PDF Source Sections

  • Section 2 (Key Principles), Section 6 (Special Categories of Data), Section 8 (Security & Risk Management), Section 13.2 (Guiding Principles — Risk-Based Application), Section 13.4.4 (Data Retention and Minimization)

Objective

Ensure sensitive data is minimized, protected, retained for justified periods and securely disposed when obligations expire.

Control Activity

Compliance and Technology review classification, retention exceptions, legal holds and scheduled disposal at least annually and require approval and evidence for deletion or continued retention. The review verifies that: data is classified by the three risk tiers from Section 13.2 (high-risk: AML/CFT and wallet transaction data; moderate-risk: employee and vendor data; low-risk: non-confidential business information); special-category data (religion, ethnicity, health, political, union, or criminal records) is prohibited per Section 6 unless required by law or with explicit consent, and where processed is stored with higher encryption, access limited to compliance staff only, and all access logged; retention schedules reflect the proportional periods from Section 13.4.4 (AML/CFT and STR data: 5 years minimum per FATF; HR and customer records: statutory or contractual period only; low-risk records: minimal retention per Article 10 purpose limitation); and encryption is applied in transit and at rest with role-based access controls and system logging per Section 8.

Evidence

  • Expected evidence: Data classification aligned to the three risk tiers from Section 13.2
  • Expected evidence: Special-category data prohibition and exception evidence per Section 6 (with higher encryption, compliance-only access, and logged access)
  • Expected evidence: Retention schedule reflecting AML/CFT 5-year minimum, statutory/contractual HR periods, and Article 10 purpose limitation per Section 13.4.4
  • Expected evidence: Legal holds and retention exceptions
  • Expected evidence: Access, encryption (in transit and at rest), and logging evidence per Section 8
  • Expected evidence: Disposal review, approval and deletion evidence
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample record categories and expired records for correct classification (three tiers per Section 13.2), Section 6 special-category prohibition and safeguard verification, retention basis (5-year AML/CFT, Article 10), holds, encryption in transit/at rest per Section 8, and defensible disposal
  • Testing frequency: annual

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-28: Enriched with verification requirements from PDF sections 2, 6, 8, 13.2, and 13.4.4 — added three-tier risk classification, Section 6 special-category prohibition and safeguards, specific retention periods (5-year FATF, Article 10), and encryption in transit/at rest verification.
  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.