AK 212 Bayrampaşa Diş Sağlığı Hizmetleri Sanayi ve Ticaret Limited Şirketi
1. Introduction
1.1 Purpose
This Personal Data Retention and Disposal Policy (“Policy”) is prepared within the framework of the applicable legislation. AK 212 Bayrampaşa Diş Sağlığı Hizmetleri Sanayi ve Ticaret Limited Şirketi (hereinafter referred to as the “Company”) applies this Policy based on nationally accepted basic principles regarding personal data destruction. It includes the framework and principles regarding the necessary destruction works within the scope of the relevant legislation.
In the third paragraph of Article 7 of the Law on Protection of Personal Data (“Law”), there is the provision: “The procedures and principles regarding the deletion, destruction or anonymization of personal data are regulated by a regulation.” Pursuant to this provision and subparagraph (e) of the first paragraph of Article 22 of the Law, the Regulation on the Deletion, Destruction or Anonymization of Personal Data (“Regulation”) has been prepared by the Personal Data Protection Board (“Board”) and was published in the Official Gazette dated 28 October 2017 and numbered 30224.
Based on the above regulation, the purpose of this Policy is to determine the procedures and principles regarding the deletion, destruction or anonymization of the personal data processed by the Company in the conduct of its activities, in accordance with the Regulation.
1.2 Scope
Personal data belonging to employees, employee candidates, visitors, third parties with whom we cooperate, and third parties working in the Company are within the scope of this Policy. This Policy is applied in all recording environments where personal data owned or managed by the Company are processed, and in all activities for personal data processing.
1.3 Abbreviations and Definitions
| Concept | Definition |
|---|---|
| Recipient Group | Natural or legal person category to whom personal data is transferred by the data controller. |
| Open Consent | Consent on a particular subject, based on information and expressed with free will. |
| Anonymisation | Making personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching with other data. |
| Electronic Environment | Environments where personal data can be created, read, changed and written by electronic devices. |
| Non-Electronic Media | All written, printed, visual and other environments other than electronic media. |
| Related Person | Natural person whose personal data is processed. |
| Related User | Persons who process personal data within the organisation of the data controller or in line with the authorisation and instruction received from the data controller, excluding those responsible for technical storage, protection and backup. |
| Destruction | Deletion, destruction or anonymisation of personal data. |
| Law | Law No. 6698 on the Protection of Personal Data. |
| Recording Media | Any medium containing personal data that is fully or partially automated or processed by non-automatic means, provided that it is a part of any data recording system. |
| Personal Data | Any information relating to an identified or identifiable natural person. |
| Personal Data Owner | Natural person whose personal data is processed. |
| Processing of Personal Data | Obtaining, recording, storing, preserving, changing, rearranging, disclosing, transferring, taking over, making available, classifying or using personal data in whole or in part. |
| Personal Data Processing Inventory | Inventory associating personal data with processing purposes, data categories, transferred recipient groups, retention periods, and data security measures. |
| Board | Personal Data Protection Board. |
| Organisation | Personal Data Protection Authority. |
| Special Categories of Personal Data | Data on race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, dress, association/foundation/union memberships, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. |
| Periodic Destruction | The deletion, destruction or anonymisation process carried out ex officio at repetitive intervals when all of the personal data processing conditions are eliminated. |
| Policy | The policy on which data controllers base the process of determining retention periods and deletion, destruction, and anonymisation. |
| Record | The registry of data controllers kept by the Personal Data Protection Authority. |
| Data Processor | The natural or legal person who processes personal data on behalf of the data controller, based on the authority given by the data controller. |
| Data Logging System | The registry system where personal data is processed and structured according to certain criteria. |
| Data Controller | The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system. |
| Regulation | Regulation on the Deletion, Destruction or Anonymisation of Personal Data, published in the Official Gazette dated 28.10.2017 and numbered 30224. |
2. Distribution of Responsibilities and Duties
All units and employees of the Company actively support the responsible units in the implementation of technical and administrative measures taken within the scope of the Policy. This includes training and awareness of unit employees, continuous supervision, prevention of unlawful processing and access to personal data, and protection of personal data to ensure proper storage in all environments where personal data is processed.
The distribution of the titles, units, and job descriptions of those involved in the storage and destruction of personal data is given below.
Table 1: Task Distribution of Storage and Disposal Processes
| Title | Unit | Job Description |
|---|---|---|
| IT Officer | Computing | Ensuring compliance of processes with retention periods, management of the periodical destruction process, performing necessary audits and controls to respond to requests of Data Owners. |
| Accounting Department Manager | Accounting | Ensuring compliance of processes with storage periods, management of the periodical destruction period, checking the continuity of book and document storage obligations arising from the Turkish Commercial Code No. 6102 and Tax Legislation. |
| Director of Human Resources | Human Resources | Ensuring compliance of personnel personal data with the retention period, management of the periodical destruction process, receiving and responding to requests for clarification of personnel regarding their rights specified in the Law. |
3. Recording Environments
Personal data is stored securely by the Company in the environments listed in Table 2, in accordance with the law.
Table 2: Personal Data Storage Environments
| Electronic Media | Non-Electronic Media |
|---|---|
| Servers (domain, backup, email, database, web, file sharing, etc.) | Paper |
| Software (office software) and information security devices (firewall, log file, antivirus, etc.) | Manual data recording systems |
| Mobile devices (phone, tablet, etc.) | Written, printed, visual media |
| Optical discs (CD, DVD, etc.) | Files |
| Removable memories (USB, Memory Card, etc.) | Folders |
| Printer, scanner, copier | |
| Removable memory such as USB, hard disk | |
| Desktop and laptop computers |
4. Explanations on Storage and Disposal
The Company stores and destroys personal data of employees, employee candidates, suppliers, supplier officials, supplier employees, product/service buyers, potential product/service buyers, employees of persons receiving products/services, relatives of persons receiving products/services, shareholders/partners, visitors, and other third parties in accordance with KVKK.
4.1 Remarks on Retention
In Article 3 of the Law, the concept of processing personal data is defined. Article 4 states that personal data processed should be related to the purpose for which it is processed, limited, measured, and kept for the period required for that purpose or as stipulated in the relevant legislation.
Accordingly, within the framework of the Company’s activities, personal data is stored for a period stipulated in the relevant legislation or suitable for our processing purposes.
4.1.1 Legal Reasons for Retention
The Company preserves the personal data processed within the framework of its activities for the period stipulated in the relevant legislation. In this context, personal data is stored in accordance with the storage periods specified in the following legislation:
- Tax Procedure Law No. 213
- Health Services Basic Law No. 3359
- Labour Law No. 4857
- Social Insurance and General Health Insurance Law No. 5510
- Law No. 5651 on Regulation of Broadcasts on the Internet and Combating Crimes Committed Through These Broadcasts
- Turkish Code of Obligations No. 6098
- Turkish Commercial Code No. 6102
- Occupational Health and Safety Law No. 6331
- Law No. 6698 on the Protection of Personal Data
- Decree Law No. 663 on the Organisation and Duties of the Ministry of Health and its Affiliates
- Regulation on Private Health Institutions Providing Oral and Dental Health Services
- Private Hospitals Regulation, Health Practice Communiqué, Patient Rights Regulation
- Other secondary legislation in force
4.1.2 Processing Purposes Requiring Storage
The Company stores the personal data it processes within the framework of its activities for the following purposes:
- Execution of emergency management processes
- Execution of information security processes
- Execution of employee candidate / intern / student selection and placement processes
- Execution of the application processes of working candidates
- Fulfilment of obligations arising from employment contracts and regulations for employees
- Execution of fringe benefits and benefits processes for employees
- Conducting educational activities
- Execution of activities in accordance with the legislation
- Execution of finance and accounting works
- Providing physical space security
- Execution of assignment processes
- Conducting communication activities
- Carrying out human resources processes
- Execution / supervision of business activities
- Execution of occupational health / safety activities
- Carrying out business continuity activities
- Execution of logistics activities
- Execution of goods / services production and operation processes
- Execution of goods / service purchasing processes
- Execution of goods / service sales processes
- Execution of risk management processes
- Organisation and event management
- Execution of contract processes
- Follow-up of requests / complaints
- Ensuring the security of movable property and resources
- Execution of supply chain management processes
- Execution of medical diagnosis, treatment and care services
- Ensuring the security of data controller operations
- Foreign personnel work and residence permit procedures
- Providing information to authorised persons, institutions and organisations
- Execution of management activities
4.2 Reasons for Destruction
Personal data is deleted, destroyed, or anonymised by the Company ex officio or upon the request of the person concerned in the following cases:
- Amendment or repeal of the provisions of the relevant legislation that are the basis for processing
- The disappearance of the purpose requiring its processing or storage
- In cases where the processing of personal data is based only on explicit consent, the data subject withdraws their explicit consent
- Acceptance of the application made by the person concerned for the deletion and destruction of personal data in accordance with Article 11 of the KVKK
- In the event that the Company rejects the application made for the deletion or destruction of personal data, the response is found insufficient, or no response is given within the period stipulated in the KVKK, and the Board approves the resulting complaint
- The maximum period for keeping personal data has passed and there are no conditions to justify keeping the data for a longer period
5. Technical and Administrative Measures
Within the framework of adequate measures determined by the Board for special categories of personal data in accordance with Article 12 and Article 6(4) of the KVKK, the Company takes the following technical and administrative measures to keep personal data safe, prevent unlawful processing and access, and ensure lawful destruction.
5.1 Technical Measures
- Network security and application security are ensured.
- Security measures are taken within the scope of procurement, development, and maintenance of information technology systems.
- The security of personal data stored in the cloud is ensured.
- Firewalls are used.
- Personal data is backed up, and the security of the backed up data is also ensured.
- User account management and authorisation control systems are implemented and monitored.
- Encryption is applied.
- Data loss prevention software is used.
5.2 Administrative Measures
- The authorisations of employees who change roles or leave their position are removed.
- Confidentiality commitments are made.
- Necessary security measures are taken regarding entry and exit to physical environments containing personal data.
- The security of physical environments containing personal data against external risks (fire, flood, etc.) is ensured.
- The security of environments containing personal data is ensured.
- Personal data is minimised as much as possible.
6. Personal Data Disposal Techniques
At the end of the period stipulated in the relevant legislation or the storage period required for processing purposes, personal data is destroyed by the following techniques, ex officio or upon the application of the person concerned, in accordance with the relevant legislation.
6.1 Deletion of Personal Data
Table 3: Deletion of Personal Data
| Data Recording Environment | Explanation |
|---|---|
| Personal data in the physical environment | Deleted by using the obfuscation method or by keeping the document in a secure environment where it cannot be accessed by the relevant users. |
| Personal data on servers | The system administrator removes the access authorisation of the relevant users and deletes the personal data on the servers for those whose retention period has expired. |
| Personal data in databases | By assigning a role and permission, the relevant user is prevented from accessing the personal data in the database. |
| Personal data on portable devices (USB, hard disk, CD, DVD, etc.) | The user is denied access to the file. |
6.2 Destruction of Personal Data
Table 4: Destruction of Personal Data
| Data Recording Environment | Explanation |
|---|---|
| Personal data in the physical environment | Paper-based personal data that has expired its retention period is irreversibly destroyed in paper-shredding machines. |
| Personal data in peripheral and local systems (network devices, flash-based environments, optical systems, etc.) | Devices containing personal data are destroyed by physical processes such as burning, breaking into small pieces, or melting. The personal data on the device may also be rendered unreadable using demagnetisation methods. Additionally, random data entry on existing data using special software prevents recovery of old data. |
6.3 Anonymisation of Personal Data
Anonymisation of personal data means making personal data unable to be associated with an identified or identifiable natural person under any circumstances, even when matched with other data.
For personal data to be anonymised, it must be rendered unrelated to an identified or identifiable natural person using appropriate techniques for the recording medium and the relevant field of activity, including returning personal data and/or preventing matching with other data.
7. Storage and Disposal Times
Regarding personal data processed within the scope of its activities, the Company maintains:
- Retention periods on the basis of personal data for all personal data within the scope of activities — recorded in the Personal Data Processing Inventory
- Storage periods on the basis of data categories — recorded in VERBIS
- Process-based retention periods — included in this Personal Data Retention and Disposal Policy
Destruction of personal data is carried out in accordance with the storage periods determined by considering the relevant legislation. Personal data whose storage period has expired is deleted, destroyed, or anonymised during the periodic destruction periods determined by the Company.
Table 5: Process-Based Storage and Disposal Times
| Period | Storage Period | Disposal Time |
|---|---|---|
| Execution of human resources employee processes | 15 years from the employee’s departure | In the periodic destruction period of the first 6 months following the end of the storage period |
| Execution of processes regarding employee candidates | 1 year from the date of application | In the periodic destruction period of the first 6 months following the end of the storage period |
| Execution of contractual relations | 10 years after the expiration of the contract | In the periodic destruction period of the first 6 months following the end of the storage period |
| Camera Recordings | 30 days after registration | Automatically destroyed at the end of the recording period |
| Execution of Accounting and Finance Processes | 10 years following registration | In the periodic destruction period of the first 6 months following the end of the storage period |
| Execution of Patient File Processes | 20 years from creation | In the periodic destruction period of the first 6 months following the end of the storage period |
The ex-officio deletion, destruction, or anonymisation of personal data whose storage period has expired is carried out by the departments listed under Section 2 (Distribution of Responsibilities and Duties).
8. Periodic Disposal Time
In accordance with Article 11 of the Regulation, the period of periodic destruction is determined by the Company as 6 months. Accordingly, the Company performs periodic destruction in June and December every year.
9. Publication and Storage of the Policy
The Policy is published in two different media, with wet signature (printed paper) and electronically, and is disclosed to the public on the website. The printed paper copy is also kept in the file of the Human Resources Department.
10. Policy Update Period
The Policy is updated as needed and as processes change.
11. Enforcement and Revocation of the Policy
This Policy is deemed to have entered into force after its publication on the Company’s website.
If it is decided to be annulled, the wet-signed old copies of the Policy are cancelled with the company stamp and the signature of the company official (cancellation stamp or by writing “cancellation”) and are kept by the Human Resources Department for at least 5 years.
Contact
For any questions about this Policy, please contact us:
Email: [email protected]
Phone: +90850 888 5 212
Address: Yenidoğan, Abdi İpekçi Cd. No:55, 34030 Bayrampaşa, Istanbul, Turkey