ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş.
POLICY ON PROTECTION AND PROCESSING OF PERSONAL DATA
VERSION : 1
DATE : 24.05.2017
TABLE OF CONTENTS
1. PRINCIPLES ON PROCESSING OF PERSONAL DATA
i. Compliance with the law and principles of good faith
ii. Accuracy and up-to-datedness
iii. Processing for specific, clear and legitimate purposes
iv. Relevance, connection and proportionality with the purpose of processing
v. Retention for the period required by the applicable legislation or for the purpose of processing
2. PURPOSES OF PROCESSING PERSONAL DATA BY ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş.
3. TRANSFER OF PERSONAL DATA BY ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş.
i. General Conditions of Transfer
iii. Recipients of Transfer by Elektronik Bilgi Güvenliği A.Ş.
4. PERSONAL DATA PROCESSED BY ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş.
5. PROCEDURE OF PROCESSING PERSONAL DATA BY ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş.
6. DETERMINATION OF DURATION OF RETAINING PERSONAL DATA BY ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş.
7. RIGHTS OF DATA SUBJECTS AND EXERCISE OF THE RIGHTS
ii. Exercise of the Rights by Data Subjects
8. PROTECTION OF PERSONAL DATA BY ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş.
9. ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş. INTERNAL GOVERNANCE STRUCTURE FOR PROTECTION OF PERSONAL DATA
ABOUT THE POLICY
Law No. 6698 on Protection of Personal Data (“Law”) took effect on 7 April 2016 and sets forth regulations on processing of any kind of information on identified or identifiable real persons.
This Elektronik Bilgi Güvenliği A.Ş. Policy on Protection and Processing of Personal Data (“Policy”) sets forth the statements and explanations of Elektronik Bilgi Güvenliği A.Ş. (“E-GÜVEN”) regarding the processing of the personal data of real persons in the categories listed below in accordance with the Law. For this purpose, the field of application of this Policy consists of the processing activities in connection with personal data of the following data subjects:
This Policy may be revised from time to time for the purpose of adapting to changing conditions and legislation.
1. PRINCIPLES ON PROCESSING OF PERSONAL DATA
Acting in the capacity of data controller, E-GÜVEN complies with the following principles pursuant to Article 4 of the Law:
i. Compliance with the law and principles of good faith
Personal data is processed in accordance with the law and principles of good faith. Accordingly, as Data Controller, E-GÜVEN acts in accordance with the applicable legislation and observes the principles of good faith in the course of processing any kind of personal data.
ii. Accuracy and Up-to-Datedness
Data Controllers must define the processes required for accuracy and up-to-datedness of the personal data processed. Accordingly, E-GÜVEN provides Data Subjects with the opportunity to update their data and takes measures to ensure accurate transfer of the data to databases.
iii. Processing for specific, clear and legitimate purposes
Data Controllers are obliged to keep Data Subjects informed about the purposes of data processing in accordance with their obligation to provide information as stipulated under the Law. Accordingly, acting as Data Controller, E-GÜVEN limits data processing activities to specific and legitimate purposes and provides clear information to Data Subjects through information notices relating to such purposes.
iv. Relevance, connection and proportionality with the purpose of processing
E-GÜVEN performs personal data processing activities only to the extent required for and in connection with the purpose notified to the Data Subject during the collection process.
v. Retention for the period required by the applicable legislation or for the purpose of processing
Data is retained for the period specified under the applicable legislation, if such a period is determined. Where no retention period is specified in the applicable legislation, reasonable retention periods are determined by considering the purpose of data use and company procedures, and data is retained only for such period. Following expiry of these periods, data is deleted, destroyed or anonymized in accordance with company procedures.
2. PURPOSES OF PROCESSING PERSONAL DATA BY ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş.
Articles 5 and 6 of the Law stipulate conditions on processing of personal data and special categories of personal data. Special categories of personal data are specified under the Law in a limited manner and consist of data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, attire and appearance, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. Article 5 of the Law stipulates the conditions for processing standard personal data, while Article 6 sets forth the conditions for processing special categories of personal data.
Pursuant to the aforementioned articles, standard personal data may be processed where:
Special categories of personal data may be processed subject to the following conditions:
Accordingly, E-GÜVEN processes the personal data of real persons in the categories specified in Annex-1 for the following purposes:
3. TRANSFER OF PERSONAL DATA BY ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş.
i. General Conditions of Transfer
Article 8 of the Law categorizes personal data as standard and special categories of personal data for the purpose of transfers.
Pursuant to the aforementioned Article, standard personal data may be transferred to third parties where one of the processing conditions specified under Section 2 above applies. Accordingly, personal data may be shared by E-GÜVEN with third parties where:
Article 8 also refers to the processing conditions specified under Section 2 in relation to special categories of personal data, but additionally requires that adequate measures be taken for the transfer. Accordingly, E-GÜVEN may share special categories of personal data with third parties where:
In all cases, such data is shared with third parties only after adequate measures have been taken.
ii. Transfer Abroad
E-GÜVEN may transfer personal data abroad:
o Provided that there is an adequate level of protection in the country to which the data is transferred, and
o Where there is no adequate protection in the country to which the data is transferred, provided that E-GÜVEN and the Data Controller in the relevant foreign country undertake adequate protection in writing and permission from the Personal Data Protection Board is obtained.
iii. Recipients of Transfer by Elektronik Bilgi Güvenliği A.Ş.
Subject to the conditions above, E-GÜVEN transfers personal data to the following parties:
4. PERSONAL DATA PROCESSED BY ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş.
The categorization of personal data processed by E-GÜVEN is provided in Annex-1.
5. PROCEDURE OF PROCESSING PERSONAL DATA BY ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş.
As stipulated under the Law, E-GÜVEN provides Data Subjects with information, at the time personal data is obtained, regarding the purposes for which personal data is processed, the recipients and purposes of transferring processed personal data, the methods and legal grounds for collecting personal data and the rights of Data Subjects.
Where any process requires explicit consent under the Law, E-GÜVEN obtains the explicit consent of Data Subjects after providing the aforementioned information.
6. DETERMINATION OF DURATION OF RETAINING PERSONAL DATA BY ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş.
E-GÜVEN determines personal data retention periods by considering the applicable legislation and the purposes for which the relevant data is processed. In all cases, E-GÜVEN determines retention periods in accordance with its legal obligations and the relevant limitation periods.
Where the purpose of data processing ceases to exist, data is deleted, destroyed or anonymized unless there is another legal reason or basis requiring retention of the data.
7. RIGHTS OF DATA SUBJECTS AND EXERCISE OF THE RIGHTS
i. Rights of Data Subjects
Pursuant to Article 11 of the Law, Data Subjects have the following rights against the Data Controller:
Paragraph 2 of Article 28 of the Law lists the cases in which Data Subjects do not have the right to make a request. Accordingly, the aforementioned rights may not be exercised in relation to data where:
Pursuant to Paragraph 1 of Article 28 of the Law, data falls outside the scope of the Law in the following cases, and requests from Data Subjects will therefore not be processed in relation to such data:
ii. Exercise of the Rights by Data Subjects
Data Subjects may use the “Form for Applications to the Data Controller by the Data Subject” available at [ww.e-guven.com] in order to exercise the aforementioned rights.
Applications shall be submitted together with documents identifying the relevant Data Subject, using one of the following methods:
E-GÜVEN responds to Data Subjects wishing to exercise the aforementioned rights within the limits stipulated under the Law and within a maximum of thirty days as stipulated under the Law. Where a third party submits an application on behalf of a Data Subject, a special power of attorney issued through a notary public in the name of the person submitting the application must be provided by the Data Subject.
Applications by Data Subjects are generally processed free of charge; however, where a fee tariff is determined by the Personal Data Protection Board, fees may be charged in accordance with such tariff.
E-GÜVEN may request information from the applicant in order to determine whether the applicant is the Data Subject and may ask the Data Subject questions regarding the application in order to clarify the matters specified therein.
8. PROTECTION OF PERSONAL DATA BY ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş.
E-GÜVEN takes reasonable technical and administrative measures to prevent risks of unauthorized access, accidental data loss, intentional deletion or damage to personal data.
Accordingly, E-GÜVEN:
9. ELEKTRONİK BİLGİ GÜVENLİĞİ A.Ş. INTERNAL GOVERNANCE STRUCTURE FOR PROTECTION OF PERSONAL DATA
A Data Protection Committee (the “Committee”) has been established within E-GÜVEN to monitor and manage the actions required to ensure compliance with the Law. The main duties of this Committee are:
|
Annex-1: Data Categorization |
||
|
Data Category |
Personal Data Categorization Description |
Types of Personal Data Included in the Relevant Personal Data Categorization |
|
Identification Details |
Information contained in documents such as driving licences, identity cards, residence permits, passports, solicitor’s ID cards and marriage certificates, which clearly belongs to an identified or identifiable person and is included in the data registration system |
Turkish National ID number (T.R. ID No.), passport number, ID card serial number, first name and surname, photograph, place of birth, date of birth, age, place of civil registry, certified copy of identification card |
|
Contact Information |
Information used to contact the person, which clearly belongs to an identified or identifiable person and is included in the data registration system |
Email address, telephone number, mobile phone number, |
|
Information on Family Members and Relatives |
Information concerning the Data Subject’s family members and relatives, which clearly belongs to an identified or identifiable person, is included in the data registration system and is processed for the purpose of protecting the legal interests of the relevant company and Data Subject |
Identification details of the Data Subject’s children and spouse, contact details and professional and educational details, etc. |
|
Customer Information |
Information relating to customers using our products and services, which clearly belongs to an identified or identifiable person and is included in the data registration system |
Customer number, professional information, etc. |
|
Customer Transaction Details |
Information related to any transaction carried out by customers using our products and services, which clearly belongs to an identified or identifiable person and is included in the data registration system |
Inquiries and instructions, purchase order and basket details, etc. |
|
Physical Space Security Information |
Personal data relating to records made and documents obtained during access to a physical area or while staying in that physical area, which clearly belongs to an identified or identifiable person and is included in the data registration system |
Entry-exit logs, visit details, camera records, etc. |
|
Transaction Security Information |
Personal data processed for the technical, administrative, legal and commercial security of E-GÜVEN and related parties, which clearly belongs to an identified or identifiable person and is included in the data registration system |
Information associated with the Data Subject, matching the person with the action and showing that the person is authorized to perform the action (e.g. website password and passphrase information) |
|
Financial Information |
Personal data contained in information, documents and records reflecting any financial consequences arising from the nature of the existing legal relationship with the Data Subject, which clearly belongs to an identified or identifiable person and is included in the data registration system |
Information showing the financial consequences of transactions carried out by the Data Subject, credit card debt, loan amount, loan payments, amount and rate of interest, debt balance, balance of receivables, etc. |
|
Marketing Information |
Data used by E-GÜVEN in its marketing activities, which clearly belongs to an identified or identifiable person and is included in the data registration system |
Reports and evaluations showing the person’s habits and preferences, targeting information, cookie records, data enrichment activities, etc. collected for marketing purposes by E-GÜVEN |
|
Information on Legal Proceedings and Compliance |
Personal data processed for the purposes of identifying and pursuing legal claims and rights, and fulfilling obligations and legal requirements, which clearly belongs to an identified or identifiable person and is included in the data registration system |
Data contained in documents such as court and administrative authority decisions |
|
Special Categories of Personal Data |
Data relating to a person’s race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, attire and appearance, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data, which clearly belongs to an identified or identifiable person and is included in the data registration system |
Data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, attire and appearance, membership of associations, foundations or trade unions, health and sexual life, criminal convictions and security measures, biometric data and genetic data |
|
Inquiry/Complaint Management Information |
Personal data relating to the receipt and assessment of any inquiry or complaint directed to E-GÜVEN, which clearly belongs to an identified or identifiable person and is included in the data registration system |
Any inquiries and complaints directed to the Company, and the relevant records and reports |
|
Reputation Management Information |
Personal data that may potentially affect the reputation of E-GÜVEN, its shareholders, employees, business partners or customers, which clearly belongs to an identified or identifiable person and is included in the data registration system |
Personal data contained in negative news coverage concerning the Company on social media, etc. |
|
Visual and Auditory Information |
Visual and auditory records associated with the Data Subject, which clearly belong to an identified or identifiable person and are included in the data registration system |
Photographs, camera records and audio records |
|
Annex-2: Definitions |
|
|
Term |
Definition in the Law |
|
Explicit Consent |
Consent given freely and based on information regarding a specific matter |
|
Anonymization |
The rendering of personal data into a form in which it cannot be linked to an identified or identifiable real person, even when combined with other data |
|
Related Person |
A real person whose personal data is processed (referred to as “Data Subject” in the Policy) |
|
Personal Data |
Any information relating to an identified or identifiable real person |
|
Processing of Personal Data |
Any operation performed on personal data, such as obtaining personal data by fully or partially automated means or by non-automated means provided that they form part of a data registration system, recording, storage, retention, modification, reorganization, disclosure, transfer, acquisition, making available, classification or prevention of the use of data |
|
Data Registration System |
A registration system in which personal data is structured and processed according to specific criteria |
|
Data Controller |
A real or legal person responsible for determining the purposes and means of processing personal data and for establishing and managing the data registration system |