Personal Data Storage and Destruction Policy
Personal Data Storage and Destruction Policy
CARPEX KURUMSAL HİJYEN ÇÖZÜMLERİ TİC. A.Ş.
PERSONAL DATA STORAGE, DESTRUCTION AND ANONYMIZATION POLICY
1.PURPOSE AND SCOPE
The Personal Data Storage and Destruction Policy (“Policy”) has been prepared to determine the procedures and principles regarding the storage and destruction activities carried out by Carpex Kurumsal Hijyen Çözümleri Tic. A.Ş. (referred to as “Carpex Kurumsal” or “Company”). As a Company, our fundamental principle is the processing of personal data belonging to product or service recipients, employees, employee candidates, service providers, visitors, and other third parties in accordance with the Constitution of the Republic of Turkey, International Conventions, the Law on the Protection of Personal Data No. 6698 (“Law”), and other relevant legislation.
In this context, it has been prioritized to ensure that relevant persons do not suffer loss of rights and can exercise their rights effectively. This Policy has been prepared in compliance with the Law No. 6698, the Regulation on the Deletion, Destruction or Anonymization of Personal Data (“Regulation”) published in the Official Gazette dated 28.10.2017 and numbered 30224, and other legislative provisions.
2.DEFINITIONS
|
Term |
Definition |
|
Recipient Group |
The category of natural or legal persons to whom personal data is transferred by the data controller. |
|
Explicit Consent |
Consent regarding a specific subject, based on information and expressed with free will. |
|
Anonymization |
Making personal data impossible to associate with an identified or identifiable natural person under any circumstances, even by matching it with other data. |
|
Employee |
Carpex Kurumsal personnel. |
|
Electronic Media |
Environments where personal data can be created, read, changed, and written with electronic devices. |
|
Non-Electronic Media |
All written, printed, visual, etc. media other than electronic media. |
|
Service Provider |
Natural or legal person providing services to the Personal Data Protection Authority within the framework of a specific contract. |
|
Data Subject (Relevant Person) |
The natural person whose personal data is processed. |
|
Relevant User |
Persons who process personal data within the organization of the data controller or in accordance with the authority and instructions received from the data controller, excluding the person or unit responsible for technical storage, protection, and backup of the data. |
|
Destruction |
Deletion, destruction, or anonymization of personal data. |
|
Law |
Personal Data Protection Law No. 6698. |
|
Recording Medium |
Any environment where personal data is processed by fully or partially automated means or by non-automated means provided that it is part of any data recording system. |
|
Personal Data |
Any information that makes a person identified or identifiable. |
|
Personal Data Processing Inventory |
An inventory in which data controllers detail their personal data processing activities based on business processes, associating them with the purposes and legal reasons for processing, data category, transferred recipient group, and data subject group, and explaining the maximum retention period required for the purposes for which personal data are processed, personal data envisaged to be transferred to foreign countries, and the measures taken regarding data security. |
|
Processing of Personal Data |
Any operation performed on data such as obtaining, recording, storing, preserving, changing, reorganizing, explaining, transferring, taking over, making available, classifying, or preventing the use of personal data by fully or partially automated means or by non-automated means provided that it is part of any data recording system. |
|
Board |
Personal Data Protection Board. |
|
Special Categories of Personal Data |
Data regarding race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, dress and appearance, membership to associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data. |
|
Periodic Destruction |
The process of deletion, destruction, or anonymization to be carried out ex officio at repeated intervals specified in the personal data storage and destruction policy in case all the conditions for processing personal data in the Law disappear. |
|
Policy |
Personal Data Storage and Destruction Policy. |
|
Data Processor |
Natural or legal person processing personal data on behalf of the data controller based on the authority granted by the data controller. |
|
Data Recording System |
The recording system where personal data are structured and processed according to specific criteria. |
|
Data Controller |
Natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system. |
|
Data Controllers Registry Information System |
The information system created and managed by the Presidency, accessible via the internet, which data controllers will use for application to the Registry and other relevant transactions. |
|
VERBİS |
Data Controllers Registry Information System. |
|
Regulation |
The Regulation on the Deletion, Destruction or Anonymization of Personal Data published in the Official Gazette dated October 28, 2017. |
3. RECORDING MEDIA
Personal data stored by Carpex Kurumsal is recorded in the environments shown in the table below and is kept in the most appropriate recording medium according to its nature and legal status.
|
Data Recording Medium |
Description |
|
Electronic Media |
Servers (Domain, backup, e-mail, database, web, file sharing, file server, etc.), Disk Units, Software (Office software, Intranet Portal, ERP software, “Netsis”, etc.), Information security devices (Firewall, intrusion detection and prevention, log files, anti-virus, etc.), Company computers (Desktop, laptop), Company-owned mobile devices (Phone, tablet, etc.), Optical disks (CD, DVD, etc.), Removable memories (USB, memory card, etc.) |
|
Non-Electronic Media |
Paper, Manual data recording systems (Notebooks, printed forms), Written, printed, visual media |
4. RESPONSIBILITY AND DISTRIBUTION OF DUTIES
Pursuant to Article 6, paragraph (f) of the Regulation, the titles, duties, and units of the persons involved in the storage and destruction processes of personal data are specified below.
|
Title |
Job Description |
|
Personal Data Manager |
Responsible for directing all kinds of planning, analysis, research, and risk identification studies in projects carried out during the Law compliance process; managing the processes that must be carried out in accordance with the Law, the Personal Data Processing and Protection Policy, the Personal Data Storage and Destruction Policy, and other regulated policies and procedures; and deciding on and responding to requests from relevant persons. |
|
Carpex Kurumsal Personal Data Protection Specialist (Technical and Administrative) |
Responsible for examining the requests of relevant persons and reporting them to the Personal Data Manager for evaluation; performing the transactions regarding the requests of relevant persons evaluated and decided by the Personal Data Manager in accordance with the decision of the Personal Data Manager; auditing the storage and destruction processes and reporting these audits to the Personal Data Manager; and carrying out the storage and destruction processes. |
|
Human Resources Manager |
Responsible for the execution and audit of policies and procedures in terms of personnel in accordance with job descriptions, and for audits regarding the protection, storage, and destruction of personal data. |
5. EXPLANATIONS REGARDING STORAGE AND DESTRUCTION
Personal data belonging to the persons served within the Company are processed in accordance with the matters specified by the Law and stored in the recording media specified in this policy, and are also destroyed in the manner specified in this policy.
In addition, our company stores and destroys personal data regarding its personnel. Personal data are stored based on one or more of the processing conditions specified in Articles 5 and 6 of the Law, and in this context, personal data are stored during the validity of the conditions specified for processing. When the said processing conditions end or upon the application of the relevant person to our Company (after checking other legal obligations that our Company must comply with), the personal data being stored are deleted, destroyed, or anonymized upon request.
Legal Reasons Requiring Storage
Personal data processed within the framework of the Company's activities are stored for the period stipulated in the relevant legislation. In this context, personal data are stored for the periods provided under:
-Labor Law No. 4857
-Turkish Commercial Code No. 6102
-Turkish Code of Obligations No. 6098
-Vocational Education Law No. 3308
-Occupational Health and Safety Law No. 6331
-Personal Data Protection Law No. 6698
-Tax Procedure Law No. 213
-Social Insurance and General Health Insurance Law No. 5510
- Industrial Property Law No. 6769
-Customs Law No. 4458
-Law No. 3577 on the Prevention of Unfair Competition in Imports
-Regulation on Occupational Health and Safety Services
-Other secondary regulations in force pursuant to these laws.
Processing Purposes Requiring Storage
The Company stores personal data for specific purposes. These purposes include, but are not limited to:
-Emergency Management
-Information Security
-Recruitment/Intern Selection
-Fulfillment of Employment Contract & Legal Obligations
-Finance and Accounting
-Physical Space Security
-Legal Affairs Tracking
-Occupational Health and Safety
-Logistics and Supply Chain Management
-Sales and After-Sales Support
-Marketing and Advertising
-Visitor Records
Reasons Requiring Destruction
Personal data shall be deleted, destroyed, or anonymized by the Company upon the request of the relevant person or ex officio in the following cases:
-Amendment or abolition of the relevant legislation serving as the basis for processing.
-Disappearance of the purpose requiring processing or storage.
-Withdrawal of explicit consent by the relevant person where processing is based solely on that consent.
-Acceptance by the Company of the application made by the relevant person for the deletion/destruction of data.
-The maximum storage period has expired and no conditions exist to justify longer storage.
6. TECHNICAL AND ADMINISTRATIVE MEASURES
Carpex Kurumsal takes all necessary technical and administrative measures appropriate to the nature of the personal data and the environment in which it is kept to ensure secure storage and prevent unlawful processing/access.
6.1 Technical Measures
-An authorization matrix has been created for employees.
-Authorizations of employees who change roles or leave the job are removed.
-Up-to-date anti-virus systems and firewalls are used.
- Physical security measures are taken for environments containing personal data.
-Log records are kept in a way that prevents user intervention.
6.2 Administrative Measures
-Disciplinary regulations containing data security provisions are in place.
-Training and awareness studies are conducted for employees.
-Corporate policies on access, security, usage, storage, and destruction have been implemented.
-Confidentiality agreements and undertakings are signed.
- Personal data is reduced as much as possible.
7. PERSONAL DATA DESTRUCTION TECHNIQUES
Personal data is deleted, destroyed, or anonymized ex officio or upon request when processing reasons disappear.
7.1 Deletion Methods
|
Method |
Description |
|
Blacking Out (Physical) |
Cutting out data from documents or making it invisible with permanent ink. |
|
Secure Software Deletion |
Deletion via digital command so that only the database manager can access it, making it unusable. |
|
Removal of Access Rights |
Removing user access rights from servers by the system administrator. |
7.2 Destruction Methods
|
Method |
Description |
|
Physical Destruction |
Using paper shredders for physical documents; melting, burning, or pulverizing optical/magnetic media. |
|
Degaussing |
Corrupting data on magnetic media by exposing it to a high magnetic field. |
|
Overwriting |
Writing random data (0s and 1s) at least seven times on rewriteable media. |
|
Cloud Destruction |
Deleting via digital command and destroying encryption keys upon termination of the cloud service relationship. |
7.3 Anonymization Methods
|
Method |
Description |
|
Variable Extraction |
Removing direct identifiers that could identify the person. |
|
Generalization |
Aggregating data into statistical values, removing distinguishing details. |
|
Masking |
Making data unintelligible (encryption, symbols, blurring) without changing the format. |
|
Data Shuffling |
Mixing or corrupting identifiers to break the link with the relevant person. |
8. STORAGE AND DESTRUCTION PERIODS
Regarding the personal data processed by Carpex Kurumsal within the scope of its activities;
-Retention periods for all personal data within the scope of activities carried out depending on the processes are specified on a personal data basis in the Carpex Kurumsal Personal Data Processing Inventory;
-Retention periods based on data categories are specified in the VERBIS registration;
-Retention periods based on processes are specified in the Personal Data Retention and Destruction Policy.Updates to the aforementioned retention periods are made by Carpex Kurumsal as deemed necessary.
8.1 Storage and Disposal
|
PROCESS |
STORAGE PERIOD |
DESTRUCTION PERIOD |
|
Human Resources Processes |
10 years following the end of activity |
First periodic destruction period following storage expiry |
|
OHS Personal Health Files |
15 years following resignation |
First periodic destruction period following storage expiry |
|
Log Records Systems |
10 years following the end of activity |
First periodic destruction period following storage expiry |
|
Internet Access Records |
2 years following the end of relationship |
First periodic destruction period following storage expiry |
|
Visitor Records |
1 year following the record |
First periodic destruction period following storage expiry |
|
Camera Recordings |
2 Months |
Destroyed on the first day following the storage period |
|
Contracts Execution |
10 years following the end of contract |
First periodic destruction period following storage expiry |
8.2 Data Destruction Periods
If the relevant person requests destruction:
-If all processing conditions have disappeared, the request is finalized within 30 days.
-If conditions have not disappeared, the request may be rejected with a reasoned explanation within 30 days.
9. PERIODIC DESTRUCTION PERIOD
Periodic destruction processes begin on [Date] and repeat every 6 (six) months.
10. PUBLICATION, STORAGE, AND UPDATING
The Policy is published in both physical (wet-signed) and electronic formats and is disclosed to the public on the Company's website. It is reviewed and updated as needed.
11. COMPLIANCE AND AMENDMENTS
The Company reserves the right to make changes to the policy due to legislative requirements or company policy. Date of Publication: ../../....