A decentralized autonomous organization without a legal wrapper is, in most commercial jurisdictions, an exposed general partnership: every token-holding participant potentially shares unlimited liability. In Hong Kong, where the Securities and Futures Commission (SFC) operates one of the most active virtual asset trading platform (VATP) licensing regimes in Asia, that exposure is not theoretical. Mis-classifying a token can convert a product launch into an unregistered securities offering – and the SFC has demonstrated its willingness to act. This guide sets out the sequential steps a DAO founding team should work through to establish a defensible legal wrapper in Hong Kong, from entity selection through token classification and smart-contract governance to banking and cross-border tax interaction.
The direct answer is this: a Hong Kong-incorporated limited company or, in appropriate cases, a limited partnership fund, is the most commonly used DAO legal wrapper in the jurisdiction. The choice turns on the DAO's economic model, its token structure and whether it has investment-fund characteristics. Neither wrapper is self-executing – the SFC's VASP licensing regime for trading platforms, the applicable financial-promotion rules and the FATF Travel Rule all interact with how the wrapper is designed. The sections below walk through each decision point in order.
Why Hong Kong for a DAO Legal Wrapper?
Hong Kong is a common-law jurisdiction with sophisticated courts, a developed blockchain-advisory ecosystem and a regulator – the SFC – that has published detailed guidance on virtual assets, token classification and operator obligations. That clarity is commercially valuable. A DAO founding team choosing between Singapore (governed by the MAS under the Payment Services Act) and Hong Kong will find that both jurisdictions apply substance-over-label classification logic, but Hong Kong's VATP licensing regime and the SFC's token-classification framework offer a well-documented path for teams willing to engage with the regime rather than try to avoid it.
The SFC has also demonstrated willingness to recognize hybrid structures. In our cross-border practice, we have seen regulators in leading hubs – including the SFC – engage constructively with founding teams that arrive with a complete governance and token-classification analysis rather than a whitepaper drafted to minimise regulatory contact. That posture is worth building into the project from day one.
A second dimension is enforcement. Hong Kong's courts, including the Court of First Instance, have confirmed that crypto assets constitute property capable of being the subject of injunctive relief. The decision in Re Gatecoin [2023] HKCFI 914 established that crypto assets held by an exchange are property for insolvency purposes. That legal certainty matters for a DAO: it means on-chain assets held through a properly structured wrapper can be the subject of enforceable rights and court orders.
CTA: The process above describes the standard path. Your facts – the entity, the token structure, the user base and the banking – change the analysis. Map your options with OBOLUS before you commit to a structure.
Step 1: Choose the Right Entity Type
The first step is selecting an entity form that gives the DAO legal personality, limited liability and a governance structure compatible with on-chain voting. Three options are in regular use in Hong Kong.
A private limited company incorporated under the Companies Ordinance is the default. It offers limited liability, a familiar counterparty identity for banks and service providers, and the ability to issue shares or tokens that track governance rights. Its weakness for a DAO is rigidity: the Companies Ordinance's default rules on director authority do not map cleanly onto token-weighted voting. The articles of association must be carefully drafted to delegate authority to smart-contract outcomes and to define the interface between on-chain governance and off-chain legal obligations.
A limited partnership suits DAOs that operate as investment vehicles – pooled capital deployed through on-chain strategies. Hong Kong's Limited Partnership Fund Ordinance provides a modern framework for this structure. The general partner carries management responsibility and liability; limited partners are protected. For a yield-generating DeFi protocol with identifiable economic interests, this structure may be cleaner from a regulatory and tax perspective.
A foundation company limited by guarantee suits protocol DAOs that do not distribute profits: open-source infrastructure, public-goods funding, or grant-allocation DAOs. There are no shareholders; the company is governed by its constitution and by whatever on-chain mechanisms are written into the governance rules. Banking is more difficult for this form, but it is the cleanest structure where the DAO genuinely has no commercial profit motive.
The choice between these three forms should be made only after token classification – because the token's legal characterisation may determine which entity type is legally required, not merely commercially preferred.
Step 2: Classify the Token Before Anything Else
Token classification under the SFC's framework is the single highest-stakes decision in a Hong Kong DAO structure. A governance token that confers rights to profits, to a share of protocol revenue or to management of an investment pool may be a security as defined under the Securities and Futures Ordinance. If it is, the full weight of the SFC's licensing and disclosure regime applies – and operating without the appropriate licence is a criminal offence.
The SFC applies a substance-over-label test. A common assumption is that attaching a "utility" label on a whitepaper settles the legal classification. It does not. The SFC looks at the rights actually conferred: does the token entitle the holder to a share of profits? Does it give economic exposure to an underlying asset pool? Is the value of the token tied to the managerial efforts of a promoter group? If the answer to any of those questions is yes, the token is likely a security regardless of how it is described.
In practice, classification analysis runs across four categories: governance-only tokens (lowest regulatory risk), utility tokens (access to services; moderate risk if the service is itself regulated), revenue-sharing tokens (high risk; likely securities), and tokens with fund-like economics (almost always securities). Each category maps to a different set of SFC obligations and a different entity structure.
This classification must be documented. The SFC expects operators to be able to demonstrate that they conducted a legal analysis of their token before going to market. An undocumented classification decision is no defence in an enforcement proceeding.
Step 3: Draft the Governance Documents
Governance documentation translates on-chain mechanics into enforceable legal terms. It is also the point at which most DAO structures fail: the smart contract governs token-weighted voting, but there is no document that specifies what happens when the smart contract is upgraded, when a governance vote conflicts with applicable law, or when a director of the wrapper entity receives an instruction from a governance vote that would require the company to breach a regulatory obligation.
The core documents for a Hong Kong DAO wrapper are: the company's articles of association (which should reference the governance protocol explicitly), a governance protocol document (which defines the voting mechanism, quorum rules and the relationship between on-chain outcomes and off-chain obligations), a token terms document (which sets out the legal characterisation and the rights attached to the token), and – where the DAO has contributors or service providers – a set of contributor agreements that establish the legal relationship between the DAO entity and its participants.
The governance protocol document is the most operationally important. It should address at minimum: how on-chain votes translate into binding instructions to the directors; the process for amending the smart contract; the mechanism for emergency intervention if a vulnerability is discovered; and the forum and governing law for disputes between token holders and the entity. For a Hong Kong entity, the governing law will ordinarily be Hong Kong law, which provides certainty and access to the Court of First Instance's established crypto jurisprudence.
Smart-contract audits are not a legal document, but they are a legal input. A well-structured DAO wrapper will include a requirement – either in the articles or in the governance protocol – that material smart-contract changes are subject to an independent security audit before deployment. This protects the entity from liability exposure in the event of a contract failure.
Step 4: Map the SFC and VASP Obligations
Once the entity is selected and the token is classified, the next step is to determine whether any of the DAO's activities require a licence or registration under the SFC's VASP licensing regime or under any other applicable Hong Kong regulatory regime.
The SFC's VATP regime applies to platforms that operate a trading venue for virtual assets. A DAO that deploys an automated market-maker protocol or a decentralised exchange may or may not fall within this definition – the analysis turns on the degree of centralisation in the protocol and the role of the DAO entity in its operation. This is not a bright line. The SFC has signalled that it will look at substance rather than form: a nominally decentralised protocol controlled by a small group of key-holders may be treated as a centralised platform for regulatory purposes.
If the DAO's token is classified as a security, additional obligations apply: prospectus requirements, intermediary licensing if the token is offered to the public, and – if the DAO operates a secondary market – potential VATP licensing. The SFC's recognised virtual assets framework determines which assets may be traded on a licensed platform.
AML/CFT obligations apply to any entity within the regulatory perimeter. Under the applicable FATF Recommendation 15 principles, virtual asset service providers are expected to implement customer due diligence, transaction monitoring and – above applicable thresholds – the Travel Rule (the obligation to pass originator and beneficiary data with a transfer). A DAO wrapper that interacts with end users in a way that constitutes a VASP activity will need a compliance programme designed around these requirements.
CTA: If a prior application stalled or a token classification analysis reached an inconclusive result, a second read can surface the structural reason and the route forward. Map your options with OBOLUS.
Step 5: Solve the Banking and Cross-Border Tax Stack
A Hong Kong DAO wrapper that cannot open a corporate bank account is operationally inert. Banking for crypto-native entities in Hong Kong is challenging but achievable. The key is presenting the bank's compliance team with a complete picture: a clean corporate structure, documented token classification, an AML/CFT programme, and a clear answer to the question of where the DAO's revenue comes from and where it goes.
The cross-border dimension is almost always present. A DAO incorporated in Hong Kong may have contributors in the EU, users in Singapore, treasury assets on-chain and a secondary incorporation in the BVI or Cayman Islands for fund-structuring purposes. Each of those connections creates a tax touchpoint. Hong Kong operates a territorial tax system: only profits arising in or derived from Hong Kong are subject to profits tax. On-chain protocol revenues may or may not have a Hong Kong source – the analysis depends on where the relevant activities that generated the profit were carried out.
Token issuance has its own tax dimension. The treatment of token proceeds – whether as capital (not taxable in Hong Kong) or revenue (taxable) – is not settled in all fact patterns. Staking rewards, liquidity provision fees and governance-vote compensation each require separate analysis. Where a DAO has contributors who are tax-resident in multiple jurisdictions, the wrapper structure should be designed with those obligations in mind from the outset, not retrofitted after the token has launched.
We structure licensing, banking and tax as one mandate rather than three disconnected workstreams. In our experience, the most common structuring failure for inbound DAO teams is optimising the entity form for one dimension – typically regulatory – while leaving banking viability and tax efficiency to be solved later. That sequencing is expensive to correct.
In a recent matter, a DeFi protocol team approached us after incorporating a Hong Kong company and launching a governance token without completing a token classification analysis. The token had revenue-sharing features that created a credible securities classification risk. We conducted a classification analysis, restructured the token economics to separate governance rights from revenue participation, updated the governance documentation and prepared the AML/CFT programme. The entity was positioned to engage with the SFC's formal guidance process without the prior launch posture being treated as a precedent. The matter concluded in the team's favour before any formal enforcement step was taken.
Step 6: Build the Ongoing Compliance Architecture
A DAO legal wrapper is not a one-time filing. It is a living compliance architecture that must evolve as the protocol evolves, as the SFC's guidance develops and as cross-border regulatory expectations shift.
The minimum ongoing compliance obligations for a Hong Kong DAO wrapper include: annual return filings and maintenance of the company register; AML/CFT programme review and update (at least annually, and whenever the protocol adds a material new activity); governance protocol review whenever a smart-contract upgrade changes the economic or voting rights attached to the token; and a periodic token classification review to confirm that the original classification remains accurate as the protocol grows.
For DAOs that have obtained or are seeking a licence under the SFC's VATP regime, the compliance obligations are more extensive: periodic reporting to the SFC, ongoing capital adequacy monitoring, client asset segregation, and technology risk management. These requirements are set out in the SFC's VATP rulebooks and should be mapped to internal processes before the licence application is submitted.
The cross-border compliance dimension is ongoing. A DAO with users in the EU will need to consider whether MiCA's CASP (crypto-asset service provider) authorisation requirements apply to its activities as they expand. A DAO with US-based participants will need to monitor SEC and CFTC guidance on DeFi. These are not hypothetical risks – they are active regulatory development areas. We have seen regulators in multiple jurisdictions issue guidance specifically addressing DAO governance structures within the past two reporting cycles.
Decision Matrix: Which Profile Fits Which Wrapper
The right wrapper for a Hong Kong DAO depends on the team's profile, the token's economics and the protocol's activities. The following analysis sets out three common profiles.
Profile A – Governance-and-grants DAO: The protocol is open-source infrastructure. The token confers voting rights only; there is no revenue distribution. The appropriate wrapper is a foundation company limited by guarantee. The timeline from incorporation to operational launch is typically a matter of weeks for the entity itself; the governance documentation and AML/CFT programme add further preparation time. The key risk is banking friction: foundations with no commercial revenue are difficult counterparties for retail banks, and a virtual-asset-friendly banking relationship must be sourced early.
Profile B – Revenue-generating protocol DAO: The protocol generates fees. Token holders receive a share of those fees. This profile carries high securities classification risk. The appropriate wrapper is a private limited company, but only after a formal token classification analysis confirms that either the token is not a security or the entity has the appropriate SFC licence. The timeline is materially longer than Profile A because the classification analysis and, if required, the licence application must precede the public token launch. Operating in reverse – launching first and classifying later – is the most common and most expensive mistake we see.
Profile C – Investment-pool DAO: The protocol pools capital and deploys it through on-chain strategies. Token holders have economic exposure to the pool's performance. This profile has fund-like characteristics and may require a Limited Partnership Fund structure and a fund-manager licence. The SFC's oversight of fund management extends to DeFi-native structures where the economic substance is investment management. Timeline and capital requirements vary by the licence category sought and should be confirmed against the SFC's current guidance.
Operators we advise routinely encounter a fourth profile: a protocol that started as Profile A and evolved into Profile B or C over time. The regulatory risk in that transition is significant. A token that was correctly classified as governance-only at launch may become a security when the protocol adds revenue distribution – and that reclassification event triggers disclosure and licensing obligations that may not have been anticipated in the original wrapper design.
Related at OBOLUS
- DeFi, Tokenization and Smart-Contract Law – legal structuring for DeFi protocols, token issuers and smart-contract-based businesses
- NFT Project Legal Structuring in Gibraltar – entity selection, token classification and regulatory positioning for NFT projects
- How to Build Economic Substance for a Licensed VASP – substance requirements across the leading licensing hubs
FAQ
Can a DeFi protocol be regulated?
Yes. Whether a DeFi protocol is regulated in Hong Kong depends on its activities and the degree of centralisation in its operation. The SFC applies a substance-over-label test: a nominally decentralised protocol that is controlled by an identifiable group may be treated as a regulated trading platform. Token classification, the nature of the protocol's activities and its user base all feed the analysis. Teams should conduct a formal regulatory scoping review before launch rather than assume decentralisation confers exemption.
What legal wrapper suits a DAO?
In Hong Kong, the most common wrappers are a private limited company, a limited partnership fund and a foundation company limited by guarantee. The right choice depends on the DAO's token economics, its governance model and whether it has investment-fund characteristics. A governance-and-grants DAO typically suits a foundation; a revenue-generating protocol suits a private limited company subject to token classification; an investment-pool DAO may require a limited partnership fund structure and a fund-manager licence from the SFC.
Who is liable when a smart contract fails?
Liability for a smart-contract failure in Hong Kong follows general principles of contract, tort and, where applicable, the Securities and Futures Ordinance. A properly structured DAO wrapper with clear governance documentation and a record of pre-deployment security audits significantly reduces – but does not eliminate – that exposure. Without a legal wrapper, contributors to the protocol may be treated as partners in a general partnership, with the unlimited personal liability that implies. The wrapper insulates individuals; the governance documents define the boundaries of institutional liability.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your DAO structure, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology and DeFi Counsel – specialising in smart-contract governance, token classification and DeFi protocol structuring across common-law jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.