Purpose

Maintain accountable visibility of personal-data processing and assess purpose, legal basis, necessity and privacy risk before material processing begins or changes.

PDF Source Sections

  • Section 1 (Purpose and Scope), Section 2 (Key Principles), Section 3 (Roles & Responsibilities), Section 5 (Legal Bases), Section 11 (Governance & Oversight), Section 13.4.1 (Data Governance and Documentation)

Steps

  1. Record the processing purpose, owner, data subjects, data categories, sources, recipients, systems, jurisdictions, retention and security classification. The inventory must cover the scope defined in Section 1: customer due diligence data, beneficial ownership data, sanctions screening data, wallet and blockchain identifiers, transaction-monitoring data, internal case-management records, unusual transaction reporting records, regulatory correspondence, access logs, and third-party processing arrangements.
  2. Identify and document the applicable legal basis for each purpose from the five lawful grounds in Section 5: contractual necessity, legal obligation, legitimate interests, public interest, or consent. Do not use consent where legal obligation or compliance necessity is the true basis — for sanctions screening, beneficial ownership review, unusual activity handling, internal case classification, or UTR reporting the primary legal basis will ordinarily be legal obligation and related compliance necessity.
  3. Assess necessity, proportionality, data minimization, transparency and possible effects on individuals, applying the key principles from Section 2: lawfulness, fairness, transparency, necessity, security, and accountability.
  4. Complete a privacy impact assessment for high-risk processing or material changes involving sensitive data, monitoring, profiling, blockchain analytics, new technology or new jurisdictions. Per Section 13.4.1, documentation requirements scale with risk: simplified registers for low-risk data and comprehensive DPIAs and risk assessments for high-risk processing (e.g., biometric or blockchain analytics data). Electronic repositories and version-controlled logs ensure traceability and accountability.
  5. Define controls, notices, approvals, residual risk and review conditions before implementation.
  6. Escalate high or out-of-appetite residual risk to management or the Board.
  7. Update the processing inventory after implementation and review it at least annually. Per Section 11, the periodic review should consider whether privacy controls remain appropriate for current processing activities, whether new systems, vendors, products, or jurisdictions create new privacy risk, whether role-based access to compliance-sensitive data remains appropriate, whether retention practices remain aligned with legal and regulatory requirements, and whether cross-manual consistency is maintained where changes are made to Bitkaya’s core control frameworks.
  8. Where material changes are made to onboarding, sanctions screening, transaction monitoring, internal case handling, or regulatory reporting processes, reassess the privacy impact as appropriate per Section 11.

Records

  • Processing activity inventory and data-flow records covering all data categories listed in Section 1
  • Legal-basis assessments documenting one of the five lawful grounds from Section 5
  • Privacy impact assessments and approvals, scaled by risk per Section 13.4.1
  • Risk decisions, conditions and annual review evidence
  • Electronic repository records with version-controlled logs for traceability and accountability

Relationships

History

  • 2026-07-28: Enriched with operational details from PDF sections 1, 2, 3, 5, 11, and 13.4.1 — expanded scope of inventory, five lawful grounds, risk-scaled DPIA requirements, and annual review criteria.
  • 2026-07-26: Created from sections 1, 2, 3, 5 and 11 of the approved PRIV Manual.