NewsCryptoThailand's SEC Finalizes Crypto Travel Rule with February 2027 Compliance Deadline

Thailand's SEC Finalizes Crypto Travel Rule with February 2027 Compliance Deadline

Author: Cryptopolitan·

Key Takeaways

  • Thai digital asset operators must comply with the finalized Travel Rule by February 27, 2027 or lose their right to do business in the country.
  • Operators must implement four core duties: transfer-risk policies, identity data collection, passing originator and beneficiary details with transfers, and retaining transaction records for at least five years.
  • Records must be kept for the first two years after a transaction in a form regulators can access on demand.
  • Verifying that users own or control self-custodial wallet funds is expected to be the most challenging compliance hurdle.
  • The rules align Thailand with FATF Recommendation 16, which the FATF first extended to virtual assets in 2019 and which 83% of surveyed jurisdictions had legislated by 2026.
Thailand's SEC Finalizes Crypto Travel Rule with February 2027 Compliance Deadline

Thailand's Securities and Exchange Commission has set February 27, 2027 as the date by which digital asset operators must have the systems in place to comply with the finalized version of its crypto "Travel Rule," or they will lose their right to do business in the country.

The Travel Rule takes its name from the requirement that identifying information must "travel" with a funds transfer — a concept long applied in traditional banking to wire transfers. Under the deadline, set roughly six months away by the regulator, licensed exchanges and other digital asset businesses must be able to identify both the sender and the receiver in every crypto transfer, among other stipulations. The new compliance regime will require crypto transactions to carry identifying data, bringing them closer to traditional bank wire transfers.

Four core duties for digital asset operators

The Thai SEC's announcement specified four core duties for digital asset business operators:

  • Operators must write policies and procedures for handling transfer risk.
  • They must gather identity data on customers and their counterparties.
  • Firms must pass originator and beneficiary details to the receiving operator alongside the transfer order.
  • A new five-year minimum requirement applies to holding accompanying records on transactions.

Operators also face new due diligence responsibilities covering any intermediaries that handle funds during transfers, as well as the firms on the other end of transfers.

Per local outlets, the five-year data retention requirement includes a further detail: firms must keep records for the first two years after a transaction in a form that regulators can access on demand.

Self-custodial wallet compliance poses challenges

The Thai SEC's demand that firms verify users actually own or control the funds they transfer from self-custodial wallets is expected to be the most challenging hurdle. Self-hosted wallets, where a person holds their own private keys, do not carry all the KYC data that customers submit at registration before they can use wallets provided by crypto exchanges. Verifying control of such wallets has been a sticking point for Travel Rule implementation in other jurisdictions as well, since there is no counterparty operator to exchange customer data with on the unhosted side of a transfer.

Before the final text was published on September 2, the Thai SEC had held two rounds of public consultations this year, floating proposed principles in March and April, followed by a draft notification in June and July.

The work was carried out alongside the Anti-Money Laundering Office (AMLO) and a government subcommittee established to link financial data for spotting suspicious transactions. The pair issued interim rules while the AMLO prepares its own rules under the anti-money laundering law.

SEC Secretary-General Pornanong Budsaratragoon said the rules are meant to "reduce the risk of digital asset operators being used for money laundering and terrorist financing."

Alignment with FATF standards

The commission frames the initiative as bringing Thai oversight into line with the standards set by the Financial Action Task Force (FATF), whose Recommendation 16 originated the Travel Rule for crypto. The FATF, an intergovernmental body that sets anti-money-laundering and counter-terrorist-financing standards adopted by more than 200 jurisdictions, first extended Recommendation 16 to virtual assets in 2019. Thailand is late rather than early in adopting it: the FATF estimated that 83% of the jurisdictions it surveyed had already passed Travel Rule legislation by 2026.

For licensed operators, the practical effect is that compliance costs rise — building data-exchange pipelines with counterparties, upgrading record-keeping systems and running fresh due diligence — while non-compliance now carries an existential penalty: loss of the license to operate. For users, transfers to and from Thai platforms are set to look more like bank wires, with identity data attached to each transaction rather than held only at onboarding.

The move also comes amid a wider Thai regulatory push. In the same week, the SEC proposed letting intermediaries offer retail investors access to certain overseas crypto derivatives and advanced draft rules for spot Bitcoin and Ether exchange-traded funds. The sequencing suggests what to watch next: the AMLO's own rules under the anti-money laundering law, further detail on how the spot ETF drafts progress, and how operators move to build the cross-platform data-exchange arrangements the February 2027 deadline requires.

Neighboring South Korea is on a parallel timeline, with its own expanded Travel Rule set to take effect the same month, as Cryptopolitan reported.