Polish law does not yet impose a bespoke virtual asset service provider (VASP) licence on NFT-specific activity, but it does apply the broader AML/CFT regime (Poland's anti-money-laundering and counter-terrorism-financing law, aligned with the FATF Recommendations) to exchanges and custodians that touch NFTs with payment or financial characteristics. Beyond that baseline, the classification question – whether a given NFT constitutes a financial instrument, an e-money token, an asset-referenced token, or simply a collectible with no regulated status – determines every downstream obligation. Get that question wrong before the mint, and a product launch can become an unregistered securities offering overnight.
This guide walks through the six sequential steps an NFT project should complete before going live in Poland, covering the applicable legal regime, the cross-border interaction with EU law and banking, and the decision points that most often cause delays. Each step opens with a direct answer so readers can locate the analysis that matters to their specific situation.
Step 1: Classify your NFT before you do anything else
Token classification is the threshold question: the legal obligations, the entity structure, and the banking strategy all follow from the answer. Under the MiCA (Markets in Crypto-Assets Regulation) regime – now directly applicable across Poland as an EU member state – NFTs that are unique and not fungible generally fall outside MiCA's core scope. That carve-out is not a blanket exemption. ESMA guidance and the MiCA text are explicit that NFTs issued in large series, or NFTs that carry fractional ownership rights, yield entitlements, or governance-token characteristics, may be reclassified as asset-referenced tokens (ARTs), e-money tokens (EMTs), or other crypto-assets subject to full CASP (Crypto-Asset Service Provider) authorisation requirements.
The classification analysis is driven by substance, not label. A whitepaper calling a token a "utility NFT" does not settle the legal question. What settles it is the bundle of rights the token actually confers: Is there an expectation of profit from others' efforts? Does the token represent a claim on a pool of assets? Can it be redeemed for fiat? Affirmative answers on any of those axes push the instrument toward regulated territory. In our cross-border practice, the projects that face the sharpest regulatory exposure are those that layered yield mechanics or governance votes onto an asset class they marketed as art.
The cross-border dimension compounds this. A Polish-registered entity minting NFTs for buyers in Germany, France, or the Netherlands is operating under MiCA as a single legal instrument. The classification conclusion reached in Warsaw applies – or is challenged – across every EU member state into which the tokens are sold.
For a scoped classification opinion on your token design, contact OBOLUS at info@oboluslaw.com. The process above describes the standard classification path. Your facts – the rights bundle, the buyer base, the yield mechanics – change the analysis.
Step 2: Choose the right legal entity in Poland
The optimal Polish entity type for an NFT project depends on the classification outcome, the team's liability tolerance, and the intended investor or banking relationships. Poland offers several corporate forms; the two most commonly used for digital-asset ventures are the spółka z ograniczoną odpowiedzialnością (sp. z o.o.) – a private limited liability company – and the spółka akcyjna (S.A.) – a joint-stock company used where a public capital structure or institutional investment is anticipated.
For most early-stage NFT projects, the sp. z o.o. structure is appropriate. Minimum share capital requirements are modest relative to EU norms, the governance structure is flexible, and the entity can be incorporated relatively quickly through the Polish court registry (KRS) system. The S.A. structure is better suited where the project anticipates a regulated token offering that requires a prospectus or where institutional co-investors require a share-class structure. Neither form is inherently "crypto-native," so the operating documents – the articles of association and any shareholder or founder agreement – must be drafted to address token-specific contingencies: IP assignment, smart-contract upgrade governance, and the treatment of on-chain treasury assets.
Where the project has a DAO governance layer, the entity question becomes more complex. Poland does not yet have a purpose-built DAO legal wrapper – a position shared by most EU member states. The practical approach is to pair an on-chain governance mechanism with a Polish sp. z o.o. or a foundation structure that holds the IP and treasury, accepts legal liability, and interfaces with banks and regulators. Allied counsel in jurisdictions that have experimented with more explicit DAO frameworks can complement that structure where the token distribution is genuinely cross-border.
Step 3: Register as a VASP if the activity requires it
Poland's AML/CFT regime requires entities that exchange virtual assets for fiat, exchange one virtual asset for another, or provide custody of virtual assets to register with the Polish Financial Intelligence Unit (GIIF) as a virtual currency business (działalność w zakresie walut wirtualnych). NFT marketplaces that only facilitate peer-to-peer sales of unique digital collectibles may fall below that threshold. The moment a marketplace adds a swap function, a wrapped-currency settlement layer, or a custodial wallet, registration obligations are engaged.
The GIIF registration process involves demonstrating AML compliance procedures, appointing an AML officer, implementing customer due-diligence (CDD) policies, and meeting the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer above the applicable threshold) where transactions cross the threshold set by the applicable Polish implementing legislation. Timeline from submission to confirmation varies; projects should budget conservatively, particularly where the business model is novel and the regulator may request supplementary information.
Under MiCA, Poland's national competent authority – anticipated to be the Polish Financial Supervision Authority (KNF) in its capacity as CASP supervisor – will have responsibility for authorising and supervising CASPs passporting into or operating from Poland. Where an NFT project's activity crosses into CASP-regulated territory (for instance, a marketplace that also offers exchange or transfer services), MiCA authorisation in Poland carries the EU passport, allowing the same entity to serve buyers across all EU and EEA states without separate national licences. That passporting benefit is one of the primary structural reasons to choose a Polish entity for an EU-facing NFT build.
Step 4: Structure the IP and smart-contract governance
Intellectual property rights in NFT projects are frequently the most commercially significant assets on the balance sheet, yet they are also the most frequently left unaddressed in the founding documents. In Poland, copyright arises automatically for original creative works, but the default rules under Polish copyright law do not automatically transfer those rights to the entity that mints the NFT. A specific written assignment – compliant with the formal requirements of the Polish Act on Copyright and Related Rights – is required to vest all relevant IP in the project entity before any token is minted.
Smart-contract governance deserves equal attention. A smart contract (self-executing code that automates the performance of agreed terms on a blockchain) is not inherently a legal contract under Polish or EU law, but the obligations it triggers – transfers of value, access rights, royalty flows – will be assessed against general contract law principles when disputes arise. The key governance questions are: Who has upgrade authority over the deployed contract? What happens if a critical bug requires a state change? How is the on-chain treasury managed if a quorum of keyholders is unavailable?
Operators we advise routinely discover that their on-chain governance documents and their off-chain corporate documents conflict on these points. The fix is straightforward: a smart-contract governance annex to the founding agreement, specifying upgrade thresholds, emergency-pause authority, and the relationship between on-chain votes and off-chain board resolutions. It is not glamorous legal work, but it is the document that prevents a seven-figure treasury from being frozen in a disputed multisig.
Step 5: Address the tax and banking stack
The tax treatment of NFT activity in Poland sits at the intersection of corporate income tax, personal income tax (for individual creators), and VAT – all of which interact in ways that are not yet fully resolved by published Polish tax rulings or EU guidance. The general principle is that the proceeds of an NFT sale are taxable income, and that determination of whether the relevant gain is treated as revenue income or capital gain turns on whether the project entity holds the NFTs as trading stock or as an investment asset. Polish corporate income tax rates and the applicable thresholds are set by current legislation; projects should obtain a binding tax ruling (interpretacja indywidualna) from the Polish tax authority before launch to fix the treatment.
VAT on NFT transactions remains one of the most contested questions in EU digital-asset taxation. The European Commission and EU member states have not yet reached a uniform position on whether NFT minting and secondary-market royalties constitute supplies of electronic services for VAT purposes. Until that position is settled, Polish projects transacting with EU consumers face a compliance risk that requires active monitoring.
Banking is the operational constraint that most frequently stalls otherwise well-structured NFT projects in Poland. Polish banks have wide discretion to decline or terminate accounts for digital-asset businesses, and the compliance requirements they impose – AML policy documentation, VASP registration certificates, source-of-funds evidence for treasury crypto – are demanding. The practical approach is to engage a bank that has an explicit digital-asset policy before corporate registration is completed, rather than arriving at the account-opening stage with a company already minting tokens. Where Polish banking proves impractical, allied counsel can map alternative banking relationships in EU jurisdictions with more established digital-asset banking markets.
If your prior banking relationship for a digital-asset build was closed or declined, contact OBOLUS at info@oboluslaw.com. A second review can surface the structural reason and map a route back to a workable banking position.
Step 6: Pre-launch compliance and the decision point
The pre-launch compliance review is the last opportunity to catch a structural problem before it becomes a regulatory enforcement issue or a civil claim by token buyers. It covers four axes: classification confirmation, entity and IP sign-off, AML/KYC procedure sign-off, and disclosure adequacy. The disclosure obligation under MiCA for crypto-assets outside the ART/EMT categories requires a whitepaper that meets the prescribed content standards and is notified to the relevant national competent authority. For pure collectible NFTs below the MiCA threshold, a disclosure document is not legally required but is increasingly expected by institutional buyers, secondary marketplaces, and banking partners.
The decision point at this stage is whether the project is genuinely below the regulated threshold or whether its design – secondary-market royalty flows, fractionalization mechanics, yield-bearing treasury tokens – has pushed it into territory that requires CASP authorisation before the public launch. We have seen projects that ran the full compliance process and discovered at Step 6 that a late-stage product change had reclassified them. The cost of catching that before the mint is a fraction of the cost of a post-launch restructuring or a regulator-initiated wind-down.
A self-assessment checklist for the pre-launch stage:
- Has a written classification opinion been obtained and documented?
- Is all relevant IP vested in the project entity by written assignment?
- Has a smart-contract governance annex been executed?
- Has the VASP/CASP registration or authorisation obligation been assessed and, if triggered, addressed?
- Has a binding tax ruling or formal tax opinion been obtained for the primary income streams?
- Has a banking relationship been confirmed in writing before launch?
- Is the whitepaper (or equivalent disclosure document) compliant with applicable MiCA or national standards?
Which NFT project profile needs which legal pathway?
Different project profiles encounter different regulatory exposure, and the legal pathway varies accordingly.
Profile A – pure digital collectible, no yield, no fractionalization. Classification outcome: likely outside MiCA's core scope and below the VASP registration threshold (assuming no exchange or custody activity). Entity: Polish sp. z o.o., IP-assigned founding documents. Key risk: a secondary market that adds exchange functionality retroactively crosses the threshold without a compliance update. Timeline to launch-ready: typically a matter of weeks once classification is confirmed and documents are prepared.
Profile B – NFT with embedded yield mechanics or governance-token characteristics. Classification outcome: potentially an ART or an "other" crypto-asset under MiCA, triggering whitepaper obligations and potentially CASP authorisation. Entity: Polish sp. z o.o. or, where capital structure matters to institutional investors, an S.A., supported by allied counsel where the token distribution is cross-border. Key risk: launching before the whitepaper is notified; retroactive reclassification by KNF. Timeline: materially longer than Profile A, driven by the CASP authorisation process.
Profile C – fractionalized NFT or NFT-backed investment product. Classification outcome: high probability of financial-instrument status under Polish and EU securities law, or ART/EMT under MiCA, with full prospectus or whitepaper obligations and possible portfolio-management licensing. Entity and structure: complex; the project likely requires a regulated wrapper and an institutional-grade compliance program. Key risk: treating the instrument as a collectible when it is, in substance, a security. Timeline: the longest path, comparable to a regulated token offering.
In our cross-border practice, the most common structural error we see in Polish NFT projects is a Profile B or Profile C project built and launched on a Profile A assumption.
In practice: a misclassified project restructured before enforcement
In a recent matter, a digital-creative collective had minted a series of NFTs that included a secondary-royalty pool distributed pro-rata to token holders. The project had been advised informally that the "utility NFT" label in its whitepaper was sufficient. By the time we were instructed, the tokens were live and the project entity – a Polish sp. z o.o. – had already attracted questions from its banking partner about the nature of the distributed royalty flows. We assessed the rights bundle against the applicable MiCA classification criteria and concluded that the royalty distribution mechanism brought the tokens within the MiCA "other crypto-assets" whitepaper-notification requirement. We prepared the required disclosure document, notified the national competent authority, updated the AML procedures, and restructured the royalty mechanics to reduce ongoing classification risk. The project was brought into compliance before any formal enforcement step was taken and retained its banking relationship. The structural lesson – that royalty distribution characterises the instrument regardless of the marketing label – is one we apply routinely on classification reviews.
Related at OBOLUS
- DeFi, Tokenization and Smart-Contract Law – our core practice covering token structuring, smart-contract governance and DeFi legal analysis for operators worldwide.
- NFT project legal structuring in Ireland – the comparable EU-jurisdiction guide for projects considering an Irish entity as their MiCA CASP base.
- Staking and rewards taxation in Georgia – how a low-tax jurisdiction structures yield-bearing digital-asset activity for cross-border operators.
FAQ
Can a DeFi protocol be regulated?
Yes – the absence of a central operator does not automatically place a DeFi protocol outside regulation. Under MiCA and applicable national AML regimes, the question turns on whether identifiable persons perform regulated activities: operating an exchange, providing custody, or issuing a token that meets the ART or EMT definition. Where a smart contract operates autonomously but a development team or governance-token holders make upgrade decisions, regulators increasingly treat those actors as the regulated persons. Classification and the identity of the legally accountable party must be assessed on the specific facts of each protocol.
What legal wrapper suits a DAO?
Most EU jurisdictions, including Poland, do not have a purpose-built DAO legal wrapper. The standard approach is to pair the on-chain governance structure with an off-chain legal entity – most commonly a limited liability company or a foundation – that holds IP, employs the team, manages banking, and accepts legal liability to third parties. The articles of association or foundation deed should mirror the on-chain governance rules as closely as possible to reduce the risk of conflict between token-holder votes and board resolutions. Where the DAO is cross-border, the entity jurisdiction is chosen for tax efficiency, banking access and regulatory posture.
Who is liable when a smart contract fails?
Liability for a smart-contract failure is assessed under the general contract and tort law of the applicable jurisdiction, not under a specific smart-contract statute. In Poland and across the EU, the person or entity that deployed the contract, marketed it to users, and profited from its operation is the most exposed party. Where the failure results from a bug in audited code, the audit firm's liability depends on the scope of its engagement. Where the failure is the result of an economic exploit, the analysis turns on whether the vulnerability was a known risk that was not disclosed and whether the project's governance documents conferred an emergency-pause right that was not exercised.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights conferred, not the marketing label, and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialises in smart-contract governance, token classification and DeFi regulatory analysis for projects operating in EU and cross-border environments.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.