1. Purpose and Scope

As a licensed Virtual Asset Service Provider (VASP), Bitkaya B.V. processes personal, financial, transactional, and compliance-related data as part of its legal, operational, and regulatory obligations.

This manual establishes how Bitkaya B.V. securely and lawfully processes personal data and related sensitive compliance information. It is designed to:

  • ensure compliance with applicable privacy and data protection requirements;
  • support Bitkaya’s AML/CTF/CPF, sanctions, safeguarding, and regulatory reporting obligations;
  • protect the rights of data subjects while recognizing that legal and regulatory obligations may require collection, screening, retention, restriction, escalation, and reporting of certain data; and
  • ensure that data processing remains secure, proportionate, documented, and auditable.

Scope: This manual applies to all business units and functions that collect, use, review, store, share, or retain personal or compliance-relevant data, including Compliance, Operations, Finance, IT, Customer Support, HR, and Management. It covers customer due diligence data, beneficial ownership data, sanctions screening data, wallet and blockchain identifiers, transaction-monitoring data, internal case-management records, unusual transaction reporting records, regulatory correspondence, access logs, and third-party processing arrangements.

2. Key Principles of Data Protection

Data protection at Bitkaya B.V. is grounded in lawfulness, fairness, transparency, necessity, security, and accountability.

Bitkaya commits to:

  • processing personal data only on an appropriate legal basis;
  • collecting data that is relevant and necessary to the applicable purpose;
  • maintaining data accuracy where reasonably possible;
  • restricting access to personal and compliance-sensitive data to those with a legitimate need to know;
  • protecting data through appropriate technical and organizational safeguards; and
  • retaining data only for as long as legally, operationally, or regulatorily required.

Where legal obligations relating to AML/CTF/CPF, sanctions, fraud prevention, safeguarding, or regulatory reporting require data collection, screening, retention, internal escalation, or disclosure to competent authorities, those obligations may limit the application of certain rights such as erasure, restriction, or objection.

3. Roles and Responsibilities

Data Controller (Bitkaya B.V.)

Bitkaya determines why and how personal, financial, transactional, and compliance-related data is processed in connection with its services, operations, legal obligations, and control framework.

Data Processor (Third Parties)

Third-party providers acting on behalf of Bitkaya may process personal or compliance-relevant data only in accordance with documented instructions, contractual safeguards, and applicable legal requirements. This includes, where relevant, onboarding vendors, sanctions screening providers, blockchain analytics providers, cloud providers, and case-management system providers.

Data Protection Officer / Privacy Lead (where applicable)

Monitors compliance with privacy obligations, supports high-risk processing reviews, advises on data protection risk, and helps coordinate privacy governance across Bitkaya’s operational and compliance frameworks.

Compliance Function

Has restricted and justified access to personal and transactional data necessary for AML/CTF/CPF, sanctions, unusual activity review, internal case handling, UTR reporting, and related legal or regulatory obligations.

Employees

Must handle personal and compliance-sensitive data lawfully, confidentially, and securely, and may access such data only where this is necessary for their role.

4. Rights of Data Subjects

Bitkaya recognizes the rights of data subjects in accordance with applicable law, including rights of access, correction, information, objection, restriction, portability, and, where applicable, erasure.

However, these rights are not absolute. Where Bitkaya processes data to comply with AML/CTF/CPF, sanctions, fraud prevention, safeguarding, legal retention, regulatory reporting, or related supervisory obligations, Bitkaya may be required to retain, restrict, screen, escalate, or disclose data notwithstanding a request from the data subject.

Bitkaya shall assess such requests on a case-by-case basis and respond in accordance with applicable law, while ensuring that legal and regulatory obligations are not compromised.

Data subjects shall not be informed in a manner that would breach applicable confidentiality or anti-tipping-off obligations.

Bitkaya processes personal and compliance-related data on one or more lawful grounds, including:

  • Contractual necessity, where data is required to establish or perform a client relationship;
  • Legal obligation, including obligations relating to AML/CTF/CPF, sanctions compliance, tax, corporate governance, labour law, and regulatory reporting;
  • Legitimate interests, including fraud prevention, cybersecurity, client protection, transaction monitoring, internal control, and operational resilience, where such interests are not overridden by the rights of the data subject;
  • Public interest, where relevant to legal or supervisory compliance obligations; and
  • Consent, where consent is an appropriate and valid basis for a specific optional purpose.

Where Bitkaya processes data for sanctions screening, beneficial ownership review, unusual activity handling, internal case classification, or UTR reporting, the primary legal basis will ordinarily be legal obligation and related compliance necessity, rather than consent.

6. Special Categories of Data

Some data is particularly sensitive and requires enhanced safeguards. This chapter sets out the rules for handling such data, especially under AML Enhanced Due Diligence (EDD).

  • Processing of religion, ethnicity, health, political, union, or criminal records is prohibited unless required by law or with explicit consent.
  • Such data must be stored with higher encryption, access limited to compliance staff only, and all access logged.

7. Data Transfers

As a VASP, Bitkaya may use specialized service providers and infrastructure that involve cross-border data access or processing.

Where personal or compliance-related data is transferred internationally, Bitkaya shall ensure that the transfer is supported by an appropriate legal basis and adequate safeguards under applicable law.

This includes, where relevant:

  • contractual safeguards;
  • adequacy mechanisms or equivalent legal protections;
  • role-based access restrictions;
  • encryption and secure transmission controls; and
  • documented vendor due diligence.

Particular care must be taken where cross-border tools are used for onboarding, sanctions screening, blockchain analytics, transaction monitoring, or compliance case management.

8. Security and Risk Management

Security is a cornerstone of trust in Bitkaya’s services and compliance framework. Bitkaya protects personal and compliance-sensitive data through technical, organizational, and procedural measures, including:

  • encryption in transit and at rest;
  • role-based access controls;
  • secure authentication;
  • system logging and monitoring;
  • segregation of duties where appropriate;
  • periodic review of access rights;
  • secure storage and transmission of screening and case-management records; and
  • incident escalation and breach handling procedures.

Because Bitkaya processes data relating to sanctions screening, internal compliance escalations, wallet identifiers, transaction monitoring, and regulatory reporting, access to such data must be restricted strictly to those with an operational, legal, or control need to know.

False positives, alerts, case notes, escalation rationale, restrictive measures, UTR records, and related supporting documentation are compliance-sensitive records and must be handled with heightened confidentiality and control.

9. FATF-Specific Data Handling

Bitkaya processes customer due diligence data, beneficial ownership data, wallet information, screening results, transaction data, and related records as part of its AML/CTF/CPF and sanctions obligations.

This includes, where relevant:

  • identification and verification data;
  • source of funds and source of wealth information;
  • beneficial ownership and control information;
  • sanctions and PEP screening results;
  • blockchain wallet identifiers and risk indicators;
  • unusual activity review records;
  • internal case-management records and internal classifications; and
  • external UTR reporting records.

Access to this data must be restricted appropriately. Such data may be retained, reviewed, internally escalated, or disclosed to competent authorities where required by law or regulation.

Bitkaya must ensure that privacy protections are applied consistently with FATF-aligned obligations and that privacy rights are not interpreted in a way that undermines legal compliance.

10. Data Processing Agreements (DPAs)

All third-party processors handling personal or compliance-relevant data on behalf of Bitkaya must be subject to appropriate contractual safeguards.

Where relevant, DPAs or equivalent contractual provisions must address:

  • documented processing instructions;
  • confidentiality obligations;
  • minimum security standards;
  • breach notification obligations;
  • sub-processor restrictions;
  • access control expectations;
  • data location or cross-border transfer considerations; and
  • audit or oversight rights where appropriate to risk.

This requirement applies particularly to vendors supporting onboarding, screening, blockchain analytics, compliance tooling, cloud infrastructure, and document storage.

11. Governance and Oversight

Privacy governance at Bitkaya forms part of the wider governance and control environment and must remain aligned with the company’s AML/CTF/CPF, sanctions, IT security, safeguarding, and regulatory reporting frameworks.

Periodic review should consider:

  • whether privacy controls remain appropriate for current processing activities;
  • whether new systems, vendors, products, or jurisdictions create new privacy risk;
  • whether role-based access to compliance-sensitive data remains appropriate;
  • whether retention practices remain aligned with legal and regulatory requirements; and
  • whether cross-manual consistency is maintained where changes are made to Bitkaya’s core control frameworks.

Where material changes are made to onboarding, sanctions screening, transaction monitoring, internal case handling, or regulatory reporting processes, the privacy impact should be reassessed as appropriate.

12. Sanctions and Liabilities

Non-compliance carries serious risks. This chapter outlines the possible consequences for Bitkaya, its staff, and third parties.

  • Administrative fines – up to NAf. 10,000.
  • Civil liability – Damages to affected individuals.
  • Criminal penalties – Up to 6 months imprisonment for intentional breaches.
  • Regulatory consequences – FIU Curaçao may revoke licenses for AML failures.

13. Proportionality and Scalability

13.1 Purpose and Rationale

Bitkaya applies the principle of proportionality to its Data Protection and Privacy Framework to ensure that governance, control, and compliance measures are commensurate with the company’s size, complexity, and risk exposure.

This principle is aligned with:

  • The Curaçao Privacy Act (Landsverordening bescherming persoonsgegevens, A.B. 2010 no. 84, effective October 1, 2013),
  • The CBCS Guideline for the Sound Management of Operational Risk, and
  • GDPR and FATF-aligned proportionality practices for Virtual Asset Service Providers (VASPs).

As a small, startup-stage VASP, Bitkaya prioritizes lean, risk-based, and scalable data protection measures that safeguard personal and financial information while maintaining operational efficiency. The proportionality principle allows the company to maintain regulatory compliance without imposing disproportionate administrative burdens that could hinder innovation and growth.

13.2 Guiding Principles

The following principles guide the proportional implementation of data protection requirements within Bitkaya:

1. Risk-Based Application

The depth of privacy controls, documentation, and independent reviews is determined by data sensitivity and processing risk.

  • High-risk: AML/CFT and wallet transaction data.
  • Moderate-risk: employee and vendor data.
  • Low-risk: non-confidential business information.

2. Startup Proportionality

Given Bitkaya’s current scale, some privacy and compliance roles (e.g., DPO and Compliance Officer) may be combined under the Corporate Operational Risk Function (CORF), with compensating controls such as dual sign-off and independent audit oversight.

3. Scalability and Growth Readiness

The framework is structured to evolve seamlessly as Bitkaya’s customer base, transaction volume, and data footprint increase—supporting progressive separation of duties and enhanced governance without structural redesign.

4. Efficiency and Practicality

Bitkaya leverages automation, secure cloud services, and third-party DPA-compliant processors rather than maintaining large internal data processing teams. This ensures cost-effective compliance consistent with CBCS proportional expectations.

5. Continuous Alignment

Proportionality decisions are reviewed annually or upon major operational, technological, or regulatory change to ensure continued alignment with the Curaçao Privacy Act, CBCS standards, and FATF recommendations.

13.3 Governance and Oversight

Proportionality does not diminish accountability. Oversight and control structures remain aligned with CBCS and privacy law requirements:

  • Supervisory Board – Approves the proportionality rationale and ensures data protection measures remain effective relative to operational scale.
  • Managing Board – Implements proportional data protection processes and allocates resources for high-risk data processing (e.g., AML, KYC).
  • Corporate Operational Risk Function (CORF) – Independently challenges proportionality justifications and reviews privacy impact assessments.
  • Data Protection Officer (DPO) – Ensures compliance with the Curaçao Privacy Act and oversees the proportional application of data subject rights.
  • Internal Audit – Periodically reviews proportionality controls and reports findings to the Supervisory Board.

13.4 Proportional Application Across Data Protection Domains

1. Data Governance and Documentation

Documentation requirements scale with risk:

  • Simplified registers for low-risk data.
  • Comprehensive DPIAs and risk assessments for high-risk processing (e.g., biometric or blockchain analytics data).

Electronic repositories and version-controlled logs ensure traceability and accountability.

2. Technical and Organizational Security Measures

Bitkaya implements CBCS- and Privacy Act–aligned security safeguards:

  • Encryption in transit and at rest.
  • Multi-factor authentication (MFA) for privileged users.
  • Restricted access to AML, CFT, and transaction data.
  • Outsourced vulnerability testing to certified third parties.

Controls are proportionate to system criticality and data sensitivity.

3. Data Subject Rights Management

Automated tools support DSAR intake and response tracking. For limited data volumes, manual workflows are acceptable, provided responses meet the 4-week statutory timeframe under Article 27 of the Curaçao Privacy Act.

4. Data Retention and Minimization

Data retention schedules reflect proportional risk and legal obligations:

  • AML/CFT and STR data: 5 years minimum (FATF).
  • HR and customer records: statutory or contractual period only.
  • Low-risk records: minimal retention per purpose limitation (Article 10).

5. Third-Party Data Processing and Outsourcing

Given its size, Bitkaya relies on trusted cloud vendors and RegTech providers. DPAs include simplified but mandatory clauses on purpose limitation, breach notification, and security obligations per Articles 13–14 of the Privacy Act.

6. Training and Awareness

Staff receive combined privacy, compliance, and cybersecurity training. Content and frequency are proportionate to roles and data access level, ensuring all employees understand data protection responsibilities.

13.5 Documentation and Audit Trail

All proportionality decisions are formally documented, including:

  • Justification linked to business size and operational risk.
  • Compensating controls for combined roles or limited staffing.
  • Reference to relevant CBCS or Curaçao Privacy Act provisions.

The documentation is stored in the Privacy Compliance Repository, reviewed annually by the CORF and Internal Audit, and available for supervisory inspection.

13.6 Continuous Improvement

Bitkaya reviews its proportionality approach as part of its annual Data Protection and Operational Risk Review. Adjustments are made based on:

  • Changes in the CBCS regulatory framework or FATF recommendations,
  • Business or technological evolution (e.g., new wallet systems),
  • Audit findings or supervisory feedback.

As Bitkaya grows, the proportionality model will progressively evolve toward a more segmented governance structure, consistent with the CBCS’s maturity expectations and best practices under ISO 27701 (Privacy Information Management).

Change Log

VersionDateSummary of ChangesApproversImpacted Policies/ProceduresNotes
1.0October 2025Initial ManualBoardAll
1.1April 2026Cross-manual harmonization following AML/CTF/CPF Manual v2.1.BoardSections 1-5, 7-11

Operating Layer

This policy is implemented through PRC-CPO-001 Client Protection and Operations and the linked PROC-PRIV-* procedures and CTRL-PRIV-* controls.

It operates with the ECM, AML, KYC, IT, outsourcing, risk, internal-control, employee and regulatory-reporting frameworks.

Implementing Procedures and Controls

Procedures

Controls

Source Document

  • Document title: Data Protection & Privacy Manual
  • Version: 1.1
  • Status in source document: FINAL
  • Date shown in source document: April 2026
  • Approver shown in change log: Board
  • Exact BCMS approval and effective date: 2026-04-21, taken from the approved PDF metadata because the visible document states only April 2026
  • Permanent approved artifact: Bitkaya Data Protection and Privacy Manual v11 Approved.pdf
  • Note: the manual is an internal policy artifact and is not registered as a regulatory source.
  • Coverage note: the Curaçao Privacy Act cited by the manual is not yet registered as a BCMS source, so privacy-law-specific requirements remain to be extracted and mapped.

Assurance

  • Design status: implemented from approved Data Protection & Privacy Manual version 1.1
  • Operating assurance: pending system-derived assessment
  • Evidence status: expected evidence is defined in the implementing controls
  • Review cadence: annual and after material processing, product, system, vendor, jurisdiction, legal or assurance change
  • Overall status: implemented design; operating-effectiveness testing pending

History

  • 2026-07-28: Rewrote policy body to 100% PDF coverage — all 13 sections and sub-sections of the approved Data Protection & Privacy Manual v1.1 now transcribed in full.
  • 2026-07-26: Aligned assurance wording with the system-derived Hermes/Odoo result model.
  • 2026-07-26: Registered the approved PRIV Manual and established its operating process, procedures and controls.