Thailand’s Securities and Exchange Commission has finalized its version of the crypto Travel Rule, requiring every digital asset business operator in the country to collect, transmit, and verify detailed information about both senders and receivers of crypto transfers. The rules take effect on February 27, 2027, giving the industry roughly 18 months to get its compliance infrastructure in order.
The regulation also imposes a five-year data retention mandate on all transaction records. For the first two years, that data must be immediately accessible to regulators on demand.
What the Travel Rule actually requires
Under Thailand’s new framework, VASPs must collect originator and beneficiary details for every digital asset transfer. That means names, account numbers, and other identifying data travel alongside the crypto itself.
The more contentious piece involves self-hosted wallets, the kind where users hold their own private keys rather than relying on an exchange. Operators will need to verify that the person initiating or receiving a transfer actually owns or controls the self-custodial wallet in question.
The regulations were developed in partnership with Thailand’s Anti-Money Laundering Office (AMLO), following public consultations held in March and April 2026. A draft notification was released in June 2026 before the final rules were issued on September 1, 2026.
Following the global compliance playbook
The Financial Action Task Force, the intergovernmental body that sets global anti-money laundering standards, first recommended the Travel Rule for crypto through its Recommendation 16. As of early 2026, approximately 83% of jurisdictions surveyed by FATF have enacted some form of Travel Rule legislation.
The Bank of Thailand has also been conducting separate assessments of stablecoin transactions, with particular attention to USDT.
What this means for the Thai crypto market
Some operators are already moving. Bitazza, a Thai digital asset platform, has been integrating compliance tools from providers like Sumsub to prepare for the new regulatory environment.
The five-year retention requirement also raises data security questions. Requiring VASPs to store detailed personal and financial information for half a decade creates a concentrated target for hackers. The regulation addresses what data must be kept, but the security standards around how it’s protected will be just as important in determining whether the framework strengthens or inadvertently undermines user trust.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

2 hours ago
18








English (US) ·