The Travel Rule is one of the most consequential anti-money-laundering (AML) obligations in the virtual asset industry. Rooted in FATF Recommendation 16 and extended to crypto in 2019, it requires virtual asset service providers (VASPs) to collect and transmit originator and beneficiary information alongside qualifying transfers. This guide explains what the Travel Rule is, who it applies to, exactly what data must be shared, how thresholds differ sharply by jurisdiction, the protocols used to transmit data, the operational challenges firms face, and the 2026 FATF updates that are reshaping the landscape.
What Is the Travel Rule?
The Travel Rule is FATF Recommendation 16 (R.16) applied to virtual asset transfers. It was originally designed for traditional bank wire transfers under the Bank Secrecy Act framework. In June 2019, the Financial Action Task Force (FATF) published guidance extending the Travel Rule to virtual assets, placing crypto transfers under the same "traveling information" principle that governs correspondent banking.
The core principle is simple but demanding: when a VASP executes a qualifying transfer, it must collect identifying information about the originator and the beneficiary, and transmit that information to the counterparty VASP at or before the point of transfer. As the industry saying goes — "the information travels with the value."
Crucially, the rule applies to activity, not to a label. A business does not escape the obligation by calling itself a "protocol" or a "wallet." If it performs the regulated activity of sending or receiving value on behalf of customers, it is in scope.
Who Must Comply?
The Travel Rule applies to a broad set of regulated entities, known by different names across regimes:
-
VASPs — the term used by FATF and most jurisdictions (Virtual Asset Service Providers)
-
CASPs — the EU term (Crypto-Asset Service Providers), defined under MiCA
-
MSBs — the US term (Money Services Businesses), registered with FinCEN
Concrete examples include centralized exchanges, custodial wallets, fiat on-ramps and off-ramps, brokers, and OTC desks. If you custody customer funds or facilitate transfers on their behalf, the Travel Rule almost certainly applies to you.
Data Requirements: What Must Travel
The data that must travel depends on whether the transfer is above or below the applicable threshold.
Above Threshold (e.g., USD/EUR 1,000 FATF default)
-
Originator: full name, account/wallet identifier, and physical address OR national identity number / date and place of birth
-
Beneficiary: full name and account/wallet identifier
Below Threshold
The intent is proportionate: small transfers carry lighter obligations, while larger transfers require robust identification to support law enforcement traceability.
Thresholds by Jurisdiction: They Differ Sharply
One of the most common compliance errors is assuming a single global threshold. There is no uniform rule — and the differences are stark.
|
Regime
|
Threshold
|
Notes
|
|
FATF global
|
USD/EUR 1,000
|
Recommendation, not law
|
|
US FinCEN
|
USD 3,000
|
BSA Travel Rule, 31 CFR 1010.410
|
|
EU TFR
|
ZERO (no de-minimis)
|
Regulation 2023/1113, applies to all transfers
|
|
Canada FINTRAC
|
CAD 1,000
|
|
|
UK FCA
|
GBP 1,000 (aligned with FATF)
|
|
|
South Korea
|
KRW 1,000,000
|
|
|
UAE
|
AED 3,500
|
|
The EU's Transfer of Funds Regulation (TFR) is the most aggressive: it applies a zero de-minimis threshold, meaning every single crypto transfer — regardless of size — must carry Travel Rule data. A VASP operating in both the US and the EU must therefore apply two completely different rule sets to the same customer flow.
How Is the Data Transmitted?
Unlike traditional banking, which relies on a single universal messaging network (SWIFT), crypto has no single mandated protocol. Instead, several competing standards have emerged:
The data must be transmitted before or at the same time as the transaction — never after. This creates a timing challenge: a compliant transfer requires the counterparty's identity to be resolved in real time before the value moves on-chain.
There is also a persistent data-security tension. VASPs must share personal data to comply with AML rules while simultaneously respecting privacy laws such as the EU's GDPR. Encrypting data in transit, minimizing what is shared, and limiting retention are all part of a defensible compliance design.
Key Operational Challenges
Interoperability Between Protocols
With multiple protocols in use, a VASP on TRISA may need to exchange data with a counterparty on Sygna or Notabene. Gateways and translation layers are essential, but friction remains.
Self-Hosted Wallet Verification
When a transfer goes to a self-hosted (non-custodial) wallet, the EU requires the VASP to verify that the customer owns or controls that wallet above €1,000. This "ownership attestation" is technically and operationally demanding.
Counterparty Due Diligence
VASPs must perform due diligence on foreign counterparties to ensure they are also regulated and compliant. Sending data to an unregulated counterparty can itself create regulatory exposure.
The "Sunrise Issue"
As of January 2026, roughly 85 of 117 FATF jurisdictions have enacted Travel Rule legislation — but holdouts remain. When one side of a transfer is in a compliant jurisdiction and the other is not, the originating VASP faces difficult decisions about whether and how to proceed.
Structuring Detection
Bad actors attempt to evade thresholds by breaking large transfers into many smaller ones ("structuring"). VASPs must deploy monitoring to detect and report patterns indicative of threshold evasion.
FATF 2026 Updates: The Scope Is Expanding
The FATF's 2026 updates signal stronger, broader enforcement:
-
Expanded scope: intermediaries that perform value-routing or key management can now themselves be classified as VASPs.
-
DeFi in scope: Decentralized finance protocols fall under the Travel Rule when they exercise control, custody, or hold administrative keys.
-
Richer data and retention: Supervisors expect more complete data capture and longer, clearer retention practices.
-
Stronger enforcement: National supervisors are issuing clearer enforcement signals, raising the cost of non-compliance.
PhotonPay's Travel Rule Implementation
✅ Cross-Border AML & Travel Rule

FAQ
What is the Travel Rule in simple terms?
The Travel Rule requires crypto businesses (VASPs/CASPs/MSBs) to collect and send customer identifying information alongside qualifying transfers, so that originator and beneficiary data "travels with the value" and remains available to law enforcement.
Does the Travel Rule apply to small transfers?
It depends on the jurisdiction. The FATF default and several regimes apply a threshold (e.g., USD 1,000), below which only names plus a wallet address or reference are needed. The EU is the major exception: its TFR applies a zero threshold, so all transfers are covered.
How do VASPs send Travel Rule data if there is no SWIFT for crypto?
VASPs use competing protocols such as TRISA, Sygna Bridge, Notabene, and Elliptic. Data must be exchanged before or at the time of the on-chain transaction, requiring real-time counterparty resolution.
Are self-hosted wallets exempt?
No. Above the EU's €1,000 threshold, a VASP must verify that its customer owns or controls a self-hosted wallet. Other jurisdictions address self-hosted wallets through risk-based controls rather than a hard verification rule.
Conclusion
The Travel Rule is no longer optional for any serious virtual asset business. With thresholds that vary from zero (EU) to USD 3,000 (US) and a fragmented protocol landscape, compliance demands both technical infrastructure and regulatory clarity. The 2026 FATF updates only raise the stakes, pulling intermediaries and even some DeFi actors into scope. For VASPs and CASPs building cross-border operations, partnering with a provider that natively supports Travel Rule compliance across all regulated jurisdictions — and layers AI-driven fraud prevention on top — is the most resilient path forward. PhotonPay's implementation delivers exactly that: native, multi-jurisdiction Travel Rule coverage with integrated screening across its entire VASP-to-VASP network.