What is Travel rule?
The travel rule requires crypto service providers to collect and transmit originator and beneficiary information alongside transfers - the FATF standard applied to crypto. In the EU it applies via the Transfer of Funds Regulation with no minimum threshold for VASP-to-VASP transfers; compliance requires dedicated messaging solutions.
What must travel with a transfer
For transfers between service providers: originator name, account/wallet identifier, and address or ID number, plus beneficiary name and wallet identifier. The EU regime (TFR, applying alongside MiCA) sets no de-minimis threshold for CASP-to-CASP transfers - data travels with every transaction. Transfers to self-hosted wallets trigger lighter duties: verification of ownership for transfers above €1,000 in the EU model. The US applies a $3,000 threshold under FinCEN rules, with proposals to lower it.
How compliance actually works
Blockchains do not carry identity data, so the industry uses parallel messaging protocols - IVMS 101 as the data standard, with solutions like Notabene, Sygna, TRP, or Travel Rule Universal Solution handling counterparty discovery and encrypted exchange. Implementation problems are practical: identifying whether a counterparty wallet belongs to a VASP (sunrise problem - not all jurisdictions enforce yet), handling non-responsive counterparties, and policy decisions on transfers to unhosted wallets. Your AML program must document each path.
Who is in scope and what it costs
Any VASP/CASP transferring crypto on behalf of customers - exchanges, custodial wallets, brokers, payment providers. Non-custodial software stays out of scope. Budget-wise, travel-rule tooling runs from a few hundred to several thousand euros monthly depending on volume, plus integration work into your transaction flow. For licensing applications (MiCA CASP, national regimes), regulators now expect a named travel-rule solution in the AML framework - 'we will address it later' no longer passes.
Frequently asked questions
Does the travel rule apply to transfers to private wallets?
Partially. In the EU, transfers between a CASP and a self-hosted wallet above €1,000 require the CASP to verify the customer owns the wallet. Full data exchange applies only between two service providers.
Do DeFi transactions fall under the travel rule?
Direct wallet-to-protocol interactions generally do not - no intermediary transfers on the customer's behalf. But when a custodial service routes customer funds into DeFi, the service provider's obligations attach to the customer leg.