Blockchain Legal in DMCC: Complete Guide
Regulators read a public website as an offer made to whoever can see it.
DMCC incorporates the company and fixes the activities it may carry on; it does not regulate virtual asset business. The article explains which authority does — Dubai's Virtual Assets Regulatory Authority, the Securities and Commodities Authority where a token is a security, the Central Bank where it works as a payment or stable-value instrument — and why the licence and the regulatory permission are separate applications on separate timelines. It also covers matching your activity code to what the business really does, writing and dating a token classification, how marketing and app listings are read as offers wherever users are, and the federal data protection, anti-money-laundering, employment and tax obligations that apply inside the free zone.
A DMCC licence is not a virtual asset permission
The Dubai Multi Commodities Centre has become the default address for crypto companies in Dubai. It offers activity codes that fit token businesses, a cluster of them in one tower complex, and a registration process founders can actually complete. What it does not offer, and does not claim to offer, is financial regulation of virtual asset activity. That comes from a separate authority, and the single most common mistake we see is a founder treating the DMCC licence as the end of the permissions question.
DMCC is the free zone authority. It incorporates your company, issues the commercial licence and sets the activity you are permitted to carry on. Regulatory oversight of virtual asset activity in Dubai outside the DIFC sits with Dubai's Virtual Assets Regulatory Authority, and where a token is a security or a commodity-based instrument the Securities and Commodities Authority is engaged. If your token functions as a means of payment or a stable-value instrument, the Central Bank of the UAE becomes relevant. You may need the free zone licence and a regulatory permission. They are obtained separately, from different bodies, on different timelines.
Match the activity code to what you actually do
Licences are granted for specified activities, and a business that drifts beyond them is operating outside its licence. Proprietary trading with the company's own funds, distributing someone else's platform, running an exchange, holding customer assets and advising on token investments are different activities with different consequences. Founders routinely describe themselves one way to DMCC and another way on the website.
Before the licence is issued, write down in plain language what the business will do: whose money moves, who holds the assets, who bears the loss if something fails, and what the customer is promised. Then check that description against the activity you have applied for. If they diverge, fix it at the application stage rather than at renewal or during an inspection.
Classify the token, in writing, first
Everything downstream depends on what your token is.
- A token conferring profit participation, a claim against the issuer or an interest resembling a security or derivative sits within securities regulation.
- A token used to pay for things, or built to hold a stable value against a currency, engages payment and central bank regulation.
- A token that only unlocks access to your own product, with no investment or payment function, may fall outside financial regulation — but only if the documents and the marketing both support that, not just the documents.
Record the analysis, the date it was made and the facts it relied on. Product changes, so revisit it when the product does. A classification kept on file is a defence; a classification remembered by the founder is not.
Marketing reaches further than your licence does
A DMCC company that promotes to retail users across Dubai, the wider UAE or overseas is making offers where those users are. Regulators read a public website and an app listing as an offer to whoever can see them. Decide which jurisdictions you accept users from, enforce it through onboarding and geo-restrictions, and make sure your terms of service and your marketing say the same thing your systems do. Inconsistency between those three is the evidence a regulator or a claimant will use.
Federal obligations that apply regardless
Personal data
Federal Decree-Law No. 45 of 2021 governs personal data. Wallet addresses combined with onboarding records are personal data whatever your marketing says about pseudonymity, and an immutable ledger sits badly beside rights of correction and erasure. Keep personal data off-chain, write only hashes or references on-chain, apply retention and deletion to the off-chain store, and record that design as a deliberate decision.
Financial crime
Federal anti-money-laundering obligations apply to designated businesses in the free zone. That means risk-based customer due diligence, sanctions and politically-exposed-person screening, monitoring designed for on-chain flows, treatment of transfers to and from unhosted wallets, a named compliance officer and reporting of suspicious transactions to the Financial Intelligence Unit. Chain-analytics software supports a framework; it is not the framework.
Companies, employment and tax
Federal Decree-Law No. 32 of 2021 sets the general company law backdrop, and DMCC's own company rules govern the entity itself. Employment is governed by Federal Decree-Law No. 33 of 2021, which matters when developers are paid partly in tokens: the employment contract still has to state remuneration in a form the law recognises, with token incentives sitting alongside rather than replacing it. Corporate tax under Federal Decree-Law No. 47 of 2022 applies to taxable income at 0% up to AED 375,000 and 9% above; free zone entities are within the scope of that law, and whether special treatment is available to a particular company is a question for advice, not assumption. VAT applies at 5%, and its treatment of token sales, custody fees and platform commissions has to be worked out transaction by transaction.
The documents that decide the outcome
Custody and keys
Who holds private keys, under what authority, with what signing thresholds, and what happens on loss, compromise or a keyholder's departure. If you hold assets for customers, say expressly whether they are held on trust or owed as a debt, segregate them and reconcile on a stated cycle.
Smart contract failure
Say which text prevails when code and contract diverge, who may pause or upgrade a contract that is already live, and how a loss from a defect is allocated. Silence hands the allocation to whichever forum hears the claim.
Development and intellectual property
Code written by contractors does not become the company's property automatically; assignment must be written and signed. Open source components carry their licence terms into your stack and can limit what you may close, resell or sublicense.
Token and platform terms
State what a holder acquires and what they do not, and what happens on a fork, a migration or a wind-down. Where the marketing promises returns the terms disclaim, the marketing is the document a claimant will put in front of a tribunal.
Where the argument gets heard
Absent an arbitration agreement, disputes involving a DMCC company are generally heard by the Dubai courts. Arbitration is available under Federal Law No. 6 of 2018, as amended in 2023; the Dubai International Arbitration Centre is the main onshore institution, and the DIFC remains available as a seat for parties who prefer a common-law supervisory court. Note that DIFC-LCIA was abolished by Dubai Decree No. 34 of 2021, with its caseload passing to DIAC, so a clause copied from an older agreement may name an institution that no longer administers cases. Use one clause consistently across the token terms, the shareholders' agreement and every services agreement; conflicting clauses create a fight about forum before the merits are reached, and settling that in advance is the cheapest technology dispute resolution you will buy.
Checklist before you launch from DMCC
- Written token classification, dated, with the reasoning retained.
- Activity codes checked against what the business actually does.
- A decision on whether a regulatory permission is needed alongside the licence.
- Named jurisdictions you accept users from, enforced technically.
- A data map showing what is on-chain, what is off-chain and why.
- Anti-money-laundering policy, screening tools and a named compliance officer.
- Signed IP assignments from every contributor, including founders.
- Tested key management and recovery procedures.
- One dispute resolution clause used across the whole contract set.
To check how your DMCC licence, token structure and contracts fit together, contact the Nour Attorneys team.
Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.
Nour Attorneys Team
Related Resources
Explore more of our insights on related topics:
- AI Regulations Compliance Requirements in the UAE
- Blockchain Legal Defense Strategies for Dubai Businesses
- Cryptocurrency Compliance Guidelines for UAE Operators
- Data Privacy Laws for Multinational Entities