[codicts-css-switcher id=”346″]

Global Law Experts Logo
dac8 crypto reporting estonia

DAC8 Crypto Reporting in Estonia (2026): What Licensed Fintechs and Casps Must Do

By Global Law Experts
– posted 56 minutes ago

Who this is for: licensed crypto-asset service providers (CASPs), electronic money institutions (EMIs), payment firms, in-house counsel and compliance officers operating in Estonia.

What this article does: it explains DAC8 scope and Estonian implementation, lists reportable transactions and counterparties, shows how DAC8 intersects with licences, AML/CFT duties and MiCA, and provides a step-by-step operational checklist, a sample data map, and a downloadable compliance checklist template.

DAC8 crypto reporting Estonia is now a live compliance priority for every licensed CASP, EMI and payment firm operating in the country, because the EU’s eighth revision of the Directive on Administrative Cooperation extends automatic tax-information exchange to crypto-asset transactions. DAC8 (Council Directive (EU) 2023/2226) requires reporting crypto-asset service providers to apply due-diligence and reporting rules, with the first reporting broadly expected to relate to the period beginning in 2026 as transposed into national law. For licensed Estonian entities this means two workstreams landing at once: a new tax-reporting obligation to the Estonian Tax and Customs Board, and the continuing pressure of licence conditions, AML/CFT duties and the MiCA rollout.

This guide takes a clear position, do not treat DAC8 as a bolt-on tax exercise, and do not wait for a national circular before you start. Below you will find who must report, what data to collect, when to file, how DAC8 dovetails with your licence, and a decision framework for sequencing the work.

What is DAC8? Does it apply to licensed crypto businesses in Estonia?

Legal basis and quick summary of dac8 crypto reporting estonia

DAC8 is the eighth amendment to the EU Directive on Administrative Cooperation in the field of taxation, adopted as Council Directive (EU) 2023/2226. Its objective is straightforward: to close the visibility gap that crypto-assets created for tax authorities by requiring reporting crypto-asset service providers to collect, verify and report information on their users and their crypto transactions, and to make that information subject to automatic exchange between EU member states (European Commission, Taxation and Customs Union). The directive largely mirrors the OECD Crypto-Asset Reporting Framework (CARF). The directive text and its precise definitions are available through the EU legislation repository (EUR-Lex). The practical effect is that dac8 crypto reporting Estonia obligations rest on the service provider, not the customer.

Which entities are caught? CASP, EMI and VASP definitions with Estonian nuance

DAC8 uses definitions that are deliberately aligned with the Markets in Crypto-Assets Regulation (MiCA). If you are a crypto-asset service provider, an exchange, custodial wallet operator, or a platform facilitating the exchange of crypto for fiat or for other crypto, you are very likely a reporting entity. Estonian nuance matters here. Many Estonian firms historically held a virtual asset service provider (VASP) authorisation issued under national AML law and supervised in that context. As Estonia transitions VASP authorisations toward the MiCA CASP regime, the entity that reports under DAC8 is the one performing the crypto-asset service, regardless of the legacy label. EMIs that also offer crypto services can fall within scope for the crypto leg of their business.

Confirm your classification against your licence category with the Estonian Financial Supervision Authority (Finantsinspektsioon).

Key exemptions and thresholds

DAC8 focuses on reportable crypto-assets and reportable users. Certain assets that cannot be used for payment or investment purposes, and certain excluded persons such as some listed entities and specified governmental bodies, may fall outside the reporting population. There is no general “small operator” carve-out that exempts a licensed CASP from the regime simply because volumes are low, if you provide the service and have reportable users, you report. Treat any perceived exemption as something to document with legal analysis rather than assume.

Reportable transactions and counterparties, scope for CASPs and EMIs

Asset types and transaction types

The reporting net covers crypto-assets that can be held and transferred in a decentralised manner and used for payment or investment, including many convertible tokens and stablecoins. The transaction types that trigger reporting are broad and worth mapping explicitly against your product ledger:

  • Fiat-to-crypto and crypto-to-fiat exchanges. Acquisitions and disposals against fiat currency are core reportable events, including the gross amounts and units involved.
  • Crypto-to-crypto exchanges. Swaps between different crypto-assets are reportable, with the fair value of each leg captured.
  • Transfers. Transfers of reportable crypto-assets to and from wallet addresses, including transfers to addresses not associated with a known provider, must be recorded and, where required, reported.
  • Retail payment transactions. Payments in crypto above the relevant reporting parameters processed on behalf of a merchant can fall within scope.

For crypto tax reporting Estonia purposes, the practical instruction is to build a single transaction taxonomy that tags each event type at the point of capture, so that reportable events are flagged automatically rather than reconstructed later.

Counterparty and jurisdiction rules

DAC8 turns on the tax residence of the user, not simply their nationality or the location of your servers. A reporting CASP must apply due-diligence procedures to establish each user’s jurisdiction(s) of residence and collect the tax identification number where applicable. Where a user is resident in another EU member state, the information is exchanged automatically with that state’s authority. The framework also anticipates exchange with certain non-EU jurisdictions under aligned international standards such as the OECD CARF, so counterparties outside the EU are not automatically out of scope, they require documentation and, in defined cases, reporting. The presence of non-EU counterparties is therefore a documentation-and-analysis trigger, never a reason to stop collecting data.

Examples

Three short, practical scenarios illustrate the decision between reporting and document-only outcomes:

  • Example 1, EU resident buys crypto with euros. A user tax-resident in another EU member state buys a stablecoin for euros on your Estonian-licensed platform. This is a reportable exchange event; you report the user identity, TIN, gross amount and units to the Estonian Tax and Customs Board for onward exchange.
  • Example 2, Swap between two tokens. An Estonian-resident user swaps one convertible token for another. Reportable as a crypto-to-crypto exchange, with the fair value of both legs and the timestamp captured.
  • Example 3, Outbound transfer to an unhosted wallet. A user transfers a reportable asset to an external address. You must record the transfer details; depending on the aggregate reporting rules, this feeds the transfer reporting fields even though there is no counterparty provider to identify.

How dac8 crypto reporting estonia dovetails with licensing, AML/CFT obligations and MiCA

The centrepiece question for compliance leaders is how the new tax-reporting duty sits alongside the AML/CFT regime, MiCA obligations and Finantsinspektsioon licence conditions. The short answer: these are distinct legal duties with different supervisors, different data purposes and different penalties, but they draw on overlapping data. The winning strategy is a shared data model that serves all three without collapsing them into one. The table below sets out the comparison dimension by dimension.

Dimension DAC8 (tax reporting) AML / MiCA / licence obligations (Estonia)
Legal basis EU Directive on Administrative Cooperation (DAC8, Directive (EU) 2023/2226), tax law Estonian AML law, MiCA Regulation, licence conditions (Finantsinspektsioon)
Primary duty Reporting of crypto-related transactions and counterparties to the tax authority for automatic exchange Prevent money laundering and terrorist financing: KYC, transaction monitoring, suspicious activity reporting
Covered entities Reporting crypto-asset service providers and certain intermediaries per DAC8 definitions Licensed CASPs/EMIs under Estonian law and MiCA obligations
Data required Counterparty ID, TIN, transaction details, wallet identifiers, timestamps, value, jurisdiction Identity data under KYC; transaction metadata for AML, substantial overlap with DAC8 fields
Due diligence standard Tax-specific due diligence to identify reportable events and reportable persons Risk-based AML/CFT due diligence, with enhanced due diligence for high-risk relationships
Timing / filing cadence Periodic (broadly annual) reporting per DAC8 schedule as implemented nationally Suspicious reports to the FIU without delay; periodic AML compliance reporting to the supervisor
Penalties & enforcement Tax penalties; cross-border exchange of information; reputational risk Administrative fines, licence sanctions, criminal exposure for ML/TF failures
Priority / conflict Tax reporting may require disclosure beyond AML logs, subject to safeguards AML confidentiality and data-protection constraints; reconcile via lawful basis and regulatory guidance
Supervisory authority Estonian Tax and Customs Board, plus mutual exchange among EU tax authorities Finantsinspektsioon (licence), Estonian FIU (AML reporting), plus EU-level MiCA coordination
Operational impact Data extraction, retention, reporting workflows, IT security for tax transfers KYC system upgrades, enhanced monitoring, STR processes, licence compliance programmes

On conflicts and priority: the two regimes are not in genuine conflict, but they impose different confidentiality and data-protection logics. AML “tipping off” rules and data-minimisation principles must be reconciled with the mandatory disclosure that DAC8 requires. The correct approach is to identify a lawful basis for each processing purpose, document it, and align your privacy notices, not to withhold DAC8 reporting on data-protection grounds. Confirm licence-condition expectations directly with Finantsinspektsioon and record the correspondence.

Practical compliance responsibilities for compliance officers and MLROs

Ownership is where most programmes fail. The MLRO owns AML monitoring and suspicious activity reporting; the compliance officer owns policy, licence conformity and supervisory communication; and a designated tax-reporting owner, often within finance or compliance, owns the DAC8 filing lifecycle. Because DAC8 and AML draw on the same onboarding and transaction data, the sensible structure is one data-capture standard feeding two reporting outputs. Assign a single accountable person for the shared data model, and hold a joint change-control forum so that a KYC field added for AML also satisfies the DAC8 due-diligence requirement.

Document every decision about what is reported, to whom, and on what legal basis, and keep an audit trail of communications with both the tax authority and Finantsinspektsioon.

Decision framework: sequencing DAC8 against AML and licence work

Take a position rather than hedging. Use this framework to decide what to fix first.

Choose the DAC8-first path, prioritise tax-reporting system changes, when:

  • Your transaction volumes generate many reportable events and the reporting deadline is near.
  • The reporting schedule is timeframe-driven and the tax penalties for late or incorrect filing are significant.
  • Your existing AML systems already capture sufficient structured transaction data but lack a tax-reporting export capability.

Choose the AML/licence-first path, prioritise KYC and licence conformity, when:

  • You have outstanding licence conditions, remediation orders, or active supervisory attention from Finantsinspektsioon.
  • Your onboarding and identity verification are weak and likely to trigger enforcement.
  • The data changes needed for DAC8 depend on upgrading KYC capture, so the AML fix is a prerequisite.

The recommended default for most licensed Estonian CASPs and EMIs is a parallel track. Run DAC8 implementation alongside AML and licence remediation using one shared data model, and split responsibilities cleanly: IT for exports and secure transmission, Compliance for KYC and jurisdiction mapping, and Legal for data-protection lawful basis and reporting-law interpretation. This is the path we recommend unless a specific enforcement or deadline trigger above forces a single-track prioritisation.

Timing, filing mechanics and penalties for dac8 crypto reporting estonia

Key dates and phased implementation in Estonia

DAC8 applies across EU member states, with the crypto-asset reporting rules broadly expected to apply from 2026 as transposed nationally, meaning the first reporting period runs on data collected from that point and the first filings follow the national schedule set by the implementing legislation. Estonia transposes the directive into national law, and the operational detail, the exact submission window and any transitional accommodations, is set out through the Estonian Ministry of Finance and administered by the Estonian Tax and Customs Board. Because the reporting obligation attaches to the full collection period, the practical instruction is unambiguous: your data-capture and due-diligence procedures should be operational from the start of the reporting period, not from the filing date.

Waiting until the filing deadline to build systems will leave you unable to report accurately for events that already occurred. Confirm the exact commencement and filing dates with the tax authority before finalising your plan.

Filing formats, secure submission channels and retention periods

Reporting is submitted to the Estonian Tax and Customs Board through its designated electronic channels in the prescribed structured format. Because the information is tax data subject to cross-border exchange, secure transmission and integrity controls are essential. Retain the underlying records and the due-diligence evidence for the retention period required under Estonian tax and AML law, and store them so they can be produced on request during any audit. Confirm the current format specification and retention rules on the Estonian Tax and Customs Board portal before you finalise your export.

Penalties and cross-border exchange consequences

Failure to report, or reporting incomplete or inaccurate data, exposes the entity to penalties under the applicable Estonian legislation and, because the data feeds automatic exchange, to scrutiny in every member state where your users are resident. Beyond the direct fine, the reputational and supervisory consequences of a reporting failure can bleed into your licence relationship with Finantsinspektsioon. Check the current penalty framework with the Estonian Tax and Customs Board.

Operational checklist: what to change in people, processes and systems

Governance and ownership: roles, training and policy updates

Start with accountability. Appoint a named DAC8 reporting owner and record the appointment in your governance framework. Update your compliance manual to add a DAC8 policy that cross-references your AML policy and licence obligations. Train front-line onboarding staff on the additional tax-residence and TIN collection steps, and brief the board on the new obligation, the deadline and the residual risk. Add DAC8 as a standing item in your compliance committee agenda so that changes to products, jurisdictions or systems are assessed against reporting scope before launch.

Data mapping and systems: fields to capture, reconciliation and retention

The heart of the programme is data. Map every reportable data element to its source system and confirm it is captured at the point of transaction or onboarding rather than reconstructed. Key elements to reconcile include user identity and tax residence, the TIN, wallet identifiers, the transaction type, the gross amount and units, fair value, timestamps and the counterparty jurisdiction. Build a reconciliation control that compares the count of reportable events in your ledger against the count in your report export, so that discrepancies surface before filing. Ensure retention aligns with the required period and that archived records remain retrievable and tamper-evident.

KYC and enhanced due diligence changes to capture counterparties for DAC8

DAC8 adds tax-specific due diligence on top of your existing AML KYC. In practice, this means collecting and validating each user’s jurisdiction(s) of tax residence and TIN, applying reasonableness checks against other onboarding data, and re-verifying where a change of circumstances is indicated. Where your onboarding does not yet capture tax residence as a structured field, add it, a free-text address is not sufficient for reliable jurisdiction mapping. For high-risk relationships already subject to enhanced due diligence under AML law, extend that review to confirm the reportable-status conclusion is documented.

Sample data map and minimal CSV field list

A minimal export for dac8 crypto reporting Estonia should carry, at least, the following fields:

  • User identifier and legal name
  • Jurisdiction(s) of tax residence and TIN
  • Date of birth / entity registration details
  • Transaction type (fiat-to-crypto, crypto-to-fiat, crypto-to-crypto, transfer, payment)
  • Crypto-asset type and units
  • Gross amount and fair value in reporting currency
  • Wallet identifier(s) and timestamp
  • Counterparty jurisdiction where applicable

Transitional issues: VASP sunset, licence upgrades and cross-border passporting

Estonian VASP sunset implications for former VASPs

Estonia is moving crypto supervision from the legacy VASP authorisation model into the MiCA CASP framework, with transitional arrangements governing how existing providers move onto CASP authorisation. For firms that operated under a VASP authorisation, the transition does not remove the DAC8 obligation, the reporting duty follows the crypto-asset service, not the label on the old permit. The practical risk during the sunset is a gap in ownership: as legal teams focus on the licence conversion, the DAC8 build can slip. Treat VASP reporting DAC8 continuity as a named workstream so that reporting responsibility carries over cleanly to the CASP entity, and confirm which legal entity is the reporting person during any restructuring. Verify the current transitional timeline with Finantsinspektsioon.

How DAC8 affects passporting and cross-border reporting obligations under MiCA

MiCA allows an authorised CASP to passport services across the EU. That expanded footprint interacts directly with crypto reporting EU obligations: serving users resident in multiple member states multiplies the jurisdictions whose authorities receive exchanged information, even though you generally report to a single national authority. The interaction between DAC8 and MiCA therefore rewards centralising your tax-residence mapping so that a single onboarding standard supports reporting across your entire passported user base. Verify the MiCA text and its interaction with reporting duties via EUR-Lex.

When to consult a licensing lawyer

Consult a licensing lawyer when a corporate restructuring, licence conversion or product launch changes who the reporting entity is, or when you are unsure whether a change triggers a licence amendment or a notification to Finantsinspektsioon.

Sample compliance checklist and downloadable template

Use the following checklist to run your DAC8 implementation, alongside the compliance checklist DAC8 items below.

  • Confirm your entity’s reporting status against your licence category
  • Appoint a named DAC8 reporting owner and record the appointment
  • Draft and approve a standalone DAC8 policy cross-referencing AML and licence obligations
  • Map every reportable data field to its source system
  • Add structured tax-residence and TIN capture to onboarding
  • Extend KYC/EDD procedures to document reportable status
  • Build the reporting export in the prescribed format
  • Implement a reconciliation control between ledger events and report output
  • Configure secure submission to the Estonian Tax and Customs Board
  • Set retention and retrievability controls for records and evidence
  • Train onboarding and compliance staff on the new steps
  • Brief the board and add DAC8 to committee agendas
  • Document the lawful basis for each processing purpose and update privacy notices
  • Log all correspondence with the tax authority and Finantsinspektsioon
  • Establish a change-control forum linking AML, licence and DAC8 workstreams

Next steps

DAC8 crypto reporting Estonia is an obligation that no licensed CASP, EMI or payment firm can defer, because the reporting duty attaches to data collected from the start of the reporting period and feeds automatic cross-border exchange. Treat it as a distinct legal duty that shares a data model with your AML and licence obligations, sequence the work using the decision framework above, and default to a parallel track unless an enforcement or deadline trigger forces otherwise. For a bespoke review of your DAC8, AML and licence integration, work with the Licensing lawyers, Estonia practice team.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Mark Gofaizen at Gofaizen & Sherle Fintech Lawyers, a member of the Global Law Experts network.

Sources

  1. European Commission, Taxation and Customs Union (Administrative Cooperation)
  2. EUR-Lex, EU legislation repository
  3. Estonian Tax and Customs Board (Maksu- ja Tolliamet)
  4. Estonian Financial Supervision Authority (Finantsinspektsioon)
  5. Estonian Ministry of Finance (Rahandusministeerium)
  6. OECD, Taxation (Crypto-Asset Reporting Framework)

FAQs

What is DAC8 and does it apply to my exchange in Estonia?
DAC8 is the eighth amendment to the EU Directive on Administrative Cooperation (Directive (EU) 2023/2226). It requires reporting crypto-asset service providers to collect and report user and transaction information for automatic exchange between EU tax authorities. If your Estonian-licensed exchange provides crypto-asset services to reportable users, it applies to you (European Commission).
Reportable events include fiat-to-crypto and crypto-to-fiat exchanges, crypto-to-crypto swaps, transfers of reportable assets, and qualifying crypto payment transactions. For example, an EU-resident user buying a stablecoin with euros on your platform is a reportable exchange event requiring the user’s identity, TIN, gross amount and units.
You file periodically in the prescribed structured format with the Estonian Tax and Customs Board, which exchanges the data with other EU member states’ authorities. Confirm the current submission window and format on the tax authority portal, and ensure data capture is live from the start of the reporting period.
They are separate legal duties with different supervisors and purposes, but they draw on overlapping onboarding and transaction data. Build a shared data model that serves both, and reconcile the mandatory DAC8 disclosure with AML confidentiality and data-protection rules by documenting a lawful basis for each purpose.
Failure to report, or reporting inaccurate data, exposes you to penalties under the applicable Estonian legislation and scrutiny in every member state where your users are resident because the data feeds automatic exchange. A reporting failure can also affect your standing with Finantsinspektsioon. Check the current penalty framework via the Estonian Tax and Customs Board and the Estonian Ministry of Finance.
DAC8 itself does not require a new licence, but a restructuring, VASP-to-CASP conversion or product change that alters who the reporting entity is may trigger a licence amendment or a notification to Finantsinspektsioon. Take licensing advice where the reporting person changes.
Operational tasks such as data export and submission can be supported by third parties, but legal responsibility for accurate and timely reporting remains with the licensed entity. Retain oversight, controls and audit evidence in-house.
Strengthening Global Connections: A YIORKAS & CO LLC Joins Global Law Experts | GLE News
By Global Law Experts

posted 41 minutes ago

Clients engaging in consultation with an attorney, shaking hands over a table with legal documents and charts.
By Irena Kolárová

posted 2 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

DAC8 Crypto Reporting in Estonia (2026): What Licensed Fintechs and Casps Must Do

Send welcome message

Custom Message