What Is the Crypto Travel Rule and What Data Is Shared?

What Is the Crypto Travel Rule and What Data Is Shared?

Marcus Reid
September 12, 2026· 8 min read

The crypto Travel Rule is an anti-money-laundering requirement under which covered financial institutions obtain, retain, and transmit specified information about the originator and beneficiary of a qualifying virtual-asset transfer. It concerns regulated service providers and their compliance messages; it does not mean that your legal name and home address are automatically written into a public blockchain transaction.[1]

Key Takeaways

  • The originator sends value; the beneficiary is intended to receive it.
  • A VASP or CASP may need identifying information before, with, or around a transfer.
  • Exact fields, thresholds, covered businesses, and self-hosted-wallet checks depend on jurisdiction.
  • Compliance data normally travels between regulated parties through separate systems, not as public on-chain text.
  • Verify requests inside the provider's official app or website and disclose only what the legitimate process requires.

Start with the online security guide before uploading identity records or responding to a time-sensitive request.

Who are the parties in a Travel Rule transfer?

The originator is the person or entity that initiates the transfer. The beneficiary is the intended recipient. A virtual asset service provider, or VASP, may include an exchange or another covered business that transfers or safeguards virtual assets. European Union rules use CASP, or crypto-asset service provider, within their own legal framework. These labels describe roles, not a guarantee that every wallet, company, or transaction is regulated in the same way.

Party or channelTypical roleWhat to verify
OriginatorSends the crypto assetLegal identity and account relationship
Originating VASP/CASPCollects and sends required dataOfficial request and transfer reference
BeneficiaryIntended receiverCorrect person or legal entity
Beneficiary VASP/CASPReceives data and may screen itSupported institution and account details
Self-hosted walletAddress controlled outside a provider accountWallet type and any lawful control check
BlockchainRecords the asset movementAddress, asset, network, amount, and transaction state

If a platform pauses a transfer while it checks these roles, use the held Travel Rule transfer guide. If it rejects the recipient fields, follow the beneficiary information checklist.

What information can be shared?

FATF Recommendation 16 calls for specified originator and beneficiary information to accompany covered transfers. Depending on the applicable regime, this can include names, account or wallet identifiers, and additional identifying data such as an address, official document number, customer identification number, or date and place of birth. The receiving institution may also need enough information to identify the beneficiary.[1]

That list is not a universal intake form. A provider should determine the fields that its governing law and risk controls require. The EU regulation, for example, defines information obligations for transfers handled by covered providers and includes specific rules for transfers involving self-hosted addresses.[2] Other jurisdictions may use different definitions, thresholds, exceptions, or implementation dates.

Never fill an unfamiliar field by guessing. A display name, nickname, exchange username, and legal name are not interchangeable. A company beneficiary should not be presented as an individual. When the counterparty is another exchange, the institution name and the account beneficiary are separate facts.

When is the information transmitted?

The policy goal is that required information be available securely and promptly to the beneficiary institution. A provider may collect it during address entry, before authorizing withdrawal, after detecting that a counterparty is covered, or during an exception review. The compliance message may use a dedicated inter-provider network or another secure mechanism. Timing in the user interface is therefore not proof that the asset has been broadcast.

Check the actual transaction state. No transaction ID can mean the withdrawal is still internal, although provider interfaces differ. A valid transaction ID with confirmations can mean the asset moved while the receiving provider is still deciding whether to credit the account. A request for more information can occur on either side. Keep those states distinct because the evidence and support owner differ.

Is crypto Travel Rule data public on the blockchain?

Usually the identifying compliance payload is exchanged separately from the public blockchain record. Public ledgers can expose addresses, amounts, timing, assets, fees, and transaction relationships. They generally do not display the off-chain Travel Rule form as a plain public attachment. However, an observer may still connect on-chain activity with identity through exchange records, address reuse, disclosures, analytics, or legal process.

This is why “not written on-chain” does not mean anonymous. Read whether Bitcoin is anonymous for the distinction between pseudonymous addresses and identity privacy. Ask a provider for its privacy notice, retention terms, recipients, cross-border transfer explanation, and correction route rather than assuming that all compliance networks use the same controls.

How do jurisdiction and thresholds change the answer?

FATF sets international standards, but countries implement them through their own laws, supervisors, and timelines. FATF's 2025 best-practices paper discusses uneven implementation and the operational problems created by a global network with different rules.[1] A transfer can touch more than one regime when the customer, originating provider, beneficiary provider, or service infrastructure sits in different places.

The EU's Regulation 2023/1113 contains a EUR 1,000 condition for certain ownership or control assessments involving self-hosted addresses.[2] That is an EU-specific provision, not a worldwide “Travel Rule threshold.” A provider may also request information below a statutory threshold because another rule, counterparty requirement, sanctions control, or risk review applies. Ask which policy applies without demanding confidential detection logic.

How should you respond to a legitimate Travel Rule request?

Open the exchange or wallet provider independently instead of following an email link. Match the request to the transfer reference, asset, network, amount, destination, and account notification. Confirm whether the counterparty is a person, legal entity, regulated provider, or self-hosted wallet. Supply truthful fields using the authenticated workflow and retain a copy of what you submitted.

Redact unrelated records when the platform permits it. Do not send passwords, MFA codes, seed phrases, private keys, or remote-access credentials. A request to prove control should use a bounded method described in the wallet ownership proof guide, never secret recovery material.

What Travel Rule privacy questions should you ask?

Useful questions are concrete: which entity is the controller, what fields are mandatory, who receives them, where they are stored, how long they are retained, how corrections work, and how a complaint can be made. The EBA guidelines describe risk-based handling of missing or incomplete information within the EU framework, but they do not turn every provider's privacy operations into one identical system.[3]

Do not ask support to falsify or suppress required data. If a field is wrong, request the formal correction route. If you cannot identify the recipient or the platform's request is inconsistent with your account, stop and contact verified support before transmitting more information.

Summary

  • The Travel Rule moves specified originator and beneficiary information between covered providers.
  • The compliance payload is generally separate from the public blockchain record.
  • Fields, thresholds, timing, and self-hosted-wallet procedures vary by legal regime and provider.
  • Verify the request, transfer state, counterparty type, and official channel before responding.
  • Provide truthful minimum-required information and never reveal wallet secrets.

Frequently Asked Questions

Does the Travel Rule apply to every crypto transfer?

No. Coverage depends on the relevant jurisdiction, providers, transfer type, and any thresholds or exceptions. A platform may still conduct other lawful compliance checks.

Are my name and address put on the blockchain?

The compliance payload is generally transmitted off-chain. The blockchain can still reveal addresses and transaction details that may later be linked to identity.

What is the difference between a VASP and a CASP?

VASP is the FATF term for covered virtual-asset service providers. CASP is used in EU crypto regulation; exact legal definitions depend on the governing framework.

Does a EUR 1,000 threshold apply worldwide?

No. The cited EUR 1,000 provision belongs to the EU framework for certain self-hosted-address checks. Other jurisdictions can use different rules.

Can a self-hosted wallet be involved?

Yes. A provider may ask whether an address is self-hosted and, where applicable, verify ownership or control using a supported method.

Can I refuse to provide beneficiary information?

You can decide not to proceed, but the provider may be unable to execute or credit the transfer. Ask what rule applies and what cancellation or return options exist.

Can a VPN remove a Travel Rule requirement?

No. A VPN cannot change the governing law, prove identity or wallet control, release a transfer, or alter a provider's compliance records.

What if the request looks like phishing?

Do not use the message link. Open the official app or typed domain, check for the same request, and contact authenticated support with the transfer reference.


Disclaimer: This article is for general informational purposes only and is not legal, financial, investment, tax, privacy, or platform-specific advice. Rules and provider procedures vary by jurisdiction and may change.

Sources

  1. FATF — Best Practices on Travel Rule Supervision: https://www.fatf-gafi.org/content/dam/fatf-gafi/recommendations/Best-Practices-Travel-Rule-Supervision.pdf
  2. EUR-Lex — Regulation (EU) 2023/1113: https://eur-lex.europa.eu/eli/reg/2023/1113/oj
  3. EBA — Travel Rule Guidelines: https://www.eba.europa.eu/sites/default/files/2024-07/6de6e9b9-0ed9-49cd-985d-c0834b5b4356/Travel%20Rule%20Guidelines.pdf

Sources checked 12 September 2026.


Related articles:

Start your 3-day free trial

Sign up to experience all premium features at no cost.

*Available only to new users. Each user is limited to one trial.

What Is the Crypto Travel Rule and What Data Is Shared? | AethoVPN