Emergency? DE

E-invoicing, ViDA, CESOP: VAT becomes a data tax

E-invoicing is not a format change. It is the moment VAT becomes a data tax — and in a data room, a company that creates no evidence of its own will be described by other people’s data.

Invoice data, payment data, reporting data, risk scores: European VAT is leaving the world of folders and filing periods and turning into a data tax. For fraud enforcement, that is progress. For honest traders, it is also a real-time risk — because the same data that exposes carousel fraud also describes every legitimate deal. The decisive question is no longer “are our processes formally correct?” It is: “do our data tell the same story as our decisions — and can we prove it?” This page is written for international groups with German and EU operations: what is already live, what is coming, and what a defensible response looks like.

The data room is not arriving in 2030. It is already running.

Anyone filing this under “future regulation” underestimates what is in force today. Three components are operational; the fourth is enacted:

German e-invoicing (since 2025). Since 1 January 2025, businesses established in Germany must be able to receive structured electronic invoices; issuing obligations phase in until 2028. The invoice no longer starts its life in an accounting folder — it starts as a data model. Description, tax number, delivery date, payment path and price exist as machine-readable fields: comparable, searchable, linkable.

CESOP (EU-wide, since 2024). Payment service providers report cross-border payments — from 25 payments per payee per quarter — into a central European electronic system of payment information. Tax administrations no longer see only what was invoiced; they see where the money actually went.

Eurofisc and Transaction Network Analysis (TNA). Through the EU’s administrative-cooperation network, VAT identification, reporting and transaction data are analysed as networks. Suspicious chains are flagged algorithmically before any auditor opens a file.

ViDA (adopted 11 March 2025). The “VAT in the Digital Age” directive introduces digital real-time reporting for cross-border B2B supplies by 2030, with national systems converging by 2035. Recapitulative statements give way to transaction-level data feeds.

There is an institutional line as well: in November 2025 the European Commission proposed giving the European Public Prosecutor’s Office (EPPO) and OLAF direct, streamlined access to VAT information. The administrative data room and the prosecution apparatus are growing together — the procedural consequences are covered on our page EPPO: when the European Public Prosecutor’s Office investigates.

The enforcement case is real. The EU’s VAT compliance gap stood at roughly €128 billion for 2023, of which an estimated €12.5–32 billion is organised missing-trader fraud. Data-driven enforcement is legitimate. That is right. But it creates a second danger: honest businesses end up inside risk grids they neither see nor control.

The second wave of formalisation

In October 2025, Germany’s Federal Ministry of Finance raised the bar again: every mandatory invoice detail under Sections 14 and 14a of the German VAT Act must be contained in the structured XML part of the e-invoice; validation becomes the trader’s own responsibility; format errors and content errors are distinguished; and the structured data set must be archived audit-proof. That is a new formal risk layer for input VAT deduction. But the counter-rights are already in place. Input VAT deduction may not be sanctioned through mere deadline mechanics where an invoice arrives late in good faith (Aptiv, March 2026). A technical failure of an official portal must not defeat a taxpayer’s claims (Harry et Associés, March 2026) — a principle that translates to failures in e-invoice transmission. And since April 2026, Germany’s Federal Fiscal Court has admitted an appeal on the question whether an invoice costs the deduction solely because the supplier, mid-renaming, already used its new name — formalism control with immediate relevance for automated e-invoice identity checks. “Substance over form”, incidentally, applies even at the customs interface, provided there is no attempted deception (Palmsträle, June 2025).

What the data room sees — and what it does not know

Administrative risk selection works on anomalies: a price below market, a new supplier, a changed bank account, an unusual route, sudden growth, clusters of cancellations. Each anomaly can indicate fraud. Each can equally indicate competition, expansion — or a simple master-data error.

This is where many proceedings go wrong, and where the most important defence sentence of the data age sits: administrative data is not trader knowledge. The fact that Eurofisc, TNA or CESOP flags a chain says nothing about what a specific company could and should have known at the moment of its own decision. The Court of Justice drew that line early. In Mahagében and Dávid (2012) it limited traders’ verification duties — no business is obliged to audit every upstream supplier across Europe; that is the task of the authorities, who hold the investigative powers. In Aquila Part Prod Com (2022) and Global Ink Trade (2024) the Court confirmed: the tax administration must define the elements of the fraud precisely, prove the fraudulent acts, and establish that the taxable person knew or should have known — not the other way around.

A mid-sized trader is not a tax office. And the more systemic the state’s own answers become — reporting systems, payment data, network analytics — the less an individual trader may be conscripted as a substitute enforcement agency. What was reasonably verifiable ex ante is measured by the information available to the company at the time, not by the authority’s data lake years later.

The algorithm is not evidence

International tax scholarship identifies four risk lines of algorithmic fraud detection: predictions treated as supposed “proof of fraud”; data-quality and model errors; bias and function creep; deficits in judicial protection. The core sentence: fraud detection may only support the human decision — never replace it (Merkx/Luna Calzado). That is the foundation against any score-based finding of bad faith. German practice adds the warning: “A forged e-invoice is, from an input VAT perspective, hard cash. Without a single security feature.” (Findeis/Braun) And even the validation services disagree among themselves: different validators assess the same invoice differently — divergences your own tax CMS has to track (Böcker/Ras). Where the data trail feeds into cross-border investigations, a distinct procedural regime begins: when the data trail becomes an investigation: the European Public Prosecutor’s Office.

The defence question: which of your data will later be read against you?

Most e-invoicing projects test formats, interfaces, archiving and ERP fields. Necessary — but not sufficient. Technically flawless data can be fiscally damaging if it contains breaks that nobody explained at the time: the invoice and the goods flow do not match. The payer is not the buyer. The margin is an outlier. The delivery location changes without visible reason.

Such breaks used to sleep in folders. Now they sit in structured fields that can be mirrored automatically against reporting, payment and risk data. The result is a gap between reality and provability — and that gap must be closed before an algorithm finds it. Authorities are gaining a faster, clearer view of transactions. Many businesses cannot yet explain those same transactions with the same clarity. That gap is where the risk now sits.

The consequence is not bureaucracy but symmetry: if the state makes its control data-driven, the honest company must make its exculpation data-driven. Good faith has to become organised and machine-verifiable. “We were careful” will not carry the day. What carries is: “we can show what we checked, when, with which result — and who decided.”

From data risk to evidence architecture: Proof of Check

VSK’s answer is Proof of Check — not a certificate, not a trusted-trader badge, not a safe harbour, but documented, risk-based diligence at the moment of trading. Translated into the data room, that means:

  1. Create your own verification data instead of merely receiving other people’s. VAT ID checks with timestamp, source and result; re-checks at trigger events; versioned onboarding records.
  2. Build consistency where the algorithm hunts for breaks. Seller, buyer, payer, bank account, transport route and invoice should tell one story — deviations are either plausibly documented or the deal is stopped. Operationally this is the job of a traffic-light system with stop and hold rules.
  3. Explain anomalies yourself, before others interpret them. A red-flag memo — signal, source, assessment, additional checks, decision, responsible person — is the core defence against any later “should have known” allegation.
  4. Stay exportable. In a dispute, volume does not win; a readable Evidence Pack does: checks, results, timestamps, approvals and reasons. One clean export instead of 80 folders — compatible with exactly the data logic the administration uses.

The VSK Digital VAT Readiness Check connects tax law, process review and data logic: which ERP and invoice fields are risk-relevant? Which controls prevent master-data errors from becoming false red flags? Which evidence must be machine-readable and human-explainable at the same time? The outcome is a prioritised 90-day roadmap — from field mapping through roles and escalation thresholds to crisis readiness.

One thing we do not promise: immunity. No system prevents every tax-office question, and no adviser should claim otherwise. But a company that creates its own evidence in the data room shifts its position — from being described to doing the explaining. That is the difference between exposure and control.

FAQ

Does German e-invoicing affect a foreign parent company?

Indirectly, yes. The German subsidiary’s structured invoice data becomes part of an EU-wide analytics environment. Group ERP templates, master data and payment routes set in the parent company shape what German algorithms will later read.

What is CESOP — and does it concern us?

CESOP is the EU’s central payment-data system: since 2024, payment service providers report cross-border payments from 25 transactions per payee per quarter. If you sell across borders, your payment flows are visible there — payment plausibility therefore belongs inside your tax compliance management system.

What exactly does ViDA change?

By 2030, digital transaction-level real-time reporting replaces recapitulative statements for cross-border B2B supplies; by 2035, national systems converge. Declaration, control and evidence merge into one data logic.

Can authority-held data alone establish that we “should have known” of fraud?

No. Under CJEU case law, “should have known” must be derived from the information reasonably available to the company at the time of the transaction. What Eurofisc, TNA or CESOP knew internally is not attributable to the trader — and the burden of proof rests with the tax administration.

What does the VSK Digital VAT Readiness Check cover?

Data fields, processes, roles, red-flag escalation, correction routes, archiving and crisis readiness — so that your data speaks for you in a dispute. The outcome is a prioritised 90-day roadmap, not a corporate manual.

Your next step

Request a Digital VAT Readiness Check. We test whether your e-invoicing, payment and ERP data would speak for you under challenge — confidential, with a clear roadmap. [Request the Readiness Check]

Or run the self-test first: the VAT CMS Quick Scan makes risk visible in ten questions — before an algorithm does. [Start the Quick Scan]

Urgent matter — inspection, dawn raid, assessment notice? [Urgent line: call-back today.]

Book your free 15-minute assessment →Or pick a slot now (Mon·Wed·Fri 10–12)
◈ Explore this structure live — infinitely deep