What is the Travel Rule?
The Travel Rule is one of the core anti-money laundering standards, recently extended to the world of cryptocurrencies. Below, we cover where the rule comes from, what data it requires, and how it is applied in the European Union.
Table of contents:
Where the Travel Rule comes from
The Travel Rule originally stems from the US Bank Secrecy Act, with the FinCEN agency introducing this obligation for traditional financial institutions back in 1996, in the context of fiat currency transactions.
The Financial Action Task Force (FATF) later incorporated the rule into its international standards, first in 2001 as Special Recommendation VII, and then in 2012 as part of the revised Recommendation 16.
A key moment for cryptocurrencies came in June 2019, when the FATF, through an Interpretive Note to Recommendation 15, extended the same obligation to virtual asset service providers (VASPs), requiring them to meet the same data-sharing standards as traditional financial institutions.
The most significant update came in June 2025, when the FATF thoroughly revised Recommendation 16. The rule's scope was expanded beyond money laundering and terrorist financing to now explicitly include fraud prevention and proliferation financing.
The update also introduced a requirement for Confirmation of Payee systems for cross-border transfers, along with full integration with the ISO 20022 messaging standard.
What data is collected
As a rule, for transactions above the set threshold, the following originator data is collected:
- name,
- account number (or unique transaction reference if no account exists),
- full physical address,
- date of birth (for natural persons),
- BIC, LEI, or another unique identifier.
For the beneficiary, the following is collected:
- name,
- account number (or unique transaction reference),
- country and city,
- BIC, LEI, or another unique identifier.
If a transaction falls below a given jurisdiction's threshold, the name and account number (or transaction reference) of both originator and beneficiary must still be provided, but this data does not need to be additionally verified unless the institution suspects money laundering or terrorist financing.
Why the Travel Rule is harder to apply to blockchain than to banks
With traditional bank transfers, banks use the SWIFT messaging system to exchange data within a closed network of known institutions. This process has become routine and standardized after more than two decades of use.
With cryptocurrencies, the situation is more complex. When a client requests a transfer to a specific wallet address, the service provider must determine whether that address belongs to another licensed service provider or to a private, self-hosted wallet, and this distinction determines which obligations apply.
The industry has developed protocols and solutions for more accurately identifying the counterparty in a transaction, but Travel Rule implementation still varies unevenly across countries, a situation the industry refers to as the "sunrise" problem. Some jurisdictions have quickly established clear rules, while others have yet to do so.
Travel Rule by jurisdiction
- United States: a threshold of 3,000 USD for cross-border transfers, with a possible reduction of the threshold for cryptocurrencies to 250 USD announced, though this is still under consideration.
- European Union: a zero threshold for all cryptocurrency transfers - the obligation applies to every transaction, regardless of amount.
- United Kingdom: the obligation introduced without a fixed threshold, requiring institutions to take "all reasonable steps" toward compliance.
- Hong Kong: mandatory platform licensing along with technical verification of ownership over self-hosted wallets.
- Singapore: a threshold of 1,500 SGD for digital payment token transfers.
The Travel Rule in the European Union
In the EU, the Travel Rule has been implemented through the revised Transfer of Funds Regulation (TFR), namely Regulation (EU) 2023/1113, which entered into force on December 30, 2024.
This is the same date on which the MiCA provisions for providers of services related to cryptocurrencies came into effect.
The regulation applies a zero threshold: every cryptocurrency transaction requires full compliance, regardless of the amount.
Before the TFR was adopted, individual EU member states had their own national solutions - for example, Germany applied the Travel Rule through the Crypto Asset Transfer Regulation (KryptoWTransferV), which required a smaller scope of data for transactions below €1,000, whereas the TFR now requires the full scope of data regardless of amount.
When it comes to self-hosted wallets, the service provider must still collect counterparty data for such transfers as well. Additional verification of ownership over a self-hosted wallet is required for transfers above €1,000, depending on the risk assessment.
The obligation does not apply to person-to-person transactions in which no licensed service provider is involved at all.
What this means for the future of cryptocurrencies
The Travel Rule shows how long-standing anti-money laundering standards are being adapted to the world of cryptocurrencies, with additional complexity introduced by the decentralized nature of blockchain.
In the European Union, this rule operates alongside the MiCA regulation as part of a unified supervisory framework, and HANFA, as the competent authority in Croatia, ensures that these standards are consistently applied.
Frequently Asked Questions
Is there a minimum amount below which the Travel Rule doesn't apply?
It depends on the jurisdiction. In the European Union, no such threshold exists, the TFR requires full compliance for every cryptocurrency transaction, regardless of amount. Some other countries, such as the US or Singapore, only apply the rule above a certain amount.
Who is responsible for collecting the data - the sender or the recipient?
Both parties. The service provider on the sender's side collects and transmits the data, while the service provider on the recipient's side is required to receive that data, verify its accuracy, and screen it against sanctions lists before the transaction is approved.
Does the Travel Rule also apply to sending cryptocurrency to a private wallet?
Yes, if a licensed service provider is involved in the transfer. The provider must collect data about the owner of such a wallet, and additional ownership verification may be required for transfers above €1,000. Transactions directly between two individuals, with no service provider involved in the chain, do not fall under this obligation.
Is the content of the exchanged data visible on the blockchain?
No. Data about the sender and recipient is exchanged directly between service providers, off-chain, and is not publicly available. The transaction itself remains visible on the blockchain as usual, but the identity of the parties behind it is not.
