Personal Data Protection and Processing Policy

Document Name Op. Dr. Niyazi Altıntoprak Personal Data Protection and Processing Policy
Target Audience All natural persons other than the employees of Op. Dr. Niyazi Altıntoprak whose personal data are processed by Op. Dr. Niyazi Altıntoprak
Prepared By Op. Dr. Niyazi Altıntoprak
Version 1.0
Approved By Approved by Op. Dr. Niyazi Altıntoprak.

© Op. Dr. Niyazi Altıntoprak, 2021

This document may not be reproduced or distributed without the written permission of Op. Dr. Niyazi Altıntoprak.

Contents

  • 1. Introduction
  • 1.1. Purpose
  • 1.2. Scope
  • 1.3. Legal Basis
  • 1.4. Definitions
  • 2. Matters Concerning the Protection of Personal Data
  • 2.1. Ensuring the Security of Personal Data
  • 2.2. Protection of Special Categories of Personal Data
  • 2.3. Raising Awareness on the Protection and Processing of Personal Data
  • 3. Processing of Personal Data
  • 3.1. Processing Personal Data in Compliance with Legislation
  • 3.2. Conditions for Processing Personal Data
  • 3.3. Processing of Special Categories of Personal Data
  • 3.4. Informing the Data Subject
  • 3.5. Transfer of Personal Data
  • 4. Categorization of Processed Personal Data and Purposes of Processing
  • 5. Measures Taken for the Protection of Personal Data
  • 6. Retention and Destruction of Personal Data
  • 7. Rights of Personal Data Subjects and Exercise of These Rights
  • 7.1. Rights of the Personal Data Subject
  • 7.2. Exercise of Rights by the Personal Data Subject
  • 7.3. Responding to Applications
  • 7.4. Rejection of the Data Subject's Application
  • 8. Implementation
  • 9. Entry into Force and Publication
  • ANNEX 1 – Personal Data Subjects
  • ANNEX 2 – Personal Data Categories
  • ANNEX 3 – Purposes of Personal Data Processing
  • ANNEX 4 – Third Parties to Whom Personal Data Are Transferred and Purposes of Transfer

1. Introduction

Op. Dr. Niyazi Altıntoprak (“Niyazi Altıntoprak”) processes and protects personal data with due care within the scope of Law No. 6698 on the Protection of Personal Data (“Law”) and the Regulation on Personal Health Data (“Regulation”). Through this Personal Data Protection and Processing Policy (“Policy”), the processes and practices of Niyazi Altıntoprak are aligned with the Law in order to ensure that healthcare services are provided more effectively and efficiently. As a data controller, particular importance is also attached to the protection of privacy, fundamental rights and freedoms.

1.1. Purpose

The purpose of the Policy is to regulate the procedures and principles to be followed by Niyazi Altıntoprak regarding the requirements stipulated by the Law and to ensure the necessary transparency by informing personal data subjects. The Policy determines the purposes for which personal data are processed and the units that will carry out such activities, establishes the administrative and technical measures necessary for processing and protecting personal data, creates internal procedures, and establishes appropriate and effective control mechanisms by taking all necessary measures to ensure the compliance of shareholders, authorized persons, employees and business partners with the processes under the Law.

1.2. Scope

All personal data belonging to patients, employees, employee candidates, supplier representatives, hospital representatives, website visitors and other persons, processed automatically or by non-automatic means provided that they form part of a data filing system (Protocol Register, Forensic Report Register and Inspection Register), are within the scope of this Policy. The data categories and personal data relating to personal data subjects (Annex 1 and Annex 2) are processed in connection with the purposes of personal data processing (Annex 3). Details regarding processing purposes by data category and data subject groups are notified under the Niyazi Altıntoprak entry at https://verbis.kvkk.gov.tr/. Personal data are processed and protected in accordance with the standards determined by the Law and with a high level of responsibility and awareness under this Policy.

1.3. Legal Basis

This Policy is based on Law No. 3359 on Basic Health Services; Decree-Law No. 663 on the Organization and Duties of the Ministry of Health and Affiliated Institutions; the Regulation on Private Healthcare Institutions Providing Outpatient Diagnosis and Treatment; the Patient Rights Regulation; the Health Implementation Communiqué; Law No. 6698 on the Protection of Personal Data; the Regulation on the Processing of Personal Health Data and Ensuring Privacy; Law No. 1774 on Identity Notification; Labor Law No. 4857; Occupational Health and Safety Law No. 6331; Social Insurance and General Health Insurance Law No. 5510; Unemployment Insurance Law No. 4447; Turkish Commercial Code No. 6102; Turkish Code of Obligations No. 6098; Tax Procedure Law No. 213; and other applicable legislation. In the event of any inconsistency between the applicable legislation and this Policy, the applicable legislation shall prevail. Requirements stipulated by the relevant legislation are implemented within the practices of Niyazi Altıntoprak through this Policy.

1.4. Definitions

For the purposes of this Policy;

EXPLICIT CONSENT Consent relating to a specific subject, based on information and expressed with free will,
OPEN HEALTH DATA Health data that have been made open data,
OPEN DATA Anonymized data made available to everyone over the internet free of charge or at a cost not exceeding the cost of preparation, not subject to any intellectual property right, freely usable for any purpose, machine-readable and therefore interoperable with other data and systems,
ANONYMIZATION Rendering personal data impossible to associate with an identified or identifiable natural person under any circumstances, even by matching them with other data,
e-NABIZ The system established by the Ministry in accordance with e-Government applications, enabling data subjects, physicians or third parties authorized by them to access health data,
AUTHORIZED USER A person who processes personal data within the data controller’s organization, or on the authority and instructions of the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data,
DESTRUCTION The deletion, destruction or anonymization of personal data,
RECORDING MEDIUM Any environment in which personal data processed wholly or partly by automatic means or by non-automatic means as part of a data filing system are stored,
DE-IDENTIFICATION Processing personal data in a manner that cannot be associated with the relevant person without combining them with other data stored in a different environment, provided that technical and administrative measures are taken to prevent association with an identified or identifiable natural person,
PERSONAL HEALTH DATA All information concerning the physical and mental health of an identified or identifiable natural person and information relating to the healthcare services provided to that person,
PERSONAL DATA Any information relating to an identified or identifiable natural person,
ANONYMIZATION OF PERSONAL DATA Rendering personal data impossible to associate with an identified or identifiable natural person under any circumstances, even by matching them with other data,
PROCESSING OF PERSONAL DATA Any operation performed on personal data, such as obtaining, recording, storing, preserving, altering, rearranging, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, wholly or partly by automatic means or by non-automatic means as part of a data filing system,
DELETION OF PERSONAL DATA Rendering personal data inaccessible and unusable in any way for Authorized Users,
DESTRUCTION OF PERSONAL DATA The process of rendering personal data inaccessible, irretrievable and unusable by anyone in any way,
BOARD The Personal Data Protection Board,
SPECIAL CATEGORIES OF PERSONAL DATA Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data,
PERIODIC DESTRUCTION The deletion, destruction or anonymization process carried out ex officio at recurring intervals specified in the personal data retention and destruction policy when all conditions for processing personal data under the Law cease to exist,
DATA SUBJECT / RELEVANT PERSON The natural person whose personal data are processed,
DATA CONTROLLER The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system,

shall mean.

2. Matters Concerning the Protection of Personal Data

2.1. Ensuring the Security of Personal Data

Niyazi Altıntoprak takes the necessary measures stipulated in Article 12 of the Law, depending on the nature of the data, in order to prevent unlawful disclosure, access, transfer or other security risks concerning personal data. In line with the guidelines published by the Personal Data Protection implementation unit, Niyazi Altıntoprak takes measures and conducts audits to ensure the necessary level of personal data security.

2.2. Protection of Special Categories of Personal Data

The measures taken to protect special categories of personal data, including data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions, security measures, biometric data and genetic data, are carefully implemented and the necessary audits are performed.

Detailed information on the processing of special categories of personal data is provided in Section 3.3 of this Policy.

2.3. Raising Awareness on the Protection and Processing of Personal Data

Niyazi Altıntoprak provides the necessary training to relevant persons in order to raise awareness regarding lawful processing of personal data, access, data retention and the exercise of rights. In order to increase employees’ awareness of personal data protection, Niyazi Altıntoprak establishes the necessary business processes and may receive support from consultants where needed. Deficiencies encountered in practice and the results of trainings are evaluated by the management of Niyazi Altıntoprak. New trainings may be organized where necessary depending on such evaluations and changes in the relevant legislation.

3. Processing of Personal Data

3.1. Processing Personal Data in Compliance with Legislation

Niyazi Altıntoprak processes personal data in compliance with legislation in accordance with the principles listed below.

i. Processing in Accordance with Law and Good Faith

Personal data are processed to the extent required by business activities, limited to such activities, without harming the fundamental rights and freedoms of individuals, and in accordance with the general principles of trust and good faith.

ii. Ensuring that Personal Data Are Accurate and Up to Date

The necessary measures are taken and systems are operated to keep processed personal data accurate and up to date.

iii. Processing for Specified, Explicit and Legitimate Purposes

Niyazi Altıntoprak processes personal data in the course of its activities in connection with specified and disclosed legitimate purposes.

iv. Being Relevant, Limited and Proportionate to the Purpose of Processing

Personal data are collected to the extent and in the quality required by Niyazi Altıntoprak’s activities and are processed in a limited manner in connection with the specified purposes.

v. Retention for the Period Required

Personal data are retained for the minimum period stipulated by the relevant legislation and necessary for the purpose of processing. If a retention period is prescribed by the relevant legislation, that period is observed; otherwise, personal data are retained for the period necessary for the purpose for which they are processed. At the end of the retention periods, personal data are destroyed by appropriate methods (deletion, destruction or anonymization) in accordance with periodic destruction periods or an application by the data subject.

3.2. Conditions for Processing Personal Data

Except where the personal data subject has given explicit consent, personal data processing may be based on one or more of the conditions specified below. The processing of special categories of personal data is based on the conditions set out in Section 3.3 of this Policy.

i. Existence of the Data Subject’s Explicit Consent

Personal data are processed with the explicit consent of the data subject. Explicit consent is obtained after informing the person about a specific matter and is based on free will. Where any of the conditions listed below applies, personal data may be processed without obtaining the data subject’s explicit consent.

a. Express Provision by Law

Where laws expressly provide for the processing of personal data, personal data may be processed without obtaining the consent of the data subject.

b. Inability to Obtain Explicit Consent Due to Actual Impossibility

Personal data may be processed where this is necessary to protect the life or physical integrity of the person or another person, where the person is unable to express consent due to actual impossibility or where consent cannot be given legal validity.

c. Direct Relevance to the Establishment or Performance of a Contract

Personal data may be processed where processing is directly related and necessary for the establishment or performance of a contract to which the data subject is a party.

d. Fulfilment of Niyazi Altıntoprak’s Legal Obligations

Personal data may be processed where processing is necessary for Niyazi Altıntoprak to fulfil its legal obligations.

e. Making Personal Data Public by the Data Subject

Personal data made public by data subjects may be processed to the extent limited to the purpose for which they were made public.

f. Processing Necessary for the Establishment or Protection of a Right

Personal data may be processed where processing is necessary for the establishment, exercise or protection of a right.

g. Processing Necessary for Niyazi Altıntoprak’s Legitimate Interests

Personal data may be processed where processing is necessary for the legitimate interests of Niyazi Altıntoprak, provided that the fundamental rights and freedoms of the data subject are not harmed.

3.3. Processing of Special Categories of Personal Data
i. Processing of Special Categories of Personal Data

When processing special categories of personal data, all necessary administrative and technical measures are taken in accordance with the principles set out in the Law and this Policy and by the methods to be determined by the Board, and such data are processed under the following conditions:

  1. Special categories of personal data other than health and sexual life data may be processed without the data subject’s explicit consent where their processing is expressly provided for by law. In cases not expressly provided for by law, the data subject’s explicit consent is obtained.
  2. Special categories of personal data relating to health and sexual life may be processed without the data subject’s explicit consent by persons under an obligation of secrecy or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and managing healthcare services and their financing. Otherwise, the data subject’s explicit consent is obtained.
ii. Principles Governing the Processing of Personal Health Data
  1. No one may be forced to provide or show a record of past health data except where necessary for the provision of healthcare services.
  2. Physical, technical and administrative measures are taken to prevent unauthorized persons from being present at counters, desks and similar areas and to prevent persons receiving services in close proximity from hearing, seeing, learning or obtaining each other’s personal data.
  3. Necessary partial de-identification or masking measures are applied to printed materials containing personal health data, such as laboratory and examination results, and other measures are taken to make it difficult to identify the person concerned if such materials fall into the hands of unauthorized persons.
iii. Access to Data by Healthcare Personnel
  1. Persons involved in the provision of healthcare services may access the relevant person’s health data only to the extent required by the healthcare service to be provided.
  2. Health data of persons who have an e-Nabız account are accessed within the framework of their privacy preferences. The relevant persons are informed in detail about their privacy preferences and consequences. The Ministry of Health shall not be responsible for disruptions or damages that may arise in the provision of healthcare services due to privacy preferences and the inability to view past health data.
  3. For persons without an e-Nabız account, health data may be accessed only for the exceptional purposes specified in Article 6(3) of the Law and only by:
    • The family physician with whom the person is registered, without any time limitation,
    • The physician with whom the person has an appointment for healthcare services, limited to the day of the appointment and until the procedures directly related to the healthcare service are completed,
    • Physicians working at the healthcare provider where the person has registered to receive healthcare services, limited to twenty-four hours,
    • Physicians working at the healthcare provider where the patient is hospitalized, until discharge.
    Access may be granted accordingly.
  4. Persons who do not want any person to access their past health data are provided with the relevant privacy preference through e-Nabız. Where this preference is used, past health data may be accessed only if the code sent to the telephone number declared by the person is shared with the physician and entered into the system by the physician.
  5. Personal health data of a higher level of confidentiality, the disclosure of which may adversely affect the social life and mental health of individuals, are determined by the Ministry of Health, and proportionate restrictions may be imposed on healthcare personnel’s access to such data.
iv. Access to Children’s Health Data

Parents may access their children’s health records through e-Nabız without any approval. Children capable of discernment may make their parents’ access to their health history subject to permission through e-Nabız.

In the event of divorce, the parent who does not hold custody may access the child’s health data in accordance with personal data protection legislation and within the limits determined by the General Directorate, taking into account the interests of the child and the custodial parent.

v. Access to Health Data by Patients’ Relatives

When personal health data are shared with patients’ relatives, action is taken in accordance with the third paragraph of Article 18 of the Patient Rights Regulation published in the Official Gazette dated 1/8/1998 and numbered 23420, without violating the principles of the Law.

vi. Access to Health Data by Lawyers

Lawyers may not request their client’s health data with a general power of attorney. In order for health data belonging to a client to be transferred to a lawyer, the power of attorney must contain a special provision indicating the data subject’s explicit consent to the processing and transfer of special categories of personal data.

vii. Access to the Health Data of Deceased Persons

The legal heirs of a deceased person are individually entitled to obtain the deceased’s health data upon presentation of the certificate of inheritance.

Health data of a deceased person are retained for at least 20 years.

ix. Correction of Personal Health Data

If, upon the request of the relevant person, the provincial health directorate concludes following an investigation at the healthcare provider that health data were created erroneously and the Health Information Systems General Directorate corrects such data, the same correction is also made in the database of Niyazi Altıntoprak.

The General Directorate determines and updates, as needed, the date as of which health data created by healthcare providers may be corrected by the providers themselves. Health data created after such date are corrected by the relevant healthcare provider, while data created before that date are corrected by the General Directorate upon the request of the relevant provincial health directorate.

x. Processing of Personal Health Data for Scientific Purposes

Scientific studies may be carried out using personal health data anonymized by the data controller within the scope of Article 28(1)(b) of the Law.

Within the scope of Article 28(1)(c) of the Law, personal health data may be processed for scientific purposes under appropriate technical and administrative measures, provided that the privacy or personality rights of the relevant persons are not violated and no criminal offence is committed.

3.4. Informing the Data Subject

Niyazi Altıntoprak informs personal data subjects, in accordance with the relevant legislation, about the purposes for which their personal data are processed, with whom and for what purposes they are shared, by which methods they are collected, the legal grounds, and the rights of data subjects in relation to the processing of their personal data. Accordingly, the protection of personal data is carried out in line with other policy documents and information notices prepared under the principles of this Policy.

3.5. Transfer of Personal Data

Niyazi Altıntoprak may transfer personal data and special categories of personal data to third parties (third-party companies, group companies and third-party natural persons) lawfully, in line with the purposes of personal data processing and by taking the necessary security measures. Transfers are carried out in accordance with the requirements of Article 8 of the Law and Annex 4, “Third Parties to Whom Personal Data Are Transferred and Purposes of Transfer”.

i. Transfer of Personal Data

Although the explicit consent of the personal data subject is required for the transfer of personal data, personal data may be transferred to third parties based on one or more of the following conditions, provided that all necessary security measures, including methods prescribed by the Board, are taken:

  1. Where expressly provided for by law,
  2. Where directly related and necessary for the establishment or performance of a contract,
  3. Where necessary for Niyazi Altıntoprak to fulfil its legal obligations,
  4. Where personal data have been made public by the data subject, limited to the purpose of making them public,
  5. Where necessary for the establishment, exercise or protection of the rights of Niyazi Altıntoprak, the data subject or third parties,
  6. Where necessary for the legitimate interests of Niyazi Altıntoprak, provided that the fundamental rights and freedoms of the data subject are not harmed,
  7. Where necessary to protect the life or physical integrity of the person or another person where the person is unable to express consent due to actual impossibility or where consent cannot be given legal validity.

Personal data may be transferred to persons in foreign countries declared by the Board to have adequate protection (“Foreign Country with Adequate Protection”), provided that at least one of the conditions listed above is met. Where adequate protection is not available, personal data may be transferred, under the conditions prescribed by legislation, to persons in foreign countries where the data controllers in Türkiye and the relevant foreign country undertake in writing to provide adequate protection and the Board grants permission (“Foreign Country Where the Data Controller Undertakes Adequate Protection”).

ii. Transfer of Special Categories of Personal Data

Special categories of personal data may be transferred under the following conditions, in accordance with the principles set out in this Policy and by taking all necessary administrative and technical measures, including methods to be determined by the Board:

  1. Special categories of personal data other than health and sexual life data may be transferred without explicit consent where their processing is expressly provided for by law; otherwise, with the data subject’s explicit consent.
  2. Special categories of personal data relating to health and sexual life may be transferred without explicit consent by persons under an obligation of secrecy or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and managing healthcare services and financing; otherwise, with the data subject’s explicit consent.

Personal data may be transferred to persons in countries with adequate protection where any of the above conditions exists, and where adequate protection is not available, to persons in countries where the data controller undertakes adequate protection, subject to the data transfer conditions regulated by legislation.

4. Categorization of Processed Personal Data and Purposes of Processing

The purpose of Niyazi Altıntoprak in processing personal data is to inform the relevant persons in accordance with Article 10 of the Law and other legislation, to carry out processing in a limited manner based on at least one of the personal data processing conditions specified in Articles 5 and 6 of the Law, and to comply with the general principles set out in the Law, in particular those specified in Article 4.

Examination-related business processes are carried out through administrative functions (Patient Admission, Security, Archive/Records, Personnel, Accounting-Finance, Procurement, Occupational Health and Safety, Information Technology, Patient Rights) and healthcare services (Healthcare Services, Emergency Services, Infection Control Services).

Patient data are recorded for the purposes of conducting information security processes, ensuring legal compliance, carrying out finance and accounting activities, managing loyalty processes relating to companies/products/services, monitoring and conducting legal affairs, carrying out communication activities, conducting and auditing business activities, ensuring business continuity, conducting procurement processes for goods/services, conducting retention and archiving activities, conducting marketing processes for products/services, providing information to authorized persons, institutions and organizations, providing healthcare services, creating and monitoring appointment records, issuing prescriptions, carrying out patient satisfaction activities, providing post-service support and information, and conducting risk management processes. Patient data are obtained via the website, e-mail and telephone.

Information relating to suppliers of goods/services is recorded to verify whether they fulfil their obligations and to ensure that services provided are carried out in accordance with standards. Personal data relating to suppliers are obtained through e-mails sent and received as a result of communications with them, telephone conversations, business cards and information available on websites.

Employees’ personal data are requested and processed in order to complete mandatory documents required in personnel files for Social Security registration and within the scope of the applicable Labor Law and Occupational Health and Safety Law.

Personal data relating to employee candidates are obtained through CVs and application forms submitted during recruitment, CV viewing methods offered by human resources software and candidate pool services such as Kariyer.net and LinkedIn, and responses given with consent to questions asked during oral interviews. Niyazi Altıntoprak requests and processes personal data of applicants in order to communicate with them for oral interviews during recruitment and to determine whether their qualifications and experience are compatible with the open position.

Niyazi Altıntoprak records the data of employees and authorized natural persons of its business partners within the purposes of establishing the relevant business partnership.

Information included in complaint and request forms submitted to Niyazi Altıntoprak is processed for the purpose of ensuring service quality.

Detailed information on processed personal data categories is included in the Policy annex “ANNEX 3 – Personal Data Categories”; detailed information on the purposes of personal data processing is included in “ANNEX 1 – Purposes of Personal Data Processing”. Details of processing purposes by data category and data subject groups are notified under the Niyazi Altıntoprak entry at https://verbis.kvkk.gov.tr/.

5. Measures Taken for the Protection of Personal Data

Niyazi Altıntoprak takes the necessary technical and administrative measures to prevent unlawful processing of personal data, prevent unlawful access to data and ensure the secure retention of data, and carries out or has carried out the necessary training, awareness and audit activities within this scope.

6. Retention and Destruction of Personal Data

Niyazi Altıntoprak carries out the retention and destruction of data in accordance with the procedures and principles regulated under the Policy annex “Personal Data Retention and Destruction Policy”. Personal data are retained for the period necessary for the purpose of processing. If a period is specified in the relevant Policy, such period is observed; if not, the statutory period is observed, and if no statutory period is prescribed, personal data are retained for the period necessary for the purpose of processing. At the end of the designated retention periods, personal data are destroyed by the designated method (deletion, destruction or anonymization) in accordance with periodic destruction periods or an application by the data subject.

7. Rights of Personal Data Subjects and Exercise of These Rights

7.1. Rights of the Personal Data Subject

Personal data subjects have the following rights:

  1. To learn whether personal data are processed,
  2. To request information if personal data have been processed,
  3. To learn the purpose of processing personal data and whether they are used in accordance with that purpose,
  4. To know the third parties to whom personal data are transferred domestically or abroad,
  5. To request correction where personal data have been processed incompletely or inaccurately and to request notification of the transactions carried out in this regard to third parties to whom the personal data have been transferred,
  6. To request deletion or destruction of personal data where the reasons requiring their processing cease to exist, even though they have been processed in accordance with the Law and other relevant laws, and to request notification of the transactions carried out in this regard to third parties to whom the personal data have been transferred,
  7. To object to the occurrence of a result against the person himself/herself by analyzing the processed data exclusively through automated systems,
  8. To claim compensation for damages arising from unlawful processing of personal data.
7.2. Exercise of Rights by the Personal Data Subject

Personal data subjects may apply regarding the rights listed in Section 6.1 by completing the “Data Subject Application Form” (Annex 6), accessible from Niyazi Altıntoprak.

7.3. Responding to Applications

Niyazi Altıntoprak finalizes applications made by personal data subjects in accordance with the Law and other legislation. Requests duly submitted to Niyazi Altıntoprak are finalized free of charge as soon as possible and within no later than 30 (thirty) days. However, where the transaction requires an additional cost, a fee may be charged in accordance with the tariff determined by the Board.

7.4. Rejection of the Data Subject's Application

Niyazi Altıntoprak may reject an application by stating the reason in the following cases:

  1. Processing of personal data for purposes such as research, planning and statistics by anonymizing them through official statistics,
  2. Processing of personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that national defense, national security, public security, public order, economic security, privacy or personality rights are not violated and no criminal offence is committed,
  3. Processing of personal data within the scope of preventive, protective and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public security, public order or economic security,
  4. Processing of personal data by judicial authorities or enforcement authorities in relation to investigation, prosecution, trial or execution proceedings,
  5. Where processing of personal data is necessary for the prevention of crime or a criminal investigation,
  6. Processing of personal data made public by the personal data subject himself/herself,
  7. Where processing is necessary for the performance of supervision or regulatory duties, or disciplinary investigation or prosecution, by authorized public institutions and organizations and professional organizations having public institution status, based on powers granted by law,
  8. Where processing is necessary for the protection of the State’s economic and financial interests concerning budgetary, tax and financial matters,
  9. Where the request of the personal data subject is likely to prevent the rights and freedoms of other persons,
  10. Where requests require disproportionate effort,
  11. Where the requested information is publicly available.

8. Implementation

This Policy has been approved by Op. Dr. Niyazi Altıntoprak. The technical implementation of the Policy is ensured through the “Personal Data Retention and Destruction Policy” (Annex 5). The Board of Directors is responsible for the implementation of the Law and this Policy and for updating them when necessary, while Op. Dr. Niyazi Altıntoprak is responsible for monitoring, coordinating and auditing all transactions and activities within this scope.

In business processes, implementation of the Policy vis-à-vis the relevant parties is carried out through the “Patient Information Notice and Explicit Consent Declaration” (Annex 7), “Supplier Confidentiality and Personal Data Protection Agreement” (Annex 8), “Employee Information Notice and Explicit Consent Declaration” (Annex 9), “Employee Candidate Information Notice and Explicit Consent Declaration” (Annex 10), and “Website Cookie Information Notice” (Annex 11).

9. Entry into Force and Publication

The Policy enters into force on the date of publication. Amendments to the Policy are published on Niyazi Altıntoprak’s website (www.niyazialtıntoprak.com) and made available to personal data subjects and relevant persons. Amendments to the Policy take effect on the date of publication.

Annexes
  • ANNEX 1 – Personal Data Subjects
  • ANNEX 2 – Personal Data Categories
  • ANNEX 3 – Purposes of Personal Data Processing
  • ANNEX 4 – Third Parties to Whom Personal Data Are Transferred and Purposes of Transfer
  • Annex 5 – Personal Data Retention and Destruction Policy
  • Annex 6 – Data Subject Application Form
  • Annex 7 – Patient Information Notice and Explicit Consent Declaration
  • Annex 8 – Supplier Confidentiality Undertaking, Supplier Information Notice and Explicit Consent Declaration
  • Annex 9 – Employee Information Notice and Explicit Consent Declaration
  • Annex 10 – Employee Candidate Information Notice and Explicit Consent Declaration
  • Annex 11 – Website Cookie Information Notice

ANNEX 1 – Personal Data Subjects

Category of Personal Data Subject Description
Employee All healthcare professionals participating in the provision of healthcare services and persons who, although not healthcare professionals, participate responsibly in the provision of healthcare services
Employee Candidate A person, including an intern candidate, who has applied for employment or made his/her CV or similar relevant information available for review by Niyazi Altıntoprak
Patient A person who needs to benefit from healthcare services
Supplier Representative Natural persons, including employees, shareholders and authorized representatives of businesses with which Niyazi Altıntoprak has any business partnership or supplier relationship (including but not limited to business partners and suppliers)

ANNEX 2 – Personal Data Categories

Data Categories Personal Data
Identity
  • Name, Surname
  • Father’s Name
  • Marital Status
  • Identity Card Serial/Sequence Number
  • Turkish ID Number
  • Passport Number
  • Temporary Turkish ID Number
  • Gender Information
  • Turkish Identity Card
Contact
  • Address
  • E-mail Address
  • Contact Address
  • Telephone Number
Personnel
  • Payroll Information
  • Disciplinary Investigation
  • Employment Entry/Exit Records
  • CV Information
Legal Transaction Correspondence with judicial authorities, information in case files, etc.
Patient Transaction
  • Invoice
  • Appointment Information
Transaction Security Information
  • Transaction security data (such as IP address information, website login/logout information, passwords and credentials)
  • IP Address Information
  • Website Login/Logout Information
  • Password and Credential Information
Risk Management Information processed for the management of commercial, technical and administrative risks, etc.
Finance
  • Bank Account Number
  • IBAN Number
Professional Experience
  • Diploma Information
  • Courses Attended
  • In-Service Training Information
  • Certificates
Information
  • Patient History Information
  • Cookie Records
Visual and Audio Records CCTV footage, audio recording
Appearance and Clothing Information relating to appearance and clothing
Foundation Membership Information relating to foundation membership, etc.
Health Information
  • Disability Status Information
  • Blood Group Information
  • Personal Health Information
  • Information on Devices and Prostheses Used
  • Laboratory and Imaging Results
  • Test Results
  • Examination Data
  • Prescription Information
  • Information Relating to Sexual Life
Sexual Life Information relating to sexual life, etc.
Criminal Convictions and Security Measures
  • Information Relating to Criminal Convictions
  • Information Relating to Security Measures
Genetic Data Genetic data, etc.
Family Information
  • Number of Children
  • Family Record Book
  • Spouse Employment Information
  • Children’s Education and Age Information
Employment Data
  • Working Method
  • Occupation
  • Last Employer Information
  • Professional Card Information
  • Reference Information
Website Usage Data
  • Website Login Frequency/Times
  • Last Login Date
  • IP Address
Audit and Inspection Information Personal data processed during internal or external audit activities of the hospital
Supplier Transaction
  • Examination, Laboratory and Radiology Information
  • Medication Information
Forensic Incident Information Health information relating to harm arising from an incident

ANNEX 3 – Purposes of Personal Data Processing

  • Conducting Emergency Management Processes
  • Conducting Information Security Processes
  • Conducting Employee Candidate Application Processes
  • Fulfilling Employment Contract and Legal Obligations for Employees
  • Conducting Fringe Benefits and Employee Benefit Processes
  • Conducting Training Activities
  • Managing Access Authorizations
  • Conducting Activities in Compliance with Legislation
  • Conducting Finance and Accounting Activities
  • Ensuring Physical Premises Security
  • Conducting Assignment Processes
  • Monitoring and Conducting Legal Affairs
  • Conducting Communication Activities
  • Conducting / Auditing Business Activities
  • Conducting Occupational Health / Safety Activities
  • Conducting Activities to Ensure Business Continuity
  • Conducting Procurement Processes for Goods / Services
  • Conducting Risk Management Processes
  • Conducting Retention and Archiving Activities
  • Conducting Contract Processes
  • Conducting Remuneration Policy
  • Ensuring the Security of Data Controller Operations
  • Providing Information to Authorized Persons, Institutions and Organizations
  • Providing Healthcare Services
  • Creating and Monitoring Appointment Records
  • Issuing Prescriptions
  • Conducting Patient Satisfaction Activities
  • Providing Support and Information After Healthcare Services

ANNEX 4 – Third Parties to Whom Personal Data Are Transferred and Purposes of Transfer

In accordance with Articles 8 and 9 of the Law, Niyazi Altıntoprak may transfer the personal data of participants, customers and employees to the categories of persons listed below:

Persons to Whom Data May Be Transferred Definition Purpose and Scope of Data Transfer
Supplier A person or organization providing a product, material or service Limited to the purpose of procuring products, materials and services from external sources in order to carry out commercial activities
Natural Persons or Private-Law Legal Entities Natural or legal persons with whom Niyazi Altıntoprak interacts or conducts transactions due to its activities Limited to the relevant business and transaction
Public Institutions and Organizations Authorized by Law Social Security Institution, Tax Offices and other public institutions and organizations authorized under the relevant legislation to request information and documents from Niyazi Altıntoprak Limited to the purpose requested within the statutory authority of the relevant public institution or organization