Purpose

Limit personal-data collection and use to what is necessary, apply enhanced protection to sensitive data and retain or dispose of records under approved schedules.

PDF Source Sections

  • Section 2 (Key Principles), Section 6 (Special Categories of Data), Section 8 (Security & Risk Management), Section 9 (FATF-Specific Data Handling), Section 13.4.4 (Data Retention and Minimization)

Steps

  1. Classify personal and compliance data by sensitivity, legal importance and access need. Per Section 13.2, the depth of privacy controls is determined by data sensitivity and processing risk: high-risk (AML/CFT and wallet transaction data), moderate-risk (employee and vendor data), low-risk (non-confidential business information).
  2. Prohibit special-category processing unless a documented legal basis and necessity exist. Per Section 6, processing of religion, ethnicity, health, political, union, or criminal records is prohibited unless required by law or with explicit consent. Such data must be stored with higher encryption, access limited to compliance staff only, and all access logged.
  3. Define minimum data fields and accuracy checks for each processing purpose, applying the key principle from Section 2 of collecting data that is relevant and necessary to the applicable purpose.
  4. Establish retention rules by record category, accounting for AML, sanctions, tax, employment, litigation, audit and supervisory needs. Per Section 13.4.4, data retention schedules reflect proportional risk and legal obligations: AML/CFT and STR data — 5 years minimum (FATF); HR and customer records — statutory or contractual period only; low-risk records — minimal retention per purpose limitation (Article 10).
  5. Apply legal or investigation holds before scheduled disposal where required.
  6. Restrict, encrypt and log access to sensitive and compliance-related records. Per Section 8, encryption must be applied in transit and at rest, with role-based access controls and system logging and monitoring.
  7. Review records reaching retention expiry and authorize secure deletion, anonymization or defensible continued retention.
  8. Preserve evidence of reviews, holds, disposal and exceptions.

Records

  • Data classification and minimization standards aligned to the three risk tiers from Section 13.2
  • Retention schedule reflecting AML/CFT 5-year minimum, statutory/contractual HR periods, and Article 10 purpose limitation per Section 13.4.4
  • Legal holds and retention exceptions
  • Access, encryption and logging evidence per Section 8 requirements
  • Disposal review, approval and deletion evidence

Relationships

History

  • 2026-07-28: Enriched with operational details from PDF sections 2, 6, 8, 9, and 13.4.4 — added three-tier risk classification, special-category prohibition and encryption requirements, specific retention periods (5-year FATF AML/CFT, Article 10), and encryption in transit/at rest.
  • 2026-07-26: Created from sections 2, 6, 8, 9 and 13.4 of the approved PRIV Manual.