Purpose
Translate the VASP Ordinance into a testable BCMS requirement for personal data access and account access needed for VASP services.
Normative
Bitkaya shall process client personal data for VASP services only with required client consent and only to the extent necessary for the provision of those services.
Descriptive
The data-control framework should cover consent, data minimization, retention, access control, use limitation and evidence of authorization. Where banking access issues affect VASP services, Bitkaya should retain evidence of objective, non-discriminatory and proportionate account-access handling and any CBCS notifications required of account providers.
Source reference: VASP Ordinance, Articles 43 and 44; commencement instrument Publicatieblad A 2025 No. 91, Article 1.
Assurance Assertions
- Client consent and data-use basis are recorded where required.
- Personal data access is limited to what is necessary for service delivery.
- Account-access dependencies and related regulatory evidence are tracked where applicable.
Relationships
- Source: SRC-VASP-001 Landsverordening toezicht virtuele activa dienstverleners
- Policies: POL-AML-001 AML CTF CPF Compliance Manual, POL-ECM-001 Enterprise Compliance Manual
- Processes: PRC-FCI-001 Financial Crime and Integrity, PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Procedures: PROC-AML-002 Perform Client Acceptance CDD EDD and Risk Classification, PROC-AML-003 Perform Sanctions Screening and Restrictive Measures Escalation, PROC-AML-006 Apply Travel Rule and Counterparty VASP Due Diligence, PROC-AML-007 Maintain AML Records and Data Retention
- Controls: CTRL-MCT-005 Ensure Client Assets and Custody Are Safeguarded, CTRL-EMP-003 Ensure Employee Conduct Conflicts Assets and Data Are Controlled, CTRL-RMF-004 Ensure Material Risk Scenarios Are Tested, CTRL-RMF-007 Ensure Third Party Counterparty and Resilience Risks Are Controlled, CTRL-RMF-009 Ensure Fraud Concerns Are Stopped Escalated and Recorded, CTRL-ICA-002 Ensure Core Internal Control Coverage Is Complete, CTRL-ESG-005 Ensure Ethical Conduct and Governance Standards Operate, CTRL-PRIV-002 Ensure Data Subject Requests and Privacy Information Are Controlled, CTRL-PRIV-003 Ensure Sensitive Data Retention and Disposal Are Controlled, CTRL-PRIV-004 Ensure Transfers Processors and Data Agreements Are Controlled, CTRL-PRIV-005 Ensure Personal Data Security Access and Incidents Are Controlled, CTRL-PRIV-006 Ensure AML Sanctions and Regulatory Data Remain Confidential, CTRL-ODOO-003 Ensure Odoo Backup Storage Access Retention and Disposal Are Controlled, CTRL-COMP-002 Ensure Complaints Are Registered and Acknowledged on Time, CTRL-COMP-003 Ensure Complaints Are Risk Triaged and Assigned Impartially, CTRL-COMP-004 Ensure Complaint Investigations Are Fair Complete and Evidenced, CTRL-COMM-004 Ensure Onboarding and Restricted Matter Communications Are Safe, CTRL-SAFU-003 Ensure Client Asset Movements Are Authorized and Permitted, CTRL-SAFU-006 Ensure Custody Technology Access Keys and Recovery Are Secure, CTRL-TRAIN-004 Ensure Quarterly Awareness Activity Occurs
- Systems: SYS-KYT-001 Crystal Intelligence Blockchain Analytics, SYS-IT-001 Odoo Automated Compliance Monitoring
- Issues: ISS-KYT-001 Approve and Validate Crystal Intelligence Calibration, ISS-COMP-001 Confirm Complaints Channels Register and CBCS Source, ISS-COMM-001 Confirm Licensing Claims Approval Workflow and Operating Evidence, ISS-SAFU-001 Confirm Safeguarding Architecture Legal Protections and Operating Evidence, ISS-IT-001 Confirm Odoo Compliance Automation Security Testing and Operating Evidence, ISS-OTC-001 Review and Complete Principal OTC Service Flow Controls
- Publications: PUB-KYT-002 Crystal Intelligence Calibration and Change Record, PUB-IT-001 Automated Compliance Monitoring Controls in Odoo SOP, PUB-TRAIN-001 Compliance Framework Onboarding for New Employees, PUB-TRAIN-002 Compliance Department Training, PUB-TRAIN-003 Front Office AML and Sanctions Training, PUB-TRAIN-005 IT Compliance Training, PUB-KYT-001 Odoo Pre-Trade and Post-Trade KYT Controls SOP, PUB-OTC-001 Bitkaya Principal OTC Service Flows Memo
Assurance
- Source verified: yes
- Implementation linked: partial; mapped to current BCMS implementation objects while detailed VASP coverage remains planned
- Wording unambiguous: review
History
- 2026-07-25: Created from SRC-VASP-001, including embedded commencement details.
- 2026-07-26: Added policy, process and procedure mappings; detailed VASP implementation remains planned.