Crypto Travel Rule Explained for Senders and Recipients

Why you should know this

A blockchain can route value using addresses. A regulated provider may also need information about the people or entities behind a transfer. When customers do not expect this, a normal compliance request can look like a scam—or a scam can imitate a normal request.

The Travel Rule is about payment transparency. It does not require a customer to give anyone a seed phrase, password or OTP.

FATF standard and local law are not the same

The Financial Action Task Force sets international AML/CFT standards. Its Travel Rule applies payment-transparency expectations to virtual-asset transfers involving VASPs and financial institutions.

Countries implement those standards through their own laws, regulations and supervisory practices. The data, thresholds, timing, scope and treatment of self-hosted wallets can differ.

FATF revised Recommendation 16 in 2025 and continued Travel Rule work in 2026. Articles and providers must check the applicable local implementation, not quote one global form as universal.

Philippine context

BSP Circular 1108 treats applicable virtual-asset transfers as wire transfers and requires covered VASPs to obtain and transmit required originator and beneficiary information in accordance with the framework described there.

The exact customer request depends on the transaction, provider and current rules. A BSP registration does not mean every foreign VASP can exchange data with every Philippine provider.

Japan context

Japan imposes notification obligations for transfers of cryptoassets and electronic payment instruments on covered providers. The FSA published finalized 2026 amendments concerning Travel Rule obligations.

This does not establish that a particular Japan–Philippines route is available. The providers, counterparties, asset, jurisdiction and customer eligibility still require verification.

Who are the parties?

Originator: the person or entity initiating the transfer.

Originator VASP: the covered provider sending on the customer’s instruction.

Beneficiary: the intended person or entity receiving value.

Beneficiary VASP: the covered provider expected to credit the beneficiary.

A self-custody wallet may change the counterparty structure, but it does not erase provider due diligence or local rules.

What information may be requested?

Depending on applicable requirements and risk, a provider may ask for:

  • originator legal name;
  • originator account or wallet reference;
  • originator address, official document number, customer number, date/place of birth or other permitted identifier;
  • beneficiary legal name;
  • beneficiary account or wallet reference;
  • beneficiary provider;
  • purpose or relationship;
  • confirmation of wallet ownership or control;
  • source or destination context.

This is an educational list, not a universal form. Provide only what the verified provider requests through the authenticated route.

Why a provider asks

The information can support:

  • identity and customer due diligence;
  • sanctions and prohibited-party screening;
  • transaction monitoring and investigation;
  • fraud and error prevention;
  • recordkeeping and regulatory obligations;
  • communication with the receiving provider;
  • allocation to the correct beneficiary.

An information request does not automatically accuse the customer. It also does not guarantee that the transfer will be approved.

Travel Rule is not KYC repeated

KYC establishes the customer relationship. Travel Rule data accompanies or supports a particular transfer. A provider may already know its customer and still need beneficiary or counterparty-provider information.

Transaction monitoring then evaluates activity and risk. Keeping these processes separate helps the user answer the actual question.

Safe information submission

  1. Open the provider through the official app or bookmarked domain.
  2. Read the specific transfer request.
  3. Confirm the legal entity and support channel.
  4. Enter accurate names and account references.
  5. Upload documents only through the authenticated process.
  6. Keep a non-secret record of what was submitted and when.
  7. Ask for a case reference if manual review begins.

Do not send identity images through a community group, employer or unsolicited support chat. Do not share more data than the verified process requires.

What is never Travel Rule information?

  • seed phrase;
  • private key;
  • account password;
  • current OTP;
  • passkey approval for another person;
  • remote-control access;
  • payment to a “compliance wallet”;
  • a fabricated address or borrowed identity.

A scammer can use regulatory language. Verify the channel, not just the vocabulary.

Self-hosted wallets

A transfer between a VASP and a self-hosted wallet may require the provider to identify the counterparty, assess risk or verify wallet control under applicable rules and policy.

The wallet itself does not transmit a customer file like another VASP. Providers may use declarations, signing, small-transfer verification, blockchain analysis or other controls. Methods vary and can change.

Do not assume “self-custody means no questions.” Do not assume every provider rejects self-custody. Read the actual rule and supported process.

Interoperability and the sunrise problem

Providers and jurisdictions can implement the Travel Rule at different times and with different technical systems. A sending provider may support one data-exchange network while the beneficiary provider does not.

This mismatch can cause delay or route unavailability even when both providers are legitimate. FATF supervision work addresses implementation and interoperability challenges, but no global standard guarantees pairwise connectivity.

Privacy and security

Travel Rule compliance requires personal data to move securely between appropriate parties. That creates privacy and cybersecurity responsibility.

Customers should know who collects the information, purpose, retention and support route. Providers must apply applicable privacy and data-security rules. In the Philippines, NPC principles and rights remain relevant; applicability and lawful basis require review.

Do not publish Travel Rule data with a transaction hash. Blockchain addresses are public, and combining them with identity data can create avoidable exposure.

Scenario: Maria sends to Paolo

Maria uses a covered provider in Japan and Paolo uses a Philippine VASP. The sending form asks for Paolo’s legal name, receiving provider and account reference.

Maria confirms the request inside her provider. Paolo reads his receiving instructions and sends only the necessary non-secret details through their established private channel. They use exact names and do not guess.

If the providers cannot support the counterparty relationship, Maria does not route through a stranger or falsify the destination. She chooses another verified compliant option.

Why transfers pause

A Travel Rule-related transfer can pause because:

  • beneficiary name or account mismatches;
  • provider identity is missing;
  • required data is incomplete;
  • the receiving provider cannot accept the data;
  • self-hosted-wallet verification is incomplete;
  • sanctions or transaction alert requires review;
  • jurisdiction or asset route is unsupported.

Ask which information remains outstanding. Do not attempt evasion.

A form-completion routine

Enter information exactly as supported by official identity and beneficiary records. Confirm which field belongs to the sender, beneficiary, sending institution and receiving institution. Use the purpose category that truthfully describes the transfer.

Before submission, recheck spelling, country, account or wallet destination and required identifiers. A minor mismatch can create manual review. Do not invent data simply to satisfy a mandatory field; ask the provider what lawful evidence it accepts.

If a provider requests additional information, confirm the request inside the official app or support channel. Ask why it is needed, the secure submission method and what happens if it cannot be provided. Never transmit the information to a person who contacts you through an unverified social-media account.

Travel Rule and public blockchains solve different problems

A blockchain record can show addresses and asset movement. It does not reliably establish the legal name of the originator or beneficiary. Travel Rule data connects regulated entities and customers at the compliance layer; it is not normally written in full on a public blockchain.

This separation explains why a provider may have a valid transaction hash yet still pause a transfer for missing beneficiary information. Technical settlement and regulatory data exchange can proceed on different systems and clocks.

False positives and respectful review

Names can match sanctions or watchlist data by coincidence, transliteration or incomplete information. A provider may ask for date of birth, address or other evidence to distinguish the customer. Do not assume that every review means wrongdoing.

At the same time, providers should collect only through lawful, secure processes and explain consumer routes. Customers should document what was requested and when. If the request appears excessive or unsafe, pause and use the official complaint process rather than bypassing controls.

Editorial freshness rule

Travel Rule implementation is changing. Every publication must name the jurisdiction, distinguish FATF standards from enacted local rules, and show an as-of date. Japan’s 2026 amendments, for example, should not be generalized to all Asia or used to prove a particular corridor is available.

A reliable article explains the principle and then directs readers to current regulator and provider instructions for the actual transfer.

How this connects to market mastery

Professional settlement requires more than price and blockchain speed. Counterparty data, sanctions screening and message interoperability affect whether value can move. Travel Rule literacy is operational-market literacy.

Key takeaways and check

  • FATF sets standards; jurisdictions implement them differently.
  • Originator and beneficiary identity can be required in addition to wallet addresses.
  • KYC, Travel Rule and transaction monitoring have different jobs.
  • Use authenticated provider channels and data minimization.
  • No compliance process needs a seed phrase, password or unofficial payment.

Intermediate check: For a fictional VASP-to-VASP transfer, list non-secret sender/recipient data, the evidence source and three fields that must never be shared.

Next lesson:
What Is the Crypto Travel Rule?

Introduces originator and beneficiary information requirements and why providers exchange data.

*Cryptocurrency and virtual asset transactions are highly volatile and irreversible, may result in significant losses, and do not guarantee returns; customers should trade only after understanding the risks involved.

Share this lesson:

Practical Crypto and Cross-Border Money

75 Lessons

Top Up, Withdrawal, crypto/PHP, stablecoins, fees, FX, Travel Rule and remittance.

9
Crypto Travel Rule Explained for Senders and Recipients

Download DOPAY.ph Now!

Bringing Your Money Closer to Home.

Whether you’re in the Philippines or working abroad as OFW, DOPAY makes it easier to manage and transfer your funds.

With our low remittance fee, you can enjoy a digital wallet built for convenient and cost-efficient transactions.