Personal Data Retention and Destruction Policy

Op. Dr. Niyazi Altıntoprak

1. Purpose

Op. Dr. Niyazi Altıntoprak (“Niyazi Altıntoprak”) issues this Personal Data Retention and Destruction Policy (“Retention and Destruction Policy”) in order to regulate the technical and administrative protection of personal data in accordance with Law No. 6698 on the Protection of Personal Data (“Law”) and, where the conditions for processing personal data cease to exist, the implementation of the provisions of the Regulation on the Deletion, Destruction or Anonymization of Personal Data (“Regulation”), published in the Official Gazette dated 28/10/2017.

2. Recording Media in Which Personal Data Are Stored

Personal data belonging to data subjects are securely stored by Niyazi Altıntoprak in the environments listed below in accordance with the relevant legislation, primarily the provisions of the Law:

Electronic media
  • E-mail Inbox
  • Microsoft Office Programs
Physical media
  • Department Cabinets
  • Folders
  • Archive

3. Explanations Regarding the Reasons Requiring Retention

Personal data belonging to data subjects are retained by Niyazi Altıntoprak particularly for the purposes of:

  1. Conducting emergency management processes,
  2. Conducting information security processes,
  3. Conducting employee candidate application processes,
  4. Fulfilling obligations arising from employment contracts and legislation for employees,
  5. Conducting fringe benefit and employee benefit processes,
  6. Conducting training activities,
  7. Managing access authorizations,
  8. Conducting activities in compliance with legislation,
  9. Conducting finance and accounting activities,
  10. Ensuring physical premises security,
  11. Conducting assignment processes,
  12. Monitoring and conducting legal affairs,
  13. Conducting communication activities,
  14. Conducting / auditing business activities,
  15. Conducting occupational health / safety activities,
  16. Conducting activities to ensure business continuity,
  17. Conducting procurement processes for goods / services,
  18. Conducting risk management processes,
  19. Conducting retention and archiving activities,
  20. Conducting contract processes,
  21. Conducting remuneration policy,
  22. Ensuring the security of data controller operations,
  23. Providing information to authorized persons, institutions and organizations,
  24. Fulfilling legal obligations,
  25. Providing healthcare services,
  26. Creating and monitoring appointment records,
  27. Issuing prescriptions,
  28. Conducting patient satisfaction activities,
  29. Providing support and information after healthcare services.

For these purposes, personal data are securely retained in the physical or electronic environments listed above within the limits specified by the Law and other relevant legislation.

Reasons requiring retention
  1. Personal data being directly related to the establishment and performance of contracts,
  2. Personal data being necessary for the establishment, exercise or protection of a right,
  3. The existence of a legitimate interest of Niyazi Altıntoprak, provided that the fundamental rights and freedoms of persons are not harmed,
  4. Personal data being necessary for Niyazi Altıntoprak to fulfil any legal obligation,
  5. The retention of personal data being expressly stipulated by legislation,
  6. The existence of explicit consent of data subjects for retention activities requiring such consent.

Pursuant to the Regulation, personal data belonging to data subjects are deleted, destroyed or anonymized by Niyazi Altıntoprak ex officio or upon request in the following cases:

  1. Amendment or repeal of the relevant legislative provisions forming the basis for processing or retaining personal data,
  2. The disappearance of the purpose requiring the processing or retention of personal data,
  3. The disappearance of the conditions requiring the processing of personal data under Articles 5 and 6 of the Law,
  4. Where processing is based solely on explicit consent, withdrawal of such consent by the relevant person,
  5. Acceptance by the data controller of an application by the relevant person requesting deletion, destruction or anonymization of personal data within the scope of the rights under Article 11(2)(e) and (f) of the Law,
  6. Where the data controller rejects the application, gives an insufficient response or fails to respond within the period stipulated by the Law, a complaint is made to the Board and the request is found appropriate by the Board,
  7. The maximum retention period has expired and there is no condition justifying longer retention of the personal data.

4. Measures Taken for the Protection of Personal Data

In accordance with Article 12 of the Law, Niyazi Altıntoprak takes the necessary technical and administrative measures to ensure an appropriate level of security in order to prevent unlawful processing of personal data, prevent unlawful access to data and ensure their secure retention, and performs or has performed the necessary audits within this scope. If processed personal data are unlawfully obtained by third parties despite all technical and administrative measures having been taken, Niyazi Altıntoprak notifies the relevant units as soon as possible.

4.1. Technical Measures
  • Security measures are taken within the scope of procurement, development and maintenance of information technology systems.
  • Disciplinary regulations containing data security provisions are in place for employees.
  • Periodic training and awareness activities on data security are carried out for employees.
  • An authorization matrix has been created for employees.
  • Access logs are regularly kept.
  • Corporate policies on access, information security, use, retention and destruction have been prepared and put into practice.
  • Confidentiality undertakings are executed.
  • Authorizations of employees who change duties or leave employment are revoked.
  • Up-to-date antivirus systems are used.
  • Firewalls are used.
  • Executed contracts contain data security provisions.
  • Personal data security policies and procedures have been determined.
  • Personal data security issues are reported promptly.
  • Personal data security is monitored.
  • Necessary security measures are taken regarding entry to and exit from physical environments containing personal data.
  • Physical environments containing personal data are secured against external risks such as fire and flood.
  • The security of environments containing personal data is ensured.
  • Personal data are minimized as much as possible.
  • Personal data are backed up and the security of backup data is also ensured.
  • User account management and authorization control systems are implemented and monitored.
  • Existing risks and threats have been identified.
  • Protocols and procedures for the security of special categories of personal data have been determined and implemented.
  • Cybersecurity measures have been taken and their implementation is continuously monitored.
  • Encryption is used.
  • Awareness of data security is ensured among data-processing service providers.
4.2. Administrative Measures
  • Employees are trained on technical measures to prevent unlawful access to personal data.
  • Within Niyazi Altıntoprak, access and authorization processes for personal data are designed and implemented in accordance with legal compliance requirements on a business-unit basis. Whether the data are of a special category and their level of importance are also taken into account when restricting access.
  • Documents regulating the relationship with Niyazi Altıntoprak personnel and containing personal data include provisions requiring compliance with obligations stipulated by the Law for lawful processing, prohibiting disclosure and unlawful use of personal data, and confirming that confidentiality obligations continue even after termination of employment with Niyazi Altıntoprak.
  • Employees are informed that they may not disclose personal data learned in the course of their duties contrary to the Law or use them outside the purpose of processing, and that this obligation continues after leaving their duties; necessary undertakings are obtained accordingly.
  • Contracts concluded with persons to whom personal data are lawfully transferred by Niyazi Altıntoprak include provisions requiring such persons to take the necessary security measures for the protection of personal data and to ensure compliance with these measures within their organizations.
  • If processed personal data are unlawfully obtained by others, the relevant person and the Board are notified as soon as possible.
  • Where necessary, knowledgeable and experienced personnel are employed for personal data processing and personnel are trained on personal data protection legislation and data security.
  • Niyazi Altıntoprak conducts or has conducted the necessary audits to ensure implementation of the Law and remedies confidentiality and security vulnerabilities identified as a result of such audits.

5. Measures Taken for the Destruction of Personal Data

Although personal data may have been processed in accordance with the relevant legal provisions, Niyazi Altıntoprak may delete or destroy such data on its own decision or upon the request of the personal data subject when the reasons requiring processing cease to exist. Following deletion, the relevant persons will no longer be able to access or use the deleted data in any way. An effective data tracking process will be managed by Niyazi Altıntoprak for defining and monitoring personal data destruction processes. The process will consist, respectively, of identifying the data to be deleted, identifying the relevant persons, determining their access methods and then deleting the data.

Depending on the medium in which the data are recorded, Niyazi Altıntoprak may use one or more of the following methods to destroy, delete or anonymize personal data:

5.1. Deletion of Personal Data

Deletion of personal data means rendering personal data inaccessible and unusable in any way for relevant users. Niyazi Altıntoprak may use one or more of the following methods:

  • Personal data on paper will be processed by blacking out, crossing out, painting over, cutting or erasing.
  • User access rights to office files located in the central file system will be revoked.
  • Rows or columns containing personal information in databases will be deleted using the “Delete” command.
  • Where necessary, secure deletion will be performed with assistance from a specialist.
5.2. Destruction of Personal Data

Destruction of personal data means rendering personal data inaccessible, irretrievable and unusable by anyone in any way.

  • Physical Destruction
  • Destruction Using a Paper Shredder
  • De-magnetization: A method of passing magnetic media through special devices where they are exposed to strong magnetic fields so that the data stored on them are corrupted beyond readability.
5.3. Anonymization of Personal Data

Anonymization of personal data means rendering personal data impossible to associate with an identified or identifiable natural person under any circumstances, even by matching them with other data. Niyazi Altıntoprak may use one or more of the following methods:

Masking: A method of anonymizing personal data by removing the basic identifying information of the personal data from the dataset.

Record Removal: A method whereby data rows containing uniqueness among the data are removed from the records, thereby anonymizing the retained data.

Regional Suppression: Where a single data element has identifying characteristics because it creates a rarely visible combination, concealing the relevant data provides anonymization.

Global Coding: Through data derivation, more general content is created from the personal data so that the data can no longer be associated with any individual. For example, ages may be stated instead of dates of birth, or the region of residence may be stated instead of a full address.

Noise Addition: Particularly in datasets dominated by numerical data, certain positive or negative deviations are added to existing values at a specified rate in order to anonymize the data. For example, in a dataset containing weight values, a deviation of (+/-) 3 kg may be applied so that actual values are not displayed and the data are anonymized. The deviation is applied equally to each value.

In accordance with Article 28 of the Law, anonymized personal data may be processed for purposes such as research, planning and statistics. Such processing falls outside the scope of the Law and the explicit consent of the personal data subject will not be required.

Niyazi Altıntoprak may decide ex officio to delete, destroy or anonymize personal data and may freely determine the method to be used according to the selected category. In addition, where the relevant person chooses one of the categories of deletion, destruction or anonymization of his/her personal data during an application under Article 13 of the Regulation, Niyazi Altıntoprak will also be free to determine the methods to be used within the relevant category.

6. Personal Data Retention and Destruction Periods

Niyazi Altıntoprak retains personal data for the purpose for which they are processed for the periods specified in Annex 1 of the Retention and Destruction Policy.

If a period is prescribed by legislation for retention of the relevant personal data, that period is observed. If no period is prescribed by legislation, personal data are retained for the maximum periods set out in the table in Annex 1. These periods have been determined by evaluating Niyazi Altıntoprak’s data categories and groups of data subjects, taking into account the periods necessary to fulfil legal obligations and the maximum limitation period under the Turkish Code of Obligations (10 years).

Where the obligation to delete, destroy or anonymize arises upon expiry of these periods, Niyazi Altıntoprak deletes, destroys or anonymizes the personal data during the first periodic destruction process following such date.

All operations relating to the deletion, destruction and anonymization of personal data are recorded and such records are retained for at least three years, without prejudice to other legal obligations.

7. Periodic Destruction Periods

Niyazi Altıntoprak’s periodic destruction period is 6 months. Personal data whose retention period has expired are destroyed every 6 months, in June and December, in accordance with the destruction periods set out in Annex 1 of this Retention and Destruction Policy and the procedures specified herein. The information will be deleted in such a way that it cannot be restored from documents, files, CDs, diskettes, hard disks or similar media on which the data are recorded.

8. Personnel

Within the scope of the Law, Niyazi Altıntoprak, as data controller, assigns personnel pursuant to Article 11(1) of the Regulation to fulfil obligations relating to implementation of the data retention and destruction process; if no assigned personnel are present during the destruction period, these obligations will be fulfilled by the Examination Physician.

These persons, whose limits of authority have been defined, are responsible for transactions and actions carried out within their own scope of authority under the Turkish Commercial Code, Code of Obligations and Turkish Penal Code. In particular, the Niyazi Altıntoprak Physician is authorized to represent Niyazi Altıntoprak and give statements before law-enforcement authorities, prosecutors’ offices, public institutions and courts.

9. Revision and Repeal

If the Retention and Destruction Policy is amended or repealed, the new regulation will be announced on the Niyazi Altıntoprak website.

10. Entry into Force

This Retention and Destruction Policy enters into force on the date of publication.

Annexes
  • ANNEX 1 – Data Retention and Destruction Periods
  • ANNEX 2 – Personal Data Retention and Destruction Personnel Table
  • ANNEX 3 – Internal Directive of the Personal Data Protection Implementation Unit

ANNEX 1 – Data Retention and Destruction Periods

Data Category Retention Period Destruction Period
Identity 10 Years During the first periodic destruction period following expiry of the retention period
Contact 10 Years During the first periodic destruction period following expiry of the retention period
Personnel 10 Years During the first periodic destruction period following expiry of the retention period
Legal Transaction 10 Years During the first periodic destruction period following expiry of the retention period
Patient Transaction 10 Years During the first periodic destruction period following expiry of the retention period
Transaction Security 10 Years During the first periodic destruction period following expiry of the retention period
Risk Management 10 Years During the first periodic destruction period following expiry of the retention period
Finance 10 Years During the first periodic destruction period following expiry of the retention period
Professional Experience 10 Years During the first periodic destruction period following expiry of the retention period
Visual and Audio Records 10 Years During the first periodic destruction period following expiry of the retention period
Health Information 15 Years During the first periodic destruction period following expiry of the retention period
Criminal Convictions and Security Measures 10 Years During the first periodic destruction period following expiry of the retention period
Genetic Data 10 Years During the first periodic destruction period following expiry of the retention period
Family Information 10 Years During the first periodic destruction period following expiry of the retention period
Employment Data 10 Years During the first periodic destruction period following expiry of the retention period
Website Usage Data 2 Years During the first periodic destruction period following expiry of the retention period
Request / Complaint Management Information 2 Years During the first periodic destruction period following expiry of the retention period
Healthcare Financing and Planning Information 10 Years During the first periodic destruction period following expiry of the retention period
Audit and Inspection Information 10 Years During the first periodic destruction period following expiry of the retention period
Supplier Transaction 10 Years During the first periodic destruction period following expiry of the retention period
Forensic Incident Information 10 Years During the first periodic destruction period following expiry of the retention period
ANNEX 3 – Internal Directive of the Personal Data Protection Implementation Unit