Purpose

Provide accurate privacy information and respond lawfully, securely and on time to requests for access, correction, objection, restriction, portability or erasure.

PDF Source Sections

  • Section 4 (Rights of Data Subjects), Section 2 (Key Principles), Section 13.4.3 (Data Subject Rights Management)

Steps

  1. Receive and log the request, date, requested right, scope and response deadline. Per Section 4, the recognized rights are access, correction, information, objection, restriction, portability, and where applicable, erasure.
  2. Verify identity proportionately without collecting unnecessary additional data.
  3. Locate relevant records and consult their owners, systems, recipients and retention obligations.
  4. Assess the request against applicable rights, exemptions, legal retention, AML, sanctions, safeguarding, supervision, confidentiality and anti-tipping-off duties. Per Section 4, these rights are not absolute — where Bitkaya processes data to comply with AML/CTF/CPF, sanctions, fraud prevention, safeguarding, legal retention, regulatory reporting, or related supervisory obligations, Bitkaya may be required to retain, restrict, screen, escalate, or disclose data notwithstanding a request from the data subject.
  5. Escalate uncertain, sensitive or potentially report-related requests to Compliance or legal counsel. Bitkaya shall assess such requests on a case-by-case basis and respond in accordance with applicable law, while ensuring that legal and regulatory obligations are not compromised.
  6. Approve and deliver a secure, clear response without disclosing protected internal classifications, reports or third-party data. Per Section 4, data subjects shall not be informed in a manner that would breach applicable confidentiality or anti-tipping-off obligations.
  7. Record the decision, searches, redactions, disclosures, corrections, restrictions and any appeal or complaint.
  8. Review privacy notices after material processing change and ensure claims match actual practice.
  9. Per Section 13.4.3, ensure responses meet the 4-week statutory timeframe under Article 27 of the Curaçao Privacy Act. Automated tools may support DSAR intake and response tracking; for limited data volumes, manual workflows are acceptable provided the statutory timeframe is met.

Records

  • Rights-request register and identity verification with deadline tracking per Article 27
  • Search, assessment, exemption and approval evidence documenting case-by-case evaluation per Section 4
  • Responses, disclosures, redactions and delivery evidence with anti-tipping-off review
  • Current notices and notice-review records

Relationships

History

  • 2026-07-28: Enriched with operational details from PDF sections 4, 2, and 13.4.3 — added seven recognized rights, non-absolute rights limitation, anti-tipping-off restriction, case-by-case assessment, and 4-week Article 27 statutory timeframe.
  • 2026-07-26: Created from sections 2, 4, 5 and 13.4 of the approved PRIV Manual.