Visa and Mastercard: what tax authorities really see from card spend

US-issued cards do not automatically send every purchase to AEAT. The real trail is issuer, network, acquirer, merchant, bank account, bookkeeping and local resident filings.

Visa, Mastercard and American Express do not automatically send your card purchases to Spain's AEAT. The serious analysis separates issuer, network, acquirer, merchant, account, bookkeeping and the real Spanish reporting models that can apply.

When someone asks "does the tax authority see what I pay with my card?", the short answer is: it depends on who issued the card, where the merchant sits and where you are tax-resident. The long answer requires understanding how the card ecosystem actually works underneath and which information returns really exist. There is a lot of myth around Visa and Mastercard, and it is worth separating it from what really happens with your <a href="/en/blog/wise-iban-and-llc-crs-holder-and-kyc">Wise card linked to a US LLC</a>, with your local bank card or with your <a href="/en/blog/revolut-business-crs-and-us-llc-banking-perimeter">Revolut card</a>.

This article walks through who is who in a card transaction, what each actor reports to tax authorities, and which card-related information returns really matter in Spain: Modelo 196 for accounts, Modelo 170 for card/mobile collections by Spanish entrepreneurs and professionals, and Modelo 174 for card information inside the scope created by Order HAC/747/2025.

CRS 2.0, CARF and DAC8 for Visa and Mastercard

What the OECD package does NOT cover is pure card spending: CRS 2.0 widens the perimeter to EMIs and electronic-money products, CARF adds crypto-assets, but Visa/Mastercard payment flows stay outside the automatic tax exchange and are governed by different rules (issuer KYC plus case-by-case administrative cooperation).

The OECD adopted an integrated package combining CRS 2.0 (the revised Common Reporting Standard, which brings EMIs and specified electronic-money products into the perimeter and tightens due diligence on controlling persons) and CARF (the Crypto-Asset Reporting Framework, which extends automatic exchange to crypto exchanges, custodians and crypto-derivative platforms). The European Union transposed it through Directive (EU) 2023/2226 (DAC8), adopted on 17 October 2023, which amends Directive 2011/16/EU to incorporate both components. The substantive application date is 1 January 2026 and the first effective exchange lands in January 2027, on the previous reporting year's data.

Card networks, acquiring banks and payment processors create a different evidence trail from ordinary bank-account CRS reporting. Visa or Mastercard activity can leave merchant, payout, chargeback and processor records that matter for compliance and tax analysis even when the underlying US account is not moving through a European CRS feed. We unpack the broader privacy layer in <a href="/en/blog/crs-carf-and-us-banking-privacy-for-llc-owners">CRS, CARF and US banking privacy for your LLC</a>.

The four-party model: issuer, network, acquirer, merchant

Every time you tap a card, four very different actors take part:

  • Issuer: the entity that issued your card and holds the account the money comes from. It can be a traditional bank (Chase, BBVA), an EMI (Wise Europe SA, Revolut Bank UAB) or a prepaid issuer.
  • Network or scheme: Visa, Mastercard, American Express, JCB, UnionPay. They do not hold your account or the merchant's: they route the authorisation message between issuer and acquirer and orchestrate the settlement.
  • Acquirer: the financial entity that has signed up the merchant and credits the payment to them. In Europe these are names like Stripe, Worldline, Redsys (through its member banks), CaixaBank Payments & Consumer, Banco Sabadell, etc.
  • Merchant: the business that takes the payment. It is identified by a Merchant Category Code (MCC) and a unique ID inside the network.

Understanding this chain is critical: no actor "sees" the entire movie. Each one only sees their own segment.

What each actor sees and what they don't

ActorWhat they know in detail
IssuerYour identity, your account, every charge with amount, currency, date, MCC and merchant name
Network (Visa/Mastercard)Authorisation messages between issuer and acquirer, aggregated data for settlement, fraud and disputes
AcquirerMerchant identity, every payment received, amount, currency, card brand and issuer BIN
MerchantTheir own payment, last 4 digits, brand, issuing country and, if you ask for an invoice, your details

What none of them does as a system is dump every single transaction live to the tax authority of every cardholder's country. That is simply not their role.

The most common (and wrong) idea about Visa and Mastercard

There is a widespread belief that "since Visa and Mastercard are American and everything goes through them, they must already be reporting everything to tax authorities worldwide". That is not the case:

  • Visa Inc. and Mastercard Inc. are payment processing networks, not depositary entities. They do not hold end-customer accounts and therefore are not "reporting financial institutions" under CRS or FATCA.
  • They do not report individual card spend by each cardholder to the <a href="https://www.irs.gov" target="_blank" rel="noopener">IRS</a>, the Spanish AEAT, France's DGFiP, the Belgian Service Public Fédéral Finances or any other national tax authority as an automatic feed.
  • They do cooperate with tax and judicial authorities in specific investigations, via formal requests, like any other company that custodies data.

Who is subject to information obligations is the card issuer (in its national filings) and, on the merchant side, the acquirer within its own books and the filings that apply in its country.

What the issuer actually reports in Spain

In Spain, domestic issuers file several information returns that are relevant for cards and accounts:

  • Modelo 196: annual return on accounts at credit institutions. It identifies holders and authorised users, balances on 31 December and, in many cases, average Q4 balances. It covers the account behind the card, not every movement.
  • Modelo 171: annual return on deposits, withdrawals and card payments above certain thresholds (classically, cash transactions above €3,000 and, for merchants, aggregated card receipts). This is the one most freelancers associate with "the tax office sees my card receipts".
  • Modelo 170: return on transactions made by businesses or professionals affiliated to a card collection scheme. Here acquirers report the receipts they have credited to merchants, not the payments you make as a consumer.
  • Modelo 199: identification of accounts with tax relevance.

Anyone using a card as a consumer in Spain whose account sits at a Spanish bank is, in practice, inside the perimeter the AEAT can consult periodically. And, above all, their balance and ownership are in Modelo 196 year after year.

The equivalent in other European countries

The scheme changes in each jurisdiction. Some representative examples:

  • France – DAS2: annual return covering fees, commissions and other income paid to third parties. For cards, the heavy lifting is done by DGFiP combining this return with the data fed by each bank. France additionally requires you to report foreign accounts (form 3916) and the digital assets attached, which typically includes Wise or Revolut IBANs.
  • Portugal – Modelo 38: annual return on transfers and remittances abroad. Modelo 40 complements it with securities transactions. Together with the obligation to disclose foreign accounts in the IRS, it draws a control perimeter similar to the Spanish one.
  • Germany: there is no Modelo-196 equivalent, but German banks operate the Kontenabrufverfahren, which lets the Bundeszentralamt für Steuern check ownership of accounts and deposits of any resident upon request from a competent authority. Card spend is not reported automatically, but the account is fully accessible.
  • Italy: the Anagrafe dei Rapporti Finanziari (Archivio dei Rapporti) collects yearly balances, aggregated movements and card data that Italian financial intermediaries send to the Agenzia delle Entrate. One of the densest schemes in Europe.
  • United Kingdom: HMRC receives aggregated data from banks via schemes such as Bulk Data Gathering, on top of CRS reporting for non-residents.

The general rule is that the account and the holder are well covered, while the transaction-level detail is not pushed by default: it is only reconstructed during a specific audit. At Exentax, sensitive steps sit in one controlled workflow, not in scattered notes.

The case of a foreign issuer: Wise, Revolut and friends

When your card is issued by a European EMI other than a Spanish bank (typically Wise Europe SA in Belgium or Revolut Bank UAB in Lithuania), the situation changes:

  • These issuers do not file the Spanish information returns (196, 171, 170, 199). Those are obligations for Spanish financial entities or branches established in Spain.
  • They are subject to CRS from their home jurisdiction. Wise Europe SA reports to the Belgian tax authority and Revolut Bank UAB to the Lithuanian one, which forward to the holder's country of residence the year-end balance and income, as we explain in <a href="/en/blog/crs-fatca-and-us-banking-privacy-for-llc-owners">CRS for LLC bank accounts</a>.
  • The detail of each card purchase does not travel via CRS. What travels is the closing balance, the holder identity and, if the account belongs to an entity classified as Passive NFE, the controlling persons.

This explains an observation many people make: a card payment from a Spanish bank shows up, aggregated with everything else, in the data the AEAT can consult; the same payment with a Wise or Revolut card is not reported directly to the AEAT, but the account balance will be reported via CRS from Belgium or Lithuania.

The reasonable conclusion is not "the foreign card makes me invisible" but that the trace exists in another layer: the account is identified, balances are reported and, in case of an audit, movements can be requested. Exentax records the decision so the next conversation starts from evidence, not memory.

And the merchant acquirer: the other end of the wire

We often forget the acquirer. When a Spanish merchant takes a card payment, its Spanish acquirer files Modelo 170 with the annual aggregate of card receipts for that merchant. If that merchant is an individual under-declaring income on their personal tax return, the AEAT cross-checks the Modelo 170 with the return and the discrepancy pops up. This does not affect the consumer, but it explains why the tax office detects under-declared card receipts so quickly.

For an entrepreneur with a US LLC charging end customers via Stripe US or a Merchant of Record like DoDo Payments, the flow is different: the acquirer sits outside Spain, no Modelo 170 is filed, and the income lands in Mercury or Wise. Traceability for the AEAT then runs through the balance and income via CRS, not through the acquirer.

What the tax authority can really see from your card spend

Mapped onto a Spanish tax resident combining a local bank with foreign fintech and, possibly, a <a href="/en/blog/us-llc-for-non-residents-tax-structure">US LLC</a>:

What the AEAT can consult on a recurring basis:

  • Spanish bank accounts where you are holder or authorised user (Modelo 196, 199).
  • Aggregated card receipts of a Spanish merchant (Modelo 170, if you are self-employed or a company).
  • Year-end balances and income of foreign accounts received via CRS from the issuer's country.
  • Foreign accounts you self-report in Modelo 720 once you cross the aggregate threshold.

What the AEAT does not receive automatically:

  • The detail of every purchase you make with any card, in Spain or abroad.
  • The list of merchants where you shop as a consumer.
  • Individual amounts below the 171 thresholds or equivalents.

What it can request if it opens an audit. With Exentax, the deadline is tied to a responsible person, a record and a practical action.

  • The full account statement directly from the issuer in Spain and, abroad, via specific exchange.
  • Targeted information from the card network or the merchant in advanced investigations.

Card myths that create reporting blind spots

  1. "Visa and Mastercard report everything live to the tax office." False. They are processing networks; they are not reporting entities or final issuers.
  2. "If I pay with a foreign card, my purchases are invisible." The detail is not reported automatically, but the account is visible via CRS and the trace is perfectly reconstructible.
  3. "Modelo 171 means the tax office sees every card purchase I make." No: 171 covers transactions above thresholds and aggregates of receipts, not every personal purchase below those thresholds.
  4. "If my LLC takes payments via Stripe, that is already reported in Spain." Not directly: Stripe US does not file Modelo 170, and information about your LLC reaches the AEAT through other channels (Mercury via FATCA is asymmetric, Wise via CRS, your own Modelo 720 if it applies).
  5. "Better always pay with the foreign bank card so I don't leave any trace." The trace exists, and operating in a way clearly designed to leave no trace is exactly the pattern that triggers alarms in an audit fastest. Exentax records the decision so the next conversation starts from evidence, not memory.
  6. "The acquirer of the European merchant where I shop reports my spending to the AEAT." No: the acquirer reports the receipts of its own merchant client, not the consumer's data.

Why this matters for your structure

If you combine a US LLC, a Mercury account, a Wise Business with card, a Revolut Business and a card from your Spanish bank for day-to-day spending, you do not have a "concealment" problem: you have a map of distinct traces, each with its own tax visibility. The right question is not "which card do I use so the tax office doesn't notice?" but "how do these pieces fit with my tax residence, my filings (IRPF, 720, 721) and the administrative doctrine that applies to my LLC?". We cover this in <a href="/en/blog/international-tax-design-3-jurisdictions-max-no-cfc">Designing a solid international tax structure</a> and, for the specific intersection with the <a href="/en/blog/wise-iban-and-llc-crs-holder-and-kyc">Wise card on top of an LLC</a>, in its dedicated article.

If you already operate with cards across several jurisdictions and you are not sure what is reported where, we review it with you and tell you what to fix before it is the tax office that sets the pace.

Card reporting follows the underlying account, not the logo

Visa and Mastercard networks are not the ones that flag your spending to the tax office: their job is to process payments. What does reach the tax authorities is information from the issuer (via national filings such as Modelo 196 or 171, DAS2, Modelo 38) and from the acquirer (aggregated merchant receipts). When the issuer sits outside your country, national filings do not apply, but balance and ownership do travel via CRS from the issuer's jurisdiction.

Card spend is not being live-streamed to your tax office, but it leaves a perfectly visible trace when someone decides to look. The difference between having problems or not is not which card you use, but whether your structure is coherent with your tax residence and your filings.

Card reporting follows the issuer and account holder

The Visa and Mastercard reporting question reads more calmly when it's treated as a stable mapping between the type of card, the issuer of the card, the country of the issuer and the channel through which information may reach the Spanish tax administration, than as a recurring rumour. The card networks themselves don't decide what's reported to whom — the legal channel that actually carries the information is set by the issuer's jurisdiction and by the agreements that apply to it. That mapping doesn't change month to month.

A short note in the personal folder that records the type of card held, the issuer, the country of issuance and the legal holder of the underlying account turns the same question into something that's reviewable in a few minutes the next time it comes up, instead of being re-derived from memory under pressure of a notification or an inspection request. Exentax makes the weak point reviewable: decision, evidence and next task.

The same note also makes it much easier to align what's declared by the resident with what arrives through the exchange channel.

> <a href="/en/book">Review my case</a>

Card-network and processor reporting should be read through entity, merchant account, payout account and tax residence. The same transaction can create different evidence depending on who is the merchant of record and where the money settles.

FinCEN and IRS reporting requirements moved recently; the current state is:

  • EIN and notice. Without an EIN you cannot file Form 5472. The IRS does not warn before imposing penalties; you find out when an EIN is flagged or a later filing is rejected. At Exentax, sensitive steps sit in one controlled workflow, not in scattered notes.

How card information actually reaches the Spanish tax authority

The flow of information from card networks to the Spanish tax authority is more concrete than it sometimes sounds. The starting point is the Spanish bank or payment institution that issues the card or processes it; the network itself is the rail, not the reporting party. Spanish issuers and acquirers feed informative returns to the Agencia Tributaria on regular cycles, and those returns contain aggregate movements per holder rather than the line-by-line restaurant or store detail that consumers see on their statements. The information that travels is therefore numerical and structural: totals, counterparties at the merchant-aggregator level, and identifiers that allow the records to be linked back to a person or company.

A second flow runs through the international information-exchange channels, where data on accounts held abroad is shared in standardised formats once a year. A card linked to a foreign account participates indirectly in this second flow because the underlying account is reportable. For an LLC member resident in Spain, the practical takeaway is that two parallel channels exist, that they overlap on the same person, and that they reconcile in the medium term. The simplest hygiene is to keep the LLC's card statements with the year's accounting record, so that any later question can be answered with a printed page and a number, without having to reconstruct the movement from memory.