CARF: your crypto provider reports you to the tax office

The Crypto-Asset Reporting Framework is the OECD standard under which crypto service providers collect tax data about their customers and report their transactions to a tax authority, which then exchanges that data with the authority in the customer's country of residence. The OECD published it in June 2023, and the European Union put it into law as DAC8.

For a provider, this is a reporting build with a fixed deadline. For a customer, it ends the practical anonymity of using a regulated exchange: the holdings and disposals a German resident makes at an exchange anywhere in the reporting network reach the German tax authority automatically.

Crypto tax reporting forms, transaction records, a hardware wallet and a generic crypto token

What a reporting provider must collect and send

The obligation falls on a Reporting Crypto-Asset Service Provider, an RCASP, which is any entity facilitating the purchase, sale or transfer of crypto-assets for customers, or handling reportable retail payment transactions. Exchanges, brokers and some wallet providers are in; the question of who exactly is caught is the first analysis any provider does.

The data has two halves. Customer identification covers the name, address, jurisdiction of tax residence and tax identification number, plus the date of birth for an individual and the controlling persons of an entity. The transaction data then reports, per customer and per asset, the aggregate amounts for each category: crypto acquired against fiat, crypto disposed of against fiat, crypto-to-crypto exchanges in and out, transfers in and out, and retail payment transactions. Grant Thornton sets out the transaction categories and the schema, with retail payments above 50,000 US dollars reportable. The report carries the asset names, the unit quantities and the fair market values.

DAC8: the EU route into national law

DAC8 is Directive (EU) 2023/2226, the eighth amendment to the Directive on Administrative Cooperation, and it is how CARF becomes binding on a European provider. Member states had to transpose it by 31 December 2025, and it applies from 1 January 2026, which makes 2026 the first collection year with reports following in 2027.

DAC8 follows CARF closely and reaches further in one respect: its scope extends to certain transactions facilitated by intermediaries outside the EU where EU customers are involved, so a non-EU platform serving European clients can be caught. It also amends the existing Common Reporting Standard, bringing e-money issuers in as financial institutions, which closes a route that previously sat between the two regimes. Deloitte's overview of the framework covers the same implementation path.

Which assets and which transactions are in scope

The definition of a relevant crypto-asset is deliberately broad. It covers cryptocurrencies, stablecoins, tradeable non-fungible tokens and crypto-linked derivatives, so a provider cannot narrow its reporting by arguing that a token is not a currency.

Two exclusions matter. Central bank digital currencies and specified electronic money products are handled under the amended Common Reporting Standard instead of CARF, since they are already financial accounts. And an asset that cannot be used for payment or investment purposes falls outside, which is the carve-out a closed in-game token relies on. A provider's scoping work is therefore per asset and per service, and a platform that lists hundreds of tokens does it once for each.

Due diligence and the self-certification

The provider cannot report data it does not have, so CARF requires it to obtain a self-certification from each customer stating their tax residence and tax identification number. The provider must then test that statement for reasonableness against the other information it holds, such as the address and documentation collected for anti-money-laundering purposes.

Where a customer does not provide the certification, the provider must follow the framework's remedy, which in practice means chasing the customer and ultimately restricting the account. For existing customers the provider has to run the procedure retrospectively over its book, which is the part of the project that takes the longest and is where most providers discover that their onboarding records are incomplete.

CARF and the Travel Rule: different data, different purpose

Both rules attach information to crypto activity and they answer to different authorities. The Travel Rule is an anti-money-laundering measure: it requires originator and beneficiary information to accompany a transfer between providers, in real time, so that each side knows who is on the other end. It is read by compliance officers and financial intelligence units.

CARF is a tax measure. It reports aggregated annual amounts per customer to a tax authority after the year ends, and nobody uses it to decide whether a single transfer may proceed. The practical overlap is the customer data: a provider that has built its Travel Rule and crypto AML processes properly already holds much of what CARF needs, and the reporting logic on top is new.

What does a German customer see of CARF?

A request from the exchange for a tax residence confirmation and a tax identification number, and then nothing. There is no new tax and no new return: German crypto taxation is unchanged, and the rules in Germany continue to apply as before. What changes is that the tax office can check a declaration against data it receives directly from the provider.

The practical consequence for a German holder is that the records have to match. A disposal inside the one-year holding period that was not declared is now visible, and so is a holding at a foreign exchange that the holder assumed was invisible. Holders with activity across several platforms generally find that reconciling their own transaction history is the work this regime creates for them.

Which countries apply CARF?

Around seventy jurisdictions have committed to the framework, with the EU member states bound through DAC8 and a group of other financial centers implementing it on their own timetables. Exchange of data only happens between two jurisdictions that have both implemented it and have an exchange relationship in place, so the network fills in over the first reporting cycles.

That is the point for a customer to understand: a jurisdiction outside the network does not report, which is why the current commitment list is worth checking against where a platform is established. The gap is closing, and the direction of travel has been one way since the OECD published the standard.

CARF and Finance Loop

Finance Loop is the meeting place for the tax, compliance and reporting teams at German and European crypto providers who have to build this reporting and answer their customers' questions about it. Finance Loop members work on the onboarding side of the obligation and on the tax side that receives the data.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.