Purpose

Protect CDD, beneficial-ownership, wallet, screening, monitoring, case, UTR and regulatory information while enabling required AML, sanctions and supervisory processing.

PDF Source Sections

  • Section 1 (Purpose and Scope), Section 4 (Rights of Data Subjects), Section 5 (Legal Bases), Section 8 (Security & Risk Management), Section 9 (FATF-Specific Data Handling)

Steps

  1. Identify compliance-sensitive data and restrict it to authorized personnel with an operational, legal or control need to know. Per Section 8, access to data relating to sanctions screening, internal compliance escalations, wallet identifiers, transaction monitoring, and regulatory reporting must be restricted strictly to those with an operational, legal, or control need to know.
  2. Collect, verify, analyze and retain required CDD, wallet, transaction, screening and case data under the applicable compliance procedure. Per Section 9, this includes: identification and verification data; source of funds and source of wealth information; beneficial ownership and control information; sanctions and PEP screening results; blockchain wallet identifiers and risk indicators; unusual activity review records; internal case-management records and internal classifications; and external UTR reporting records.
  3. Keep alerts, false positives, internal classifications, escalation rationale, restrictive measures and UTR records confidential. Per Section 8, these are compliance-sensitive records and must be handled with heightened confidentiality and control.
  4. Separate internal escalation, restrictive action, FIU reporting, CBCS notification and data-subject response decisions. Per Section 5, where Bitkaya processes data for sanctions screening, beneficial ownership review, unusual activity handling, internal case classification, or UTR reporting, the primary legal basis will ordinarily be legal obligation and related compliance necessity, rather than consent.
  5. Prevent direct or indirect tipping off through communications, access, request handling and disclosures. Per Section 4, data subjects shall not be informed in a manner that would breach applicable confidentiality or anti-tipping-off obligations.
  6. Release information to competent authorities only through authorized channels and preserve proof of authority, approval and transmission. Per Section 9, such data may be retained, reviewed, internally escalated, or disclosed to competent authorities where required by law or regulation. Bitkaya must ensure that privacy protections are applied consistently with FATF-aligned obligations and that privacy rights are not interpreted in a way that undermines legal compliance.
  7. Apply required retention and secure disposal after legal and supervisory obligations expire.
  8. Review access and confidentiality incidents and remediate weaknesses promptly.

Records

  • Data classification, access approvals and logs with need-to-know restriction per Section 8
  • CDD, screening, monitoring and case records covering the eight FATF data categories from Section 9
  • Reporting and disclosure authorization with legal obligation basis per Section 5
  • Retention, review and confidentiality-incident evidence with anti-tipping-off review per Section 4

Relationships

History

  • 2026-07-28: Enriched with operational details from PDF sections 1, 4, 5, 8, and 9 — added eight FATF data categories, compliance-sensitive record types, anti-tipping-off obligation, legal-obligation basis for AML/sanctions processing, and FATF-aligned privacy limitation.
  • 2026-07-26: Created from sections 1, 4, 5, 8 and 9 of the approved PRIV Manual.