Civil Law And Decentralized Autonomous Organization Liability Frameworks In Europe .
Civil Law and Decentralized Autonomous Organization Liability Frameworks in Europe
A Decentralized Autonomous Organization (DAO) is a blockchain-based organization in which governance, voting, treasury management, contractual execution, or other organizational functions are performed partly through smart contracts, tokens, automated protocols and decentralized voting.
The central civil-law problem is simple:
If a DAO causes loss, who is legally responsible—the DAO itself, token holders, developers, delegates, multisig signatories, a foundation/company behind it, or some combination of them?
European law does not yet provide a single, comprehensive DAO civil-liability regime. The legal answer depends heavily on the DAO's structure, the jurisdiction, whether it has a legal wrapper, the functions actually performed by identifiable persons, and the applicable national private law. Recent European legal scholarship likewise identifies legal personality, capacity, jurisdiction and identification of defendants as major unresolved issues. (OUP Academic)
1. Meaning of DAO Liability
DAO liability can arise from several types of conduct:
misappropriation of treasury assets;
unauthorized governance decisions;
defective smart contracts;
hacking;
negligent software development;
misleading token disclosures;
breach of fiduciary duties;
conflicts of interest;
unlawful token issuance;
consumer harm;
data-protection violations;
market manipulation;
breach of contractual obligations;
negligence causing financial loss;
unjust enrichment;
wrongful transfer of digital assets.
The important point is:
Decentralization is a technological characteristic, not automatically a civil-law immunity.
2. The Fundamental European Legal Problem
A traditional company usually has:
Company → Directors → Shareholders → Employees → Creditors
A DAO may instead have:
Protocol → Smart Contracts → Token Holders → Developers → Delegates → Multisig Signers → Front-End Operators → Users
This creates several legal questions:
Does the DAO have legal personality?
Can it own property?
Can it sue or be sued?
Who represents it?
Who owns the treasury?
Are token holders members?
Are governance delegates fiduciaries?
Are developers merely software providers or organizational actors?
Does voting create a partnership or association?
Which country's law applies?
Where is a borderless DAO domiciled?
Who is liable for a defective smart contract?
These questions are particularly difficult because a DAO can operate across many countries simultaneously.
3. DAO Legal Personality
There are broadly four possibilities.
Model 1 — DAO has a legal wrapper
Example:
DAO → Foundation / Company / Association → Members
The legal entity can potentially:
own assets;
enter contracts;
employ people;
sue and be sued;
hold intellectual property;
operate bank accounts;
assume liabilities.
This is legally easier to analyse.
Model 2 — DAO operates through a foundation
A foundation may hold:
treasury assets;
intellectual property;
governance infrastructure;
contractual rights.
The foundation's directors or officers may have duties under the relevant national law.
The DAO's governance layer and the legal entity's governance layer therefore need not be identical.
Model 3 — DAO operates through an unincorporated association or partnership
This creates potentially serious personal-liability issues.
If a court characterises the participants as partners or members of an unincorporated association, individual participants could potentially face personal obligations depending on national law.
Model 4 — Pure code-based DAO
The DAO has:
no company;
no foundation;
no registered office;
no formal directors;
anonymous or pseudonymous token holders;
smart contracts controlling the treasury.
This is the most difficult model.
European legal analysis has recognised that a DAO may be difficult to locate geographically and may create uncertainty over both its legal nature and the liability of participants. (EU Blockchain Observatory and Forum)
4. MiCA and DAOs
The Markets in Crypto-Assets Regulation (MiCA) is highly relevant, but it is important not to treat MiCA as a general DAO law.
MiCA regulates identifiable actors such as:
crypto-asset issuers;
offerors;
persons seeking admission to trading;
crypto-asset service providers.
It also contains civil-liability provisions concerning misleading crypto-asset white papers and regulatory requirements for crypto-asset service providers. (EUR-Lex)
Fully decentralised activities
MiCA's Recital 22 provides that crypto-asset services provided "in a fully decentralised manner without any intermediary" are outside MiCA's scope.
However, ESMA states that whether a platform is genuinely fully decentralised is assessed case by case. (ESMA)
Therefore:
Using the word "DAO" does not automatically make an activity outside MiCA.
If identifiable persons or entities retain significant control, provide services, operate infrastructure or perform regulated functions, other EU regulatory regimes may become relevant.
5. DAO Treasury Liability
A DAO treasury may contain:
ETH;
BTC;
stablecoins;
governance tokens;
NFTs;
tokenised securities;
DeFi positions;
liquidity-provider positions.
Mismanagement can occur through:
unauthorized transfers;
fraudulent proposals;
governance manipulation;
compromised private keys;
multisig failure;
conflicts of interest;
malicious smart contracts;
negligent investment decisions.
Example
A DAO treasury contains €20 million.
Five multisig signatories approve a transfer of €5 million to an entity controlled by one signatory.
Potential legal questions include:
Was the transaction authorized?
Was there a conflict of interest?
Was the signatory a fiduciary?
Did the DAO's rules impose duties?
Was the transfer a breach of contract?
Can the €5 million be traced?
Can the recipient be sued?
Can the signatory be personally liable?
6. Case Law 1 — Tulip Trading Ltd v Bitcoin Association
Tulip Trading Ltd v Bitcoin Association for BSV & Ors [2023] EWCA Civ 83
This is one of the most important European authorities for decentralized blockchain governance.
The claimant lost access to substantial Bitcoin following a hack and argued that developers controlling the relevant networks owed fiduciary and tortious duties requiring them to assist in recovering the assets.
The Court of Appeal allowed the claim to proceed at the relevant procedural stage because the proposed duties were sufficiently arguable. It did not establish that every blockchain developer is automatically a fiduciary. (Bailii)
DAO relevance
The case raises the fundamental question:
Can persons exercising meaningful control over decentralized infrastructure owe legal duties to users?
This is directly relevant to:
DAO developers;
protocol maintainers;
governance administrators;
multisig operators;
core contributors.
Principle
Technical decentralization does not automatically prevent a court from examining whether identifiable actors have assumed legally relevant responsibilities.
7. Case Law 2 — Lehtimaki v Cooper
Lehtimaki v Cooper [2020] UKSC 33
This case concerned fiduciary obligations in the governance of a charitable foundation.
Although it was not a DAO case, its significance lies in governance through delegated decision-making.
The case demonstrates that where a person undertakes a role involving decision-making for another's interests, fiduciary obligations may arise depending on the relationship and function.
DAO application
Consider:
Token holders → elect delegate → delegate votes on treasury proposal.
If the delegate has undertaken to act for the DAO or its members, questions can arise concerning:
loyalty;
conflicts of interest;
misuse of voting power;
secret profits;
unauthorized self-dealing.
Principle
The legal character of a governance role depends on the substance of the responsibility undertaken, not merely its technological form.
Tulip Trading itself relied on the fiduciary principles discussed in Lehtimaki. (Bailii)
8. Case Law 3 — FHR European Ventures LLP v Cedar Capital Partners
FHR European Ventures LLP v Cedar Capital Partners LLC [2014] UKSC 45
The Supreme Court held that a bribe or secret commission received by an agent in breach of fiduciary duty can belong beneficially to the principal.
DAO relevance
Suppose:
DAO delegate negotiates a protocol investment.
The delegate secretly receives:
€500,000 from the counterparty.
Potential legal issues include:
conflict of interest;
secret profit;
fiduciary breach;
restitution;
proprietary remedies.
The principle is useful for DAO governance where an identifiable fiduciary exercises delegated power.
Principle
A governance participant cannot necessarily exploit entrusted authority for personal gain merely because the governance mechanism is blockchain-based.
9. Case Law 4 — Wang v Darby
Wang v Darby [2021] EWHC 3054 (Comm)
The dispute involved cryptocurrency and whether a trust relationship arose concerning Tezos transferred between the parties.
The court accepted, for the purposes of the case, that cryptocurrency such as Tezos could constitute property capable in principle of being subject to a trust. (Bailii)
DAO relevance
This is important for DAO treasury disputes.
If DAO assets are legally treated as property, questions arise concerning:
beneficial ownership;
trusts;
constructive trusts;
proprietary claims;
tracing;
restitution.
Example
If a DAO treasury is wrongfully transferred to a contributor's wallet, the claimant may potentially seek:
declaration + proprietary injunction + tracing + restitution.
10. Case Law 5 — AA v Persons Unknown
AA v Persons Unknown [2019] EWHC 3556 (Comm)
The English High Court recognised Bitcoin as property capable of supporting proprietary relief.
DAO relevance
DAO treasury disputes frequently concern digital assets rather than conventional bank money.
Recognition of crypto-assets as property allows courts to consider familiar private-law remedies such as:
proprietary injunctions;
freezing orders;
tracing;
restitution;
constructive trust.
Principle
The digital nature of an asset does not necessarily prevent conventional property remedies from applying.
This becomes particularly important when DAO treasury assets are stolen or misappropriated.
11. Case Law 6 — D'Aloia v Persons Unknown
D'Aloia v Persons Unknown [2022] EWHC 1723 (Ch)
The case concerned cryptocurrency fraud and tracing.
The court considered proprietary claims involving crypto-assets and questions concerning the location/situs of cryptocurrency for jurisdictional purposes.
DAO relevance
DAO disputes are frequently cross-border.
A treasury transaction could involve:
DAO participants in Germany + developer in Switzerland + wallet in an unknown jurisdiction + exchange in another country.
Tracing and jurisdiction therefore become central.
Principle
Crypto-assets can be the subject of proprietary and tracing analysis, but the claimant must prove the factual chain connecting the original asset to the defendant's asset.
12. Case Law 7 — Piroozzadeh v Persons Unknown
Piroozzadeh v Persons Unknown [2023] EWHC 1024 (Ch)
The case involved cryptocurrency transferred through exchange infrastructure and the difficulties created by pooled or unsegregated wallets.
DAO relevance
DAO treasury structures may involve:
pooled wallets;
multisig wallets;
protocol-controlled liquidity;
bridging contracts;
treasury managers.
If assets are mixed together, tracing can become more complicated.
Principle
Recognition of crypto as property does not automatically guarantee successful tracing.
13. Case Law 8 — LMN v Bitflyer Holdings Inc
LMN v Bitflyer Holdings Inc & Ors [2022] EWHC 2954 (Comm)
This case involved a major cryptocurrency hack and applications concerning disclosure and tracing across cryptocurrency exchanges.
The court considered the practical difficulties of following stolen crypto through multiple addresses and exchanges. (Bailii)
DAO relevance
DAO treasury theft may similarly involve:
DAO wallet → bridge → DEX → mixer → exchange → second wallet.
Courts can potentially use disclosure and tracing mechanisms to identify the path of the assets.
14. Case-Law Summary
| Case | Legal principle | DAO relevance |
|---|---|---|
| Tulip Trading [2023] EWCA Civ 83 | Possible fiduciary/tort duties of blockchain developers | Very high |
| Lehtimaki v Cooper [2020] UKSC 33 | Governance/fiduciary responsibility | Very high |
| FHR European Ventures [2014] UKSC 45 | Secret profits and fiduciary loyalty | High |
| Wang v Darby [2021] EWHC 3054 | Crypto-property and trust | High |
| AA v Persons Unknown [2019] EWHC 3556 | Crypto can constitute property | High |
| D'Aloia [2022] EWHC 1723 | Crypto tracing/proprietary remedies | High |
| Piroozzadeh [2023] EWHC 1024 | Pooling and tracing difficulties | High |
| LMN v Bitflyer [2022] EWHC 2954 | Crypto theft, disclosure and tracing | High |
Important qualification
There remains very limited European reported case law directly deciding DAO civil liability as such. Most of the above authorities concern blockchain developers, governance, cryptocurrency property, fiduciary relationships and tracing rather than a court formally declaring:
"DAO X is liable as a DAO."
That distinction is important for accurate legal research. Current European scholarship continues to identify the legal personality and litigation status of DAOs as unresolved issues. (SSRN)
15. DAO Developer Liability
Developers may potentially face liability where they:
intentionally insert malicious code;
knowingly introduce a security vulnerability;
misrepresent protocol capabilities;
exercise continuing control over user assets;
operate upgrade keys;
manipulate governance;
divert treasury assets;
assume contractual obligations;
breach a fiduciary relationship.
But:
Writing open-source software does not automatically make a developer liable for every loss suffered by users.
The court must identify:
duty;
assumption of responsibility;
control;
breach;
causation;
damage.
Tulip Trading is particularly important because it illustrates the difficulty of converting technical influence into a legally recognised fiduciary relationship. (Bailii)
16. Token-Holder Liability
Token holders are not automatically liable merely because they own tokens.
However, greater risk may arise where token holders:
collectively control governance;
participate actively in management;
approve transactions;
appoint managers;
receive profits;
exercise contractual authority;
operate a legal wrapper;
knowingly participate in wrongful conduct.
The legal analysis therefore should distinguish:
Passive token holder
Holds tokens but does not participate in governance.
Active governance participant
Votes on proposals and directs treasury decisions.
Governance delegate
Exercises authority on behalf of others.
Core contributor
Controls protocol development or administration.
Multisig signatory
Has practical ability to move treasury assets.
These categories can produce very different liability outcomes.
17. DAO as Partnership
One possible judicial characterisation is an unincorporated partnership or association.
The court may examine:
common purpose;
agreement;
contribution;
profit sharing;
control;
management;
representation;
conduct of participants.
If a DAO is legally characterised as a partnership, consequences can be substantial because partners may have personal liability under applicable national law.
But this is not an automatic European rule.
The court would need to apply the relevant national law.
18. DAO as Company
A DAO may instead operate through:
limited company;
public company;
GmbH;
SAS;
BV;
foundation;
association;
LLP or similar structure.
This provides an important liability shield.
Example
DAO governance token holders
↓
Foundation
↓
Smart contract protocol
If the foundation is the contracting entity, creditors may generally need to establish liability against the foundation or specific individuals rather than simply suing every token holder.
19. Smart Contract Liability
A smart contract can perform functions such as:
transferring tokens;
calculating interest;
liquidating collateral;
distributing rewards;
executing votes;
allocating treasury funds.
But:
Code execution and legal enforceability are not necessarily identical.
A transaction may be technically irreversible while the underlying legal relationship remains subject to:
contract law;
mistake;
fraud;
unjust enrichment;
consumer law;
fiduciary law;
property law.
European institutions have recognised continuing legal uncertainty around smart contracts, including questions concerning enforceability and cross-border application. (European Parliament)
20. "Code Is Law" Is Not a Complete Civil-Law Defence
Suppose a DAO smart contract accidentally transfers:
€10 million instead of €100,000.
The blockchain may record the transaction as final.
That does not necessarily answer the legal question:
Who is entitled to the €9.9 million difference?
Traditional civil-law concepts may still become relevant:
mistake;
unjust enrichment;
restitution;
fraud;
negligence;
contractual interpretation.
Therefore:
Blockchain finality ≠ necessarily legal finality.
21. DAO Governance Liability
Governance disputes may involve:
invalid votes;
manipulated voting;
flash-loan voting;
quorum manipulation;
delegation abuse;
conflicted voting;
treasury transfers;
unauthorized upgrades;
malicious proposals.
A civil court may have to determine:
what governance rules applied;
whether the proposal was valid;
whether voting was manipulated;
who had authority;
whether the decision caused damage;
whether the claimant has standing.
22. Treasury Mismanagement
A particularly important DAO liability category is treasury mismanagement.
Example
A DAO treasury has €50 million.
A governance proposal authorises:
€2 million investment.
A delegate secretly invests:
€10 million.
The investment fails.
Potential claims may involve:
breach of fiduciary duty;
breach of governance rules;
negligence;
unauthorized transaction;
restitution;
tracing;
damages.
The critical question is:
Who had legal authority over the treasury?
23. DAO and Consumer Liability
If a DAO provides services to consumers, additional EU consumer legislation may become relevant.
Potential areas include:
unfair contract terms;
misleading commercial practices;
digital services;
consumer information;
crypto-asset disclosures;
data protection.
A DAO cannot necessarily avoid consumer protection simply by replacing conventional contractual language with:
"Accept smart contract."
The legal substance of the relationship remains important.
24. DAO and Data Protection
DAOs may process:
wallet addresses;
IP addresses;
governance records;
voting information;
KYC information;
transaction histories.
Blockchain creates special difficulties because personal information may be:
distributed;
copied;
difficult to modify;
permanently recorded.
Potential liability may concern:
controller identification;
lawful basis;
transparency;
data minimisation;
security;
erasure;
international transfers.
The question:
"Who is the GDPR controller?"
may itself become a DAO governance problem.
25. Cross-Border Liability
A DAO can simultaneously involve:
founder in France;
developers in Germany;
foundation in Switzerland;
token holders in Italy;
front-end operator in Ireland;
treasury wallet controlled globally.
This creates private-international-law questions concerning:
Jurisdiction
Which court hears the case?
Applicable law
Which country's substantive law applies?
Legal personality
Where is the DAO legally situated?
Recognition
Will one country's judgment be recognised elsewhere?
Enforcement
Against whom can judgment be enforced?
European legal scholarship specifically identifies the difficulty of locating a borderless DAO and determining the applicable law as major private-international-law problems. (SSRN)
26. DAO Liability Matrix
| DAO actor | Possible liability |
|---|---|
| Foundation | Contractual/statutory/civil liability |
| Company | Corporate contractual/tort liability |
| Developer | Negligence, contract, fiduciary liability in appropriate circumstances |
| Core contributor | Possible assumption-of-responsibility liability |
| Governance delegate | Fiduciary/governance liability |
| Multisig signatory | Unauthorized transfer/negligence/fiduciary issues |
| Token holder | Usually limited, but potentially greater where active control/partnership is established |
| Front-end operator | Consumer/contract/data/regulatory liability |
| Protocol administrator | Potential contractual/tort/regulatory liability |
| Smart contract itself | Generally not a conventional legal person |
| Anonymous participant | Identification and jurisdiction problems |
27. DAO Liability Test
A European court could approach a DAO dispute through the following sequence:
Step 1 — Identify the legal structure
Is it:
company?
foundation?
association?
partnership?
contractual network?
unincorporated organisation?
pure protocol?
Step 2 — Identify the actors
Who actually:
developed;
controlled;
voted;
signed;
administered;
received funds?
Step 3 — Identify the legal relationship
Was there:
contract?
fiduciary relationship?
agency?
partnership?
tort/delict?
unjust enrichment?
Step 4 — Identify the wrongful act
Examples:
hacking;
unauthorized transfer;
defective code;
fraud;
misleading disclosure;
governance abuse.
Step 5 — Establish causation
Did the conduct actually cause the loss?
Step 6 — Determine the remedy
Possible remedies include:
damages;
restitution;
injunction;
declaration;
tracing;
constructive trust;
freezing order;
account of profits.
28. Remedies in DAO Litigation
A. Damages
Compensation for:
financial loss;
property loss;
contractual loss;
consequential loss;
certain non-material damage.
B. Proprietary injunction
Useful where a claimant asserts ownership of identifiable crypto-assets.
C. Freezing order
Can prevent dissipation of assets.
D. Tracing
Allows a claimant to follow misappropriated assets through transactions.
E. Restitution
Can reverse unjust enrichment.
F. Account of profits
Potentially relevant where a fiduciary improperly profits.
G. Declaration
A court may declare:
ownership;
validity of a governance decision;
existence of a legal relationship;
invalidity of a transaction.
29. Special Problem: DAO Treasury and Insolvency
Suppose a DAO controls:
€100 million.
It owes:
€120 million.
Who is the debtor?
If the DAO has a legal entity, the answer is relatively straightforward.
If there is no legal entity, creditors may have to identify:
contract counterparties;
token holders;
developers;
trustees;
foundation;
partnership members;
wallet controllers.
This makes DAO insolvency significantly more complex than ordinary corporate insolvency.
30. DAO and Criminal/Civil Liability Must Be Distinguished
A person can potentially face:
Criminal/regulatory liability
for fraud, money laundering, market abuse or other offences.
Civil liability
for:
damages;
restitution;
breach of contract;
tort/delict;
fiduciary breach.
Administrative liability
for regulatory violations.
One does not automatically prove the others.
31. Important European Regulatory Direction
MiCA already creates specific obligations for identifiable crypto actors, including requirements that crypto-asset service providers act honestly, fairly and professionally and provide information that is fair, clear and not misleading. (EUR-Lex)
For DLT market infrastructures, EU legislation also expressly contemplates written legal terms identifying rights, obligations, responsibilities, liabilities, governing law and dispute mechanisms. (EUR-Lex)
These developments show a broader European regulatory direction:
Digital infrastructure is increasingly being connected to identifiable legal responsibility.
At the same time, the ECB noted in 2026 that Europe still needs greater legal clarity regarding tokenised-asset ownership, settlement, liability, custody and enforceability of smart-contract outcomes. (European Central Bank)
32. Core Problems in DAO Civil Liability
| Problem | Legal question |
|---|---|
| No legal personality | Who can be sued? |
| Anonymous token holders | Who is responsible? |
| Distributed governance | Who controls the DAO? |
| Smart-contract error | Who owes the duty? |
| Treasury theft | Who owns the assets? |
| Governance manipulation | Was the vote legally valid? |
| Cross-border activity | Which law applies? |
| Pseudonymous wallets | How can defendants be identified? |
| No registered office | Which court has jurisdiction? |
| Code-based contract | What happens when code conflicts with legal rights? |
| Decentralized development | Can developers owe duties? |
| Delegated voting | Can delegates be fiduciaries? |
33. Six Most Important Principles
1. Decentralization does not automatically eliminate liability
Courts examine actual control and relationships.
2. DAO legal personality must be determined
A DAO is not automatically a company or separate legal person.
3. Developers may face duties in appropriate circumstances
Tulip Trading demonstrates that this question can be legally arguable. (Bailii)
4. Governance participants may potentially owe fiduciary duties
This is especially relevant to delegates and persons exercising entrusted authority.
5. Crypto-assets can support conventional property remedies
AA, Wang, D'Aloia, Piroozzadeh and LMN demonstrate the usefulness of property, tracing and restitution concepts.
6. Purely decentralized structures create major jurisdictional uncertainty
The absence of a registered entity can make both jurisdiction and applicable law difficult to determine. (SSRN)
34. Final Legal Framework
The most useful European civil-law formula is:
DAO Liability =
DAO Structure
↓
Legal Personality / Legal Characterisation
↓
Identification of Controllers and Participants
↓
Contract / Fiduciary / Tort / Property Relationship
↓
Governance or Smart-Contract Conduct
↓
Breach or Wrongful Act
↓
Causation
↓
Economic or Other Legally Recognised Damage
↓
Damages / Restitution / Tracing / Injunction / Declaration
35. Conclusion
DAO liability in Europe is presently a framework rather than a single unified doctrine. The central legal challenge is that blockchain governance can distribute practical power among many actors while traditional civil law generally wants to identify a legal person, contractual party, fiduciary, tortfeasor or property holder.
The most significant European authorities are Tulip Trading, Lehtimaki, FHR European Ventures, Wang v Darby, AA v Persons Unknown, D'Aloia, Piroozzadeh, and LMN v Bitflyer. They do not collectively establish that every DAO is a legal entity or that every token holder is personally liable. Instead, they provide the doctrinal tools for analysing control, fiduciary responsibility, crypto-property, tracing, governance and remedies.
The most important practical distinction is:
"DAO" describes an organisational technology; it does not, by itself, determine the civil-law identity of the liable person.
Accordingly, a European court is likely to look beyond the label and examine who created the system, who controlled it, who exercised governance authority, who benefited, what legal relationships existed, and what conduct actually caused the claimant's loss. (OUP Academic)
Ultra-short revision formula
DAO → Legal Personality → Control → Governance → Duty → Breach → Causation → Loss → Tracing → Remedy.

comments