Merhaba!

Kurumsal Kimliğimiz yenilendi.
Yeni web sitemize hoş geldiniz.

Sağlık yolculuğunuz
artık daha kolay.

Sizi daha iyi bilgilendirmek ve
sağlık hizmetlerimize daha hızlı
ulaşmanızı sağlamak için yanınızdayız.


Çakırtepe Hastanesi
Corporate

ÇAKIRTEPE HOSPITAL
PROTECTION AND PROCESSING OF PERSONAL DATA POLICY

1. INTRODUCTION

The Personal Data Protection Law (PDPL) No. 6698, published in the Official Gazette on 07.04.2016, aims to protect the fundamental rights and freedoms of individuals, particularly the privacy of personal life.

Within the scope of the PDPL, which was prepared in light of European Union regulations and international conventions, only the data of natural persons is protected. The Law includes principles and procedures that natural or legal persons processing data must comply with.

The Protection and Processing of Personal Data Policy, prepared based on the principles and rules stipulated in the Law and relevant regulations, includes the methods, principles, and purposes adopted in the data processing activities of the Company, the rights of data subjects, and application procedures. Our Company processes and protects your personal data with an awareness of its responsibilities, in line with its principles of transparency and respect for human rights.

2. PURPOSE AND SCOPE

This Policy aims to effectively implement the basic principles and rules adopted during the processing of personal data of third-party data subjects other than Company employees, suppliers, and business partners.

The Policy regulates the principles and rules the Company will apply in this process and the obligations imposed by the Law.

Employees within our Company are obliged to act in accordance with this Policy, the Law, and relevant legislation in applicable processes.

3. IMPLEMENTATION OF THE POLICY AND RESPONSIBILITIES

The Company, as the data controller, is responsible for the implementation of this Policy during data processing activities.

Employees, business partners, visitors, and all relevant third parties within the Company are obliged to act in accordance with this Policy and to cooperate with the Company to prevent legal liabilities and violations arising from the Law and relevant regulations.

This Policy will be published on the official website of the Company. In case of any changes in the Policy, the current Policy will be updated as soon as possible after the change and made accessible to data subjects.

4. PERSONAL DATA PROCESSING PRINCIPLES

The Company conducts its data processing activities in accordance with the following principles based on Article 4 of the Law;

Compliance with Law and Good Faith

The Company carries out personal data processing activities in accordance with relevant Laws and jurisprudence, primarily the Constitution, and the rule of good faith specified in Article 2 of the Turkish Civil Code.

Being Accurate and Up-to-Date When Necessary

The Company takes administrative and technical measures stipulated by the Law and relevant regulations to ensure the accuracy and currency of processed personal data. The accuracy and currency of the processed data will be audited upon the request of the data subject.

Processing for Specific, Explicit, and Legitimate Purposes

The Company processes personal data in connection with the stated purpose and considering the principle of transparency.

Being Relevant, Limited, and Proportionate to the Purposes for Which They are Processed

The Company processes personal data only to the extent required by the purpose, in connection with the processing purposes. As a rule, data that is not related to the processing purpose and does not serve this purpose will not be requested from data subjects.

Retention for the Period Stipulated in Relevant Legislation or Required for the Purpose of Processing

The Company retains personal data for the minimum period stipulated by the legal regulation governing the relevant data processing activity and the processing purpose.

Minimum periods are determined primarily by checking whether any period is stipulated in the relevant legal regulations; if there is no period regulation, it is determined according to the data processing purpose.

Although the Company has taken necessary technical and administrative measures to prevent exceeding the periods specified in the relevant legal regulations or the minimum retention periods determined according to the processing purpose; relevant data is destroyed at the end of the retention period, during the periodic destruction process, or upon the application of the data subject, using one of the deletion, destruction, or anonymization methods in accordance with the Company Destruction Policy.

5. CONDITIONS FOR PROCESSING PERSONAL DATA

Personal Data is processed with the explicit consent of the data subject if one of the conditions stipulated in Article 5 of the Law is absent.

In the presence of one of the conditions in the relevant legal provision, explicit consent of the data subject is not required to perform the data processing activity.

As a rule, Special Categories of Personal Data are processed only by obtaining the explicit consent of the data subject.

When Explicitly Provided for by Laws

Personal data may be processed if there is a provision in the relevant legal provisions stating that data can be processed.

When Necessary for the Protection of Life or Physical Integrity of the Person or Another Person Who is Unable to Express Consent Due to Actual Impossibility or Whose Consent is Not Legally Valid

Personal data may be processed to protect the life or physical integrity of the person or another person who is unable to express their consent due to actual impossibility or whose consent cannot be deemed valid.

When Necessary for the Processing of Personal Data of the Parties of a Contract, Provided That it is Directly Related to the Establishment or Performance of the Contract

The Company may process personal data if data processing is directly related to the establishment or performance of a contract.

When the Personal Data Has Been Made Public by the Data Subject Themselves

If the data subject has made their personal data public, the Company may process the relevant personal data limited to the purpose of making it public.

When Data Processing is Mandatory for the Establishment, Exercise, or Protection of Any Right

Personal data may be processed by the Company for the establishment, exercise, or protection of a right.

Processing of Personal Data for the Legitimate Interest of the Company

The Company may process personal data, provided that it does not violate the fundamental rights and freedoms of the data subject.

6. PROCESSING OF SPECIAL CATEGORIES OF PERSONAL DATA

In the Law, special categories of personal data are listed limitedly as data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and dress, membership of association, foundation or trade-union, health, sexual life, criminal conviction and security measures, and biometrics and genetics.

Special categories of personal data are processed by taking the technical and administrative security measures included in the relevant Law and regulations, and under the conditions stipulated in the relevant Law and regulations.

6.1. Processing Special Categories of Personal Data with Explicit Consent

As a rule, special categories of personal data can only be processed with the explicit consent of the data subject.

However, if there is a provision in the relevant laws regarding the data processing activity stating that data can be processed without explicit consent, the Company may process special categories of personal data without explicit consent.

6.2. Processing Special Categories of Personal Data Related to Health and Sexual Life for Preventive Medicine, Medical Diagnosis, Treatment, and Care Services...

Special categories of personal data relating to health and sexual life may be processed without seeking explicit consent only for the purposes of protection of public health, operation of preventive medicine, medical diagnosis, treatment, and care services, planning and management of health services and financing, by persons under the obligation of secrecy or authorized institutions and organizations.

Otherwise, the Company is obliged to obtain the explicit consent of the data subject to process the special categories of personal data in question.

6.3. Measures to be Taken in Processing Special Categories of Personal Data

Necessary technical and administrative measures have been taken to process special categories of personal data. Detailed information can be found in the Company's policy on the protection and processing of special categories of personal data.

7. TRANSFER OF PERSONAL DATA

The Company will act in accordance with the provisions of relevant legislation regarding the transfer of personal data and will adapt transfer processes to the provisions of legislation currently in force or to enter into force.

Transfer of personal data is divided into two: domestic data transfer and cross-border data transfer;

7.1. Domestic Transfer of Personal Data

Personal data of data subjects may be transferred domestically without seeking explicit consent if at least one of the personal data processing conditions stipulated in the second paragraph of Article 5 of the Law exists.

Otherwise, obtaining explicit consent of the data subject is mandatory.

7.1.1. Domestic Transfer of Special Categories of Personal Data

Special categories of personal data other than health and sexual life may be transferred domestically without seeking explicit consent, as stipulated in Paragraph 3 of Article 6 of the Law, if there is a provision in the law to which the data processing activity is subject stating that data can be processed.

Otherwise, obtaining explicit consent of the data subject is mandatory. The Company also applies the necessary technical and administrative measures for processing special categories of personal data during domestic data transfers.

7.2. Cross-Border Transfer of Personal Data

The Company may transfer the personal data of Data Subjects abroad without seeking explicit consent in cases stipulated in the second paragraph of Article 5 and the third paragraph of Article 6 of the Law; provided that the country to which the transfer is to be made is on the safe country list to be announced by the Board, or if the Data Controllers in the country to which the transfer is to be made commit to adequate protection in writing and the Board grants permission.

Otherwise, obtaining explicit consent of the data subject is mandatory.

8. DELETION, DESTRUCTION, OR ANONYMIZATION OF PERSONAL DATA

The Company retains personal data in accordance with the minimum periods stipulated in the relevant legislation governing the data processing activity or required by the processing purpose.

The retention period of personal data by the Company is primarily determined by checking whether there is a provision in the relevant legislation; if not, the necessary time for the data processing purpose is determined.

At the end of the determined retention periods, personal data is destroyed using determined destruction methods (deletion, destruction, or anonymization) in accordance with periodic destruction periods or data subject applications.

9. OBLIGATIONS OF THE COMPANY AS DATA CONTROLLER

9.1. Obligation to Inform

As stipulated in Article 10 of the Law, the Company is obliged to inform the data subject about;

  • The identity of the data controller and its representative, if any,
  • The purpose for which personal data will be processed,
  • The method and legal reasons for collecting personal data,
  • The rights of the personal data subject

In order to fulfill the obligation to inform lawfully, the Company has reviewed the issues included in the privacy notice, made necessary classifications, and transferred them to the inventory showing data processing processes.

9.2. Obligation to Ensure the Security of Personal Data

9.2.1. Obligation to Prevent Unlawful Processing of Personal Data

The Company is obliged to process personal data with the principles and conditions specified in the Law and relevant legislation and to take technical and administrative measures specified in the relevant legislation to prevent unlawful processing of personal data and unlawful access to processed data.

The Company has taken the necessary technical and administrative measures and established related procedures to prevent unlawful processing and access.

9.2.2. Administrative Measures to Ensure Lawful Processing of Personal Data

In order to process personal data lawfully, the Company has provided all its employees with necessary Personal Data Protection training and created awareness of data protection security.

The Company has made its employees aware of their obligations regarding processing any information and documents containing personal data in accordance with relevant laws, properly retaining data, and confidentiality; and informed them that these obligations continue after employment termination.

In case of a breach of these obligations, the Company may rightfully terminate the employment contract and claim damages from the employee.

Personal data inventories have been filled out by the units processing relevant data, and access to this data is only possible by the relevant unit.

Employee access is restricted for all data processed by the Company as a data controller.

Employees are granted access permissions only to data required by their job descriptions.

In order for units to lawfully fulfill their obligations in this Policy and relevant legal regulations, the Company has notified employees of necessary policies, procedures, and other related regulations.

9.3. Obligation to Prevent Unlawful Access to Personal Data

9.3.1. Technical measures for lawful access and preservation of personal data

The Company has taken technical and administrative measures stipulated in relevant regulations to prevent unlawful access to processed personal data; additionally, system security will be audited regularly.

Taken measures will be subjected to internal audits, an audit report will be presented to the authorized unit, and risky issues in the report will be resolved immediately.

Software and hardware including anti-virus programs and firewalls are used in all systems where the Company conducts data processing, and all programs will be kept up to date.

Access authorizations of units are restricted to ensure lawful access; user accounts and devices allowed to access systems containing personal data are limited.

The Company has provided necessary software/hardware to prevent external infiltration and avoid potential risks, and will conduct periodic penetration tests.

Personal data backups will also be protected with the same technical and administrative measures.

9.3.2. Administrative measures for the preservation of personal data

All Company employees have been made aware of the technical and administrative measures taken to prevent unlawful access to personal data.

Employee access authorization is limited to data processed in accordance with the personal data inventory.

The Company has prepared relevant documents regarding access authorizations and notified all employees.

9.4. Auditing of measures taken regarding personal data protection

The Company will have audits conducted regarding the operation of technical and administrative measures taken to protect personal data and establish systems for this purpose.

Audit reports will be forwarded to authorized units; improvement efforts will be initiated immediately for units deemed risky.

The Company will conduct activities, regular audits, and reporting to raise awareness among units, business partners, and suppliers regarding the processing and protection of personal data.

As stipulated in Article 12 of the Law, the Company is responsible for ensuring that third parties to whom personal data is transferred fulfill their obligations to process, retain, and lawfully access data.

10. RIGHTS OF THE DATA SUBJECT

As stipulated in Article 11 of the Law, the data subject has the right to apply to the Company, acting as the data controller, to;

  • Learn whether personal data is processed,
  • Request information if personal data has been processed,
  • Learn the purpose of processing personal data and whether they are used in accordance with their purpose,
  • Know the third parties to whom personal data is transferred at home or abroad,
  • Request rectification in case personal data is processed incompletely or inaccurately,
  • Request deletion or destruction of personal data within the framework of conditions stipulated in Article 7,
  • Request notification of rectification, deletion, or destruction operations to third parties to whom personal data has been transferred,
  • Object to the occurrence of a result against the person themselves by analyzing the processed data exclusively through automated systems,
  • Request compensation for damages in case of suffering damage due to unlawful processing of personal data.

When data subjects submit their requests regarding the above rights in writing or through other methods determined by the Board; the Company is obliged to conclude these requests within thirty days at the latest as stipulated in Article 13 of the Law.

The Company must convey responses in comprehensible language and illuminatingly.

Unless the data subject has an additional request regarding the delivery method, the Company must ensure delivery in writing or electronically through methods it chooses.

The Company may accept the application or decline it by providing necessary explanations in case of a justified reason.

If the request is rejected, the response is found insufficient, or not answered in time, the data subject has the right to file a complaint with the Board within thirty days.

11. ENTRY INTO FORCE AND UPDATES

This policy shall enter into force on the date it is approved by the Company's board of directors.

This policy is periodically updated at least once a year.

In addition, this Policy will be updated, amended, or recreated if necessitated by changes in legislation and decisions of the Board and courts.

The authority to abolish this Policy belongs to the Company's board of directors.

E-Appointment
E-Consultation
Contact Us