Newsroom
2026/08/13Industry Trends

The Travel Rule Is Coming: How Can VASPs Prepare for Virtual Asset Transfer Compliance?

The Travel Rule Is Coming: How Can VASPs Prepare for Virtual Asset Transfer Compliance?

Taiwan's Virtual Asset Service Providers (VASPs) are gradually entering the practical implementation phase of the Travel Rule.

For VASPs, the Travel Rule is not merely about “collecting a few more pieces of customer data.” The real challenges are: Who is the counterparty? What information needs to be exchanged? What rules apply across different jurisdictions? How can data be exchanged securely while leaving an auditable record?

What Is the Travel Rule?

The Travel Rule requires virtual asset service providers, when transferring assets on behalf of customers, to transmit the identity information of both the originator and the beneficiary to the counterparty provider along with the transaction. The information “travels” together with the funds — which is where the name comes from.

It originates from Recommendation 16 of the FATF (Financial Action Task Force) and initially applied mainly to wire transfers by traditional financial institutions.

When Bank A remits funds on behalf of a customer to Bank B, A must tell B who sent the money and who is to receive it. The purpose is simple: if no one knows who is at either end when funds move, sanctions screening, money-laundering detection, and fund-flow tracing all become impossible.

In June 2019, the FATF issued an Interpretive Note that extended this obligation to virtual assets. The rationale: because VASPs (Virtual Asset Service Providers) transfer cryptocurrency on behalf of customers — functionally equivalent to a bank executing a wire transfer — they should be subject to the same rules. In other words, the Travel Rule is not a newly invented form of regulation for the crypto industry, but an extension of existing financial rules.

The Travel Rule can therefore be understood as: enabling the necessary information about both parties to a transaction to be securely transmitted between the relevant providers at the same time that a virtual asset is transferred.

What Information Must Be Transmitted

To let different providers interpret these fields consistently, the industry established IVMS101, a common data model (maintained by the interVASP Standards Working Group) used specifically for exchanging originator and beneficiary information between VASPs, avoiding the interoperability failures that arise when each firm uses its own definitions.

Common Information Items Under the FATF Travel Rule

Originator

Beneficiary

Name

Name

Account number or transaction identifier

Account number or transaction identifier

Address, national ID number, or customer identification number

Wallet address

Wallet address

Date of birth / place of birth (jurisdiction-dependent)

Based on FATF Recommendation 16, the Travel Rule requires VASPs to transmit the necessary information relating to both parties to a transaction; the actual fields and verification requirements vary by jurisdiction.

Common Misconception: The Travel Rule Does Not Mean Putting Personal Data On-Chain

The Travel Rule does not require personal data such as names or national ID numbers to be written directly onto the blockchain. The blockchain handles the asset transfer, while the Travel Rule infrastructure handles the identification, exchange, and compliance processing of both parties' information.

Thresholds Vary by Country

The EU and the UK apply no de minimis exemption for crypto assets, meaning that even the smallest transfers are covered. For providers operating across multiple markets at once, this effectively lowers the global compliance baseline to a zero threshold.

Thresholds are not uniform globally — this is one of the points most easily misjudged in practice:

Jurisdiction

Applicable threshold

FATF (global baseline)

Countries may apply a simplified threshold of up to USD / EUR 1,000

EU

No de minimis exemption for crypto assets; additional verification requirements apply to self-hosted wallets above €1,000

UK

No de minimis exemption for crypto assets (since September 2023)

US

USD 3,000 (a proposal to lower this to USD 250 has not been finalized)

Singapore

SGD 1,500

Taiwan (planned)

No de minimis exemption; enhanced information collection and beneficiary verification for transfers above NT$30,000

Falling below a threshold does not entirely remove information-collection obligations — the names of both parties and a wallet address or unique transaction identifier must generally still be obtained; only the verification requirements are simplified. Actual rules vary by jurisdiction.

Why Is Implementing the Travel Rule Difficult?

1. You Don't Always Know Who the Counterparty Is

On the blockchain you typically see only a string of wallet addresses, but behind an address there may be an exchange, a VASP, a financial institution, a custodian, or a self-hosted wallet. To transmit information to the counterparty provider, you first have to identify who that provider is.

2. Jurisdictions Are Not Implementing on the Same Timeline

The industry calls this the “Sunrise Problem”: when your jurisdiction has already mandated the rule but the counterparty's jurisdiction has not, information can neither be sent nor received, creating a one-way gap.

3. There Is No Standard Answer for Self-Hosted Wallets

Whether transfers into wallets that users hold themselves fall within scope varies by jurisdiction, and the FATF has left room for discretion. The EU requires such transfers to be covered even when a VASP cannot verify the wallet owner's identity — a stricter approach, but not a universal rule. The correct approach is risk-based, rather than applying a single blanket rule.

The Travel Rule in Taiwan: Current Status

Taiwan is progressively advancing a Travel Rule regime for virtual asset transfers. Based on the competent authority's current announcements and planned direction, the requirements will be introduced in phases: the first phase is expected to apply from October 2026 to virtual asset transfers between domestic VASPs, with a second phase gradually extending to cross-border transfers. The actual effective date and scope of application remain subject to the competent authority's subsequent official announcements.

Under the current plan, Taiwan will adopt a relatively comprehensive information-collection mechanism: regardless of the transfer amount, VASPs must carry out the Travel Rule as required; where the value of a single transfer exceeds NT$30,000, information-collection and verification requirements are further strengthened.

For example, a natural-person originator may be required to provide a date of birth and residential address, while a legal-entity originator may be required to provide an official identification number and registered address. For transfers exceeding the relevant threshold, the beneficiary VASP must also verify the beneficiary's information as required.

On 22 July 2026, the Virtual Asset Service Act was formally promulgated, marking a further step toward dedicated legislation for virtual asset regulation in Taiwan; the relevant provisions and supporting measures will continue to be implemented progressively in accordance with the competent authority's subsequent rules.

For VASPs, the question to start considering now is not only “when will the Travel Rule formally take effect?” but, more importantly: are the organization's Travel Rule processes, systems, and counterparty network already prepared?

What Must Be Solved to Implement the Travel Rule?

A complete Travel Rule process must handle, at a minimum:

Counterparty identification  —  confirming the counterparty behind an on-chain address and its institutional information.

Secure information exchange  —  securely transmitting the necessary information between the two parties in a standardized data format.

Cross-jurisdictional rule determination  —  determining the appropriate compliance measures based on the two parties, the transaction type, and the applicable regulations.

Transaction records and audit  —  retaining records of information exchange, counterparty determinations, and processing outcomes to build a complete, auditable trail.

As a result, the Travel Rule is gradually shifting from a mere regulatory requirement to part of the infrastructure for virtual asset transactions.

BlockChain Security × Notabene

BlockChain Security (BCS) is Notabene's reseller in Taiwan.

Notabene is one of the world's leading providers of Travel Rule and digital-asset transaction compliance infrastructure. Its network currently connects more than 2,000 verified financial institutions and related businesses across over 100 jurisdictions.

By pairing Notabene's global network and compliance infrastructure with BlockChain Security's local implementation and technical-service capabilities, we help Taiwan's virtual asset service providers meet the demands of Travel Rule implementation:

Identify and verify counterparties  —  helping identify counterparty institutions and obtain the relevant identity and regulatory information to support pre-transaction Travel Rule decisions.

Securely exchange the information the Travel Rule requires  —  exchanging the necessary originator and beneficiary information through standardized data formats and secure communication mechanisms.

Perform compliance determinations  —  making decisions according to the specific transaction scenario and jurisdictional requirements.

Maintain auditable records  —  retaining records of pre-transaction information exchange, decisions, and processing to support subsequent review and internal controls.

BlockChain Security × Notabene — helping Taiwan's virtual asset service providers build a more efficient, scalable, and compliance-ready Travel Rule process.

Evaluating Travel Rule implementation, system integration, or cross-border transaction compliance? Contact BlockChain Security to learn more about the Notabene Travel Rule solution.

Contact Us

Email: service@blockchainsecurity.asia    |    Phone: +886 2 2515-2533

This article was last updated on 10 August 2026. Its contents are compiled from publicly available information as of the publication date and are provided for general informational purposes only; they do not constitute legal or compliance advice. The actual scope of application, effective dates, and compliance requirements are subject to the latest official laws, orders, and announcements issued by the competent authority.

Welcome to our website! We use cookies to enhance your experience. View our Privacy Policy for more information.

Learn More