İDEA MODA KONF. SAN VE TİC.LTD ŞTİ
PERSONAL DATA PROCESSING, PROTECTION AND PRIVACY
POLICY
PREPARED BY : HUMAN RESOURCES
APPROVED BY : COMPANY DIRECTOR
VERSION HISTORY
|
Version No.
|
Release Date
|
Explanation Of Changes
|
|
1
|
…/…/… Publication Date
|
All
|
Contents
Page
- PURPOSE AND SCOPE ................................................................................................. 3
- DEFINITIONS .............................................................................................................. 3
- POLICY IMPLEMENTATION AND RESPONSIBILITIES ............................................4
- POLICY PRINCIPLES ................................................................................................4
- BASIC PRINCIPLES ADOPTED BY IDEA ……………….…..….4
- PERFORMING PERSONAL DATA PROCESSING ACTIVITIES IN ACCORDANCE WITH THE KVKK (Law on Protection of Personal Data) …...5
- TRANSFER OF PERSONAL DATA IN ACCORDANCE WITH THE KVKK (Law on Protection of Personal Data).………..………7
- ENSURING THE SECURITY OF PERSONAL DATA …………………………………..……….7
- Administrative Measures to be Taken ……………………………………………………………..……………...7
- Technical Measures to be Taken……………………………………………………………………………8
- Conducting Audit Activities Regarding the Protection of Personal Data…….……8
- Measures to Prevent Unlawful Disclosure of Personal Data………..8
5. OBLIGATIONS REGARDING PERSONAL DATA PROCESSING ACTIVITIES …………………………….8
- Registration Obligation with the Data Controllers Registry (VERBIS)………….…………………….9
- Obligation to Inform the Data Subject……………………………………………………….9
- Obligation to Collect and Transfer Personal Data in Accordance with the Law…..9
- Obligation to Ensure the Security of Personal Data……………………………………..9
- Obligation to Comply with Decisions Issued by the Personal Data Protection Board……….9
- Obligation to Respond to Data Subject Requests…………………………………9
PUBLICATION AND STORAGE OF THE E-POLICY …………………………………..………………10
F - UPDATING THE POLICY …………………………………..…………………………………………..10
- PURPOSE AND SCOPE
IDEA, recognizing that the rule of law is one of the cornerstones of social life, has adhered to general legal principles since its establishment and strives to protect the rights and interests of individuals to the utmost extent. IDEA's Personal Data Processing, Protection, and Privacy Policy ("IDEA GDPR Policy") sets out the fundamental principles regarding IDEA's compliance with the regulations in the Law No. 6698 on the Protection of Personal Data ("PDP Law") and outlines the obligations IDEA must fulfill in this regard.
By implementing IDEA's GDPR policies across our campuses, we will ensure the sustainability of IDEA's adopted data security principles.
IDEA's Personal Data Protection Policy has been prepared as a guide for the implementation of the regulations set forth in the Personal Data Protection Law and related legislation. Personal data of IDEA employees, job applicants, visitors, and employees of third parties, institutions, or organizations with whom IDEA has a relationship as a service provider, as well as personal data of other third parties, are covered by this Policy. This Policy applies to all record media owned or managed by IDEA where personal data is processed, and to all activities related to the processing of personal data.
B.DEFINITIONS
The terms used in the legislation and also in the IDEA GDPR Policy are listed below.
- Personal Data: Any kind of relating to an identified or identifiable natural person
- Special Category Personal Data: Data relating to race, ethnicity, political opinion, philosophical belief, religion, sect or other beliefs, clothing, membership in associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
- Data Subject / Relevant Person: The natural person whose personal data is being processed. For example; employees, customers.
- Explicit Consent : Consent given freely and based on prior information regarding a specific matter,
- Processing of personal data: Any operation performed on personal data, such as obtaining, recording, storing, preserving, modifying, reorganizing, disclosing, transferring, acquiring, making available, classifying or preventing the use of data, whether wholly or partly automated or non-automated, provided that it is part of any data recording system,
- Data processor: a natural or legal person who processes personal data on behalf of the data controller, based on the authority given by the data controller,
- Anonymization : Making personal data impossible to link to an identified or identifiable natural person, even when combined with other data.
- Personal Data Protection Law : The Law on the Protection of Personal Data, numbered 6698 and dated March 24, 2016, was published in the Official Gazette numbered 29677 and dated April 7, 2016.
- Personal Data Protection Board : Personal Data Protection Board.
- Personal Data Protection Authority : Personal Data Protection Authority.
- POLICY IMPLEMENTATION AND RESPONSIBILITIES
In the implementation of procedures, standards, and training activities prepared in accordance with the IDEA GDPR Policy within IDEA, the Legal Counsel will serve as a source of advice and guidance. All personnel and relevant third parties throughout IDEA are obligated to comply with the IDEA GDPR Policy and to cooperate with HR in preventing risks/hazards.
All IDEA personnel are responsible for ensuring compliance with the IDEA GDPR Policy.
- POLICY PRINCIPLES
- CORE PRINCIPLES ADOPTED BY HR
IDEA adopts the following fundamental principles to ensure and maintain compliance with personal data protection legislation:
- Personal data includes any information that belongs to and identifies an individual, and therefore its protection is of paramount importance to the data subject. It is essential to act with the understanding that it is a duty to prioritize the data subject's right to know which of their data is being processed, for what purpose, and whether or not their data is being transferred.
- It conducts data processing activities in accordance with the law and the principle of fairness.
- Personal data processed must be accurate and up-to-date when necessary, and if the data is inaccurate, it must be corrected/updated.
- Personal data is processed only for specific, explicit, and legitimate purposes and only to the extent required by the purpose of processing. Excessive data should not be processed with the expectation of future use; the data subject's rights and the purpose of processing must be considered together.
- Personal data processed is retained for the period stipulated in the relevant legislation or for the period necessary for the purpose for which it was processed. In particular, the time limits arising from Article 138 of the Turkish Penal Code and Articles 4 and 7 of the Personal Data Protection Law are observed. IDEA deletes, destroys, or anonymizes personal data upon the expiration of the period stipulated in the legislation or when the reasons requiring the processing of personal data cease to exist.
- PERFORMING PERSONAL DATA PROCESSING ACTIVITIES IN ACCORDANCE WITH THE KVKK (Law on Protection of Personal Data).
When carrying out personal data processing activities, companies must comply with the fundamental principles and the data processing conditions set forth in Articles 5 and 6 of the Personal Data Protection Law and the Regulation on the Processing of Personal Health Data. The following stages are followed in the data processing activity:
- The data owner must be informed. Information should be provided before obtaining consent (signature) in cases where explicit consent is required for data processing, and before commencing data processing in cases where explicit consent (signature) is not required, explaining which data will be processed and why. If data is processed using camera footage, written warning signs should be placed where necessary.
- It must be determined whether the conditions for data processing exist; if the conditions are not met, personal data processing activities should not be carried out. The existence of data processing conditions is accepted in the following situations, and consent is not required:
- It is explicitly stipulated in the laws (for example, obtaining the employee's identity information is mandatory due to the obligation to report to the Social Security Institution).
- The processing of personal data belonging to the parties to a contract is necessary provided that it is directly related to the establishment or performance of the contract (for example, it is necessary to obtain the seller's full name and bank account information in order to pay for the purchased product).
- Personal data may be processed if it is necessary for the data controller to fulfill its legal obligations, if the data has been made public by the data subject themselves, if data processing is necessary for the establishment, exercise or protection of a right, or if data processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.
- Except in the cases mentioned above, or when processing "special categories of data," EXPLICIT CONSENT MUST BE OBTAINED.
- It is necessary to limit the amount of data to be processed to "what is necessary" and not to process more data than is needed for each processing purpose.
- IDEA personnel must comply with the rules set forth in the Constitution of the Republic of Turkey, the Turkish Penal Code, the Personal Data Protection Law, other relevant legislation, and the IDEA Personal Data Protection Policy regarding the processing of personal data.
Within the scope of these explanations, personal data processing at IDEA will be carried out in accordance with the conditions and purposes specified in Articles 5 and 6 of the Personal Data Protection Law, and for the purposes stated below;
Customer and business partner data;
- Data processing due to contractual relationship; Personal data relating to any contractual relationship with a business partner (or the authorized representative of the business partner if the business partner is a legal entity) and third-party natural and legal persons (or the authorized representative of the business partner if the partner is a legal entity) due to commercial business may be processed for the establishment, implementation, and termination of the contract without the need for further consent. Prior to and during the commencement of the contract, personal data may be processed for the purpose of preparing offers, preparing purchase forms, or fulfilling the Data Subject's requests regarding the implementation of the contract.
Personal data of customers (customers and potential customers) may be processed with their explicit consent.
- Data processing carried out by IDEA due to its legal obligation or because it is explicitly provided for in the law.; Personal data may be processed without consent only if the processing is explicitly stated in the relevant legislation or for the purpose of fulfilling a legal obligation determined by legislation. The type and scope of data processing must be necessary for the legally permitted data processing activity and must comply with the relevant legal provisions.
- Data processing in accordance with IDEA's legitimate interests; Personal data may also be processed without the need for consent when it is necessary for a legitimate interest of IDEA. Legitimate interests are generally legal (e.g., collecting debts) or economic (e.g., avoiding breaches of contract) interests.
Personnel data;
- Processing of Personal Data for business relationships;Personal data is processed without further consent if it is necessary for the establishment, implementation, and termination of an employment contract. Candidates' personal data is processed when an employment relationship is initiated. If a candidate is rejected, their information is retained for an appropriate data retention period for a subsequent selection process, after which it is deleted, destroyed, or anonymized.
- Data processing carried out as explicitly provided for in the law or due to IDEA's legal obligation;Personal data of employees may be processed without the need for additional consent if the processing is explicitly stated in the relevant legislation or for the purpose of fulfilling a legal obligation determined by legislation.
- Processing data in accordance with legitimate interests.; Personal data of employees may also be processed without consent when IDEA has a legitimate interest (e.g., filing, enforcing or defending legal rights, or evaluating IDEA). Personal data is not processed for legitimate interest purposes in situations where the protection of employees' interests is necessary. It is determined whether there are interests requiring protection before processing the data. When employee data is processed based on IDEA's legitimate interest, it is examined whether the processing is proportionate. IDEA checks that its legitimate interest in taking this control measure does not infringe upon a right of the employee concerned, and it is only applied if it is proportionate.
- TRANSFER OF PERSONAL DATA IN ACCORDANCE WITH THE KVKK (Law on Protection of Personal Data).
In personal data transfers to be carried out by İDEA (actively sharing personal data with third parties or making personal data accessible to third parties), compliance with the personal data transfer conditions regulated in Articles 8 and 9 of the Personal Data Protection Law is required. Except for data relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership in associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data, other data may be transferred in the following cases:
- It is explicitly stipulated in the laws (for example, reporting an employee's identity information to the Social Security Institution is mandatory due to Social Security regulations)..
- The processing of personal data belonging to the parties to a contract is necessary provided that it is directly related to the establishment or performance of the contract (for example, it is necessary to transfer the seller's name, surname and account information to the bank section in order to pay for the purchased product).
- Personal data may be transferred if it is necessary for the data controller to fulfill its legal obligations, if the data has been made public by the data subject themselves, if data processing is necessary for the establishment, exercise or protection of a right, or if data processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject (for example, it is mandatory to obtain a health report for an employee at legally mandated intervals and to transfer this data to accounting personnel).
- Personal data cannot be transferred abroad without the explicit consent of the data subject.
- ENSURING THE SECURITY OF PERSONAL DATA
IDEA must take all necessary measures, within its capabilities and according to the nature of the data to be protected, to prevent the unlawful disclosure, transfer, unlawful access to personal data, or other security vulnerabilities that may occur. This includes implementing administrative and technical measures, establishing an audit system within IDEA, and initiating legal proceedings under the Personal Data Protection Law in cases of unlawful disclosure of personal data.
- The administrative measures taken to ensure the lawful processing and transfer of personal data and to prevent unlawful access to personal data are as follows:
- It trains and raises awareness among its employees regarding the protection of personal data.
- In cases where personal data is transferred, clauses are added to the contracts concluded with the recipients stating that the recipient will fulfill its obligations to ensure data security. In this context, the recipient undertakes to take all necessary measures to protect personal data and to ensure the implementation of these measures within its own organization.
- The processes carried out by factories and workplaces are examined in detail, and the personal data processing activities conducted within the scope of these processes are identified for each unit. In this context, the steps that need to be taken to ensure that the data processing activities comply with the personal data processing conditions stipulated in the Personal Data Protection Law are determined.
- The technical measures taken to ensure the lawful processing and transfer of personal data and to prevent unlawful access to personal data are as follows:
- Regarding the protection of personal data, technical measures have been taken to the extent permitted by technology, and these measures should be updated and improved in parallel with developments.
- For technical matters, expert personnel are employed.
- Regular checks should be carried out to ensure the measures taken are being implemented.
- Software and systems that ensure security are updated.
- Access to personal data being processed by personnel is limited to the relevant IDEA employee in accordance with the defined processing purpose.
- Conducting Audit Activities Regarding the Protection of Personal Data
The compliance, operation, and effectiveness of the technical, administrative, and practical measures taken by IDEA to ensure the protection and security of personal data are in accordance with relevant legislation, policies, procedures, and instructions. This audit may also be conducted by external auditing firms. The results of the audit activities are reported to the Company Director and the relevant functional managers. Regular follow-up of planned actions related to the audit results is the primary responsibility of the process owners. Activities aimed at improving and developing data protection measures, not limited to audit results, are carried out by the relevant unit.
- Measures to be Taken in Case of Unlawful Disclosure of Personal DataIDEA must immediately notify the Personal Data Protection Board and the relevant data owners if the personal data they process is obtained unlawfully by unauthorized persons. Simultaneously, the IDEA Data Breach Notification Procedure must be implemented.
- OBLIGATIONS REGARDING PERSONAL DATA PROCESSING ACTIVITIES
IDEA must comply with the obligations stipulated by the Personal Data Protection Law for data controllers.
a. Registration Obligation with the Data Controllers Registry (VERBIS): The following information must be submitted to the Data Controllers Registry with the registration application:
1. Identity information and addresses of the data controller and, if applicable, their representative.
2. The purpose of processing personal data,
3. Information about data subject groups and the categories of personal data processed for these individuals,
4. The person or group of people to whom personal data may be transferred,
5. The maximum retention period for personal data as required by the purpose of processing,
6. Measures taken to ensure the security of processed personal data.
- Obligation to Inform the Data Subject: The following information must be provided to data subjects as part of the obligation to inform:
1. The identity of the data controller and, if applicable, their representative,
2. The purpose for which personal data will be processed,
3.To whom and for what purpose the processed personal data may be transferred,
4. Method and legal basis for collecting personal data,
5. The data subject's rights are listed in Article 11 of the Personal Data Protection Law.
- Obligation to Collect and Transfer Personal Data in Accordance with the Law: Data subjects must be informed which of their data is being processed, for what purpose, and whether or not the data is being transferred. Collected data must be processed in accordance with the law and the principle of fairness. Personal data should only be processed for specific, explicit, and legitimate purposes, and only to the extent required by the processing purpose. Data must be accurate and up-to-date. If the reason for processing data no longer exists, data processing companies must establish the necessary internal systems for deleting, anonymizing, or destroying the data.
- Obligation to Ensure the Security of Personal Data: To ensure that the data subject does not suffer any loss of rights, IDEA must take all necessary technical and administrative measures to ensure an appropriate level of security to prevent the unlawful processing of personal data, to prevent unlawful access to personal data, and to ensure the preservation of personal data. IDEA is obliged to conduct or have conducted the necessary audits within the scope of operating the mechanisms aimed at ensuring data security.
- Obligation to Comply with Decisions Issued by the Personal Data Protection Board: IDEA must act in accordance with the decisions of the Personal Data Protection Board, which is the executive body of the Personal Data Protection Authority and operates to ensure that personal data is processed in a manner consistent with fundamental rights and freedoms.
- Obligation to Respond to Data Subject Requests:IDEA, as the data controller, must finalize the written requests of data subjects regarding their personal data as soon as possible and within thirty (30) days at the latest, depending on the nature of the request.
Data subjects may contact data controllers to make requests regarding the following matters concerning them:
- To find out whether your personal data is being processed,
- The right to request information regarding the processing of personal data.
- To learn the purpose of processing personal data and whether it is being used appropriately for that purpose.
- Knowing the third parties to whom personal data is transferred, whether domestically or internationally.
- Requesting the correction of personal data if it has been processed incompletely or inaccurately.
- Requesting the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the KVKK (Law on Protection of Personal Data).
- In case of correction or deletion/deletion of data, the right to request notification of the situation to third parties to whom personal data has been transferred,
- The right to object to an outcome that is detrimental to oneself, resulting from the analysis of processed data exclusively through automated systems.
- The right to claim compensation for damages incurred as a result of the unlawful processing of personal data.
E- PUBLICATION AND CONFIDENTIALITY OF POLICY
The policy document is published in two formats: a printed copy with a wet signature and an electronic version, and is made publicly available on the website. The printed copy is also kept in the file by the DATA CONTROLLER CONTACT PERSON.
F- UPDATING THE POLICY
This policy enters into force upon approval by the Company Director. This policy will be reviewed and updated as needed. The Board of Directors has authorized the General Manager to make changes to this policy and to implement them. Changes to this policy may be made and implemented with the approval of the Company Director. Implementation rules specifying how the matters mentioned in this policy will be enforced in particular will be added to the relevant regulations. IDEA's GDPR policy has been published on the website and made public. In case of any conflict between the provisions of this policy and the current legislation, primarily the GDPR, the provisions of the legislation shall prevail.