What the EU Crypto Travel Rule Is
The Travel Rule requires that identifying information about the originator (sender) and beneficiary (recipient) travels alongside a transfer of value. It originates in FATF Recommendation 16 and was historically applied to bank wire transfers. The EU extended it to crypto through the recast Transfer of Funds Regulation (EU) 2023/1113, which applies to crypto-asset transfers from 30 December 2024 — the same day MiCA's CASP regime took effect.
The goal is to remove the anonymity that made crypto attractive for money laundering and sanctions evasion. For a licensed CASP, the Travel Rule is now an operational reality on every transaction, sitting directly on top of your AML/KYC programme.
What Information Must Accompany a Transfer
For a crypto-asset transfer between CASPs, the originating CASP must obtain, hold, and transmit:
- Originator: name; distributed-ledger address (or account number); address, official personal document number, customer identification number, or date and place of birth.
- Beneficiary: name; distributed-ledger address (or account number).
The beneficiary CASP must implement procedures to detect whether this information is present and to handle transfers where it is missing or incomplete. Information must be transmitted securely and in a way that travels with — or is linked to — the transaction.
The No-Threshold Rule — Why Crypto Is Different
For conventional fund transfers, simplified information applies below €1,000. For crypto-asset transfers there is no such de minimis threshold. The full originator and beneficiary data set is required regardless of value — a €5 transfer is in scope just as a €5 million one is.
This is the detail that catches firms migrating from a lighter VASP regime. There is no "small transfer" carve-out for crypto. Your systems must capture and transmit Travel Rule data on every single CASP-to-CASP transfer.
Transfers To and From Self-Hosted Wallets
The TFR also addresses transfers involving self-hosted (unhosted) wallets — wallets not controlled by a CASP. Where a transfer to or from a self-hosted wallet exceeds €1,000, the CASP must take additional measures to verify that the customer controls the self-hosted wallet, or that the wallet belongs to them, using suitable technical means.
Below that amount, standard customer due diligence applies but the enhanced wallet-verification step is not mandatory. CASPs serving customers who self-custody need a clear policy and tooling for wallet ownership verification, address screening, and risk scoring.
Handling Missing or Incomplete Information
A beneficiary CASP that receives a transfer with missing or incomplete originator/beneficiary information must have risk-based procedures to decide whether to execute, reject, return, or suspend the transfer, and whether to request the missing data. Repeated failures by a counterparty CASP can require escalation and, ultimately, restricting or terminating the relationship.
These decisions must be documented. Regulators expect a defined policy, not ad hoc judgement calls at the transaction desk.
What CASPs Must Build to Comply
Practical Travel Rule compliance for a CASP means:
- A Travel Rule messaging solution to exchange originator/beneficiary data with counterparty CASPs securely (typically via an industry protocol).
- Counterparty CASP identification — knowing whether the receiving address belongs to a regulated provider or a self-hosted wallet.
- Self-hosted wallet verification tooling for transfers above €1,000.
- Sanctions and address screening integrated into the transfer flow.
- Documented policies for missing-information handling and recordkeeping.
This is a build, not a checkbox. We design Travel Rule data flows as part of a CASP's wider AML and MiCA compliance framework.