Travel Rule

Collect travel rule information from your end customer

Overview

The EU Transfer of Funds Regulation (TFR) applies under MiCA, and it requires crypto-asset service providers (CASPs) such as zerohash to collect, verify and transmit originator and beneficiary information on every crypto transfer, regardless of amount.

zerohash checks every EU transfer against multiple Travel Rule networks (Notabene and TRUST) plus an internal allow list for self-custody wallets. Where the counterparty CASP participates in one of those networks, the information is exchanged automatically and neither your Platform nor the end customer has to do anything. Where it is not available, zerohash needs the missing information from the end customer, and this guide covers the API path for supplying it.


Verified deposits clear automatically. Unverified deposits are held pending verification, and your Platform is notified so it can either collect the missing information itself or hand the customer to a zerohash-hosted flow. Withdrawals transmit the required data before initiation, so the receiving wallet's information must be on file before the withdrawal call is made.

Requirements

What has to be collected varies by wallet type, by who owns the wallet, and by the amount moved in the last 12 hours. The two tables below are the reference for what is required.

Deposits: Sending Wallet

RequirementExchange walletSelf-custody wallet
What is the wallet type?
Determines whether the sending wallet is hosted by an exchange or self-custodied by the sender.
Name of the exchange, submitted as its casp_did.Deposit source address.
Who owns the sending wallet?Confirms whose identity information is required to release a deposit sent from a self-custody wallet. Not required when the sending wallet is hosted by an exchange.Not required.

If the end user owns the wallet, confirm their KYC or KYB data. If someone else owns it, collect that person or entity's data.

Individuals: full name, legal address, date of birth, place of birth.

Businesses: business name, business legal address, LEI.

Proof of ownership
Verifies control before releasing funds.
Not required.Required only when more than €1,000 has been received from the wallet in the last 12 hours. The end user uploads a screenshot of the source wallet showing the address in the image.

Withdrawals: Receiving Wallet

Withdrawals need less identity information than deposits: a full name for individuals, or a business name and LEI for businesses. Deposits from self-custody wallets additionally need a legal address, date of birth and place of birth.

RequirementExchange walletSelf-custody wallet

What is the wallet type?

Determines whether the receiving wallet is hosted by an exchange or self-custodied by the recipient.

Name of the exchange, submitted as its casp_did.Receiving wallet address.

Who owns the receiving wallet?

Confirms whose identity information is required to initiate a withdrawal. Required for both self-custody and exchange wallets.

Individuals: full name.


Businesses: business name, LEI.

Individuals: full name.


Businesses: business name, LEI.

Proof of ownership

Verifies control before sending funds.

Not required.Required only when more than €1,000 has been sent to the wallet in the last 12 hours. The end user uploads a screenshot of the receiving wallet showing the address in the image.

Withdrawals need less identity information than deposits: a full name for individuals, or a business name and LEI for businesses. Deposits from self-custody wallets additionally need a legal address, date of birth and place of birth.


Two options for collecting sending or receiving wallet information:


Did this page help you?