Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

travel rule explained

Crypto Travel Rule: The Complete EU Guide With No Threshold (2026)

The travel rule for crypto-assets in the EU is Regulation (EU) 2023/1113 — the recast Transfer of Funds Regulation adopted alongside MiCA — and it has applied since 30 December 2024 with no de minimis threshold: every transfer of crypto-assets in which the originator’s or the beneficiary’s crypto-asset service provider is established in the Union must be accompanied by a defined set of originator and beneficiary information, submitted in advance of or simultaneously with the transfer, verified before it is executed, and retained for five years. Transfers to or from self-hosted addresses are not exempt; the CASP must obtain and hold the same information, and above €1,000 must assess whether the self-hosted address is owned or controlled by its own customer. The EBA’s travel rule Guidelines of 4 July 2024 specify how CASPs detect missing information and what to do when it is missing. This guide sets out the scope, the exact Article 14 data set, the originator, beneficiary and intermediary duties, the self-hosted address rules, the missing-information procedure, the record-keeping and data-protection requirements, and how the EU rule compares with the FATF standard it implements.

The EU crypto travel rule: Regulation (EU) 2023/1113
Originator CASP: collect + verify Art 14 data, send before or with the transfer → Intermediary CASP: transmit and retain (Arts 19–21) → Beneficiary CASP: detect missing data, reject/return/suspend or request (Arts 16–17) → self-hosted: obtain and hold, >€1,000 ownership check (Arts 14(5), 16(2)) → 5-year retention (Art 26) · no threshold · applies from 30 Dec 2024.

Scope

Provision What it says Consequence
Article 2(1) Applies to transfers of crypto-assets, including those executed by crypto-asset ATMs, where the CASP of the originator or of the beneficiary is established in the Union One EU CASP on either end brings the transfer in
Article 2(4) Does not apply to person-to-person transfers carried out without the involvement of a CASP Wallet-to-wallet transfers between individuals are outside; anything a CASP touches is in
Article 2(4) E-money tokens are treated as crypto-assets under the Regulation Stablecoin transfers are covered
No threshold The Regulation sets no minimum amount for crypto-asset transfers Unlike the FATF’s optional USD/EUR 1,000 threshold, every transfer carries the data
Article 40 Applies from 30 December 2024 The same day as MiCA Title V

Our guide to CASP authorisation covers the MiCA licence that makes an entity a CASP; the travel rule then applies to it as an AML obligation supervised under the amended Directive (EU) 2015/849.

The Article 14 data set

Originator (Article 14(1)) Beneficiary (Article 14(2))
Name (a) The name of the originator (a) The name of the beneficiary
Ledger address / account (b) The distributed ledger address where the transfer is registered on a DLT network, and the crypto-asset account number where one exists and is used; (c) the account number where the transfer is not on a DLT network (b) and (c) — the same for the beneficiary
Identity data (d) Address including country, official personal document number and customer identification number — or, alternatively, date and place of birth Not required
Identifier (e) The current LEI or equivalent official identifier, where the message format has the field and the originator provided it (d) The same, where provided
No DLT and no account Article 14(3): a unique transaction identifier The same

Article 14(4) requires the information to be submitted in advance of, or simultaneously or concurrently with, the transfer, in a secure manner and in accordance with the GDPR — and states that it need not be attached to or included in the on-chain transfer itself. That is what makes the industry’s off-chain messaging protocols the compliance mechanism. Article 14(6)–(7) require the originator’s CASP to verify the originator information from a reliable and independent source before transferring, with verification deemed done where the customer was identified under Article 13 of the AML Directive and the records kept. Article 14(8): no transfer may be initiated or executed before full compliance.

Duties by role

Role Articles Duties
Originator’s CASP 14–15 Collect the full data set; verify the originator; submit before or with the transfer; for batch files from one originator, the batch carries the data and each transfer carries the address, account or identifier
Beneficiary’s CASP 16–17 Effective procedures, including monitoring during or after transfers, to detect whether the data is included or follows; verify the beneficiary information; risk-based procedures to execute, reject, return or suspend a transfer lacking data; request missing data or reject or return without undue delay; on repeated failure by a counterparty CASP, warn and set deadlines, then reject future transfers or restrict or terminate the relationship — and report the failure to the competent authority
Intermediary CASP 19–21 Transmit all received originator and beneficiary information with the transfer; retain records; detect whether the Article 14(1)(a)–(c) and 14(2)(a)–(c) data has been submitted, including for self-hosted transfers; risk-based procedures for transfers lacking it
All CASPs 26 Retain the Article 14–16 records for five years, delete personal data on expiry unless national law provides otherwise, and retain no longer than strictly necessary

Self-hosted addresses under the travel rule

Direction Provision Requirement
Transfer to a self-hosted address Article 14(5) The originator’s CASP obtains and holds the Article 14(1)–(2) information and ensures the transfer can be individually identified; above €1,000, takes adequate measures to assess whether the address is owned or controlled by the originator
Transfer from a self-hosted address Article 16(2) The beneficiary’s CASP obtains and holds the same information and ensures the transfer can be individually identified; above €1,000, assesses whether the address is owned or controlled by the beneficiary
Risk measures Article 19b of Directive (EU) 2015/849 (as amended) Specific risk-mitigating measures for self-hosted transfers, without prejudice to the above

The EBA Guidelines describe the ownership-verification methods CASPs may use — including cryptographic signing of a message from the self-hosted address, a micro-transaction, and other technical proofs — and the risk factors for unverified addresses. The point for design is that “self-hosted” is not an exit from the rule; it is a variant in which the CASP fills in both sides of the data set itself.

Travel rule: EU vs FATF Recommendation 16

EU Regulation 2023/1113 FATF Recommendation 16 / VASP guidance
Threshold None for crypto-asset transfers Countries may set a de minimis of USD/EUR 1,000, below which only names and addresses/accounts are required
Originator data Name, DLT address/account, address with country, document and customer ID number or date and place of birth, LEI where available Name, account/wallet, and one of: address, national identity number, customer ID, date and place of birth
Beneficiary data Name, DLT address/account, LEI where available Name and account/wallet
Self-hosted Obtain and hold both sides’ data; ownership assessment above €1,000 Obtain originator/beneficiary information; risk-based measures for unhosted wallets
Timing In advance of or simultaneously with the transfer; verified before execution Immediately and securely
Retention Five years At least five years
Enforcement Article 111-style AML sanctions under national law; EBA Guidelines apply from 30 December 2024 FATF mutual evaluations; national implementation varies

The EU implementation is stricter than the FATF baseline on the threshold and on self-hosted transfers, which matters for CASPs that also operate under regimes following the FATF text more closely. Our guide to the MiCA Regulation covers the parallel regime, and MiCA compliance checklist places the travel rule among the CASP’s obligations.

Implementing the travel rule

  1. Choose and integrate a messaging solution. The data travels off-chain under Article 14(4); a protocol that can reach counterparty CASPs, carries the full Article 14 fields, and supports batch files under Article 15 is the core control. Interoperability with counterparties matters more than any single vendor.
  2. Bind the data to KYC. Article 14(7) deems verification done where AML Directive customer identification was performed and retained — so the travel rule fields should be generated from the KYC record, not re-typed.
  3. Counterparty CASP due diligence. Identify the counterparty CASP for each transfer, its jurisdiction and its ability to receive data; keep a register with the Article 17(2) escalation status (warnings, deadlines, rejection or termination).
  4. Self-hosted workflow. Collect both sides’ data from your customer, individually identify the transfer, and apply an ownership check above €1,000 with a documented method and outcome.
  5. Missing-data procedure. Risk-based rules for reject, return, suspend or request, applied without undue delay, with the follow-up documented; report repeated counterparty failures to the competent authority.
  6. Retention and deletion. Five-year retention with deletion on expiry, and a GDPR basis and transfer mechanism for the personal data sent to non-EU CASPs.
  7. Test against the EBA Guidelines. The Guidelines list the detection steps and missing-information actions supervisors expect; use them as the audit checklist.

Frequently asked questions

What is the crypto travel rule in the EU?
Regulation (EU) 2023/1113, applying from 30 December 2024, which requires the originator’s CASP to send a defined set of originator and beneficiary information with every transfer of crypto-assets, the beneficiary’s CASP to detect and act on missing information, intermediaries to transmit and retain it, and all of them to keep records for five years.

Is there a minimum amount below which the travel rule does not apply?
No. Unlike the FATF’s optional USD/EUR 1,000 de minimis, the EU Regulation sets no threshold for crypto-asset transfers; the €1,000 figure appears only in the self-hosted ownership check under Articles 14(5) and 16(2).

Does the travel rule apply to self-hosted wallets?
Yes. The CASP must obtain and hold the full originator and beneficiary information for transfers to or from a self-hosted address, ensure the transfer can be individually identified, and above €1,000 assess whether the address is owned or controlled by its customer.

Does the information have to go on-chain?
No. Article 14(4) requires it to be submitted in advance of or simultaneously with the transfer, securely and in accordance with the GDPR, and states it need not be attached to or included in the transfer itself — off-chain messaging between CASPs is the mechanism.

What must a beneficiary CASP do if data is missing?
Under Article 17, on a risk-sensitive basis and without undue delay, reject or return the transfer or request the missing information before making the assets available; on repeated failure by a counterparty CASP, warn and set deadlines, then reject future transfers or restrict or end the relationship, and report the failure to the competent authority.

Where this leaves you

Run the travel rule as a data-and-counterparty discipline: generate the Article 14 fields from KYC, send them off-chain before the transfer, know every counterparty CASP and its escalation status, treat self-hosted transfers as a workflow with an ownership check above €1,000, act on missing data without undue delay, and keep everything for five years — because from 30 December 2024 there is no threshold and no exemption for the wallet at the other end.

References

More on MiCA

The Travel Rule Procedure, the Article 14 data-set specification, the counterparty CASP register with the Article 17(2) escalation ladder, the self-hosted address ownership-check record and the five-year retention schedule are in the MiCA Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.