Procedure for the Acceptance, Evaluation and Responding of the Data Subject Applications in Accordance with the Law No. 6698
VERSION : 1
DATE : 24.05.2017
TABLE OF CONTENTS
I. Definitions
II. Acceptance of Application
A. Method of Application
B. Content of Application
C. Other Events
1. Application Submitted by an Agent or Legal Representative
2. Mass Application
3. Application Fee
III. Evaluation of the Application
A. Durations for Evaluating Applications
B. Examples of Evaluation Processes
1. Applications received pursuant to Article 11/1 (a), (b), (c), (ç) of the Law
2. Applications received pursuant to Article 11/1 (d) of the Law
3. Applications received pursuant to Article 11/1 (e) of the Law
4. Applications received pursuant to Article 11/1 (f) of the Law
5. Applications received pursuant to Article 11/1 (g) of the Law
6. Applications received pursuant to Article 11/1 (ğ) of the Law
IV. Responding to Applications
I. Definitions
|
Abbreviation |
Description |
|
Law |
Law No. 6698 on Protection of Personal Data |
|
Procedure |
Procedure for the Acceptance, Evaluation and Responding of the Data Subject Applications in Accordance with the Law No. 6698 |
|
Application Form |
The form provided in the annexes to the Procedure or drafted by the Company on the basis of these annexes, for use in applications made by the Data Subject pursuant to Article 13 of the Law |
|
Authority |
Personal Data Protection Authority |
|
Board |
Personal Data Protection Board |
|
Employees |
Employees of the Company |
|
Company |
[Elektronik Bilgi Güvenliği A.Ş.] |
|
Data Processor |
Any real or legal person who processes personal data on behalf of APOLLO with the authority granted by it, as defined in the Law, including but not limited to suppliers, consultancy firms and subcontractors |
|
Data Subject |
A real person of whom personal data are processed |
|
Personal Data |
Any information relating to an identified or identifiable real person to the extent it is within the scope of the Law |
|
Preliminary Evaluation Team |
The team that will receive applications submitted to the Company in the first instance |
|
Application Response Function |
The team responsible for responding to applications |
|
Data Categorization |
Category information regarding the data subject, personal data and details of the parties with whom data is shared, as listed in the Data Inventory |
|
Data Inventory |
The document located on the E-GÜVEN shared server, which contains an inventory of all the Company’s data processing operations and purposes |
|
Process |
Any data processing activity in the Data Inventory |
II. Acceptance of Application
A. Method of Application
Written Application . Article 13 of the Law stipulates that the application must be submitted “in writing or using other methods specified by the Board”. The Board has not yet determined any other application method; therefore, applications must be submitted via “written” channels.
The following methods are recommended for compliance with the written application requirement:
A contact person should be designated within the Company in order to keep records of applications and ensure their prompt delivery to the relevant person, and the relevant procedure should be established so that applications received in this manner can be quickly forwarded by the correspondence function to the relevant person.
B. Content of Application
Identification of the Applicant: In order for Data Subject requests to be evaluated, it must first be determined whether the applicant is the Data Subject of the personal data processed by the Company.
Extra information should be requested from the Data Subject regarding how the relevant condition has been fulfilled for conditional inquiries <#_ftn1">[1], as illustrated in the application form, and documents should be requested to support such claims. Applications may also be received through channels that are not valid under the Law (e.g. call centre, website, email, etc.). If an application is received through these channels, warning and guidance texts should be designed to direct the Data Subject to valid application channels established in accordance with the Procedure.
Applications not submitted through the methods specified in the Procedure may also be considered if:
Applications submitted through such channels may also be evaluated.
Applications that do not meet these requirements should nevertheless be evaluated and contact should be maintained with the applicant until the information requested in the form is obtained; it should be stated that the application has been rejected due to non-compliance with the procedure.
In case an application is submitted through the aforementioned channels, examples of practices relating to the procedures that may be implemented by the Company are provided in Annex-3.
C. Other Events
1. Application Submitted by an Agent or Legal Representative
Even though the Law states that the Data Subject may submit an application to the Data Controller, there is no provision preventing the Data Subject’s agent or legal representative from making such an application. Therefore, some applications may not be submitted directly by the Data Subject.
In such a case, the applicant’s authority to submit the application should be verified. For example, the application may be submitted by the Data Subject’s attorney. In this case, the attorney should be requested to provide a copy of the power of attorney for the purpose of verifying the authorization.
Applications concerning the Personal Data of children may be submitted by their legal representative. In such cases, copies of the documents establishing the authority of the legal representative must be requested.
2. Mass Application
Depending on the Company’s structure or business operations, it may be possible for multiple Data Subjects to submit a collective application regarding processed Personal Data. For example, an application may be made regarding the Personal Data of several persons under a single power of attorney.
In case of a mass application, it is recommended that the Company separate and evaluate the application for each person individually. In such a case, the following actions should be taken:
Verification of the third party’s authority to act on behalf of the Data Subjects,
3. Application Fee
The Law requires the Data Controller to process the application free of charge. However, where the process incurs an additional cost, it may be possible to charge a fee in accordance with the principles to be determined by the Board.
The Board had not established a fee tariff as of the date this Procedure was prepared. It is recommended that developments in this regard be monitored.
III. Evaluation of the Application
Applications submitted by Data Subjects may contain incomplete information in relation to the information required, may include information belonging to third parties, or may need to be rejected for various reasons. Therefore, the Company must take all such possibilities into consideration.
The following three-step evaluation process may be applied where it is not possible to respond to an information request without sharing personal data belonging to third parties:
First, an attempt should be made to obtain explicit consent from the Data Subject whose Personal Data would need to be disclosed.
If the third party does not consent to the sharing of the data, the third party’s information should be completely removed and the application should be answered accordingly.
If it is not possible to contact the third-party Data Subject whose Personal Data would be disclosed, particular care should be taken when sharing information containing the third party’s Personal Data. Where necessary, information containing third-party Personal Data may also be shared.
A. Durations for Evaluating Applications
The Company must evaluate and conclude Data Subject requests as soon as possible and in any event within 30 days following the date of application.
Internal procedures should be developed to process requests so that applications can be answered in a timely manner. These procedures should provide, at a minimum, for the following time periods:
B. Examples of Evaluation Processes
1. Applications received pursuant to Article 11/1 (a), (b), (c), (ç) of the Law
iii. The relevant “Process” is identified in the Data Inventory based on the information provided in Part 2 of the Application Form. The Data Categorization in the Data Inventory and the information provided in the Application Form are compared when determining the relevant “Process”. The query is narrowed down to the Processes included within the relevant categories under Data Categorization and Data Subject Categorization. The data processing purposes and information concerning the parties with whom data is shared within this Process are used to prepare the response.
vii. During the aforementioned stages, the actions taken, details of the transactions and timing, event records, documents and query results are recorded by the Application Evaluation Team and stored in the electronic directory created for this purpose.
2. Applications received pursuant to Article 11/1 (d) of the Law
viii. Steps 1. (i) and (ii) above are followed.
xii. Step 1. (vi) above is followed.
3. Applications received pursuant to Article 11/1 (e) of the Law
iii. If there is no legal obligation to store and process the data, the response «Your personal data held by our Company has been deleted and/or anonymized upon your request» is prepared and forwarded to the Application Response Function, while the deletion and anonymization process is initiated in parallel.
iii. If the request for deletion or anonymization has been accepted, the relevant third parties are requested to fulfil this request. In parallel, the response «Following acceptance of your request for deletion or anonymization, your personal data held by the persons to whom your personal data has been transferred has been deleted or anonymized» is prepared and forwarded to the Application Response Function.
iii. If, as a result of the examination, no omission or error is identified in the automated Process or in the Personal Data processed within such Process, the response «As a result of the examinations carried out, your objection has been rejected since no omission or error has been identified in the reports generated using your personal data held by our Company.» is prepared and forwarded to the Application Response Function.
iii. The result of this examination is used to prepare a response, which is forwarded to the Application Response Function.
All applications are responded to by the Application Response Function.
Responding within 30 Days: The Company reviews the requests specified in the application. Depending on the nature of the request, the Company is obliged to fulfil the request as soon as possible and in any event within thirty (30) days at the latest. If no response is provided within this period, the applicant may file a complaint with the Board.
Information that must be provided in the Company’s response:
Responses given to applications submitted via notary public: The response is printed on Company letterhead and signed in two copies by the person authorized by the Company pursuant to the Personal Data Protection and Processing Policy. The response is delivered to the correspondence function to be sent to the applicant by mail.
Responses sent using electronic signature : The response is prepared on Company letterhead and signed electronically using a secure electronic signature by the person authorized by the Company pursuant to the Personal Data Protection and Processing Policy. The response is sent to the applicant’s electronic mail account.
Event records, documents and results created in connection with the relevant application are stored in the electronic directory created for this purpose. A copy of the written dispatch record is also retained in the archive.