UK MDR: Moving towards implementation

Outside HMRC

What is UK MDR (Mandatory Disclosure Rules)?

The Mandatory Disclosure Rules (MDR) in the UK are a set of regulations that aim to combat tax evasion and promote tax transparency. These rules require certain taxpayers and their advisors to disclose specific information to the tax authorities regarding certain types of cross-border transactions and arrangements.

The MDR framework is designed to enhance tax compliance and ensure that relevant tax authorities receive timely and relevant information about potentially aggressive tax planning. It helps tax authorities identify and scrutinise transactions that may involve tax evasion or abuse. By having access to comprehensive information, tax authorities can take appropriate action to protect the integrity of the tax system and prevent tax avoidance.

UK MDR implementation

UK MDR is making small steps towards implementation. The IT and Policy teams at HMRC are hard at work finalising everything that is required ahead of the new legislation.

Between November 2021 and February 2022, HMRC conducted a consultation on the new UK MDR legislation. While the results of the consultation have not yet been published, we understand that the results are ready and HMRC are making good progress with the final legislation. The announcement of a start date for UK MDR is expected soon.

VinciWorks MDR reporting system

HMRC’s IT team have been very busy preparing a new system to accommodate UK MDR reporting. VinciWorks and other key stakeholders have been helping HMRC with their technical research. It is understood that the UK MDR reporting system will sit side by side with the current DAC6 system. This is in order to allow for a short period where there might be reporting requirements under both UK MDR and UK DAC6. Reports under UK MDR will remain in the same XML format as UK DAC6.

Once legislation is confirmed and dates are finalised, VinciWorks will release updated DAC6 courses including new references to UK MDR, together with a new short course “UK MDR – What’s changed”. VinciWorks developers have been hard at work and the MDR reporting system is already able to support XML reports under UK MDR; this too will be released once legislation is confirmed.

How are you managing your GDPR compliance requirements?

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

“In a world older and more complete than ours they move finished and complete, gifted with extensions of the senses we have lost or never attained, living by voices we shall never hear.”

Picture of James

James

VinciWorks CEO, VInciWorks

Spending time looking for your parcel around the neighbourhood is a thing of the past. That’s a promise.

How are you managing your GDPR compliance requirements?

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

How are you managing your GDPR compliance requirements?

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.