# Travel Rule: Two Regimes, Divergent Thresholds and the Data That Travels With a Transfer

> Two Travel Rules, not one: a zero threshold in the EU since Dec 2024, £800 in the UK since June 2026, USD 3,000 in the US since 1996, zero in Korea from Feb 2027.

Author: Ksenia Voronova — Lawyer, Family Office (https://wiki.private.law/en/authors/voronova)
Last modified: 2026-09-07T00:00:00.000Z
Canonical: https://wiki.private.law/en/travel-rule
Publisher: wiki.private.law (https://wiki.private.law)
Version: 1eeec4494174b3e3b137e37034ec32cc09e1ccf14c8731b55577c7666b382f84
Cite as: Travel Rule: Two Regimes, Divergent Thresholds and the Data That Travels With a Transfer. wiki.private.law. https://wiki.private.law/en/travel-rule. Version 1eeec4494174b3e3b137e37034ec32cc09e1ccf14c8731b55577c7666b382f84.
Topics: banking
Jurisdictions: global, eu, usa, uk, switzerland, singapore, hong-kong, japan, korea, canada
Functional tags: license-vasp-mica
Product tags: compliance, crypto, banking, stablecoin
Semantic tags: license-vasp-mica, compliance, crypto, banking, stablecoin

---

## Two Travel Rules That Keep Getting Merged Into One

The requirement that identifying data on payer and payee travel alongside a transfer exists in the FATF standard in two separate copies — and they are routinely collapsed into one. Recommendation 16 ("payment transparency") addresses banks and payment providers and describes wire transfers. Recommendation 15 and its interpretive note (INR.15) address virtual asset service providers; the Travel Rule reaches VASPs not directly but through INR.15's cross-reference to R.16.

The distinction stopped being academic in June 2025, when FATF adopted the [revised R.16](https://www.fatf-gafi.org/en/publications/Fatfrecommendations/update-Recommendation-16-payment-transparency-june-2025.html). The [explanatory note](https://www.fatf-gafi.org/content/dam/fatf-gafi/recommendations/Explanatory%20note%20for%20revised%20R.16.pdf.coredownload.pdf) says it plainly: VASPs are not brought within the scope of R.16, the requirements continue to apply to them indirectly via R.15, and INR.15 will be updated "as necessary" to keep the cross-references current.

Two conclusions follow. First, any commentary claiming that "FATF updated the crypto Travel Rule in 2025" is wrong. Second, since June 2025 there is an officially acknowledged gap between the data-field sets for the banking rail and the crypto rail, with no closing date. An operator running both corridors in one [compliance stack](https://wiki.private.law/en/compliance-stack) inherits two mismatched data schemas for years, and the question "which field set does a CASP use when passing data to a bank" has no official answer.

- Rule · FATF Recommendation 16 (wire transfers), R.15 and INR.15 (virtual assets); in the EU — Regulation (EU) 2023/1113
- Who is caught · Banks and payment providers under R.16; virtual asset service providers indirectly, through R.15
- Threshold · FATF benchmark — de minimis up to USD/EUR 1,000; no crypto threshold in the EU, USD 3,000 in the US
- Data set · Above the threshold: originator — name, account number or reference, address or identifier; beneficiary — name, account, country and town
- Implementation deadline · Revised R.16 — end-2030; INR.15 is updated separately, with no date attached
- Liability · Cannot be delegated: a third-party Travel Rule solution does not relieve the VASP itself
- Status as at · 07.09.2026: the FATF consultation on R.16 guidance is closed, adoption expected around October 2026

## The R.16 Reform: Fewer Fields, Higher Quality Bar

The revision reorganised the interpretive note by transaction type rather than by entity type, aligned originator-side and beneficiary-side obligations symmetrically, and added fraud to the list of key predicate offences. Above the USD/EUR 1,000 de minimis the required set is: for the originator, name (the ordering institution verifies its accuracy), account number or unique transaction reference, and either an address or a national identifier, customer ID or date of birth; for legal persons, BIC, LEI or another unique official identifier. For the beneficiary: name, account number or reference, and **country and town only**, not a full address. Below the threshold, names and account numbers suffice without verification.

The set was simultaneously softened for financial inclusion: country and town are acceptable for the originator without a standardised postal format, the year of birth suffices where the full date is unavailable, and national identification numbers and customer IDs of natural persons are no longer mandatory fields. The result is captured by the phrase "present but poor": fewer fields, but the test has moved from whether a field exists to whether it is usable. A truncated name, a placeholder, an unstructured address line, a mismatch between what was sent and what was received — each is now a standalone basis for a supervisory finding on a perfectly lawful payment. The beneficiary institution must in addition run alignment checks: post-validation, holistic monitoring, or pre-validation in the Confirmation of Payee format.

The timeline is long. The implementation deadline is **end-2030**; the annex to the assessment methodology appeared in October 2025, and the current edition of the Recommendations is marked "Updated October 2025". Draft guidance went to [public consultation on 24 June 2026](https://www.fatf-gafi.org/en/publications/Fatfrecommendations/R16-Public-Consultation-June-2026.html); the comment window closed on 21 August 2026. The consultation agenda covers four themes:

- misdirected payments and alignment checks;
- financial inclusion;
- digital wallets and mobile money;
- the balance between R.16 and data protection requirements.
Adoption is expected around October 2026, which is when the five-year window effectively starts. For a sense of pace: it took seven years from FATF's 2019 crypto standard to 83% adoption.

## Thresholds by Jurisdiction: From Zero in the EU to USD 3,000 in the US

The monetary thresholds and the dates they took effect, across the FATF standard and nine jurisdictions.

| **Jurisdiction** | **Fiat threshold** | **Crypto threshold** | **In force since** |
| --- | --- | --- | --- |
| **FATF (standard)** | de minimis up to USD/EUR 1,000; below it, names and account numbers without verification | USD/EUR 1,000 (INR.15 §7(b)) | R.16 revision — June 2025, implementation by end-2030 |
| **EU** | EUR 1,000; intra-Union below that, account numbers suffice and verification is not required absent cash, anonymous e-money or suspicion | **0 — no threshold**; recital 30: identical requirements regardless of amount | 30.12.2024 |
| **US** | **USD 3,000** | USD 3,000 (CVC treated as "money" under 2019 FinCEN guidance) | 31 CFR 1010.410(e),(f) — unchanged since 1996 |
| **UK** | n/a (Part 7A covers cryptoassets only) | Basic set (names and identifiers) at any amount; extended set from **£800** | Part 7A — 01.09.2023; £800 threshold — 30.06.2026 |
| **Switzerland** | CHF 0 | **CHF 0** — all transfers | FINMA Guidance 02/2019 — 26.08.2019 |
| **Singapore** | n/a | **SGD 1,500**; below, names and account numbers; above, the full PII set | 28.01.2020 (Notice PSN02) |
| **Hong Kong** | n/a | **HKD 8,000**; below, names and account numbers; above, plus originator address or ID | 01.06.2023 (AMLO and the SFC AML Guideline) |
| **Japan** | n/a | **No de minimis** | 01.06.2023 |
| **South Korea** | n/a | KRW 1,000,000 → **0** | Zero threshold — 20.02.2027 |
| **Canada** | CAD 1,000 | CAD 1,000 (plus separate reporting at CAD 10,000) | 01.06.2021 (transition period to 31.03.2022) |

The second dimension of the same matrix is what each jurisdiction demands on a transfer to an external, self-hosted wallet.

| **Jurisdiction** | **Self-hosted / unhosted** |
| --- | --- |
| **FATF (standard)** | Party data collected even for transfers to unhosted addresses; measures are risk-based |
| **EU** | Above EUR 1,000 — "adequate measures" to assess whether the address belongs to the client (Arts. 14(5) and 16(2)); the identity of a self-hosted address user need not be verified (recital 39) |
| **US** | No requirement |
| **UK** | reg. 64G: risk-based information request, £800 threshold; if the information is not obtained, the asset must not be made available to the beneficiary |
| **Switzerland** | Verification of power of disposal over an external wallet at any amount; Satoshi test or signed message; the separate CHF 1,000-per-30-days threshold (Art. 51a AMLO-FINMA) applies only to crypto-for-cash exchange |
| **Singapore** | Non-custodial sits outside the Travel Rule perimeter, but EDD and proof of address ownership are required |
| **Hong Kong** | Ownership of an unhosted wallet must be verified before the transfer and periodically for whitelisted addresses; cryptographic signature |
| **Japan** | Data collection and risk assessment for self-hosted transactions |
| **South Korea** | From 20.02.2027: transfers to overseas exchanges outside the low-risk list and to personal wallets only where sender and recipient are the same person; high-risk destinations barred |
| **Canada** | No specific non-custodial requirements |

The EU runs the strictest regime by design. [Regulation (EU) 2023/1113](https://eur-lex.europa.eu/eli/reg/2023/1113/oj/eng) has applied since 30 December 2024 in step with [MiCA](https://wiki.private.law/en/mica-eu), and it carries no de minimis for crypto transfers: recital 30 requires the same data set irrespective of amount. That is a choice by the European legislator, not a FATF requirement — FATF permits a threshold up to USD/EUR 1,000.

The regulation is supplemented by the [Travel Rule Guidelines EBA/GL/2024/11](https://www.eba.europa.eu/sites/default/files/2024-07/6de6e9b9-0ed9-49cd-985d-c0834b5b4356/Travel%20Rule%20Guidelines.pdf) of 4 July 2024: "missing" information covers not only an empty field but meaningless content — random characters, a title with no name, inadmissible characters; the window to chase missing data is 3 business days intra-Union, 5 from outside and up to 7 for complex intermediary chains.

The US is the principal outlier. The threshold in [31 CFR 1010.410](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-D/section-1010.410) remains **USD 3,000** and has not moved since 1996. The [joint FinCEN–Federal Reserve NPRM of 27 October 2020](https://www.federalregister.gov/documents/2020/10/27/2020-23756/threshold-for-the-requirement-to-collect-retain-and-transmit-information-on-funds-transfers-and) (85 FR 68005) proposed lowering it to USD 250 for transfers beginning or ending outside the US and expressly bringing convertible virtual currency into the definition of "money".

That proposal is dead: in the Unified Agenda, [RIN 1506-AB41](https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202504&RIN=1506-AB41) sits under Completed Actions marked "Withdrawn 04/16/2025" — even though a substantial share of 2025–2026 industry commentary still describes it as pending. The US is assessed partially compliant with R.16; the detail sits on the [MSB and FinCEN](https://wiki.private.law/en/msb-license-usa) page, with the Canadian perimeter on the [map of financial licences by jurisdiction](https://wiki.private.law/en/fintech-license-map).

The UK quietly tightened its threshold in June 2026. [MLR 2017 Part 7A](https://www.legislation.gov.uk/uksi/2017/692/part/7A) has applied since 1 September 2023: [reg. 64C](https://www.legislation.gov.uk/uksi/2017/692/regulation/64C)(5) requires the parties' names, firm names and account numbers or unique transaction identifiers at any amount, while the extended set — customer ID, address, document number, date and place of birth — was triggered at "1,000 euros". [SI 2026/621](https://www.legislation.gov.uk/uksi/2026/621/made) replaced that wording with **£800** in both reg. 64C(4) and reg. 64G(1)(b) with effect from 30 June 2026.

The instrument was made on 9 June 2026 and comes into force 21 days later; it redenominates every euro figure in the MLR at once.

| Euro figure | After SI 2026/621 |
| --- | --- |
| 15,000 euros | £12,000 |
| 10,000 euros | £10,000 |
| 2,000 euros | £2,000 |
| 1,000 euros | £800 |

For crypto that conversion is not neutral: £800 is roughly EUR 930, so the threshold fell. The amendment is buried in regs 32–33 of an instrument carrying dozens of MLR changes; the wider UK perimeter is covered in the analysis of the [FCA and Bank of England crypto regime](https://wiki.private.law/en/uk-safeguarding-crypto-regime).

Korea is not merely zeroing its threshold — it is campaigning to move the global standard. Under the [Cabinet decision of 11 August 2026](https://www.fsc.go.kr/no010101/87499) the KRW 1,000,000 floor disappears six months after promulgation of the amended decree — on 20 February 2027; from the same date, transfers to overseas exchanges outside the low-risk list and to personal wallets are allowed only where sender and recipient are the same person, and high-risk destinations are barred outright. The head of KoFIU argued at the June 2026 FATF plenary in Paris that a de minimis becomes a loophole for anyone willing to split a withdrawal into a few hundred small transactions. If FATF adopts a zero threshold, the US position becomes untenable and the European model becomes the global norm; the likelier compromise is that the threshold survives while linked-transaction aggregation rules tighten.

## Self-Hosted Wallets: Ownership Is Tested, Identity Is Not

The EU tests something narrow. Articles 14(5) and 16(2) TFR require a CASP, when sending to or receiving from a self-hosted address above EUR 1,000, to take adequate measures to assess whether the address is owned or controlled by its own client. Recital 39 states expressly that a CASP is in principle under no obligation to verify information about the user of a self-hosted address: what is checked is the client's ownership of the address, not the counterparty's identity — a compromise against the European Parliament's far harsher opening position on unhosted wallets.

The EBA lists sufficient methods: unattended verification (demonstrating the address under remote onboarding rules), attended verification, a Satoshi test sending a predetermined amount, signing a specified message with the key corresponding to the address, and other reliable technical means. Whitelisting after verification is permitted, subject to monitoring for changes in ownership and risk, and the indicators of linked transactions are set out separately (one payer and one payee over a short period, multiple payees, multiple accounts of the same person) — with "short period" left to the institution's own risk assessment.

From there the spectrum opens. Switzerland, under FINMA Guidance 02/2019, requires verification of power of disposal over an external wallet at any amount and for any wallet, including third-party ones; the Travel Rule itself carries no threshold, and the 30-day window in [Art. 51a AMLO-FINMA](https://www.finma.ch/en/news/2022/11/20221102-mm-gwv-finma/) (in force since 1 January 2023) concerns something else — the CHF 1,000 identification threshold for exchanging virtual currency for cash, counted across linked transactions. Hong Kong verifies unhosted wallet ownership before the transfer and re-verifies whitelisted addresses periodically. [Singapore](https://www.mas.gov.sg/regulation/notices/psn02-aml-cft-notice---digital-payment-token-service) puts non-custodial outside the Travel Rule perimeter but keeps EDD and proof of ownership. The UK operates on a risk basis from £800, and [reg. 64G](https://www.legislation.gov.uk/uksi/2017/692/regulation/64G)(4) supplies a hard consequence: if the requested information is not received, the cryptoasset must not be made available to the beneficiary. The US requires nothing.

Where FATF moves next is open. The [targeted report on stablecoins and unhosted wallets of 3 March 2026](https://www.fatf-gafi.org/en/publications/Virtualassets/targeted-report-stablecoins-unhosted-wallets.html) introduces no new standards: it records more than 250 [stablecoins](https://wiki.private.law/en/stablecoins) with capitalisation above USD 300bn by mid-2025, finds that they accounted for 84% of illicit virtual-asset transaction volume in 2025, and recommends requiring issuers to hold freeze/burn and allow/deny-list capability — while leaving the obligation to transmit party data with CASPs. The same gap shows in P2P: 88% of surveyed jurisdictions (58 of 66) treat such transfers as high risk, but only 23% (31 of 133) collect market metrics.

## Sunrise Became an Enforcement Gap and a Technical Debt

The sunrise problem, as defined in [FATF's Best Practices on Travel Rule Supervision](https://www.fatf-gafi.org/content/dam/fatf-gafi/recommendations/Best-Practices-Travel-Rule-Supervision.pdf) (June 2025), is "the uneven adoption of the Travel Rule across jurisdictions due to delays and/or inconsistent standards" — named the single largest obstacle. By 2026 the legislative gap is nearly closed: the [seventh Targeted Update of 16 July 2026](https://www.fatf-gafi.org/en/news/targeted-updated-va-vasps-2026.html) records the Travel Rule in force in 83% of jurisdictions (91 of 109) against 73% a year earlier, with 11 more in progress — 93% in total; among the 69 materially important jurisdictions (roughly 97% of global VA trading volume) adoption reaches 94%.

The other side of the same dataset reads differently: legislative coverage runs ahead of both supervision and technical compliance.

| Indicator | Value |
| --- | --- |
| No finding, direction or enforcement action at all | 60% of jurisdictions with a law in force (55 of 91) |
| Meet criterion R.15.9 (preventive measures including the Travel Rule) | 13 of 149 jurisdictions |
| R.15 technical compliance as at April 2026 | compliant — one; largely compliant — 34% (51 of 149) |
| R.15 partially and non-compliant | 43% and 22% |
| Licensing required | 73% (95 of 130) |
| Licensing actually performed | 58% (76 of 130) — down from 65% |
| Prohibit VASPs | 23% (33 of 144) in 2026 against 11% in 2023 |

A correction for anyone reading progress charts: a prohibition counts as a risk response even though the Travel Rule is simply unnecessary in such a jurisdiction.

Sunrise and interoperability are legally distinct problems. Under sunrise, the counterparty sits in a jurisdiction without a Travel Rule and is under no duty to exchange personal data; the answer is documented best efforts. Under interoperability, the counterparty is compliant and willing but runs an incompatible solution; the answer is direct protocol integration or the expensive route of supporting several networks at once. The second is now the dominant one.

IVMS101 is a data model (which fields, in which format), not a transport protocol, and it is going through a "reboot" in 2025–2026. The channels are fragmented: open TRP, OpenVASP and TRISA, the closed TRUST network, commercial Sygna Bridge, VerifyVASP, Shyft Veriscope, GTR, CODE, and gateways such as Notabene SafeTransact. The problem is being solved by mergers rather than standards: on 29 April 2026 VerifyVASP acquired Sygna, consolidating members into the Verified Network, while TRISA and TRP announced mutual interoperability. The regulatory consequence is addressed nowhere: critical compliance infrastructure is concentrating in a handful of commercial operators, liability stays with the VASP, and no supervisory regime exists for the network operators themselves.

Enforcement confirms the diagnosis. Pure "Travel-Rule-only" penalties barely exist: the rule appears as a component of broader AML cases.

| Case | Penalty | Authority | Date |
| --- | --- | --- | --- |
| OKX | USD 505m | DOJ resolution | 24.02.2025 |
| KuCoin | USD 300m | — | 27.01.2025 |
| Paxos | USD 48.5m | NYDFS | 06.08.2025 |
| Cryptomus | CAD 176.96m | FINTRAC | 22.10.2025 |
| Upbit | KRW 35.2bn (about USD 25m) | KoFIU | November 2025 |

The FINTRAC penalty was for failing to file large virtual currency transfer reports, and the Korean case is closest to the genre: Upbit was fined for roughly 5.3 million breaches of customer verification duties. The second format is a direction without a monetary penalty: the [FCA](https://www.fca.org.uk/news/statements/fca-sets-out-expectations-uk-cryptoasset-businesses-complying-travel-rule) required a firm to onboard an additional Travel Rule solution and remediate historic non-compliant transactions.

## Privacy: The Mandatory Guidelines That Do Not Exist

Article 25 TFR subjects the processing to the GDPR, prohibits further incompatible processing and expressly bars commercial use, and requires Article 13 GDPR information to be given **before** the business relationship is established; the Article 26 retention period is five years. Article 25(4) obliges the EDPB to issue guidelines on the practical implementation of data protection requirements for transfers of personal data to third countries in the crypto-transfer context. Twenty months after the regulation began to apply, no such document appears in the [EDPB register](https://www.edpb.europa.eu/our-work-tools/general-guidance/guidelines-recommendations-best-practices_en).

The practical consequence: the legal basis for the transmission is Article 6(1)(c) GDPR (legal obligation), but everything runs into Chapter V — most VASP jurisdictions have no adequacy decision. The market holds together on five supports:

- SCCs with the counterparty CASP;
- transfer impact assessments;
- field minimisation;
- encryption;
- the pattern of "first confirm the address belongs to a regulated counterparty able to receive the data, then send the PII".
Relying on the Article 49(1)(d) derogation for a continuous flow is fragile: the EDPB insists Chapter V derogations must be occasional, and the Travel Rule is systematic by definition. This is the most exposed point in the European regime, and FATF acknowledges the conflict — the balance between R.16 and data protection is on the June 2026 consultation agenda.

## Why an Address and Date of Birth for EUR 50

First: the EU has no threshold at all for crypto transfers — EUR 20 is handled exactly like EUR 20,000, a choice by the European legislator rather than a demand of the standard. A EUR 50 crypto transfer carries more data obligations than a EUR 900 intra-Union SEPA payment. Your data goes to the counterparty CASP, including into countries with no adequacy decision; commercial use is prohibited, retention is five years, and processing information must be provided before the relationship starts. What a regulated intermediary collects and why is covered in [AML/KYC for the private client](https://wiki.private.law/en/aml-kyc-private-client).

Second: a "stuck" transfer is usually Article 17 TFR, which lets the beneficiary CASP execute, reject or suspend where data is incomplete, plus the EBA chase windows — 3 business days intra-Union, 5 from outside, up to 7 in a complex chain. A refusal is not always justified: the EBA states that missing or inadmissible information **does not in itself give rise to suspicion** of money laundering and requires a holistic risk assessment. That is a usable argument in a complaint.

Third: withdrawing to your own wallet. In the EU, above EUR 1,000 the exchange must satisfy itself that the address is yours — hence the request to sign a message or run a Satoshi test; Switzerland does this at any amount, the UK on a risk basis from £800, the US not at all. Fourth: structuring below a threshold reads plainly — the EBA requires linked transfers to be identified, UK reg. 64C(4) counts them together towards the £800, and in Switzerland the Travel Rule has no threshold at all, the 30-day window of Art. 51a AMLO-FINMA applying only to crypto-for-cash exchange. How this interacts with holding structures is covered in [crypto for private wealth](https://wiki.private.law/en/crypto-private-wealth).

## A Matrix of Corridors, Not One Configuration

One stack has to carry three mismatched thresholds: zero in the EU, roughly a thousand under FATF logic and across most of Asia, USD 3,000 in the US. From February 2027 the Korean zero is added, while the UK runs a hybrid — a basic set at any amount plus an extended set from £800. The June 2026 UK change is a trap of its own: systems with the threshold hard-coded in euros with auto-conversion will misfire in both directions.

Liability cannot be delegated: both the FCA and Hong Kong's SFC state that using a third-party Travel Rule solution does not relieve the VASP — which makes vendor due diligence a control in its own right. The weakest link is counterparty due diligence: 57% of jurisdictions (49 of 85) confine domestic VASPs to licensed, registered or compliant foreign counterparties, 22 of them require both a licence and Travel Rule compliance, and only 9 impose no restriction at all — while no global register of licensed VASPs exists. The working stack: "equivalent jurisdiction" lists (Japan publishes one annually), network provider directories, your own counterparty KYB, and documented reasonable steps for sunrise cases. Offshore VASPs are a separate risk layer: per FATF's [March 2026 report](https://www.fatf-gafi.org/en/publications/Virtualassets/Understanding-Mitigating-Risks-Offshore-VASPs.html) only 46% of jurisdictions regulate on an activity basis, and 44% (50 of 114) licence domestic providers only.

Three items belong in the plan now: data validation rather than mere transmission; a GDPR perimeter built without waiting for the EDPB guidelines; and vendor selection based on the overlap between coverage and your actual corridors rather than headline VASP counts. The roadmap: the Korean zero in February 2027, AMLR and the reshaping of the European regime in July 2027, direct AMLA supervision of some forty high-risk cross-border obliged entities from January 2028, and the revised R.16 on the banking rail by end-2030. If you operate under someone else's licence, the matrix is still yours — the model itself is set out in the guide to the [CASP licence](https://wiki.private.law/en/casp-license-guide).

### What Happens to the TFR on 9 July 2027

One fork, now resolved. EUR-Lex metadata for Regulation (EU) 2023/1113 does show 9 July 2027 — precisely one day before [AMLR](https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng) starts to apply and CASPs become obliged entities under it. But the annotation on that date carries the code FIN/VAL/PART: a partial end of validity, tied to Article 38 and to a partial implicit repeal (AI/PAR) by Directive (EU) 2024/1640. The same metadata still records the regulation as in force. So the TFR is not repealed wholesale on that date — the European perimeter is being reshaped around the [AML package](https://wiki.private.law/en/eu-aml-package) either way, but the regulation itself does not vanish on 9 July 2027.

## Calendar: What Happens When

| **Date** | **Milestone** |
| --- | --- |
| 26.08.2019 | Switzerland: FINMA Guidance 02/2019 — Travel Rule and external wallet verification |
| 28.01.2020 | Singapore: PSN02 takes effect (SGD 1,500 threshold) |
| 01.06.2021 | Canada: Travel Rule applies, transition period to 31.03.2022 |
| 01.06.2023 | Hong Kong and Japan: Travel Rule in force |
| 01.09.2023 | UK: MLR 2017 Part 7A, the FCA statement, JMLSG guidance |
| 04.07.2024 | EU: EBA adopts the Travel Rule Guidelines (EBA/GL/2024/11) |
| **30.12.2024** | **EU: TFR applies alongside MiCA; zero threshold for crypto** |
| **16.04.2025** | **US: the proposal to lower the threshold to USD 250 is formally withdrawn** |
| **June 2025** | **FATF: R.16 revision and Best Practices on Travel Rule Supervision** |
| 18.07.2025 | US: the GENIUS Act is signed — a federal stablecoin framework |
| October 2025 | FATF: Recommendations "Updated October 2025" plus the R.16 assessment methodology annex |
| November 2025 | Korea: KRW 35.2bn fine on Upbit |
| 03.03.2026 / 11.03.2026 | FATF: reports on stablecoins and unhosted wallets, then on offshore VASPs |
| 29.04.2026 | VerifyVASP acquires Sygna — consolidation of Travel Rule networks |
| **30.06.2026** | **UK: SI 2026/621 — £800 threshold replaces "1,000 euros"** |
| 24.06.2026 – 21.08.2026 | FATF: public consultation on the draft R.16 guidance |
| 16.07.2026 / 21.07.2026 | FATF: 7th Targeted Update on VAs/VASPs, then the targeted report on DeFi |
| around October 2026 | Expected adoption of the R.16 guidance |
| **20.02.2027** | **Korea: zero Travel Rule threshold; personal-wallet transfers only to oneself** |
| **10.07.2027** | **EU: AMLR applies, CASPs become obliged entities; the day before, the TFR sees a partial end of validity for art. 38 — not a wholesale repeal** |
| **January 2028** | **AMLA begins direct supervision of high-risk cross-border obliged entities** |
| end-2030 | FATF: implementation deadline for the revised R.16 on the banking rail |

> 🍓 The Travel Rule is not one rule but two: banking R.16, revised in June 2025 with an implementation deadline of end-2030, and the crypto regime under R.15/INR.15, which that revision does not directly touch. Thresholds diverge radically: zero in the EU since 30.12.2024, £800 in the UK since 30.06.2026, USD 3,000 in the US unchanged since 1996, and zero in Korea from 20.02.2027. That explains both the date-of-birth question on a EUR 50 transfer and the request to sign a message when withdrawing to your own wallet.

## Q/A

### Did anything change for crypto after the June 2025 R.16 reform?

Legally, no. FATF's explanatory note states expressly that VASPs are not brought within R.16's scope: the requirements reach them indirectly through R.15, and INR.15 will be updated "as necessary". The new field set — symmetry between the parties, country and town only for the beneficiary, year of birth instead of a full date, removal of mandatory national IDs — belongs to the banking rail. In practice, though, the supervisory logic that data must be not merely present but usable will reach crypto too.

### Why does the EU ask for data even on a EUR 20 transfer?

Because the TFR (Reg. 2023/1113) contains no de minimis for crypto transfers: recital 30 requires the same data set regardless of amount, and the rule has applied since 30 December 2024. This is a European legislative choice, not a FATF requirement — FATF permits a threshold up to USD/EUR 1,000. The fiat side of the regulation keeps the EUR 1,000 threshold, producing the paradox in which a crypto transfer is regulated more tightly than a larger intra-Union SEPA payment.

### My transfer is suspended over incomplete data. What can I do?

Article 17 TFR gives the beneficiary CASP the right to execute, reject or suspend the transfer and request what is missing; the EBA allows 3 business days intra-Union, 5 for inbound transfers from outside and up to 7 for a complex intermediary chain. In the UK, reg. 64G(4) MLR 2017 prohibits making the asset available until the information is obtained. The EBA nonetheless states that missing or inadmissible information does not in itself give rise to suspicion of money laundering — which is the basis of a complaint where the refusal rests solely on a formal field gap.

### How real is the risk of a penalty specifically for the Travel Rule?

Low so far, but the profile is shifting. On FATF's July 2026 data, 60% of jurisdictions with a law in force (55 of 91) have issued no finding or action, and only 13 of 149 meet criterion R.15.9. Pure Travel Rule fines barely exist: the rule appears as a component of broad AML cases (OKX, KuCoin, Cryptomus) or as a direction without a monetary penalty. The closest case in the genre is KoFIU's KRW 35.2bn fine on Upbit; the FCA precedent requiring remediation of historic transactions shows where supervision is heading.

---

## Factual claims

- Adoption is expected around October 2026, which is when the five-year window effectively starts.
- That proposal is dead: in the Unified Agenda, RIN 1506-AB41 sits under Completed Actions marked "Withdrawn 04/16/2025" — even though a substantial share of 2025–2026 industry commentary still describes it as pending.
- The instrument was made on 9 June 2026 and comes into force 21 days later; it redenominates every euro figure in the MLR at once.
- For crypto that conversion is not neutral: £800 is roughly EUR 930, so the threshold fell.
- The FINTRAC penalty was for failing to file large virtual currency transfer reports, and the Korean case is closest to the genre: Upbit was fined for roughly 5.3 million breaches of customer verification duties.
- The practical consequence: the legal basis for the transmission is Article 6(1)(c) GDPR (legal obligation), but everything runs into Chapter V — most VASP jurisdictions have no adequacy decision.
- Relying on the Article 49(1)(d) derogation for a continuous flow is fragile: the EDPB insists Chapter V derogations must be occasional, and the Travel Rule is systematic by definition.
- First: the EU has no threshold at all for crypto transfers — EUR 20 is handled exactly like EUR 20,000, a choice by the European legislator rather than a demand of the standard.

---

Source: wiki.private.law — the private.law legal knowledge base. When quoting, cite the canonical page URL.
Consultation with a lawyer: https://t.me/private_law_bot
