The danger of indirect tax non-compliance
A guide for VPN and privacy-service businesses selling subscriptions across borders
Why VPN companies face indirect tax exposure
VPN subscriptions are treated as taxable supplies in most jurisdictions worldwide when sold to overseas consumers. For CFOs of VPN companies, this creates exposure that traditional corporate tax planning does not address. VAT, GST and equivalent consumption taxes apply based on where the customer is located, not where the business is established, which means a company selling subscriptions across dozens of markets may carry registration and reporting obligations in every one of them.
The compliance burden scales quickly. The EU operates the One Stop Shop (OSS) for cross-border digital sales, while other territories impose their own registration thresholds, filing frequencies and payment mechanisms. Misclassifying a supply or missing a registration deadline can trigger back-taxes, penalties and interest that fall directly to the bottom line—amounts that are rarely recoverable from customers after the fact.
For subscription models with high transaction volumes and low individual values, even small errors compound. CFOs should also weigh the audit risk: tax authorities increasingly track digital service providers through payment data and platform reporting.
Building indirect tax into pricing, systems and forecasting from the outset protects margins and avoids retrospective liabilities. It is a governance issue as much as a compliance one and belongs on the CFO’s agenda.
What cross-border VPN sales mean in practice
The core implication is that a single VPN subscription can create a tax obligation in the customer’s country regardless of where the provider is based, often from the very first transaction. A VPN subscription is an electronically supplied service, so for B2C supplies the place of supply is the consumer’s location, determined by where the consumer normally lives. Within the EU there is no registration threshold for non-EU suppliers: the first euro of a digital sale to an EU consumer is within scope, and non-EU businesses can meet the obligation through a single Non-Union One Stop Shop (OSS) return rather than registering in all 27 member states.
For B2B supplies the position is different. Where the customer is a business that provides a valid VAT number, the reverse charge generally applies: the supplier does not charge VAT and the customer self-accounts for it in their own country. The distinction between a consumer and a verified business customer therefore directly determines whether tax is charged, and getting it wrong shifts an uncharged liability back onto the seller.
How VPN subscriptions differ from goods and physical services
The rules that apply to a VPN subscription are not the rules that apply to a shipped parcel or an on-site service. The differences are material:
- VPN subscriptions (VAT/OSS): taxed where the consumer is located, with no EU registration threshold for non-EU sellers. Reported through the Union or Non-Union OSS. No customs, no physical movement — the obligation is triggered purely by the subscriber’s location.
- Physical goods (IOSS): goods imported into the EU in consignments not exceeding €150 can use the Import One Stop Shop (IOSS) to charge VAT at checkout and clear customs faster; the previous €22 low-value relief has been abolished, so VAT applies to all imports.
- Physical (in-person) services: generally taxed where the service is physically performed or where the property is located.
- Marketplace goods: an online marketplace may become the deemed supplier and account for the VAT itself, the deemed supply rules also apply for digital services sold via a marketplace.
The practical consequence is that a VPN business selling a mix of subscriptions, any bundled hardware and human-delivered services cannot apply one VAT logic across the board. Each stream may sit under a different regime, a different threshold and a different return.
Making VPN subscriptions compliant
Selling a VPN subscription exposes a business to a set of obligations that are easy to underestimate because there is nothing physical to declare. Four issues cause most of the difficulty.
The end consumer can be anywhere
A VPN subscription can be bought by a consumer in any country at any time, and each country may have its own rate, rules and reporting. Because place of supply follows the consumer, the provider must be able to determine the subscriber’s country for every single transaction and apply the correct local rate. Within the EU alone, standard VAT rates on digital services range from 17% to 27% depending on the member state.
You need proof of the customer’s location
It is not enough to charge the right rate — the seller must be able to prove why that rate was correct. EU law requires businesses to obtain and keep two pieces of non-contradictory evidence of the customer’s location, and to retain that evidence for 10 years. Acceptable evidence includes the billing address, the customer’s IP address, the location of the bank, the country code of the SIM card, and other commercially relevant information.
Where evidence conflicts — a German billing address but a French IP address, for example — the supplier must exercise judgement and document how the discrepancy was resolved. A limited simplification exists: EU-established businesses with cross-border digital sales below €100,000 a year may rely on a single piece of evidence. Tax authorities do audit this evidence trail, so it is not a formality.
The channels you sell through matter
Where a sale is facilitated by an online marketplace or electronic interface, that platform may be treated as the deemed supplier and be responsible for calculating, charging and remitting the VAT. For VPN providers this matters because subscriptions are frequently sold through the Apple App Store and Google Play as well as direct. This is helpful — the store can remove the obligation from the provider for in-scope transactions — but it is not a blanket exemption. The provider remains responsible for subscriptions sold directly (through its own website), for B2B supplies, and for anything outside the platform’s deemed-supplier scope. Assuming “the app store handles VAT” when it does not is a common and expensive error.
You may be selling a combination of services with different VAT treatment
VPN businesses rarely sell one clean product. A single commercial offer can bundle elements that attract different VAT treatment, and the provider must decide whether it is making one composite supply or several separate supplies. Examples where treatment can diverge:
- VPN plus bundled add-ons: a plan that bundles the core VPN service (a digital service) with add-ons such as cloud storage, a password manager or antivirus may need to be split or treated as a single composite supply.
- Live virtual events: from 1 January 2025 the EU taxes live-streamed virtual events based on where the customer resides, aligning them with other digital services — a change from the previous position.
- Content plus a physical item: a product that includes both a download and a physical component can involve multiple supplies, each requiring its own VAT analysis.
- E-learning: automated online courses are typically digital services, whereas live, human-taught distance learning may fall under different rules depending on the jurisdiction.
A customer can also change the analysis mid-contract; for instance by providing a valid VAT number partway through, flipping a B2C supply into a B2B reverse-charge supply. Systems and contracts need to accommodate this rather than assume a fixed treatment.
Changes in taxation: the new obligations
The direction of travel is unmistakable: more jurisdictions are taxing non-resident digital sales, thresholds are being simplified, and transaction-count tests are being dropped in favour of pure revenue thresholds. This matters for VPN providers because subscriptions fall squarely within these digital-services rules. In the United States, an increasing number of states now tax digital products and SaaS, and the South Dakota v. Wayfair decision allows states to require out-of-state sellers to collect tax based on economic activity rather than physical presence. SaaS is taxable in some form in around 25 US jurisdictions, with New York, Pennsylvania, Texas and Washington among the clearest examples.
States are also removing the old “200 transactions” trigger: Alaska did so from 1 January 2025, Utah from 1 July 2025, and Illinois from 1 January 2026 — leaving a $100,000 sales threshold as the single test in each. The table below summarises representative digital-services registration thresholds for non-resident or remote sellers. Thresholds and taxability change frequently and should be verified before relying on them.
| Jurisdiction | Regime / rate | Threshold for non-resident / remote sellers | |
| European Union | VAT via OSS (17%–27%) | No threshold for non-EU sellers — VAT from the first sale; €10,000 intra-EU threshold for EU-established sellers | |
| United Kingdom | VAT (20%) | £0 for non-UK digital service providers — register from the first sale | |
| United States (SaaS/digital) | State sales tax (varies) | Commonly $100,000 in sales (many states have dropped the 200-transaction test) | |
| Australia | GST (10%) | AUD 75,000 in Australian sales | |
| New Zealand | GST (15%) | NZD 60,000 in a 12-month period | |
| Canada | GST/HST (5%+) | CAD 30,000 in Canadian sales | |
| Singapore | GST | SGD 1m global turnover AND SGD 100,000 into Singapore | |
| Taiwan | VAT (5%) | NTD 600,000 (raised from NTD 480,000 in April 2025) | |
| Nigeria | VAT (7.5%) | USD 25,000 in a 12-month period | |
| Tajikistan | VAT (18%) | No threshold — register from the first sale |
Note: rates and thresholds are indicative and subject to change; registration rules sometimes differ between resident and non-resident suppliers. Always confirm the current position for each jurisdiction before acting.
Tax authorities are acting
Rules only matter if they are enforced, and enforcement has moved from policy development to what one analysis calls “enforcement maturity.”Tax authorities now hold near-complete, often real-time transaction data and increasingly treat VAT risk as a data-governance issue for the whole enterprise.
Tax authorities are auditing digitally-delivered businesses — VPN providers among them — more aggressively, and the sums recovered are climbing steeply. In the UK, HMRC opened 11,894 VAT investigations into large and medium-sized businesses in the year to March 2025 — a 31% jump on the 9,071 the year before, and those probes yielded £5.3 billion in additional tax, equivalent to £8.6 million per case. In the 12 months to 31 July 2025, HMRC imposed 582,000 penalties for late VAT payments, up from 569,000 a year earlier, with the total value rising to £302 million from £294 million — and the authority is adding 5,500 compliance staff to sustain the push.
The pattern is mirrored across Europe:
- Romania’s ANAF launched a 2025 audit programme targeting over 500 major taxpayers — more than one-third of its largest economic entities — with a specific focus on cross-border operations, while penalty regimes themselves are severe
- Italy imposing a penalty of 120% of VAT due for an omitted return (reduced from the former 120%–240% band for infringements committed from 1 September 2024)
- Belgium levying up to 200% of the VAT owed.
For a VPN business, the message is consistent wherever it sells: enforcement is now data-led, better resourced and materially more likely to result in a costly assessment.
More proactive, more data-driven
- Cross-checking platform data against returns. Authorities cross-reference platform transaction data (for example DAC7 reports) against VAT returns to identify discrepancies, with the €150 IOSS threshold and facilitation status among common audit focus points.
- E-invoicing and real-time reporting. The EU’s VAT in the Digital Age (ViDA) reform introduces e-invoicing, real-time automated reporting and cross-border data matching specifically to detect fraud and close the compliance gap.
- Risk-based audit programmes. Romania’s ANAF launched a 2025 programme announcing audits of over 500 major taxpayers — more than one-third of its largest economic entities — scrutinising cross-border operations and classifying taxpayers into risk categories.
- Evidence from digitalisation. Academic work using the full universe of Rwandan tax filings found that audits uncovered underreported tax bases of about 28% of the potential tax base audited (around 31% including fines), and that e-invoicing meaningfully improved audit effectiveness.
Rising penalties
Penalty regimes for non-compliance are severe and compound quickly for high-volume subscription businesses:
- Italy: failure to submit an annual return attracts a penalty of 120% of the VAT due for infringements committed from 1 September 2024 (previously 120%–240%); late or omitted payment carries a base penalty of 25% (reduced from 30%).
- Belgium: penalties of up to 200% of the VAT owed, plus fines for late or non-filing of up to €5,000,000.
- Spain: audit-discovered non-payment can trigger penalties of 50%–150% of the unpaid VAT; fraudulent conduct can bring 80% surcharges, fines above €75,000 and prison sentences of up to five years.
- France: late submissions can trigger penalties of 10%–80% of the VAT due.
- Look-back and lost registration. Authorities can typically look back four years — or up to ten in fraud cases — and a suspended or revoked VAT registration can stop a business trading in that market entirely.
Case studies: authorities pursuing digital businesses
No VPN provider has yet faced a public settlement on this scale, but the following cases show what is at stake for any digitally-delivered business whose liability follows its customers rather than its physical footprint — precisely the position a VPN company is in.
- Uber — United Kingdom (HMRC)
Uber settled its UK VAT dispute with HMRC for all periods before 14 March 2022, making a payment of approximately $733 million (£613 million) in the fourth quarter of 2022. It subsequently received further HMRC assessments of roughly $789 million (£631 million) disputing its VAT treatment for the period from March 2022 to June 2023.
- Booking.com — Italy (Revenue Agency)
Following a tax investigation, and after the claim was extended to 2022, Booking.com agreed a settlement of €94 million with the Italian Revenue Agency. The original accusation, dating from 2021, alleged VAT evasion of nearly €153 million across 2013–2019. The case underlined the need for digital platforms to reassess VAT compliance continuously when operating across multiple jurisdictions.
- Netflix — Italy (tax authorities)
Netflix agreed to pay €55.8 million to settle a tax dispute with Italian authorities, who argued the streaming company had breached tax rules — notwithstanding Netflix’s position that it had complied with Italian and international rules. The case demonstrated that a digital business can face substantial liability in a country where it has customers but limited physical presence.
The common thread: none of these businesses had a conventional bricks-and-mortar footprint proportionate to the tax assessed. A VPN provider, selling an intangible subscription into dozens of markets from a single base, sits in exactly the same position. Liability followed the customers, the settlements ran into hundreds of millions, and the disputes stretched back years — exactly the exposure that a robust, well-documented compliance position is designed to prevent.
Impacts on companies
Smaller VPN providers and start-ups
For early-stage and scaling VPN businesses, indirect tax compliance is not just a regulatory box to tick — it is increasingly a condition of raising money and of surviving growth.
- Due diligence and a clean audit trail. Any serious investor or acquirer will examine indirect tax exposure. Undisclosed VAT/GST or sales-tax liabilities — with four-to-ten-year look-back periods and penalties layered on top — are a classic deal-breaker or valuation-reducer. A complete, documented audit trail (location evidence, correct rates, filed returns) turns a potential red flag into a non-issue.
- Liability grows silently with revenue. Because many regimes have no threshold for non-resident digital sellers, an unregistered start-up can accrue liability from its very first international sale. The problem is invisible until an audit or a diligence process surfaces it — by which point back tax, interest and penalties have compounded.
- The cost of getting it wrong scales badly. For a business processing thousands of transactions a month, per-jurisdiction audit costs and compounding penalties escalate rapidly, and a suspended registration can shut off a market entirely.
- Credibility with customers and partners. Correct invoicing, valid VAT numbers and proper reverse-charge treatment are expected by B2B customers; getting them wrong creates friction and undermines trust.
Large multi-jurisdictional and multi-subsidiary companies
For established groups operating across many countries and legal entities, the challenge is scale and consistency. The benefits of centralising and automating indirect tax are substantial.
- Transparency and control. With authorities now holding near-real-time transaction data, VAT risk is a data-governance issue. A centralised, automated approach gives the group a single, consistent view of its obligations and reduces the chance that one subsidiary’s error becomes a group-wide assessment.
- Lower audit exposure and cost. A modest, coordinated programme of governance, systems and documentation materially reduces audit exposure and cost — poor data quality, not just legal positions, now drives assessments, penalties and cash-flow delays on input VAT.
- Reputational risk. As the case studies show, high-value disputes attract headlines. Centralised compliance protects the brand as well as the balance sheet.
- Continuity of supply and trading rights. A registration suspended for non-compliance can halt trading in a market; automation across all jurisdictions guards against the disruption of losing the right to sell.
CFO checklist: selling VPN subscriptions
Key questions for the finance team before and while selling VPN subscriptions across borders.
- Where are our customers? Can we identify the country of every B2C customer for every transaction, and apply the correct local rate?
- Can we prove location? Are we capturing and retaining two non-contradictory pieces of location evidence (billing address, IP, bank, etc.) for 10 years, with a documented process for conflicts?
- B2B or B2C? Are we validating VAT numbers (e.g. via VIES) and applying the reverse charge correctly; can we handle a customer switching status mid-contract?
- Where are we over the threshold? Have we mapped registration thresholds in every market, recognising that many digital-services regimes have no threshold for non-resident sellers?
- Are we using OSS / IOSS correctly? Are we filing through the right simplification scheme, and do we still hold any local registrations we cannot avoid (e.g. domestic stock, B2B, goods over €150)?
- Who accounts for the VAT on each channel? For every app store and platform we sell through, do we know whether it is the deemed supplier or whether the obligation remains ours?
- Are our bundles analysed? Have we reviewed composite vs multiple supplies for every plan that bundles the VPN with add-ons such as storage, antivirus or a password manager?
- Is the audit trail complete? Could we withstand an audit or investor diligence today: evidence, rates, invoices, returns and filings all reconciled and retained?
- Are we ready for e-invoicing and real-time reporting? Do our systems support ViDA-era e-invoicing and digital reporting obligations as they come into force?
- Do we monitor change? Do we have a process to track rate, threshold and rule changes across every jurisdiction we sell into?
Meet the team who can help
Tax Desk is an indirect tax compliance specialist; we are not a generalist accountancy firm or a tech-only provider. We handle registration, submissions, payments and audit support across VAT, US Sales Tax, GST, EPR, IOSS and OSS for VPN and other subscription businesses selling anywhere in the world.
Our pedigree is Big 4. Tax Desk was originally built by KPMG for Amazon before being sold as a standalone business. Our platform and the people behind it were designed from the outset to handle indirect tax compliance at genuine scale, under the standards of one of the world’s largest professional services firms. That heritage is why enterprise and high-growth e-commerce clients trust us with their most complex, multi-jurisdictional obligations.
| 300,000 submissions to date | 20,535 submissions this year | €300M VAT payable |
Xiayang Liu — Commercial Director and Head of Indirect Tax
Xiayang leads our indirect tax practice and commercial strategy, bringing deep technical expertise across the full spectrum of VAT, GST and sales tax regimes. He is the senior point of authority on complex, cross-border and multi-jurisdictional questions — the person clients turn to when a position needs to be defensible in front of an auditor.
Anna Hutton-North — Sales & Marketing
Anna heads sales and marketing, and is the first point of contact for businesses working out where their exposure sits and how Tax Desk can help. She translates the technical detail of indirect tax into a clear commercial picture, so clients understand exactly what they need, why, and what it will take to get compliant.
Our Account Management team — Your dedicated day-to-day partners
Every client is supported by a dedicated account manager who owns the relationship end to end — coordinating registrations, submissions, payments and deadlines across every jurisdiction, and making sure nothing falls through the cracks. They are your single, consistent point of contact through the client portal, keeping your compliance calendar on track all year round.
Our Country Experts — Local specialists across 90+ jurisdictions
Behind every filing sits a network of in-country specialists who know the local rules, rates, formats and authorities intimately. This is what lets us handle country-specific obligations, from EU VAT to US State sales tax through to Australian GST, accurately and on time – wherever your customers are.
If any answer on the CFO checklist is “not sure,” we can help you close the gap before an auditor or investor finds it. www.taxdesk.com



