If you process crypto transfers between the EU and the US, you're currently running two different compliance postures at once, whether your systems are built for that or not. The EU applies a zero threshold to crypto-asset transfers under Regulation (EU) 2023/1113, meaning originator and beneficiary data has to travel with every transfer regardless of size. The US applies a $3,000 threshold.
A single cross-border payment can trigger one regime, both, or neither, depending on where the counterparty's provider sits.
What the Travel Rule actually requires
The Travel Rule traces back to FATF Recommendation 16, first applied to wire transfers in 2003 and extended to virtual asset service providers (VASPs) in FATF's 2019 guidance update. The core principle is simple: when funds or crypto-assets move between institutions, identifying information about the originator and beneficiary has to travel with the transfer, not just sit in each institution's own records.
FATF adopted a further revision to R.16 in June 2025 aimed at standardising cross-border payment messages further, with a compliance runway out to the end of 2030.
For crypto specifically, that means a payment service provider or crypto-asset service provider (CASP) has to attach and pass along originator and beneficiary data on both ends of a transfer, and through any intermediary in between.
Why the threshold isn't one number
This is where most explanations of the Travel Rule fall short for a payments business operating across borders. In the EU, Regulation (EU) 2023/1113 applies a zero threshold to crypto-asset transfers. Every transfer, regardless of amount, requires the full data set. The regulation entered into force in June 2023 and became fully applicable on 30 December 2024, timed to align with the start of MiCA's CASP licensing regime.
The US takes a different approach. FinCEN's Travel Rule threshold for crypto transactions sits at $3,000, meaning smaller transfers fall outside the mandatory data-collection requirement.
A business that only builds to its home jurisdiction's threshold will miss obligations the moment a counterparty's provider is based somewhere stricter. If you're settling a transfer where either the originating or receiving institution is EU-based, the zero threshold applies to that leg of the transaction regardless of what your own jurisdiction requires.
This is the corridor a lot of B2B crypto flow sits in already: OTC and iGaming settlement routinely moves between EU-based counterparties and US-based ones on the same client relationship, meaning both thresholds can apply within a single month of activity for the same customer. The safer design principle is to build for the strictest applicable threshold across every corridor you operate in, rather than defaulting to your own.
The data fields regulators actually expect
The EU's implementation didn't leave data-field requirements to individual interpretation. The European Banking Authority published Travel Rule Guidelines (EBA/GL/2024/11) in July 2024, applying from the same 30 December 2024 date as the regulation itself, standardising what originator and beneficiary information has to accompany a transfer.
At minimum, that includes name, wallet or account identifier, and either address or an identification number, plus date and place of birth for individuals. The EBA guidelines also set out procedures for what an institution does when a counterparty transfer arrives with missing or incomplete information, which sits closer to a risk-based judgment call than a fixed checklist (more on that below).
The Wolfsberg Group's Payment Transparency Standards add a second layer, aimed specifically at the private-sector due diligence banks and payment providers run on top of the regulatory minimum. Wolfsberg's guidance treats completeness of transaction data as a control point in its own right, something to actively verify rather than assume is present because the regulation requires it.
Self-hosted wallets: the extra layer
Transfers involving a self-hosted (unhosted) wallet carry an additional requirement under the EU regime specifically. For transfers to or from a self-hosted address of €1,000 or more, the receiving institution has to take extra steps to verify ownership or control of that wallet, rather than simply accepting the counterparty data at face value.
This is the part of the regime a lot of VASPs underbuild for. It's straightforward to design a system that captures originator and beneficiary data for institution-to-institution transfers. It's a different engineering problem to verify that the person controlling a self-hosted wallet actually is who the transaction claims, and the €1,000 threshold means this isn't a rare edge case for a business processing meaningful crypto volume.
Who's actually enforcing this
In the EU, enforcement runs through national competent authorities, the same regulators responsible for MiCA and CASP authorisation more broadly, meaning Travel Rule compliance and licensing status are effectively linked. A CASP that can't demonstrate adequate Travel Rule controls has a genuine authorisation problem, not just a fine risk.
In the US, FinCEN holds the equivalent enforcement role for the $3,000 threshold regime. FATF's own enforcement role runs through its mutual evaluation process, which assesses whether member jurisdictions have actually implemented Recommendation 16 effectively — which is part of why the EU and US ended up with different thresholds in the first place: each jurisdiction transposed the same underlying standard through its own legislative process.
What ties all three together is missing or incomplete Travel Rule data. The EBA guidelines set out a range of responses (rejecting the transfer, suspending it pending more information, or filing a suspicious activity report) and which response applies is a risk-based decision built on the specific gap in the data, following each institution's own documented procedure.
Onboarding matters here too. A relationship-based, hands-on KYC process, where the institution actively collects and verifies documentation up front rather than relying purely on self-serve upload, puts a business ahead of Travel Rule data requirements before a transfer even happens, since the underlying identity data is already verified rather than assembled reactively at the point of transfer.
Data-field checklist and threshold decision tree
Minimum data fields for a compliant transfer (both originator and beneficiary):
- Name
- Wallet or account identifier
- Address, or a national identification number
- Date and place of birth (for individuals)
Name, wallet identifier, and address/ID are EBA-standardised under GL/2024/11. Additional fields beyond this baseline can still be jurisdiction-dependent, so check local guidance for any corridor outside the EU/US pairing covered here.
Threshold decision tree:
- Where is the counterparty's PSP or CASP based?
- EU-based → zero threshold applies. Collect full data on every transfer, regardless of size.
- US-based → $3,000 threshold applies. Data collection is mandatory above that amount.
- Is a self-hosted wallet involved on either side?
- Yes, and the transfer is €1,000 or more → additional ownership/control verification is required under the EU regime, independent of where the counterparty institution sits.
- No → standard institution-to-institution data requirements apply as above.
- Is any required field missing on receipt?
- Assess risk-based response: request the missing data, suspend the transfer, or file a suspicious activity report, following your institution's documented procedure.
Building compliance to the strictest applicable threshold in each corridor, rather than defaulting to home-jurisdiction rules, is what keeps a cross-border payments operation from discovering a gap only when a regulator, or a counterparty's compliance team, points it out.
Related reading: Sanctions Screening Configuration: Fuzzy Matching, Thresholds and False-Positive Tuning · The EU AI Act Meets AML: What Automated KYC Systems Now Have to Prove · KYC for Crypto Payments: What Businesses Need to Know Before Onboarding
Frequently asked questions
What is the crypto Travel Rule threshold in the EU?
The EU applies a zero threshold under Regulation (EU) 2023/1113, meaning originator and beneficiary data must accompany every crypto transfer regardless of size. This became fully applicable on 30 December 2024.
What is the crypto Travel Rule threshold in the US?
FinCEN's Travel Rule threshold for crypto transactions is $3,000. Transfers below that amount fall outside the mandatory data-collection requirement.
What data fields does the Travel Rule require?
At minimum, name, wallet or account identifier, and either address or an identification number, plus date and place of birth for individuals. These fields are standardised under the EBA's Travel Rule Guidelines (EBA/GL/2024/11).
Does the Travel Rule apply to self-hosted wallets?
Yes. Under the EU regime, transfers to or from a self-hosted wallet of €1,000 or more require the receiving institution to take extra steps verifying ownership or control of that wallet, beyond standard originator/beneficiary data.
Who enforces the crypto Travel Rule?
In the EU, national competent authorities enforce it alongside MiCA and CASP authorisation. In the US, FinCEN enforces the $3,000-threshold regime. FATF itself doesn't enforce directly but assesses implementation through its mutual evaluation process.