Our Expert in Estonia
No results available
Who this is for: licensed crypto-asset service providers (CASPs), electronic money institutions (EMIs), payment firms, in-house counsel and compliance officers operating in Estonia.
What this article does: it explains DAC8 scope and Estonian implementation, lists reportable transactions and counterparties, shows how DAC8 intersects with licences, AML/CFT duties and MiCA, and provides a step-by-step operational checklist, a sample data map, and a downloadable compliance checklist template.
DAC8 crypto reporting Estonia is now a live compliance priority for every licensed CASP, EMI and payment firm operating in the country, because the EU’s eighth revision of the Directive on Administrative Cooperation extends automatic tax-information exchange to crypto-asset transactions. DAC8 (Council Directive (EU) 2023/2226) requires reporting crypto-asset service providers to apply due-diligence and reporting rules, with the first reporting broadly expected to relate to the period beginning in 2026 as transposed into national law. For licensed Estonian entities this means two workstreams landing at once: a new tax-reporting obligation to the Estonian Tax and Customs Board, and the continuing pressure of licence conditions, AML/CFT duties and the MiCA rollout.
This guide takes a clear position, do not treat DAC8 as a bolt-on tax exercise, and do not wait for a national circular before you start. Below you will find who must report, what data to collect, when to file, how DAC8 dovetails with your licence, and a decision framework for sequencing the work.
DAC8 is the eighth amendment to the EU Directive on Administrative Cooperation in the field of taxation, adopted as Council Directive (EU) 2023/2226. Its objective is straightforward: to close the visibility gap that crypto-assets created for tax authorities by requiring reporting crypto-asset service providers to collect, verify and report information on their users and their crypto transactions, and to make that information subject to automatic exchange between EU member states (European Commission, Taxation and Customs Union). The directive largely mirrors the OECD Crypto-Asset Reporting Framework (CARF). The directive text and its precise definitions are available through the EU legislation repository (EUR-Lex). The practical effect is that dac8 crypto reporting Estonia obligations rest on the service provider, not the customer.
DAC8 uses definitions that are deliberately aligned with the Markets in Crypto-Assets Regulation (MiCA). If you are a crypto-asset service provider, an exchange, custodial wallet operator, or a platform facilitating the exchange of crypto for fiat or for other crypto, you are very likely a reporting entity. Estonian nuance matters here. Many Estonian firms historically held a virtual asset service provider (VASP) authorisation issued under national AML law and supervised in that context. As Estonia transitions VASP authorisations toward the MiCA CASP regime, the entity that reports under DAC8 is the one performing the crypto-asset service, regardless of the legacy label. EMIs that also offer crypto services can fall within scope for the crypto leg of their business.
Confirm your classification against your licence category with the Estonian Financial Supervision Authority (Finantsinspektsioon).
DAC8 focuses on reportable crypto-assets and reportable users. Certain assets that cannot be used for payment or investment purposes, and certain excluded persons such as some listed entities and specified governmental bodies, may fall outside the reporting population. There is no general “small operator” carve-out that exempts a licensed CASP from the regime simply because volumes are low, if you provide the service and have reportable users, you report. Treat any perceived exemption as something to document with legal analysis rather than assume.
The reporting net covers crypto-assets that can be held and transferred in a decentralised manner and used for payment or investment, including many convertible tokens and stablecoins. The transaction types that trigger reporting are broad and worth mapping explicitly against your product ledger:
For crypto tax reporting Estonia purposes, the practical instruction is to build a single transaction taxonomy that tags each event type at the point of capture, so that reportable events are flagged automatically rather than reconstructed later.
DAC8 turns on the tax residence of the user, not simply their nationality or the location of your servers. A reporting CASP must apply due-diligence procedures to establish each user’s jurisdiction(s) of residence and collect the tax identification number where applicable. Where a user is resident in another EU member state, the information is exchanged automatically with that state’s authority. The framework also anticipates exchange with certain non-EU jurisdictions under aligned international standards such as the OECD CARF, so counterparties outside the EU are not automatically out of scope, they require documentation and, in defined cases, reporting. The presence of non-EU counterparties is therefore a documentation-and-analysis trigger, never a reason to stop collecting data.
Three short, practical scenarios illustrate the decision between reporting and document-only outcomes:
The centrepiece question for compliance leaders is how the new tax-reporting duty sits alongside the AML/CFT regime, MiCA obligations and Finantsinspektsioon licence conditions. The short answer: these are distinct legal duties with different supervisors, different data purposes and different penalties, but they draw on overlapping data. The winning strategy is a shared data model that serves all three without collapsing them into one. The table below sets out the comparison dimension by dimension.
| Dimension | DAC8 (tax reporting) | AML / MiCA / licence obligations (Estonia) |
|---|---|---|
| Legal basis | EU Directive on Administrative Cooperation (DAC8, Directive (EU) 2023/2226), tax law | Estonian AML law, MiCA Regulation, licence conditions (Finantsinspektsioon) |
| Primary duty | Reporting of crypto-related transactions and counterparties to the tax authority for automatic exchange | Prevent money laundering and terrorist financing: KYC, transaction monitoring, suspicious activity reporting |
| Covered entities | Reporting crypto-asset service providers and certain intermediaries per DAC8 definitions | Licensed CASPs/EMIs under Estonian law and MiCA obligations |
| Data required | Counterparty ID, TIN, transaction details, wallet identifiers, timestamps, value, jurisdiction | Identity data under KYC; transaction metadata for AML, substantial overlap with DAC8 fields |
| Due diligence standard | Tax-specific due diligence to identify reportable events and reportable persons | Risk-based AML/CFT due diligence, with enhanced due diligence for high-risk relationships |
| Timing / filing cadence | Periodic (broadly annual) reporting per DAC8 schedule as implemented nationally | Suspicious reports to the FIU without delay; periodic AML compliance reporting to the supervisor |
| Penalties & enforcement | Tax penalties; cross-border exchange of information; reputational risk | Administrative fines, licence sanctions, criminal exposure for ML/TF failures |
| Priority / conflict | Tax reporting may require disclosure beyond AML logs, subject to safeguards | AML confidentiality and data-protection constraints; reconcile via lawful basis and regulatory guidance |
| Supervisory authority | Estonian Tax and Customs Board, plus mutual exchange among EU tax authorities | Finantsinspektsioon (licence), Estonian FIU (AML reporting), plus EU-level MiCA coordination |
| Operational impact | Data extraction, retention, reporting workflows, IT security for tax transfers | KYC system upgrades, enhanced monitoring, STR processes, licence compliance programmes |
On conflicts and priority: the two regimes are not in genuine conflict, but they impose different confidentiality and data-protection logics. AML “tipping off” rules and data-minimisation principles must be reconciled with the mandatory disclosure that DAC8 requires. The correct approach is to identify a lawful basis for each processing purpose, document it, and align your privacy notices, not to withhold DAC8 reporting on data-protection grounds. Confirm licence-condition expectations directly with Finantsinspektsioon and record the correspondence.
Ownership is where most programmes fail. The MLRO owns AML monitoring and suspicious activity reporting; the compliance officer owns policy, licence conformity and supervisory communication; and a designated tax-reporting owner, often within finance or compliance, owns the DAC8 filing lifecycle. Because DAC8 and AML draw on the same onboarding and transaction data, the sensible structure is one data-capture standard feeding two reporting outputs. Assign a single accountable person for the shared data model, and hold a joint change-control forum so that a KYC field added for AML also satisfies the DAC8 due-diligence requirement.
Document every decision about what is reported, to whom, and on what legal basis, and keep an audit trail of communications with both the tax authority and Finantsinspektsioon.
Take a position rather than hedging. Use this framework to decide what to fix first.
Choose the DAC8-first path, prioritise tax-reporting system changes, when:
Choose the AML/licence-first path, prioritise KYC and licence conformity, when:
The recommended default for most licensed Estonian CASPs and EMIs is a parallel track. Run DAC8 implementation alongside AML and licence remediation using one shared data model, and split responsibilities cleanly: IT for exports and secure transmission, Compliance for KYC and jurisdiction mapping, and Legal for data-protection lawful basis and reporting-law interpretation. This is the path we recommend unless a specific enforcement or deadline trigger above forces a single-track prioritisation.
DAC8 applies across EU member states, with the crypto-asset reporting rules broadly expected to apply from 2026 as transposed nationally, meaning the first reporting period runs on data collected from that point and the first filings follow the national schedule set by the implementing legislation. Estonia transposes the directive into national law, and the operational detail, the exact submission window and any transitional accommodations, is set out through the Estonian Ministry of Finance and administered by the Estonian Tax and Customs Board. Because the reporting obligation attaches to the full collection period, the practical instruction is unambiguous: your data-capture and due-diligence procedures should be operational from the start of the reporting period, not from the filing date.
Waiting until the filing deadline to build systems will leave you unable to report accurately for events that already occurred. Confirm the exact commencement and filing dates with the tax authority before finalising your plan.
Reporting is submitted to the Estonian Tax and Customs Board through its designated electronic channels in the prescribed structured format. Because the information is tax data subject to cross-border exchange, secure transmission and integrity controls are essential. Retain the underlying records and the due-diligence evidence for the retention period required under Estonian tax and AML law, and store them so they can be produced on request during any audit. Confirm the current format specification and retention rules on the Estonian Tax and Customs Board portal before you finalise your export.
Failure to report, or reporting incomplete or inaccurate data, exposes the entity to penalties under the applicable Estonian legislation and, because the data feeds automatic exchange, to scrutiny in every member state where your users are resident. Beyond the direct fine, the reputational and supervisory consequences of a reporting failure can bleed into your licence relationship with Finantsinspektsioon. Check the current penalty framework with the Estonian Tax and Customs Board.
Start with accountability. Appoint a named DAC8 reporting owner and record the appointment in your governance framework. Update your compliance manual to add a DAC8 policy that cross-references your AML policy and licence obligations. Train front-line onboarding staff on the additional tax-residence and TIN collection steps, and brief the board on the new obligation, the deadline and the residual risk. Add DAC8 as a standing item in your compliance committee agenda so that changes to products, jurisdictions or systems are assessed against reporting scope before launch.
The heart of the programme is data. Map every reportable data element to its source system and confirm it is captured at the point of transaction or onboarding rather than reconstructed. Key elements to reconcile include user identity and tax residence, the TIN, wallet identifiers, the transaction type, the gross amount and units, fair value, timestamps and the counterparty jurisdiction. Build a reconciliation control that compares the count of reportable events in your ledger against the count in your report export, so that discrepancies surface before filing. Ensure retention aligns with the required period and that archived records remain retrievable and tamper-evident.
DAC8 adds tax-specific due diligence on top of your existing AML KYC. In practice, this means collecting and validating each user’s jurisdiction(s) of tax residence and TIN, applying reasonableness checks against other onboarding data, and re-verifying where a change of circumstances is indicated. Where your onboarding does not yet capture tax residence as a structured field, add it, a free-text address is not sufficient for reliable jurisdiction mapping. For high-risk relationships already subject to enhanced due diligence under AML law, extend that review to confirm the reportable-status conclusion is documented.
A minimal export for dac8 crypto reporting Estonia should carry, at least, the following fields:
Estonia is moving crypto supervision from the legacy VASP authorisation model into the MiCA CASP framework, with transitional arrangements governing how existing providers move onto CASP authorisation. For firms that operated under a VASP authorisation, the transition does not remove the DAC8 obligation, the reporting duty follows the crypto-asset service, not the label on the old permit. The practical risk during the sunset is a gap in ownership: as legal teams focus on the licence conversion, the DAC8 build can slip. Treat VASP reporting DAC8 continuity as a named workstream so that reporting responsibility carries over cleanly to the CASP entity, and confirm which legal entity is the reporting person during any restructuring. Verify the current transitional timeline with Finantsinspektsioon.
MiCA allows an authorised CASP to passport services across the EU. That expanded footprint interacts directly with crypto reporting EU obligations: serving users resident in multiple member states multiplies the jurisdictions whose authorities receive exchanged information, even though you generally report to a single national authority. The interaction between DAC8 and MiCA therefore rewards centralising your tax-residence mapping so that a single onboarding standard supports reporting across your entire passported user base. Verify the MiCA text and its interaction with reporting duties via EUR-Lex.
Consult a licensing lawyer when a corporate restructuring, licence conversion or product launch changes who the reporting entity is, or when you are unsure whether a change triggers a licence amendment or a notification to Finantsinspektsioon.
Use the following checklist to run your DAC8 implementation, alongside the compliance checklist DAC8 items below.
DAC8 crypto reporting Estonia is an obligation that no licensed CASP, EMI or payment firm can defer, because the reporting duty attaches to data collected from the start of the reporting period and feeds automatic cross-border exchange. Treat it as a distinct legal duty that shares a data model with your AML and licence obligations, sequence the work using the decision framework above, and default to a parallel track unless an enforcement or deadline trigger forces otherwise. For a bespoke review of your DAC8, AML and licence integration, work with the Licensing lawyers, Estonia practice team.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Mark Gofaizen at Gofaizen & Sherle Fintech Lawyers, a member of the Global Law Experts network.
posted 14 minutes ago
posted 32 minutes ago
posted 47 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message