Real-world asset tokenization in Turkey sits at the intersection of capital markets law, digital-asset regulation, and cross-border structuring – a combination that demands precise legal analysis before a single line of smart-contract code is deployed. Turkey's Capital Markets Board (Sermaye Piyasası Kurulu, or CMB) holds primary supervisory authority over instruments that may constitute capital market products, and a mis-classified token can convert a product launch into an unregistered securities offering under the applicable CMB regime. This guide walks through the legal steps an issuer, platform operator, or fund manager must complete to tokenize a real-world asset in Turkey, and it addresses the cross-border structuring decisions that follow.
What is real-world asset tokenization and how does Turkey's legal regime apply?
Real-world asset tokenization is the process of representing ownership rights, economic entitlements, or debt claims over a physical or financial asset – real estate, receivables, commodities, or fund units – as a cryptographic token recorded on a distributed ledger. In Turkey, that token is not automatically treated as a simple payment instrument. The CMB has established that instruments conferring rights similar to securities, fund units, or structured products fall within the capital markets perimeter, regardless of the technology used to represent them. The governing principle is substance over form: what matters is the nature of the rights the token confers, not the label on the whitepaper.
Turkey also operates a dedicated crypto-asset regime administered by the CMB, which brought crypto-asset service providers (CASPs) – exchanges, custodians, and transfer platforms – under registration and operational rules. That regime governs secondary-market infrastructure, not the issuance itself. Issuers of tokenized assets must assess classification under both the capital markets framework and the CASP regime, and often under the Banking Regulation and Supervision Agency (BDDK) rules where a token resembles a deposit or payment product.
Two regulatory bodies therefore matter at the outset: the CMB for securities and capital-market products, and the BDDK for anything that touches payment, deposit, or lending mechanics. Issuers operating from abroad who direct a Turkish-resident investor base face the same analysis – jurisdiction is determined by where the product is offered, not where the issuer is incorporated.
The process above describes the standard classification path. Your facts – the underlying asset, the investor base, the smart-contract architecture – change the analysis materially. For a scoped initial assessment, contact OBOLUS at info@oboluslaw.com or map your options here.
Step 1: Determine whether your token is a capital market instrument
Classification is the first and most consequential step in any Turkish real-world asset tokenization project, because it determines which regulatory pathway – and which regulator – governs every subsequent decision. The CMB applies a substance-based test: a token that grants the holder a right to profits, a residual claim on assets, or a voting right over an enterprise will typically be treated as a capital market instrument, triggering the full suite of prospectus, offering, and registration requirements under the applicable CMB rules.
Tokens representing receivables or debt obligations are similarly scrutinized. A receivables-backed token that promises periodic payments and a defined redemption amount shares the economic profile of a debt security. The CMB has consistently held that economic substance, not technical architecture, governs classification. A utility label in a whitepaper does not, by itself, exclude the token from the capital markets perimeter – a point we address in the myth-busting section below.
Three classification outcomes are possible. First, the token is a capital market instrument and requires a prospectus, CMB registration, and likely a licensed intermediary. Second, the token falls outside the capital markets perimeter but is still a crypto-asset under the CASP regime, attracting its own operational and custody requirements. Third, the token has characteristics of a payment instrument, bringing the BDDK into the frame. Many real-world asset tokens straddle the first and second categories simultaneously, particularly where a secondary-market function is built into the protocol.
Common mistake at this step: assuming that structuring the token as a "governance" instrument removes it from the securities analysis. Governance rights that carry economic value – fee entitlements, redemption rights, or participation in a token buyback – are routinely examined for their economic substance, not their label.
Step 2: Choose the correct legal wrapper for the issuer
The issuer's legal form shapes the enforceability of investor rights, the tax treatment of distributions, and the viability of the chosen custody and transfer architecture. In Turkey, common issuer structures for tokenized assets include a joint-stock company (anonim şirket), a fund vehicle established under CMB rules, or a special-purpose vehicle with a cross-border parent – typically domiciled in a jurisdiction with a developed crypto-asset or securities regime, such as the ADGM in Abu Dhabi or the AIFC in Kazakhstan, with the Turkish operational entity acting as originator or servicer.
The cross-border SPV route is frequently chosen by issuers who want access to an established regulatory and contractual framework for the tokenization itself while retaining a Turkish asset base. Under this structure, the SPV holds legal title to the asset (or holds the benefit of a charge over it), issues the tokens, and contracts with a Turkish entity for origination, servicing, and distribution. The critical legal question in this structure is whether the offer of tokens to Turkish residents triggers a Turkish prospectus or registration obligation regardless of the SPV's domicile. The answer turns on the marketing and distribution conduct, not the issuer's corporate address.
Where the asset base is Turkish real estate, additional constraints apply. Turkish law restricts certain categories of direct foreign ownership, and a tokenization structure that effectively transfers beneficial ownership to foreign investors must be mapped against those restrictions before issuance. A fund structure authorized by the CMB may resolve this, but it introduces its own licensing and minimum-capital requirements that vary by fund category.
Step 3: Commission a smart-contract legal review before deployment
A smart contract deployed on a public blockchain is, in substance, a legal instrument – and Turkish courts and regulators will assess it as one. The legal review at this stage is not a code audit; it is a mapping exercise between the on-chain logic and the off-chain legal obligations the issuer has assumed. Three mismatches generate most of the liability exposure we see in practice.
First, the token's transfer mechanics may not reflect the investor rights stated in the offering document. If the smart contract permits unrestricted secondary transfers but the offering documentation limits resales to qualified investors, the issuer faces a distribution compliance problem the moment the first secondary transfer occurs. Second, upgrade and governance mechanisms – proxy contracts, multisig admin keys, DAO voting modules – create ambiguity about who bears fiduciary or contractual responsibility when a protocol parameter changes. Third, the oracle feeding real-world data into the contract (a property valuation, a rental income figure, a commodity price) is a counterparty with legal significance: if the oracle fails or is manipulated, the question of who bears the loss requires a contractual answer, not just a technical one.
In our practice, we conduct the smart-contract legal review in parallel with the offering-document drafting, so that the two are consistent. Regulators increasingly expect this alignment: the CMB and, in analogous matters, ESMA under the MiCA regime have both signaled that technical documentation must be consistent with disclosure obligations. The review also informs the investor agreement and the terms of any custodian or transfer-agent arrangement.
If your smart-contract architecture is already live and a structural review has not been conducted, the exposure window is open. To commission a review, contact OBOLUS at info@oboluslaw.com or map your options here.
Step 4: Build AML, KYC, and Travel Rule compliance into the issuance architecture
Any platform facilitating the issuance, custody, or transfer of tokenized assets in Turkey is subject to anti-money laundering and counter-terrorism financing obligations under the applicable Turkish AML regime, which aligns with FATF Recommendation 15 on virtual assets. The Travel Rule – the FATF obligation requiring that originator and beneficiary information accompany virtual-asset transfers above the applicable threshold – applies to crypto-asset service providers operating in or serving Turkish users.
For an RWA tokenization project, the practical implication is that investor onboarding, token issuance, and secondary-market transfers all require a KYC-compliant investor verification layer. Purely anonymous token transfers are incompatible with Turkish CASP registration requirements. Where the distribution chain involves a licensed intermediary – a CMB-licensed brokerage or a registered CASP – the intermediary's AML programme will impose its own onboarding standards, and the issuer must ensure that the smart contract's transfer restrictions and the intermediary's KYC gate are technically consistent.
Cross-border distributions amplify this complexity. An issuer tokenizing a Turkish asset and distributing to investors in the EU, the UAE, or Singapore simultaneously faces the AML regimes of those destinations. Under MiCA and the EU's Transfer of Funds Regulation, EU-side CASPs will require Travel-Rule data from the Turkish-side transfer agent. Designing the data architecture for this exchange before deployment – not retroactively – is significantly less costly.
Common mistake at this step: treating KYC as a one-time onboarding event. Secondary-market transfers, staking or redemption events, and governance votes that carry economic consequences may each be re-evaluated as qualifying transactions under the applicable threshold rules.
Step 5: Map the tax and banking interaction before the token goes live
Turkey taxes income from crypto-asset transactions under its income tax and corporate tax regimes. The precise characterization of tokenized-asset income – whether distributions are treated as dividends, interest, rental income, or capital gains – depends on the legal structure of the issuer and the nature of the underlying asset. Because the numeric rates are subject to legislative change and verification, we describe the analytical framework rather than quote a figure: an issuer structured as a joint-stock company faces one set of rules; a fund vehicle faces another; a cross-border SPV faces Turkish withholding tax considerations on payments made to or from Turkish residents.
VAT treatment of the token issuance and subsequent transfers is a separate analysis. The Turkish Revenue Administration has provided guidance on the tax treatment of crypto-asset transactions, but that guidance does not comprehensively address the full range of RWA token structures. Where the token represents a real-estate interest, the transfer of that interest may attract real-estate transaction taxes at the underlying-asset level, even if the token transfer itself is a different legal act.
Banking access is a practical constraint that can derail a structurally sound tokenization. Turkish banks have historically applied cautious policies to crypto-asset businesses. An issuer holding a CASP registration or operating under a CMB licence will be in a stronger position to open and maintain business accounts than an unregistered entity, but banking approval is not automatic. In our cross-border practice, we advise clients to engage the banking relationship in parallel with the licensing process – not after authorisation is received – because onboarding timelines at Turkish banks can exceed the time required to complete the regulatory application.
A practical illustration: cross-border RWA tokenization with a Turkish asset base
In a recent structuring matter, a real-estate investment platform sought to tokenize a portfolio of Turkish commercial properties and offer the resulting tokens to institutional investors across multiple jurisdictions. The platform's initial structure placed the issuer in an offshore jurisdiction, with no regulatory analysis of whether the Turkish asset base and Turkish-resident service providers brought the offering within the CMB's perimeter. We identified that the origination and servicing arrangements created a sufficient nexus with Turkey to attract CMB scrutiny of the offering documentation, and that the oracle feeding rental income data into the distribution contract had no contractual liability cap. We restructured the issuer as a CMB-compliant fund vehicle, revised the smart-contract architecture to align transfer restrictions with the investor-category limitations in the prospectus, and engaged allied counsel in the target distribution jurisdictions to clear the offering under their respective regimes. The platform launched on schedule with a legally consistent documentation set across three jurisdictions.
Self-assessment checklist: are you ready to tokenize a real-world asset in Turkey?
Before committing capital to a Turkish RWA tokenization, an issuer should be able to answer each of the following questions affirmatively. If any answer is uncertain, the corresponding step above identifies the legal work required.
- Has the token been classified under both the CMB capital markets framework and the CASP regime, based on the substantive rights it confers?
- Has the issuer legal wrapper been selected with reference to Turkish civil law, capital markets rules, and the tax and banking implications of distributions?
- Has a smart-contract legal review confirmed consistency between the on-chain logic and the offering documentation?
- Is the AML/KYC architecture and the Travel Rule data flow designed into the issuance structure, not bolted on after deployment?
- Has the tax characterization of distributions and the VAT treatment of token transfers been assessed by reference to current Turkish Revenue Administration guidance?
- Has banking access been engaged in parallel with the licensing process, and is the issuer's account-opening position documented?
- Have the distribution jurisdictions been cleared with allied counsel, and are the offering restrictions technically enforced in the smart contract?
A common assumption: the utility label settles legal classification
A common assumption among first-time token issuers is that labeling a token as a "utility token" in the whitepaper resolves the securities-classification question in their favor. It does not – and Turkish regulators are not the only ones who take this view. The CMB, like ESMA under the MiCA regime and the SEC under US federal securities law, assesses classification against the substance of the rights the token actually confers on its holder. A token that grants the holder a proportional claim on rental income generated by a Turkish property is economically a security, regardless of what the whitepaper calls it.
We regularly see issuers who discovered this after launch – when a regulator inquiry or an investor dispute forced the analysis that should have occurred at the design stage. The cost of reclassification after the fact – restructuring the legal wrapper, revising the offering documentation, re-papering investor agreements, and managing any regulatory notification – is a multiple of the cost of getting the classification right at the outset.
In our practice, we assess classification against the substance of rights, not the marketing label. That analysis is the first deliverable in every tokenization engagement we accept.
Related at OBOLUS
- DeFi, Tokenization & Smart-Contract Law – the practice-area overview for token issuers, DeFi protocols, and DAO structures.
- Smart-Contract Legal Review for Regulated Entities – scoped review of on-chain logic against off-chain legal obligations.
- Pre-exit Tax Restructuring in Turkey – structuring decisions for founders and investors ahead of a token or equity exit.
FAQ
Can a DeFi protocol be regulated?
Yes, in substance if not in form. Regulators – including the CMB in Turkey and ESMA under the MiCA regime – assess whether a protocol's economic function places it within a regulated activity category, regardless of whether a legal person operates it. Where a protocol facilitates exchange, lending, or asset management for users, the operator or deployer may be treated as a regulated entity. The analysis turns on who controls the protocol and who benefits from its operation.
What legal wrapper suits a DAO?
No single wrapper is universally appropriate. The choice depends on the DAO's governance model, the economic rights token holders exercise, and the jurisdictions in which it operates or has members. Common options include foundation structures in Switzerland or the Cayman Islands, LLC wrappers in Wyoming, or fund vehicles in regulated jurisdictions. In each case, the wrapper must reflect the actual distribution of control and liability within the DAO, or it will fail under regulatory or judicial scrutiny.
Who is liable when a smart contract fails?
Liability follows the law of the off-chain legal relationship, not the on-chain architecture. If a smart contract fails to execute as the offering documentation described, the issuer or deployer who made that representation is the primary exposure point. Where the failure results from an oracle error, liability may follow the oracle provider's contractual terms. Where an upgrade or governance vote changed contract behavior, the individuals who controlled the multisig or passed the proposal may face personal liability in certain jurisdictions.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance architecture that sits around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – and we bring that discipline to every Turkish RWA tokenization engagement. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialist in smart-contract legal review, token classification, and DeFi protocol structuring for regulated and unregistered digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.