Thailand SEC introduces crypto travel rule for P2P, self-hosted wallets

Thailand’s Securities and Exchange Commission has introduced a stricter set of crypto rules that will affect peer-to-peer transfers and self-hosted wallets. The plan is not immediate, but the direction is clear. Exchanges operating in Thailand will soon need to know more about the people behind every transaction.

The new policy, known as the Travel Rule for Digital Assets, was published on September 2. It will take effect on February 27, 2027. Thailand’s SEC says the goal is to make sure digital asset business operators have enough information to assess money laundering risks and meet international standards.

What the Thai SEC wants

Licensed crypto platforms will have to identify customers and their counterparties. That includes cases where someone owns a self-hosted wallet, sometimes called a self-custody wallet. Platforms must also submit information about the sender and the beneficiary for each crypto transfer. This data needs to be stored for at least five years, so authorities can access it when needed.

The regulator thinks the rest of 2026 gives companies enough time to prepare. I suspect the actual rollout will be messy. Verifying who controls a self-hosted wallet is not simple, and there is still no clear technical standard for it.

Why this is not a surprise

Thailand is following a path that many other countries have already taken. The Financial Action Task Force, or FATF, sets global guidelines for anti-money laundering and terrorism financing. Countries that do not meet those guidelines risk being put on a greylist, which can hurt their financial reputation.

Crypto still represents a small part of global illegal money flows. But the anonymous feel of crypto, especially with peer-to-peer transfers and self-custody wallets, keeps it in the regulator’s crosshairs. Since it is hard to track transactions that never touch a bank or exchange, the easiest point for enforcement is the cashout stage. That is when a user converts crypto into regular money through a licensed service.

Thailand’s rules, like similar ones elsewhere, treat those cashout points as a control gate. It is a practical approach, but it creates a real privacy problem. If every exchange must collect and hold personal data for five years, that is a lot of sensitive information in one place.

What happens next

Other regions are moving in the same direction. The European Union expects to have similar crypto AML rules around mid-2027. South Africa has already activated stricter exchange capital controls linked to crypto funds. This is becoming a coordinated global effort, not just a local policy shift.

The punishment for not complying with FATF standards can be harsh. Entire countries or regions can be restricted from international financial channels. That pressure probably explains why so many regulators are adopting similar rules, even when their domestic crypto industry is still small.

The next few years will show how these rules work in practice. Thailand has given operators time to adjust, but the difficult questions remain. How do you track self-hosted wallets without breaking privacy expectations? Can exchanges really collect accurate data on counterparties? These issues may not have satisfying answers before 2027.

I think the industry needs to watch this closely. The rules are not just about Thailand. They are part of a broader shift that is likely to define how crypto platforms handle personal data in the future.