# The EU's €10,000 Cash Cap and Your ID Data

> The EU's €10,000 cash cap and stricter crypto KYC start in July 2027. Who has to show ID, who doesn't, and why the bigger risk is where the ID data ends up.

By Rose · October 2, 2026 · 12 min read · Privacy

Source: https://bluwarden.com/blog/eu-cash-limit-crypto-aml-rules

---

From 10 July 2027, a car dealer in Berlin can't take €15,000 in notes for a used Audi anymore. The EU's new [Anti-Money Laundering Regulation](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1624) (AMLR) caps cash payments to businesses at €10,000 across the whole bloc. The same law makes crypto exchanges fully identify anyone doing a one-off transaction of €1,000 or more, and stops them offering anonymous accounts or privacy coins.

Online, this has turned into "the EU is banning cash and will supervise every transaction." Neither part is true. You can still hold cash, withdraw it, deposit it and pay your neighbour with it. Nobody in Brussels gets a feed of your card payments. And on the crypto side, most of the identification people are angry about has been in place since the end of 2024.

What does change is how often you'll hand over your ID, and to whom. That's the part I think deserves more attention, because every new copy of your passport sitting in some company's system is something that can leak. So this post covers what the rules say, what they mean for an ordinary person and for a business, and what to actually do about the security side. Same approach as our [Chat Control](/blog/chat-control-is-back) piece.

## What changes in July 2027

The AMLR is part of a package [the Council adopted in May 2024](https://www.consilium.europa.eu/en/press/press-releases/2024/05/30/anti-money-laundering-council-adopts-package-of-rules/). Until now every member state ran its own version of the anti-money-laundering rules. The regulation replaces them with one rulebook that applies directly, pulls in sectors that weren't covered before (most of the crypto industry, luxury goods dealers, football clubs) and sets up a new EU authority, AMLA, in Frankfurt.

### The €10,000 cash cap

Article 80 is short. Anyone selling goods or services can accept or make a cash payment of up to €10,000, and that includes several smaller payments that are obviously one deal split up. Paying €9,000 on Monday and €6,000 on Tuesday for the same car doesn't get around it.

The exemptions matter more than the headline. Payments between private individuals who aren't acting in a professional capacity are excluded, so selling your old car to a neighbour for cash is fine. Deposits and payments made at a bank, payment institution or e-money issuer are outside the cap too. Nothing in it limits how much cash you can keep at home.

For a lot of people the €10,000 figure won't change anything, because their country already has a lower limit and that lower limit stays. Italy and Spain are both well under it. Where it really lands is in countries like Germany that never had a cap.

### ID from €3,000, which is the bit that affects more people

This got far less coverage than the cap. Under the agreed text, traders have to identify and verify the customer for occasional cash transactions between €3,000 and €10,000. So if you pay a jeweller €4,000 in cash, they'll need to see your ID and keep a record of it.

In other words, the point where cash stops being anonymous with a business is €3,000.

### Crypto

There are four separate pieces of law here, and most articles mash them together. Only the last one actually starts in 2027:

| Rule | What it does | When |
|---|---|---|
| Transfer of Funds Regulation ("travel rule") | Names of sender and recipient travel with every transfer between crypto providers, whatever the amount. Above €1,000 to or from your own wallet, the provider has to check the wallet is really yours. | Since 30 December 2024 |
| DAC8 | Exchanges record your tax residence and report your transactions to the tax office, which shares them with other EU countries. | Collecting since 1 January 2026, first reports in 2027 |
| MiCA | Only licensed providers can serve EU customers. | Fully in force since 1 July 2026 |
| AMLR | Full due diligence for one-off transactions from €1,000. No anonymous accounts, and no accounts that allow anonymisation, including through privacy coins. | From 10 July 2027 |

The privacy coin rule is narrower than it sounds. It applies to regulated providers. Holding Monero in your own wallet isn't made illegal, and a transfer between two self-custody wallets with no exchange involved is outside the travel rule. In practice you just won't find them on any EU-licensed exchange.

## Is the EU going to watch every transaction?

No. AMLA [started work on 1 July 2025](https://www.jonesday.com/en/insights/2025/12/investigatory-powers-of-the-new-european-antimoney-laundering-authority) and from January 2028 it will directly supervise up to 40 financial groups, the large high-risk ones operating in at least six member states. Everyone else stays with their national supervisor.

AMLA supervises banks and other firms. It doesn't look at individual customers. The system works the same way it does today: your bank or exchange monitors your account and, if something looks off, reports it to your country's financial intelligence unit. The rules for doing that get stricter and the same everywhere, and more types of business have to do it. That's a real expansion, but it's a long way from an EU office reading everyone's statements.

Where people have a point is crypto. Between the travel rule and DAC8, if you use a licensed exchange, your identity is attached to every transfer and your tax office will see your trades. That has been the case since 2024 and 2026 respectively. 2027 mostly closes the last gaps.

## What it means for you as a normal person

Most people won't notice the cash cap at all. Hardly anyone pays a shop more than €10,000 in notes.

You'll notice the €3,000 ID rule if you buy jewellery, a used car or furniture with cash. And if you use crypto, it's safest to assume the exchange and your tax office can see everything you've bought, sold and sent. The EU's stated aim is that crypto on regulated platforms should be about as private as a bank account. You can disagree with that and still plan for it.

The security side is what I'd worry about more.

**Your ID will be stored in more places, and some of them won't look after it well.** Banks have security teams. A small car dealership that suddenly has to verify customers for every €3,000 cash sale probably doesn't. Those scans could easily end up in someone's email or a shared drive.

**Exchanges are a target because of what they hold.** Name, address, ID scan, balance, all in one record. In 2025 [Coinbase disclosed](https://thehackernews.com/2025/05/coinbase-agents-bribed-data-of-1-users.html) that criminals had bribed overseas support staff to copy customer data, including ID images, balances and transaction history, and then used it to phone customers pretending to be Coinbase and talk them into moving their money. More KYC means more of exactly that kind of data.

**Scammers will use the new rules as a cover story.** Expect texts and emails like "Under new EU rules you must re-verify your account" or "Confirm your tax residence for DAC8 to avoid suspension." What makes this tricky is that some real exchanges will ask you to prove you own a wallet, usually by sending a tiny test amount or signing a message, so the fake version won't sound strange. No rule will ever require you to share a seed phrase, install remote access software or move funds to a "safe wallet". Our [smishing breakdown](/blog/smishing-anatomy-phone-protection) goes through how these messages are put together.

### What I'd do

1. Don't pull your cash or crypto out in a panic. Nothing here confiscates anything or stops you holding either.
2. Check your exchange is on the ESMA register. Since July 2026 unlicensed providers aren't allowed to serve EU customers, and the marketing page won't tell you that.
3. Secure the exchange account properly: a passkey or hardware security key if it supports one, an authenticator app if not, never SMS on its own. Turn on withdrawal address allowlisting if there is one. If your phone number is on the account, set a carrier PIN so nobody can port your number. Our [password and MFA guide](/blog/password-best-practices-2026) covers the setup.
4. If a message about "EU compliance" arrives, don't click it. Open the app yourself. Only do a wallet check you started from inside the app.
5. When a shop asks for your passport for a cash purchase, ask them how they store it and how long they keep it. It's a fair question and you'll learn a lot from the answer.
6. If you move to self-custody for privacy reasons, treat it as a security project. A hardware wallet takes the exchange out of the picture, but losing your recovery phrase is then your problem alone.

## What it means for businesses

Most small businesses won't be affected much. AMLA isn't going to call a bakery. If you sell high-value goods for cash, or touch crypto, it's a different story.

If you sell cars, jewellery, watches, art, building work or anything else where customers sometimes pay large amounts in cash, from July 2027 you have to refuse cash above €10,000 (including split payments), identify and verify customers paying €3,000 or more in cash, keep records, and you can be fined if you get it wrong. Crypto providers get full due diligence from €1,000 and lose anonymous and privacy-coin accounts, on top of the travel rule, MiCA and DAC8 they already deal with. Banks and payment firms get one rulebook instead of 27, and the biggest cross-border groups get AMLA supervision from 2028. If you just accept crypto through a payment processor, expect them to ask you for more paperwork.

The regulation tells you to collect ID. It says nothing useful about protecting it. That's on you under GDPR, and I expect it's where a lot of businesses will slip.

1. **Keep ID scans in one place.** One system, encrypted, with access limited to the people who need it and every view logged. Not email, not WhatsApp, not a folder on the shared drive.
2. **Keep only what you're required to keep.** Verifying someone doesn't mean storing a high-resolution colour scan of their passport forever. Follow the retention rules and then delete.
3. **Assume an insider might be the problem.** The Coinbase leak wasn't a sophisticated hack. Support staff could see too much and were paid to copy it. Give support tools masked fields and least-privilege access, and alert on anyone pulling lots of customer records.
4. **Check your KYC provider.** If you outsource identity checks, that company now holds your customers' documents. Ask where they're stored, for how long, and who can get at them.
5. **Warn your staff.** Emails saying "AMLA requires urgent verification of your beneficial owners" or "under the new EU rules this invoice must go to a new account" will turn up. AMLA doesn't email small businesses and your bank won't change payment details by email. Our post on [what actually breaks company security](/blog/what-actually-breaks-company-security-2026) explains why these work so often.
6. **Sort the cash process before next summer.** Staff at the till need a clear rule for split payments and another way to take the money, otherwise a €12,000 sale turns into someone improvising.

If you also make connected products, the [Cyber Resilience Act](/blog/cyber-resilience-act-what-changes) lands around the same time and will probably need the same people.

## Key dates

| Date | What happens |
|---|---|
| 30 December 2024 | Crypto travel rule applies, no minimum amount |
| 1 July 2025 | AMLA starts work in Frankfurt |
| 1 January 2026 | DAC8 crypto tax data collection starts |
| 1 July 2026 | MiCA transition ends, unlicensed crypto providers must stop serving EU customers |
| 10 July 2027 | AMLR applies: €10,000 cash cap, ID from €3,000 in cash, crypto due diligence from €1,000, anonymous crypto accounts banned |
| 2027 | First DAC8 reports filed and shared between tax offices |
| 1 January 2028 | AMLA starts directly supervising up to 40 financial groups |
| 10 July 2029 | Rules extend to the remaining new sectors, including football clubs and agents |

## Summary

1. Cash isn't banned. Business payments are capped at €10,000 and you'll show ID from €3,000. Private payments, savings and bank deposits aren't affected.
2. Nobody at EU level is watching individual transactions. Banks and exchanges still do the monitoring, and AMLA supervises about 40 big institutions from 2028.
3. Anonymity on licensed crypto platforms was mostly gone already. 2027 removes anonymous and privacy-coin accounts. Self-custody is still legal.
4. The practical risk is all the ID data. Lock down exchange accounts with a passkey or security key and a carrier PIN, and ignore unsolicited "compliance" messages.
5. Businesses need to protect what they collect: encrypt it, restrict access, plan for insiders, check KYC vendors and brief staff before July 2027.

Whether a €10,000 limit actually catches money launderers is a separate argument. What's certain is that from next summer more of your identity will be sitting in more databases, and some of those databases will be badly protected.

*Handling customer ID, large cash sales or crypto payments and not sure your setup is ready? [Get in touch](/#contact) - bluwarden can review how your business stores and protects identity data before the rules kick in.*

*This guide is general information, not legal or tax advice. Cash limits and implementation details differ between member states, so check the rules that apply to you with the relevant authority or a qualified adviser.*
