Skip to content

News

Travel Rule and KYC: why a crypto exchange asks for your data

Travel Rule and KYC: why a crypto exchange asks for your data

A request for an ID document, a question about the source of funds or whether a wallet really belongs to you - many customers see this as needless bureaucracy. In fact, these are obligations under EU law and anti-money laundering (AML) rules that apply to every legitimately operating crypto-asset service provider. We explain what the Travel Rule is, which data “travels” with a transfer and what you can expect when exchanging crypto.

Key points

  • Since 30 December 2024, Regulation (EU) 2023/1113 covers crypto-asset transfers - this is the EU version of the Travel Rule.
  • Sender and recipient data must accompany every transfer between providers, regardless of the amount.
  • For transfers over EUR 1,000 involving a self-hosted wallet, the provider must assess whether the wallet belongs to the customer.
  • Identity verification (KYC) stems from AML rules - in Poland, from the act of 1 March 2018.
  • Since 2026, providers also collect tax data (DAC8), and the EU AML Regulation (AMLR) will apply from July 2027.

1. What the Travel Rule is

The Travel Rule is a principle known from traditional bank transfers: information about the originator and the beneficiary “travels” with the money, so that at every stage it is clear who is sending funds to whom. The Financial Action Task Force (FATF) extended it to virtual assets, and the EU implemented it in Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets. The rules have applied since 30 December 2024, and the European Banking Authority’s guidelines (EBA/GL/2024/11) set out the details.

This is a global trend: according to a FATF report from July 2026, 91 of the 109 jurisdictions surveyed (83%) have passed Travel Rule legislation, although in 60% of them supervisors have not yet taken any enforcement action.

2. What data travels with a transfer

Travel Rule: what data "travels" with a crypto transfer. Since 30 Dec 2024, crypto-asset service providers in the EU pass on sender and recipient data with every transfer.
Data accompanying a crypto-asset transfer in the EU. Sources: Regulation (EU) 2023/1113, EBA/GL/2024/11 guidelines.
Data Originator Beneficiary
Full name (or company name) yes yes
Blockchain address or crypto-asset account number yes yes
Address including country, ID document number and customer ID - or date and place of birth yes -
LEI (for companies, where available) yes yes

The key difference from bank transfers: for crypto-assets there is no minimum amount - recital 30 of the Regulation states explicitly that the obligations apply regardless of the transfer’s value. A provider that receives a transfer with incomplete data must follow up on the gaps and, in certain cases, may suspend or reject it.

3. Self-hosted wallets and the EUR 1,000 threshold

The Travel Rule mainly concerns transfers between providers (e.g. from an exchange service to an exchange). When one side is a self-hosted wallet, the provider still records its customer’s data, and for transfers over EUR 1,000 it must also assess whether the address is owned or controlled by the customer (Article 14(5) and Article 16(2) of the Regulation).

In practice, you may be asked to confirm ownership of the wallet, for example by signing a message with that wallet’s key, making a small verification transfer or providing a declaration. This is not a sign of suspicion - it is a standard procedure.

4. KYC: why an exchange asks for ID and the source of funds

The Travel Rule says what data to send; AML rules say whom to verify and how. In Poland, virtual currency service providers are obliged institutions under the act of 1 March 2018 on counteracting money laundering and terrorist financing. They must apply customer due diligence measures, including:

  • identifying the customer and verifying their identity against a document,
  • establishing the beneficial owner when the customer is a company,
  • assessing the purpose and nature of the relationship and, where needed, asking about the source of funds,
  • screening against sanctions lists and checking politically exposed person (PEP) status,
  • monitoring transactions on an ongoing basis and reporting suspicious activity to the financial intelligence unit (GIIF in Poland).

If a customer refuses to provide the required information, the obliged institution cannot carry out the transaction. From 10 July 2027, the EU AML Regulation (AMLR, 2024/1624) will harmonise these rules across the EU, and the new EU authority AMLA, based in Frankfurt, will directly supervise selected entities from 2028.

No KYC is a red flag. A service that promises to exchange any amount “without verification” is most likely operating outside the law - which increases the risk of losing your funds. Read more in our article on crypto scams.

5. What it means for you in practice

  1. Have your ID document and up-to-date details ready - verification is one-off but may be refreshed.
  2. Provide accurate recipient details when sending funds to another platform; errors can hold up the transfer.
  3. Be ready to prove wallet ownership for larger amounts.
  4. Never use someone else’s account or lend yours - it is a quick route to a block and legal liability.
  5. Keep documents showing the source of funds (contracts, statements, tax returns) - they will also help with reporting crypto tax.

Your data is protected by the GDPR: the provider may process it only for purposes required by law and must keep it secure. The rules on storing and sharing data are set out in the privacy policy of every legitimately operating service.

6. DAC8: data for tax authorities

Alongside AML rules, the DAC8 Directive has applied since 1 January 2026. Crypto-asset service providers collect customers’ identification and tax data and information about their transactions, and report it once a year to the tax administration, which exchanges it with other EU countries. This is a separate obligation from the Travel Rule - it serves tax compliance rather than anti-money laundering.

7. Frequently asked questions

Can I refuse to provide my data?

You can, but then the provider will not carry out the transaction - AML rules expressly prohibit it when due diligence cannot be applied.

Does the Travel Rule apply to transfers to my own wallet?

Yes, in a simplified form: the provider records the transfer data and, for amounts over EUR 1,000, checks that the wallet belongs to you.

Why was my transfer put on hold?

The most common reasons are incomplete sender or recipient data, missing proof of wallet ownership, or the need for additional checks, e.g. on the source of funds. Contact support and have the transaction ID (TXID) ready.

Does an exchange share my data with the tax office?

Under DAC8 - yes, once a year in a report. Separately, obliged institutions report suspicious transactions to the financial intelligence unit under AML rules.

Sources

  1. Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets - EUR-Lex
  2. EBA - Travel Rule Guidelines (EBA/GL/2024/11)
  3. EBA - press release on the Travel Rule guidance
  4. FATF - targeted update on virtual assets and VASPs (2026)
  5. Regulation (EU) 2024/1624 (AMLR) - EUR-Lex
  6. AMLA - Anti-Money Laundering Authority
  7. Council of the EU - adoption of the AML package
  8. Polish Act of 1 March 2018 on counteracting money laundering and terrorist financing (ISAP)
  9. European Commission - DAC8

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore the world of cryptocurrencies

Explore our cutting-edge cryptocurrency exchange platform for swift and secure transactions.

Join the crypto world with White Money!

Register

By registering you agree to our Privacy Policy