
Cross-Border Contractor Compliance: A Practical Checklist for European Companies
Education
Education
A Tallinn-based company hires a developer in Portugal, a designer in Poland and a consultant who splits the year between two countries. The work may begin within days. The compliance questions usually arrive later: Which entity should sign the contract? Is the invoice subject to VAT or reverse charge? Where is the work actually performed? Who may see the contractor's identity and bank data?
Those questions are easier to answer before the first payment than six months into the engagement. A good process does not need to turn every contractor into a lengthy legal project. It needs to identify the few facts that can change the tax, employment, social-security or data-protection treatment — and preserve the evidence behind each decision.
Do not let the contract label do all the work
Calling someone an “independent contractor” in an agreement does not settle their legal status. The practical relationship matters. A useful first review asks who controls the working time and methods, whether the person can serve other clients, who provides equipment, how the fee is calculated and whether the work has become part of the company's normal organisation.
There is no single shortcut that works in every European country. Employment status is determined under the applicable national rules and the facts of the engagement. That is why the assessment should be written down when the contractor is onboarded and revisited if the role becomes longer, exclusive or more closely supervised.
Build a file that explains the relationship
The point of an onboarding file is not to collect every document available. It is to make the relationship understandable to a finance manager, auditor or adviser who was not involved in the original discussion.
For most cross-border engagements, the file should answer six questions:
Who is providing the service — an individual, sole trader or company?
Where is that person or company registered and tax-resident?
Where will the work actually be performed?
What is being delivered, for what fee and during which period?
Which account will receive payment, and how was it verified?
Will the contractor have access to personal data, financial systems or regulated activity?
The supporting records will vary. They may include identity or registry evidence, a tax number, a certificate of residence, the signed contract, approved changes, invoices and payment confirmations. A certificate should not be requested merely because it exists; it should support a specific tax or reporting conclusion.
Connect the contract, invoice and payment
Many problems are not caused by an obscure rule. They start because three ordinary records tell three different stories. The contract names one supplier, the invoice arrives from another entity and the payment goes to a personal account in a third country.
Use a short control trail:
Control point | Question to answer | Evidence to keep |
|---|---|---|
Contract | Are the parties, service, fee, currency and termination terms clear? | Signed agreement and approved amendments |
Invoice | Does it match the supplier, service period and agreed amount? | Original invoice and approval record |
Payment | Does the recipient match the approved counterparty? | Payment confirmation and account-verification note |
Tax | What treatment was chosen, and why? | Tax IDs, residence evidence and dated review note |
Data | What personal or confidential information can the contractor access? | Access approval, confidentiality and data-processing terms |
A change of bank details deserves a separate check, preferably through a second channel. Familiar email is not proof that the request is genuine.
Treat VAT as a decision, not a default line on an invoice
The European Commission's VAT guidance says that the general place-of-supply rule for B2B services is where the business customer is established. It also lists important exceptions, including some services connected with property, events, transport and other specific activities. In qualifying cross-border cases, the customer rather than the supplier may be responsible for accounting for VAT under the reverse-charge mechanism.
That general rule is a starting point, not an instruction to copy “reverse charge” onto every contractor invoice. Before approving the invoice, confirm the status of both parties, the exact service, the relevant establishments and any country-specific reporting requirements.
For an Estonian company, the contractor's residence evidence can also matter outside VAT. The Estonian Tax and Customs Board's guidance on non-resident income shows that the place and nature of the service, an applicable tax treaty and a valid certificate of residence can affect withholding and declaration. The practical lesson is simple: record the facts before choosing the treatment.
Check where the person works, not only where they were hired
A remote engagement can become a cross-border working arrangement when the contractor travels, relocates or regularly works from another country. That may affect personal tax, social-security coverage and the company's own registration or taxable-presence analysis.
EU social-security guidance explains that a self-employed person temporarily working in another EU country may need a Portable Document A1 to prove continued coverage in the home system, subject to the applicable conditions. It is not a universal onboarding document for every remote contractor. It becomes relevant when the actual pattern of work fits the cross-border rules.
Record the expected work location at the start and require the contractor to report a material change. If the person begins working from a new country, do not assume the original conclusion still holds.
Collect less personal data, but protect it properly
Contractor files often contain passports, addresses, tax numbers, signatures and bank details. The European Data Protection Board's guidance for small businesses emphasises purpose limitation, data minimisation, storage limitation and access controls. In practical terms, that means deciding why each item is needed, who can see it and when it should be deleted or archived.
Do not keep identity documents in a shared project folder simply because it is convenient. Limit access by role, use secure transfer methods, remove obsolete permissions and set a retention period that reflects legal and operational needs. If the contractor processes personal data on the company's behalf, determine whether appropriate controller–processor terms and instructions are required.
Use AML/KYC checks where they genuinely apply
Not every contractor relationship triggers formal AML customer due diligence. The scope depends on the company's regulated status, the service, the jurisdiction and other legal or contractual duties. Where checks are required, FATF guidance supports a risk-based approach: the type and depth of identification, beneficial-ownership review and ongoing monitoring should reflect the risk rather than follow a single maximum checklist for every case.
Even outside a formal AML obligation, proportionate counterparty checks can be sensible when an engagement involves regulated work, unusual payment routes, sensitive financial access or a corporate supplier whose ownership is unclear. The reason for the check and its outcome should be recorded.
Review the relationship when the facts change
Calendar reminders are useful, but event-based reviews catch the changes that matter most. Reopen the file when:
the contractor moves or starts working regularly from another country;
the contracting entity, beneficial owner or payment account changes;
the role becomes exclusive, longer or more closely managed;
access expands to personal data, payment systems or regulated activity;
tax, residence or registration evidence expires;
invoices or transactions stop matching the agreed commercial purpose.
Each review should end with a dated conclusion, an owner and a next-review trigger. “Checked” is not enough if nobody can later see what was checked or why the decision was reasonable.
Make the process usable
The best compliance workflow is one that operations and finance teams can follow without improvising. It should connect corporate information, tax evidence, contracts, invoices, access rights and payment controls while reserving specialist review for uncertain or higher-risk cases.
Companies that need an independent review of this workflow can use FPRO compliance services for corporate and tax compliance, AML/KYC procedures, financial monitoring, licensing requirements and data-protection reviews.
The aim is not a larger document archive. It is a clear record of who was engaged, what they were paid for, which rules were considered and what needs to be reviewed when the relationship changes.