classify the token, select the entity, draft the smart contract and terms, meet the AML baseline, address the banking stack, and stress-test the cross-border exposure. Each step carries a common mistake and a registry-anchored regime reference.
Step 1: Classify your NFT before anything else – the BaFin and MiCA analysis
Token classification is the foundational step, and getting it wrong turns a product launch into an unregistered securities offering. BaFin applies a rights-based analysis: what does the token actually do, irrespective of what the whitepaper calls it? Under MiCA, most standard NFTs – genuine one-of-ones with no financial return embedded – fall outside the regulation's scope as "unique and not fungible" tokens. That carve-out is narrower than it reads.
BaFin's supervisory practice, consistent with guidance issued by ESMA and the national competent authorities, treats fractionalized NFTs, royalty-sharing tokens and NFTs in series with interchangeable characteristics as potentially fungible – and therefore potentially within MiCA or, if the rights resemble equity or debt, within the scope of the securities regime. An NFT that entitles the holder to a share of revenue, a governance vote over a commercial entity, or a contractual claim against the issuer carries economic substance that mirrors a transferable security. BaFin will look past the "NFT" label.
In our cross-border practice, the most frequent misclassification error is a project team relying on a utility characterisation adopted in a non-EU jurisdiction – say, a Cayman or BVI structure that received a legal opinion under local law. That opinion does not travel. German users accessing the project from Germany expose the operator to BaFin's enforcement jurisdiction regardless of where the smart contract is deployed or the entity is incorporated.
The practical first step is a structured classification memo: map the rights embedded in the token against the MiCA taxonomy (other crypto-assets, asset-referenced tokens, e-money tokens) and against the German securities law definition of a transferable security. Where the analysis is not clean, the memo should document the reasoning and the structural adjustments made to stay outside the regulated perimeter. That memo becomes your defence file if BaFin inquires.
Common mistake at Step 1: Treating the token classification as a one-time exercise. If the token's utility or economic rights evolve post-launch – for example, if a governance mechanism is added or royalty flows are introduced – the classification analysis must be repeated.
Step 2: Select the right entity structure for a German-market NFT project
Entity selection for an NFT project targeting German users is a decision with tax, liability and regulatory dimensions that interact. For most commercial NFT projects, the realistic options are a German GmbH (Gesellschaft mit beschränkter Haftung), a non-German EU entity with German market access, or a non-EU entity operating at arm's length from a German-facing front end.
A GmbH is the standard German operating entity for a regulated or commercially active digital-asset business. It provides limited liability, a familiar structure for banking counterparties, and a clear contractual counterpart for smart-contract terms. If the project's token analysis concludes that BaFin authorisation is required – for instance, because the project operates a secondary marketplace or provides custody – the GmbH or an equivalent EU entity is the vehicle through which that authorisation is held.
For projects that classify cleanly outside the regulated perimeter, a non-German EU entity – a Lithuanian or Maltese company, for example – can operate into Germany under the EU single-market principles. MiCA passporting means a CASP (Crypto-Asset Service Provider) authorised in one EU member state may provide services across the EU/EEA, including into Germany, without a separate BaFin authorisation. That route has conditions: the entity must be genuinely authorised in its home state, not merely registered, and the passporting notification to BaFin must be completed before German-resident users are onboarded.
A DAO structure raises separate questions. German law does not recognise a DAO (decentralised autonomous organisation) as a legal entity. Operating a German-facing project through an unincorporated DAO exposes token holders and active contributors to joint-and-several personal liability under partnership law principles. The practical answer is to wrap the DAO in a recognised legal entity – a GmbH, a Swiss association, a Cayman foundation company or a Marshall Islands LLC, depending on the governance and tax objectives – and use a governance charter that maps on-chain voting to the entity's constitutional documents.
Common mistake at Step 2: Choosing the entity for tax efficiency alone without mapping the regulatory trigger points. A Cayman entity that holds the smart contract but employs staff in Germany or maintains servers with German IP addresses may face a permanent establishment analysis and BaFin's extraterritorial supervision argument simultaneously.
The process above describes the standard path. Your facts – the entity, the user base, the token rights – change the analysis. For a scoped entity assessment before you commit to a structure, contact OBOLUS at info@oboluslaw.com.
Step 3: Draft the smart contract and commercial terms to match the legal structure
A smart contract is a binding legal instrument in Germany, but its enforceability depends on how it interacts with the governing law and with the consumer-law obligations that apply when German residents are contracting parties. The terms embedded in code and the off-chain terms of service must be aligned; where they conflict, a German court will apply general contract law principles to resolve the gap – which may not produce the result the project intended.
The key drafting points for a German-market NFT project are these. First, governing law and jurisdiction: if the project targets German consumers as well as businesses, the choice-of-law clause does not displace mandatory German consumer-protection rules. A project selling NFTs to the public should assume German consumer law applies to German purchasers regardless of the clause. Second, the terms must accurately describe what the NFT confers – including what it does not confer. A claim to "ownership" of underlying intellectual property when the smart contract conveys only a licence is a misrepresentation under German law and an unfair commercial practice under the applicable EU directive.
Third, the smart contract code itself should be audited not only for technical vulnerabilities but for legal effect: does the on-chain logic match the off-chain description? Does an automatic royalty distribution create a profit-sharing arrangement that shifts the token's classification? In our practice, we work through the smart-contract logic alongside the legal analysis, not after it.
For projects with a DeFi (decentralised finance) component – staking, liquidity provision, lending against NFT collateral – the German regulatory analysis deepens. Each financial function requires its own classification pass. BaFin has been explicit that the decentralised label does not automatically remove a protocol from its supervisory perimeter if a de-facto central operator can be identified.
Common mistake at Step 3: Treating the terms of service as boilerplate adapted from a US or UK template. German law has specific requirements for distance contracts, mandatory withdrawal rights and data-processing disclosures that are not captured in most common-law templates.
How does the BaFin AML regime apply to an NFT project?
AML obligations under the German Money Laundering Act (GwG) and the underlying FATF Recommendations attach to virtual asset service providers, not to NFT issuers as such – but the line is thinner than most project teams assume. If the project operates a secondary marketplace (whether peer-to-peer or pooled), facilitates exchange between NFTs and fungible tokens, or provides custody of users' digital assets, it is likely operating as a VASP and must register with BaFin under the applicable VASP provisions.
VASP registration in Germany requires the entity to implement a written AML programme, appoint a money-laundering officer, conduct customer due diligence on users above the applicable thresholds, and maintain transaction records. The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data with a virtual-asset transfer – applies to transfers above the applicable threshold. Projects that route transfers between users must have a technical and operational solution for Travel Rule compliance before launch.
A project that is a pure NFT issuer with no secondary-market or custody function is not automatically a VASP. That structural choice – separating the issuance function from any marketplace or custody function – is one of the most effective ways to manage the AML compliance burden in the early stages of a project. The trade-off is that it constrains the business model: the project cannot operate its own secondary marketplace without acquiring the compliance infrastructure.
Common mistake at Step 4: Assuming that because the NFT is non-fungible, the AML regime does not apply. BaFin assesses the function, not the token label.
What banking and payments infrastructure works for a German NFT project?
Banking is the operational chokepoint for most NFT projects entering the German market. Traditional German banks apply conservative correspondent-banking policies to digital-asset businesses. A project without a completed regulatory analysis – classification memo, entity opinion, AML programme – will find it difficult to open an account with a Tier 1 or Tier 2 German bank.
The practical options for most early-stage projects are: a German EMI (e-money institution) account for fiat on-ramp and off-ramp; a Lithuanian or Estonian licensed EMI with German IBAN capability under EU passport; or a crypto-native payment processor that handles the fiat-to-crypto conversion without requiring the project to hold a bank account for the purchase flow. Each option carries a different KYC burden on the project's users and a different exposure to account-closure risk if the project's token classification becomes contested.
For projects with a seven-figure or larger treasury, the banking question extends to asset segregation: how are fiat reserves, stablecoin reserves and native tokens held, and what happens to users if the project entity becomes insolvent? German law expectations around client-money segregation – which apply to regulated entities – are increasingly referenced by BaFin in its supervisory communications about crypto businesses, even where formal regulatory status is not yet established.
The cross-border interaction with tax is material here. A German GmbH that receives euro proceeds from NFT sales and holds a crypto treasury will face questions about the tax treatment of token issuance proceeds, the deductibility of smart-contract development costs, and the VAT status of NFT sales. Germany's tax authority (the Bundeszentralamt für Steuern and the relevant Finanzamt) does not treat NFTs uniformly: the VAT analysis turns on whether the sale is a supply of a digital service, a supply of a unique work, or something else. These questions are jurisdiction-specific and should be resolved before the first sale, not after.
Cross-border reality: Selling to German users from outside the EU
A common structural choice for early-stage NFT projects is to incorporate outside Germany – in the BVI, Cayman Islands, or UAE – and to sell to a global user base including German residents. That structure does not insulate the project from BaFin's reach. BaFin applies its supervisory jurisdiction on the basis of where the service is actively directed, not where the operator is incorporated.
Under the MiCA framework, a non-EU issuer of crypto-assets that actively markets to EU retail clients may be required to comply with whitepaper obligations and, depending on the token type, to seek CASP authorisation. The "reverse solicitation" exemption – the concept that a client who approaches a non-EU provider entirely on their own initiative is not subject to the EU marketing rules – is interpreted narrowly by ESMA and by BaFin. A project with a German-language social media account, German influencer partnerships or geo-targeted advertising is unlikely to satisfy the reverse-solicitation threshold.
The practical consequence is that most NFT projects with any material German-user exposure need either a MiCA-compliant EU entity or a deliberate, documented geo-blocking and non-solicitation architecture that is robust enough to survive regulatory scrutiny. Partial measures – a click-through disclaimer without IP geoblocking – are not sufficient.
In a recent structuring matter, a digital-collectibles platform incorporated in a Gulf free zone was expanding its European user base. Its existing terms of service used a non-EU choice of law and made no reference to MiCA. We advised on a dual-entity structure: the Gulf entity retained custody of the intellectual property and the smart-contract deployment, while a newly incorporated EU entity took on the user-facing commercial terms and the MiCA whitepaper obligations. The platform was able to continue operating its existing non-EU user base from the Gulf entity while building a compliant EU channel in parallel.
If a prior application stalled or a bank account was closed, a structural review can surface the cause and the route back. Write to OBOLUS at info@oboluslaw.com or message us at t.me/oboluslaw.
Self-assessment checklist for NFT project founders considering the German market
Before engaging German counsel or filing anything with BaFin, a project team should be able to answer – in writing – the following questions. The answers shape the entire legal and compliance architecture.
- What rights does the NFT confer, and have those rights been tested against the MiCA taxonomy and the German securities law definition of a transferable security?
- Is the token genuinely unique and non-fungible, or are there series characteristics, fractionalisation features or royalty mechanisms that could establish fungibility?
- Does the project operate any secondary marketplace, custody function or exchange service that would constitute VASP activity under German law?
- What entity holds the smart contract, employs the development team, and enters into contracts with German users – and is there a mismatch between those three that creates regulatory or tax exposure?
- Is there a documented AML programme, and has a money-laundering officer been appointed if VASP registration is required?
- What is the fiat on-ramp and off-ramp, and has the banking counterparty seen and accepted the token classification analysis?
- If the project is incorporated outside the EU, is there a geo-blocking architecture or a MiCA-compliant EU entity to manage the German-user exposure?
- Have the smart-contract logic and the off-chain terms of service been cross-referenced to confirm they are legally consistent?
A "no" or "unsure" answer to any of these questions is a structural risk that should be resolved before launch, not after the first BaFin inquiry.
A common assumption that costs projects dearly: the utility-label myth
A common assumption among NFT project teams is that placing a "utility token" label on the whitepaper and restricting the token's use to access to the project's platform settles the legal classification. It does not. BaFin – and, under the MiCA regime, ESMA and the national competent authorities across the EU – assess substance over label. The question is not what the whitepaper calls the token; it is what economic rights the token in fact confers and what a reasonable investor would understand from the project's marketing materials.
Where those materials emphasise future appreciation, secondary-market liquidity, the founding team's track record or the project's growth roadmap, BaFin may treat them as evidence of an investment offer regardless of the utility characterisation. The relevant test is an objective one, applied at the time of the offer – which means that marketing copy written before the legal analysis is completed can, and regularly does, create classification problems that no subsequent re-labelling can fix.
We assess classification against the substance of the rights conferred, not the marketing label. In practice, that means reviewing not only the whitepaper but the Discord announcements, the social media campaign and the secondary-market mechanics before the token classification memo is finalised.
Related at OBOLUS
- DeFi, Tokenization & Smart-Contract Law – the full practice overview for on-chain legal structuring and DeFi protocol advice
- Cross-chain bridge legal risk in South Africa – a comparative analysis of smart-contract liability across emerging-market digital-asset regimes
- Fund domicile selection in Lithuania – EU entry structuring options for digital-asset funds and CASPs considering a MiCA-passport hub
FAQ
Can a DeFi protocol be regulated?
Yes. BaFin and ESMA have both indicated that decentralised labelling does not automatically remove a protocol from the regulatory perimeter. Where a de-facto central operator, developer team or governance token holder can exercise meaningful control over the protocol, regulators in Germany and across the EU will assess whether the protocol's functions – lending, exchange, custody – constitute regulated activities requiring authorisation under the applicable regime.
What legal wrapper suits a DAO?
German law does not recognise a DAO as a legal entity. An unincorporated DAO whose members take active decisions risks being treated as a civil-law partnership, exposing members to personal liability. Practical wrappers used in cross-border DAO structures include a Swiss association, a Cayman foundation company, a Marshall Islands DAO LLC and, for operationally simple structures, a GmbH with governance documents mapped to on-chain voting mechanics. The right choice depends on the DAO's economic model, user base and tax objectives.
Who is liable when a smart contract fails?
Liability for a smart-contract failure in Germany is assessed under general contract and tort law principles. The developer, the project entity and, in some circumstances, the governance token holders who approved a flawed upgrade may each be exposed. Where the smart contract is deployed by a legal entity and the terms of service establish that entity as the contractual counterpart, liability is generally confined to the entity – provided the smart-contract logic and the off-chain terms are legally consistent and no misrepresentation was made about the code's function.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We assess every classification matter against the substance of the rights conferred, not the marketing label – because that is the standard BaFin and ESMA apply. To discuss your NFT project's legal structure, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – specialising in smart-contract legal analysis, DeFi protocol structuring and token classification under EU and German law.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.