Special Personal Data:
Data regarding individuals’ race, ethnic origin, political views, philosophical beliefs, religion, sect or other beliefs, appearance and dress, membership in associations, foundations or unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data are special personal data.
2.3. ENVIRONMENTS WHERE PERSONAL DATA IS STORED
| Electronic Media |
Non-Electronic Media |
- • Servers (Domain, backup, e-mail, database, web, file sharing, etc.) Software (office software.)
- • Information security devices (firewall, attack detection and prevention, log file, antivirus, etc.)
- • Personal computers (Desktop, laptop)
- • Mobile devices (phone, tablet, etc.)
- • Optical disks (CD, DVD, etc.)
- • Removable memories (USB, Memory Card, etc.)
|
- • Printer, scanner, photocopier
- • Paper
- • Manual data recording systems (survey forms, visitor log)
- • Written, printed, visual media
- • Unit cabinets
|
2.4.PURPOSES OF PROCESSING PERSONAL DATA:
As a company, we process personal data for purposes similar to, but not limited to, the following:
• Carrying out legal compliance processes,
• Managing operations,
• Carrying out financial and fiscal affairs,
• Determining and implementing commercial and business strategies,
• Fulfilling service obligations based on the service contract,
• Fulfilling employer responsibilities,
• Ensuring job security, managing, supervising and performing the job,
• Providing information about possible changes in our service terms,
• Organizing all records and documents that will form the basis of transactions in electronic (internet/mobile etc.) or physical environments,
• Providing information to public officials upon request and in accordance with the legislation on matters related to public safety,
• Fulfilling legal obligations and exercising rights arising from the current legislation,
• Fulfilling legal obligations in the event that the relevant authority requests and responds are mandatory within the scope of judicial and administrative investigations,
• Carrying out emergency management processes,
• Conducting communication activities,
• Conducting accounting and finance activities,
• Conducting information security processes,
• Ensuring physical space security,
• Conducting assignment processes,
• Following up and conducting legal affairs,
• Fulfilling legal obligations,
• Conducting communication activities,
• Planning human resources processes,
• Conducting / supervising business activities,
• Conducting occupational health / safety activities,
• Receiving and evaluating suggestions for improving business processes,
• Conducting business continuity activities,
• Conducting logistics activities,
• Ensuring quality standards,
• Keeping entries and exits to the institution building under control and preventing unauthorized entries,
• Conducting goods / service purchasing processes,
• Conducting goods / service after-sales support services,
• Conducting goods / service sales processes,
• Conducting goods / service production and operation processes,,
• Ensuring the security of goods resources.
• Increasing customer reliability,
• Conducting contract processes,
• Following up on requests/complaints,
• Ensuring the security of movable goods and resources,
• Conducting supply chain management processes,
• Conducting supplier relationship management processes,
• Conducting wage policy,
• Issuing product invoices,
• Conducting product policy,
• Conducting marketing processes of products/services,
• Foreign personnel work and residence permit procedures,
• Conducting talent/career development activities,
• Providing information to authorized persons, institutions and organizations,
• Conducting management activities,
• Creating and following up visitor records,
• Conducting storage and archive activities.
SECTION 3
ISSUES RELATED TO THE PROTECTION OF PERSONAL DATA:
3.1. Ensuring the Security of Personal Data:
In accordance with Article 12 of the Law, our Company takes the necessary measures according to the nature of the data to be protected in order to prevent unlawful disclosure, access, transfer of personal data or any other security deficiencies that may occur. In this context, our Company takes administrative measures, carries out or has audits carried out in accordance with the guidelines published by the Personal Data Protection Board (“Board”) to ensure the necessary level of security.
All our employees, stakeholders, guests, visitors and relevant third parties are obliged to cooperate throughout the Company in the operation, activities and processes and implementation of the Company’s Personal Data Protection Policy throughout the Company, and in preventing legal risks and imminent danger. All organs and departments of the Company are responsible for overseeing compliance with the Company’s Personal Data Protection Policy.
All personnel and employees are obliged to ensure that the data processed by the Company and under their responsibility are kept securely and not disclosed to third parties unless they sign a confidentiality agreement.
3.2. Protection of Special Personal Data
The Law has given special importance to certain personal data due to the risk of causing victimization or discrimination when processed illegally. These data are; data related to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, association, foundation or union membership, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data. Our Company is meticulous in protecting special personal data determined as “special” by the Law and processed in accordance with the law. In this context, the technical and administrative measures taken by the Company for the protection of personal data are meticulously implemented in terms of special personal data and the necessary controls are provided within the Company. Detailed information on the processing of special personal data is provided in section 4.3 (“Processing of Special Personal Data”) of this Policy.
3.3. Increasing Awareness and Supervision of Business Units Regarding the Protection and Processing of Personal Data
Our company ensures that the necessary training is organized for business units to increase awareness on preventing unlawful processing of personal data, unlawful access to personal data and ensuring the preservation of personal data. The necessary systems are established to raise awareness of the company employees on the protection of personal data, and when necessary, consultants are employed on the subject. In this regard, our company evaluates the participation in relevant trainings, seminars and information sessions, and updates and renews its trainings in parallel with the updating of the relevant legislation.
3.4. Increasing the Awareness and Supervision of Business Partners and/or Suppliers Regarding the Protection and Processing of Personal Data:
The Company ensures that the necessary documents are prepared for business partners and/or suppliers in order to increase awareness of preventing the unlawful processing of personal data, unlawful access to data and ensuring the preservation of data. In addition, mutual awareness is ensured by signing confidentiality commitments.
SECTION 4
ISSUES RELATED TO THE PROCESSING OF PERSONAL DATA
One of the issues that is of primary importance for the Company is to act in accordance with the general principles stipulated in the legislation in the processing of personal data. In this context, the Company acts in accordance with the principles listed below in the processing of personal data in accordance with the Constitution and the Personal Data Protection Law.
4.1. Processing of Personal Data in Accordance with the Principles Stipulated in the Legislation
4.1.1. Carrying out Personal Data Processing Activities in Accordance with Law and the Rule of Integrity
In accordance with Article 4 of the Personal Data Protection Law, the Company carries out personal data processing activities in accordance with the law and the rules of honesty; accurately and up-to-date when necessary; for specific, clear and legitimate purposes; and in a purpose-related, limited and proportionate manner.
In this context, the Company takes into account the requirements of proportionality in the processing of personal data and does not use personal data other than as required for the purpose.
4.1.2. Ensuring Personal Data is Accurate and Up-to-Date Where Necessary
Necessary measures are taken in data processing procedures to ensure that the processed data is accurate and up-to-date, and the Data Subject is provided with the opportunity to update their data and to correct any errors in their processed data, if any.
4.1.3. Processing for Specified, Clear and Legitimate Purposes
Personal data is processed in a limited and proportionate manner, in connection with clearly and precisely determined purposes. Personal data that is not relevant or does not need to be processed is avoided. Therefore, unless there is a legal requirement, we do not process special personal data, or when we need to process it, we provide information on the subject and obtain explicit consent.
4.1.4. Being Relevant, Limited and Proportionate to the Purpose of Processing
Personal data is processed in a limited and proportionate manner, in connection with clearly and precisely determined purposes. Personal data that is not relevant or does not need to be processed is avoided. Therefore, unless there is a legal requirement, we do not process special personal data, or when we need to process it, we provide information on the subject and obtain explicit consent.
4.1.5. Storage for the Period Stipulated in the Relevant Legislation or Necessary for the Purpose for which they are Processed
In accordance with Article 138 of the Turkish Penal Code and Articles 4 and 7 of the Personal Data Protection Law, the Company retains the personal data it processes only for the period stipulated in the relevant legislation and laws or required for the purpose of processing personal data.
In this context, the Company first determines whether a period is stipulated in the relevant legislation for the storage of personal data, and if a period is specified, it acts in accordance with this period. If there is no legal period, personal data is stored for the period necessary for the purpose for which it is processed. At the end of the specified storage periods, personal data is destroyed in accordance with the periodic destruction periods or the application of the Relevant Person and with the specified destruction methods (deletion and/or destruction and/or anonymization).
Details are specified in the Personal Data Storage and Destruction Policy.
4.2.Conditions for Processing Personal Data
Unless the personal data owner gives explicit consent, the basis for personal data processing may be only one of the conditions specified below, or more than one condition may be the basis for the same personal data processing activity. If the processed data is special personal data, the conditions set forth in heading 4.3 (“Processing of Special Personal Data”) of this Policy shall apply.
I. Explicitly Provided in Laws
If the personal data of the relevant Person is clearly stipulated in the law, in other words, if there is a clear provision in the relevant law regarding the processing of personal data, the existence of this data processing condition can be mentioned.
II. Failure to Obtain the Explicit Consent of the Person Concerned Due to Actual Impossibility
If the processing of personal data is necessary to protect the life or physical integrity of the person or another person who is unable to give his/her consent due to a de facto impossibility or whose consent cannot be validated, the personal data of the Relevant Person may be processed.
III. Direct Interest in the Establishment or Performance of the Contract
This condition may be deemed to be fulfilled if the processing of personal data is necessary, provided that it is directly related to the establishment or performance of a contract to which the Data Subject is a party.
IV. Fulfillment of Legal Obligations by the Data Controller
If processing is necessary for the Company to fulfill its legal obligations, the Personal Data of the Relevant Person may be processed.
V. Publication of Personal Data by the Personal Data Subject
If the Data Subject has made his/her personal data public, the relevant personal data may be processed limitedly for the purpose of making it public.
VI. Data Processing is Necessary for the Establishment or Protection of a Right
If data processing is necessary for the establishment, exercise or protection of a right, the personal data of the Relevant Person may be processed.
VII. Data Processing is Necessary for the Legitimate Interest of the Data Controller
Personal data of the Data Subject may be processed if data processing is mandatory for the legitimate interests of the Company, provided that it does not harm the fundamental rights and freedoms of the Data Subject.
4.3-Processing of Special Personal Data
The Company shows special sensitivity in the processing of special personal data, the protection of which is believed to be of more critical importance to the Relevant Person in various respects. Special personal data is processed by our Company in accordance with the principles set forth in this Policy and by taking all necessary administrative and technical measures, including the methods to be determined by the Board, and in the presence of the following conditions:
(i) Special personal data other than health and sexual life may be processed without the explicit consent of the data owner if it is clearly provided for in the laws, in other words, if there is an explicit provision regarding the processing of personal data in the law governing the relevant activity. Otherwise, the explicit consent of the data owner will be obtained for the processing of such special personal data.
(ii) Special personal data related to health and sexual life may be processed without the explicit consent of persons or authorized institutions and organizations under the obligation of confidentiality for the purposes of protecting public health, conducting preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and their financing. Otherwise, the explicit consent of the data owner will be obtained for the processing of such special personal data.
4.3.1 Measures Regarding the Protection of Special Personal Data
In the processing of Special Personal Data, as stipulated in Article 6 of the Law, the Company takes the following measures as the data controller in accordance with the Board’s decision dated 31.01.2018 and numbered 2018/10:
A- A systematic, clearly defined, manageable and sustainable separate policy has been determined for the security of special personal data,
B- For the Employees involved in the processing of special personal data;
• Regular training is provided on the Law and related regulations and Special Personal Data security,
• Confidentiality agreements are made,
• The scope and duration of authorization of users authorized to access data are clearly defined,
• Authorization checks are carried out periodically,
• The authorizations of Employees who change their duties or leave their jobs are immediately revoked in this area. In this context, the Data Controller receives the inventory allocated to it back
C- If the environments where Special Personal Data is processed, stored and/or accessed are electronic media,
• Personal Data is stored using cryptographic methods,
• Transaction records of all movements performed on Personal Data are securely logged,
D- If the environments where Special Personal Data is processed, stored and/or accessed are physical media;
• Adequate security measures (against electrical leakage, fire, flood, theft, etc.) are taken according to the nature of the environment where Special Personal Data is located, The physical security of these environments is ensured and unauthorized entry and exit are prevented.
If E-Special Personal Data is to be transferred,
• If Personal Data needs to be transferred via e-mail, it is transferred encrypted with a corporate e-mail address or using a Registered Electronic Mail (KEP) account,
• If it needs to be transferred via media such as Portable Memory, CD, DVD, it is encrypted with cryptographic methods and the cryptographic key is kept in a different medium,
• If Personal Data needs to be transferred via paper, necessary precautions are taken against risks such as theft, loss or unauthorized persons viewing the document and the document is sent in “Confidential” format.
In addition to the above-mentioned precautions, technical and administrative measures are also taken to ensure the appropriate level of security specified in the Personal Data Security Guide published on the Personal Data Protection Authority’s website.
4.4. Information to the Personal Data Owner
The Company informs personal data owners in accordance with Article 10 of the Law and secondary legislation. In this context, the Company informs the relevant persons as the data controller about who processes personal data, for what purposes, with whom it is shared and for what purposes, by what methods it is collected and the legal reason, and the rights of data owners within the scope of processing their personal data.
4.5.Transfer of Personal Data
The Company acts in accordance with the decisions and regulations stipulated in the LPPD and taken by the KVK Board regarding the transfer of personal data. Our Company may transfer the personal data and special personal data of the Relevant Person to third parties (official and private authorities, third real persons) by taking the necessary security measures in line with the purposes of processing personal data in accordance with the law. In this regard, the Company acts in accordance with the regulations stipulated in Article 8 of the Law. In the event of groups of persons with whom personal data is/may be shared, the relevant person is informed with an information text.
4.5.1 Transfer of Personal Data
Even if the personal data owner does not have explicit consent, if one or more of the conditions specified below are present, personal data may be transferred to third parties by our Company, taking due care and taking all necessary security measures, including the methods prescribed by the Board.
• The relevant activities regarding the transfer of personal data are clearly prescribed by law,
• The transfer of personal data by the Company is directly related to and necessary for the establishment or execution of a contract,
• The transfer of personal data is mandatory for our Company to fulfill its legal obligation,
• The transfer of personal data by our Company is limited to the purpose of publicization, provided that the personal data has been made public by the data owner,
• The transfer of personal data by the Company is mandatory for the establishment, exercise or protection of the rights of the Company or the data owner or third parties,
• It is mandatory to carry out personal data transfer activities for the Company’s legitimate interests, provided that it does not harm the fundamental rights and freedoms of the data owner,
• It is mandatory for the person who is unable to express his/her consent due to actual impossibility or whose consent is not legally valid to protect his/her own life or physical integrity or that of another person.
In addition to the above, personal data may be transferred to foreign countries declared by the Board to have sufficient protection (“Foreign Country with Sufficient Protection”) if any of the above conditions are met. In the absence of sufficient protection, data may be transferred to foreign countries where the data controllers in Turkey and the relevant foreign country have undertaken to provide sufficient protection in writing and where the Board has granted its permission (“Foreign Country Where the Data Controller Undertakes to Provide Sufficient Protection”) in accordance with the data transfer conditions stipulated in the legislation.
4.5.2.Transfer of Special Personal Data:
Our company may transfer the Special Personal Data of the Relevant Person to third parties by taking the necessary administrative and technical measures in line with the data processing purposes, and the Special Personal Data of the Relevant Person, which it has obtained in accordance with the law. Accordingly, the Company may transfer the Special Personal Data to third parties if one of the processing conditions specified in the section above and the conditions below are present.
(i) Special personal data other than health and sexual life may be processed without the explicit consent of the data owner if it is clearly provided for in the laws, in other words, if there is an explicit provision in the relevant law regarding the processing of personal data. Otherwise, the explicit consent of the data owner will be obtained.
(ii) Special personal data related to health and sexual life may be processed without the explicit consent of persons or authorized institutions and organizations under the obligation of confidentiality for the purposes of protecting public health, conducting preventive medicine, medical diagnosis, treatment and care services, planning and managing health services and their financing. Otherwise, the explicit consent of the data owner will be obtained.
In addition to the above, personal data may be transferred to Foreign Countries with Sufficient Protection if any of the above conditions are present. If there is no adequate protection, the data may be transferred to Foreign Countries Where the Data Controller Undertakes to Provide Adequate Protection, in accordance with the data transfer conditions stipulated in the legislation.
SECTION 5
STORAGE AND DESTRUCTION OF PERSONAL DATA
Our Company stores personal data in accordance with the period required for the purpose for which they are processed and the minimum periods stipulated in the legal legislation applicable to the relevant activity. In this context, our Company first determines whether a period is stipulated in the relevant legislation for the storage of personal data, and if a period is specified, it acts in accordance with this period. If there is no legal period, personal data is stored for the period required for the purpose for which they are processed. At the end of the specified storage periods, personal data is destroyed in accordance with the periodic destruction periods or the application of the data owner and with the specified destruction methods (deletion and/or destruction and/or anonymization).
SECTION 6
RIGHTS OF PERSONAL DATA OWNERS AND EXERCISE OF THESE RIGHTS
6.1. Rights of the Personal Data Owner
Within the scope of the obligation to inform, the relevant person is informed by the company and the systems and infrastructures related to this information are established. The technical and administrative arrangements necessary for the relevant person to exercise his/her rights regarding his/her personal data are made by our company.
The relevant person has the right to;
• Learn whether personal data is processed,
• Request information if personal data is processed,
• Learn the purpose of processing personal data and whether it is used in accordance with its purpose,
• Know the third parties to whom personal data is transferred domestically or abroad,
• Request correction of personal data if it is processed incompletely or incorrectly,
• Request deletion or destruction of personal data if the reasons requiring processing of personal data are eliminated,
• Request notification of the correction, deletion or destruction processes mentioned above to third parties to whom personal data is transferred,
• Object to an adverse result arising from the analysis of processed data exclusively through automated systems,
• Request compensation for damages in the event of damages incurred due to unlawful processing of personal data.
6.2. Personal Data Owner’s Exercise of Rights
Relevant Persons may exercise their rights listed above by submitting their requests through the Relevant Person application form available at kirlioglu.com.tr. Detailed information on filling out the form or sending it to the Company is included in this form.
6.3. Our Company’s Response to Applications
Our Company takes the necessary administrative and technical measures to finalize applications made by personal data owners in accordance with the Law and secondary legislation. If the personal data owner submits his/her request regarding the rights set forth in section 6.1 (“Rights of Personal Data Owners”) to our Company in accordance with the procedure, our Company will finalize the relevant request free of charge as soon as possible and within 30 (thirty) days at the latest, depending on the nature of the request. However, if the transaction requires an additional cost, a fee may be charged in accordance with the tariff determined by the Board.
6.4. Cases in Which the Data Subject Cannot Claim His/Her Rights
Pursuant to Article 28/2 of the LPPD, except for the right to request compensation for damages, it will not be possible for the relevant persons to benefit from the rights specified in Article 11 of the Law in the following cases;
• Personal data processing is necessary for the prevention of crime or criminal investigation,
• Personal data that has been made public by the relevant person.
• Personal data processing is necessary for the performance of supervisory or regulatory duties and disciplinary investigation or prosecution by authorized public institutions and organizations and professional organizations with the status of public institution, based on the authority granted by the law.
• Personal data processing is necessary for the protection of the economic and financial interests of the State in relation to budget, tax and financial matters.
SECTION 7
SPECIAL CASES WHERE PERSONAL DATA IS PROCESSED
7.1. Camera Monitoring Activities Conducted at the Entrances and Inside the Company Buildings and Facilities
The Company carries out camera monitoring activities in accordance with the Law on Private Security Services and relevant legislation in order to ensure security in its buildings and facilities. The Company carries out security camera monitoring activities in accordance with the purposes stipulated in the relevant legislation in force and the personal data processing conditions listed in the Law in order to ensure security in its buildings and facilities.
In accordance with Article 10 of the Law, the Company informs the personal data owner with more than one method regarding camera monitoring activities. In addition, the Company processes personal data in a limited and proportionate manner in connection with the purpose for which they are processed in accordance with Article 4 of the Law.
The purpose of the Company’s video camera monitoring activities is limited to the purposes listed in this Policy. Accordingly, the monitoring areas, numbers and when monitoring will be carried out by security cameras are implemented in a sufficient and limited manner to achieve the security purpose. Only a limited number of employees have access to live camera images and records recorded and stored in a digital environment. The limited number of people who have access to the records declare that they will protect the confidentiality of the data they access with a confidentiality commitment.
7.2. Monitoring of Guest Entrances and Exits at and Inside Company Buildings and Facilities
The Company carries out personal data processing activities to monitor guest entries and exits in Company buildings and facilities for the purposes of ensuring security and as specified in this Policy. While obtaining the names and surnames of persons visiting Company buildings as guests or through texts hung at the Company or made accessible to guests in other ways, the owners of the personal data in question are informed in this context. The data obtained for the purpose of monitoring guest entries and exits are processed only for this purpose and the relevant personal data is recorded in the data recording system in a physical environment.
7.3.Website Visitors
Cookie records are used to improve the operation and use of the company’s official website. The aim is to make the time spent on the company’s official website more efficient and enjoyable. In addition, some cookies are used to remember preferences made on the website, thus providing users with an improved and personalized experience. Personal data is collected through cookies on the website, and the collected data can be processed, transferred and stored. For detailed information about the cookies used on the website, you can review the Cookie Policy on the official website.
SECTION 8
LIABILITIES REGARDING PERSONAL DATA PROCESSING ACTIVITIES
Our company must comply with the obligations set forth by the Personal Data Protection Law for data controllers. The main issues we are obliged to comply with in this context are listed below:8.1. Obligation to Register and Notify the Data Controllers Registry
Our Company is obliged to register with the Data Controllers Registry in accordance with Article 16 of the Personal Data Protection Law and the procedures and principles of the Regulation on the Data Controllers Registry, and the said obligation has been fulfilled by our Company.
8.2. Obligation to Inform the Data Owner
When the company collects personal data; first of all, the relevant persons are clearly informed and enlightened in accordance with Article 10 of the LPPD and the Communiqué on the Procedures and Principles to be Complied with in Fulfilling the Obligation to Inform. In our disclosure texts;
• The company’s title, full address and contact information,
• Information on the representative identity, if any,
• Personal data categories,
• For what purpose personal data will be processed,
• To whom and for what purpose processed personal data can be transferred,
• Data collection method and legal reason,
• The rights of the relevant person listed in Article 11 of the LPPD, are included as subheadings and contents. In addition to the information provided above, application methods are also listed in our disclosure text. With these methods, it is aimed to be transparent and accessible in the Protection of Personal Data.
As a company, we take care to ensure that this Policy, which is open to the public, is clear, understandable and easily accessible. In addition, the “Information Texts” regarding the Personal Data Protection Law for employees, job candidates, visitors, customers and camera systems can be reviewed on the company’s website.
8.3. Obligation to Ensure the Security of Personal Data
The Company is obliged to take all necessary technical and administrative measures to ensure the appropriate level of security in order to;
1. Prevent the unlawful processing of personal data,
2. Prevent unlawful access to personal data, and
3. Ensure the preservation of personal data, with the awareness of the importance of ensuring the security of personal data and the fundamental rights and freedoms of data owners, in accordance with Article 12 of the Personal Data Protection Law.
Aware of the importance of ensuring security in every respect within the Company, the Company takes the necessary technical and administrative measures to prevent the unlawful processing of personal data it processes, to prevent unlawful access to data and to ensure the preservation of data, in accordance with Article 12 of the Personal Data Protection Law, and to ensure the appropriate level of security, and the necessary inspections are carried out within this scope. The Company takes the necessary technical and administrative measures, within the technological possibilities, to ensure the lawful processing of personal data. The measures taken by our Company within this scope are as follows:
8.3.1. Administrative Measures
• Information Texts (Employee, Employee Candidate, Customer, Camera Systems, Covid-19 Outbreak Process) and Explicit Consent Texts have been prepared.
• Disciplinary regulations that include data security provisions are in place for employees.
• Training and awareness activities are carried out at certain intervals for employees on data security.
• Department access authorizations have been regulated.
• Training has been provided to the department to protect certain personal data.
• Confidentiality commitments have been made.
• Disciplinary regulations to be applied to employees who do not comply with security policies and procedures have been prepared.
• Signed contracts include data security provisions.
• Layered camera information texts have been hung in the areas where cameras are located.
• Employees have been informed about the technical and administrative risks related to the storage of personal data and awareness has been raised.
• A personal data processing inventory has been prepared.• Personal Data Protection Committee has been established.
• Personal data security policies and procedures have been determined.
• Personal data security issues are reported quickly.
• Personal data security is monitored.
• Necessary security measures are taken regarding entry and exit to physical environments containing personal data.
• Security of physical environments containing personal data is ensured against external risks (fire, flood, etc.).
• Security of environments containing personal data is ensured.
• Personal data is reduced as much as possible.
Protocols and procedures for special personal data security have been determined and implemented.
• Personnel duty and title lists have been prepared.
• Contracts have been made compatible with LPPD.
8.3.2. Technical Measures
• The company employs knowledgeable and experienced people to ensure data security and provides its personnel with the necessary training on the protection of personal data.
• Necessary internal controls are carried out within the scope of the established systems.
• Network security and application security are provided.
• An authorization matrix has been created for employees.
• Access logs are kept regularly.
• Corporate policies have been prepared and implemented on access, information security, usage, storage and destruction.
• Data masking measures are implemented when necessary.
• Authorizations of employees who change their duties or leave their jobs are revoked in this area.
• Up-to-date anti-virus systems are used.
• Personal data is backed up and the security of backed up personal data is also ensured.
• Periodic and/or random audits are carried out and carried out within the institution.
• Log records are kept in a way that prevents user intervention.
• Existing risks and threats have been determined.
• Data of special persons transferred on portable memory, CD, DVD are encrypted.
• Data processing service providers are audited at certain intervals regarding data security.
• Awareness of data processing service providers regarding data security is ensured.
8.4. Obligation to Fulfill Decisions Made by the KVK Board
The Company acts in accordance with the decisions made by the KVK Board, which is the executive body of the KVK Institution and operates to ensure that personal data is processed in accordance with fundamental rights and freedoms.
8.5. Obligation to Respond to Data Owner Applications
The Company, as the data controller, finalizes the requests of data owners regarding their personal data in accordance with Article 13 of the Personal Data Protection Law, as soon as possible and within thirty (30) days at the latest, depending on the nature of the request. Data owners must make their requests regarding their personal data in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller.
8.6. Obligation to Erase, Destroy and Anonymize Personal Data:
If all the processing conditions of personal data specified in Articles 5 and 6 of the LPPD are eliminated, personal data must be erased, destroyed or anonymized by the data controller ex officio or upon the request of the relevant person. In the erasure, destruction or anonymization of personal data, it is mandatory to act in accordance with the general principles in Article 4 of the Law and the technical and administrative measures to be taken within the scope of Article 12, the relevant legislative provisions, Board decisions and the personal data storage and destruction policy. The data controller is obliged to explain the methods it applies regarding the deletion, destruction and anonymization of personal data in its relevant policies and procedures. In accordance with Article 7 of the Regulation on the Erasure, Destroy or Anonymization of Personal Data mentioned above, the company has also established a Storage and Destruction Policy.
8.6.1 Conditions for Deletion, Destruction and Anonymization of Personal Data:
According to Article 138 of the Turkish Penal Code, Article 7 of the Personal Data Protection Law and the “Regulation on Deletion, Destruction and Anonymization of Personal Data”, personal data shall be deleted, destroyed or anonymized upon the company’s own decision or upon the request of the relevant person, in case the reasons requiring processing are eliminated, despite being processed in accordance with the provisions of the relevant law. The company has established a policy in this regard in accordance with the provisions of the regulation, and the destruction process is carried out according to the nature of the data in accordance with this policy. Periodic destruction dates have been determined by the company in accordance with this regulation, and a calendar has been created according to which periodic destruction will be carried out at various intervals with the commencement of the obligation.
SECTION 9
9.1. Implementatıon Of The Polıcy And Related Legıslatıon
The relevant legal regulations on the deletion and protection of personal data will primarily find their area of application. If there is a discrepancy between the current legislation and the Policy, the Policy accepts to find the area of application of the current legislation. The Policy is organized by concretizing the rules set forth by the relevant legislation within the scope of Company practices.
9.2. Enforcement Of The Polıcy
The effective date of this Policy is 09/01/2024. This Policy is published on the Company’s website, kırlıoğlu.com.tr, and made accessible to relevant persons upon the request of personal data owners.
9.3. Dıstrıbutıon
The Policy is published on the Company’s website and announced to third parties and Company employees.