

On 13 July 2026, alongside the draft DeFi and stablecoin tax measures we broadly welcome, the government published a third measure, on the reach of HMRC's information powers. It would let HMRC send a compulsory demand for records to any "person who provides services relating to cryptoassets", with no tribunal approval, no taxpayer consent and no right of appeal against the notice itself. It would also oblige anyone who "created, developed or produced" a piece of software to help HMRC inspect it.
Read literally, that includes us. So on 7 September we sent HMRC a response opposing the breadth of the measure.
Our position is simple. HMRC needs information powers, and we say so in the letter. These proposals are wider than the evidence supports, they have drawn little public comment so far, and they create a risk to the physical safety of crypto holders that the published impact assessment does not mention.
What L-Day is
Legislation Day is the day each July when the government publishes draft Finance Bill clauses for technical comment. Nothing on it is law yet. We covered the two tax measures, on stablecoins and DeFi, in a separate post. Unlike them, this measure takes effect from Royal Assent, expected in spring 2027.
What the measure does, and the gap it does not fill
Financial Institution Notices were introduced in 2021 so that HMRC could ask a bank for a customer's records without the taxpayer's consent or a tribunal's approval, after an international review found the UK too slow to answer overseas requests. The recipients were banks and similar institutions that hold customers' money and transaction records. The draft clauses extend the same notice to any "cryptoasset service provider", defined as anyone providing "services relating to cryptoassets".
That is not the definition already used in the UK's Cryptoasset Reporting Framework regulations, which is built around businesses that hold customers' assets or carry out transactions for them. On its face it catches tax software, wallet software, block explorers, data vendors and hardware wallet makers, none of which holds a customer's assets.
Three other things travel with it. The duty to assist an inspection extends from whoever runs a system to whoever built it, covering "software applications and logic, coding and metadata", with no express safeguard for proprietary code, no limit on the work demanded and no cost recovery. The annual report to Parliament on how these notices are used is abolished in the same measure that widens them, having just recorded the first legal challenge to a notice. And a notice to a bank or crypto service provider about a deceased person loses its four-year time limit altogether, while other notices keep it subject to tribunal approval.
Here is the point we most wanted HMRC to hear. Everything a tax software provider holds about a taxpayer comes from records the taxpayer and their exchanges already hold, and HMRC can already reach those with a notice to the taxpayer or a third-party notice that the taxpayer agrees to or a tribunal approves. A notice to a software provider adds a route without a safeguard. It does not add information HMRC could not otherwise obtain.
The asymmetry
As far as we know, Recap is the only crypto tax calculation provider incorporated in the UK and serving UK retail investors. The other significant providers UK investors use are incorporated overseas, even where they market from a UK address.
So a compulsory notice lands squarely and enforceably on the domestic business, and on its overseas competitors only in theory. A UK investor who values privacy, and is fully tax compliant, will see that their UK provider is named in UK legislation as a recipient of compulsory notices and the overseas alternatives are not. The response is obvious: use an overseas product.
That would not improve HMRC's access to information. It would move UK taxpayers' records to businesses HMRC can reach only through slower international channels. The published impact assessment says the change affects businesses "in the 100s", that the administrative impact is "negligible", and that "other impacts have been considered and none have been identified". We asked for it to consider this one.
A wallet address is not a bank statement
A bank record shows what a bank holds for you. A crypto accounting record shows where your own wealth sits, how much there is and at which addresses, because most people hold crypto themselves. Read against a public blockchain, a wallet address is a live, permanent, publicly checkable balance.
Checking someone's capital gains needs historic information: what they sold, when, for how much, and what it cost. It does not need a map of where their wealth is today. Extending these powers to accounting records and systems of record produces that map anyway.
Datasets like that have become a target for violent crime. In 2024 an employee of the French tax administration is alleged to have used an internal system to look up taxpayers who had declared crypto holdings and to have sold their names, home addresses and holdings to criminals. In January 2026 a French crypto tax software provider disclosed a breach of 50,000 users' gains, losses and balances, followed by an extortion demand. In each case the controls failed through the people with legitimate access, not the systems. We say clearly in the letter that this is not a criticism of HMRC's own security. It is a reason to collect less.
Parliament already accepts the principle: since 2025 anyone can apply to keep their home address off the Companies House public register. We asked for the same reasoning here: a statement that current holdings and wallet addresses are not "reasonably required" when historic disposal data answers the question, tribunal approval for any notice that seeks them, and limits on how long they are kept and who they are passed to.
Why we built Recap this way
Dan and Ben started Recap in 2018 because nothing on the market was built for UK rules or respected users' privacy. Privacy was not a feature we added later. It was the reason the company exists.
Your transactions, holdings and calculations are encrypted on your device before they reach our servers, with keys we do not hold. We cannot read your portfolio, and neither can anyone who obtains a copy from us. What we can see is what we need to run the service, your login identity and your billing, and lawful requests for that will be answered, as at any business.
A notice cannot compel what we were built not to hold. The only way this measure could reach a Recap user's portfolio data is by compelling us to weaken the encryption, build a new way in, or run our software over data HMRC has obtained elsewhere. We asked for the clauses to rule out each of those in terms. Reasonable assistance should mean explaining how our software works. It should never mean a backdoor.
For advisers weighing where clients' crypto records should sit, these proposed extensions to HMRC's information powers are the clearest argument yet for Recap. Because portfolios are encrypted client-side, a notice cannot compel what the platform was built not to hold, so a UK investor keeps HMRC's lawful access to historic disposal data without handing over a live map of where their wealth sits today.

What we asked for
- Narrow the definition. Align it with the definition already used in the Cryptoasset Reporting Framework regulations, or at minimum exclude businesses whose only crypto service is software, calculation, record-keeping, information or advice.
- Put a tribunal between HMRC and a person's holdings. Where a notice seeks wallet addresses or current balances, require First-tier Tribunal approval, as a third-party notice already does.
- Limit what happens to the data. Express rules on retention, internal access and onward disclosure overseas, with physical safety considered first.
- Keep Parliament informed. Retain the statutory annual report on these notices and extend it to cryptoasset service providers.
- Put limits around compelled assistance from developers. Voluntary cooperation first, a written request tied to an identified enquiry, no compelled disclosure of source code where an explanation will do, a tribunal route before work begins, and costs recovered.
- Assess the impacts that were missed. Competition between UK and overseas providers, and the physical security consequences of holding self-custody position data.
The full response
The full response is available here:
For the two tax measures published the same day, see our response on loans, liquidity pools and stablecoins. We would like to hear from accountants, investors and UK crypto businesses the measure would reach, and from anyone at HMRC who wants to talk through how encrypted, client-side architectures interact with these powers.
Tax should follow the economics. Information powers should follow the evidence.




