Guides · Terms of service

Crypto terms of service for EU users: seven clauses that fail

By Arturo Ferrándiz Fernández, regulatory compliance consultant · Last reviewed 29 September 2026 · 6-minute read

In short. Many crypto projects copy terms written for US users or for other businesses. When retail users in the EU accept them, the Unfair Terms Directive decides which clauses bind those users, and an unfair clause simply does not. These seven clauses are the ones we find most often, with the rule behind each one and what to write instead.

The rule in two lines

Under Directive 93/13/EEC, a standard clause in a consumer contract is unfair if, contrary to good faith, it causes a significant imbalance in the parties' rights to the consumer's detriment (Art. 3), and an unfair clause is not binding on the consumer (Art. 6). Terms must be in plain, intelligible language (Art. 5). The Annex lists clauses that may be regarded as unfair; the letters below refer to point 1 of that Annex.

1. "We are not liable for anything"

Blanket exclusions for losses, hacks, downtime or your own errors. Clauses that inappropriately exclude or limit the consumer's rights when you do not perform, or perform badly, are listed as potentially unfair (Annex 1(b)). Instead: keep liability for your own negligence and non-performance, limit it to foreseeable loss, and explain the risks you genuinely cannot control, such as network failures or the user's loss of their own keys.

2. "We may change these terms at any time"

Unilateral changes without a valid reason set out in the contract (Annex 1(j)), or changes to the service itself without one (Annex 1(k)). Instead: list the reasons for changes, give notice in advance, and let users leave and withdraw their assets before a change takes effect.

3. "We may suspend or close your account at our sole discretion"

Ending an open-ended contract without reasonable notice, except on serious grounds (Annex 1(g)). Instead: state the grounds for suspension (legal orders, AML and sanctions checks, security), give notice where the law allows, and explain how users recover their assets.

4. "These terms are governed by the laws of [offshore jurisdiction]"

You can choose the governing law, but the choice cannot deprive a consumer of the mandatory protections of the law of the country where they live (Rome I Regulation, Art. 6(2)). Instead: choose your law and add that consumers keep the protection of the mandatory rules of their country of residence.

5. "All disputes go to arbitration in [city]"

Excluding or hindering the consumer's right to go to court, in particular by forcing arbitration (Annex 1(q)); and EU consumers can in any case sue in the courts of their own Member State (Brussels I bis Regulation, Arts. 18 and 19). Instead: offer a complaints procedure with response times, and leave court routes open.

6. No one is named as the provider

"The Protocol" or "the DAO" is not a provider. Online services must show the provider's name, geographical address, contact details including email, and trade register and VAT details where they exist (E-Commerce Directive 2000/31/EC, Art. 5; in Spain, LSSI Art. 10). Instead: name the legal entity that operates the website and the service, in the terms and in a legal notice.

7. Silence on the right of withdrawal

Where retail users buy a token directly from you or through a placing service in an offer to the public, MiCA gives them 14 calendar days to withdraw, unless the token was already admitted to trading before they bought (MiCA Art. 13). Your terms and white paper must explain it. Instead: state the right, the deadline, how to exercise it and how refunds are paid.

What these clauses have in common

Each one shifts a risk you control onto a user who cannot negotiate. EU law does not stop you from limiting your exposure; it stops you from doing it in a way the user cannot see or cannot challenge. Clear terms are also what exchanges, payment partners and investors look at in due diligence.

Want your terms checked? The free scanner flags missing governing law and blanket exclusions in seconds. The MiCA Readiness Review reads your full terms, privacy notice and marketing and gives you corrected wording within 72 working hours.

Scan my website See the review

This guide is general information about EU law as it stood on the date above. It is not legal advice and does not create a client relationship. Sources: Directive 93/13/EEC, Regulation (EC) 593/2008 (Rome I), Regulation (EU) 1215/2012 (Brussels I bis), Directive 2000/31/EC, Regulation (EU) 2023/1114.