Data Subject Application Processes Procedure

Procedure for the Acceptance, Evaluation and Responding of the Data Subject Applications in Accordance with the Law No. 6698

VERSION : 1
DATE : 24.05.2017

TABLE OF CONTENTS
I. Definitions
II. Acceptance of Application
A. Method of Application
B. Content of Application
C. Other Events
1. Application Submitted by an Agent or Legal Representative
2. Mass Application
3. Application Fee
III. Evaluation of the Application
A. Durations for Evaluating Applications
B. Examples of Evaluation Processes
1. Applications received pursuant to Article 11/1 (a), (b), (c), (ç) of the Law
2. Applications received pursuant to Article 11/1 (d) of the Law
3. Applications received pursuant to Article 11/1 (e) of the Law
4. Applications received pursuant to Article 11/1 (f) of the Law
5. Applications received pursuant to Article 11/1 (g) of the Law
6. Applications received pursuant to Article 11/1 (ğ) of the Law
IV. Responding to Applications

I. Definitions

Abbreviation

Description

Law

Law No. 6698 on Protection of Personal Data

Procedure

Procedure for the Acceptance, Evaluation and Responding of the Data Subject Applications in Accordance with the Law No. 6698

Application Form

The form provided in the annexes to the Procedure or drafted by the Company on the basis of these annexes, for use in applications made by the Data Subject pursuant to Article 13 of the Law

Authority

Personal Data Protection Authority

Board

Personal Data Protection Board

Employees

Employees of the Company

Company

[Elektronik Bilgi Güvenliği A.Ş.]

Data Processor

Any real or legal person who processes personal data on behalf of APOLLO with the authority granted by it, as defined in the Law, including but not limited to suppliers, consultancy firms and subcontractors

Data Subject

A real person of whom personal data are processed

Personal Data

Any information relating to an identified or identifiable real person to the extent it is within the scope of the Law

Preliminary Evaluation Team

The team that will receive applications submitted to the Company in the first instance

Application Response Function

The team responsible for responding to applications

Data Categorization

Category information regarding the data subject, personal data and details of the parties with whom data is shared, as listed in the Data Inventory

Data Inventory

The document located on the E-GÜVEN shared server, which contains an inventory of all the Company’s data processing operations and purposes

Process

Any data processing activity in the Data Inventory

II. Acceptance of Application

A. Method of Application

Written Application . Article 13 of the Law stipulates that the application must be submitted “in writing or using other methods specified by the Board”. The Board has not yet determined any other application method; therefore, applications must be submitted via “written” channels.

The following methods are recommended for compliance with the written application requirement:

A contact person should be designated within the Company in order to keep records of applications and ensure their prompt delivery to the relevant person, and the relevant procedure should be established so that applications received in this manner can be quickly forwarded by the correspondence function to the relevant person.

B. Content of Application

Identification of the Applicant: In order for Data Subject requests to be evaluated, it must first be determined whether the applicant is the Data Subject of the personal data processed by the Company.

Extra information should be requested from the Data Subject regarding how the relevant condition has been fulfilled for conditional inquiries <#_ftn1">[1], as illustrated in the application form, and documents should be requested to support such claims. Applications may also be received through channels that are not valid under the Law (e.g. call centre, website, email, etc.). If an application is received through these channels, warning and guidance texts should be designed to direct the Data Subject to valid application channels established in accordance with the Procedure.

Applications not submitted through the methods specified in the Procedure may also be considered if:

Applications submitted through such channels may also be evaluated.

Applications that do not meet these requirements should nevertheless be evaluated and contact should be maintained with the applicant until the information requested in the form is obtained; it should be stated that the application has been rejected due to non-compliance with the procedure.

In case an application is submitted through the aforementioned channels, examples of practices relating to the procedures that may be implemented by the Company are provided in Annex-3.

C. Other Events

1. Application Submitted by an Agent or Legal Representative

Even though the Law states that the Data Subject may submit an application to the Data Controller, there is no provision preventing the Data Subject’s agent or legal representative from making such an application. Therefore, some applications may not be submitted directly by the Data Subject.

In such a case, the applicant’s authority to submit the application should be verified. For example, the application may be submitted by the Data Subject’s attorney. In this case, the attorney should be requested to provide a copy of the power of attorney for the purpose of verifying the authorization.

Applications concerning the Personal Data of children may be submitted by their legal representative. In such cases, copies of the documents establishing the authority of the legal representative must be requested.

2. Mass Application

Depending on the Company’s structure or business operations, it may be possible for multiple Data Subjects to submit a collective application regarding processed Personal Data. For example, an application may be made regarding the Personal Data of several persons under a single power of attorney.

In case of a mass application, it is recommended that the Company separate and evaluate the application for each person individually. In such a case, the following actions should be taken:

Verification of the third party’s authority to act on behalf of the Data Subjects,

3. Application Fee

The Law requires the Data Controller to process the application free of charge. However, where the process incurs an additional cost, it may be possible to charge a fee in accordance with the principles to be determined by the Board.

The Board had not established a fee tariff as of the date this Procedure was prepared. It is recommended that developments in this regard be monitored.

III. Evaluation of the Application

Applications submitted by Data Subjects may contain incomplete information in relation to the information required, may include information belonging to third parties, or may need to be rejected for various reasons. Therefore, the Company must take all such possibilities into consideration.

The following three-step evaluation process may be applied where it is not possible to respond to an information request without sharing personal data belonging to third parties:

First, an attempt should be made to obtain explicit consent from the Data Subject whose Personal Data would need to be disclosed.

If the third party does not consent to the sharing of the data, the third party’s information should be completely removed and the application should be answered accordingly.

If it is not possible to contact the third-party Data Subject whose Personal Data would be disclosed, particular care should be taken when sharing information containing the third party’s Personal Data. Where necessary, information containing third-party Personal Data may also be shared.

A. Durations for Evaluating Applications

The Company must evaluate and conclude Data Subject requests as soon as possible and in any event within 30 days following the date of application.

Internal procedures should be developed to process requests so that applications can be answered in a timely manner. These procedures should provide, at a minimum, for the following time periods:

B. Examples of Evaluation Processes

1. Applications received pursuant to Article 11/1 (a), (b), (c), (ç) of the Law

  1. The application is recorded and reviewed by the Preliminary Evaluation Team.
  2. The person’s identification details are checked to determine whether he/she is authorized to submit the application.

iii. The relevant “Process” is identified in the Data Inventory based on the information provided in Part 2 of the Application Form. The Data Categorization in the Data Inventory and the information provided in the Application Form are compared when determining the relevant “Process”. The query is narrowed down to the Processes included within the relevant categories under Data Categorization and Data Subject Categorization. The data processing purposes and information concerning the parties with whom data is shared within this Process are used to prepare the response.

  1. In addition to the review carried out through the Data Inventory, an actual test is performed by searching the Company’s databases using the Data Subject information provided in the application form. The results of the actual test are compared with the Data Inventory steps described in step iii. If the actual test identifies data that may not be included in the Data Inventory, the Data Inventory is updated and the query described in step iii is repeated.
  2. If the personal data specified by the Data Subject in the application form cannot be found in the relevant processes or in the actual test, the Application Response Function is provided with the response: «No personal data record relating to the applicant has been found; no personal data relating to the applicant is being processed.»
  3. If the personal data specified by the Data Subject in the application form is found in the relevant processes and the actual test, the appropriate information regarding the purpose of data processing, the parties with whom data is shared and the purpose of such sharing, as specified in the Data Inventory in step iii, is included in the response text in accordance with the Data Subject’s request.

vii. During the aforementioned stages, the actions taken, details of the transactions and timing, event records, documents and query results are recorded by the Application Evaluation Team and stored in the electronic directory created for this purpose.

2. Applications received pursuant to Article 11/1 (d) of the Law

viii. Steps 1. (i) and (ii) above are followed.

  1. The Personal Data provided by the Data Subject or his/her representative and the supporting documents are compared with the information held in the Company’s records, and any information identified as incorrect or incomplete within the scope of the application is examined.
  2. If the Personal Data provided and the information contained in supporting documents also match the information in systems such as MERNIS and the Address Registration System, a note is created for correction of the records. The matter is forwarded to the unit responsible for the database so that the necessary correction can be made.
  3. At this stage, the note “Your application has been reviewed and your personal data has been updated based on the information and documents provided in your application” is forwarded to the Application Response Function.

xii. Step 1. (vi) above is followed.

3. Applications received pursuant to Article 11/1 (e) of the Law

iii. If there is no legal obligation to store and process the data, the response «Your personal data held by our Company has been deleted and/or anonymized upon your request» is prepared and forwarded to the Application Response Function, while the deletion and anonymization process is initiated in parallel.

  1. If there is a legal obligation to process and store the data, a note is prepared stating: “As a result of your application, we carried out the necessary reviews and determined that [...] personal data processing activities are no longer carried out because the legal purpose underlying the processing of personal data has ceased to exist. Accordingly, the necessary measures have been taken to ensure that the relevant business units do not engage in data processing activities for which the legal purpose has ceased to exist. Nevertheless, under our Company’s legal obligations, your personal data must be processed and retained for [...] purposes for the periods stipulated in the relevant legislation and disclosed when requested; however, such data will only be processed for the purpose of responding to official requests from authorized institutions and organizations under the legislation establishing such obligations and/or for the purpose of fulfilling our Company’s legal obligations. Therefore, since processing your personal data for the aforementioned purposes constitutes a legal obligation on our part, we are unable to comply with your request for deletion or anonymization of your personal data; however, we wish to inform you that your personal data will only be processed for the purposes stated above.” This note is forwarded to the Application Response Function.
  2. Step 1. (vi) above is followed. 
    4. Applications received pursuant to Article 11/1 (f) of the Law
  3. Steps 1 (i), (ii), (iii) and (iv) above are followed.
  4. The persons with whom information is shared are identified categorically from the relevant section of the Process Card within the narrowed Processes.

iii. If the request for deletion or anonymization has been accepted, the relevant third parties are requested to fulfil this request. In parallel, the response «Following acceptance of your request for deletion or anonymization, your personal data held by the persons to whom your personal data has been transferred has been deleted or anonymized» is prepared and forwarded to the Application Response Function.

  1. Step 1. (vi) above is followed.
    5. Applications received pursuant to Article 11/1 (g) of the Law
  2. Steps 1. (i) and (ii) above are followed.
  3. The process carried out exclusively through automated systems, which the Data Subject claims has produced an adverse result against him/her, is examined based on the information and documents provided by the Data Subject or his/her representative.

iii. If, as a result of the examination, no omission or error is identified in the automated Process or in the Personal Data processed within such Process, the response «As a result of the examinations carried out, your objection has been rejected since no omission or error has been identified in the reports generated using your personal data held by our Company.» is prepared and forwarded to the Application Response Function.

  1. If the information provided by the person changes the data used in the existing evaluation process and therefore changes the automatically generated result in favour of the person, this result is prepared as the response, together with information that the person’s objection has been recorded in accordance with the revised result and that the systems have been updated accordingly, and forwarded to the Application Response Function.
  2. Step 1. (vi) above is followed.
    6. Applications received pursuant to Article 11/1 (ğ) of the Law
  3. Steps 1. (i) and (ii) above are followed.
  4. The claim for damages is reviewed with the participation of the legal and relevant departments in light of the information provided by the Data Subject or his/her representative.

iii. The result of this examination is used to prepare a response, which is forwarded to the Application Response Function.

  1. Step 1. (vi) above is followed.
    Responding to Applications

All applications are responded to by the Application Response Function.

Responding within 30 Days: The Company reviews the requests specified in the application. Depending on the nature of the request, the Company is obliged to fulfil the request as soon as possible and in any event within thirty (30) days at the latest. If no response is provided within this period, the applicant may file a complaint with the Board.

Information that must be provided in the Company’s response:

Responses given to applications submitted via notary public: The response is printed on Company letterhead and signed in two copies by the person authorized by the Company pursuant to the Personal Data Protection and Processing Policy. The response is delivered to the correspondence function to be sent to the applicant by mail.

Responses sent using electronic signature : The response is prepared on Company letterhead and signed electronically using a secure electronic signature by the person authorized by the Company pursuant to the Personal Data Protection and Processing Policy. The response is sent to the applicant’s electronic mail account.

Event records, documents and results created in connection with the relevant application are stored in the electronic directory created for this purpose. A copy of the written dispatch record is also retained in the archive.

E-Güven
Değirmen Sokak Nida Kule İş Merkezi No:18 Kat:5 Kozyatağı / İstanbul
Satış Ofisleri