CESOP Reporting in Luxembourg: The Quarterly PSP Filing to the AED

CESOP reporting in Luxembourg is triggered when, in a calendar quarter, a PSP provides payment services corresponding to more than 25 cross-border payments to the same payee. The count is calculated separately for payment services provided per Member State and per Article 243c(2) payee identifier; where the PSP knows that several identifiers belong to the same payee, those identifiers are aggregated for the threshold test. A payment service provider that crosses that line has to record prescribed data on the payee and every qualifying payment, then transmit it as an XML file to the Administration de l’enregistrement, des domaines et de la TVA (AED) through MyGuichet.lu by the end of the month after the quarter closes. The obligation has applied since 1 January 2024, and the first reporting quarter, January to March 2024, was already due by 30 April 2024.

The measure exists to help tax authorities detect e-commerce VAT fraud carried out by sellers who have no physical presence in the country of consumption. In Luxembourg, the AED receives CESOP payment data messages from in-scope PSPs through MyGuichet.lu before the information is transmitted into the EU CESOP process. For a Luxembourg PSP that provides in-scope payment services, the live question is whether the firm has mapped the 25-payment count correctly, populated the payee fields the schema demands, and cleared validation before the deadline.

Get the scope test wrong and a firm either over-reports payees it should have excluded, or misses a reporting quarter altogether. The Article 243b scope and threshold logic should therefore be controlled in the PSP’s reporting process before the XML is generated, rather than relying on downstream file validation to identify population errors.

Related reading: CESOP Reporting Explained

The framework sits on a two-instrument package the Council adopted on 18 February 2020. Council Directive (EU) 2020/284 amended the VAT Directive (2006/112/EC), inserting Articles 243a to 243d, which create the record-keeping and reporting duty for payment service providers. Council Regulation (EU) 2020/283 amended Regulation (EU) No 904/2010 on administrative cooperation and established the CESOP framework; the Commission develops, maintains, hosts and technically manages CESOP, which stores, aggregates and analyses the transmitted information. Commission Implementing Regulation (EU) 2022/1504 of 6 April 2022 then set the detailed technical rules, including the standard XML form in which the data reach CESOP, which Luxembourg also applies to the PSP submission.

The rules apply from 1 January 2024. Luxembourg transposed the Directive through the Law of 26 July 2023, published in the Journal officiel (A no. 473), which folded the payee-monitoring and transmission obligations into the national VAT legislation. That placement matters for who you deal with. CESOP is a VAT-law obligation in Luxembourg, and the reporting counterparty is the AED, the country’s indirect-tax authority, not the CSSF and not the customs administration. Reporting officers who sit in a payments or prudential function still file this one to the tax authority.

Once validated nationally, the data flows on from the AED into CESOP and is made available to anti-fraud specialists across the Member States through Eurofisc, the EU network that also includes Norway. The Directive builds the obligation on the PSP; the Regulation builds the machine that reads it.

Who must report: the four PSP categories providing services in the EU

For CESOP, Article 243a imports defined terms from PSD2. A ‘payment service provider’ is any of the categories in PSD2 Article 1(1)(a) to (d) (credit institutions, electronic money institutions, post-office giro institutions and payment institutions) or a natural or legal person benefiting from the PSD2 Article 32 exemption. A ‘payment service’ is limited to the activities in points (3) to (6) of PSD2 Annex I. The ECB, national central banks and Member State or regional or local authorities in PSD2 Article 1(1)(e) and (f) are not included in that CESOP definition.

Two assumptions are worth testing. The first is the small-provider exemption. Article 32 of PSD2 lets Member States waive parts of the licensing regime for small payment institutions. That waiver does not carry into CESOP: the Article 243a definition of a payment service provider expressly includes persons benefiting from the Article 32 exemption. A small payment institution that meets the other conditions still reports. The second is the belief that holding a PSD2 licence settles the question. It does not, because the duty attaches only to payment services within the definition in point (2) of Article 243a, that is points (3) to (6) of PSD2 Annex I; the Commission’s guidelines (section 2.3) confirm that payment initiation and account information services fall outside it. A payment initiation service provider that never holds or moves funds can hold a licence and still fall outside the reporting duty.

The marketplace case needs its own check. Where an online platform collects funds from the payer, holds them, and then pays the payee, the Commission’s guidelines treat it as a payment service provider that must register and report on the payees it pays. If your firm services those platforms, or is one, the classification decides everything downstream. The PSD2 reporting requirements that define these payment services are the right starting point for the scope test.

What the report contains: payee identity, transaction data and refunds

The payment data message is built around the payee and the reportable payment or refund. Article 243d and the standard electronic form require the reporting PSP’s BIC or other business identifier; the payee’s name or business name; the payee’s VAT or national tax number if available; the payee’s IBAN or another identifier that unambiguously identifies and gives the location of the payee; where the payee receives funds without a payment account, the BIC or other identifier of the payee’s PSP; the payee’s address if available; and transaction or refund details including date and time, amount, currency, Member State of origin or refund destination, the information used to determine that location, a unique transaction reference and, where applicable, an indication that the payment was initiated at the merchant’s physical premises.

The message carries payer-location metadata, meaning the Member State of origin of the payment or destination of a refund and an indication of the information used to determine that location, but no payer identity, no underlying payer IBAN, BIN, address or other identifier, and no payment purpose.

Granularity works on two levels. The count that triggers the obligation is assessed per payee, but the message carries the payments and associated refunds that the reporting PSP is required to record under Article 243b. For a payer’s PSP, payments for which at least one of the payee’s PSPs is located in a Member State still count towards the more-than-25 threshold but are excluded from that payer PSP’s Article 243b(1) record-keeping and reporting obligation.

Deadlines: the quarterly calendar and Luxembourg’s end-of-month filing dates

Reporting is quarterly under Article 243b, and the transmission is due by the end of the month following the calendar quarter. The AED publishes the Luxembourg dates as:

  • Q1 (January to March): 30 April
  • Q2 (April to June): 31 July
  • Q3 (July to September): 31 October
  • Q4 (October to December): 31 January

The first reference period was Q1 2024, transmitted by 30 April 2024. Whichever quarter is closing, its message is due by the end of the following month. The calendar repeats without variation, which is why the deadline is easy to schedule and easy to forget when a quarter produces no reportable payees.

The threshold resets every quarter, and that resets a common misconception. Assuming the PSP is required under Article 243b(3) to report the relevant payments, a payee that receives 30 cross-border payments in Q2 but only 10 in Q3 exceeds the threshold in Q2 but not in Q3. The count is a quarterly test, not a running annual total, so the population of reportable payees can change every three months. On record retention, the Directive requires the PSP to keep the records in electronic form for three calendar years from the end of the calendar year of the payment date, which runs well past the filing itself.

Where no payee crosses the threshold in a quarter, there is no payment data to transmit for that period. Neither the AED page nor the Guichet.lu procedure describes a formal nil declaration for Luxembourg, so a firm that wants certainty on whether the AED expects a nil notification should confirm that directly with the authority rather than assume silence discharges it.

Submission: XML payment data messages through MyGuichet.lu

Filing runs through a business eSpace on MyGuichet.lu. Before a firm can transmit anything, it completes an online CESOP certification of that eSpace to prove it is an authorised representative of the PSP. The AED asks for a duly signed mandate, on the form it provides, and a recent extract from the Trade and Companies Register showing the signatory’s authority. To create the MyGuichet.lu business eSpace, the user needs a LuxTrust product, a Luxembourg identity card with an activated electronic certificate, or an eIDAS means of identification from another EU or EEA state. The CESOP upload procedure itself is authenticated and Guichet.lu states that it requires LuxTrust or eIDAS. If the user does not have a Luxembourg national identification number (Matricule), Guichet.lu links to the dedicated procedure for obtaining one.

The payment data message is uploaded through the dedicated AED procedure for uploading a CESOP payment data message. The file can be XML, or a ZIP using the DEFLATE method, and the AED accepts one file with a maximum size of 80 MB per submission, provided the unzipped file stays below 900 MB. Larger populations are split into parts, and the file name carries the structure the Commission defined: PMT, then the quarter, the year, the reporting Member State, the PSP identifier, the part number and the total number of parts. If a PSP splits a message, it must create and transmit one MyGuichet.lu procedure per file, and every filename must follow the Commission naming convention, including the part-number and total-parts fields.

Notifications about a submission, including validation messages, land at the email address registered when the eSpace was created. A shared, monitored mailbox beats a single named inbox here, because the person who set up the eSpace is not always the person watching the deadline.

Validation: the EU module, national checks and common rejection causes

Validation happens twice. The Commission’s guidelines describe a national-level check, run by the AED, and a second check at the CESOP central level once the data reaches the database. Luxembourg’s current Guichet procedure instructs PSPs to validate their files beforehand using the European Commission’s Validation Module before uploading a payment data message. The module, distributed with a user manual and updated over time, tells a PSP whether its message complies with the schema while the firm can still fix it quietly. The Commission also publishes a CESOP Data Quality Checklist to help firms catch weak data before it becomes a rejection.

When the AED’s systems reject a file, they return a list of the errors to the firm’s business eSpace. The firm corrects the message and resubmits by opening a new upload procedure with a corrected XML file, and it needs to land the corrected file before the quarterly deadline to be on time. The standard electronic form applies presence and syntactic checks to specified fields including BIC, IBAN, country code and currency. PSPs should also verify which XSD and Validation Module versions are supported by Luxembourg and by the CESOP Central System for the relevant filing period. Our guide to common CESOP filing errors and fixes walks through the ones PSPs hit most.

Caveats and interactions: passporting, the payment count and adjacent tax reporting

Passporting widens the perimeter in both directions. A PSP established in another EEA state, including Iceland, Liechtenstein or Norway, that provides payment services in Luxembourg under PSD2 freedom-to-provide-services rules can be in scope even without a branch here. The mirror image applies to a Luxembourg PSP passporting into other Member States, which may carry a reporting obligation in each host state where it provides services. The test is whether the firm provides the payment service in Luxembourg, whatever its physical footprint.

The question of which PSP reports is governed by Article 243b(3). Where both the payer’s PSP and the payee’s PSP are located in a Member State, only the payee’s PSP reports, though the payer’s PSP still counts those payments for its own threshold assessment. Where the payee’s PSP is outside the EU, the obligation shifts to the payer’s PSP. One Brexit trap sits inside this: for CESOP purposes, payees and PSPs in Northern Ireland are treated as established in a third country, despite Northern Ireland’s position in the EU VAT area for goods.

CESOP also sits next to other Luxembourg reporting regimes that look similar but serve different regulatory functions. It is a VAT anti-fraud measure filed to the AED, distinct from the platform-operator regime under DAC7 reporting for Luxembourg platform operators, and distinct again from the automatic exchange regimes for financial accounts. Teams that run several of these should keep the scope tests separate, because a payee under CESOP is a different concept from a reportable seller under DAC7 or an account holder under the common reporting standard.

Recent and upcoming changes: guidelines updates and the simplification review

The obligation itself has been stable since 2024, but the supporting documents move. The Commission issued version 1.2 of its guidelines for the reporting of payment data in June 2025, following an additional clarification note in September 2024, and it refreshes the technical package on its own cadence, with an updated XSD package in 2026 and a Validation Module release carrying a user manual dated October 2025. A firm that builds once and never revisits the technical files risks filing against a schema version the central system no longer accepts.

The larger question hanging over the regime is simplification. On 18 August 2025 the Commission published two questionnaires on its EU Survey portal, one to Member State tax administrations and one to payment service providers, asking for views on simplifying CESOP reporting obligations. It published a summary of those surveys on 2 February 2026. This is a review rather than an enacted change, so the current scope test, data set and quarterly calendar all still apply. My working assumption is that firms should track the simplification track for direction while continuing to build and file to the rules in force.

Frequently Asked Questions

Does a Luxembourg PSP with no presence in another Member State still have cross-border payments to report?

Yes. Cross-border is defined by the location of the payer and payee, determined from identifiers such as the IBAN or BIC, not by the PSP’s own footprint. A Luxembourg PSP that serves payees located in other Member States, third territories or third countries can trip the threshold without any branch abroad.

A payee crosses 25 payments in one quarter but not the next. What gets reported?

For a PSP that has reportable payments to that payee under Article 243b(3), only the quarter in which the more-than-25 threshold is exceeded is in scope. The count resets each calendar quarter, so the reportable population can change from one quarter to the next.

Are refunds and reversals part of the message?

Yes. The records must include the details of any refund associated with a cross-border payment, reported alongside the underlying transaction data for the payee.

We qualify for the small payment institution exemption under PSD2. Does that remove the CESOP obligation?

No. The Article 32 PSD2 exemption for small payment institutions does not carry over to CESOP. A small provider that meets the other conditions still records and reports.

The payee’s payment service provider is outside the EU. Who files?

The payer’s PSP. Where the payee’s PSP is not located in a Member State, Article 243b(3) shifts the record-keeping and reporting obligation for that payment onto the payer’s PSP.

Do we ever report the consumer or the reason for the payment?

Only payer-location metadata is transmitted, meaning the Member State of origin and an indication of the information used to determine that location; payer identity, the underlying payer IBAN, BIN, address or other identifier, and the payment purpose are not.

Our quarterly file exceeds the 80 MB upload limit. What then?

Split the message into parts and upload them using the part-number and total-parts fields in the PMT file name. The AED accepts one file of up to 80 MB per submission, with the unzipped content under 900 MB, so a large book is transmitted as an ordered set of parts.

Key Takeaways

  • The trigger is more than 25 cross-border payments to the same payee in a calendar quarter, calculated separately for payment services provided per Member State and per Article 243c(2) payee identifier, with known identifiers for the same payee aggregated for the threshold test.
  • Luxembourg deadlines fall on 30 April, 31 July, 31 October and 31 January, one month after each quarter closes.
  • File the XML payment data message through a certified MyGuichet.lu business eSpace, at most 80 MB per file, splitting larger messages with the PMT part and total-parts naming.
  • Run the Commission Validation Module against the current XSD before transmitting; the AED returns errors to the eSpace and the firm resubmits before the deadline.
  • Report the required payee and transaction or refund data, including the payee’s address and VAT or national tax number where available; include the required payer-location metadata, but do not transmit payer identity, the underlying payer-location identifier or the payment purpose.
  • The Article 32 PSD2 small-provider exemption does not apply, and a PSD2 licence alone is not scope unless the firm provides an in-scope payment service.
  • Retain the records electronically for three calendar years from the end of the calendar year of the payment, as required by the Directive.
  • Track the Commission’s simplification review (surveys of 18 August 2025, summary of 2 February 2026) while filing to the current rules until any change is enacted.

Sources and References

Filing your next Luxembourg CESOP quarter

The practical work for a Luxembourg PSP is the same every three months: confirm which payees crossed 25 cross-border payments, build the payee and transaction records to the current XSD, validate the message with the Commission module, and upload it to the certified MyGuichet.lu eSpace before the end of the month after the quarter. For whichever quarter has just closed, that means having its payment data message validated and transmitted to the AED by the end of the following month, with a corrected resubmission still possible if the file is rejected before that date.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts