• Home
  • General Data Protection Regulation

General Data Protection Regulation

KARMOD PREFABRİK YAPI TEKNO. İNŞ. SAN. TİC. LTD. ŞTİ.
CORPORATE PERSONAL DATA PROTECTION POLICY

Document Information:

 

Document Name:

Personal Data Protection Policy

   

Document Relevancy:

The purpose of the Personal Data Protection Policy is to plan the processes for the protection of personal data by KARMOD and to determine the principles to be applied to this issue.

   

Issuance date:

March 1, 2020  

   

Version No:

1

   

Reference / Justification:

Personal Data Protectıon Law (the “PDPL”) No. 6698 and other legislation

   

Approval Authority:

KARMOD Management

   
  1. PURPOSE

To request the protection of personal data of his/her own by each individual is a sacred right arising from the Constitution. As KARMOD, we consider that fulfilling the requirements of this right is one of our most valuable tasks. We therefore care that your personal data is lawfully processed and protected.

The Corporate Personal Data Protection Policy is designed to determine the principles and procedures that we follow while processing and protecting personal data as a result of the emphasis we place on the protection of personal data.

  1. SCOPE

The policy covers all kinds of processes carried out on data, such as obtaining, recording, storing, maintaining, changing, rearranging, disclosing, transferring, taking over, making available, classifying or preventing its use, etc. of all personal data managed by KARMOD, wholly or partially by automated means or by non-automated means which provided that form part of a data filing system.

The policy relates to all personal data of KARMOD's partners, officials, customers, employees, supplier officials and employees, and third parties that are processed.

KARMOD may modify the policy for the purposes of compliance with legislation and the resolutions of the Personal Data Protection Authority and for better protection of personal data.

  1. DEFINITIONS

Abbreviation

Definition

   

Group of Recipients

The category of real or legal persons to whom the personal data is transferred by data controller.

   

Explicit Consent

The consent which is context-specific, informed, and freely given.

   

Anonymization

Rendering personal data impossible to link with an identified or identifiable natural person, even through matching them with other data.

   

Data Subject

The natural person, whose personal data are processed.

   

Relevant User

Verilerin teknik olarak depolanması, korunması ve yedeklenmesinden sorumlu olan kişi Except for the person or unit, technically responsible for storing, protecting and backing up the data, the person who processes the personal data within the organization of the data controller or in accordance with the authority and instruction received from the data controller.

   

İmha

Erasure, destruction or anonymization of personal data

   

Law/PDPL

Personal Data Protectıon Law (the “PDPL”) No. 6698

   

Filing Medium

Any medium containing personal data processed, wholly or partially, by automated means or by non-automated means which provided that form part of a data filing system.

   

Personal Data

Erasure, destruction or anonymization of personal data  .

   

Data Inventory

The inventory in which the data controllers explain and detail the personal data processing activities that they carry out in accordance with their business processes; the personal data processing purposes and legal reasons, the data category, and maximum storage period created by linking with the group of recipients to whom data transferred and the data subject group that is needed for the purposes for which the personal data is processed; the personal data intended to be transfer to foreign countries and the measures taken for the data security.

   

Personal Data Processing

Kişisel verilerin tamamenAll kinds of processes carried out on data, such as obtaining, recording, storing, maintaining, changing, rearranging, disclosing, transferring, taking over, making available, classifying or preventing its use, etc., wholly or partially, by automated means or by non-automated means which provided that form part of a data filing system.

   

Commission

The Personal Data Protection Commission established by KARMOD to manage the Policy and other related procedures and to ensure the enforcement of the Policy.

   

Board

Personal Data Protection Board.

   

Authority

Personal Data Protection Authority

   

Special Categories of Personal Data

The data of persons related to their race, ethnicity, political thought, philosophical belief, religion, sect or other beliefs, dress and clothing, association, foundation or union membership, health, sex life, criminal convictions and security measures, as well as biometric and genetic data.

   

Periodic Destruction

rasure, destruction or anonymization process to be performed ex officio with periodic intervals specified in the policy of storage and destruction of personal data in case of elimination of all the conditions for the processing of personal data contained in the Law.

   

Policy

Personal Data Protection Policy

   

Data Processor

The natural or legal person who processes personal data on behalf of the data controller upon the authorization given by the data controller.

   

Data Controller

The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data filing system.

   
  1. GENERAL PRINCIPLES

KARMOD checks the compliance of the data to be processed in the preparation phase of each work flow requiring a new personal data processing to the following principles. Inappropriate work flows are not realized.

While processing data,  KARMOD shall;

(I) Observe the lawfulness and fairness rules.

(II) Ensure that the personal data are accurate and, where necessary, up to date.

(III) Pay attention they are processed for specified, explicit and legitimate purposes.

(IV) Control that processed data are relevant, limited and proportionate to the purposes for which they are processed.

(V) Store the data for the period laid down by relevant legislation or the period required for the purpose for which the personal data are processed and destruct when the purpose of processing is no longer exist.

  1. DUTIES AND RESPONSIBILITIES

The Personal Data Protection Commission has been established within KARMOD in order to manage the Policy and other related procedures and to ensure the enforcement of the Policy. The Commission consists of the General Manager, Human Resources Officer, Chief Financial Officer and Information Technology Department Manager. KARMOD, when necessary, also receives the PDPL consultancy in order to comply with the Personal Data Protection Law No. 6698. The commission, if deems necessary, may call the PDPL consultant to its meetings.

  1. Measures Taken For Data Security

KARMOD takes all kinds of technical and administrative measures necessary to ensure the appropriate level of security in order to (I) prevent unlawful processing of personal data, (II) prevent unlawful access to personal data, (III) ensure the protection of personal data.

6.Technical Measures

6.Administrative Measures 

  1. Rights of Data Subject Regarding Personal Data

Data Subject can apply to KARMOD and make a claim in the following matters:

  1. REPORTING BREACHES

KARMOD employees report to the commission any work, action or fact they consider to be in breach of the provisions of the PDPL and/or the Policy. If the commission deems it necessary following this reporting of breach, it convenes and creates an action plan against the breach.

If the breach occurred through the obtainment of personal data by third persons by unlawful means, the Commission shall communicate this situation to the data subject and the Board within 72 hours within the scope of the decision of the Board dated 24.01.2019 and numbered 2019/10.

  1. AMENDMENTS

The amendments in the Policy are prepared by the Commission and submitted for the approval of the Board of Directors of KARMOD. The updated policy man be sent to the employees by e-mail or posted on the website.

  1. EFFECTIVE DATE

This version of the policy was approved by the Board of Directors and entered into force on 01.03.2020.

Phone
+90 216 321 3221 Mon - Fri 08:00 - 18:00
Sat 08:00 - 16:00
E-Mail
info@karmodcabin.com 7 / 24
For Your Project Works
project@karmodcabin.com Mon - Fri 08:00 - 18:00
Sat 08:00 - 16:00
Hello,
How can we help you?
Start Chat