Crypto-Asset Service Providers, Records of Communication with Clients
In force since .
An interception and recording consent rule binding private bodies.
- Obligation class
- Governance, Retention
As of .
What it requires
- Delegated Regulation (EU) 2025/1140 is binding in its entirety and directly applicable in all Member States and entered into force on the twentieth day after its publication on (Article 18); it specifies the records that Article 68(9) of Regulation (EU) 2023/1114 requires crypto-asset service providers to keep (Article 68(10) of that Regulation).
- It reaches you if you are a crypto-asset service provider, meaning a legal person or other undertaking whose occupation or business is the provision of one or more crypto-asset services to clients on a professional basis and that is allowed to provide crypto-asset services in accordance with Article 59 of Regulation (EU) 2023/1114 (Article 3(1), point (15), of that Regulation): keep records of telephone conversations or electronic communications relating to transactions or to the reception, transmission and execution of client orders, including where such conversations or communications do not result in the conclusion of a transaction or in the provision of the services of reception and transmission of orders or execution of order (Article 2(2) and Annex, Section 1, communication with clients).
- Retain the records in a medium that lets the competent authority access them readily and reconstitute each key stage of the processing of each crypto-asset service, activity, order or transaction, lets any corrections or other amendments and the earlier contents be ascertained, and does not allow the records to be manipulated or altered (Article 2(1)).
- Provide the records to clients upon request and keep them for five years and, where the competent authority requests before five years have elapsed, for up to seven years (Article 68(9) of Regulation (EU) 2023/1114).
Who enforces it
Enforcement body
The competent authority each Member State designates under Article 93(1) of Regulation (EU) 2023/1114, for which Article 111(1) provides administrative penalties and other administrative measures for infringements of Articles 65 to 83.
What this law does
Article 68(9) of Regulation (EU) 2023/1114 requires crypto-asset service providers to arrange for records to be kept of all crypto-asset services, activities, orders, and transactions undertaken by them. The records are provided to clients upon request and are kept for five years and, where requested by the competent authority before five years have elapsed, for up to seven years.
Article 68(10) of that Regulation provides for regulatory technical standards that further specify the records to be kept of all crypto-asset services, activities, orders and transactions undertaken.
Article 3(1), point (15), of that Regulation defines a crypto-asset service provider as a legal person or other undertaking whose occupation or business is the provision of one or more crypto-asset services to clients on a professional basis, and that is allowed to provide crypto-asset services in accordance with Article 59.
Article 2(2) of Commission Delegated Regulation (EU) 2025/1140 requires crypto-asset service providers to keep the records listed in Section 1 of its Annex, depending upon the nature of their services and activities.
The Annex lists, under communication with clients, records of telephone conversations or electronic communications relating to transactions or to the reception, transmission and execution of client orders, including where such conversations or communications do not result in the conclusion of a transaction or in the provision of the services of reception and transmission of orders or execution of order.
Article 2(1) requires the records to be retained in a medium that lets the competent authority access them readily, ascertain any corrections and the contents before them, and that does not allow the records to be manipulated or altered.
Article 111(1) of Regulation (EU) 2023/1114 requires Member States to provide for competent authorities to have the power to take administrative penalties and other administrative measures for infringements of Articles 65 to 83, which include Article 68, and lets Member States decline to lay down administrative penalties for infringements already subject to criminal penalties in their national law by . Regulation (EU) 2023/1114 applies from .
Article 18 of the Delegated Regulation provides that it enters into force on the twentieth day following that of its publication in the Official Journal of the European Union.
When LexLint raises it
When your app profile says your app records conversations, processes voice recordings or provides financial services.