PDF Source Sections
- Section 3 (Roles & Responsibilities), Section 11 (Governance & Oversight), Section 13 (Proportionality and Scalability — all sub-sections 13.1–13.6), Section 13.4.6 (Training and Awareness)
Objective
Ensure privacy governance, competence, proportionality, assurance and improvement remain appropriate to Bitkaya’s scale and risk.
Control Activity
Compliance completes an annual privacy review covering governance, training, combined-role safeguards, control performance, material changes, audit results and proportionality and obtains management and Board oversight. The review verifies that: the five oversight roles from Section 13.3 are functioning (Supervisory Board approves proportionality rationale; Managing Board implements proportional data protection processes and allocates resources for high-risk data processing; CORF independently challenges proportionality justifications and reviews privacy impact assessments; DPO ensures compliance with the Curaçao Privacy Act and oversees proportional application of data subject rights; Internal Audit periodically reviews proportionality controls and reports to the Supervisory Board); the five guiding principles from Section 13.2 are applied (risk-based application, startup proportionality, scalability and growth readiness, efficiency and practicality, continuous alignment); combined privacy, compliance, and cybersecurity training per Section 13.4.6 is proportionate to roles and data access level; proportionality decisions are formally documented per Section 13.5 (justification linked to business size and operational risk, compensating controls, reference to CBCS or Curaçao Privacy Act provisions) and stored in the Privacy Compliance Repository, reviewed annually by CORF and Internal Audit, and available for supervisory inspection; and the continuous improvement trajectory per Section 13.6 is tracked (adjustments based on CBCS/FATF changes, business/technological evolution, audit findings) with progressive evolution toward ISO 27701-aligned segmented governance.
Evidence
- Expected evidence: Governance and responsibility matrix covering the five oversight roles from Section 13.3
- Expected evidence: Training records and assessments verifying combined privacy/compliance/cybersecurity content proportionate to role and data access level per Section 13.4.6
- Expected evidence: Annual privacy and proportionality review covering the five Section 13.2 guiding principles and five Section 11 review criteria
- Expected evidence: Proportionality documentation in the Privacy Compliance Repository per Section 13.5 (justification, compensating controls, CBCS/Privacy Act references)
- Expected evidence: Control testing, audit and supervisory findings
- Expected evidence: Improvement plan, approvals and closure evidence with ISO 27701 maturity trajectory per Section 13.6
- Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: inspect annual review completeness (five Section 13.3 oversight roles, five Section 13.2 guiding principles), training coverage per Section 13.4.6, Privacy Compliance Repository documentation per Section 13.5, approved proportionality decisions, and timely action closure with ISO 27701 trajectory per Section 13.6
- Testing frequency: annual
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-28: Enriched with verification requirements from PDF sections 3, 11, 13.1–13.6, and 13.4.6 — added five oversight roles, five guiding principles, Privacy Compliance Repository documentation, combined training model, and ISO 27701 maturity trajectory.
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.