01

DeFi regulation in Switzerland: key points

  • There are no special rules solely for DeFi; the same principles apply as for all digital assets.
  • The greatest challenge is attributing activities to a responsible person.
  • FINMA assesses DeFi economically and in a technology-neutral manner: the same services and risks generally lead to the same rules.
  • Every piece of software, tool and activity must ultimately be attributable to a natural or legal person.

02

Does Switzerland have specific laws for DeFi?

No. There are no additional rules specific to DeFi. DeFi projects are assessed according to the same principles as any other activity involving digital assets. The fundamental challenges are the same as in other jurisdictions: to which jurisdiction can an activity be attributed, and who exactly belongs to the group of participants? In Switzerland, these questions can be even more pronounced because of the comparatively small domestic market and the many international parties involved in DeFi projects.

03

How does Switzerland deal with tasks being distributed among several parties?

FINMA distinguishes projects without an identifiable operator from applications that, despite being described as DeFi, are centrally organised or controlled. Dividing tasks among several legal entities or jurisdictions does not automatically eliminate an authorisation requirement; the overall economic assessment is decisive.

Because of the decentralised nature of such activities, it may happen in practice that no regulator considers itself competent, creating a negative conflict of jurisdiction, or that several regulators consider themselves competent at the same time, creating a positive conflict of jurisdiction.

04

Who is liable when an activity is carried out in a decentralised manner?

Every technical tool, piece of software and activity — whether decentralised or centralised — must ultimately be attributable to a natural or legal person. Only persons, not code or protocols, can be held accountable. Governance rights, admin keys, upgrade options, fee flows and actual influence may be relevant to attribution. The assessment remains case-specific.

05

Frequently asked questions

Can I avoid an authorisation requirement through decentralisation? No. The concept of coordinated action is designed to prevent exactly this; dividing an activity among several parties or jurisdictions does not eliminate the requirement.

Who bears responsibility for a DeFi protocol? The person or group of persons that can actually exercise control, for example through the ability to change the underlying code.

Is it possible that no regulator has jurisdiction? In theory yes, creating a negative conflict of jurisdiction, but in practice FINMA is increasingly examining where activities actually take place.

Does the concept apply only to DeFi? It was developed for decentralised arrangements but can generally be applied to any situation involving several parties acting together.

Does a DeFi project in Switzerland require authorisation? That depends on the specific activity; the same criteria apply as for centralised projects.

Primary sources

Official sources for this article