AN-EL SWITCHES AND ELECTRICAL HOUSEHOLD APPLIANCES IND. INC.
PERSONAL DATA PROTECTION POLICY
Document Information
Document Title: Personal Data Protection Policy
Purpose of the Document: The purpose of the Personal Data Protection Policy is to plan the processes related to the protection of personal data by AN-EL and to determine the principles to be applied in this regard.
Publication Date: 01/01/2020
Version No.: 1
Reference / Rationale: Law No. 6698 on the Protection of Personal Data and other applicable legislation
Approving Authority: AN-EL Board of Directors
1. PURPOSE
Every individual’s right to the protection of their personal data is a sacred right derived from the Constitution.
As AN-EL, we consider fulfilling the requirements of this right to be one of our most valuable responsibilities.
For this reason, we place great importance on the lawful processing and protection of your personal data.
The Personal Data Protection Policy has been prepared as a result of the importance we place on the protection of personal data,
with the aim of defining the principles we adhere to and the procedures we implement when processing and protecting personal data.
2. SCOPE
This Policy applies to all personal data managed by AN-EL, whether processed fully or partially by automated means or obtained, recorded,
data recording system, such as the collection, recording,
storage, retention, modification, reorganization, disclosure, transfer,
acquisition, making available, classification, or restriction of use of such data
.
This Policy applies to all personal data processed regarding AN-EL’s partners, authorized representatives, customers, employees, supplier representatives, and
employees, as well as third parties.
AN-EL may amend this Policy to ensure compliance with legislation and the decisions of the Personal Data Protection Authority, as well as to provide better protection of personal data.
3. DEFINITIONS
Abbreviation Definition
Recipient Group
The category of natural or legal persons to whom personal data is transferred by the data controller.
Explicit Consent Consent that is specific to a particular matter, based on information provided, and expressed of one’s own free will.
AN-EL AN-EL Key and Electrical Household Appliances Ind. Inc.
Anonymization
The process of rendering personal data incapable of being associated with any identified or identifiable natural person, even when combined with other data.
Data Subject A natural person whose personal data is processed.
Relevant User
A person or unit within the data controller’s organization—excluding those responsible for the technical storage, protection, and backup of data—or a person or unit acting on behalf of the data controller in accordance with the authority and instructions received from the data controller,
in accordance with the authority and instructions received from the data controller.
Destruction The erasure, destruction, or anonymization of personal data.
Law/KVKK Law No. 6698 on the Protection of Personal Data.
Data Storage Medium
Any medium in which personal data is stored, whether processed fully or partially by automated means or, provided it is part of any data recording system,
by non-automated means.
Personal Data Identity: Any information relating to an identified or identifiable natural person.
Data Inventory
The personal data processing activities carried out by data controllers in connection with their business processes; these activities are documented by linking the purposes of processing, the legal
basis, data category, recipient group to whom the data is transferred, and the group of data subjects;
and detailing the maximum retention period necessary for the purposes for which the personal data is processed,
and the measures taken regarding data security; this inventory provides a detailed account of these aspects.
Processing of Personal Data
The processing of personal data—whether fully or partially automated or obtained through non-automated means
recording system, whether fully or partially automated or through non-automated means;
collection, recording, storage, retention, modification,
reorganization, disclosure, transfer, acquisition, or any other operation
, classified, or restricted from use—such as the prevention of use—are considered to be part of the processing of personal data.
Commission
The Personal Data Protection Commission established by AN-EL to manage the Policy and other related procedures and to ensure the enforcement of the Policy.
Board: Personal Data Protection Board.
Agency: Personal Data Protection Agency.
Sensitive Personal Data:
Data regarding individuals’ race, ethnic origin, political opinions, philosophical beliefs, religion, denomination, or
other beliefs, dress and attire, membership in associations, foundations, or unions, health,
sexual life, criminal convictions, and security measures, as well as
biometric and genetic data.
Periodic Destruction
The process of deleting, destroying, or anonymizing personal data, as specified in the personal data retention and destruction policy, which is carried out automatically at regular intervals when all conditions for the processing of personal data set forth in the Law have ceased to apply.
Policy: Personal Data Protection Policy
Data Processor: A natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the data controller.
Data Controller:
The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording
system.
4. GENERAL PRINCIPLES
AN-EL verifies, during the preparation phase of every new workflow requiring the processing of personal data, that the data to be processed complies with the following
principles. Workflows found to be non-compliant are not implemented.
When processing personal data, AN-EL:
(I) Complies with the law and the principles of good faith.
(II) Ensures that personal data is accurate and, where necessary, up-to-date.
(III) Ensures that the purpose of processing is specific, clear, and legitimate.
(IV) Verifies that the data being processed is relevant to the purpose of processing, is limited to what is necessary for that purpose, and is proportionate.
(V) Retains data only for as long as required by applicable laws or as necessary for the purpose of processing, and
destroys it when the purpose of processing no longer exists.
5. DUTIES AND RESPONSIBILITIES
To manage this Policy regarding the processing of personal data within AN-EL and related procedures, and
ensure the Policy’s implementation.
The Commission consists of the General Manager, the Human Resources Manager, the Head of Administrative and Financial Affairs, and the Head of Quality Assurance. In addition, AN-EL receives consulting support from a Data Protection Authority (KVKK) advisor as needed to ensure compliance with the Personal Data Protection Law No. 6698. If deemed necessary, the Commission may invite the Data Protection Act (KVKK) consultant to its meetings.
The Commission’s duties and responsibilities are outlined below.
(I) It meets regularly every six months. Extraordinary meetings may be convened if circumstances require it (for example, in the event of a potential data breach).
(II) It discusses matters in the Policy that need to be amended or improved.
(III) It identifies measures that can be implemented to ensure the lawful processing and protection of personal data.
(IV) The Committee identifies steps that can be taken to raise awareness of the Personal Data Protection Law (KVKK) within the company and among business partners.
(V) It identifies risks that may arise regarding the processing and protection of personal data and takes the necessary administrative and
technical measures.
(VI) Facilitates communication with the Authority and manages relations with it.
(VII) Evaluates requests received from Data Subjects.
(VIII) Monitors periodic data destruction processes.
(IX) Updates the Data Inventory.
(X) Assigns responsibilities regarding the matters listed above.
6. Measures Taken for Data Security
AN-EL takes all necessary technical and administrative measures to (i) prevent the unlawful processing of personal data, (ii) prevent unlawful access to personal data, and (iii) ensure an appropriate level of security to safeguard personal data.
.
6.1. Technical Measures
(I) Network security and application security are ensured.
(II) Security measures are implemented throughout the procurement, development, and maintenance of information technology systems.
(III) Access logs are maintained on a regular basis.
(IV) Up-to-date antivirus systems are used.
(V) Firewalls are used.
(VI) Necessary security measures are taken regarding entry to and exit from physical environments containing personal data.
(VII) The security of physical environments containing personal data against external risks (fire, flood, etc.) is ensured.
(VIII) The security of environments containing personal data is ensured.
(IX) Personal data is backed up, and the security of the backed-up personal data is also ensured.
(X) A user account management and authorization control system is in place, and these are monitored.
(XI) Log records are maintained in a manner that prevents user interference.
(XII) Attack detection and prevention systems are used.
(XIII) Encryption is used.
6.2. Administrative Measures
(I) Disciplinary regulations containing data security provisions for employees are in place.
(II) Training and awareness programs on data security are conducted for employees at regular intervals.
(III) Corporate policies regarding access, information security, use, storage, and disposal have been developed and
implemented.
(IV) Data masking measures are applied when necessary.
(V) Confidentiality agreements are in place.
(VI) An authorization matrix has been created for employees.
(VII) The relevant authorizations of employees who change roles or leave the company are revoked.
(VIII) Signed contracts include data security provisions.
(IX) Personal data security policies and procedures have been established.
(X) Personal data security issues are reported promptly.
(XI) Personal data security is monitored.
(XII) Personal data is minimized as much as possible.
(XIII) Periodic and/or random internal audits are conducted and commissioned.
(XIV) Existing risks and threats have been identified.
(XV) Protocols and procedures regarding the security of special-category personal data have been established and are being implemented.
(XVI) If special-category personal data is to be sent via email, it is always sent encrypted and using KEP or a corporate email account.
(XVII) Data processors’ awareness of data security is ensured.
7. Data Subject’s Rights Regarding Personal Data
The data subject may submit a request to AN-EL regarding the following matters:
(I) To learn whether their personal data is being processed,
(II) To request information regarding the processing of their personal data, if it has been processed,
(III) To learn the purpose of the processing of their personal data and whether it is being used in accordance with that purpose,
(IV) To learn the third parties to whom their personal data has been transferred, both domestically and abroad,
(V) To request the correction of their personal data if it has been processed incompletely or incorrectly, and to request that the
that this action be notified to the third parties to whom the personal data has been transferred,
(VI) To request the erasure, destruction, or anonymization of their personal data, even if it has been processed in accordance with the provisions of the Personal Data Protection Law (KVKK) and other relevant laws,
in the event that the grounds justifying its processing no longer exist,
7,
and to request that the third parties to whom the personal data has been transferred be notified of the action taken in this regard,
(VII) To object to a decision made solely through the automated analysis of processed data that is detrimental to the individual,
result arising to their detriment,
(VIII) To request compensation for damages in the event they suffer harm due to the unlawful processing of their personal data.
8. VIOLATION REPORTS
AN-EL employees shall report to the Commission any business practice, action, or incident that they believe violates the provisions of the KVKK and/or this Policy.
Following such a breach report, the Committee shall convene if it deems it necessary and develop an action plan regarding the breach.
If the violation occurred through the unlawful acquisition of personal data by third parties, the Commission shall, in accordance with the Board’s decision No. 2019/10 dated January 24, 2019, notify the relevant party and the Board of this situation within 72 hours.
9. AMENDMENTS
Amendments to the Policy are prepared by the Commission and submitted to the AN-EL Board of Directors for approval.
The updated Policy may be sent to employees via email or published on the website.
10. EFFECTIVE DATE
This version of the Policy was approved by the Board of Directors on 01/01/2020 and entered into effect.
Related Documents:
Data Protection Policy
Privacy Notice Regarding Personal Data Processed in the Contact Form
Website Information Notice
Job Applicant Information Notice
General Corporate Information Notice on the Protection of Personal Data
Camera Surveillance Systems Information Notice