Cash register security regulation

from Wikipedia, the free encyclopedia

The Cash Register Security Ordinance ( RKSV ) is an Austrian legal regulation about mandatory technical security devices in cash registers , with the help of which a manipulation security for cash transactions is to be achieved.

As of January 1, 2016, the cash register security regulation in Austria is based on the obligation to keep individual records, the cash register obligation and the obligation to provide receipts. The Cash Register Security Ordinance itself came into force on April 1, 2017.

Legal basis

Individual record requirement

The general individual obligation to record (i.e. the ongoing and individual recording of all income and expenses) is given by §§ 131 and 132, in particular by § 131 para. 4 line 2 of the Federal Tax Code (BAO). Exceptions are stipulated in the cash turnover regulation.

Cash register obligation

Section 131b of the BAO prescribes the use of an "electronic cash register, cash register system or other electronic recording system" for the fulfillment of the individual recording obligation, provided that the annual turnover is at least 15,000 euros and of which at least 7,500 euros are cash transactions. Cash transactions also include payments with ATM or credit cards , other electronic payment methods such as Quick or mobile phone, and payment with vouchers, receipts or gift coins.

The Cash Register Security Ordinance describes requirements that a cash register must meet in terms of this obligation.

Documentation requirement

Section 132a of the BAO regulates the obligation to provide evidence. Every entrepreneur must issue a receipt for every cash transaction, regardless of the amount, and the customer is obliged to take it with him outside of the business premises.

The receipt must contain at least the following information:

  1. the name of the entrepreneur
  2. a consecutive document number
  3. the date the receipt was issued
  4. the quantity and the “customary description” of the goods or services supplied
  5. the payment amount
  6. (from 2017) the cash register identification number, the time, the breakdown of the amount according to tax rates and a machine-readable signature; these are not prescribed by the BAO, but by the Cash Register Security Ordinance.

Number 4 can also be fulfilled by a reference to another document if reference is made to this document in the document.

Cash turnover regulation

In the Cash Sales Ordinance 2015 , individual exceptions and reliefs to the individual recording obligation and the cash register obligation are defined. These concern sales that are carried out from house to house or in public places without connection to closed rooms ("cold hands"), certain machines and, under certain conditions, web shops.

Content of the regulation

The principle of the cash register security regulation is a chaining of cash transactions with the help of an electronic signature . This means that every receipt bears a signature that not only includes the receipt data itself, but also the signature of the immediately preceding receipt. This creates a seamless chain of all documents, and any subsequent manipulation of a document in the chain would not only result in the invalidity of its own signature, but also all the signatures of all subsequent documents.

Every cash register must have a so-called "security device" with a signature creation unit. Furthermore, it has to keep a data log in which every single cash transaction is recorded and saved, as well as a turnover counter that continuously adds up all cash receipts. The data acquisition log must be regularly saved on a data carrier and made available to the tax office on request.

Every single receipt from the register must be electronically signed. The signature value must be printed on the receipt as a QR code or in another machine-readable form together with the data that went into creating the signature .

Cash registers must have a unique identification number that must be printed on all receipts and also be included in the signature. Each individual cash register must be registered via FinanzOnline or the responsible tax office; a failure of the cash register or the signature creation unit must also be reported.

Closed overall systems, i.e. electronic recording systems in which merchandise management, accounting and cash register systems are seamlessly linked, can be subjected to an expert assessment of tamper-proof compliance at the expense of the entrepreneur from a volume of 30 cash registers. If the report is positive, there is no need for an external signature creation unit.

Most of the Cash Register Security Ordinance will come into force on April 1, 2017. The obligation to keep and provide a data log as well as the regulation for the failure of a cash register already apply from January 1st, 2016. From July 1st, 2016 cash registers can be registered with the tax office or via FinanzOnline, and the assessment of closed systems is also from this date Date possible.

Machine readable code

The signature consists of a string of data separated by underscores . Apart from the sales counter, the individual fields are in clear text and can easily be compared with the data printed on the receipt. The cash register number is a company-selected identifier that is only unique within the company. The number is not, such as B. in Hungary clearly assigned nationwide. The company is identified via the certificate serial number. The current status of the sales counter is encrypted with a freely selected, but the financial reported key with AES-256 / ICM .

  • Algorithm identifier R1 - identifier for the so-called "closed overall system" (AT0) or the respective trust service provider (AT1 - A-Trust, AT2 - e-commerce monitoring or AT3 - PrimeSign)
  • Cash register number
  • Document number
  • Document date-time in the format YYYY-MM-DD'T'hh: mm: ss
  • Amount at the normal tax rate (20%)
  • Amount at reduced tax rate 1 (10%)
  • Amount at reduced tax rate 2 (13%)
  • Tax-free amount (0%)
  • Amount at a special tax rate (19%)
  • Revenue counter status encrypted or U1RP for cancellation receipt
  • Certificate serial number
  • Signature of the previous receipt
  • Signature or replacement text if the signature creation unit fails

Example: _R1-AT0_DEMO CASH BOX524_366596_2015-12-17T11: 23: 44_0,00_0,00_3,64_-2,60_1,79_VFJB_47be737cb1f6d1f1_ZvNxJw6a1A4 = _J7YC28zquHfHzMpx02TqElbXOTSgXQu5JAA9Xu1Xzzu5p8eUYT + == sgmyhzRps5nYyEp5Yh8ATIa9130zmuiACHw

This code can be printed either as a QR code or as an OCR code . When displaying as OCR code (according to RKSV "OCR-compatible character string"), a BASE32 display of the binary data of the machine-readable code must be generated. If the printer cannot use an OCR font either, it is also possible to print a URL that leads to the machine-readable code. However, this address must contain the hash value of the signature.

Tax rates

The above tax rates apply according to the current version of the UStG 1994 .

Quote §10:

(1) The tax is 20% of the assessment base for each taxable turnover (Sections 4 and 5).
(2) The tax is reduced to 10% for ...
(3) If the tax rate according to Paragraph 2 is not applicable, the tax is reduced to 13% for ...
(4) The tax is reduced to 19% for in the areas of Jungholz and Mittelberg generated sales within the meaning of § 1 Paragraph 1 Z 1 and 2 by entrepreneurs who ...

Position of the Chamber of Commerce

The Chamber of Commerce said in a statement on the draft Regulation "massive overhead," "disproportionate cost" and a "clearly tight timetable" and called for changes in detail without jeopardizing the cash registers duty as such in question.

The signature creation units, which will be necessary for every cash register from 2017, require a certificate for a qualified signature according to the Signature Act . In Austria, at the time the law was passed, there were only two active providers. The Chamber of Commerce holds the largest share of the A-Trust , the much larger of the two. Signature certificates for the RKSV are currently offered by three of the Austrian trust service providers.

Web links

Individual evidence

  1. Beatrix Pausz: Only small club parties are exempt from the requirement to provide receipts. DerStandard.at , December 6, 2015, accessed on December 23, 2015 .
  2. Determinations of the BMF On detailed questions of the Cash Register Security Ordinance (RKSV) [1]
  3. a b BMF - security device in cash registers. Retrieved June 20, 2019 .
  4. Current information on the Cash Register Security Ordinance - WKO.at ( Memento from December 22, 2015 in the Internet Archive )
  5. Rundfunk- und Telekom Regulierungs-GmbH: List of certification service providers
  6. derStandard.at: A-Trust relies on mobile phone signature and e-safe
  7. ^ RTR - List of Trust Service Providers. Retrieved June 20, 2019 .