The preceding How to issue a stablecoin in the EU addresses issuer obligations. The transfer inquiry concerns who must obtain, verify, transmit and retain information, including when missing data prevents release. EU and UK requirements differ on thresholds, self-hosted wallets and responses to incomplete information. Regulation (EU) 2023/1113 (TFR), Articles 14–22; Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs), S.I. 2017/692, Part 7A.
Summary
- EU: The crypto information requirements apply without a general minimum transfer value. The €1,000 threshold concerns additional checks for self-hosted addresses, rather than the initial duty to collect transfer information. TFR, Articles 14 and 16.
- EU: For self-hosted transfers exceeding €1,000, the provider must assess whether its customer owns or controls the address. Transfers involving another person's address require their own risk assessment; they are not automatically prohibited. TFR, Articles 14(5) and 16(2); EBA/GL/2024/11, paragraphs 87–90.
- UK: Covered inter-business transfers require basic identifying information. Additional originator details accompany qualifying transfers of at least £800, including apparently linked transfers. The sterling threshold took effect on 30 June 2026. MLRs, regulation 64C; S.I. 2026/621, regulations 1(2) and 32.
- UK: Information requests for unhosted-wallet transfers depend on the prescribed risk assessment. Once requested information remains unprovided, the business must not make the cryptoasset available to the beneficiary. MLRs, regulation 64G.
- EU and UK: Sending businesses must satisfy their verification and information duties before transferring. Receiving businesses and intermediaries have separate checking, follow-up and reporting obligations. TFR, Articles 14(6)–(8) and 16–22; MLRs, regulations 64C(8)–(9) and 64D–64F.
- EU and UK: Software must support the applicable legal requirements, including secure transmission and usable records. A messaging supplier does not assume the regulated firm's compliance responsibilities. TFR, Articles 14 and 25–26; EBA/GL/2024/11, paragraphs 21–26; FCA, Travel Rule statement, 17 August 2023.
Transfers covered
The EU rules have applied since 30 December 2024. They cover crypto-asset transfers, including transfers through crypto-ATMs, where a relevant provider or intermediary has its registered office in the Union. A transfer can fall within scope even where the originator and beneficiary are the same person or use the same provider. TFR, Articles 2(1), 3(10) and 40.
Pure person-to-person transfers without a crypto-asset service provider (CASP) are excluded. Another exclusion applies where the originator and beneficiary are both CASPs acting on their own behalf. A customer transfer through a custodial business must therefore be distinguished from a transfer between two private wallets without provider involvement. TFR, Article 2(4).
For TFR purposes, e-money tokens are treated as crypto-assets. A narrow exclusion concerns transfers of funds or e-money tokens through specified payment instruments used exclusively to purchase goods or services, with their identifying number accompanying every transfer. That exclusion does not cover consumer-to-consumer transfers through those instruments. It is not a general exemption for stablecoins used in payments. TFR, Article 2(3)–(4).
The UK's Part 7A has applied since 1 September 2023. An inter-cryptoasset business transfer requires at least two cryptoasset businesses, with at least one carrying on business in the UK in respect of the transaction. An intermediary can supply that UK connection. The statutory territorial test concerns the business conducted for the transaction, rather than the customer's residence alone. MLRs, regulations 64A–64B; S.I. 2022/860, regulations 1(3) and 5(5).
EU information requirements
The originating CASP must provide the originator's and beneficiary's names. It must include their distributed-ledger addresses where the transfer uses a distributed ledger, together with applicable crypto-asset account numbers. For transfers without a distributed ledger, the relevant account numbers apply; where no account exists, Article 14(3) requires a unique transaction identifier. TFR, Article 14(1)(a)–(c), (2)(a)–(c) and (3).
The originator particulars under Article 14(1)(d) comprise the address, including country, official personal-document number and customer-identification number, or alternatively date and place of birth. A current legal entity identifier, or, in its absence, an available equivalent official identifier, is also required for each party where the message format provides the field and the originator supplied it. The statutory conditions govern which fields must accompany the transfer. TFR, Article 14(1)(d)–(e) and (2)(d).
There is no general €1,000 exemption from these crypto information requirements. A provider cannot treat every smaller transfer as outside the Travel Rule. The separate provisions for self-hosted addresses determine what must be collected and what additional ownership assessment is required. TFR, Articles 14(1)–(5) and 16(2).
Verification and transmission timing
Before sending, the originating CASP must verify the required originator information against a reliable, independent source. Existing customer due diligence can satisfy this requirement where the statutory verification and retention conditions are met. The receiving CASP must verify its beneficiary's information before making the assets available. These provisions do not require a new identity-document submission for every transfer where qualifying verification already exists. TFR, Articles 14(6)–(8) and 16(3)–(4).
The information must be transmitted securely before, simultaneously with or concurrently with the transfer. It need not be attached directly to the blockchain transaction. The European Banking Authority's (EBA) non-legislative Travel Rule Guidelines specify transmission no later than initiation of the blockchain transaction. A separate secure message can satisfy the transmission method, provided it carries the required information at the required time. TFR, Article 14(4); EBA/GL/2024/11, paragraph 25.
EU self-hosted addresses
Transfers to and from self-hosted addresses still require the CASP to obtain and hold originator and beneficiary information. It must also make each transfer individually identifiable. The absence of another provider does not remove these duties or require a private wallet owner to operate a provider-to-provider messaging system. TFR, Articles 14(5) and 16(2).
Where the transfer exceeds €1,000, the CASP must assess whether its own customer owns or controls the self-hosted address. The customer is the originator for an outgoing transfer and the beneficiary for an incoming transfer. The test is not satisfied merely by showing that an address exists or has previously received crypto-assets. TFR, Articles 14(5) and 16(2).
EBA's supervisory guidelines identify ways to establish control: remote verification, a predefined transfer from and to the address, a signed message or another reliable technical method. An inadequate method requires additional measures. Austria's Financial Market Authority (FMA) expressly states that a customer's self-declaration alone does not constitute the required technical verification. EBA/GL/2024/11, paragraphs 83–85; FMA, Transfer of Funds Regulation, self-hosted-address guidance.
A finding that the address belongs to someone else does not create an automatic prohibition. EBA's guidelines address transfers involving third parties and require the corresponding risk assessment and controls. Reusing an earlier address check also requires monitoring for ownership or risk changes. A provider should not treat a previously accepted address as permanently verified. EBA/GL/2024/11, paragraphs 86–90.
UK information and the £800 threshold
Covered inter-business transfers must carry the parties' names and account numbers, or a unique transaction identifier where no account number exists. A firm's registered name applies, with its trading name used where it has no registered name. The originating business must verify the originator information against an independent, reliable source before transferring. MLRs, regulation 64C(1), (5) and (8)–(9).
Where every executing business, including intermediaries, carries on business in the UK for the transaction, additional originator information is supplied on request. The originating business has three working days to respond to the beneficiary's business. Where that condition is not met, the additional information must accompany transfers of at least £800, counting apparently linked transfers together. MLRs, regulation 64C(2)–(4).
For an individual, the additional information is one permitted identifier: customer-identification number, address, specified identity-document number, or date and place of birth. For a firm, it is the customer-identification number or the prescribed business address. Regulation 64C(6) defines the alternatives; the EU data-field structure should not be substituted for that UK provision. MLRs, regulation 64C(6).
The £800 amount replaced the former €1,000 threshold on 30 June 2026. The amendment also changed the corresponding amount for incoming unhosted-wallet transfers. Threshold configurations must therefore distinguish current UK sterling amounts from the EU's separate euro-denominated test. S.I. 2026/621, regulations 1(2) and 32–33; MLRs, regulations 64C(4) and 64G(1)(b).
UK unhosted-wallet transfers
A UK cryptoasset business decides whether to request missing information from its customer through the assessment required by regulation 64G. It must consider money laundering, terrorist financing and proliferation financing risks, alongside the prescribed transaction and relationship factors. Where the customer receives at least £800, including apparently linked transfers, the request can include additional originator particulars. MLRs, regulation 64G(1)–(3).
The consequences change once the business requests information. If it does not receive that information, it must not make the cryptoasset available to the beneficiary. This prohibition is mandatory under regulation 64G(4), even though the preceding decision whether to request information is risk-based. The EU's automatic information-collection and address-assessment provisions cannot be used as a statement of the UK rule. MLRs, regulation 64G(1)–(4); TFR, Articles 14(5) and 16(2).
Missing or inconsistent information
An EU receiving CASP must operate procedures to detect missing information and determine its response according to risk. Where required information is missing or incomplete, Article 17 requires rejection or return, or a request for that information before making the assets available. The provider must retain a procedure for deciding whether to execute, reject, return or suspend affected transfers. TFR, Articles 16(1) and 17(1).
The UK receiving business must check information completeness and compare beneficiary details against its verified customer records before release. Missing information requires a request to the originating business. The receiver must consider enquiries about discrepancies and whether to delay release or return the assets after a reasonable period. Regulation 64D makes those delay and return decisions risk-based; it differs from regulation 64G's express prohibition following an unanswered unhosted-wallet request. MLRs, regulation 64D(1)–(4).
Intermediaries and batch transfers
Intermediaries have independent duties. EU intermediaries must preserve and transmit received information and address omissions under Articles 19–22. UK intermediaries must check before forwarding, request missing information and assess delay or return. Information received after onward transfer must be forwarded as soon as practicable. A firm's intermediary role does not remove its responsibility for the information passing through it. TFR, Articles 19–22; MLRs, regulations 64E–64F.
Batching permits specified information to accompany the batch instead of every individual transfer. Under the EU rule, the batch must come from one originator, contain the prescribed verified information and preserve the required identifiers for individual transfers. The UK provision applies where the beneficiary's business operates wholly outside the UK and retains its own batch-information and identifier conditions. Neither provision exempts an undocumented batch. TFR, Article 15; MLRs, regulation 64C(7).
Counterparties in countries without the Travel Rule
The FCA's published supervisory position addresses jurisdictions that have not implemented the Travel Rule. For outgoing transfers, it expects all reasonable steps to establish whether the overseas business can receive the required information. Where it cannot, the FCA states that the UK business must still collect and verify the required information under the MLRs and should store it before transferring. For incoming transfers, the country's implementation status informs the missing-information risk assessment. FCA, Travel Rule statement, 17 August 2023, sending and receiving expectations.
That statement does not create a statutory exemption for every failed message or apply to EU providers. A custodial counterparty also does not become a self-hosted wallet because it uses an incompatible messaging system. The EU address definition turns on the absence of a linked provider, while the UK wallet definition concerns administration of the private key. TFR, Article 3(20); MLRs, regulation 64B.
Travel Rule software and operating controls
A Travel Rule solution needs testing against the firm's actual transfer routes. EBA's guidelines require technical arrangements capable of transmitting the required information without errors or omissions, alongside secure communications and interoperability. Its limited allowance for technical limitations ended on 31 July 2025. Continuing system incompatibility cannot be treated as an open-ended implementation period. EBA/GL/2024/11, paragraphs 21–26.
Practical acceptance tests should cover correct jurisdiction and threshold selection, complete field mapping and transmission timing. They should also test self-hosted-address procedures, missing-data decisions, intermediary forwarding and retrieval of retained records. These tests follow from the separate legal duties; a successful blockchain transfer alone cannot establish that the information duties were performed. TFR, Articles 14–22 and 26; MLRs, regulations 40 and 64C–64G.
The firm should record who can approve an exception, what evidence supports the decision and when unresolved transfers are escalated. Those arrangements implement the required risk-based procedures. The FCA expressly retains responsibility with the cryptoasset business when third-party suppliers perform Travel Rule work. MLRs, regulations 64D–64G; FCA, Travel Rule statement, 17 August 2023.
Personal data and record retention
EU Travel Rule processing remains subject to the General Data Protection Regulation. Article 25 restricts the purposes for which the collected information can be processed and prohibits commercial use. It also requires information for new customers about the relevant legal obligations. Sending personal information abroad does not displace the GDPR's international-transfer conditions. TFR, Article 25.
The TFR requires originator and beneficiary information to be kept for five years. Member States can require or permit further retention under the statutory conditions, for no more than five additional years. Personal data must be deleted when the applicable period ends. The provider must identify the applicable national retention rule before configuring automatic deletion. TFR, Article 26(1)–(2).
UK regulation 40 uses different starting points: completion of an occasional transaction or the end of the business relationship. The ordinary retention period is five years from the date on which the business knows, or has reasonable grounds to believe, that the relevant event has occurred. The regulation does not require business-relationship transaction records to be retained beyond ten years. Deletion remains subject to its statutory, proceedings-related and consent exceptions. MLRs, regulation 40(2)–(5).
UK personal-data use is restricted to the prescribed financial-crime purposes, subject to the exceptions in regulation 41(3). New customers must receive the required explanation before the relationship or occasional transaction begins. A provider's Travel Rule database cannot be repurposed merely because its software permits another use. MLRs, regulation 41(1), (3) and (6).
Reporting and enforcement
Repeated counterparty information failures require more than resolving an individual transfer. EU receiving CASPs must take the measures required by Article 17(2) and report the failure and their response to the competent anti-money laundering authority. Article 18 separately requires missing information to inform the assessment of suspicious activity and reporting to the financial intelligence unit. The two reporting questions should not be collapsed into one notification. TFR, Articles 17(2) and 18.
UK receiving businesses and intermediaries must report repeated information failures and their responses to the FCA. They must also respond fully and without delay to qualifying written requests from law enforcement. These duties require records that can establish what information was received, requested and forwarded. MLRs, regulations 64D(5), 64E(5) and 64H.
Complete transfer information does not resolve sanctions restrictions. EU providers must maintain policies, procedures and controls for implementing applicable Union and national restrictive measures. A complete Travel Rule message does not authorise a transfer prohibited by those measures. TFR, Article 23.
Member States determine the administrative penalties and measures required by the TFR. In the UK, breach of a relevant Part 7A requirement can constitute a criminal offence. On indictment, regulation 86 permits imprisonment for up to two years, a fine, or both. The statutory defence requires all reasonable steps and due diligence; a deficient message does not, by itself, establish criminal liability. TFR, Articles 28–29; MLRs, regulation 86(1), (3) and Schedule 6, paragraph 11A.
