Purpose
Control third-party processing and cross-border access or transfer through due diligence, documented safeguards, approval and ongoing oversight.
PDF Source Sections
- Section 3 (Roles & Responsibilities — Data Processor), Section 7 (Data Transfers), Section 10 (Data Processing Agreements), Section 13.4.5 (Third-Party Data Processing and Outsourcing)
Steps
- Identify the processor role, services, data, purpose, locations, access paths and proposed sub-processors. Per Section 3, third-party providers acting on behalf of Bitkaya may process personal or compliance-relevant data only in accordance with documented instructions, contractual safeguards, and applicable legal requirements — this includes onboarding vendors, sanctions screening providers, blockchain analytics providers, cloud providers, and case-management system providers.
- Assess legal basis, transfer safeguards, security, resilience, confidentiality, regulatory access and concentration risk. Per Section 7, ensure the transfer is supported by an appropriate legal basis and adequate safeguards under applicable law, including contractual safeguards, adequacy mechanisms or equivalent legal protections, role-based access restrictions, encryption and secure transmission controls, and documented vendor due diligence. Particular care must be taken where cross-border tools are used for onboarding, sanctions screening, blockchain analytics, transaction monitoring, or compliance case management.
- Complete risk-based vendor due diligence before data access or transfer.
- Require written terms covering the mandatory DPA provisions from Section 10: documented processing instructions, confidentiality obligations, minimum security standards, breach notification obligations, sub-processor restrictions, access control expectations, data location or cross-border transfer considerations, and audit or oversight rights where appropriate to risk. Per Section 13.4.5, DPAs include simplified but mandatory clauses on purpose limitation, breach notification, and security obligations per Articles 13–14 of the Curaçao Privacy Act.
- Obtain privacy, security, outsourcing and business approval before activation.
- Record the arrangement and transfer details in the applicable inventories and registers.
- Monitor performance, incidents, location and sub-processor changes and assurance evidence.
- Reassess at renewal, after material change or incident, and execute controlled exit and data return or deletion.
Records
- Vendor and transfer assessment including the Section 7 safeguard checklist
- Due diligence and security assurance
- Data-processing agreement containing all Section 10 mandatory clauses and Articles 13–14 Privacy Act provisions per Section 13.4.5
- Processor and sub-processor register
- Monitoring, renewal, incident and exit evidence
Relationships
- Policy: POL-PRIV-001 Data Protection and Privacy Manual
- Process: PRC-CPO-001 Client Protection and Operations
- Control: CTRL-PRIV-004 Ensure Transfers Processors and Data Agreements Are Controlled
History
- 2026-07-28: Enriched with operational details from PDF sections 3, 7, 10, and 13.4.5 — added processor types, Section 7 transfer safeguard checklist, all eight Section 10 mandatory DPA clauses, and Articles 13–14 Privacy Act reference.
- 2026-07-26: Created from sections 3, 7, 10 and 13.4 of the approved PRIV Manual.