Tax audits of crypto assets have so far been based on information provided by users themselves. This will change starting in 2026, when crypto asset service providers will be required to report information about their users’ transactions to the Danish Tax Agency. This obligation covers more activities than those regulated by MiCA and includes, among other things, staking, lending, and certain NFTs. We’ll go over who is covered, what must be reported, how entities and transactions are classified, and what deadlines apply.
The new rules stem from an international collaboration aimed at making trading in crypto-assets transparent to tax authorities. The OECD has developed the common standard, the Crypto-Asset Reporting Framework (CARF), which requires crypto-asset service providers to report information about their users and transactions so that the information can be exchanged among participating countries. In the EU, the standard has been implemented through the DAC8 Directive, which we have written about here.
In Denmark, the rules are set forth in an executive order that took effect on January 1, 2026, and apply to reporting for the 2026 calendar year and thereafter.
The reporting requirement applies to most businesses that offer products or services related to cryptoassets. This includes, among others:
The rules thus go beyond the scope of MiCA. The obligation applies to both providers with a MiCA license and crypto-asset operators without such a license. Whether a company is covered or not depends on a case-by-case assessment.
The reporting is divided into two parts: (1) information about the users and (2) information about their transactions.
The provider must report the following information about each user:
If the user is a business, the provider must also determine the entity’s status, which determines whether information about the entity’s controlling persons must also be reported.
The classification determines whether the reporting can be limited to the entity itself, or whether the provider must “look through” the entity and report on the controlling persons—that is, the natural persons who actually own or control it. There are three types of entities:
Exempt entities are those that the law considers to pose a low tax risk, and as a general rule, no reporting is required for them. This applies in particular to publicly traded companies and their group companies, public authorities, central banks, and international organizations, as well as financial institutions. However, financial institutions are not exempt if they are certain passive or managed investment entities.
Active entities are businesses engaged in actual commercial activity, and in such cases, reporting may be limited to the entity itself. An entity is considered active when less than 50% of its revenue consists of passive income and less than 50% of its assets are of a passive nature. These will typically be operating companies or active holding companies.
Other entities, which are typically holding or investment companies, are treated as “transparent,” however. In such cases, the provider must “look through” the entity and report on the controlling persons if they are tax residents of a relevant jurisdiction.
Practical Examples
Operating Business with Crypto Holdings (the 50% Test): Company A operates a business—such as an online store or a manufacturing company—and has accumulated a small holding of Ethereum to manage its liquidity. As long as the company’s passive income accounts for less than 50% of its total income, and its passive assets account for less than 50% of its total assets, Company A can generally be treated as an active entity.
Newly established company in the process of becoming operational (up to 24 months): Company B has not yet commenced operations, but has raised capital and invested the funds in assets—such as fiat currency or stablecoins—while its product is being developed. During the startup phase, Company B may be treated as an active entity when the purpose is to establish actual operations, even if passive income during this period exceeds 50%. This exception ceases to apply 24 months after incorporation if the company effectively remains an investment or holding company.
The reporting requirement applies to transactions conducted on or after January 1, 2026—that is, for the entire calendar year 2026. Transactions from previous years do not need to be reported.
The report must include transactions involving reportable cryptoassets, including:
The information is reported in aggregate form by user and by asset type, specifying the total amount or total market value and the number of transactions. The provider must therefore regularly collect and store this data.
Reports are submitted in a fixed XML format, and the Danish Tax Agency expects that the files will be uploadable via TastSelv Erhverv starting in January 2027. DTI codes, issued by the Digital Token Identifier Foundation, are used to identify a cryptoasset. For example, the DTI code for bitcoin is 4H95J0R2X.
Example 1: Purchasing crypto assets with fiat currency (purchasing BTC with DKK)
During 2026, a user purchases Bitcoin with Danish kroner in three separate transactions: 0.10 BTC for 50,000 DKK, 0.05 BTC for 27,500 DKK, and 0.02 BTC for 11,200 DKK. For the asset type BTC, the total gross amount paid in fiat currency (88,700 DKK), the total number of crypto assets (0.17 BTC), and the number of transactions (3) are reported.
Example 2: Exchanging crypto assets (from ETH to BTC)
In 2026, a user exchanges a total of 5 ETH for 0.10 BTC in a single transaction. The market value at the time of the transaction, calculated in a fiat currency, is reported here. For BTC, the total market value of acquisitions in exchange for other crypto assets is reported, and for ETH, the total market value of disposals in exchange for other crypto assets is reported.
The provider must carry out a series of customer due diligence procedures to identify users and determine what information must be reported. The key requirement is that the user submit a self-certification regarding their tax residence and other relevant information. For users registered on or after January 1, 2026, the self-certification must be obtained when the customer relationship is established, while for users with a customer relationship that already existed as of December 31, 2025, the self-certification must be obtained no later than January 1, 2027.
If the user fails to provide the required information even after two reminders, the provider must prevent the user from conducting reportable transactions. However, the block may not be imposed until at least 60 days have elapsed since the original request.
A service provider that is also a financial institution may, to a large extent, reuse the customer due diligence procedures and self-declarations already carried out in accordance with the CRS (Common Reporting Standard), provided that the requirements of the executive order are met. The work itself may be outsourced to a third party, but the responsibility remains with the service provider.
Not all cryptoassets are subject to the reporting requirement. The executive order defines the scope of cryptoassets subject to reporting, so that central bank digital currencies (CBDCs) and electronic money (e-money tokens) are excluded. The decisive factor is not whether a token is called a stablecoin, but whether it meets the definition of e-money in the executive order or constitutes a CBDC. The definition includes several conditions, and not all stablecoins meet them.
An e-money token (EMT) issued under a license granted pursuant to MiCA and listed in ESMA’s register meets the definition and is therefore excluded from the scope of CARF and DAC8. However, such tokens must be reported in accordance with the CRS rules. This distinction should therefore be treated as a classification issue for each individual token or product and documented in the company’s internal procedures.
Thereafter, reports must be submitted once a year for the preceding calendar year. Danish companies submit their reports to the Danish Tax Agency, which forwards the information to the tax authorities in the user’s home country, provided that the jurisdiction participates in the exchange. The relevant jurisdictions are listed in Appendix 1 to the executive order, where List A includes 29 jurisdictions and List B includes 26 others. The countries that will actually exchange information for the calendar year 2026 are regularly updated in the Danish Tax Agency’s guidelines.
Violations of the executive order are punishable by a fine, including for inadequate customer due diligence procedures, failure to register, and inaccurate or missing reports. A user who provides inaccurate information may be similarly penalized. If registration is submitted late, the Danish Tax Agency may also impose daily penalty fines, and a crypto-asset operator’s registration may be revoked if reports are not submitted.
The executive order also contains an anti-circumvention clause. This means that if a user takes actions with the primary purpose of preventing a transaction from being correctly identified or reported, the transaction is disregarded, and it is reported as if the action had not been taken. An example of this could be splitting a single payment into several smaller payments to stay below the $50,000 limit.
For corporate groups and companies operating in multiple countries, there is an option to avoid duplicate reporting. A service provider is not required to comply with Danish requirements if those requirements are already met in another EU member state or in a qualified jurisdiction outside the EU. In certain cases, however, the exemption is contingent upon the Danish Tax Agency being notified of this. Whether the exemption can be applied in a specific case depends on a detailed assessment.
The new rules mean that companies must incorporate reporting into their business operations. Providers subject to reporting requirements would be well advised to start taking the following steps right away:
With CARF and DAC8, tax compliance for crypto assets is shifting from information reported by users themselves to automatic reporting by third parties. For providers, the scope of their responsibilities is therefore expanding from know-your-customer (KYC) and anti-money laundering (AML) measures to also include tax classification of both users and assets. In our view, the classification of entities and individual tokens will be the most challenging part of the work, because it determines both what must be reported and how much must be reported.
If you have any questions about the rules, please feel free to contact us.
You can access Executive Order No. 1155 of September 10, 2025, regarding reporting requirements for providers of crypto-asset services here.