Source: OJ L, 2025/1140, 10.6.2025

Current language: EN

Article 4 Record-keeping of documents setting out the crypto-asset service provider’s and the client’s rights and obligations


Summary What does Article 4 of the RTS on record keeping say?

This article establishes the retention period for contractual documents held by crypto-asset service providers.

It sets a default five-year retention window from the end of a service agreement, covering documents that define the rights and obligations of both the provider and its clients.

It also introduces a mechanism by which a competent authority can extend that period, pushing retention up to seven years from the termination date.

Important points:

  • Retain all contractual documents setting out your rights and obligations, and those of your clients, for five years from the termination of the service agreement.
  • Competent authorities are empowered to extend this retention period to up to seven years, provided they make such a request before the original five-year period expires.
  • The extension is triggered solely by a competent authority request, not automatically.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Crypto-asset service providers shall keep the documents setting out their rights and obligations in relation to their provision of service, as well as those setting out the rights and obligations of their clients for a period of five years from the termination of the agreement to provide services.

    1. At the request of a competent authority, made before the expiry of the five-year period referred to in paragraph 1, crypto-asset service providers shall keep the documents referred to in paragraph 1 for a period of up to seven years from the date of termination of the agreement to provide crypto-asset services.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod