Purpose
Provide accurate privacy information and respond lawfully, securely and on time to requests for access, correction, objection, restriction, portability or erasure.
PDF Source Sections
- Section 4 (Rights of Data Subjects), Section 2 (Key Principles), Section 13.4.3 (Data Subject Rights Management)
Steps
- Receive and log the request, date, requested right, scope and response deadline. Per Section 4, the recognized rights are access, correction, information, objection, restriction, portability, and where applicable, erasure.
- Verify identity proportionately without collecting unnecessary additional data.
- Locate relevant records and consult their owners, systems, recipients and retention obligations.
- Assess the request against applicable rights, exemptions, legal retention, AML, sanctions, safeguarding, supervision, confidentiality and anti-tipping-off duties. Per Section 4, these rights are not absolute — where Bitkaya processes data to comply with AML/CTF/CPF, sanctions, fraud prevention, safeguarding, legal retention, regulatory reporting, or related supervisory obligations, Bitkaya may be required to retain, restrict, screen, escalate, or disclose data notwithstanding a request from the data subject.
- Escalate uncertain, sensitive or potentially report-related requests to Compliance or legal counsel. Bitkaya shall assess such requests on a case-by-case basis and respond in accordance with applicable law, while ensuring that legal and regulatory obligations are not compromised.
- Approve and deliver a secure, clear response without disclosing protected internal classifications, reports or third-party data. Per Section 4, data subjects shall not be informed in a manner that would breach applicable confidentiality or anti-tipping-off obligations.
- Record the decision, searches, redactions, disclosures, corrections, restrictions and any appeal or complaint.
- Review privacy notices after material processing change and ensure claims match actual practice.
- Per Section 13.4.3, ensure responses meet the 4-week statutory timeframe under Article 27 of the Curaçao Privacy Act. Automated tools may support DSAR intake and response tracking; for limited data volumes, manual workflows are acceptable provided the statutory timeframe is met.
Records
- Rights-request register and identity verification with deadline tracking per Article 27
- Search, assessment, exemption and approval evidence documenting case-by-case evaluation per Section 4
- Responses, disclosures, redactions and delivery evidence with anti-tipping-off review
- Current notices and notice-review records
Relationships
- Policy: POL-PRIV-001 Data Protection and Privacy Manual
- Process: PRC-CPO-001 Client Protection and Operations
- Control: CTRL-PRIV-002 Ensure Data Subject Requests and Privacy Information Are Controlled
History
- 2026-07-28: Enriched with operational details from PDF sections 4, 2, and 13.4.3 — added seven recognized rights, non-absolute rights limitation, anti-tipping-off restriction, case-by-case assessment, and 4-week Article 27 statutory timeframe.
- 2026-07-26: Created from sections 2, 4, 5 and 13.4 of the approved PRIV Manual.