Purpose
Maintain accountable privacy oversight, role-based competence, proportionate controls, independent challenge and continuous improvement.
PDF Source Sections
- Section 3 (Roles & Responsibilities), Section 11 (Governance & Oversight), Section 13 (Proportionality and Scalability — all sub-sections 13.1–13.6)
Steps
- Define privacy governance roles, reporting, escalation, combined-role safeguards and independent challenge. Per Section 13.3, oversight and control structures remain aligned with CBCS and privacy law requirements: Supervisory Board approves the proportionality rationale; Managing Board implements proportional data protection processes and allocates resources for high-risk data processing (e.g., AML, KYC); Corporate Operational Risk Function (CORF) independently challenges proportionality justifications and reviews privacy impact assessments; Data Protection Officer (DPO) ensures compliance with the Curaçao Privacy Act and oversees the proportional application of data subject rights; Internal Audit periodically reviews proportionality controls and reports findings to the Supervisory Board.
- Provide induction and periodic training proportionate to role, data access and processing risk. Per Section 13.4.6, staff receive combined privacy, compliance, and cybersecurity training — content and frequency are proportionate to roles and data access level, ensuring all employees understand data protection responsibilities.
- Review processing, rights requests, incidents, access, retention, vendors, transfers, complaints, changes and overdue actions at least annually. Per Section 11, periodic review should consider whether privacy controls remain appropriate for current processing activities, whether new systems, vendors, products, or jurisdictions create new privacy risk, whether role-based access to compliance-sensitive data remains appropriate, whether retention practices remain aligned with legal and regulatory requirements, and whether cross-manual consistency is maintained where changes are made to Bitkaya’s core control frameworks. Where material changes are made to onboarding, sanctions screening, transaction monitoring, internal case handling, or regulatory reporting processes, the privacy impact should be reassessed as appropriate.
- Assess whether controls remain proportionate to data sensitivity, business scale, complexity, technology, jurisdictions and risk. Per Section 13.2, the five guiding principles are: risk-based application (high-risk: AML/CFT and wallet transaction data; moderate-risk: employee and vendor data; low-risk: non-confidential business information), startup proportionality (combined roles under CORF with compensating controls such as dual sign-off and independent audit oversight), scalability and growth readiness, efficiency and practicality (automation, secure cloud services, and third-party DPA-compliant processors), and continuous alignment (reviewed annually or upon major operational, technological, or regulatory change to ensure continued alignment with the Curaçao Privacy Act, CBCS standards, and FATF recommendations).
- Document compensating controls for combined roles or limited staffing and obtain appropriate approval. Per Section 13.5, all proportionality decisions are formally documented, including justification linked to business size and operational risk, compensating controls for combined roles or limited staffing, and reference to relevant CBCS or Curaçao Privacy Act provisions. The documentation is stored in the Privacy Compliance Repository, reviewed annually by the CORF and Internal Audit, and available for supervisory inspection.
- Coordinate control testing, internal audit and response to supervisory findings.
- Approve improvement actions, resources, separation of duties, tooling and assurance as maturity or risk increases. Per Section 13.6, Bitkaya reviews its proportionality approach as part of its annual Data Protection and Operational Risk Review; adjustments are made based on changes in the CBCS regulatory framework or FATF recommendations, business or technological evolution (e.g., new wallet systems), and audit findings or supervisory feedback. As Bitkaya grows, the proportionality model will progressively evolve toward a more segmented governance structure, consistent with the CBCS’s maturity expectations and best practices under ISO 27701 (Privacy Information Management).
- Report material gaps and the annual review to management and the Board.
Records
- Governance and responsibility matrix covering the five oversight roles from Section 13.3
- Training plan, content, attendance and assessment with combined privacy/compliance/cybersecurity content per Section 13.4.6
- Annual privacy and proportionality review covering the Section 11 review criteria and Section 13.2 guiding principles
- Proportionality documentation stored in the Privacy Compliance Repository per Section 13.5
- Control testing, audit and supervisory records
- Improvement plan, approvals and closure evidence with ISO 27701 maturity trajectory per Section 13.6
Relationships
- Policy: POL-PRIV-001 Data Protection and Privacy Manual
- Process: PRC-CPO-001 Client Protection and Operations
- Control: CTRL-PRIV-007 Ensure Privacy Governance Training and Proportionality Are Reviewed
History
- 2026-07-28: Enriched with operational details from PDF sections 3, 11, and 13.1–13.6 — added five oversight roles (Supervisory Board, Managing Board, CORF, DPO, Internal Audit), five guiding principles, Privacy Compliance Repository documentation, combined training model, and ISO 27701 maturity trajectory.
- 2026-07-26: Created from sections 3, 11 and 13 of the approved PRIV Manual.