Purpose

Apply proportionate technical and organizational safeguards and coordinate rapid, documented response to suspected personal-data incidents.

PDF Source Sections

  • Section 8 (Security & Risk Management), Section 11 (Governance & Oversight), Section 13.4.2 (Technical and Organizational Security Measures)

Steps

  1. Classify systems and records by sensitivity, criticality and legal importance. Per Section 8, security is a cornerstone of trust in Bitkaya’s services and compliance framework.
  2. Apply the technical, organizational, and procedural measures from Section 8: encryption in transit and at rest, role-based access controls, secure authentication, system logging and monitoring, segregation of duties where appropriate, periodic review of access rights, secure storage and transmission of screening and case-management records, and incident escalation and breach handling procedures. Per Section 13.4.2, also implement multi-factor authentication (MFA) for privileged users, restricted access to AML, CFT, and transaction data, and outsourced vulnerability testing to certified third parties. Controls are proportionate to system criticality and data sensitivity.
  3. Approve access on documented need to know and review privileged and sensitive-data access periodically. Per Section 8, access to data relating to sanctions screening, internal compliance escalations, wallet identifiers, transaction monitoring, and regulatory reporting must be restricted strictly to those with an operational, legal, or control need to know. False positives, alerts, case notes, escalation rationale, restrictive measures, UTR records, and related supporting documentation are compliance-sensitive records and must be handled with heightened confidentiality and control.
  4. Receive and triage suspected loss, unauthorized access, alteration, disclosure or unavailability.
  5. Contain the event, preserve evidence and assess affected data, subjects, systems, recipients, jurisdictions, consequences and continuing risk.
  6. Coordinate security, privacy, legal, AML, regulatory and management escalation without compromising investigations or protected reporting.
  7. Determine and complete required notifications within applicable deadlines.
  8. Remediate causes, record decisions and verify closure and lessons learned.

Records

  • Security design, access approvals and reviews including MFA for privileged users per Section 13.4.2
  • Logs, monitoring and resilience evidence including vulnerability testing results
  • Incident register, assessment and preserved evidence with heightened confidentiality for compliance-sensitive records per Section 8
  • Notifications, remediation and closure review

Relationships

History

  • 2026-07-28: Enriched with operational details from PDF sections 8, 11, and 13.4.2 — added full eight-item security measures list, MFA for privileged users, outsourced vulnerability testing, compliance-sensitive record handling, and need-to-know access restriction.
  • 2026-07-26: Created from sections 8, 11 and 13.4 of the approved PRIV Manual.