Since 1 January 2026, crypto exchanges, brokers and other crypto-asset service providers that serve customers resident in the European Union have been collecting tax information under DAC8, the eighth amendment to the EU Directive on Administrative Cooperation. Most individual users meet it as a pop-up asking for a tax residence and a tax identification number. A company that holds crypto on an exchange meets a longer version: a self-certification for the entity, a classification question and, in many cases, details of the people who control it.
This guide is written for founders and small businesses that hold or move crypto through a provider. It explains what DAC8 requires a provider to collect, what the provider reports, the dates that matter in 2026 and 2027, and what to prepare so the company’s answers match its own records. The rules come from Council Directive (EU) 2023/2226 and the European Commission’s DAC8 page. National laws transpose the directive, so local forms, deadlines and penalties differ.
What DAC8 is, and what it is not
DAC8 is a reporting and exchange system. Providers collect information about their users and transactions, report it to the tax authority of the Member State where they report, and that authority passes information about residents of other Member States to their tax administrations.
It does not set a tax rate, create a new crypto tax or decide whether a particular disposal is taxable. The European Parliament’s briefing on the proposal described it as dealing exclusively with the reporting of information, without obliging Member States to impose taxes on the transactions. Whether a company owes tax on a gain, a payment received in tokens or a staking reward is still a question for the tax law of the country where the company is resident.
The practical change is visibility. In a 2023 interview published by the Commission’s tax directorate, the official responsible for the file said there was no exchange of crypto information before DAC8, and that a platform in another country would usually leave the home tax authority without data. From the 2026 reporting year onwards, a tax administration can receive yearly figures from providers it does not supervise.
The timeline that matters
The Council adopted the directive on 17 October 2023 and it was published in the Official Journal on 24 October 2023. Member States had to transpose it by 31 December 2025 and apply it from 1 January 2026.
| Date | What happens | Source |
|---|---|---|
| 1 January 2026 | Providers start collecting data on reportable transactions of EU-resident users, including residents of their own Member State | Commission DAC8 page |
| From onboarding | New users give a self-certification when the relationship is established | Annex VI, Section III |
| 1 January 2027 | Deadline for providers to obtain self-certifications from users who already had a relationship on 31 December 2025 | Annex VI, Section III |
| During 2027 | Providers report the 2026 information to their tax authority in the year after the reporting year; the Commission tells providers to check national deadlines and formats | Annex VI, Section II; Commission DAC8 page |
| By 30 September 2027 | Tax authorities exchange the first-year information with the users’ Member States of residence | Article 8ad(6); Commission DAC8 page |
If your company opened its exchange account before the end of 2025, the 1 January 2027 date is the one to watch. A provider that has not yet asked for your self-certification must obtain it by then.
Which providers collect the data
The directive calls them Reporting Crypto-Asset Service Providers. The group covers two kinds of business:
- crypto-asset service providers authorised under the EU’s Markets in Crypto-Assets Regulation (MiCA); and
- crypto-asset operators that are not authorised under MiCA but serve EU-resident users. These operators must register in a single Member State for DAC8 reporting.
The Commission’s page says the obligation applies to providers that effectuate exchange transactions in relevant crypto-assets, and the Annex defines crypto-asset services by reference to MiCA, “including staking and lending”. The directive’s recitals describe reportable crypto-assets broadly: assets usable for payment or investment, including stablecoins, e-money tokens and certain non-fungible tokens. Providers assess borderline tokens case by case.
A provider based outside the EU can be relieved of EU registration and reporting where it reports in a non-EU jurisdiction covered by an effective qualifying agreement with the Member States. For a user, that changes where the data flows, not whether it is collected.
What your company will be asked for
The directive sets out the minimum content of a valid self-certification. For an entity, it must be signed or otherwise positively affirmed, dated no later than the date it is received, and contain:
- the legal name;
- the address;
- the Member State or States of residence for tax purposes;
- for each reportable person, the tax identification number (TIN) issued by each relevant Member State;
- for an entity that is neither an Active Entity nor an Excluded Person, the same personal details for each controlling person, unless that person has given their own self-certification, plus the role that makes them a controlling person; and
- where it applies, the criteria the entity meets to be treated as an Active Entity or Excluded Person.
The provider must confirm that the self-certification is reasonable against what it already knows, including documents collected for customer due diligence. A company that tells its exchange it is resident in one country while its onboarding file shows management elsewhere should expect follow-up questions.
Tax residence is a company question first
The self-certification asks where the company is resident for tax purposes, not where it is registered or where its bank is. Those can differ. If the entity certifies that it has no tax residence, the provider may rely on its place of effective management or the address of its principal office. A partnership or similar arrangement with no tax residence is treated as resident where its place of effective management is situated.
SGK Academy’s guide to company tax residence explains incorporation, central management and control and treaty tie-breakers. Settle that position with your adviser before you certify it to a provider, because the same answer will appear in data sent to tax authorities.
Active Entity, Excluded Person or neither
Classification decides whether the provider must look through the company to the individuals behind it.
Excluded Persons include an entity whose stock is regularly traded on an established securities market and its related entities, governmental entities, international organisations, central banks and most financial institutions. Most founder-owned companies are not Excluded Persons.
Active Entities are defined by a list of criteria. The one most small trading companies will look at is the income and assets test: less than 50% of the entity’s gross income for the preceding year is passive income, and less than 50% of the assets it held during that year produce, or are held to produce, passive income. Another criterion covers a new entity that is not yet operating a business and has no prior operating history but is investing capital into assets with the intent to operate a business other than a financial institution. That status ends 24 months after the entity was first organised.
If the company is neither, the provider must establish whether it has controlling persons who are resident in a Member State and, if so, report them. A holding company whose income is mostly dividends, or a company that mainly holds crypto as an investment, may well fall into this group. The classification should come from the company’s accounts, not from a guess made in an onboarding form.
Who counts as a controlling person
Controlling persons are the natural persons who exercise control over an entity. For trusts the directive lists settlors, trustees, protectors and beneficiaries. For providers, the term must be read consistently with “beneficial owner” in the EU anti-money-laundering directive, and providers may rely on the information they collected for customer due diligence.
For each controlling person who is a reportable person, the self-certification needs the first and last name, residence address, Member State or States of tax residence, the TIN for each of those Member States and the date of birth. In practice, a founder who owns most of a passive holding company should expect their own name and TIN in the company’s crypto report.
What the provider reports each year
The report is aggregated by type of crypto-asset, not a list of every trade. For each reportable user, or each entity with reportable controlling persons, a provider reports identifying details and, for each crypto-asset type:
| Category | What is reported |
|---|---|
| Acquisitions against fiat currency | Aggregate gross amount paid, number of units, number of transactions |
| Disposals against fiat currency | Aggregate gross amount received, number of units, number of transactions |
| Acquisitions against other crypto-assets | Aggregate fair market value, number of units, number of transactions |
| Disposals against other crypto-assets | Aggregate fair market value, number of units, number of transactions |
| Reportable Retail Payment Transactions | Aggregate fair market value, units and number of transactions |
| Other transfers to the user | Aggregate fair market value, units and number, by transfer type where known |
| Other transfers by the user | Aggregate fair market value, units and number, by transfer type where known |
| Transfers to addresses not known to belong to a provider or financial institution | Aggregate fair market value and units |
Fiat amounts are reported in the currency in which they were paid or received; where several currencies are involved, the provider converts them consistently into one. Fair market values are reported in a single currency, valued at the time of each transaction.
Two lines deserve attention from a business.
Retail payments. A Reportable Retail Payment Transaction is a transfer of reportable crypto-assets in consideration of goods or services for a value exceeding USD 50,000, or the equivalent in another currency. Where a reporting provider processes such payments for or on behalf of a merchant, it must also treat the merchant’s paying customer as a crypto-asset user for that payment, provided domestic anti-money-laundering rules require it to verify that customer’s identity. A company that accepts large crypto payments through a payment provider should expect the provider to ask its customers for more information.
Withdrawals to private wallets. Transfers that a provider makes to addresses it cannot associate with another provider or a financial institution are reported as a separate total. A company that moves treasury holdings from an exchange into self-custody will see those movements appear in that line.
When information is missing
The Parliament’s research service noted that DAC8 goes further than the OECD model in one respect. Where a crypto-asset user does not provide the required information after two reminders following the provider’s initial request, but not before 60 days have passed, the provider must prevent the user from performing reportable transactions.
For a business that relies on an exchange account to receive client payments or pay suppliers, that is an operational risk, not just a compliance detail. A request that sits unanswered in a shared inbox can end with a blocked account.
Penalties for providers are set nationally. The directive requires Member States to lay down effective, proportionate and dissuasive penalties for infringements of the rules that transpose it, but leaves the choice of penalty to them.
The UK runs a parallel system
The United Kingdom is outside the EU but applies the OECD Crypto-Asset Reporting Framework (CARF), on which DAC8 is modelled. HMRC’s guidance for users says that, from 1 January 2026, UK providers collect and record customer details. According to HMRC’s page for users, an entity user must provide its legal business name, main business address, a company registration number for UK companies, and a TIN and its country of issue for non-UK companies; some entities must also give details of their controlling person.
HMRC states that giving inaccurate details, or not giving details, to a UK service provider can lead to a penalty of up to £300, and that the penalty could be higher for non-UK providers. UK providers submit their first report between 1 January and 31 May 2027, according to HMRC’s provider guidance. A UK company using an EU exchange, or an EU company using a UK exchange, should expect both frameworks to touch its accounts.
A pending change: the DAC recast
On 24 June 2026 the Commission adopted a proposal to recast the Directive on Administrative Cooperation (COM(2026) 308). It would codify DAC1 to DAC9 into a single act and add simplifications. The Commission’s announcement focuses on other parts of the framework, such as cross-border arrangements and platform reporting of goods sales, and describes a new taxpayer-identification verification tool. According to the proposal’s explanatory memorandum, where a reporting entity verifies a TIN with that optional tool, it would report the name and the TIN without the additional identifying information.
The recast is a proposal sent to the European Parliament for consultation and to the Council for adoption. Until it is adopted and transposed, the DAC8 rules described above remain the ones providers apply.
Worked example: a two-founder consultancy
The following scenario is illustrative, not a description of a real company.
A consultancy incorporated in Ireland, managed by its two founders from Ireland, has held a corporate account at an EU exchange since 2024. During 2026 it receives two client payments in USDC, converts most of the balance to euros and withdraws the rest to a hardware wallet the company controls.
- Because the account existed on 31 December 2025, the exchange must obtain the company’s self-certification by 1 January 2027.
- The company certifies Irish tax residence and its Irish TIN. Its income is consulting fees, so it can assess itself against the Active Entity income and assets test using last year’s accounts.
- If it qualifies as an Active Entity, the exchange does not need to report the founders as controlling persons. If the company held mainly investments instead, the founders’ details would be reported.
- The exchange’s 2026 report shows, for USDC, the aggregate euros received on disposals, the transfers into the account, and the total sent to the hardware wallet as a transfer to an address not known to belong to a provider.
- Neither founder’s personal tax position changes because of the report. What changes is that the Irish authority receives figures it can compare with the company’s return.
A preparation checklist for founders
- List every crypto account the company holds, with the provider’s legal name, country and the date the account was opened.
- Confirm the company’s tax residence and TIN for each relevant Member State, and keep the evidence on file.
- Assess whether the company is an Active Entity using last year’s accounts, and write down the figures behind the conclusion.
- If it is not, identify the controlling persons as they appear in your anti-money-laundering onboarding file, and check their residence details and TINs.
- Answer provider requests through the provider’s authenticated account channel, and record the date and content of each self-certification you give.
- Reconcile your own ledger with the categories a provider reports: fiat disposals, crypto-to-crypto exchanges, transfers in and out, and withdrawals to self-custody.
- Update self-certifications when circumstances change. A provider that knows or has reason to know a certification is incorrect cannot keep relying on it and must obtain a new one.
- Treat unexpected “DAC8 verification” emails with care. Check them inside the provider’s app or website rather than through links; SGK Academy’s guide to crypto custody, liquidity and risk covers account access controls.
Sources and version
Checked 10 October 2026 against Council Directive (EU) 2023/2226 (Annex VI and Article 8ad), the European Commission’s DAC8 page, the Commission’s 24 June 2026 tax simplification announcement, the European Parliament Research Service DAC8 briefing, and HMRC’s guidance for users and providers. National transposing laws can add requirements and set their own deadlines and penalties; this guide does not determine any company’s tax position.





