The crypto travel rule in India, the UAE, the EU and the US
The crypto travel rule sets four different thresholds across India, the UAE, the EU and the US. India has none: FIU-IND requires full originator and beneficiary data on every VDA transfer between reporting entities, before or with the transfer, never after. Dubai’s VARA starts at an equivalent value exceeding AED 3,500. The EU has no de minimis for the data itself; EUR 1,000 triggers only the self-hosted ownership check. The US codified rule is USD 3,000, and FinCEN’s December 2020 unhosted-wallet proposal is still a proposal.
Four regimes at a glance
| Regime | Legal basis and threshold | Required fields | Self-hosted wallet treatment | Counterparty due diligence | Penalty basis |
|---|---|---|---|---|---|
| India (FIU-IND) | PML Rules 2005, Rule 4; FIU-IND guidelines of 8 January 2026, para 5.3. No threshold; data before or with the transfer, never after | Originator: PAN, identity document number, name, wallet address, verified address, date of birth; PAN mandatory at onboarding (para 4.1.4(c)) | Hosting reporting entity carries the onus: collect data, enhanced CDD, limits or prohibitions (para 7.2); no mixers (paras 7.4 to 7.5) | Not separately paragraphed in the guidance we cite; transfers run between registered reporting entities and the travel-rule stack is demonstrated live at FIU-IND registration | PMLA section 13: Rs 10,000 to Rs 1,00,000 per failure, each day of delay a separate violation (rule 8(4)); Binance fined Rs 18.82 crore, June 2024 |
| UAE (VARA, Dubai) | CRM Rulebook Part III.G, a floor under Federal AML-CFT Laws. Exceeding AED 3,500 equivalent: originator VASP before initiating (III.G.2), beneficiary VASP before releasing (III.G.3) | Originator: name, account number or wallet address, residential or business address (III.G.4). Beneficiary: name, account number or wallet address (III.G.5) | Unhosted wallets are “non-obliged entities” whose risk the VASP decides how to handle (III.G.7); no prescribed threshold, limit or ban | Before the first transaction with each counterparty VASP (III.G.6); sunrise plan at licensing (III.G.8); structuring monitoring (III.G.9) | Part III.J: action against the VASP, directors, Responsible Individuals, MLRO and senior management; no amounts stated |
| EU (TFR) | Regulation (EU) 2023/1113, applicable from 30 December 2024. No de minimis for CASP-to-CASP transfers (Article 14). EUR 1,000 triggers only the self-hosted ownership assessment (Articles 14(5), 16(2)) | Originator: name, DLT address and account number, address with country, official document number and customer ID or date and place of birth, LEI (14(1)). Beneficiary: name, DLT address, account number, LEI (14(2)) | Information held on every self-hosted transfer; above EUR 1,000, ownership or control assessed by the EBA/GL/2024/11 methods | Reject, return or request missing data before release (Article 17); missing data a suspicion factor (Article 18); intermediaries pass data on (Articles 19 to 21) | Article 28: Member States set the sanctions; no amounts in the Regulation. Records kept five years (Article 26) |
| US (FinCEN) | 31 CFR 1010.410(e) and (f): transmittals of USD 3,000 or more. Hosted wallet providers are money transmitters under FIN-2019-G001. The USD 250 cross-border figure (October 2020) is only a proposal | Transmittor name, account number if any, address; amount; execution date; recipient institution; recipient details as received (1010.410(f)) | No codified provision. The December 2020 proposal (records and verification at USD 3,000, reports at USD 10,000) never entered the CFR | Intermediaries relay transmittor information; the recipient’s institution retains the transmittal order | Civil penalty provisions not stated here; the duties enforced are the Bank Secrecy Act duties FinCEN lists for money services businesses, including transmittal records and retention (1010.430) |
Law stated as at 25 September 2026 from the primary texts linked in each row. FATF’s Interpretive Note to Recommendation 15, para 7(b), is the standard behind the India, UAE and EU rules and states no de minimis for virtual asset transfers; its USD/EUR 1,000 is the occasional-transaction CDD threshold (para 7(a)), not a transfer threshold.
Thresholds and data fields: where each regime starts
India is the strictest. Under Rule 4 of the PML Rules 2005, applied through FIU-IND’s guidelines of 8 January 2026, originator and beneficiary information is submitted before or when a VDA transfer between reporting entities is conducted; para 5.3 states no threshold and permits no post-facto submission. As reported on 9 September 2026, FIU-IND issued PMLA section 13 notices to offshore VDA providers operating in India without complying. Who must register with FIU-IND is covered separately.
VARA writes a figure into the rule: an equivalent value exceeding AED 3,500, on the originating VASP before initiating (Rule III.G.2) and on the beneficiary VASP before releasing (Rule III.G.3). Part III.G is a floor that Federal AML-CFT Laws may supplement (Rule III.G.1), and Rule III.G.9 requires monitoring for transfers structured to circumvent it: a client splitting transfers is itself a monitoring event.
The EU is where the misreading happens. Under Regulation (EU) 2023/1113 a transfer is inside the regime where at least one CASP acts for the originator or the beneficiary (Article 3(10)), and Article 14 requires the full data set on every such transfer with no de minimis; the review clause that asks whether one should be introduced confirms none exists. EUR 1,000 appears only in Articles 14(5) and 16(2) and triggers the self-hosted ownership or control assessment. A programme that starts collecting data at EUR 1,000 is non-compliant on every smaller transfer.
31 CFR 1010.410(e) and (f) apply to transmittals of USD 3,000 or more, and FIN-2019-G001 treats a hosted wallet provider as a money transmitter bound by them. FinCEN’s October 2020 proposal to cut the cross-border threshold to USD 250 and its December 2020 unhosted-wallet proposal are absent from the codified text as at 25 September 2026; nothing enacted since, including the CLARITY Act (Senate cloture failed 49-50 on 15 September 2026), has changed that, so the US row stays proposal-not-rule.
The field sets differ, so a corridor group builds to the widest and maps down: India’s originator set (PAN, identity document number, name, wallet address, verified address, date of birth) is the broadest on identity, the EU’s Article 14(1) set adds an official document number or date and place of birth, and VARA’s floor is three originator and two beneficiary fields. On timing the regimes converge: India before or with the transfer, never after; the EU in advance of or concurrently with it, not necessarily on-chain (Article 14(4)), with no transfer executed before full compliance (Article 14(8)) and missing data rejected, returned or requested before release (Article 17); VARA’s “prior to” wording produces the same result.
Self-hosted wallets: the duty in each regime
This page owns the self-hosted duty: the self-custody compliance controls checklist keeps one control row that points here, and whether a wallet product is inside custody licensing is answered separately. FATF’s 2021 guidance (paras 203 and 204) sets the baseline: with one obliged entity on the transfer, that VASP takes the originator and beneficiary information from its own customer and need not transmit it to the unhosted-wallet user.
India puts the onus on the reporting entity hosting the wallet: collect the data, apply enhanced CDD, impose limits or prohibitions where warranted (para 7.2). Mixers and tumblers may not be facilitated (paras 7.4 to 7.5), and STRs are filed irrespective of amount (paras 5.5 to 5.7). There is no self-hosted threshold because there is no threshold anywhere in the rule.
The UAE makes it a governance decision. Rule III.G.7 requires the VASP to decide how it handles deposits and withdrawals whether travel-rule compliant or not, non-obliged entities, meaning unhosted VA wallets, and anonymity-enhanced transactions. No threshold, limit or ban is prescribed; the documented answer is shown at licensing with the sunrise plan (Rule III.G.8).
The EU is the only regime with a figure in the self-hosted duty. A self-hosted address is one not linked to a CASP or an equivalent non-EU firm (Article 3(20)). On every transfer to or from one, the CASP obtains and holds the Article 14 information; above EUR 1,000 it assesses whether the address is owned or controlled by its own customer (Articles 14(5) and 16(2)), with enhanced due diligence where that information proves inaccurate (recital 45). EBA/GL/2024/11 supplies the method: detect self-hosting through blockchain analytics, third-party data and messaging identifiers, otherwise ask the customer (paras 77 to 79); value it at the exchange rate at transfer time, ignoring fees (paras 81 and 82); prove ownership by remote verification displaying the address, a small test amount sent from and to it, or a message signed with the address key (paras 83 to 85); whitelist a verified address while monitoring for change (para 86); apply at least one AMLD Article 19a(1) mitigating measure (paras 87 and 88).
The US has no codified unhosted-wallet rule. The December 2020 proposal (records and identity verification at USD 3,000, reports at USD 10,000) closed for comment on 4 January 2021 and never entered the CFR, so a US money transmitter applies the Funds Travel Rule to hosted-to-hosted transmittals and its AML programme to the rest.
What breaks between them: an Indian reporting entity with a Dubai VASP
The corridor pattern is an FIU-IND-registered Indian exchange with a VARA-licensed sister company in Dubai, with flows between them, to third-party VASPs and to self-hosted wallets. Each entity answers to its own regime; the group needs one standard that satisfies both:
- Map every flow by its legal pair. India RE to Dubai VASP and back, either entity to a third-country VASP or a self-hosted address. Each pair has its own threshold, field set and timing rule; the intra-group pair is not exempt.
- Build to the widest field set. The India originator set plus the VARA floor covers every India-to-Dubai transfer; add the Article 14 set where an EU CASP is in the flow. Collect once at onboarding.
- Run the India threshold on both sides. The Indian entity sends the full record on every transfer; the Dubai entity must hold it before releasing anything above AED 3,500 equivalent. The India standard group-wide removes the gap and answers Rule III.G.9 on structuring.
- Complete counterparty due diligence before the first transaction (Rule III.G.6); treat the Indian sister company as a counterparty VASP for this purpose. Document the sunrise plan (Rule III.G.8).
- Write the self-hosted policy per entity. India: para 7.2 onus, enhanced CDD, limits, no mixers. Dubai: a documented Rule III.G.7 decision. Where an EU CASP sits in the group, the EUR 1,000 test with the EBA para 83 methods.
- Settle missing-data handling and retention. Reject, return or hold on a written risk basis, feeding the STR assessment on both sides. Retain to the longest period: India at least five years for records generally; VARA screening records at least eight years (Rules III.F and III.H); EU five years (Article 26); US under 31 CFR 1010.430. The same file serves VARA at licensing (Rule III.G.8) and the live demonstration at FIU-IND registration.
On an engagement of this shape, Infinilex counsel qualified in India and the UAE sign the policy and procedure work for those legs; where an EU CASP sits in the group, Infinilex scopes the work, builds the fact record and briefs the EU local counsel who sign, named to the client before they act. The crypto AML programme service describes the programme that carries the travel rule; crypto licence requirements by country and MiCA vs VARA cover the licensing questions that come first.
Frequently asked questions
What is the crypto travel rule threshold in India under FIU-IND?
There is none. FIU-IND's AML and CFT guidelines for VDA reporting entities, updated on 8 January 2026, require originator and beneficiary information to be submitted before or when a transfer between reporting entities is conducted, with no monetary threshold and no post-facto submission (para 5.3). The originator set includes PAN, identity document number, name, wallet address, verified address and date of birth.
What are VARA's travel rule requirements in Dubai?
Part III.G of VARA's Compliance and Risk Management Rulebook sets the floor. Before initiating any virtual asset transfer with an equivalent value exceeding AED 3,500, the originating VASP must obtain and hold required and accurate originator information and required beneficiary information (Rule III.G.2); the beneficiary VASP must hold the same data before releasing assets received above that figure (Rule III.G.3). Counterparty due diligence precedes the first transaction with any VASP (Rule III.G.6).
Does the EU crypto travel rule have a threshold?
Not for the information duty. Under Regulation (EU) 2023/1113, applicable since 30 December 2024, Article 14 requires the full originator and beneficiary data set on every transfer where a CASP acts for at least one side, with no de minimis amount. The EUR 1,000 figure is a different test: it triggers only the duty to assess whether a self-hosted address is owned or controlled by the CASP's own customer (Articles 14(5) and 16(2)).
What does the travel rule require for self-hosted wallets?
Each regime answers differently; only the EU writes a figure into the rule. In India the reporting entity hosting the wallet carries the onus: collect the data, apply enhanced CDD, impose limits or prohibitions (para 7.2). VARA treats unhosted wallets as non-obliged entities to be risk-handled by the VASP (Rule III.G.7). The EU requires information on every self-hosted transfer and, above EUR 1,000, an ownership or control assessment. The US has no codified unhosted-wallet rule.
Which threshold governs an India-to-Dubai crypto transfer?
Both, each on its own entity, and the stricter one sets the group standard. The Indian reporting entity must submit the full originator and beneficiary record before or with every transfer regardless of amount. The Dubai VASP must hold that data before releasing anything above AED 3,500 equivalent (Rule III.G.3) and may set its own policy below. In practice the group runs the India standard: full data, every transfer, never after.
Running transfers across two travel-rule regimes?
Tell us which entities you hold, where your counterparties sit and how much self-hosted flow you carry. We will map the duty on each leg and the single standard that satisfies all of them.
Further reading
FIU-IND registration in India · Self-custody compliance controls checklist · Self-custody meets institutional control · MiCA vs VARA · Crypto licence requirements by country · Crypto AML programme · MPC and smart-contract wallets: which key arrangements are custody?
General information, not legal advice on your transfers or programme. Law stated as at 25 September 2026 from the primary texts linked above; FIU-IND paragraphs are those cited on our live pages; the US position is re-checked every thirty days and the page re-verified quarterly. Have your own flows reviewed before relying on it.