• Home
  • Special Categories of Personal Data Retention and Destruction Policy

Special Categories of Personal Data Retention and Destruction Policy

Special Categories of Personal Data Retention and Destruction Policy


 

NEVRESTA TURİZM MİMARLIK İNŞAAT İŞLETMECİLİK TİCARET ANONİM ŞİRKETİ

 

 

 

KVKK

SPECIAL CATEGORIES OF PERSONAL DATA RETENTION AND

DESTRUCTION POLICY

 

 

Address               : Mustafa Kemal Mah. Dumlupınar Bul. No: 266a İç Kapı No: 18 Çankaya /Ankara

Phone            : 0(312) 770 03 33

Web                  : https://www.akropol.com

E-mail              : bilgi@akropol.com

 

 

 

 

Table of Contents

1. PURPOSE.. 3

2. DEFINITIONS. 3

3. PROCESSING OF SPECIAL CATEGORIES OF PERSONAL DATA 5

4. TECHNICAL AND ADMINISTRATIVE MEASURES TAKEN TO PROTECT SPECIAL CATEGORIES OF PERSONAL DATA. 6

4.1 ADMINISTRATIVE MEASURES. 6

4.2 TECHNICAL MEASURES. 7

4.2.1. Technical Measures Taken with Respect to Special Categories of Personal Data Stored and/or Accessed in Electronic Media 7

4.2.2. Technical Measures Taken with Respect to Special Categories of Personal Data Stored and/or Accessed in Physical Media 7

5. TRANSFER OF SPECIAL CATEGORIES OF PERSONAL DATA 7

5.1. Transfer by E-mail.. 7

5.2. Transfer via Media Such as Portable Memory Devices, CDs and DVDs.. 8

5.3. Transfer Between Servers in Different Physical Locations.. 8

5.4. Transfer in Paper Form.. 8

6. RETENTION AND DESTRUCTION OF SPECIAL CATEGORIES OF PERSONAL DATA 8

7. TECHNIQUES FOR THE DESTRUCTION OF SPECIAL CATEGORIES OF PERSONAL DATA 9

7.1. Deletion of Special Categories of Personal Data 9

7.1.1. Secure Deletion of Personal Data on Servers by Software. 9

7.1.2. Secure Deletion by an Expert. 10

7.1.3. Redaction of Personal Data in Paper Form 10

Table 4: Deletion of Personal Data 10

7.2. Destruction of Special Categories of Personal Data 10

7.2.1. Degaussing. 10

7.2.2. Physical Destruction. 11

7.2.3. Overwriting. 11

7.2.4. Cloud Destruction 11

7.2.5. Destruction of Personal Data in Peripheral Systems 11

Table 5: Destruction of Special Categories of Personal Data 11

7.3. Anonymization of Special Categories of Personal Data 11

7.3.1. Anonymization Methods That Do Not Introduce Value Irregularity 12

7.3.2. Anonymization Methods That Introduce Value Irregularity 12

7.3.3  Assurance of Anonymity 13

8. RETENTION AND DESTRUCTION PERIODS 13

9. UPDATES. 14

 

 

1. PURPOSE

The purpose of this Policy on the Protection and Processing of Special Categories of Personal Data, prepared by Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi, is to fulfill the legal obligations arising from the decision of the Personal Data Protection Board dated 31/01/2018 and numbered 2018/10 on “Adequate Measures to Be Taken by Data Controllers in the Processing of Special Categories of Personal Data,” and to set out the technical and administrative measures taken in the processing of special categories of personal data. Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi, acting as the Data Controller, shall hereinafter be referred to as the “Company.”

Recipient Group

The category of natural or legal persons to whom personal data are transferred by the Data Controller.

Explicit Consent

Consent relating to a specific matter, based on information and expressed of free will.

Relevant User

Persons who process personal data within the Data Controller’s organization or in accordance with the authorization and instructions received from the Data Controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.

Data Subject

The natural person whose personal data are processed. (Also referred to in the “Policy” as the “data owner.”)

Employee

Personnel employed by Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi

Electronic Media

Media in which personal data can be created, read, modified and written by means of electronic devices.

Non-Electronic Media

All other written, printed, visual and similar media outside electronic media.

Service Provider

A natural or legal person providing services to Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi within the framework of a specific agreement.

Destruction

The deletion, destruction or anonymization of personal data.

Law

Personal Data Protection Law No. 6698

Recording Medium

Any medium containing personal data processed by fully or partially automated means, or by non-automated means provided that they form part of a data recording system.

Personal Data Processing Inventory

The inventory created by data controllers detailing the personal data processing activities they carry out in connection with their business processes, by associating such activities with the purposes and legal basis for processing, the data category, the recipient group to which data are transferred and the data subject group, and by specifying the maximum retention period necessary for the purposes for which the personal data are processed, the personal data envisaged to be transferred abroad, and the measures taken with regard to data security.

Processing of Special Categories of Personal Data

Any operation performed on personal data, whether by fully or partially automated means or by non-automated means provided that they form part of a data recording system, such as collection, recording, storage, preservation, alteration, reorganization, disclosure, transfer, takeover, making available, classification or prevention of use.

Anonymization of Special Categories of Personal Data

Rendering personal data incapable of being associated in any way with an identified or identifiable natural person, even when matched with other data.

Deletion of Special Categories of Personal Data

The deletion of personal data; rendering personal data inaccessible and non-reusable in any way for Relevant Users.

Destruction of Special Categories of Personal Data

The process of rendering personal data inaccessible, irretrievable and non-reusable by anyone in any way.

Policy

Policy on the Processing, Retention and Destruction of Special Categories of Personal Data

Board

Personal Data Protection Board

Special Categories of Personal Data

Data relating to individuals’ race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and attire, membership of associations, foundations or trade unions, health, sex life, criminal convictions and security measures, as well as biometric and genetic data.

Biometric

Fingerprints, palm prints, face, iris, retina, ear, voice, signature, gait, hand vein, body odor and DNA information of individuals fall within the scope of biometric data. A general concept encompassing the unique physical or behavioral characteristics that enable the identification of individuals.

Periodic Destruction

The deletion, destruction or anonymization process to be carried out ex officio at recurring intervals specified in the personal data retention and destruction policy where all of the conditions for processing personal data set forth in the Law cease to exist.

Data Owner/Data Subject

The natural person whose personal data are processed

Data Processor

A natural or legal person who processes personal data on behalf of the Data Controller based on the authority granted by the Data Controller.

Data Controller

A natural or legal person who determines the purposes and means of processing personal data and who is responsible for establishing and managing the data recording system.

Data Controllers’ Registry Information System

The information system, accessible via the internet, established and managed by the Presidency of the Personal Data Protection Authority, which data controllers use to apply to the Registry and for other procedures relating to the Registry.

VERBİS

Data Controllers’ Registry Information System

Regulation

The Regulation on the Deletion, Destruction or Anonymization of Personal Data, published in the Official Gazette on October 28, 2017

 

Data relating to individuals’ race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and attire, membership of associations, foundations or trade unions, health, sex life, criminal convictions and security measures, as well as biometric and genetic data, constitute special categories of personal data.

The Company complies with the Law and other applicable legislation in the processing of special categories of personal data. Accordingly, special categories of personal data are processed in accordance with the following principles:

·         Lawfulness and fairness

·         Accuracy and, where necessary, being kept up to date

·         Being relevant, limited and proportionate to the purposes for which they are processed

·         Being processed for specified, explicit and legitimate purposes

·         Being retained for the period stipulated in the relevant legislation or necessary for the purposes for which they are processed

By way of exception, the processing of special categories of personal data is permitted where:

a) the Data Subject has given Explicit Consent;

b) it is expressly provided for by law;

c) it is necessary for the protection of the life or physical integrity of a person, or of another person, who is unable to express consent due to actual impossibility or whose consent is not legally valid;

ç) it relates to personal data made public by the Data Subject and is in line with the Data Subject’s intention to make such data public;

d) it is necessary for the establishment, exercise or protection of a right;

e) it is necessary for the protection of public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning, management and financing of health services, by persons under an obligation of confidentiality or by authorized institutions and organizations;

f) it is necessary for the fulfillment of legal obligations in the fields of employment, occupational health and safety, social security, social services and social assistance; or

g) it concerns current or former members of foundations, associations and other non-profit organizations or entities established for political, philosophical, religious or trade union purposes, or persons who are in regular contact with such organizations and entities, provided that the processing complies with the legislation to which they are subject and their purposes, is limited to their fields of activity, and the data are not disclosed to third parties.

In such cases, the foregoing statutory provisions are relied upon.

In addition, in the processing of health data, the provisions of the Regulation on Personal Health Data, published in Official Gazette No. 30808 dated 21.06.2019 and entered into force on that date, are also complied with.

The Company takes the adequate measures announced by the Personal Data Protection Authority in order to ensure that special categories of personal data are processed in compliance with the Law and the relevant legislation and to ensure the security of special categories of personal data. The measures taken in this context are listed below:

·         The Company provides regular training on the confidentiality of special categories of personal data to employees involved in the processing of such data.

·         The Company enters into confidentiality agreements with its employees to ensure data security.

·         The scope and duration of the authorizations of users with access to the data are clearly defined, and periodic authorization checks are carried out.

·         The personal data access rights of employees who change roles or leave the Company are revoked immediately. In this context, the Company promptly retrieves any assets allocated to such employees.

4.2.1. Technical Measures Taken with Respect to Special Categories of Personal Data Stored and/or Accessed in Electronic Media

·         Special categories of personal data are stored using cryptographic methods.

·         Cryptographic keys are kept in secure and separate environments.

·         Transaction records of all actions performed on special categories of personal data are securely logged.

·         Security updates for the environments in which special categories of personal data are located are continuously monitored, the necessary security tests are regularly performed or commissioned, and the test results are recorded.

·         User authorizations are defined for the software through which special categories of personal data are accessed, security tests of such software are regularly performed or commissioned, and the test results are recorded.

·         Where remote access to special categories of personal data is provided, at least a two-factor authentication system is used.

·         Adequate security measures are taken according to the nature of the environment in which special categories of personal data are located.

·         The physical security of these environments is ensured, and unauthorized entry and exit are prevented.

The Company transfers special categories of personal data within the framework of the data processing conditions set forth in Articles 8 and 9 of the Law. In order to ensure data security, the following rules are applied by the Company in data transfers, and periodic audits are carried out in this regard.

Where special categories of personal data are transferred by e-mail, the transfer is made in encrypted form using a corporate e-mail address or a Registered Electronic Mail (KEP) account.

Where special categories of personal data are transferred via media such as portable memory devices, CDs or DVDs, the data are encrypted using cryptographic methods and the cryptographic key is kept in a separate environment.

In the transfer of special categories of personal data between servers in different physical locations, the data are transferred by establishing a VPN between the servers or by using the sFTP method.

Where special categories of personal data must be transferred in paper form, the necessary precautions are taken against risks such as theft, loss or viewing of the documents by unauthorized persons, and the documents are sent in the “classified documents” format.

Special categories of personal data are retained by the Company in the following cases, in accordance with the Law, other applicable legislation and the Board’s decision on Adequate Measures to Be Taken by Data Controllers in the Processing of Special Categories of Personal Data:

·         Where the Explicit Consent of the Data Subject has been obtained

·         Where the retention of special categories of personal data other than those relating to health and sex life is provided for by law

·         Where data relating to health and sex life are retained for the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning and management of health services and their financing

·         Special categories of personal data retained by the Company in accordance with the Law and other applicable legislation are deleted, destroyed or anonymized ex officio or upon the request of the Data Subject upon the occurrence of any of the following:

·         Withdrawal of Explicit Consent, where the retention of special categories of personal data is based on the Explicit Consent of the Data Subject

·         The purpose of retaining the special categories of personal data has been fulfilled, has become impossible or has otherwise ceased to exist

·         Amendment or repeal of the statutory provisions forming the basis for the retention of special categories of personal data

·         All of the processing conditions set forth in Article 6 of the Law have ceased to exist

·         A request duly submitted by the Data Subject to the Company for the destruction of their special categories of personal data is deemed justified and approved by the Company

·         Where the Company rejects an application made by the Data Subject for the destruction of their special categories of personal data, its response is found insufficient, or it fails to respond within the period stipulated in the Law, a complaint is filed with the Board and the request is found appropriate by the Board.

Personal data obtained by the Company in accordance with the KVKK and other relevant legislation shall, where the personal data processing purposes listed in the Law and the Regulation cease to exist, be destroyed by the Company ex officio or upon the application of the Data Subject, likewise in accordance with the Law and the relevant legislation, using the techniques set out below.

 

The procedures and principles applied by the Company regarding the techniques for the deletion and destruction of personal data are set out below.

 

7.1.1. Secure Deletion of Personal Data on Servers by Software

Data processed by fully or partially automated means and stored in digital media shall be deleted using methods for deleting the data from the relevant software in such a manner that the data are rendered inaccessible and non-reusable in any way for Relevant Users.

 

Where the relevant data are deleted in the cloud system by issuing a delete command, the process shall be carried out using methods such as revoking the relevant user’s access rights to the file, or to the directory containing the file, on the central server; deleting the relevant rows in databases using database commands; or deleting data on portable media, i.e., flash media, using appropriate software.

 

However, where the deletion of personal data within the Company would, when necessary, result in other data also becoming inaccessible and unusable within the system, the personal data shall also be deemed deleted if they are archived in a manner that prevents their association with the Data Subject, provided that the following conditions are met:

 

·         The data are closed to access by any other institution, organization or person;

·         All necessary technical and administrative measures are taken to ensure that the personal data can be accessed only by authorized persons.

 

 

 

7.1.2. Secure Deletion by an Expert

Where it deems necessary, the Company may engage an expert to delete personal data on its behalf. In such a case, the personal data are securely deleted by a person with expertise in this field in such a manner that they are rendered inaccessible and non-reusable in any way for Relevant Users.

 

7.1.3. Redaction of Personal Data in Paper Form

In order to prevent the use of personal data for purposes other than those intended, or to delete data whose deletion has been requested, personal data may also be deleted by physically cutting the relevant personal data out of the document, or by covering them with permanent ink so that they become invisible in an irreversible manner and cannot be read by means of technological solutions.

Table 4: Deletion of Personal Data

Data Recording Medium

Description

Personal Data on Servers

For personal data on servers whose required retention period has expired, deletion is carried out by the system administrator by revoking the access authorization of the relevant users.

Personal Data in Electronic Media

Personal data in electronic media whose required retention period has expired are rendered inaccessible and non-reusable in any way for other employees (Relevant Users), except for the database administrator.

Personal Data in Physical Media

Personal data kept in physical media whose required retention period has expired are rendered inaccessible and non-reusable in any way for all employees other than the manager of the unit responsible for the document archive. In addition, redaction is applied by striking through, painting over or erasing the data so that they cannot be read.

Personal Data on Portable Media

Personal data kept on flash-based storage media whose required retention period has expired are encrypted by the system administrator and stored in secure environments with encryption keys, with access authorization granted solely to the system administrator.

 

The destruction methods to be used by our Company are set out below.

7.2.1. Degaussing

A method whereby magnetic media are subjected to physical alteration in a high-strength magnetic field so that the data on them are corrupted and rendered unreadable.

 

 

 

7.2.2. Physical Destruction

Personal data may also be processed by non-automated means, provided that they form part of a data recording system. Physical destruction is the process of physically destroying such data so that they cannot subsequently be used. In particular, written paper, notebooks and microfiches are destroyed in this manner.

 

7.2.3. Overwriting

Overwriting is a data destruction method that makes it impossible to read and recover the old data by writing random data consisting of 0s and 1s at least eight times over magnetic media and rewritable optical media using special software.

 

7.2.4. Cloud Destruction

The process of destroying all copies of the encryption keys of personal data stored on cloud systems after notice of the destruction of such personal data has been given to the contracted service provider.

 

7.2.5. Destruction of Personal Data in Peripheral Systems

Devices containing personal data within systems such as printers, fingerprint units and door access turnstiles are destroyed by overwriting, degaussing or physical destruction. These destruction operations are performed before the devices are subjected to backup, maintenance and similar operations.

 

Table 5: Destruction of Special Categories of Personal Data

Data Recording Medium

Description

Personal Data in Physical Media

Personal data in paper form whose required retention period has expired are irreversibly destroyed in paper shredders.

Personal Data on Optical / Magnetic Media

Personal data on optical and magnetic media whose required retention period has expired are physically destroyed by methods such as melting, incineration or pulverization. In addition, magnetic media are passed through a special device and exposed to a high-strength magnetic field, thereby rendering the data on them unreadable.

Anonymization of personal data means rendering personal data incapable of being associated in any way with an identified or identifiable natural person, even when matched with other data.

 

For personal data to be deemed anonymized, they must be rendered incapable of being associated with an identified or identifiable natural person, even through the use of techniques appropriate to the recording medium and the relevant field of activity, such as reversal by the Data Controller or third parties and/or matching of the data with other data.

These are anonymization methods applied, without any alteration, addition or removal to the stored personal data, by generalizing a personal data group, swapping data with one another, or removing a specific data item or data subgroup from the group.

Variable Removal: Under the method of removing descriptive data, the existing data set is anonymized by removing the “highly descriptive” variables from the data set created after the collected data have been compiled.

Record Removal: Under the record removal method, the stored data are anonymized by removing from the records those data rows that are unique among the data. For example, if a company has only one senior manager, the remaining data may be anonymized by removing that person’s data from the records containing the seniority, salary and gender data of employees at the same level.

Regional Suppression: Under the regional suppression method, where a single data item has an identifying character because it creates a combination that is very rarely seen, suppressing the relevant data item ensures anonymization. For example, in a data set in which age, gender and health status information indicating whether a person is fit to play football is stored together, if only one person on the reserve list of the company’s football team is 65 years old, entering ‘Unknown’ instead of ‘Age: 65’, or leaving this field blank, will ensure anonymization.

Top and Bottom Coding: Under the top and bottom coding method, the values in a data group containing predefined categories are anonymized by combining them according to a specified criterion.

Generalization: Under the data aggregation method, multiple data items are aggregated and the personal data are rendered incapable of being associated with any individual. For example, indicating that there are Z employees aged X without showing the ages of employees individually.

Global Coding: Under the data derivation method, content more general than that of the personal data is created, and the personal data are rendered incapable of being associated with any individual. For example, indicating ages instead of dates of birth, or the region of residence instead of the full address.

Unlike methods that do not introduce value irregularity, anonymization methods that introduce value irregularity create distortion by altering certain values within personal data groups. When using these methods, deviations must be applied carefully in line with the expected/desired benefit. The expected benefit of the data can continue to be obtained by ensuring that aggregate statistics are not distorted.

Noise Addition: Under the noise addition method, particularly in a data set consisting predominantly of numerical data, the data are anonymized by adding certain positive or negative deviations at a specified rate to the existing data. For example, in a data group containing weight values, by applying a (+/) 3 kg deviation, the display of the actual values is prevented and the data are anonymized. The deviation is applied equally to each value.

Micro-Aggregation: Under the micro-aggregation method, all data are first arranged in a meaningful order (such as from largest to smallest) and divided into groups; anonymization is then achieved by calculating the average of each group and substituting the resulting value for the relevant data in that group.

(For example, for salary information, if two groups are created, below and above TRY 10,000, the total salaries of persons earning TRY 10,000 or less are divided by the number of such persons, and the resulting value is entered in the salary set of everyone earning less than TRY 10,000.)

Data Swapping: Under the data swapping method, the values of a variable are exchanged between pairs selected from the stored data. The aim of this method, which is generally used for data that can be categorized, is to transform the database by exchanging the data of data subjects with one another.

In order for a decision to be made to anonymize personal data instead of deleting or destroying them, the following conditions must be met:

·         The anonymity of the anonymized data set cannot be compromised by combining it with another data set;

·         One or more values cannot form a meaningful whole that could render a record unique;

·         The values in the anonymized data set cannot be combined to produce an assumption or conclusion.

 

With respect to personal data processed by the Company within the scope of its activities:

·         Retention periods on a per-data basis for all personal data within the scope of activities carried out in connection with business processes are set out in the Personal Data Processing Inventory;

·         Retention periods by data category are set out in the VERBİS registration; and

·         Retention periods by process are set out in the Personal Data Retention and Destruction Policy.

Such retention periods are updated by the Company’s management where necessary.

 

For personal data whose retention periods have expired, ex officio deletion, destruction or anonymization is carried out, with the approval of the Company’s management, by the responsible personnel assigned to the personal data protection process.

Amendments made to this Policy are shown in the table below.

DATE

PREPARED BY

REVISION NO.

AMENDMENT

30.07.2024

KVKK Team

-

Initial Publication