Source: OJ L, 2025/1140, 10.6.2025

Current language: EN

Article 2 Retention of records


Summary What does Article 2 of the RTS on record keeping say?

This article sets out the technical and qualitative standards that crypto-asset service providers must meet when storing records.

Rather than prescribing a specific technology, it focuses on what the records must achieve: they must be accessible to competent authorities, tamper-proof, auditable for any amendments, and machine-readable where data volume demands it.

The article also directs providers to keep the specific records listed in the Annex, calibrated to the nature of their services, and clarifies that these obligations sit alongside, rather than replacing, any record-keeping duties under other EU legislation.

Important points:

  • Ensure records are stored in a format that is accessible, non-manipulable, and allows competent authorities to reconstruct each stage of any service, order, or transaction.
  • Keep the records specified in Section 1 of the Annex, with the scope of that obligation determined by the nature of your services and activities.
  • Compliance with record-keeping requirements under other Union acts remains fully intact alongside the obligations set out here.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. The records shall be retained in a medium that allows the storage of information in a way accessible for future reference by the competent authority, in such a form and manner that all of the following conditions are met:

      1. competent authorities are able to access those records readily and to reconstitute each key stage of the processing of each crypto-asset service, activity, order or transaction;

      2. it is possible to easily ascertain any corrections or other amendments to the records, and the contents of the records prior to such corrections or amendments;

      3. it is not possible to manipulate or alter the records;

      4. it allows for the exploitation of the data by means of an ICT or any other efficient system, where it is not possible to easily analyse the data due to its volume and nature;

      5. the crypto-asset service provider's record-keeping arrangements comply with the record keeping requirements under this Regulation irrespective of the technology used.

    1. Crypto-assets service providers shall keep the records listed in Section 1 of the Annex, depending upon the nature of their services and activities.

    1. The obligation to keep the records listed in Section 1 of the Annex shall not affect any obligation to keep records set out in any other Union act.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod