Issue 01 · September 2026Where the protection function actually sits when the valuable intangible is software — and why the entity that owns the asset usually cannot protect it.
There is a line in a lot of transfer pricing files that has stopped meaning anything, and almost nobody has noticed.
It says the intellectual property holding entity performs the protection function. The evidence offered is that the entity engages external counsel, pays their invoices, and holds the registrations in its name. Patents are filed. Trademarks are renewed. Infringement actions are brought. All of it is documented, and all of it is paid for from the right place.
None of it demonstrates control.
When the DEMPE framework was written, protection had a fairly settled meaning. It described the work of keeping a legal right enforceable — filing, renewing, policing, litigating. That work is largely legal work, and legal work is largely outsourced, so an entity that instructed and paid the lawyers had a reasonable claim to be performing the function.
That reading has quietly stopped working, for two reasons.
The first is that engaging a service provider has never been the same as controlling the risk that provider is engaged to manage. This is not a new principle and it is not specific to protection. An entity that outsources a function while retaining control must have people capable of evaluating what the provider does. Otherwise it has bought a service, not exercised a function. Applied to protection, the question is not who signed the engagement letter. It is who decides which infringements are worth pursuing, what a reasonable settlement looks like, and when to stop spending.
The second reason is that for a large share of valuable intangibles, protection is no longer a legal activity at all.
Consider what actually protects the intangibles of a software business. The source code. The model weights. The customer database. The pricing logic. The internal know-how that would take a competitor four years to reconstruct.
Almost none of that is protected by a registration. It is protected by access controls, encryption, network segmentation, secrets management, threat detection, incident response, and a set of decisions about which risks are worth mitigating and at what cost.
Those decisions are made by a Chief Information Security Officer and a security operations team, and in most groups they sit nowhere near the entity that owns the intangibles.
Which produces a distinctly odd situation. The entity that formally bears the risk of losing the asset has no capacity to prevent the loss, and would not know it had occurred. The entity that would detect the breach, contain it and decide how to respond has no claim to the protection function at all, because the file describes protection as a legal activity and the legal activity happens elsewhere.
Both entities are behaving reasonably. The file is describing a company that does not exist.
The obvious response is that security is a general operating cost. Every group runs a security function, it protects everything the group owns, and treating it as a DEMPE function for intangibles would mean allocating a share of the security budget to every intangible in the group. That is unworkable, and it would make the analysis meaningless.
The objection is right about the general case and wrong about the specific one.
Nobody should attribute residual intangible return to routine IT security. Perimeter defence is overhead. But there is a distinction between running a security programme and making decisions that determine whether a specific valuable asset survives — deciding that the model weights get a different control regime than the marketing site, deciding what is acceptable exposure for the customer database, deciding whether a zero-day warrants pulling a product offline.
Those are risk decisions about identified assets, and they are made by named people who could have decided otherwise. That is what control looks like in every other part of the framework. There is no reason protection should be the exception.
Nothing dramatic, and nothing that requires restructuring.
Take the three most valuable intangibles in the group. For each, write down who would find out first if it were compromised, who would decide how to respond, and who has the authority to spend money preventing it.
Then compare those names against the entity your file says performs the protection function.
If they do not overlap, you have not necessarily got a problem — plenty of groups can explain the gap. But you have got a question you should answer before someone else asks it, and answering it is much easier while the people involved still work for you.
So: if the most valuable thing your group owns were exfiltrated tonight, who gets the call — and which entity does that person work for?
A new report in the minerals pricing series arrives on 14 September. Determining the Price of Minerals is listed for publication at 11:00 CET. Earlier reports in the series applied the mineral pricing framework to bauxite and to lithium, using the comparable uncontrolled price method to help resource-rich jurisdictions price exports.
The subtitle has not been published, so what this one covers is not yet confirmed. It is worth two minutes on the day if your group moves commodities between related parties — the series has been consistently practical.
Three decisions this issue, and they share a question: who has to prove what.
**United Kingdom — First-tier Tribunal (Tax Chamber), 28 May 2026, Lifeplus Europe Ltd v HMRC, [2026] UKFTT 797 (TC)**
Question: whether HMRC could compel a UK distributor to hand over its US parent's consolidated and entity-level accounts, through a Schedule 36 information notice, in a dispute about whether TNMM or CUP was the right method.
Decision: it could not. The accounts were neither reasonably required nor within the company's possession or power. The tribunal found no rational connection between the parent's financial statements and a dispute about method selection, and rejected the argument that the company had de facto power over privately held US documents through its directors.
Why it matters: the tribunal grounded this in the tested party. Section 164 TIOPA requires consistency with OECD principles, comparability turns on economically relevant characteristics, and the tested party here was the distributor — not the parent's overall finances. Which means the choice of tested party does not only decide how you benchmark. It decides what an administration can ask you for.
[caselaw.nationalarchives.gov.uk — [2026] UKFTT 797 (TC)](https://caselaw.nationalarchives.gov.uk/ukftt/tc/2026/797)
**Italy — Corte di Cassazione, sezione tributaria, decided 3 March 2026, published 25 March 2026, judgments 7169/2026 and 7163/2026, *GE Medical Systems Italia / Nuovo Pignone Holding***
Question: whether the Revenue Agency's TNMM analysis, built on nine comparables, established that intra-group purchase prices for medical equipment from French and US affiliates exceeded normal value.
Decision: the transfer pricing grounds were dismissed in both appeals. The lower court had found a lack of evidence that the prices departed from normal value under Article 9(3), and the Cassation held that reasoning adequate — reasoning is sufficient where it is clear, unambiguous and exhaustive, even where it adopts a party's arguments.
Why it matters: nine comparables and a method are not the same thing as proof. The administration carried the burden and did not discharge it, and the case failed on evidence rather than on methodology.
Denmark — National Tax Tribunal, 12 May 2025, case 19-0043023, published as SKM2025.704.LSR
Question: whether the price at which a Danish company sold intangibles to an affiliate was at arm's length, where the valuation applied a 20% required return to the business as a whole but only 8% to the routine functions being retained.
Decision: the adjustment was upheld. The tribunal accepted that routine functions form an integral part of the business, and that using a lower discount rate for them alone inflated their value — on the Tax Agency's figures, applying the same 20% would have cut the routine function deduction from over half the total to roughly a seventh.
Why it matters: the discount rate is not a technical input. It is a statement about risk, and applying two different ones inside the same valuation is a statement that one part of the business is safer than the whole it belongs to. That is a claim, and it has to survive being read as one.
Note on the burden here: because the Agency made an arm's length adjustment rather than an estimated assessment, it had to prove the reported price was not at arm's length. It did so using the independent price paid for the shares in an earlier year, the company's own DCF valuations, and documented changes in performance — the taxpayer's own material, in other words.
Luxembourg — the side-by-side protection regime, and the one jurisdiction that currently qualifies for it. Bill 8795 was deposited on 17 July, amending the law of 22 December 2023 on effective minimum taxation. It introduces three protection regimes into Luxembourg's Pillar Two law.
The first is the side-by-side regime: where a group's ultimate parent sits in a jurisdiction the Inclusive Framework recognises as having a qualified side-by-side system, the UTPR charge for Luxembourg constituent entities can be reduced to zero on election. The bill states plainly that at the time of deposit, only the United States is considered by the Inclusive Framework to have such a regime.
The second is a qualified ultimate parent entity regime, working similarly where the parent's jurisdiction has an eligible domestic tax system. At deposit, no jurisdiction qualifies for it at all.
The third covers qualified tax incentives — those generally available and tied to substantial economic activity.
What to do: if your ultimate parent is US-based and you have Luxembourg constituent entities, this is the provision that decides whether a UTPR charge arises. Read the conditions, not the summary.
chd.lu — bill 8795, deposited 17 July 2026
Italy — eight FAQs on the global minimum tax return, more useful than they sound. The Agenzia delle Entrate has published FAQs for businesses on the GloBE declaration, most recently on 17 July, with earlier batches on 26 June, 19 June and 29 May.
They answer the questions that only surface once you are filing: what happens to options exercised in a late Relevant Communication, how mid-year transitions between groups are reported, identification of funds that have been liquidated, filing responsibility where the parent is in Italy, equivalent minimum taxes operating as safe harbours, and currency conversion.
What to do: the point worth extracting is that options exercised in a late communication keep their effect. The penalty applies; the election does not lapse.
agenziaentrate.gov.it — GloBE FAQs for businesses
Canada — simplified documentation, and the window closes on 4 September. The Department of Finance released draft legislative proposals on 23 July allowing simplified transfer pricing documentation in four scenarios: small taxpayers and partnerships, small transfers of tangible property, small intragroup services transactions, and small loans. The same package carries a second set of hybrid mismatch amendments and changes to the Global Minimum Tax Act.
What to do: comments go to consultation-legislation@fin.gc.ca by 4 September 2026.
canada.ca — consultation on draft legislation
Belgium — the GIR notification deadline is narrower than it reads. The 30 September deadline for notifying which entity will file the GloBE Information Return applies only to fiscal years beginning between 31 December 2023 and 31 December 2024 and ending no later than 28 February 2025, or beginning on or after 1 January 2025 and ending no later than 31 May 2025. The obligation sits in articles 53 §3 and 54 §2 of the law of 19 December 2023.
Worth knowing: every group entity owes the notification annually, but a group may designate a single Belgian entity to file once for all of them. Filing runs through MyMinfin and needs the Pillar 2 role or mandate; the Biztax route works only until the end of 2026.
The clarification was never published as a news item. The page was edited.
finances.belgium.be — GIR filing entity notification
Transfer pricing, economic substance and valuation. One long piece, then what moved at the OECD, in the courts, and across jurisdictions — each item with its primary source.
One message a week. Your address is never shared or sold. Unsubscribe from any issue. See privacy.