ASSOC. PROF. DR. Nu0130LAY u015eENGu00dcL CLINIC
PERSONAL DATA RETENTION AND DISPOSAL POLICY
u00a0
- INTRODUCTION
- Purpose of the Policy
In accordance with Article 20 of the Constitution, titled u201cPrivacy of Private Life,u201d the Law No. 6698 on the Protection of Personal Data (u201cthe Lawu201d), and the provisions of applicable regulations and circulars, this policy governs the processing of personal data collected by Assoc. Prof. Dr. Nilay u015eengu00fcl. It aims to protect the fundamental rights and freedomsu2014primarily the right to privacyu2014of data subjects (employees, job applicants, patients, patientsu2019 relatives, suppliers, interns, visitors, and other relevant third parties)u2014primarily the right to privacyu2014and to ensure that the data controller processes personal data in compliance with the law, and to establish the principles governing the protection, storage, and, when necessary, destruction of the personal data collected.
- Scope of the Policy
Any information relating to an identified or identifiable natural person is considered personal data. This Policy covers the collection, recording, storage, retention, modification, reorganizing, disclosing, transferring, acquiring, making available, classified, or restricted from useu2014is considered a data processing activity; therefore, the establishment of the procedures and principles governing the data processing activities carried out by Assoc. Prof. Dr. Nilay u015eengu00fcl defines the scope of this Policy.
- Application of the Policy and Relevant Legislation
Your personal data and personal health data are processed in accordance with the purposes outlined in this policy and the following legislation: the Basic Law on Health Services No. 3359, the Decree Law No. 663 on the Organization and Duties of the Ministry of Health and Its Affiliated Institutions, the Private Hospitals Regulation, the Regulation on the Processing of Personal Health Data and the Protection of Privacy, relevant regulations, andu2014primarilyu2014Law No. 6698, as well as the regulations, circulars, decisions, and guidelines published by the Board. In the event that any changes are made to the Law or other relevant legislation after the Policyu2019s publication date, and the Policy becomes inconsistent with such changes, the amended provisions and rules shall apply. All circulars, decisions, and guidelines published by the Board are monitored by Assoc. Prof. Dr. Nilay u015eengu00fcl, and the rules set forth in the Policy are kept up to date.
u00a0
- Entry into Force of the Policy
The Policy has been published on the nilaysengul.com website owned by Assoc. Prof. Dr. Nilay u015eengu00fcl and entered into force on the date of publication.
- MATTERS RELATING TO THE PROTECTION OF PERSONAL DATA
2.1. Ensuring the Security of Personal Data
Pursuant to Article 12 of Law No. 6698, the data controller:
- Prevent the unlawful processing of personal data,
- prevent unlawful access to personal data,
- Ensure the preservation of personal data,
is obligated to take all necessary administrative and technical measures to ensure an appropriate level of security.
For the reasons stated above, Assoc. Prof. Dr. Nilay u015eengu00fcl implements security measures to prevent the unlawful processing, transfer to third parties, and disclosure of personal data, as well as unauthorized access and security vulnerabilities arising through other means. Explanations regarding the administrative and technical measures taken are provided in Section VI. ADMINISTRATIVE AND TECHNICAL MEASURES TAKEN FOR THE PROTECTION OF PERSONAL DATA.
2.2. Protection of Special Category Personal Data
Sensitive personal data, such as the health data of data subjects, may be processed without the data subjectu2019s explicit consent solely for the purposes of protecting public health, preventive medicine, and the provision of medical diagnosis, treatment, and care services, planning and managing healthcare services and their financing, by persons or authorized institutions and organizations subject to a duty of confidentiality. Furthermore, regardless of their type, all special category personal data may be processed in accordance with the law only if the adequate safeguards specified by the KVKK are implemented.
The personal data you share with us as part of our clinical activities; may be processedu2014whether through automated or non-automated meansu2014by Assoc. Prof. Dr. Nilay u015eengu00fcl for the purposes of protecting public health, providing preventive medicine, conducting medical diagnosis, treatment, and care services, and planning and managing healthcare services and their financing; collected, recorded, stored, modified, and reorganized through all channelsu2014including websites, surveys, social media applications such as corporate social responsibility initiatives, as well as verbal, written, visual, or electronic mediau2014via the helpline/call center, website, verbal, written, and similar channels. Under the KVKK, any operation performed on data is considered u201cprocessing of personal data.u201d
Additionally, when you use our helpline or website for information, appointments, complaints, or other purposes related to service provision, or when you visit our clinic or website and browse this site, your personal data may be processed.
Data that is sensitive by nature and could lead to the data subject suffering harm or discrimination if it falls into the hands of third parties is classified as u201cSpecial Category Personal Datau201d under the Law. Special-category personal data consists of data related to a personu2019s race, ethnic origin, political opinions, philosophical beliefs, religion, denomination, or other beliefs, dress and attire, membership in associations, foundations, or labor unions, health, sex life, criminal convictions, and security measures, as well as biometric and genetic data. Sensitive personal data may not be processed without the explicit consent of the data subject. Assoc. Prof. Dr. Nilay u015eengu00fcl ensures that all necessary measures are taken to protect sensitive personal data, and the principle is to avoid collecting and processing such data as much as possible.
III. MATTERS RELATED TO THE PROCESSING OF PERSONAL DATA
3.1. Processing of Personal Data in Accordance with the Principles Set Forth in the Legislation
Pursuant to Article 4 of the Law, the principles to be applied in the processing of your personal data are as follows:
- Compliance with the law and the principle of good faith,
- Accuracy and, where necessary, up-to-date status,
- Processing for specific, explicit, and legitimate purposes,
- Processing that is relevant, limited, and proportionate to the purpose for which it is processed,
- Retention for the period prescribed by applicable legislation or as necessary for the purpose of processing.
3.2. Conditions for the Processing of Personal Data
Personal data collected by Assoc. Prof. Dr. Nilay u015eengu00fcl may not be processed without the explicit consent of the data subject, except for the exceptions provided for in the Law. Your personal data may be processed without explicit consent in the following cases:
- When explicitly provided for by law,
- Where it is necessary to protect the life or physical integrity of the individualu2014or another personu2014whose consent cannot be expressed due to actual impossibility or whose consent is not legally valid,
- Where the processing of personal data belonging to the parties to a contract is necessary, provided that such processing is directly related to the conclusion or performance of the contract,
- Where it is necessary for the data controller to fulfill its legal obligations,
- The data has been made public by the data subject themselves,
- Where the processing of data is necessary for the establishment, exercise, or protection of a right,
- Where the processing of data is necessary for the legitimate interests of the data controller, provided that such processing does not infringe upon the fundamental rights and freedoms of the data subject.
3.3. Exceptions to the Obligation to Obtain Explicit Consent
- Explicitly Provided for by Law
One of the conditions for data processing is that it is explicitly provided for by law. Provisions in laws stating that personal data may be processed may constitute a condition for data processing. In such a case, obtaining the data subjectu2019s explicit consent is not required.
- Actual Impossibility
In cases where it is necessary to protect the life or physical integrity of the data subject or another person, and the data subject is unable to express consent due to actual impossibility or their consent is not legally valid, the data subjectu2019s personal data may be processed without obtaining their explicit consent.
- Directly Related to the Conclusion or Performance of a Contract
If the processing of personal data is necessary for the conclusion or performance of a contract to which the data subject is a party, the processing of personal data may take place without obtaining explicit consent.
- Assoc. Prof. Dr. Nilay u015eengu00fclu2019s fulfillment of her legal obligations
As the data controller, Assoc. Prof. Dr. Nilay u015eengu00fcl may process personal data without obtaining explicit consent for the purpose of fulfilling her legal obligations.
- Personal data made public by the data subject
Personal data that has been made public by the data subjectu2014in other words, personal data that has been disclosed to the public in any wayu2014may be processed without obtaining explicit consent. Even in such cases, the personal data that has been made public may not be used for purposes other than those for which it was originally disclosed.
- Necessity for the establishment, exercise, or protection of a right
In cases where it is necessary for the establishment, exercise, or protection of a right, the data subjectu2019s personal data may be processed even without their explicit consent.
- Where it is necessary for the legitimate interests of the data controller, provided that it does not infringe upon the data subjectu2019s fundamental rights and freedoms
If the processing of personal data is necessary from the data controlleru2019s perspective and the data processing activity will not infringe upon the data subjectu2019s fundamental rights and freedoms, personal data may be processed without obtaining explicit consent.
The data controlleru2019s legitimate interest is directed toward the benefit and advantage it will derive from the processing to be carried out. The benefit to be derived by the data controller must relate to a legitimate interest that is sufficiently substantial, specific, and currently existing to balance against the data subjectu2019s fundamental rights and freedoms. The processing must be related to the data controlleru2019s current activities and must provide a benefit to the data controller in the near future.
3.4. Processing of Special Category Personal Data
The processing of special category personal data is subject to Article 6 of the Law, and such processing is prohibited without the data subjectu2019s explicit consent.
Data concerning a personu2019s race, ethnic origin, political opinions, philosophical beliefs, religion, denomination, or other beliefs; attire; membership in associations, foundations, or unions; health; sexual life, criminal convictions, and security measures, as well as biometric and genetic data, constitute special category personal data. The scope of such data is limited and cannot be expanded through interpretation.
By their very nature, special category personal data are data that, if disclosed, could lead to the data subject being subjected to discrimination or harm. For this reason, they must be protected much more rigorously than other personal data.
- Sensitive personal data other than that related to health and sexual life
Sensitive personal data other than that related to health and sexual life may be processed without the data subjectu2019s explicit consent in cases provided for by law.
- Special-category personal data related to health and sexual life
Special-category personal data related to health and sexual life may only be processed by persons subject to a duty of confidentiality or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, and the provision of medical diagnosis, treatment, and care services, as well as the planning and management of health services and their financing.
3.5. Informing and Notifying the Data Subject
During the collection of personal data, Assoc. Prof. Dr. Nilay u015eengu00fcl, in her capacity as the data controller, or persons authorized by her, provides information to the data subjects. The procedures and principles regarding this notification are specified in the u201cInformation Texts on the Protection of Personal Datau201d published by Assoc. Prof. Dr. Nilay u015eengu00fcl; the notification summarily includes the following elements:
- The identity of the data controller and, if applicable, their representative,
- The purposes for which personal data will be processed,
- To whom and for what purposes personal data may be transferred,
- The method and legal basis for collecting personal data,
- The rights of the data subject as set forth in Article 11 of the Law.
- Identity of the data controller and its representative
In accordance with Article 10 of the Law, personal data obtained from data subjects (employees, job applicants, patients, patientsu2019 relatives, suppliers, pharmacies, visitors, interns, and other relevant third parties) are processed by Assoc. Prof. Dr. Nilay u015eengu00fcl in her capacity as the data controller; contact information for the relevant unit can be obtained via email at info@nilaysengul.comor the website nilaysengul.com.
- Purposes of Processing Personal Data
The processing of personal data is carried out for specific, explicit, and legitimate purposes and is based on the principle of informing data subjects. The purposes for which your collected data is processed are outlined in Section V of the Policy, titled u201cCATEGORIZATION AND PURPOSES OF PROCESSING OF PERSONAL DATA PROCESSED BY ASSOC. PROF. DR. Nu0130LAY u015eENGu00dcL CLINIC.u201d
- Recipients of Personal Data and Purposes of Transfer
Within the framework of the data controlleru2019s obligation to inform the data subject, the parties to whom personal data is transferred and the purposes of such transfers must be clearly specified. Personal data may not be transferred to third parties without the data subjectu2019s explicit consent. The recipient groups to whom personal data is transferred and the purposes of such transfers, as outlined by Assoc. Prof. Dr. Nilay u015eengu00fcl, are presented in Section IV. TRANSFER OF PERSONAL DATA.
u00a0
u00a0
u00a0
u00a0
- Method and Legal Basis for Collecting Personal Data
In accordance with Articles 5 and 6 of the Law, the data controller must clearly specify which of the conditions for processing personal data serves as the basis for such processing. The method and means of data collection are determined by the data controller. The conditions for processing personal datau2014that is, the grounds for lawful processingu2014are enumerated in a limited number in the Law (Articles 5u20136) and cannot be expanded.
The data controller, Assoc. Prof. Dr. Nilay u015eengu00fcl, assesses whether the purpose of the personal data processing activity is primarily based on one of the processing conditions other than explicit consent; and if this purpose does not meet at least one of the conditions other than explicit consent specified in the Act, the data controller proceeds to obtain the individualu2019s explicit consent to continue the data processing activity.
- TRANSFER OF PERSONAL DATA
4.1. Domestic Transfer
Personal data may not be transferred without the data subjectu2019s explicit consent. However:
- As provided in the second paragraph of Article 5,
- provided that adequate safeguards are in place, if any of the conditions
the data may be transferred without the data subjectu2019s explicit consent.
Accordingly, personal data may be transferred if explicitly provided for by law (1); if it is necessary to protect the life or physical integrity of the data subjectu2014who is unable to express consent due to actual impossibilityu2014or of another person, or if the data subjectu2019s consent is not legally valid (2); it is necessary to process personal data belonging to the parties to a contract, provided that such processing is directly related to the conclusion or performance of the contract (3), it is necessary for the data controller to fulfill its legal obligations (4), the data has been made public by the data subject themselves (5), the processing of data is necessary for the establishment, exercise, or protection of a right (6), provided that it does not harm the data subjectu2019s fundamental rights and freedoms, and where processing is necessary for the legitimate interests of the data controller, personal data pertaining to the data subject may be transferred to third parties without obtaining the data subjectu2019s explicit consent.
Your personal data and personal health data will be processed in accordance with the purposes outlined in this policy and within the framework of the Basic Law on Health Services No. 3359, the Decree-Law No. 663 on the Organization and Duties of the Ministry of Health and Its Affiliated Institutions, the Personal Data Protection Law No. 6698, the Private Hospitals Regulation, the Regulation on the Processing of Personal Health Data and the Protection of Privacy, and other relevant regulations;
For the purposes of fulfilling our contractual and legal obligations and conducting our clinicu2019s administrative, commercial, and economic activities, we may share your personal health data with the Ministry of Health, the Social Security Institution, the General Directorate of Security and other law enforcement agencies, Cu0130MER, SABu0130M, the Ministry of Labor, the General Directorate of Population, courts, and enforcement offices, the Turkish Pharmacistsu2019 Association, regulatory and supervisory bodies, insurance companies, representatives authorized by patients, partner laboratories, and other centers, as well as to Electronic Medical Records and Electronic Health Records systems.
Information regarding the recipient groups to which your personal data processed by Assoc. Prof. Dr. Nilay u015eengu00fcl is transferred is provided in Section 4 of this Policyu2014Third Parties to Whom Personal Data Is Transferred and the Purposes of Transfer.
4.2. Cross-Border Transfer
Personal data may not be transferred abroad without the explicit consent of the data subject. However, this does not apply if one of the conditions specified in the second paragraph of Article 5 and the third paragraph of Article 6 of the Law is met, and if the foreign country to which the personal data is to be transferred provides
- Adequate protection is in place,
- If adequate protection is not available, the data controllers in Turkey and the relevant foreign country must commit in writing to providing adequate protection, and the Boardu2019s authorization must be obtained,
the personal data may be transferred abroad without the explicit consent of the data subject.
- CATEGORIZATION OF PERSONAL DATA PROCESSED BY THE ASSOC. PROF. DR. Nu0130LAY u015eENGu00dcL CLINIC AND PURPOSES OF PROCESSING
The categorization of data obtained by Assoc. Prof. Dr. Nilay u015eengu00fcl and the purposes for which personal data is processed are outlined in the relevant sections of the privacy notices available on our website for each category of data subject.
u00a0
- ADMINISTRATIVE AND TECHNICAL MEASURES TAKEN TO PROTECT PERSONAL DATA
Assoc. Prof. Dr. Nilay u015eengu00fcl has implemented administrative and technical measures to ensure the secure storage of personal data and to prevent its unlawful processing and unauthorized access.
To ensure the security of personal data, Assoc. Prof. Dr. Nilay u015eengu00fcl identifies the types of personal data being processed and assesses the likelihood of risks related to the protection of such data; In identifying these risks, the following factors are taken into account: whether the personal data constitutes special-category personal data (1), the level of confidentiality required by the nature of the data (2), and the nature and extent of potential harm to the data subject in the event of a security breach (3).
After these risks are identified and prioritized, control measures and solutions aimed at mitigating or eliminating them are evaluated in accordance with the principles of cost, feasibility, and effectiveness, and the necessary technical and administrative measures are planned and implemented.
6.1. Administrative Measures
In the event of attacks that could compromise personal data security or related to cybersecurity, it is of great importance for employees to take initial action, even if they have limited knowledge, to ensure the security of personal data. For this reason, as the data controller, we conduct awareness and training initiatives within our internal organization.
Providing employees with the necessary training on topics such as the unlawful disclosure or sharing of personal data, conducting awareness campaigns for employees, and creating an environment where security risks can be identified; ensuring that the roles and responsibilities regarding personal data security for everyone working under the data controlleru2014regardless of their positionu2014are defined in their job descriptions, and that employees are aware of their roles and responsibilities in this regard.
Furthermore, confidentiality agreements are signed as part of the employee onboarding process, and a disciplinary process is in place to address instances where employees fail to comply with security policies and procedures.
In the event of any changes to the policies and procedures regarding personal data security, training sessions are conducted to notify and explain the changes to employees, ensuring that information regarding data security and related threats remains up to date.
In accordance with Article 4(b) and (d) of the Law, personal data must be accurate and up-to-date when necessary and retained for the period prescribed by relevant legislation or as long as necessary for the purpose for which it is processed. Within this scope, the data processed is handled in accordance with the principles and rules that must be observed in data processing activities, and are retained for as long as necessary for the purpose for which they are processed. The retention periods for personal data processed by Assoc. Prof. Dr. Nilay u015eengu00fcl are set forth in Section VIII. RETENTION AND DISPOSAL OF PERSONAL DATA of this Policy.
The table below provides a summary of the administrative measures taken to ensure data security:
|
Administrative Measures |
|
Preparation of the Personal Data Processing Inventory |
|
Corporate Policies (Access, Information Security, Use, Retention, and Destruction, etc.) |
|
Contracts (Between Data Controllers, and Between Data Controllers and Data Processors) |
|
Confidentiality Agreements |
|
Internal Periodic and/or Random Audits |
|
Risk Analyses |
|
Employment Contracts, Disciplinary Regulations (Inclusion of Provisions Compliant with the Law) |
|
Corporate Communications (Crisis Management, Processes for Informing the Board and Relevant Parties, Reputation Management, etc.) |
|
Training and Awareness Activities (Information Security and the Law) |
|
Notification to the Data Controller Registry Information System (VERBu0130S) |
|
Personal Data Security Policies and Procedures |
|
Rapid Reporting of Personal Data Security Incidents |
|
Monitoring of Personal Data Security |
|
Establishment of Disciplinary Regulations for Employees That Include Data Security Provisions |
|
Minimizing Personal Data as Much as Possible |
|
Developing and Implementing Corporate Policies on Access, Information Security, Use, Storage, and Disposal |
|
Revoking Authorizations in This Area for Employees Who Change Roles or Leave the Company |
|
Inclusion of Data Security Provisions in Signed Contracts |
|
Identifying Existing Risks and Threats |
|
Conducting Periodic and/or Random Internal Audits |
|
Establishing and Implementing Protocols and Procedures for the Security of Special Category Personal Data |
|
Ensuring Data Security Awareness Among Data Processing Service Providers |
6.2. Technical Measures
Among the measures taken to protect our information technology systems containing personal data against unauthorized access and threats from third parties over the internet, firewalls and network gateways are used. The firewall in use helps prevent breaches of the information network, while the network gateway restricts employeesu2019 access to websites or online platforms that pose a threat to personal data security.
In addition, regular checks are conducted to ensure that software and hardware are functioning properly and that the security measures in place for the systems are adequate. Access to systems containing personal data is restricted; within this scope, employees are granted access permissions only to the extent necessary for the work and duties they perform, as well as their authorities and responsibilities, and access to the relevant systems is provided through the use of a username and password. When creating these passwords, the organization avoids, as much as possible, sequences of numbers or letters that are related to personal information or are easy to guess.
Access authorization and control matrices are established within the data controlleru2019s organization; furthermore, to protect against malicious software, products such as antivirus and antispam software that regularly scan the information systems network and detect threats are used.
To ensure data security, paper documents containing personal data, as well as servers, backup devices, CDs, DVDs, USB drives, and other similar storage devices, are restricted to authorized personnel only, and necessary measures are taken to enhance physical security in this regard.
The table below provides a
:
|
Technical Measures |
|
Authorization Matrix |
|
Authorization Control |
|
Access Logs |
|
User Account Management |
|
Network Security |
|
Application Security |
|
Encryption |
|
Intrusion Detection and Prevention Systems |
|
Data Loss Prevention Software |
|
Backup |
|
Firewalls |
|
Up-to-Date Antivirus Systems |
|
Deletion, Destruction, or Anonymization |
|
Key Management |
VII. PERSONAL DATA PROCESSING ACTIVITIES AT BUILDING AND FACILITY ENTRANCES AND WITHIN BUILDINGS AND FACILITIES
7.1. Video Surveillance Activities Conducted at Building and Facility Entrances and Inside Buildings and Facilities
Under the Law on Private Security Services, video surveillance is conducted at the Assoc. Prof. Dr. Nilay u015eengu00fcl building, work areas, common areas, parking lot, and surrounding areas to ensure security and to protect the interests related to the safety of Assoc. Prof. Dr. Nilay u015eengu00fcl and other individuals. Camera surveillance is conducted in compliance with the Law and is carried out in accordance with the data processing conditions set forth in both the Law and this Policy.
u00a0
7.2. Tracking of Visitor Entries and Exits at Building and Facility Entrances and Inside the Premises
For the purpose of controlling and tracking entries and exits to the Assoc. Prof. Dr. Nilay u015eengu00fcl building and ensuring security, the identification information of guests visiting Assoc. Prof. Dr. Nilay u015eengu00fcl is subject to personal data processing activities. The personal data processed within the scope of this activity is limited solely to the purpose of recording guestsu2019 entries and exits, and the relevant personal data is recorded in a data recording system in either electronic or physical form.
VIII. STORAGE AND DISPOSAL OF PERSONAL DATA
8.1. Retention Periods for Personal Data
Your personal data held by Assoc. Prof. Dr. Nilay u015eengu00fcl is retained for as long as necessary for the data processing activity; and if an obligation to erase, destroy, or anonymize personal data arises, such data will be erased, destroyed, or anonymized within the first periodic destruction period following the date on which the obligation arises.
Assoc. Prof. Dr. Nilay u015eengu00fcl acts in accordance with the general principles set forth in Article 4 of the Law and the technical and administrative measures specified in Article 12 regarding the erasure, destruction, or anonymization of your personal data.
All processes related to the erasure, destruction, or anonymization of personal data by our organization are documented and retained for at least 30 years, as required by law, for the duration of the processing of personal data.
The personal data specialist appointed by Assoc. Prof. Dr. Nilay u015eengu00fcl is responsible for implementing and overseeing the policy on the retention and destruction of personal data.
8.2. Obligation to Erase, Destroy, and Anonymize Personal Data
Personal data processed by Assoc. Prof. Dr. Nilay u015eengu00fcl is deleted, destroyed, or anonymized ex officio or upon the request of the relevant data subject once the grounds requiring its processing in accordance with Article 7 of the Law and the provisions of the u201cRegulation on the Deletion, Destruction, or Anonymization of Personal Data,u201d are deleted, destroyed, or anonymized either on our own initiative or upon the request of the relevant data subject once the reasons requiring their processing no longer exist.
u00a0
- Erasure of Personal Data
The erasure of personal data is the process of rendering personal data inaccessible and unusable in any way by the relevant users.
All necessary technical and administrative measures are taken to ensure that deleted personal data is inaccessible and cannot be reused by the relevant users.
- Destruction of Personal Data
The destruction of personal data is the process of rendering personal data inaccessible, irrecoverable, and unusable by anyone in any way. The data controller is obligated to take all necessary technical and administrative measures regarding the destruction of personal data.
- Anonymization of Personal Data
Anonymization of personal data is the process of rendering personal data incapable of being associated with any identified or identifiable natural person, even if matched with other data.
Your personal data is anonymized by Assoc. Prof. Dr. Nilay u015eengu00fcl through the application of methods consistent with our personal data retention and destruction policy, while taking all necessary technical and administrative measures.
8.3. Techniques for the Deletion, Destruction, and Anonymization of Personal Data
The techniques for erasing, destroying, or anonymizing personal data processed by Assoc. Prof. Dr. Nilay u015eengu00fcl are listed below; the specific technique applied may vary depending on the nature of the personal data being processed.
To this end, the first step is to identify the personal data subject to deletion, destruction, or anonymization (1); next, using an access authorization and control matrix or a similar system, identify the relevant users for each piece of personal data (2); identifying the relevant usersu2019 permissions and methods regarding access, retrieval, and reuse (3), and deactivating and removing the relevant usersu2019 permissions and methods for accessing, retrieving, and reusing the personal data (4).
The procedure followed for the deletion of personal data is as follows:
- Issuing a deletion command in cloud or application-based solutions,
- Redacting, cutting, or rendering data on paper media unreadable,
- Deleting data stored on removable media using appropriate software.
The procedure followed for the destruction of personal data is as follows:
- Physical destruction by melting, burning, or pulverizing optical and magnetic media,
- Other destruction processes performed on paper or electronic media.
- RIGHTS OF THE DATA SUBJECT AND THE EXERCISE OF THESE RIGHTS
9.1. Rights of the Data Subject
Pursuant to Law No. 6698, as a data subject, you have the right to:
- To learn whether your personal data has been processed,
- If your personal data has been processed, to request information regarding such processing,
- To learn the purpose of the processing of your personal data and whether it is being used in accordance with that purpose,
- To know the third parties to whom your personal data has been transferred, both within and outside the country,
- To request the correction of your personal data if it has been processed incompletely or incorrectly,
- Request the erasure or destruction of your personal data within the framework of the conditions set forth in this provision,
- To request that third parties to whom your personal data has been transferred be notified of the rectification of incomplete or incorrect data and the erasure or destruction of such data,
- To object to a decision made solely through the automated processing of your personal data that adversely affects you,
- You have the right to request compensation for any damage suffered as a result of the unlawful processing of your personal data.
9.2. Exercising the Data Subjectu2019s Rights
Requests regarding the application of the Law by the data subject must be submitted in writing to Assoc. Prof. Dr. Nilay u015eengu00fcl via the contact email address info@nilaysengul.com or to the address Memorial u015eiu015fli Hospital, u015eiu015fli / Istanbul. For such requests, the u201cData Subject Request Formu201d published on the website by Assoc. Prof. Dr. Nilay u015eengu00fcl must be used.
9.3. Assoc. Prof. Dr. Nilay u015eengu00fclu2019s Response to Requests
Depending on the nature of the request, Assoc. Prof. Dr. Nilay u015eengu00fcl will process it as soon as possible. This period may not exceed 30 days from the date the request is properly served to us. However, if the process incurs any costs, a fee may be charged in accordance with the tariff determined by the Personal Data Protection Board.
APPENDIX 1: Definitions
Explicit consent: Consent that is specific to a particular matter, based on information provided, and freely given;
Anonymization: The process of rendering personal data incapable of being associated with any identified or identifiable natural person, even when combined with other data;
Recipient group: The category of natural or legal persons to whom the data controller transfers personal data,
Direct identifiers: Identifiers that, on their own, directly reveal, disclose, and distinguish the person to whom they relate,
Indirect identifiers: Identifiers that, when combined with other identifiers, reveal, disclose, or distinguish the individual to whom they relate,
Data subject: The natural person whose personal data is being processed,
Relevant user: Natural or legal persons who process personal data within the data controlleru2019s organizationu2014excluding the person or unit responsible for the technical storage, protection, and backup of the datau2014or who process personal data in accordance with the authority and instructions received from the data controller,
Destruction: The erasure, destruction, or anonymization of personal data,
Law: The Law on the Protection of Personal Data No. 6698 dated March 24, 2016,
Redaction: Processes such as crossing out, blacking out, or blurring the entirety of personal data so that it cannot be associated with an identified or identifiable natural person,
Data Storage Medium: Any medium containing personal data processed either fully or partially by automated means, or by non-automated means provided that it forms part of a data recording system,
Personal data: Any information relating to an identified or identifiable natural person,
Processing of personal data: Any operation or set of operations performed on personal data, whether fully or partially automated or carried out by non-automated means as part of a data recording system, such as the collection, recording, storage, retention, alteration, restructuring, disclosure, transfer, acquisition, making available, classification, or restriction of use of personal data,
Board: The Personal Data Protection Board,
Agency: The Personal Data Protection Agency,
Data Processor: A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller,
Data recording system: A recording system in which personal data is processed according to specific criteria,
Data Controller: A natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system,
Identification Information: Your first name, last name, Turkish ID number, passport number, or temporary Turkish ID number; your place and date of birth; your marital status; your gender; your insurance or patient ID number; and any other identifying information that can be used to identify you;
Contact Information: Your address, phone number, email address, and other contact information; personal data obtained from voice call recordings retained by customer service representatives or patient services in accordance with call center standards, as well as personal data collected when you contact us via email, letter, or other means;
Financial Information: Your financial data, such as your bank account number, IBAN number, credit card information, and billing details; data related to private health insurance for the purposes of financing and planning healthcare services; and your Social Security Institution data; If you visit our clinic, your images from camera recordings retained for security and monitoring purposes;
Health Information: Your laboratory results, test results, examination data, appointment information, and prescription information, as well as any other personal health and sexual life-related data obtained during or as a result of the provision of medical diagnosis, treatment, and care servicesu2014including but not limited to the aforementionedu2014by Assoc. Prof. Dr. Nilay u015eengu00fcl, if you submit a job application, your personal data provided in this contextu2014including your resumeu2014as well as any other personal data related to your employment contract if you are an employee or affiliated employee of Assoc. Prof. Dr. Nilay u015eengu00fcl.
u00a0
u00a0
u00a0
u00a0
u00a0
APPENDIX 2: Data Subjects (Data Subjects)
|
Categories of Data Subjects |
Description |
|
Employee |
Refers to individuals working within the clinic. |
|
Job Applicant |
Refers to individuals who have applied for a job at the clinic by submitting a resume or through other means. |
|
Intern |
Refers to individuals who are applying their professional training in a practical setting at the clinic to enhance their professional knowledge. |
|
Patient |
Refers to individuals who receive services provided by the Clinic. |
|
Family Member |
Refers to the companions or relatives of patients who use the services provided by the clinic. |
|
Supplier |
Refers to individuals and employees of legal entities from whom services are procured. |
|
Visitor |
Refers to third parties visiting the Clinic. |
|
Other Relevant Third Parties |
Refers to individuals other than those who have applied to or communicated with the Clinic. |
u00a0
APPENDIX 3: Third Parties to Whom Personal Data Is Transferred
|
Recipient/Entity to Which Data Is Transferred |
Purpose of Transfer |
|
Ministry of Health |
Transfer of information required by public health and legislation. |
|
Social Security Institution |
Transfer of information for the purpose of processing matters related to employees, job applicants, and patients under the Social Security system. |
|
Authorized Public Institutions and Organizations |
Sharing/transferring information and documents requested by the Clinic with relevant public institutions and organizations, strictly limited to the purpose of such requests. |
|
Suppliers |
Transfer of personal data, limited to the purpose of procuring services from suppliers. |
u00a0
u00a0
Any personal data collected by Assoc. Prof. Dr. Nilay u015eengu00fcl may be processed in accordance with the stated purposes; verifying your identity, protecting public health, providing preventive medicine, conducting medical diagnosis, treatment, and care services, planning and managing healthcare services and their financing, planning and managing the Clinicu2019s operations and daily activities, procuring medications, informing you about your appointment if you have scheduled one, carrying out risk management and quality improvement activities, conducting evaluations to improve healthcare services, conducting research, complying with legal and regulatory requirements, verifying your relationship with institutions that have agreements with the clinic, billing for our healthcare services; sharing requested information with private insurance companies as part of the financing of healthcare services; sharing requested information with the Ministry of Health and relevant public institutions and organizations in accordance with applicable legislation; responding to any questions or complaints regarding our healthcare services; taking all necessary technical and administrative measures regarding data security for our clinicu2019s systems and applications; analyzing your use of our healthcare services and storing your health data for the purpose of developing and improving the healthcare services we provide; providing the necessary information to regulatory and supervisory bodies in accordance with the requests and audits of official authorities; training and developing our employees; monitoring, preventing, and reversing instances of misuse and unauthorized transactions; retaining information regarding your health data that must be stored in accordance with applicable legislation; ensuring financial reconciliation with our contracted institutions regarding the healthcare services provided to you; measuring patient satisfaction; and, without limitation to the foregoing, the provision and development of medical diagnosis, treatment, and care services; the planning and management of healthcare services and their financing; enhancing patient satisfaction; and research and similar purposes.
APPENDIX 5: Retention Periods
|
Personal Data Category |
Retention Period |
Legal Basis |
|
Health Data (Biometric, genetic, and examination data; laboratory, test, analysis, and diagnostic results; check-up and prescription information; patient records; and other health data, including, but not limited to, information obtained from patientsu2019 relatives when necessary) |
30 years from the termination of the personal data processing activity |
Regulation on Private Hospitals, Turkish Penal Code |
|
All Records Related to Accounting and Financial Transactions |
10 years |
Law No. 6102, Law No. 213 |
|
Cookies and Log Records |
6 Months u2013 Up to 2 Years |
Internet Law No. 5651 |
|
Traffic Information Regarding Online Visitors |
2 Years |
Law No. 5651 |
|
Personal Data Regarding Suppliers |
10 years after the legal relationship ends |
Law No. 6102, Law No. 6098, and Law No. 213 |
|
Personal Data Protection Board Proceedings |
10 years |
Personal Data Retention and Destruction Policy Published by the Personal Data Protection Authority (KVKK) |
|
Contracts |
10 Years from the Termination of the Contract |
Law No. 6102 and Law No. 6098 |
|
Human Resources Processes |
10 Years from the Termination of the Activity |
Labor Law No. 4857 and Related Legislation |
|
Visitor Log |
2 Years from the End of the Event |
Personal Data Retention and Destruction Policy Published by the Personal Data Protection Authority (KVKK) |
|
Data Related to Personnel Files Retained Under the Labor Code |
10 years from the termination of the employment relationship |
Labor Code No. 4857 and Related Legislation, and the Turkish Code of Obligations No. 6098 |
|
Data Collected Under Occupational Health and Safety (OHS) Legislation (Medical reports, OHS training records, records related to occupational health and safety activities, etc.) |
15 years from the termination of the employment relationship |
Occupational Health and Safety Law No. 6331 and Related Legislation |
|
Data retained under Social Security Institution (SGK) regulations (employment registration forms, contribution/service records, etc.) |
10 years from the termination of the employment relationship |
Social Insurance and General Health Insurance Law No. 5510 and Related Legislation |
|
Data Related to Job Applications (CV, Resume, Cover Letter, Application Form, etc.) in Cases Where the Application Is Not Accepted |
1 year |
Industry practices apply. |
|
Personal Data Processed in Contractual Relationships |
10 years following the termination of the contract |
Turkish Code of Obligations No. 6098 |
|
Personal Data Related to Tax Records |
5 Years |
Turkish Tax Procedure Code No. 213 |
|
Personal Data Processed for Security Purposes via CCTV Cameras (Camera Recordings) |
90 Days |
Industry Practice |
|
Traffic Data Processed During the Use of the Clinicu2019s Internet Network, Internet Access, and Remote Connections (IP address, start and end times of the service provided, type of service used, amount of data transferred, and, if applicable, subscriber identification information, etc.) |
2 Years |
Law No. 5651 on the Regulation of Publications Made on the Internet and the Fight Against Crimes Committed Through Such Publications |
|
Personal Data of a Deceased Person |
At Least 20 Years |
Regulation on Personal Health Data, published in the Official Gazette No. 30808 dated June 21, 2018 |
