From the journal

EU DAC8 Directive Mandates Crypto-Asset Reporting by Member State Tax Authorities from 2026

Council Directive (EU) 2023/2226 of 17 October 2023, known as DAC8, entered into force on 12 December 2023 and amended Directive 2011/16/EU on administrative cooperation in the field of taxation. Member States must transpose DAC8 into national law by 31 December 2025, with the reporting obligations applying to reportable transactions completed from 1 January 2026 onward. DAC8 is fully operative as of the 2026 reporting year, with the first automatic exchange of information between tax

4 min read

Council Directive (EU) 2023/2226 of 17 October 2023, known as DAC8, entered into force on 12 December 2023 and amended Directive 2011/16/EU on administrative cooperation in the field of taxation. Member States must transpose DAC8 into national law by 31 December 2025, with the reporting obligations applying to reportable transactions completed from 1 January 2026 onward. DAC8 is fully operative as of the 2026 reporting year, with the first automatic exchange of information between tax authorities due by 31 December 2026. The directive is at the final, effective stage in EU law; national implementation is a transposition obligation rather than an option.

DAC8 inserts a new Section III bis into Directive 2011/16/EU. Article 8ad sets the core obligation: crypto-asset service providers (CASPs) operating within or providing services to EU-resident users must collect, verify, and report specified information to the competent tax authority of the Member State where the CASP is registered or has its registered address. The reportable data includes user identification information, tax identification numbers, residential addresses, aggregate transaction values, and the type of crypto-asset transferred. The directive defines "crypto-asset" by reference to Regulation (EU) 2023/1114 (MiCA), covering assets not excluded under Article 2(2) to (4) of MiCA. Article 8ad(3) lists the categories of transfers subject to reporting, including exchanges for fiat currency, exchanges between crypto-assets, and transfers to wallet addresses.

Crypto-asset service providers with EU-resident clients must implement compliance programs to collect and verify user data, calculate reportable aggregate values per crypto-asset type per calendar year, and transmit XML-format reports to the relevant competent authority. The obligation applies to providers established in a Member State and, under Article 8ad(1)(b), to providers established outside the EU that nonetheless provide services to EU-resident users. Providers that already report under equivalent third-country regimes designated by the Commission may be exempt from duplicative EU reporting under Article 8ad(6). Tax administrations will exchange the received data automatically with other Member States' tax authorities under Article 8(1) of DAC, enabling cross-border assessment of unreported crypto income.

CASPs operating from non-EU jurisdictions face the broadest exposure: they must either register with an EU Member State competent authority or demonstrate equivalent third-country reporting to avoid double compliance burdens. Member States may impose penalties for non-reporting at national level; the Directive does not harmonize the penalty amounts but requires penalties to be effective, proportionate, and dissuasive. Providers whose services qualify purely as decentralized and peer-to-peer without an intermediary may fall outside the CASP definition under MiCA and therefore outside DAC8 scope, though this question remains subject to national competent authority interpretation.

Our firm advises on DAC8 compliance, MiCA licensing, and cross-border digital asset regulatory matters, and maintains a dedicated partner network covering all EU jurisdictions. We invite crypto-asset operators, exchanges, and wallet providers to contact us to assess their reporting obligations under DAC8. We regularly advise on: DAC8 transposition analysis, CASP registration, MiCA licensing, crypto-asset AML compliance, tax reporting for digital assets, and cross-border information exchange procedures.

Source: Council Directive (EU) 2023/2226 of 17 October 2023 amending Directive 2011/16/EU on administrative cooperation in the field of taxation, OJ L 2023/2226, 24.10.2023; Art. 8ad, Section III bis; available at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023L2226; confirmed current 1 May 2026.

The information provided is not legal, tax, investment, or accounting advice and should not be used as such. It is for discussion purposes only. Seek guidance from your own legal counsel and advisors on any matters. The views presented are those of the author and not any other individual or organization. Some parts of the text may be automatically generated. The author of this material makes no guarantees or warranties about the accuracy or completeness of the information.

Crypto Regulatory

More from the journal

See all
Illia Prokopiev

MLR Registration and the FCA Cryptoasset Gateway to 25 October 2027

This matter concerns the transition of a United Kingdom cryptoasset business from FCA registration under the Money Laundering Regulations 2017 to Part 4A permission under the Financial Services and Markets Act 2000. The question is whether MLR registration gives conversion, grandfathering, priority, or a right to continue after 25 October 2027, and what an affected firm should do before the gateway closes. This analysis assumes an existing UK-facing cryptoasset business, no relevant Part 4A permission, and an intention to continue after commencement.

Illia Prokopiev

ESMA's 2026 Custody Resilience CSA and the Rules That Actually Bind

ESMA’s 2026 Common Supervisory Action is a coordinated national review of digital operational resilience in crypto-asset custody. It will test whether selected crypto-asset service providers can demonstrate effective controls across six announced workstreams. The legal questions are which requirements are binding, how national competent authorities may assess control effectiveness, and what consequences may follow from a deficiency. This analysis assumes that the firm is permitted under MiCA Article 59 to provide custody and administration within Article 3(1)(17).

Illia Prokopiev

Stablecoin regulation in the US, Hong Kong and Singapore

Stablecoin and digital-token regulation now combines market-entry authorization with continuous financial-crime controls in daily operations. The question is whether the United States’ proposed payment-stablecoin customer identification program, Hong Kong’s narrow first licensing round, and Singapore’s digital payment token (DPT) directory support a bank-like compliance characterization. They do, with material limits. The more accurate proposition is that compliance is moving beyond approval into continuous financial-institution-grade operations.