Germany's tax offices sent their first mass wave of DAC7-triggered letters to platform sellers in 2026, built on data from the January filing cycle, in a country where investigators in North Rhine-Westphalia alone suspect over €300 million in undeclared influencer income across roughly 200 open proceedings.
Gigapay is the Merchant of Record for creator payouts: the one vendor solution that pays your creators on your behalf by taking on the compliance, payouts, and support so you don't have to.
Every payment to a creator in Europe is now a compliance event, and the three obligations that dominate 2026 are DAC7 platform reporting, Germany's Künstlersozialkasse (KSK) levy, and the TIN and VAT validation work that sits underneath both.
This article breaks down exactly what each obligation requires, who carries the liability, what the penalties look like per country, and how platforms and brands handle all of it in practice.
Key Takeaways
- DAC7 requires platforms to verify seller tax data and file annually by 31 January.
- Germany's KSK levy is 4.9% in 2026 on creator payments above €1,000 per year.
- German DAC7 fines reach €50,000 per report; Sweden fines SEK 2,500–12,500 per seller.
- Platforms must offboard sellers after two reminders plus 60 days without valid TIN data.
- A Merchant of Record becomes the counterparty and absorbs the reporting workload.

Why Regulators Turned Their Attention to Creator Payments
The creator economy professionalized faster than the payment infrastructure behind it. Roughly 8.6 million European creators now earn money from content, and creator marketing budgets are compounding at around 26% per year. For most of that growth, the money moved like it was 2015: bank transfers, PayPal, spreadsheets, and no structured reporting to anyone.
Tax authorities noticed the gap between visible creator income and declared creator income, and they closed it with data. DAC7 turned every digital platform into a data-collection arm of the tax authorities starting in 2023.
The first reports were filed in January 2024, and for two cycles the data mostly sat in databases. That changed in 2025 and 2026. Germany's Bundeszentralamt für Steuern now matches DAC7 data against tax filings via each seller's Steuer-ID, Hamburg's tax office is auditing 140 influencers, and the Deutsche Rentenversicherung is running KSK-only out-of-cycle audits that reach back retroactive years.
In the UK, HMRC recovered over £41 billion in FY2024 with employment status as a stated priority, and creators are receiving platform-data nudge letters built on the same reporting pipelines.
The direction is consistent across every major European market: the entity in the middle of the payment now carries a documented duty to know who is being paid, verify their tax identity, and report it.
The 2026 Regulatory Stack Every Creator Payment Touches
DAC7 is the most visible obligation, but it sits inside a stack of instruments that all apply to creator payments in 2026.
Two of these deserve their own breakdowns, because they generate the most fines and the most confusion: DAC7 and the KSK.

What DAC7 Requires From Platforms Paying Creators
DAC7 (EU Directive 2021/514) obliges digital platform operators to collect, verify, and annually report information about sellers earning income through them. Content creation, design work, and marketing services all count as "personal services" under the directive, so creator platforms and marketplaces are squarely in scope. Payment processors are exempt; platforms that connect sellers with buyers are not.
Which Seller Data Platforms Must Collect and Verify
For each reportable seller with a company, the platform must collect the official name, primary address, tax registration number for each issuing Member State, VAT registration number, company registration number, and the existence and location of any permanent establishment in the EU.
For individuals, that means legal name, primary address, TIN, date of birth, and in most implementations the financial account identifies the money that lands in. In total, the directive's reporting schema runs to over 20 data points per seller.
Verification is a directive requirement, not a best practice. Platforms must check TINs against authoritative registries, including VIES for VAT numbers, and complete due diligence on new sellers by the end of the year in which they start selling.
DAC7 Deadlines and the Mandatory Offboarding Rule
The reporting cycle is annual. Activity from a calendar year must be filed by 31 January of the following year, so 2026 activity is due by 31 January 2027 (Germany extends its own deadline to 2 February). The report is a structured XML filing submitted to one EU tax authority, which then routes each seller's data to their home state through the automatic exchange of information.
The rule with the sharpest operational edge is offboarding. If a seller does not provide the required information after two reminders and 60 days, the platform must close their account or withhold their payouts. A platform cannot legally keep paying a creator who refuses to hand over valid tax data.
DAC7 Penalties by Country in 2026
Penalties are set nationally, and the spread is wide:
- Germany fines up to €50,000 per report.
- Sweden applies kontrolluppgifter fines of SEK 2,500 to 12,500 per seller.
- Spain runs a DAC7-equivalent regime through Modelo 238 with per-seller fines of roughly €200, on top of its VeriFactu invoicing-software rules and IRPF withholding at 15% (7% for new professionals).
Because fines in several countries scale per seller or per report, a platform with a few thousand creators and one bad filing cycle faces six-figure exposure.
There is one narrow exclusion: sellers with fewer than 30 transactions and no more than €2,000 in gross consideration in a calendar year fall below the reporting threshold. Most working creators clear that bar within a quarter.
How the KSK Levy Works for Companies Paying German Creators
The Künstlersozialkasse, established in 1983, funds social security for self-employed artists and publicists in Germany, a category that explicitly includes influencers and content creators. It runs a half-payment system: the KSK covers 50% of the creator's social insurance contributions, the share an employer would carry in regular employment, and finances that share partly through a levy on the companies that commission creative work.
Who Pays the KSK and at What Rate
The levy (Künstlersozialabgabe) is 4.9% for 2026, reduced from 5.0% in 2023 through 2025 per the official BMAS announcement. It applies to German companies that commission artistic or publicist work, including advertising and PR for their own business through self-employed creators, and it applies regardless of whether the creator is based in Germany or abroad.
The legal basis sits in §§24–25 of the Künstlersozialversicherungsgesetz (KSVG).
The trigger threshold, the Bagatellgrenze, has climbed steadily: €450 until 2024, €700 in 2025, and €1,000 for 2026. Once total payments to self-employed creators exceed €1,000 in a calendar year, the German company must register with the KSK, report the amounts, and pay 4.9% on top.
Companies based outside Germany do not pay the contribution. An intermediary that sits between the German client and the creator is also exempt, which is why the obligation stays with the German brand even when a payout provider handles the actual payment.
Why KSK Enforcement Got Serious in 2026
The Deutsche Rentenversicherung, which audits KSK compliance, is running KSK-only out-of-cycle audits in 2026, reaching back over retroactive years, with fines up to €50,000. Combined with the NRW criminal probes into roughly €300 million of suspected influencer tax evasion and Hamburg's audit of 140 influencers, Germany is currently the hottest enforcement environment in Europe for creator payments.
A German brand running creator campaigns without KSK registration is carrying a quantifiable, auditable liability that compounds every year it goes unreported.
Record-keeping matters as much as payment. The KSK requires liable companies to keep records of amounts paid, the context of the work, and the names of the creators involved (Informationsschrift Nr. 17). A brand that cannot produce that paper trail in an audit has a problem even if it would have owed relatively little.
How TIN and VAT Validation Works Under DAC7
TIN and VAT validation is the unglamorous layer that makes everything above it function. A DAC7 report built on unverified identifiers gets rejected or, worse, gets filed and later flagged, and each flagged seller record is a potential per-seller fine.
Why TIN Validation Is Harder Than It Sounds
Every EU country issues its own TIN in its own format, and creators frequently do not know which number is their TIN. A sample of what a platform must handle correctly:
Sole traders add a second layer, because in some countries the personal number doubles as the business identifier (Portugal's NIF, Croatia's OIB) while in others a separate registration number exists (Bulgaria's BULSTAT, Ireland's TRN). Companies add a third.
A platform onboarding creators in 20+ EU countries needs format validation, checksum validation where the algorithm exists, and registry lookups for every one of these variants.
Where VAT Validation and the Reverse Charge Fit
VAT numbers are validated against VIES, the EU's official cross-border VAT registry, and DAC7 expects platforms to use it. Validation also determines how the invoice itself is taxed. When a creator with a registered business invoices a company in another EU country, the reverse charge under Article 44 of the VAT Directive applies: the invoice carries no VAT, and the buyer self-assesses it.
That treatment is only defensible if the VAT number on the invoice is valid on the date of supply, which is why serious platforms validate at onboarding and revalidate periodically rather than trusting a number typed into a form once.
In a Merchant of Record structure, the creator invoices the MoR entity rather than the client directly. Because the creator is invoicing a Swedish company, the cross-border reverse charge applies in most cases even when the creator and the end client sit in the same country, which removes VAT handling from the brand's side of the transaction entirely.

How Platforms Handle Creator Tax Compliance in Practice
Companies paying creators at scale in 2026 land on one of three models, and the difference between them is who holds the liability when a filing is wrong.
Model 1: Build It In-House on Payment Rails
Stripe Connect, PayPal Payouts, and similar rails move money reliably, but their own documentation states that users remain fully responsible for tax compliance, and their tax-form tooling is built for US 1099 reporting, not EU DAC7.
A platform building EU compliance on top of rails is looking at an estimated €80,000 to €250,000 in build cost, plus permanent maintenance of TIN validation logic for 27 member states, annual XML schema updates, offboarding workflows, and a January filing operation. The relevant question for any team considering this path: who files your DAC7 report in January, and who pays the fine if it's wrong?
Model 2: AP Automation Tools
Tipalti and comparable accounts-payable platforms handle supplier invoices well, but they do not absorb liability and they struggle with the defining feature of the creator economy: most creators are individuals without a registered company.
A 19-year-old German creator with no company cannot be onboarded as a standard supplier, and no AP tool answers the question of who owes the KSK levy on her payment. AP tools and creator payout infrastructure coexist; they do not substitute for each other.
Model 3: Merchant of Record
Under the MoR model, the provider becomes the contractual counterparty: it formally purchases the creator's deliverable and resells it to the client. The client gets one vendor, one contract, and one consolidated invoice per campaign instead of hundreds of micro-vendor setups.
The MoR carries the platform-operator reporting duties that come with being the payer, including DAC7 due diligence, TIN and VAT validation, and the annual filing, while each party remains responsible for their own taxes: the creator for their income tax and social contributions, and the German client for its KSK levy, with the MoR supplying the payment data the client needs to report it.
For creator platforms and marketplaces specifically, the embedded version of this model matters most. Payouts through an API integration, with KYC, self-employment status checks, and DAC7 reporting scope handled by the infrastructure provider, means the platform's engineers stay on the product roadmap and the platform never becomes a regulated reporting entity itself.
What Creator Tax Compliance Costs When Handled Manually
The cost of doing this by hand is measurable, and it is larger than most finance teams assume before they count it.
For a brand running 600 creator collaborations per year, the manual process costs roughly €139,590 annually: around 840 admin hours across vendor onboarding, tax data collection, invoice processing, error cycles, and payment support, plus 300+ individual vendor records sitting in the ERP. The true cost per manual creator payment lands at €40 to €60 once you count the roughly 6 hours of cumulative admin each one generates across marketing, finance, and procurement.
The same volume through a consolidated MoR setup runs closer to €46,350 per year at around 60 admin hours, with invoice volume cut by roughly 80% through consolidated invoicing and self-billing automation. The delta is not the payment fee; it is the disappearance of the admin machine around each payment.
The tail risk sits on top of that baseline. DAC7 fines that scale per seller, KSK audits reaching back retroactive years, and a German §50a withholding regime of 15.825% on payments for commissioned creative work to foreign creators (where the paying company is liable if the deduction was missed, and exemption certificates take a year or more to obtain) all mean that the expensive scenario is not the admin hours. It is the audit you cannot document your way out of.
The 2026–2027 Creator Compliance Calendar
Compliance obligations in this space are dated, which makes planning possible for teams that look ahead.
- Q3 2026: DAC7 data-collection season for platforms. Every seller record that is incomplete now becomes a reminder-and-offboarding case before year end. France's e-invoicing mandate lands 1 September 2026: all French companies must be able to receive e-invoices.
- Q4 2026: The EU Platform Work Directive transposition deadline hits 2 December 2026, bringing a rebuttable presumption of employment with the burden of proof on the platform. Germany's KSK typically announces the following year's levy rate in November.
- Q1 2027: DAC7 filing deadline 31 January (Germany 2 February) covering all 2026 activity. This is when incomplete TIN data converts into per-seller fines.
- Ongoing: German criminal probes and DRV audits continue; the UK's umbrella joint-and-several liability rules have been live since 6 April 2026, putting agencies and end clients on the hook for umbrella PAYE failures; Sweden's plattformsarbete law (SOU 2026:3) is in consultation.
How Gigapay Handles DAC7, KSK Data, and TIN/VAT Validation
Gigapay operates as the Merchant of Record for creator payouts from its base in Stockholm, and the compliance workload described in this article is the core of what the product absorbs.
On DAC7, Gigapay collects the full required data set from every user during onboarding: official name, primary address, tax registration number per issuing Member State, VAT registration number, company registration number, and any EU permanent establishment.
Users cannot receive compensation without providing all requested information, which resolves the offboarding problem structurally rather than through reminder chains. Gigapay files DAC7 reports to Skatteverket for EU-resident sellers, and Skatteverket routes the data to each creator's home tax authority through the automatic exchange mechanism.
For Swedish payments, KU14 reporting runs alongside, including the Sweden–Denmark bilateral exchange.
On the KSK, the levy is legally the German client's obligation, and Gigapay as a Swedish intermediary is exempt from paying it. What Gigapay does is make the client's obligation manageable: a DPA signed with the service agreement allows Gigapay to share per-creator payment data, flag when a German creator crosses the €1,000 Bagatellgrenze, and supply the records (amounts, work context, names) that KSK record-keeping rules require in an audit.
On TIN and VAT validation, Gigapay runs KYC and KYB verification plus tax ID and VAT validation at onboarding across 65+ supported countries, with country-specific format handling for every identifier in the table above and dozens more. Creators onboard as individuals, sole traders, or companies, and no registered business or VAT number is required to get paid, which is the gap that blocks most AP tools from serving this market at all.
The scale behind the model: 105,000+ payouts processed, 911M SEK in total payout volume, creators paid in 40+ countries, payouts landing in as little as 7 seconds when pre-funded, and ISO 27001 certified infrastructure.
One important boundary stated plainly: in its MoR capacity, Gigapay does not withhold or pay social security or other taxes on behalf of users (Swedish exceptions apply). Each party complies with their own tax responsibilities, and Gigapay's job is to make sure the data, reporting, and paper trail behind those responsibilities exist without the client building any of it.

Conclusion
Gigapay is the Merchant of Record for creator payouts, the one vendor solution that pays your creators on your behalf by taking on the compliance, payouts, and support so you don't have to.
Creator tax compliance in 2026 comes down to three connected obligations: DAC7 reporting with its 31 January deadline, per-seller fines, and mandatory offboarding rule; Germany's 4.9% KSK levy on creator payments above €1,000, now backed by out-of-cycle audits; and the TIN and VAT validation layer that determines whether everything filed above it holds up.
Companies can build that machinery themselves, stretch AP tools past their design limits, or move the entire workload to a counterparty built for it.
If your creator program is reaching the scale where these obligations have your name on them, book a demo and see what the setup looks like with one vendor of record.
Read Next:
- Best Merchant of Record Platform for German Companies: September 2026 Review
- Multi-Currency Payouts and FX Reconciliation
- How to Bring Unmanaged Purchases, One-Off Vendors, and Long-Tail Suppliers Under Control
FAQs:
1. What is DAC7 reporting for creator platforms in 2026?
DAC7 reporting for creator platforms in 2026 is the EU obligation under Directive 2021/514 to collect and verify seller tax data (TIN, address, VAT number, company registration) and file it annually with an EU tax authority by 31 January, with mandatory offboarding of sellers who fail to provide valid data after two reminders and 60 days.
2. How much is the KSK levy on influencer payments in Germany in 2026?
The KSK levy on influencer payments in Germany in 2026 is 4.9%, reduced from 5.0% in 2023–2025, and it applies to German companies once payments to self-employed creators exceed the €1,000 Bagatellgrenze in a calendar year, regardless of where the creator is based.
3. What are the penalties for DAC7 non-compliance in 2026?
The penalties for DAC7 non-compliance in 2026 vary by country: Germany fines up to €50,000 per report, Sweden applies fines of SEK 2,500–12,500 per seller, and Spain fines roughly €200 per seller under its Modelo 238 regime, meaning exposure scales directly with creator count.
4. How do platforms validate creator TINs and VAT numbers under DAC7?
Platforms validate creator TINs and VAT numbers under DAC7 through country-specific format and checksum checks for each Member State's identifier (such as Germany's 11-digit Steuer-ID or Portugal's 9-digit NIF) and through registry lookups, with VAT numbers verified against the EU's VIES database at onboarding and periodically afterward.
5. Who is responsible for DAC7 reporting when a Merchant of Record pays creators?
The responsibility for DAC7 reporting when a Merchant of Record pays creators sits with the Merchant of Record as the platform-side payer: Gigapay, for example, collects the required seller data during onboarding and files DAC7 reports with the Swedish tax authority Skatteverket, which exchanges the data with each creator's home tax authority.
.jpg)

.jpg)



