ÇAKIRTEPE HOSPITAL
PERSONAL DATA RETENTION AND DESTRUCTION POLICY
1. PURPOSE AND SCOPE
This Policy has been prepared in accordance with the Personal Data Protection Law (GDPR/PDPL) No. 6698 and the Regulation on the Deletion, Destruction or Anonymization of Personal Data drafted based on this Law, and regulates the principles of the Company (ÇAKIRTEPE SAĞLIK HİZ.TUR.LTD.ŞTİ) regarding the retention and destruction of personal data, and the methods and obligations to be followed during the retention and destruction activity.
This Policy covers personal data and special categories of personal data contained in the systems where the Company processes data by fully or partially automatic means, or by non-automatic means provided that they are part of any data recording system, as defined in the Law.
2. GENERAL SCOPE AND LEGAL BASIS
2.1. Legal, Technical or Other Reasons Requiring the Retention of Personal Data
Pursuant to the Personal Data Protection Law No. 6698, the Company, in its capacity as "Data Controller";
For the purpose of carrying out transportation and storage activities, it will be able to process, record, retain, update and transfer the personal data obtained from the direct or indirect parties of these activities to third parties as stipulated in the relevant legislation, as specified in the Policy on the Processing and Protection of Personal Data prepared in accordance with the Law and relevant legislation.
The Company may process personal data belonging to the identity, contact, customer, customer transaction, transaction security, legal transaction and compliance information categories from individuals such as customers, employees, employee candidates, business partners and suppliers.
2.2. Purposes of Processing Personal Data and Legal Reasons
By the Company;
- Realizing the processing purposes explained in the privacy notice, carrying out the specific activities of the Company and fulfilling the obligations towards the customers, organizing the relevant records and documents, fulfilling the information and document retention, reporting, information, audit, etc. obligations required by local and international legal regulations,
- Fulfilling information processing procedures, system infrastructure, requiring the received information processing support services, establishing communication in order to transfer the necessary information to the data subjects regarding the relevant services and products,
- Measuring and increasing customer satisfaction, complaint management, receiving opinions and suggestions regarding the services provided, receiving problem-error notifications, providing information regarding complaints and requests,
- Executing payment transactions, ensuring the delivery of necessary information and documents by establishing logistics cooperation with third parties,
- Fulfilling the obligations regarding the retention of necessary information and documents, reporting, information, auditing and the fulfillment of the contracts to which it is a party, in accordance with the official institutions and the provisions of the relevant legislation,
- Examining, evaluating and responding to requests from official institutions or data subjects,
- In line with the purpose of determining and implementing Company strategies; managing finance operations, health services financing, planning and provision of health services, communication, purchasing operations (request, offer, evaluation, order, budgeting, contract), internal system and application management operations, and legal activities carried out by the Company,
It will be processed in accordance with the personal data processing principles and conditions stipulated in Articles 5 and 6 of the Law for these purposes.
2.3. Technical and Administrative Measures Taken for the Lawful Destruction of Personal Data, Procedure to be Followed in Case the Conditions for Processing Personal Data Cease to Exist
The Personal Data Protection Committee audits whether the conditions related to the processing of personal data in the personal data processing inventory have disappeared in data recording systems in six-month periods.
Upon notification from the Board or the court, the personal data protection committee shall immediately take the necessary action regarding the decisions/notifications, regardless of the periodic audit period.
Regarding the personal data whose processing conditions are determined to have disappeared as a result of the periodic audits conducted by the personal data protection committee, it is decided to retain, delete, destroy or anonymize the data according to this Policy.
The personal data protection committee immediately implements the warrants or decisions issued by the Authority or the court, without prejudice to the Company's legal rights such as objection, appeal, etc.
In the event that a lawsuit is filed regarding the processing of Personal Data and this lawsuit is notified to the Corporate Customer / our Company, the Personal Data Protection Committee stops the deletion, destruction or anonymization of personal data until the end of the trial in order to prevent the destruction of evidence, even if the data processing conditions stipulated in Articles 5 and 6 of the Law are not met.
If the deletion of personal data will result in other data being inaccessible and unusable within the system;
Necessary technical and administrative measures are taken to ensure that personal data is archived in a way that it cannot be associated with the relevant person, is closed to the access of any other institution, organization and/or person, and is accessed only by the Personal Data Protection Committee and the technical personnel responsible for storing personal data to the extent required by the access, and thus the deletion of personal data is fulfilled.
The deletion of personal data that is part of any data recording system and processed by non-automatic means;
Is done by limiting the access of users other than the Personal Data Protection Committee and the technical personnel responsible for the retention of data.
To perform these operations, the Company uses software and other technical tools and equipment that will fulfill these functions.
In the event that the data subject requests the destruction of their personal data, or there is a Board or court decision regarding the destruction, or the conditions for processing personal data cease to exist/the statute of limitations expires, the Personal Data Protection Committee closes the personal data requested to be destroyed to the access of the relevant users in the physical or electronic recording environments where it is retained.
A data destruction report is kept regarding the deleted, destroyed or anonymized data, and these reports are kept for three years.
The data subject's request for the destruction of personal data is fulfilled by the Company officials within 30 days following the receipt of the request, provided that the conditions for processing personal data have completely disappeared.
The Company has the right to reject the request to delete, destroy or anonymize personal data if the conditions for processing personal data have not disappeared or if there is no legislation, Board or court decision to the contrary.
The rejection decision, along with its justification, is notified in writing or electronically to the data subject who made the request by the Contact Person within 30 days from the date of the request.
2.4. Administrative and Technical Measures Taken for the Secure Retention of Personal Data and the Prevention of Unlawful Processing and Access to Personal Data
Personal data, within the scope of administrative and technical measures taken regarding its retention and access in accordance with the Law and relevant legislation;
Is secured with the information security policy, administrative texts and policy, procedures and processing instructions.
This Policy and the changes and regulations to be made in the Policy are notified to all Company employees.
In addition, within the scope of GDPR/PDPL compliance efforts, all Company personnel are informed, necessary trainings are provided, and important developments are notified to all Company employees.
The audit and follow-up regarding the fulfillment of the duties and obligations specified in this Policy are carried out by the Personal Data Protection Committee.
In the event that the duties and obligations specified in the Policy are violated, the relevant unit Manager to whom the violating employee is affiliated is immediately notified and the relevant Manager takes the necessary measures to eliminate the violation.
Disciplinary penalties may be applied for the action to be taken against the employee acting contrary to the Policy, and depending on the severity of the violation, termination of the employment contract for a valid or just cause may also be carried out.
To fulfill the requirements of this Policy, necessary software/systems/applications are used by the Company, and the changes in the legislation and the changes that may occur due to the Board or court decisions notified to the Company are followed by the Contact Person and the Personal Data Protection Committee.
Necessary changes are made as soon as possible after the change occurs.
2.5. Duties and Responsibilities of Those Involved in Personal Data Retention and Destruction Processes
2.5.1. Personal Data Protection Committee
Personal Data Protection Committee;
- To ensure the implementation of this policy,
- To follow the changes made in the relevant legislation, Board and court decisions and changes in the infrastructure,
- To follow the activities related to data retention and destruction, to audit whether these activities comply with this Policy, to ensure the elimination of this violation in case an activity contrary to this Policy is detected,
- To receive or accept notifications or correspondence made by the Authority on behalf of the data controller,
- To receive the requests directed to the data controller by the Authority on behalf of the data controller and forward their responses to the Authority,
- Unless another procedure and principle is determined by the Board, to receive the applications directed to the data controller by the relevant persons in accordance with the first paragraph of Article 13 of the Law on behalf of the data controller and to forward the answers,
- To perform the affairs and transactions regarding the Registry on behalf of the data controller,
- To process the contact person information into the registry during registration on behalf of the data controller,
- To follow up and fulfill other obligations set forth in this policy,
Is obliged to fulfill its duties and responsibilities.
2.5.2. Duties and Powers of the Contact Person
The contact person is assigned to ensure communication regarding answering the requests directed to the data controller by the data subject.
The duties and powers of the contact person stipulated in the Law are listed below;
- Unless another procedure and principle is determined by the Board, to receive the applications directed to the Data Controller by the data subjects on behalf of the Data Controller and forward them to the Personal Data Protection Committee,
- Unless another procedure and principle is determined by the Board, to forward the Data Controller's response to the applications of the data subjects on behalf of the Data Controller,
- The Company is obliged to provide all kinds of information and documents requested during audits within the framework of the Commercial Code and its regulations, to present the books and documents and keep them ready for inspection, and to keep all information and documents related to Company transactions for 10 years.
3. PERSONAL DATA RETENTION AND DESTRUCTION PERIODS
The Company is obliged to provide all kinds of information and documents requested during audits, to present the books and documents and keep them ready for inspection in accordance with the Commercial Code and relevant regulations, and all relevant information and documents will be retained by the Company for 10 years.
Due to the fact that the general statute of limitations for receivables is stated as 10 years in Article 146 of the Code of Obligations No. 6098 and there is an obligation to retain documents for 10 years in Article 82 of the Turkish Commercial Code No. 6102, personal data is retained for 10 years from the date of the last transaction in order for the Data Controller to fulfill its legal obligation, protect its legitimate interests and provide the documents to the judicial authorities in case of need.
As stipulated in the provision of Article 7/1-b of the Regulation on Occupational Health and Safety Services, health and safety records belonging to Company employees are retained for 15 years, and in accordance with the relevant articles of the Social Insurance and General Health Insurance Law No. 5510, other personal data other than health and safety records belonging to Company employees are retained for 10 years.
Personal data obtained from support service companies, corporate customers and supplier companies;
Due to the fact that the general statute of limitations for receivables is regulated as 10 years in Article 146 of the Code of Obligations No. 6098 and the retention of documents for 10 years is stipulated in Article 82 of the Turkish Commercial Code No. 6102, it is retained for a period of 10 years from the date of the last transaction in order for the Company to fulfill its legal obligation, protect its legitimate interests and submit the documents to the judicial authorities if requested.
Personal Data Retention and Destruction Periods Table
| Data Subject | Description | Retention/Destruction Period |
|---|---|---|
| Direct or indirect parties of Company transactions | Personal Data | 10 years |
| Personnel | Personal Data | 10 years |
| Personnel | Health and Safety Records | 15 years |
| Support service provider/Supplier | Personal Data | 10 years |
In the first 6-month periodic destruction time interval following the expiration of the periods stipulated in the table, personal data is deleted by closing it to the access of the relevant users.
Personal data closed to the access of the relevant users is archived in such a way that it is open only to the access of the Personal Data Protection Committee and the technical personnel assigned to retain the data, to the extent required by the access.
4. ENFORCEMENT
- This Policy was approved by the Board of Directors Decision.
- This Policy enters into force on the date it is accepted by the Board of Directors.
- The provisions of this Policy are executed by the Personal Data Protection Committee.