Introduction
The Travel Rule, originally developed by the Financial Action Task Force (FATF), is a critical component of anti-money laundering (AML) and counter-terrorist financing (CFT) efforts in the crypto industry.
Under the EU's Markets in Crypto-Assets Regulation (MiCA), Crypto-Asset Service Providers (CASPs) are required to implement the Travel Rule, which mandates the collection, verification, and transmission of specific information about the originator and beneficiary for crypto-asset transfers.
This regulation aims to enhance transparency and traceability in crypto transactions, aligning the crypto industry with traditional financial sector standards. Key requirements include collecting and verifying customer information, implementing risk-based procedures, handling transfers involving self-hosted wallets, maintaining records, and ensuring compliance with data protection laws. CASPs must adapt their systems and processes to meet these requirements, balancing regulatory compliance with user experience and operational efficiency.
This document provides a comprehensive overview of the Travel Rule requirements, implementation challenges, and practical considerations for CASPs operating under MiCA.
Travel Rule Requirements Under MiCA
Based on Regulation (EU) 2023/1113 (TFR) and the EBA Travel Rule Guidelines, critical requirements for crypto exchanges include:
- Information Collection (TFR: Article 14(1) and (2)):
- Originator: name, crypto-asset account number or distributed ledger address, address (including country), official personal document number, customer ID number (or date and place of birth), and LEI (if available).
- Beneficiary: name, crypto-asset account number or distributed ledger address, and LEI or, in its absence, any other available equivalent official identifier of the beneficiary.
- Verification (TFR: Article 14(6) and Article 16(3)):
- The originator's CASP must verify the accuracy of the originator's information before initiating a transfer. This verification should be based on documents, data, or information from reliable and independent sources.
- The beneficiary's CASP must verify the beneficiary's information before making the crypto-assets available. This is to ensure the integrity of the information throughout the transfer chain.
- Transfer of Information (TFR: Article 14(4)):
- All required information must accompany the transfer of crypto-assets.
- The information should be submitted securely, either in advance of the transfer, simultaneously with it, or concurrently.
- The information doesn't need to be attached directly to the transfer itself, but it must be readily available to appropriate authorities upon request.
- Risk-Based Procedures (TFR: Article 16(1) and 17(1); EBA Guidelines: Section 4.5 and 4.6):
- CASPs must implement effective procedures to detect transfers with missing or incomplete information.
- They need to establish risk-based procedures to determine whether to execute, reject, return, or suspend such transfers.
- These procedures should include monitoring during and after transfers, and should be commensurate with the level of ML/TF risk associated with the transfer.
- Self-Hosted Wallets (TFR: Article 14(5) and 16(2)):
- For all transfers involving self-hosted wallets, CASPs must obtain and hold the required information on both the originator and the beneficiary.
- For transfers exceeding €1,000 to or from a self-hosted address, CASPs must take adequate measures to assess whether the address is owned or controlled by their customer.
- This may involve using blockchain analytics tools or other verification methods.
- Record Keeping (TFR: Article 26(1)):
- CASPs must retain all collected information for a period of five years.
- After this period, personal data should be deleted unless national law provides otherwise.
- Member states may allow or require further retention for up to an additional five years if necessary for preventing, detecting, or investigating money laundering or terrorist financing.
- Compliance and Reporting (TFR: Article 23 and 18; EBA Guidelines: Section 4.7):
- CASPs must implement internal policies, procedures, and controls to ensure compliance with the regulation.
- They must report suspicious transactions to the relevant Financial Intelligence Unit (FIU).
- This includes considering missing or incomplete information as a factor when assessing whether a transfer is suspicious.
- Data Protection (TFR: Article 25):
- All personal data processing must comply with the General Data Protection Regulation (GDPR).
- CASPs must provide new clients with the information required under GDPR Article 13 before establishing a business relationship or carrying out an occasional transaction.
- The processing of personal data under this regulation should be only for the purposes of preventing money laundering and terrorist financing.
- No De Minimis Threshold (TFR: Recital 30):
- There is no general de minimis threshold for crypto-asset transfers between CASPs. All such transfers, regardless of amount, are subject to the Travel Rule requirements.
- For transfers involving self-hosted wallets (TFR: Article 14(5) and 16(2)):
- Basic information collection is required for all transfers.
- For transfers exceeding €1,000, CASPs must take additional steps to assess whether the self-hosted address is owned or controlled by their customer.
- Batch Transfers (TFR: Article 15):
Batch file transfers are bundles of several individual transfers of crypto-assets put together for transmission. The regulation specifies: