
EN KALİTE DANIŞMANLIK OLARAK KVKK DANIŞMANLIĞIMIZDA
- Teklif Talep Sözleşme
- Business Site Control
- Law
- Consent, Personal Data, Data Controller
- Processing of Personal Data
- Deletion and Anonymization of Personal Data
- Rights of Relevant Persons
- Obligations of the Data Controller
- Transfer of Personal Data
- Information on Crimes and Misdemeanors
- Information Security
- Data Classification and Labeling
- Identity and Access Management
- Protecting Data Confidentiality and Integrity
- Protecting and Preventing Data Leaks
- Supplier Security
- Security Monitoring and Evaluation
- Security Standards
- Emergency Action Plans
- Cyber Reviews
- Risk Analysis
- Operation
- Designing the Institutional Operation Model and Business Processes in Compliance with the Law
- Establishing Relevant Policies and Procedures
- Customer Corporate Communication Processes
- Human Resources Processes
- Management of Service Providers
- Customer Experience Regarding Personal Data Management
- Audit Studies for the Protection of Personal Data
- Audit Studies on Information System Security
- Organization
- Appointment of Personal Data Controller
- New Roles and Responsibilities that May Come with Data Processing, Storage and Destruction Processes
- Roles of Suppliers and Service Providers
- Continuing Education and Awareness
- Establishment of the Institutional Kvkk Board
- Data Management (IT UNIT)
- Access Management
- Data Architecture
- Evaluation of Data Processing Procedures on the Basis of Information Technologies
- Data Storage Backup and Recovery Procedures
- Data Discovery
- Reporting
With the development of technology, both government institutions and private organizations can access various information about thousands of people every day. The information obtained can be easily processed and transferred with the influence of developments in information technologies. As a result, the need to protect personal data has arisen. The first data protection law was published by Germany in 1970. Data protection laws were published in Switzerland in 1973 and in France in 1978. Since those years, many draft laws have been created. In our country, the "Draft Law on the Protection of Personal Data" was submitted to the Presidency of the Turkish Grand National Assembly on 26 December 2014. The bill became law on 24 March 2016 and the Personal Data Protection Law No. 6698 came into force by being published in the Official Gazette No. 29677 dated 7 April 2016.
Nowadays, when technology has completely penetrated into daily life, it is of great importance to protect the privacy of the individual's personal data such as identity, communication, health and financial information, private life, religious beliefs and political views. Personal data is frequently used by both the private sector and the public sector in automatic ways through information systems. Although the use of this information provides some conveniences and advantages for individuals and those who provide goods and services, it also brings with it the risk of information being exploited. Therefore, it is necessary to establish a legitimate and reasonable balance between these two interests.
The purpose of the law is to protect the fundamental rights and freedoms of individuals, especially the privacy of private life, in the processing of personal data and to regulate the obligations of real and legal persons processing personal data and the procedures and principles to be followed.
Scope of the Law The provisions of this Law apply to natural persons whose personal data are processed, and to real and legal persons who process this data by fully or partially automatic or non-automatic means, provided that it is part of any data recording system.
In the implementation of this Law;
a) Explicit consent: Consent regarding a specific issue, based on being informed and expressed with free will,
b) Anonymization: Making personal data impossible to associate with an identified or identifiable natural person in any way, even by matching it with other data,
c) President: President of the Personal Data Protection Authority,
ç) Relevant person: The real person whose personal data is processed,
d) Personal data: Any information regarding an identified or identifiable natural person,
e) Processing of personal data: All kinds of operations performed on data such as obtaining, recording, storing, preserving, changing, rearranging, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data by fully or partially automatic or non-automatic means provided that it is part of any data recording system,
f) Board: Personal Data Protection Board,
g) Institution: Personal Data Protection Authority,
g) Data processor: Real or legal person who processes personal data on behalf of the data controller, based on the authority given by the data controller,
h) Data recording system: The recording system in which personal data is structured and processed according to certain criteria,
i) Data controller: Refers to the natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.
WHAT IS PERSONAL DATA?
Personal data is any information regarding a specific or identifiable person. In this case, it can be said that basically two criteria are used to distinguish personal data from non-personal data. Accordingly, in order to be considered personal data, the data must relate to a person and this person must be specific or identifiable.
Personal data is any information that shows the personal, professional and family characteristics of an individual, and that is capable of distinguishing that individual from other individuals and revealing his qualifications. Personal data in law; It is defined as "all kinds of information regarding an identified or identifiable natural person". This information includes issues such as a particular person's identity, ethnic origin, physical characteristics, health, education, employment status, sexual life, family life, communications with others, residence address, credit card, personal thoughts and beliefs, association and union memberships, and shopping habits.
Collection or recording: Processing of personal data begins as soon as it is first obtained.
• Organizing/storing: Storing, hosting or storing personal data in digital or physical media is considered within the scope of processing.
• Use/change: Any use of personal data, including viewing, is considered processing.
• Transfer: Transmission of personal data through various methods.
• Dissemination/making available: Just like distributing or sharing physically, making data available to third parties in a digital environment is also a type of processing.
•Blocking/deleting/destroying/anonymizing: These are also considered a processing activity. Personal data may be processed by automatic or non-automatic means:
WHAT BUSINESSES SHOULD DO WITHIN THE SCOPE OF KVKK
- Processing of personal data into the system
- Data Analysis
- Personal Data Processing Inventory
- Processing of personal data into the system by obtaining the consent of the relevant employee or person
- Illumination has taken place
- Personal Data Storage and Destruction Policy
- Requirements regarding the processing of special personal data
- Processing is limited to purpose and duration
- Requirements regarding data liability
- Periodic Destruction Period
- Determining Periodic Destruction Period
DATA CONTROLLER
Data controller refers to the natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system. Legal entities are themselves "data controllers" within the scope of the activities they carry out in processing personal data, and the legal liability specified in the relevant regulations will arise in the person of the legal entity. In this regard, there is no difference between public law legal entities and private law legal entities. In this context, general provisions in private law and public law regarding the liability of legal entities are applied in terms of both criminal and civil liability.
Data processor is defined as real or legal persons who process personal data on behalf of the data controller, based on the authority given by the data controller. These persons are separate natural or legal persons who process personal data within the framework of the instructions given to them, and are authorized by the data controller by entering into a personal data processing agreement. Any natural or legal person can be both a data controller and a data processor at the same time. For example, while an accounting company is considered a data controller for the data it holds about its own personnel, it will be considered a data processor for the data it holds for its customer companies.
To determine the data controller, it should be taken into account who decides on the following issues:
• Collection of personal data and purpose of collection,
• Types of personal data to be collected,
• For what purposes the collected data will be used,
• Which individuals' personal data will be collected,
• Whether the collected data will be shared, and if so, with whom it will be shared,
• How long the data will be stored,
• Whether the right of access and other rights of data owners will be implemented.
By making a personal data processing agreement, the data controller may give the data processor the authority to decide on the following issues, for example:
• Which information technology systems or other methods will be used to collect personal data,
• The method by which personal data will be stored,
• Details of the security measures to be taken to protect personal data, • The method by which personal data will be transferred,
• The method to be used to ensure the correct application of the periods for storing personal data,
• Method of deleting, destroying and anonymizing personal data.