CESOP
What is CESOP?
Central Electronic System of Payment Information (CESOP) is an EU database that collects cross-border payment records from and makes them available to national tax authorities. It was created by Council Directive (EU) 2020/284 and Council Regulation (EU) 2020/283, with reporting obligations starting on 1 January 2024.
CESOP exists to close a VAT gap. When a seller in one country ships goods or delivers digital services to buyers in another, tax authorities in the buyer's market have little independent visibility into whether VAT was declared on those sales. Payment data supplies that trail: who received the money, from which country, and how often. National authorities cross-check the resulting pattern against VAT filings to surface sellers who under-report or never registered in the first place.
Key requirements
Reporting is triggered per payee, not per transaction. Once a payment service provider processes more than 25 cross-border payments to the same payee within a calendar quarter, every cross-border payment to that payee in that quarter becomes reportable – including the first 25.
For each reportable payment, providers record identifying data on the payee alongside detail on the payment itself:
- Payee name or business name, plus VAT or tax identification number where available
- Payee address, where available
- Account identifiers such as , BIC, or another unique reference
- Date, time, amount, and currency of the payment
- Member state of origin and country of destination
- Payment method, and whether the transaction was or
- Refunds linked to a reported payment
Records are kept in electronic form for three years. Providers file quarterly with the tax authority of each member state where they operate, and those authorities forward the compiled data to the central CESOP database by the 10th day of the second month after the quarter closes.
Access to the central database is restricted to anti-fraud specialists designated by each member state through Eurofisc, the EU network for exchanging VAT fraud intelligence. The system aggregates records for the same payee across every reporting provider, so a seller collecting through several PSPs still resolves to a single profile rather than a set of unconnected fragments.
Who it applies to
CESOP covers the four categories of payment service providers recognised under : credit institutions, electronic money institutions, payment institutions, and post office giro institutions.
Which provider files depends on where the payee's provider sits. When the payee's provider is located in the EU, that provider reports. When the payee's provider sits outside the EU, the obligation shifts to the payer's provider, so the payment doesn't fall out of scope simply because the recipient banks elsewhere.
A payment counts as cross-border when the payer is located in one member state and the payee is in a different member state or a third country. Location is determined from the account identifier or the BIC. Purely domestic payments sit outside CESOP.
Merchants don't file CESOP reports themselves. Their payout data is what gets reported, which is why and gateways request tax identification and registered address details during onboarding.
Penalties for non-compliance
CESOP sets no single EU-wide penalty. Each member state defines its own sanctions for late, incomplete, or inaccurate filings, so a provider operating across several markets faces a different exposure in each. What counts as a breach and how a fine is calculated both vary by national implementation – the local tax authority's guidance is the governing reference.
Data quality carries its own consequence. Filings are validated on submission, and records that fail validation are rejected and have to be corrected and refiled, which turns a data-hygiene problem into a recurring operational cost. Incomplete payee data also sits badly next to and obligations: a provider that can't produce accurate payee identification for tax reporting invites the same question about its transaction monitoring.


