PDF Source Sections

  • Section 3 (Roles & Responsibilities — Data Processor), Section 7 (Data Transfers), Section 10 (Data Processing Agreements), Section 13.4.5 (Third-Party Data Processing and Outsourcing)

Objective

Ensure processors and international transfers are risk-assessed, contractually controlled, approved and monitored.

Control Activity

Compliance, Technology and the business owner approve privacy and transfer assessments and required contractual safeguards before data access and review material processors at least annually. The review verifies that: the processor is among the types identified in Section 3 (onboarding vendors, sanctions screening providers, blockchain analytics providers, cloud providers, case-management system providers); the Section 7 transfer safeguard checklist is addressed (contractual safeguards, adequacy mechanisms or equivalent legal protections, role-based access restrictions, encryption and secure transmission controls, documented vendor due diligence) with particular care for cross-border tools used for onboarding, sanctions screening, blockchain analytics, transaction monitoring, or compliance case management; the DPA contains all eight mandatory clauses from Section 10 (documented processing instructions, confidentiality obligations, minimum security standards, breach notification obligations, sub-processor restrictions, access control expectations, data location or cross-border transfer considerations, audit or oversight rights); and simplified but mandatory clauses on purpose limitation, breach notification, and security obligations per Articles 13–14 of the Curaçao Privacy Act are included per Section 13.4.5.

Evidence

  • Expected evidence: Processor, location and sub-processor inventory identifying processor types per Section 3
  • Expected evidence: Due diligence and transfer assessments covering the Section 7 safeguard checklist
  • Expected evidence: Data-processing agreements containing all eight Section 10 mandatory clauses and Articles 13–14 Privacy Act provisions per Section 13.4.5
  • Expected evidence: Monitoring, incident, renewal and exit evidence
  • Evidence location: source evidence in SYS-OUT-001 Outsourcing Register, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample processors for complete assessment, Section 7 safeguard checklist, all eight Section 10 mandatory DPA clauses, Articles 13–14 Privacy Act provisions per Section 13.4.5, approved access, monitored changes and controlled exit provisions
  • Testing frequency: before engagement and annual

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-28: Enriched with verification requirements from PDF sections 3, 7, 10, and 13.4.5 — added processor type verification, Section 7 safeguard checklist, all eight Section 10 mandatory DPA clauses, and Articles 13–14 Privacy Act provisions.
  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.