Publicité
ERP IMPLEMENTATION
🇫🇷 Lire en français →

DAC7 and ERP: A CTO's Guide to Reporting Obligations for Digital Platforms in 2026

DAC7 requires marketplaces and platforms to report seller revenues to tax authorities. Operational guide for configuring your ERP to meet EU compliance requirements.

DAC7 and ERP: A CTO's Guide to Reporting Obligations for Digital Platforms in 2026

Since 1 January 2023, every digital platform facilitating transactions between third-party buyers and sellers has been subject to the DAC7 directive. The first declarations were filed in January 2024, covering revenues from fiscal year 2023. Yet three years after the rules came into force, many IT teams are still discovering that their ERP cannot produce the required report: seller data scattered across multiple tables, fiscal-year aggregates never computed, XML schema unknown to the team.

This guide is aimed at CTOs and CFOs of B2B marketplaces, service platforms, freelance marketplaces, and short-term rental platforms. It answers three questions: does this apply to you? What data must you collect? And how do you configure your ERP to produce the declaration?

DAC7: The Directive That Turns Platforms Into Tax Collectors

Who Is a “Digital Platform Operator” Under DAC7?

Council Directive (EU) 2021/514 of 22 March 2021 defines a platform operator as any entity — company or individual — that makes an electronic interface available enabling sellers to connect with buyers, in exchange for remuneration.

The common misconception: believing DAC7 only applies to GAFA-scale platforms or large consumer marketplaces. That is not the case. A mid-market company running a B2B marketplace for industrial subcontracting, a SaaS platform connecting independent consultants, or an equipment-rental solution used between businesses all fall within scope if they earn commissions on transactions. Size is not the criterion — the intermediary function is.

Explicitly excluded are: operators that process payments without facilitating the transaction, and those whose users are exclusively listed public entities.

Which Revenues Are Covered?

The directive covers four categories of “relevant activities”:

  • Sale of goods: resale of physical or digital products between third-party sellers and buyers
  • Personal services: freelance assignments, consulting, maintenance, delivery
  • Rental of means of transport: vehicles, equipment, machinery
  • Immovable property rental: short or long-term, residential or commercial

Critical point: the de minimis exemption (fewer than 30 transactions AND less than €2,000 in cumulative revenues) applies only to sellers of goods. An independent service provider billing €500 on your platform must be reported from the very first transaction. This asymmetry is one of the most frequent sources of non-compliance in service platforms.

Reporting Timeline

The directive has been transposed across EU member states, with obligations applying to transactions carried out from 1 January 2023 onwards:

Reporting periodFiling deadlineStatus
202331 January 2024First declaration — past
202431 January 2025Past
202531 January 2026Past
202631 January 2027Prepare now

Each member state’s tax authority receives an electronic XML file structured according to the OECD/Model Rules schema adapted for DAC7. This schema is updated each year: verify with your local tax authority which version applies for the 2025 revenues declaration.

What DAC7 Requires You to Collect About Your Sellers

Seller Identity

For each reportable seller, you must collect and verify the following data according to their legal status:

Individuals: first and last name, date and place of birth, address of tax residence, Tax Identification Number (TIN) in the country of residence.

Entities (companies, associations): legal name, registered office address, TIN, company registration number, details of permanent establishments located in the EU.

The critical constraint is TIN verification: you cannot simply collect the number the seller provides. The directive requires you to verify its reliability, notably through EU member states’ identification services. In practice, most specialist solutions rely on the European Commission’s VIES VAT verification API for entities, and format-based checks for individual TINs.

If a seller fails to provide their data after two reminders, the platform must suspend the account within a minimum of 60 days. This account closure obligation must be built into the platform’s terms and conditions and managed in the CRM or ERP.

Financial Aggregates to Report

Beyond identity, you must report for each seller:

  • The total revenues paid per quarter and per activity type
  • The number of transactions per quarter
  • Fees, commissions and taxes withheld by the platform per quarter
  • For immovable property rental: the number of rental days and the address of each property

Quarterly granularity matters: your ERP must aggregate this data by seller, by quarter, and present it in a structured format. Annual-only reporting is not sufficient to produce the XML file.

The Threshold Below Which Reporting Is Lighter

A goods seller may be excluded from the declaration if, over the fiscal year, they accumulate fewer than 30 transactions AND less than €2,000 in revenues. Both conditions must be met simultaneously.

Reminder: this exemption applies only to goods sales. Service providers, equipment lessors, and property owners are reportable from the first euro. In an ERP or platform combining multiple activity types, each transaction must therefore be categorised correctly to apply the right treatment.

The 4 ERP Workstreams for DAC7 Compliance

Workstream 1 — KYS (Know Your Seller): Collecting and Verifying Seller Identity Data

This is the most underestimated workstream. Most platforms capture an email address and an IBAN, but not a structured TIN or a verified tax residence. You need to extend the seller data model in your ERP or CRM to include:

  • Tax residence country (a separate field from shipping or billing address)
  • TIN (with format constraints by country)
  • Verification status (unverified / verified / rejected) with timestamp

This data model must be populated during the seller onboarding process, not retroactively. For sellers already active on 1 January 2023 whose data is missing, a remediation campaign is necessary — platforms that waited typically found that 20–40% of active sellers do not respond promptly.

Workstream 2 — Aggregation Engine: Consolidating Transactions by Seller and Fiscal Year

The ERP must be able to produce, for each reportable seller, quarterly aggregates of revenues and transaction counts. This requires:

  1. A stable, unique seller identifier across all transaction tables (orders, invoices, payments, credit notes)
  2. A categorisation of each transaction according to the four DAC7 activity types
  3. An aggregation engine that computes totals by seller, by type, by quarter, excluding cancelled or refunded transactions

In platforms that use a general-purpose ERP for finance and a separate business system (marketplace engine, OMS) for transaction management, this aggregation may require a reconciliation middleware. OMS data (order lines, statuses) must be reconciled with accounting data (actual payments, invoiced commissions).

Workstream 3 — Export and Submission: The DAC7 XML File

Tax authorities do not accept Excel spreadsheets or CSV files. Submission is mandatory via an XML file conforming to the DAC7 XSD schema published by each national tax authority. This schema follows the OECD/CRS standard adapted for digital platforms.

The file goes through two levels of validation:

  • Structural controls: schema compliance, presence of mandatory fields
  • Blocking controls: TIN consistency, amount validity, seller uniqueness per declaration

A file with blocking errors is treated as if no declaration was filed — with the same consequences as a missing submission. XML file generation is rarely native in general-purpose ERPs and typically requires either a dedicated module or a custom ETL pipeline.

Workstream 4 — 10-Year Archiving and Audit Trail

Collected and declared data must be retained for 10 years from 31 December of the year following the declaration. For 2023 data declared in January 2024, that means retention until 31 December 2034.

The audit trail must cover: data collected and their collection date, TIN verifications performed, reminders sent to non-compliant sellers, account suspension decisions, and XML files submitted to the tax authority. These records may be subject to a specific tax audit under each member state’s procedural rules.

Technical Solutions: Native ERP vs DAC7 Middleware

Specialist Tax Compliance Solutions

For platforms operating at scale or across multiple EU countries, specialist tax compliance solutions offer native DAC7 management:

Sovos Compliance Cloud: Sovos offers a unified tax and reporting compliance solution covering multiple EU countries. The solution is SAP-certified (for both S/4HANA and ECC) and covers e-invoicing, e-reporting and regulatory reporting. For platforms using SAP as their central ERP, this is a credible option for externalising DAC7 file production without bespoke development.

Taxdoo and comparable solutions: Several specialists in European e-commerce tax compliance (VAT OSS, DAC7, Intrastat) offer connectors to major OMS and CRM platforms. These solutions handle seller data collection, TIN verification and XML file generation.

Middleware Approach for General-Purpose ERPs

For platforms using Odoo, Sage 200/X3, Microsoft Business Central, or a sector-specific ERP as their financial back-office, DAC7 file production typically runs through a middleware pipeline:

  1. Extract transaction and seller data from the ERP via API or SQL export
  2. Transform in a dedicated calculation engine (Python, dbt, or ETL): aggregation, categorisation, threshold application
  3. Validate TIN data quality and file completeness
  4. Generate the XML file according to the tax authority’s XSD schema
  5. Submit via the national tax authority’s electronic filing portal

This middleware approach is more flexible but requires annual maintenance with each update to the XSD schema. It also means defining clear ownership within the IT team for this annual process.

Penalties and Deadlines: What Non-Compliant Platforms Risk

Penalties vary by member state. In most EU jurisdictions, sanctions for DAC7 non-compliance typically include:

  • Missing declaration: fines ranging from €10,000 to €50,000 depending on severity
  • First self-reported infraction: typically not sanctioned if remedied within prescribed deadlines
  • Uncorrected errors: per-error fines, generally capped at €10,000–50,000 total
  • Lack of due diligence (TIN verification not performed, register not maintained): fines of €10,000 to €50,000

The statute of limitations runs 4 years from the infraction. In practice, tax authorities can audit a platform’s DAC7 compliance through 2028 for the first 2024 declarations.

Note: DAC8, which extends similar obligations to crypto-asset service providers, entered into force on 1 January 2026. First DAC8 declarations are expected in January 2027.

What Your CTO Must Do Before January 2027

The declaration for 2026 revenues is due on 31 January 2027. If your ERP is not yet configured to produce it, here are the workstreams in priority order:

  1. Audit your seller data model: TIN, tax residence, verification status — present or absent in your current system?
  2. Categorise transaction types according to the four DAC7 activity categories
  3. Quarterly aggregation engine: does the data exist and can it be cleanly aggregated by seller?
  4. XML file production: in-house development or specialist solution?

For broader context on the EU regulatory landscape affecting your ERP, see also our guide on ViDA and ERP: Action Plan for the Digital VAT Era 2026–2030 and our analysis of the EU AI Act and its compliance obligations for your ERP modules.

Lorem ipsum dolor sit amet consectetur?

Lorem ipsum dolor sit amet consectetur adipiscing elit, the Lorem Brand sed do eiusmod tempor incididunt ut labore.

Lorem ipsum dolor sit amet?

Sed ut perspiciatis unde omnis iste natus error, with Lorem Brand sit voluptatem accusantium doloremque laudantium totam rem aperiam eaque ipsa quae ab illo inventore veritatis et quasi architecto beatae vitae dicta sunt explicabo nemo enim ipsam voluptatem quia voluptas sit aspernatur aut odit aut fugit.

Quis nostrud exercitation ullamco laboris?

Lorem ipsum criteria for consideration:

  1. Lorem ipsum dolor sit amet consectetur adipiscing
  2. Sed do eiusmod tempor incididunt ut labore
  3. Ut enim ad minim veniam quis nostrud exercitation
  4. Duis aute irure dolor in reprehenderit voluptate
  5. Excepteur sint occaecat cupidatat non proident

Duis aute irure dolor in reprehenderit?

Nemo enim ipsam voluptatem quia voluptas sit aspernatur aut odit aut fugit, the Lorem Brand sed quia consequuntur magni dolores eos qui ratione voluptatem sequi nesciunt neque porro quisquam est qui dolorem ipsum quia dolor sit amet consectetur adipisci velit.

Lorem ipsum dolor: Lorem Brand