Purpose

Translate the VASP Ordinance into a testable BCMS requirement for personal data access and account access needed for VASP services.

Normative

Bitkaya shall process client personal data for VASP services only with required client consent and only to the extent necessary for the provision of those services.

Descriptive

The data-control framework should cover consent, data minimization, retention, access control, use limitation and evidence of authorization. Where banking access issues affect VASP services, Bitkaya should retain evidence of objective, non-discriminatory and proportionate account-access handling and any CBCS notifications required of account providers.

Source reference: VASP Ordinance, Articles 43 and 44; commencement instrument Publicatieblad A 2025 No. 91, Article 1.

Assurance Assertions

  • Client consent and data-use basis are recorded where required.
  • Personal data access is limited to what is necessary for service delivery.
  • Account-access dependencies and related regulatory evidence are tracked where applicable.

Relationships

Assurance

  • Source verified: yes
  • Implementation linked: partial; mapped to current BCMS implementation objects while detailed VASP coverage remains planned
  • Wording unambiguous: review

History

  • 2026-07-25: Created from SRC-VASP-001, including embedded commencement details.
  • 2026-07-26: Added policy, process and procedure mappings; detailed VASP implementation remains planned.