Privacy Policy
AN-EL SWITCHES AND ELECTRICAL HOUSEHOLD APPLIANCES IND. INC.
PRIVACY POLICY
Document Information
Document Title: Privacy Policy
Purpose of the Document: The purpose of the Personal Data Protection Policy is to plan the processes related to the protection of personal data by AN-EL and to establish the principles to be applied in this regard.
Publication Date: 01/01/2020
Version No.: 1
Reference / Rationale: Law No. 6698 on the Protection of Personal Data and other relevant legislation
Approving Authority: AN-EL Board of Directors
1. PURPOSE
Every individual’s right to the protection of their personal data is a sacred right derived from the Constitution.
At AN-EL, we consider fulfilling the requirements of this right to be one of our most valuable responsibilities.
For this reason, we place great importance on the lawful processing and protection of your personal data.
The Personal Data Protection Policy has been prepared as a result of the importance we place on the protection of personal data,
with the aim of defining the principles we adhere to and the procedures we implement when processing and protecting personal data.
2. SCOPE
This Policy applies to all personal data managed by AN-EL that is processed either fully or partially automatically or,
data recording system, such as the collection, recording,
storage, retention, modification, reorganization, disclosure, transfer,
acquisition, making available, classification, or restriction of use of such data
.
This Policy applies to all personal data processed regarding AN-EL’s partners, authorized representatives, customers, employees, supplier representatives and
employees, and third parties.
AN-EL may amend this Policy to ensure compliance with legislation and the decisions of the Personal Data Protection Authority, as well as to ensure better protection of personal data.
3. DEFINITIONS
Abbreviation Definition
Recipient Group
The category of natural or legal persons to whom personal data is transferred by the data controller.
Explicit Consent Consent that is specific to a particular matter, based on information provided, and expressed of one’s own free will.
AN-EL AN-EL Key and Electrical Household Appliances Ind. Inc.
Anonymization
The process of rendering personal data incapable of being associated with any identified or identifiable natural person, even when matched with other data.
Data Subject A natural person whose personal data is processed.
Relevant User
A person or unit within the data controller’s organization—excluding those responsible for the technical storage, protection, and backup of data—or a person who processes personal data in accordance with the authority and instructions received from the data controller.
in accordance with the authority and instructions received from the data controller.
Destruction The erasure, destruction, or anonymization of personal data.
Law/KVKK The Personal Data Protection Law No. 6698.
Data Storage Medium
Any medium in which personal data is stored, whether processed fully or partially automatically, or processed by non-automated means provided that it is a part of any data recording system.
Personal Data Identity: Any information relating to an identified or identifiable natural person.
Data Inventory
The personal data processing activities carried out by data controllers in connection with their business processes; these activities are documented by linking the purposes of processing, legal
basis, data category, recipient group to whom the data is transferred, and the group of data subjects,
and which details the maximum retention period necessary for the purposes for which the personal data is processed,
and the measures taken regarding data security; this inventory provides a detailed account of these elements.
Processing of Personal Data
The processing of personal data—whether fully or partially automated, or obtained, recorded, stored, retained, modified, reorganized, disclosed, or transferred through non-automated means, provided that it is part of any data
recording system, whether fully or partially automated or by non-automated means; the collection, recording, storage, retention, modification, reorganization, disclosure, transfer, acquisition, or any action taken on the data to make it accessible, classify it, or prevent its use;
, classified, or restricted from use—such as the prevention of use—of such data.
The Commission
The Personal Data Protection Commission established by AN-EL to manage the Policy and other relevant procedures and to ensure the enforcement of the Policy.
Board: Personal Data Protection Board.
Agency: Personal Data Protection Agency.
Special Category Personal Data:
Data regarding individuals’ race, ethnic origin, political opinions, philosophical beliefs, religion, denomination, or
other beliefs, dress and attire, membership in associations, foundations, or unions, health,
sexual life, criminal convictions, and security measures, as well as
biometric and genetic data.
Periodic Destruction
The process of deleting, destroying, or anonymizing personal data, as specified in the personal data retention and destruction policy, which will be carried out automatically at regular intervals when all conditions for the processing of personal data set forth in the Law have ceased to exist.
Policy: Personal Data Protection Policy
Data Processor: A natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the data controller.
Data Controller:
The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording
system.
4. GENERAL PRINCIPLES
AN-EL verifies, during the preparation phase of any new workflow requiring the processing of personal data, that the data to be processed complies with the following
principles. Workflows found to be non-compliant are not implemented.
When processing personal data, AN-EL:
(I) Complies with the law and the principles of good faith.
(II) Ensures that personal data is accurate and, where necessary, up-to-date.
(III) Ensures that the purpose of processing is specific, clear, and legitimate.
(IV) Verifies that the data being processed is relevant to the purpose of processing, is limited to the extent necessary for that purpose, and is proportionate.
(V) Retains data only for as long as required by applicable legislation or as necessary for the purpose of processing, and
destroys it when the purpose of processing no longer exists.
5. DUTIES AND RESPONSIBILITIES
To manage this Policy regarding the processing of personal data within AN-EL and related procedures, and
ensure the Policy’s implementation.
The Commission consists of the General Manager, the Human Resources Manager, the Head of Administrative and Financial Affairs, and the Head of Quality Assurance. In addition, AN-EL obtains KVKK consulting support as needed to ensure compliance with the Personal Data Protection Law No. 6698. If deemed necessary, the Commission may invite the Personal Data Protection consultant to its meetings.
The duties and responsibilities of the Commission are outlined below.
(I) It meets regularly every six months. Extraordinary meetings may be convened if circumstances require it (for example, in the event of a potential data breach).
(II) It discusses matters in the Policy that need to be amended or improved.
(III) It identifies measures that can be implemented to ensure the lawful processing and protection of personal data.
(IV) The Committee identifies steps that can be taken to increase awareness of the Personal Data Protection Law (KVKK) within the company and among business partners.
(V) It identifies risks that may arise regarding the processing and protection of personal data and takes the necessary administrative and
technical measures.
(VI) Facilitates communication with the Authority and manages relations with it.
(VII) Evaluates requests received from the Data Subject.
(VIII) Monitors periodic data destruction processes.
(IX) Updates the Data Inventory.
(X) Assigns responsibilities regarding the matters listed above.
6. Measures Taken for Data Security
AN-EL takes all necessary technical and administrative measures to (i) prevent the unlawful processing of personal data, (ii) prevent unlawful access to personal data, and (iii) ensure an appropriate level of security to safeguard personal data.
.
6.1. Technical Measures
(I) Network and application security are ensured.
(II) Security measures are implemented in the procurement, development, and maintenance of information technology systems.
(III) Access logs are maintained on a regular basis.
(IV) Up-to-date antivirus systems are used.
(V) Firewalls are used.
(VI) Necessary security measures are taken regarding entry and exit to and from physical environments containing personal data.
(VII) The security of physical environments containing personal data against external risks (fire, flood, etc.) is ensured.
(VIII) The security of environments containing personal data is ensured.
(IX) Personal data is backed up, and the security of the backed-up personal data is also ensured.
(X) A user account management and authorization control system is in place, and these are monitored.
(XI) Log records are maintained in a manner that prevents user interference.
(XII) Intrusion detection and prevention systems are used.
(XIII) Encryption is used.
6.2. Administrative Measures
(I) Disciplinary regulations containing data security provisions for employees are in place.
(II) Training and awareness programs on data security are conducted for employees at regular intervals.
(III) Corporate policies regarding access, information security, use, storage, and disposal have been developed and
implemented.
(IV) Data masking measures are applied when necessary.
(V) Non-disclosure agreements are in place.
(VI) An authorization matrix has been created for employees.
(VII) The relevant authorizations of employees who change roles or leave the company are revoked.
(VIII) Signed contracts include provisions on data security.
(IX) Personal data security policies and procedures have been established.
(X) Personal data security issues are reported promptly.
(XI) Personal data security is monitored.
(XII) Personal data is minimized as much as possible.
(XIII) Periodic and/or random internal audits are conducted and commissioned.
(XIV) Current risks and threats have been identified.
(XV) Protocols and procedures regarding the security of special-category personal data have been established and are being implemented.
(XVI) If special-category personal data is to be sent via email, it is always sent in an encrypted format using KEP or a corporate email account.
(XVII) Data processors’ awareness of data security is ensured.
7. Data Subject’s Rights Regarding Personal Data
The data subject may submit a request to AN-EL regarding the following matters:
(I) To learn whether their personal data is being processed,
(II) To request information regarding the processing of their personal data, if it has been processed,
(III) To learn the purpose of the processing of their personal data and whether it is being used in accordance with that purpose,
(IV) To learn the third parties to whom their personal data has been transferred, whether within or outside the country,
(V) To request the correction of their personal data if it has been processed incompletely or incorrectly, and to request that
that the third parties to whom the personal data has been transferred be notified of the rectification,
(VI) To request the erasure, destruction, or anonymization of their personal data, even if it has been processed in accordance with the provisions of the Personal Data Protection Law (KVKK) and other relevant laws, if the reasons justifying its processing have ceased to exist,
and to request that the action taken in this regard be notified to the third parties to whom the personal data has been transferred,
7,
and to request that the third parties to whom the personal data has been transferred be notified of the action taken in this regard,
;
(VII) To object to a decision made solely through the automated analysis of processed data that is detrimental to the data subject,
result arising to his or her detriment,
(VIII) To request compensation for damages in the event he or she suffers harm due to the unlawful processing of his or her personal data.
8. VIOLATION REPORTS
AN-EL employees shall report to the Commission any business activity, action, or incident that they believe violates the provisions of the Personal Data Protection Law (KVKK) and/or this Policy.
Following such a breach report, the Committee shall convene if it deems necessary and develop an
action plan regarding the breach.
If the violation occurred through the unlawful acquisition of personal data by third parties, the Commission shall, within 72 hours, notify the relevant parties and the Board of this situation in accordance with the Board’s decision No. 2019/10 dated January 24, 2019.
9. AMENDMENTS
Amendments to this Policy are prepared by the Commission and submitted to the AN-EL Board of Directors for approval.
The updated Policy may be sent to employees via email or published on the website.
10. EFFECTIVE DATE
This version of the Policy was approved by the Board of Directors on January 1, 2020, and entered into effect on that date.
Related Documents:
Data Protection Policy
Privacy Notice Regarding Personal Data Processed in the Contact Form
Website Information Notice
Job Applicant Information Notice
General Corporate Information Notice on the Protection of Personal Data
Camera Surveillance Systems Information Notice