PDF Source Sections

  • Section 4 (Rights of Data Subjects), Section 13.4.3 (Data Subject Rights Management)

Objective

Ensure rights requests are authenticated, assessed, approved and answered on time and privacy information remains accurate.

Control Activity

Compliance monitors the rights-request register and deadlines, reviews legal restrictions and sensitive responses before release, and reviews notices after material processing change. The review verifies that: each request is assessed on a case-by-case basis per Section 4; the seven recognized rights (access, correction, information, objection, restriction, portability, erasure) are correctly identified; the non-absolute rights limitation under Section 4 is applied where AML/CTF/CPF, sanctions, fraud prevention, safeguarding, legal retention, or regulatory reporting obligations require retention, restriction, screening, escalation, or disclosure; responses do not breach applicable confidentiality or anti-tipping-off obligations per Section 4; and the 4-week statutory timeframe under Article 27 of the Curaçao Privacy Act is met per Section 13.4.3 (automated tools for DSAR intake and response tracking, or manual workflows for limited data volumes, both subject to the statutory timeframe).

Evidence

  • Expected evidence: Rights-request register and deadline tracking with Article 27 4-week timeframe verification
  • Expected evidence: Identity, search, assessment and approval evidence documenting case-by-case evaluation per Section 4
  • Expected evidence: Responses, redactions and secure delivery with anti-tipping-off review per Section 4
  • Expected evidence: Privacy notices and change reviews
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample requests for timely logging (Article 27 4-week deadline), identity verification, complete search, justified case-by-case decision per Section 4, anti-tipping-off review, approved response, and secure delivery
  • Testing frequency: per request and quarterly register review

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-28: Enriched with verification requirements from PDF sections 4 and 13.4.3 — added case-by-case assessment, non-absolute rights limitation, anti-tipping-off check, and Article 27 4-week statutory timeframe.
  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.