Thailand Finalizes Digital-Asset Travel Rule: Expanded Information and Self-Hosted Wallet Control Checks for Transfers of 30,000 Baht or More, Effective February 2027

The Office of the Securities and Exchange Commission, Thailand (SEC), issued a press release on September 2 local time announcing the final Digital Asset Travel Rule requirements set out in Notification No. Sor Thor. 9/2026, dated August 25. The Travel Rule requires digital asset business operators to verify originator and beneficiary information and to transmit that information with transfer orders sent to other operators. Licensed operators in Thailand must establish policies and operating procedures to manage risks arising from transfers and receipts and complete the required checks before sending a transfer order. The information required varies at the 30,000-baht threshold. For transfers below 30,000 baht, operators must obtain the names of the originator and beneficiary, account numbers where needed for processing, and, for onchain transfers, wallet addresses or reference numbers that allow the transaction to be traced. For transfers of 30,000 baht or more, the required information additionally includes the originator's address and, if the originator is an individual, date of birth; the beneficiary's country and state, province or city; and a government-issued personal identification number, corporate registration number or Legal Entity Identifier (LEI), as appropriate to the type of party. Operators must use analytics tools to determine whether the counterparty wallet is managed by another business or is a self-hosted wallet controlled directly by the user. If the counterparty wallet is managed by a business, the operator must verify that its manager qualifies as a service provider recognized under the notification. A foreign provider must not be based in a jurisdiction on the Financial Action Task Force's list of High-Risk Jurisdictions subject to a Call for Action and must operate lawfully where it is based. Regardless of where the wallet manager is located, operators must also use analytics tools to check that it does not provide services designed to conceal, alter or evade the tracing of transfer paths. For transfers of 30,000 baht or more involving a self-hosted wallet, the operator must verify that the beneficiary owns or controls the wallet when sending assets and that the originator owns or controls it when receiving assets. An outgoing transfer order cannot be released until the check is complete. If the check cannot be completed for an incoming transfer, the operator may not allow the user to access or use the received assets. Operators must establish risk-appropriate procedures for assets restricted in this way. When assets are sent to a wallet managed by another operator, originator and beneficiary information must be transmitted to that operator before or together with the transfer order. This transmission requirement does not apply when assets are sent to a self-hosted wallet because there is no receiving operator to accept the information, but the Thai operator must still collect the transaction information and, for transfers of 30,000 baht or more, verify the beneficiary's ownership or control of the wallet. Information accompanying transactions must be retained for at least five years in a form that the regulator can retrieve and examine immediately. The SEC said it coordinated with the Anti-Money Laundering Office (AMLO) in establishing the requirements and described them as an interim framework that will apply while AMLO prepares related regulations under the Anti-Money Laundering Act. The rules underwent two consultation rounds, in March-April and June-July, and will take effect on February 27, 2027. They apply directly to digital asset business operators supervised by the Thai SEC and do not prohibit possession of self-hosted wallets or wallet-to-wallet transfers that do not pass through an operator.

Metanomia View

The significance of these rules lies in requiring licensed Thai operators to classify counterparty wallets and, for transfers at or above a set threshold, determine who actually controls a self-hosted wallet. Because operators must also assess the eligibility of businesses managing counterparty wallets and the risk of trace-evasion services, a single determination by an operator can decide whether a transfer proceeds and whether received assets can be used. Korean operators connecting with Thai businesses should decide in advance what information to exchange based on the 30,000-baht threshold and how users can challenge verification errors and have restrictions on their assets lifted.

Sources