Commission Delegated Regulation (EU) 2025/1140 of 27 February 2025 supplementing Regulation (EU) 2023/1114
as it stood on 2025-02-27, permalink: /eu-eurlex/32025r1140/2025-02-27
Outline, 18 provisions
art_1 art_2 art_3 art_4 art_5 art_6 art_7 art_8 art_9 art_10 art_11 art_12 art_13 art_14 art_15 art_16 art_17 art_18
Article 1
For the purposes of this Regulation, the following definitions shall apply:
| (1) | ‘transaction’ means the conclusion of an acquisition or disposal of crypto-assets other than the crypto-assets referred to in Article 2(3) and (4) of Regulation (EU) 2023/1114; |
|---|
| (2) | ‘undertaking a transaction’ means executing a transaction or transmitting an order for crypto-assets on behalf of a client; |
|---|
| (3) | ‘executing a transaction’ means providing any of the following services or performing any of the following activities that result in a transaction:(a)reception and transmission of orders for crypto-assets on behalf of clients;(b)execution of orders on behalf of clients;(c)exchange of crypto-assets for funds or for other crypto-assets;(d)making an investment decision in accordance with a discretionary mandate given by a client;(e)transfer of crypto-assets to or from accounts. |
|---|---|
| (a) | reception and transmission of orders for crypto-assets on behalf of clients; |
| (b) | execution of orders on behalf of clients; |
| (c) | exchange of crypto-assets for funds or for other crypto-assets; |
| (d) | making an investment decision in accordance with a discretionary mandate given by a client; |
| (e) | transfer of crypto-assets to or from accounts. |
Article 2
- The records shall be retained in a medium that allows the storage of information in a way accessible for future reference by the competent authority, in such a form and manner that all of the following conditions are met:
| (a) | competent authorities are able to access those records readily and to reconstitute each key stage of the processing of each crypto-asset service, activity, order or transaction; |
|---|
| (b) | it is possible to easily ascertain any corrections or other amendments to the records, and the contents of the records prior to such corrections or amendments; |
|---|
| (c) | it is not possible to manipulate or alter the records; |
|---|
| (d) | it allows for the exploitation of the data by means of an ICT or any other efficient system, where it is not possible to easily analyse the data due to its volume and nature; |
|---|
| (e) | the crypto-asset service provider's record-keeping arrangements comply with the record keeping requirements under this Regulation irrespective of the technology used. |
|---|
Crypto-assets service providers shall keep the records listed in Section 1 of the Annex, depending upon the nature of their services and activities.
The obligation to keep the records listed in Section 1 of the Annex shall not affect any obligation to keep records set out in any other Union act.
Article 3
Crypto-asset service providers shall keep records of any policies and procedures they are required to maintain in writing under Regulation (EU) 2023/1114 and its implementing measures.
Crypto-asset service providers shall also keep the records of the assessment and periodical review, carried out by their management body, of the effectiveness of the policy arrangements, and procedures referred to in Articles 68(6) of Regulation (EU) 2023/1114, including of any deficiencies identified in relation to such policy arrangements and procedures and of any measures taken to address such deficiencies.
Article 4
Crypto-asset service providers shall keep the documents setting out their rights and obligations in relation to their provision of service, as well as those setting out the rights and obligations of their clients for a period of five years from the termination of the agreement to provide services.
At the request of a competent authority, made before the expiry of the five-year period referred to in paragraph 1, crypto-asset service providers shall keep the documents referred to in paragraph 1 for a period of up to seven years from the date of termination of the agreement to provide crypto-asset services.
Article 5
Crypto-asset service providers shall keep records enabling them to distinguish, at any time and without delay, crypto-assets and funds held for one client from crypto-assets and funds held for any other client and from their own assets.
Crypto-asset service providers shall maintain their records in a way that ensures that they may be used for auditing purposes as records.
Such records shall include the following:
| (a) | records that readily identify the balances of crypto-assets and funds held for each client; |
|---|
| (b) | where clients’ funds are held by crypto-asset service providers in accordance with Article 70(2) and (3) of Regulation (EU) 2023/1114, details of the accounts in which those funds are held and the relevant agreements between the crypto-assets service provider with the credit institutions or central banks with which the clients’ funds are placed; |
|---|
| (c) | details of the accounts opened with third parties holding crypto-assets for the crypto-assets service provider and of the outsourcing agreements with those third parties; |
|---|
| (d) | details of third parties carrying out any tasks outsourced in accordance with Article 73 of Regulation (EU) 2023/1114 and details of the outsourced tasks; |
|---|
| (e) | names and functions of persons responsible for the safekeeping of clients’ crypto-assets and funds within the crypto-asset service provider; |
|---|
| (f) | agreements that establish client ownership over crypto-assets and funds. |
|---|
Article 6
For every initial order received from a client and for every initial decision to deal taken, crypto-asset service providers shall record and keep the details set out in the second and third columns of Table 2 of Section 2 of the Annex and the details set out in Table 4 of Section 4 of that Annex, to the extent that such details concern the initial orders and those decisions to deal.
Where a competent authority requests any of the details referred to in paragraph 1 in accordance with Article 94(1), points (a) or (d), or Article 94(3), point (a), of Regulation (EU) 2023/1114, the crypto-assets service providers shall provide such details as set out in the fourth column of Table 2 of Section 2 of the Annex to this Regulation.
Where the details set out in Table 2 of Section 2 of the Annex to this Regulation are also required pursuant to Article 76 of Regulation (EU) 2023/1114 or to Articles 25 and 26 of Regulation (EU) No 600/2014, they shall be maintained according to the standards set out in those Regulations.
Article 7
Crypto-asset service providers shall, immediately after having undertaken a transaction, record the details set out in the second and third columns of Table 3 of Section 3 and Table 4 of Section 4 of the Annex.
Where competent authorities request any of the details referred to in paragraph 1 in accordance with Article 94(1), points (a) or (d), or Article 94(3), point (a), of Regulation (EU) 2023/1114, the operators of trading platforms for crypto-assets shall provide such details as set out in the fourth column of Table 3 of Section 3 of the Annex.
Article 8
Where a person or computer algorithm within a crypto-asset service provider makes the investment decision to acquire or dispose of a specific crypto-asset on behalf of the crypto-asset service provider or on behalf of a client in accordance with a discretionary mandate given by the client, that person or computer algorithm shall be identified and recorded as specified in Field 41 of Table 3 of Section 3 of the Annex.
Where a person and computer algorithm are both involved in taking the investment decision, or more than one person or algorithm are involved in taking that decision, the crypto-asset service provider shall record the person or computer algorithm with primary responsibility for that decision.
Article 9
A client who is a natural person shall be identified in the crypto-asset service provider’s records using the designation resulting from the concatenation of the ISO 3166-1 alpha-2 (2-letter country code) of the client’s nationality, followed by the national client identifier specified in Annex II to Delegated Regulation (EU) 2017/590, based on the client’s nationality.
The national client identifier referred to in paragraph 1 shall be assigned in accordance with the priority levels provided for in Annex II of Delegated Regulation (EU) 2017/590 using the highest priority identifier that a person has, regardless of whether that identifier is already known to the crypto-asset service provider.
For the purposes of identifying a natural person, if the person is a national of more than one European Economic Area (EEA) country, the country code of the first nationality when sorted alphabetically by its ISO 3166-1 alpha-2 code and the identifier of that nationality assigned in accordance with paragraph 2 shall be used.
Where a natural person has a non-EEA nationality, the highest priority identifier in accordance with the field referring to ‘all other countries’ provided in Annex II of Delegated Regulation (EU) 2017/590 shall be used. Where a natural person has EEA and non-EEA nationality, the country code of the EEA nationality and the highest priority identifier of that nationality assigned in accordance with paragraph 2 shall be used.
Where a client is a resident of a country other than the one of its nationality, crypto-asset service providers shall also identify that person based on the country of residence of the person as prescribed in Field 41 of Table 2 in the Annex.
Where the identifier assigned in accordance with paragraph 2 is based on CONCAT, the client shall be identified by the crypto-asset service provider using the concatenation of the following elements in the following order:
| (a) | the date of birth of the person in the format YYYYMMDD; |
|---|
| (b) | the five first characters of the first name of the person; |
|---|
| (c) | the five first characters of the surname of the person. |
|---|
- For the purposes of paragraph 6, prefixes to names shall be excluded and first names and surnames shorter than five characters shall be appended by ‘#’ so as to ensure that references to names and surnames in accordance with paragraph 6 contain five characters. All characters shall be in upper case. No apostrophes, accents, hyphens, punctuation marks or spaces shall be used.
Article 10
Where a person or computer algorithm within the crypto-asset service provider which executes a transaction determines which trading platform for crypto-assets located outside the Union to access, which other crypto-asset service provider to transmit orders to or any conditions related to the execution of a transaction, that employee or computer algorithm shall be identified in Field 41 of Table 3 in Section 3 of the Annex.
Where a person within the crypto-asset service provider takes decisions determining the execution of the transaction, the crypto-asset service provider shall assign a designation for identifying that person in its transaction records in accordance with Article 9.
Where a computer algorithm operating under the control of the crypto-asset service provider takes decisions determining the execution of the transaction, that computer algorithm shall be identified in Field 43 of the Table in Section 3 of the Annex.
Where a person and computer algorithm are both involved in execution of the transaction, or more than one person or algorithm are involved, the crypto-asset service provider shall record the person or computer algorithm primarily responsible for the execution of the transaction in Field 43 of Table 3 in Section 3 of the Annex.
Article 11
Crypto-asset service providers that receive and transmit to another crypto-asset service provider an order for crypto-assets on behalf of clients as referred to in Article 1(3)(a) shall record the details of such orders as specified in Fields 1, 2, 10, 12, 14, 15, 16, 17, 19, 20, 21, 25, 37 of Table 2 of Section 2 of the Annex, if and to the extent that those fields are relevant for that order.
Where the order transmitted was received from a crypto-asset service provider who had previously transmitted that order, the fields provided pursuant to paragraph 1 shall be those identifying the transmitting crypto-asset service provider.
Where an order is transmitted more than one time, the order details referred to in paragraph 1 shall be those of the client of the crypto-asset service provider who first transmitted the order and shall be recorded by the crypto-asset service provider who transmitted the order for the first time.
Where orders are aggregated for more than one client, the order details referred to in paragraph 1 shall be recorded for each client.
Article 12
Where a crypto-asset service provider executes an order or a transaction on behalf of a client through a trading platform for crypto-assets or a service provider to which Regulation (EU) 2023/1114 does not apply, the crypto-asset service provider shall record the details of the order or transaction as if it had executed the order or transaction itself.
The crypto-asset service provider shall record the information referred to in paragraph 1 in the fields specified in Table 2 of Section 2 and in Table 3 of Section 3 of the Annex, where those fields are applicable to the order or transaction in question.
Article 13
Where a crypto-asset service provider transmits an order to an entity to which Regulation (EU) 2023/1114 does not apply, the crypto-asset service provider shall record the details of the transmitted order in the fields specified in Table 2 of Section 2 of the Annex, to the extent those fields are applicable to the order or transaction in question.
Where the order is aggregated for several clients, the information referred to in Article 9 and 14, as applicable, shall be recorded for each client.
Article 14
When providing to the competent authorities the information referred to in Articles 6 and 7, a crypto-asset service provider shall identify any clients that are legal entities by using a legal entity identifier code corresponding to those clients.
Crypto-asset service providers shall record the legal entity identifier codes that comply with the ISO 17442 standard and are included in the Global LEI database maintained by the Central Operating Unit appointed by the Legal Entity Identifier Regulatory Oversight Committee.
Where the client does not have a legal entity identifier compliant with the ISO 17442 standard, the crypto asset service provider shall obtain one for the client, or use an identifier defined at Union level which meets all of the following characteristics:
| (a) | is unique; |
|---|
| (b) | is neutral; |
|---|
| (c) | is reliable; |
|---|
| (d) | is open source; |
|---|
| (e) | is scalable; |
|---|
| (f) | is accessible; |
|---|
| (g) | is available for free or at a reasonable cost; |
|---|
| (h) | is subject to an appropriate governance framework. |
|---|
Article 15
When providing information to competent authorities under Articles 6 and 7, a crypto-asset service provider shall identify the crypto-assets that are the subject of the recorded order or transaction, or used as a means of payment, by using a digital token identifier that is compliant with the ISO 24165 standard or an equivalent unique identifier approved by ESMA at Union level, which meets all of the following characteristics:
| (a) | is unique; |
|---|
| (b) | is neutral; |
|---|
| (c) | is reliable; |
|---|
| (d) | is open source; |
|---|
| (e) | is scalable; |
|---|
| (f) | is accessible; |
|---|
| (g) | is available at a reasonable cost basis; and |
|---|
| (h) | is subject to an appropriate governance framework. |
|---|
Article 16
Where a crypto-asset service provider undertakes a transaction wholly or partly through its branch, it shall include in its transaction records, the ISO 3166 country code of such branch, in accordance with Fields 7, 16, 34, 42 or 44 of Table 3 in Section 3 of the Annex.
The crypto-asset service provider shall include in the transaction records the following information:
| (a) | whether the branch received the order from a client or whether the branch made an investment decision for a client in accordance with a discretionary mandate given to it by the client; |
|---|
| (b) | whether the branch has supervisory responsibility for the person taking the investment decision concerned; |
|---|
| (c) | whether the branch has supervisory responsibility for the person determining the conditions for execution of the transaction; |
|---|
| (d) | whether the transaction was fully or partially undertaken on a trading platform for crypto-assets located outside the Union using the branch’s membership of that trading platform for crypto-assets. |
|---|
Article 17
Crypto-asset service providers that undertake orders or transactions which trigger the obligation to keep records shall ensure that they are identified in the records to be maintained pursuant to this Regulation with a correct legal entity identifier which complies with the ISO 17442 standard and is included in the Global LEI database maintained by the Central Operating Unit appointed by the Legal Entity Identifier Regulatory Oversight Committee.
Crypto-asset service providers shall ensure that the reference data related to their legal entity identifier is renewed in accordance with the terms of any of the accredited Local Operating Units of the Global Legal Entity Identifier System.
Article 18
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Provenance and validity dates, identifier, hash
| as of | 2025-02-27 → this version applied |
| valid | 2025-02-27 → open publisher-asserted |
| type | REG_DEL Commission Delegated Regulation (EU) 2025/1140 of 27 February 2025 supplementing Regulation (EU) 2023/1114 of the European Parliament and of the Council with regard to regulatory technical standards specifying records to be kept of all crypto-asset services, activities, orders and transactions undertaken |
| language | en |
| published | 2025-02-27 |
| lex_id | eu-eurlex:32025r1140:2025-02-27 |
| record sha256 | 8b205a33826f2b99b857c1d89db51e69bd3b90faf9e840bd520567208832d313 |
New here? What am I looking at?
This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.
It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.
“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.
timeline next version (2025-02-27) →
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |