Listen to Article — 6 min
Thailand’s Securities and Exchange Commission has unveiled a draft notification that would force digital asset operators to collect, verify, and retain records of every crypto transfer for at least five years, drawing on the global Travel Rule standard set by the Financial Action Task Force (FATF). The proposed framework aims to close anti-money laundering gaps in the crypto ecosystem by requiring operators to identify both senders and recipients, including transactions involving self-hosted wallets, and to maintain searchable data that supervisory authorities can inspect immediately for the first two years. What the Draft Travel Rule Mandates Under the SEC’s proposal, all licensed digital asset operators in Thailand must establish a comprehensive risk management system for digital asset transfers and receipts. The goal is to equip operators with enough information to identify transactions that may be linked to money laundering or technology-related crime. Key requirements include: Customer and counterparty information collection: Operators must gather identifying details about their own customers and the counterparties on the other side of a transaction. Service provider verification: Operators must examine the service providers used by the counterparty to ensure they are legitimate. Five-year record retention: All transaction records must be kept for at least five years. For the first two years, the data must remain in a format that allows supervisory authorities to retrieve or inspect it immediately. Self-hosted wallet transactions: When a customer sends or receives digital assets to/from a self-hosted wallet, the operator must verify that the customer owns or controls the wallet. Counterparty checks extend to all intermediaries: The checks apply to any digital asset operator or other service provider involved in the transfer. The SEC stated that the controls are intended to provide enough information to trace the financial route of a digital asset transaction, allowing suspicious activity to be examined, prevented, or intercepted. The Global Travel Rule Standard Driving the Proposal The Travel Rule is not a new concept. It was originally developed by the FATF for traditional financial transfers to combat money laundering and terrorist financing. In 2019, the FATF extended its Travel Rule standards to cover virtual assets and virtual asset service providers (VASPs). The framework requires covered crypto service providers to collect, share, and retain identifying information about senders and recipients. This includes: Name of the sender and recipient Account numbers or wallet addresses Transaction amount and timestamp Beneficiary information Thailand’s draft notification mirrors this international standard, assigning separate obligations depending on whether an operator is the sending institution, the receiving institution, or an intermediary. The SEC’s move aligns Thailand with FATF recommendations that many jurisdictions are now adopting, including the United States, the European Union, and Singapore. Timeline and Next Steps for the Thai Crypto Industry The SEC has opened the draft for public consultation. Market participants - including exchanges, custodians, and other VASPs - will have a limited window to submit feedback before the regulation is finalized. The timeline for implementation has not yet been announced, but the industry expects a phased rollout given the operational complexity of building data-sharing infrastructure. Operator Type Core Obligation Under Proposed Rule Data Retention Period Immediate Inspection Requirement Sending VASP Collect and transmit sender & recipient info to receiving VASP 5 years (first 2 years in immediately retrievable format) Yes, for first 2 years Receiving VASP Verify sender info and maintain records 5 years Yes, for first 2 years Intermediary VASP Pass through required data without modification 5 years N/A (must pass data intact) Self-hosted wallet handler Verify customer ownership/control of wallet 5 years Yes, for first 2 years Potential Impact on Thai Crypto Exchanges and Users The five-year retention mandate will impose significant operational costs on Thai crypto operators. They must build or upgrade compliance systems to capture, store, and retrieve identity and transaction data on demand. Smaller exchanges may struggle with the expense, potentially leading to market consolidation. For users, the rule means that every transaction - including those to self-hosted wallets - will be linked to verified identity information. Privacy advocates may raise concerns, but the SEC frames the measure as a necessary tool to combat illicit finance. The regulator explicitly stated that the data is intended to allow authorities to trace the financial route of a digital asset transaction and examine suspicious activity. Industry Reaction and Regulatory Context Thailand has been gradually tightening its crypto oversight. In 2022, the SEC banned the use of crypto as a means of payment for goods and services. The Travel Rule proposal is the latest step in a broader push to bring digital assets under the same anti-money laundering regime as traditional finance. The FATF’s 2019 extension of the Travel Rule to virtual assets has forced countries worldwide to update their laws. Jurisdictions that fail to implement the rule risk being placed on the FATF’s “grey list” of countries with deficient AML controls. Thailand’s draft notification signals that Bangkok intends to stay compliant and avoid such designation. What Is the Thailand SEC Travel Rule Proposal for Crypto? Thailand’s Securities and Exchange Commission has proposed a draft notification requiring digital asset operators to collect, verify, and retain identifying information for all crypto transfers for at least five years, mirroring the FATF’s Travel Rule standard for virtual assets. How Long Will Crypto Transfer Records Be Kept Under the New Rule? Operators must retain records for a minimum of five years. For the first two years, the data must be stored in a format that allows supervisory authorities to retrieve or inspect it immediately. Does the Rule Apply to Self-hosted Crypto Wallets? Yes. When a customer sends or receives digital assets to or from a self-hosted wallet, the licensed operator must verify that the customer owns or controls the wallet and must keep records of the transaction. What Information Must Thai Crypto Exchanges Collect Under the Travel Rule? Exchanges must collect sender and recipient names, wallet addresses or account numbers, transaction amounts, and timestamps. They must also verify the service providers used by the counterparty. When Will the Thailand SEC Travel Rule Take Effect? The draft is currently open for public consultation. The implementation timeline has not been announced, but industry observers expect a phased rollout once the regulation is finalized.
Follow Our News on Google
Be instantly informed of developments.
Thailand’s Securities and Exchange Commission has unveiled a draft notification that would force digital asset operators to collect, verify, and retain records of every crypto transfer for at least five years, drawing on the global Travel Rule standard set by the Financial Action Task Force (FATF). The proposed framework aims to close anti-money laundering gaps in the crypto ecosystem by requiring operators to identify both senders and recipients, including transactions involving self-hosted wallets, and to maintain searchable data that supervisory authorities can inspect immediately for the first two years.
What the Draft Travel Rule Mandates
Under the SEC’s proposal, all licensed digital asset operators in Thailand must establish a comprehensive risk management system for digital asset transfers and receipts. The goal is to equip operators with enough information to identify transactions that may be linked to money laundering or technology-related crime.
Key requirements include:
- Customer and counterparty information collection: Operators must gather identifying details about their own customers and the counterparties on the other side of a transaction.
- Service provider verification: Operators must examine the service providers used by the counterparty to ensure they are legitimate.
- Five-year record retention: All transaction records must be kept for at least five years. For the first two years, the data must remain in a format that allows supervisory authorities to retrieve or inspect it immediately.
- Self-hosted wallet transactions: When a customer sends or receives digital assets to/from a self-hosted wallet, the operator must verify that the customer owns or controls the wallet.
- Counterparty checks extend to all intermediaries: The checks apply to any digital asset operator or other service provider involved in the transfer.
The SEC stated that the controls are intended to provide enough information to trace the financial route of a digital asset transaction, allowing suspicious activity to be examined, prevented, or intercepted.
The Global Travel Rule Standard Driving the Proposal
The Travel Rule is not a new concept. It was originally developed by the FATF for traditional financial transfers to combat money laundering and terrorist financing. In 2019, the FATF extended its Travel Rule standards to cover virtual assets and virtual asset service providers (VASPs).
The framework requires covered crypto service providers to collect, share, and retain identifying information about senders and recipients. This includes:
- Name of the sender and recipient
- Account numbers or wallet addresses
- Transaction amount and timestamp
- Beneficiary information
Thailand’s draft notification mirrors this international standard, assigning separate obligations depending on whether an operator is the sending institution, the receiving institution, or an intermediary. The SEC’s move aligns Thailand with FATF recommendations that many jurisdictions are now adopting, including the United States, the European Union, and Singapore.
Timeline and Next Steps for the Thai Crypto Industry
The SEC has opened the draft for public consultation. Market participants – including exchanges, custodians, and other VASPs – will have a limited window to submit feedback before the regulation is finalized. The timeline for implementation has not yet been announced, but the industry expects a phased rollout given the operational complexity of building data-sharing infrastructure.
| Operator Type |
Core Obligation Under Proposed Rule |
Data Retention Period |
Immediate Inspection Requirement |
| Sending VASP |
Collect and transmit sender & recipient info to receiving VASP |
5 years (first 2 years in immediately retrievable format) |
Yes, for first 2 years |
| Receiving VASP |
Verify sender info and maintain records |
5 years |
Yes, for first 2 years |
| Intermediary VASP |
Pass through required data without modification |
5 years |
N/A (must pass data intact) |
| Self-hosted wallet handler |
Verify customer ownership/control of wallet |
5 years |
Yes, for first 2 years |
Potential Impact on Thai Crypto Exchanges and Users
The five-year retention mandate will impose significant operational costs on Thai crypto operators. They must build or upgrade compliance systems to capture, store, and retrieve identity and transaction data on demand. Smaller exchanges may struggle with the expense, potentially leading to market consolidation.
For users, the rule means that every transaction – including those to self-hosted wallets – will be linked to verified identity information. Privacy advocates may raise concerns, but the SEC frames the measure as a necessary tool to combat illicit finance. The regulator explicitly stated that the data is intended to allow authorities to trace the financial route of a digital asset transaction and examine suspicious activity.
Industry Reaction and Regulatory Context
Thailand has been gradually tightening its crypto oversight. In 2022, the SEC banned the use of crypto as a means of payment for goods and services. The Travel Rule proposal is the latest step in a broader push to bring digital assets under the same anti-money laundering regime as traditional finance.
The FATF’s 2019 extension of the Travel Rule to virtual assets has forced countries worldwide to update their laws. Jurisdictions that fail to implement the rule risk being placed on the FATF’s “grey list” of countries with deficient AML controls. Thailand’s draft notification signals that Bangkok intends to stay compliant and avoid such designation.
What Is the Thailand SEC Travel Rule Proposal for Crypto?
Thailand’s Securities and Exchange Commission has proposed a draft notification requiring digital asset operators to collect, verify, and retain identifying information for all crypto transfers for at least five years, mirroring the FATF’s Travel Rule standard for virtual assets.
How Long Will Crypto Transfer Records Be Kept Under the New Rule?
Operators must retain records for a minimum of five years. For the first two years, the data must be stored in a format that allows supervisory authorities to retrieve or inspect it immediately.
Does the Rule Apply to Self-hosted Crypto Wallets?
Yes. When a customer sends or receives digital assets to or from a self-hosted wallet, the licensed operator must verify that the customer owns or controls the wallet and must keep records of the transaction.
What Information Must Thai Crypto Exchanges Collect Under the Travel Rule?
Exchanges must collect sender and recipient names, wallet addresses or account numbers, transaction amounts, and timestamps. They must also verify the service providers used by the counterparty.
When Will the Thailand SEC Travel Rule Take Effect?
The draft is currently open for public consultation. The implementation timeline has not been announced, but industry observers expect a phased rollout once the regulation is finalized.
This article is provided for informational and educational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice. The digital asset market is highly volatile, speculative, and subject to rapid regulatory changes. While we strive to ensure the accuracy of the information presented, market conditions change quickly, and data may become outdated. You are solely responsible for your own research (DYOR) and financial decisions. ATHPost, its owners, and its authors assume no liability whatsoever for any direct or indirect financial losses, liquidations, or damages arising from the use of this content.