CORPORATE
Personal Data Protection Law
CORPORATE
Personal Data Protection Law
SİNERJİ BİLGİ TEKNOLOJİLERİ TİC.A.Ş. INFORMATION TEXT IN ACCORDANCE WITH LAW NO. 6698 ON THE PROTECTION OF PERSONAL DATA
Protecting personal data is not only a legal obligation for our organization, but also a fundamental responsibility towards data subjects and our customers. In this regard, we, as senior management, commit to the following:
- To establish, maintain and continuously improve the effectiveness of the ISO/IEC 27701:2019 Personal Data Management System,
- To process personal data in accordance with the law and principles of fairness; to keep it accurate and up-to-date when necessary,
- To process personal data for specific, explicit and legitimate purposes; to keep the processing relevant, limited and proportionate to the purpose for which it is processed,
- We will process personal data only on the legal grounds stipulated in Law No. 6698; and in cases requiring explicit consent, we will obtain that consent freely and based on informed knowledge.
- The obligation to inform must be fulfilled at the time the data is obtained and in a clear and understandable manner; the information text should not be combined with the explicit consent text.
- We process sensitive personal data only in cases permitted by law, with additional security measures and by limiting access to the narrowest possible scope.
- To process the applications of the relevant individuals free of charge within the legal timeframe; to ensure that they can effectively exercise their rights to request information, make corrections, delete files, and appeal.
- We will store personal data for the periods specified in the Personal Data Storage and Destruction Policy; after these periods, we will delete, destroy, or anonymize it.
- To keep the personal data processing inventory up-to-date and to fulfill VERBİS obligations on time,
- To enter into data processing agreements with suppliers who process personal data on behalf of the organization and to monitor these parties’ compliance with their obligations,
- To take the necessary technical and administrative measures to detect personal data breaches; and in case of a breach, to notify the Personal Data Protection Board and the relevant individuals within the legal timeframe.
- To assess personal data security risks within the scope of PR.05 Risk Management Procedure; to consider the impact on the data subject in the assessment of severity,
- To provide all employees with regular awareness training on personal data protection,
- To appoint a Data Controller Contact Person who will serve as the point of contact for all matters relating to the processing of personal data,
- We aim to keep this policy up-to-date by reviewing it at least once a year and with legislative changes.
Click to view: SinerjiBT Application Form