Anonymity-enhancing assets or unattributed transfers are barred outright, or barred for regulated firms.
What EU Transfer of Funds Regulation actually says
This, not the privacy-coin headline, is what actually ends unattributed transfers at the EU perimeter. The recast travel rule attaches originator and beneficiary name, address and account identifier to every crypto transfer between providers, with no de minimis threshold at all, where the fiat regime it recasts has one. Above EUR 1,000 to or from a self-hosted address, the provider must take adequate measures to establish that its own customer owns or controls that address. Self-hosted wallets are not banned and peer-to-peer transfers between two of them sit outside the regulation entirely. Applicable since 30 December 2024, operationalised by EBA guidelines that specify the data fields, it is the reason EU exchanges now ask who owns the withdrawal address.
The instruments that matter
- No de minimis threshold
- originator and beneficiary data travel with every CASP-to-CASP transfer regardless of amount
- Articles 14(5) and 16(2)
- transfers above EUR 1,000 to or from a self-hosted address require the CASP to verify its own customer controls that address
- EBA/GL/2024/11
- travel rule guidelines specifying the data fields and the missing-information procedures, applicable 30 December 2024
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- FATFGlobal · The source of almost every travel rule on earth
- NorwayEurope · MiCA via the EEA, with a privacy-innovation sandbox
- The travel rule binds institutions, not ledgersGlobal · The rule everyone assumes ends on-chain confidentiality
- EU AMLR Article 79Europe · Anti-money laundering · Regulation (EU) 2024/1624
- FinCENAmericas · Bank Secrecy Act · the deepest US constraint
- CJEU on identifiabilityEurope · Case law · is a wallet address personal data
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.