logo_black.png

19/08/2026

Your exchange is now reporting on you: CARF, DAC8 and the UK investor

This guide explains what exchanges must report, how information from overseas platforms can reach HMRC, what data is shared, how mismatches arise, and what UK investors should do before the first 2026 reporting cycle.

For most of the last decade, crypto tax operated on a quiet and slightly embarrassing understanding. Taxpayers declared, or did not declare, and tax authorities had very little practical ability to check. Enforcement was episodic. It relied on information requests to individual exchanges, on the occasional bank transfer that looked interesting, and on people volunteering the truth.

That understanding ended on 1 January 2026.

On that date the UK's implementation of the Cryptoasset Reporting Framework came into force. On the same date, across the Channel, the EU's DAC8 obligations began applying in member states. Both derive from the same OECD standard. Both require crypto platforms to identify their users, establish tax residence, and report transaction data to tax authorities on an annual basis. And both feed into a network designed to exchange that information across borders.

If you are a UK resident holding crypto on a UK platform, this has probably already been explained to you. What has been explained far less is what happens when you are a UK resident holding crypto on a platform based in Ireland, Malta, Lithuania, France or anywhere else that DAC8 reaches. Or on a platform in a jurisdiction that has signed up to CARF but sits outside Europe entirely.

The short version: the reporting still happens, it happens to a tax authority that is not HMRC, and then it travels.

This guide explains what was actually built, what data moves, when it moves, why UK residents with accounts abroad are squarely inside it, and what an honest investor should do about the fact that HMRC is about to receive a second version of their crypto history assembled by someone else.

Two frameworks, one architecture

The UK route: CARF

The Cryptoasset Reporting Framework is an OECD standard, published in 2022 and adopted by a large group of jurisdictions. The UK confirmed its adoption and implemented the rules through domestic legislation and HMRC guidance.

From 1 January 2026, UK reporting cryptoasset service providers must carry out tax due diligence on their users. That means:

  • identifying reportable persons,

  • collecting tax residence information, and

  • maintaining structured records of reportable cryptoasset transactions.

The first reporting period covers the 2026 calendar year, with reports due to HMRC by 31 May 2027. From there, information can be exchanged with other participating tax administrations under the CARF framework.

Note the deliberate phrasing in the standard: this is not limited to centralised exchanges. It extends to custodial wallet providers and, in some cases, to decentralised applications or protocols where a controlling entity can be identified. The perimeter is drawn around who provides the service, not around what the technology is called.

The EU route: DAC8

DAC8 is the eighth revision of the EU Directive on Administrative Cooperation, the framework that has governed the exchange of tax information between member states for years. It was adopted in October 2023 and published in the Official Journal shortly afterwards.

Directives are not directly applicable. Each member state had to transpose it into national law, with a deadline of 31 December 2025. Operational obligations therefore began on 1 January 2026, with the first automatic exchanges between EU tax administrations expected in 2027 covering the 2026 calendar year.

DAC8 brings crypto asset service providers inside the same reporting perimeter that already covered banks and traditional brokers. It also extends existing reporting obligations to cover e-money and central bank digital currencies.

They are the same machine

This is the point that matters and the one most coverage misses. CARF and DAC8 are not two competing systems. DAC8 is, in substance, the EU's implementation of the OECD CARF standard, with some additional EU-specific extensions.

The data fields align. The due diligence procedures align. The reporting cycles align. That alignment is not accidental, and it is what makes cross-border exchange work: a report generated by a Lithuanian exchange under DAC8 and a report generated by a UK exchange under CARF are describing the same things in the same way.

The result is a single global reporting fabric with two labels on it.

Why a UK resident is inside the EU system too

Brexit removed the UK from DAC8 as a matter of direct application. It did not remove UK residents from the flow of information, and the reason is simple.

Reporting obligations attach to the provider, not to the customer. An exchange established in an EU member state must carry out due diligence on all of its users, establish their tax residence, and report accordingly. Where a user is resident in a jurisdiction outside the EU, the report is prepared so that it can be exchanged with that jurisdiction's tax administration under the applicable international arrangements.

So if you are a UK tax resident with an account at an EU-based platform, that platform has spent 2026 collecting your details and building a report about you. It is not filed with HMRC directly. It is filed with the tax authority where the platform is established, and from there it is capable of reaching HMRC.

The same logic runs in every direction. A UK resident using a platform in a non-EU CARF jurisdiction is captured by that jurisdiction's implementation. A UK platform holding an account for a French resident reports data that will reach France.

There are practical wrinkles. Exchange of information depends on the relevant agreements being in place and operational, and the first cycle of any new framework is rarely as smooth as the timetable suggests. Data will be late in places, incomplete in places, and misattributed in places. None of that changes the direction of travel, and none of it is a plan.

The Binance episode as a preview

Mid-2026 provided a useful demonstration of how quickly this landscape moves. Binance failed to secure a MiCA licence in time for the end of the transitional period on 1 July 2026 and suspended services across the European Union.

For UK investors the direct impact was limited, since the UK sits outside MiCA and runs its own regime. The indirect lesson was significant. Platforms exit jurisdictions, sometimes at short notice, and when they do, users discover that their complete transaction history is not something they can extract at leisure. Cost basis lives inside that history. Losing access to it does not remove the obligation to report; it just removes your ability to report accurately.

The UK has its own version of this pressure building. The FCA published its final policy statements for the UK cryptoasset regime on 30 June 2026, with the rules coming into force on 25 October 2027 and the authorisation gateway opening on 30 September 2026. The transitional window between now and then is exactly when firms decide whether serving UK customers is worth the compliance cost.

The practical instruction is unglamorous and urgent: export your full transaction history from every platform you use, in every jurisdiction, and keep those exports somewhere you control.

accertamento - UK.png

What is actually in the report

The standard specifies not just who reports but what they report, and the list is more comprehensive than most users assume.

  • Identity: name, address, jurisdiction of tax residence, and tax identification number or equivalent. For a UK resident, that means your National Insurance number or Unique Taxpayer Reference is now attached to your exchange account in a structured, machine-readable field.

  • Transactions: acquisitions and disposals of cryptoassets against fiat currency. Exchanges of one cryptoasset for another. Transfers to and from wallet addresses not held with the reporting provider. Movements involving stablecoins. Retail payment transactions above the relevant threshold, including in some cases activity through crypto debit cards.

  • Aggregates: gross amounts paid and received, the number of units involved, and the number of transactions, broken down by asset type.

  • Cash-outs: movements from crypto into a bank account receive particular attention, because they are the easiest point at which reported data can be matched against something a tax authority can already see.

That last point deserves emphasis. Tax authorities have always been able to see money arriving in bank accounts. What they lacked was the other half of the story. CARF and DAC8 supply it.

What HMRC does with the data, and where honest people get caught

Cross-referencing is the entire point

None of this creates a new tax. Not a single rate, allowance or filing obligation changed because of CARF or DAC8. The rules for how a gain is calculated are exactly what they were in 2024.

What changed is that HMRC now receives an independent second version of your activity, assembled without reference to anything you file. Its job is comparison.

HMRC was already doing this at scale before the framework existed. In the 2024 to 2025 year alone it sent roughly 65,000 letters to people it suspected of under-reporting crypto, built on data obtained from exchanges under existing information powers. Those letters were the manual, campaign-based version. CARF is the industrialised version, arriving annually, in a standard format, from every participating jurisdiction at once.

The mismatch problem affects careful people too

Here is what makes this different from ordinary evasion detection, and why it is worth taking seriously even if you have always tried to report properly.

The report HMRC receives from any single platform is accurate about that platform and blind to everything else.

Suppose you bought ETH on a UK exchange in 2021, withdrew it to a hardware wallet in 2022, moved part of it to an EU-based platform in 2024, and sold it there in 2026. The EU platform's report shows a disposal with a certain value. It knows nothing about where the ETH came from, what it cost, or that the intervening movements were transfers between accounts you control rather than purchases and sales.

From HMRC's side, that report shows proceeds and very little context. If your return does not reconstruct the missing history, the gap is visible, and it is visible without anyone opening an enquiry to find it.

The uncomfortable arithmetic is that a well-intentioned investor with fragmented records and an evasive one can produce a similar-looking discrepancy. The difference is what happens next, and that depends almost entirely on whether you can evidence your position.

The common sources of genuine mismatch

  • Internal transfers read as disposals: moving crypto between your own wallets and accounts is not a disposal, because beneficial ownership does not change. But a report from the sending platform shows an outbound transfer and a report from the receiving platform shows an inbound one, with nothing connecting them. Unless your own records link the two legs explicitly, the acquisition cost fails to carry across and the movement reads as a sale.

  • Swaps never reported: exchanging one cryptoasset for another is a disposal in the UK, valued in sterling at the time, whether or not fiat is ever involved. Rotating into a stablecoin during a downturn is a disposal. Rotating back is another one. These are the events most commonly omitted from returns, and they are precisely the events CARF captures.

  • Cost basis calculated per platform: UK rules require Section 104 pooling across your entire holding of an asset, with same-day and thirty-day matching applied first. A report produced by one exchange reflects only its own slice. A calculation built on that slice is arithmetically wrong even when every individual number in it is correct.

  • Income never valued: staking rewards, lending returns, referral bonuses and reward-based airdrops are generally taxable at their sterling value on receipt. Reported balances and flows will show these tokens arriving. If they never appeared as income on a return, the omission is now legible.

What the UK actually requires of you

This is where UK residents need to unlearn something, because a great deal of European crypto tax content does not translate.

There is no UK wealth monitoring form

There is no form on which you declare that you own crypto, and no annual wealth or balance disclosure for cryptoassets.

This differs from other Europena countries and it is genuinely important, since:

  • It is simpler, because merely holding cryptoassets creates no reporting obligation in the UK. You can hold Bitcoin for a decade and file nothing.

  • It is also, in a specific sense, more exposed. Because there is no balance declaration to compare against, HMRC's comparison focuses on flows: disposals, income and cash-outs. Those are exactly the fields CARF is built around.

What you do report

UK residents are taxable on their worldwide income and gains. The location of the platform is irrelevant. An account in Malta, Singapore or Dubai carries the same UK obligations as an account in London.

  • Capital gains and losses go on the SA108 Capital Gains Summary, which now includes a dedicated cryptoassets section. The figures must reflect your consolidated position across every platform and wallet, not one exchange's export.

  • Crypto income treated as miscellaneous income is reported in the other taxable income section of the main SA100. Where activity is organised and commercial enough to amount to trading or self-employment, the relevant supplementary pages apply instead.

For the 2025/26 tax year, capital gains are taxed at 18 per cent within your unused basic rate band and 24 per cent above it, after the £3,000 annual exempt amount. Crypto income is taxed at your marginal Income Tax rate.

The 2025/26 tax year covers 6 April 2025 to 5 April 2026, with a paper filing deadline of 31 October 2026 and an online filing and payment deadline of 31 January 2027. The 2026/27 year, the first full year of CARF data, will be reported by 31 January 2028.

One point for recent arrivals

If you became UK resident recently, the rules governing foreign income and gains changed from 6 April 2025, when the remittance basis was replaced by a residence-based regime offering relief on foreign income and gains for a limited period in the early years of UK residence.

Whether crypto held on an overseas platform counts as foreign for these purposes is a question that turns on the situs of the asset, which for cryptoassets is not always obvious and is generally linked to the residence of the beneficial owner. If you have arrived in the UK in the last few years and hold crypto abroad, this is worth taking advice on specifically rather than assuming either answer.

Losses are worth claiming

Capital losses are set against gains in the same tax year, with any excess carried forward indefinitely, but only if claimed, and the claim must be made within four years of the end of the tax year in which the loss arose.

Investors routinely skip filing in a losing year because there was no tax to pay, and those losses expire quietly. Now that HMRC receives reports showing your disposals regardless, filing a year in which you lost money costs you nothing and preserves relief you would otherwise forfeit.

Finbooks rated 4.5 out of 5 stars on Trustpilot

You invest. We take care of you accounting

blog-box-cta.png

If earlier years were not handled properly

A good proportion of people reading this will conclude, somewhere around part four, that previous returns are wrong. Swaps were never treated as disposals. Staking was never valued. A year with heavy activity was filed as though nothing happened.

This is common, it is fixable, and the timing is unusually favourable right now.

HMRC operates a Cryptoasset Disclosure Service for exactly this situation. Unprompted disclosures generally attract materially lower penalties than prompted ones, and HMRC has consistently shown more flexibility towards people who correct their own position than towards those it has to identify.

The window in which coming forward remains your own decision has a known closing date. The first CARF report reaches HMRC by 31 May 2027, covering the 2026 calendar year, with EU data flowing under DAC8 on a comparable timetable.

Correcting a past year properly means reconstructing the missing transactions, recalculating gains and income under the rules applicable to that year, checking whether losses or claims are available, and choosing the right disclosure route. It is real work. It is also finite, and it ends with a position you never have to think about again.

The alternative is waiting to see whether the report matches, which is not a strategy so much as a bet with poor odds and a deadline attached.

Getting ready with Finbooks

The problem CARF and DAC8 create is not a tax problem. It is a data problem that becomes a tax problem.

Your evidence arrives in incompatible formats from platforms in different countries, in different currencies, with different labels, none of which can see the others. The connections between them, which is to say the entire cost basis of your portfolio, exist nowhere except in your memory and a folder of CSV files.

Meanwhile HMRC is assembling its own version from standardised, machine-readable reports.

Finbooks exists to make sure your version is the better one.

Connect your exchanges and wallets, wherever they are based, by read-only API or public address, and Finbooks rebuilds a single consolidated history across all of them. From there it applies UK rules rather than generic international ones:

  • Section 104 pooling across the whole portfolio, per asset, with HMRC's same-day and thirty-day matching applied across platforms rather than within them, so a disposal on one venue is costed against your genuine pooled position.

  • Sterling valuations at the correct timestamp for every event, including staking rewards credited daily and payments made through crypto cards.

  • Income separated from capital, with staking, lending returns, referrals and airdrops classified according to how they were actually received, and every classification visible and editable.

  • Transfers matched leg to leg, so movements between your own accounts carry their acquisition cost across instead of generating phantom disposals, which is exactly the mismatch CARF reporting is most likely to surface.

  • Fees attributed to the transactions that incurred them, so they reduce your position wherever they legitimately can.

  • Self Assessment-ready output mapped to SA100 and SA108, with a full audit trail behind every figure, so that if HMRC asks in three years how a gain was calculated, the answer already exists rather than needing to be excavated.

You can start the 7 days free trial, connect your platforms and review your full transaction history and classifications before paying anything.

The grey zone is closed. The only question left is whether your numbers and HMRC's numbers tell the same story, and that is entirely within your control.

Other contents for you

30/03/2026

UK crypto tax guide 2026: HMRC rules, CGT, Income Tax and Self Assessment

Cryptoassets are taxable in the UK when they are sold, exchanged, spent, received as income, or used in transactions that HMRC treats as taxable events. This guide explains how UK crypto tax works for the 2025/26 tax year.

04/04/2026

UK crypto tax rules explained: the hidden cost of staking and yield farming

Staking, yield farming, and DeFi rewards feel like passive income, but HMRC treats every token as taxable. With automated tracking tools like CryptoBooks, staying compliant becomes far easier.

04/04/2026

Avoid Kraken tax mistakes: a UK investor's guide

Track your Kraken crypto activity and generate HMRC-ready tax reports with CryptoBooks.

20/04/2026

How to report your Rabby wallet taxes with Finbooks

Managing crypto with Rabby Wallet in the UK requires careful tax reporting. Finbooks helps classify transactions, convert to GBP, and generate HMRC-ready reports, simplifying compliance and reducing risk.