REYSAS VEHICLE INSPECTION STATIONS OPERATION JOINT STOCK COMPANY
PERSONAL DATA STORAGE AND DESTRUCTION POLICY
This Personal Data Storage and Destruction Policy ("Policy") applies to the entirety of Reysaş Taşıt Muayene İstasyonları İşletim Anonim Şirketi (hereinafter referred to as "the Company") under the current legislation and is based on nationally accepted fundamental principles regarding personal data destruction. It outlines the framework and principles for carrying out necessary destruction activities within the scope of relevant legislation.
The third paragraph of Article 7 of the Personal Data Protection Law ("Law") states that "The procedures and principles for the deletion, destruction, or anonymization of personal data shall be regulated by a regulation." Pursuant to this provision and Article 22, paragraph 1, subparagraph (e) of the Law, the Personal Data Protection Board ("Board") prepared the Regulation on the Deletion, Destruction or Anonymization of Personal Data ("Regulation"), which was published in the Official Gazette dated October 28, 2017, and numbered 30224.
Based on the above regulation, the purpose of this Policy is to determine the procedures and principles for the deletion, destruction, or anonymization of personal data processed by the Company in the course of its operations, in accordance with the Regulation.
1.2. Scope
This Policy covers personal data belonging to employees, employee candidates, visitors, third parties with whom our Company has legal relationships, and employees of third parties. This Policy applies to all record-keeping environments where personal data owned or managed by the Company is processed, and to all activities related to personal data processing.
1.3. Abbreviations and Definitions
| Term | Definition |
|---|---|
| Receiver group | A personal data category transferred by the data controller to a real or legal person. |
| Explicit Consent | Consent given voluntarily, based on specific information, and without any influence. |
| Anonymization | The process of rendering personal data in such a way that it can no longer be associated with an identified or identifiable natural person, even by matching it with other data. |
| Electronic Medium | Environments where personal data can be created, read, modified, and written using electronic devices. |
| Non-Electronic Medium | All written, printed, visual, etc., other environments apart from electronic environments. |
| Data Subject | The natural person whose personal data is being processed. |
| Authorized User | Persons processing personal data within the data controller's organization or under the authority and instruction received from the data controller, excluding the person or unit responsible for the technical storage, protection, and backup of the data. |
| Destruction | The deletion, destruction, or anonymization of personal data. |
| Law | Law No. 6698 on the Protection of Personal Data. |
| Record-keeping Environment | Any environment containing personal data processed wholly or partly by automatic means or as part of a data recording system by non-automatic means. |
| Personal Data | Any information relating to an identified or identifiable natural person. |
| Personal Data Owner | The natural person whose personal data is processed. |
| Processing of Personal Data | Any operation performed upon personal data, wholly or partly by automatic means or as part of a data recording system by non-automatic means, such as obtaining, recording, storing, preserving, altering, reorganizing, disclosing, transferring, acquiring, making available, classifying, or preventing the use thereof. |
| Personal Data Processing Inventory | An inventory created by data controllers detailing their personal data processing activities based on their business processes, associating them with personal data processing purposes, data categories, recipient groups transferred, and data subject groups, and explaining the maximum duration for which personal data is processed for the intended purposes, personal data intended for transfer to foreign countries, and data security measures taken. |
| Board | Personal Data Protection Board. |
| Authority | Personal Data Protection Authority. |
| Special Categories of Personal Data | Data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, dress and appearance, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. |
| Periodic Destruction | The deletion, destruction, or anonymization process carried out ex officio at recurring intervals as specified in the personal data storage and destruction policy, in cases where all personal data processing conditions set forth in the Law no longer exist. |
| Policy | The policy adopted by data controllers as a basis for determining the maximum duration for which personal data is processed for its intended purpose, and for the deletion, destruction, and anonymization process. |
| Registry | The data controllers' registry kept by the Personal Data Protection Authority Presidency. |
| Data Processor | The natural or legal person who processes personal data on behalf of the data controller based on the authority granted by them. |
| Data Recording System | The recording system in which personal data is processed by structuring it according to certain criteria. |
| Data Controller | Refers to the natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system. |
| Regulation | The Regulation on the Deletion, Destruction or Anonymization of Personal Data, published in the Official Gazette dated 28.10.2017 and numbered 30224. |
All departments and employees of the Company actively support the responsible units in properly implementing the technical and administrative measures taken within the scope of the Policy, increasing the training and awareness of departmental employees, monitoring and continuously auditing, preventing unlawful processing of personal data, preventing unlawful access to personal data, and taking technical and administrative measures to ensure the lawful storage of personal data in all environments where personal data is processed.
The distribution of titles, departments, and job descriptions of those involved in personal data storage and destruction processes is provided below.
Table 1: Storage and Destruction Process Duty Distribution
| Title | Department | Job Description |
|---|---|---|
| Information Technology Officer | Information Technology | Ensuring the compliance of processes within their duty with the storage period, managing the periodic destruction process, conducting necessary audits and controls to respond to Data Owners' requests. |
| Accounting Department Manager | Accounting | Ensuring the compliance of processes within their duty with the storage period, managing the periodic destruction period, controlling the continuation and cessation of book and document retention obligations arising from the Turkish Commercial Code No. 6100 and Tax Legislation. |
| Human Resources/Personnel Manager | Human Resources/Personnel | Ensuring the compliance of personnel personal data with the storage period, managing the periodic destruction process, receiving and responding to personnel's requests for clarification regarding their rights specified in the Law. |
| Other Managers and Authorized Personnel | Vehicle Inspection, Legal, Administrative Affairs, OHS, Customer Acceptance, Purchasing, Insurance | Ensuring the compliance of processes within their duty with the storage period, managing the periodic destruction process, controlling the continuation and cessation of document retention obligations related to contracts and relevant legislation. |
Personal data is stored securely and lawfully by the Company in the environments listed in Table 2.
Table 2: Personal Data Storage Environments
| Electronic Environments | Non-Electronic Environments |
|---|---|
| Servers (Domain, backup, email, database, web, file sharing, etc.) | Paper |
| Software (office software) Information security devices (firewall, log file, antivirus etc.) | Manual data recording systems |
| Mobile devices (phone, tablet, etc.) | Written, printed, visual media |
| Optical discs (CD, DVD, etc.) | Folders |
| Removable memories (USB, Memory Card, etc.) | Files |
| Printer, scanner, photocopy machine | |
| USB, hard disk and other removable storage devices | |
| Desktop and laptop computers |
The Company stores and destroys personal data of natural persons, including employees, employee candidates, employee candidate relatives, employee relatives, auditors, business partner representatives, public institution officials, potential product or service buyers, suppliers, supplier employees, supplier officials, product or service recipients, product or service recipient employees, chairman of the board, board members, visitors, and other third parties, in accordance with the KVKK (Personal Data Protection Law).
Detailed explanations regarding storage and destruction are provided below.
4.1. Explanations Regarding Storage
Article 3 of the Law defines the concept of personal data processing, and Article 4 states that processed personal data must be connected to, limited, and proportionate to the purpose for which they are processed, and must be retained for the period stipulated in the relevant legislation or for the period necessary for the purpose for which they are processed. Articles 5 and 6 list the conditions for processing personal data.
Accordingly, within the scope of Company activities, personal data is stored for the period stipulated in the relevant legislation or for a period appropriate to our processing purposes.
4.1.1. Legal Reasons Requiring Storage
The Company retains personal data processed within the scope of its activities for the period stipulated in the relevant legislation. In this context, personal data is stored for the periods specified in, but not limited to, the following legislation:
as well as other secondary legislation in force.
4.1.2. Processing Purposes Requiring Storage
The Company stores personal data processed within the scope of its activities for the following purposes:
4.2. Reasons Requiring Destruction
Personal data is deleted, destroyed, or anonymized by the Company, upon the request of the data subject or ex officio, in accordance with the relevant legislation, in the following circumstances:
The Company takes technical and administrative measures for the secure storage, prevention of unlawful processing and access, and lawful destruction of personal data, in accordance with Article 12 and Article 6, paragraph 4 of the KVKK, and within the scope of adequate measures determined and announced by the Board for special categories of personal data.
5.1. Technical Measures
Measures taken by the Company regarding the personal data it processes are listed below:
5.2. Administrative Measures
Measures taken by the Company regarding the personal data it processes are listed below:
At the end of the retention period stipulated in the relevant legislation or required for the purpose for which they were processed, personal data is destroyed by the Company ex officio or upon the request of the data subject, in accordance with the relevant legislation provisions, using the techniques specified below.
6.1. Deletion of Personal Data
Personal data is deleted using the methods provided in Table 3.
Table 3: Deletion of Personal Data
| Data Recording Environment | Description |
|---|---|
| Personal data in physical environments | Personal data in physical environments is deleted by using the blacking out method or by storing the document in a secure environment where it cannot be accessed by relevant users. |
| Personal data on servers | For personal data on servers whose retention period has expired, the system administrator removes the access rights of the relevant users, thereby performing the deletion process. |
| Personal data in databases | Access to personal data in the database is prevented by assigning roles and permissions to the relevant user. |
| Personal data on portable devices (USB, Hard disk, CD, DVD, etc.) | The relevant user's access to the file is blocked. |
6.2. Destruction of Personal Data
As the Company, the methods we use to lawfully destroy personal data are as follows:
Table 4: Destruction of Personal Data
| Data Recording Environment | Description |
|---|---|
| Physical personal data | Paper personal data that has completed the retention period is eliminated by being rendered irreversible in paper shredders. |
| Environmental (network devices, flash-based media, optical systems, etc.) and local personal data | Personal data on devices is eliminated through physical processes such as burning, fragmentation, and melting. In addition, the demagnetization method renders the personal data on the device unreadable, thereby destroying it. Furthermore, special software is used to overwrite existing data with random data, preventing the recovery of old data and performing destruction. |
6.3. Anonymization of Personal Data
Anonymization of personal data is the process of making personal data impossible to link to an identified or identifiable natural person, even when matched with other data.
For personal data to be anonymized, it must be rendered impossible to link to an identified or identifiable natural person, even through techniques such as reversing or matching the data with other data by the data controller or third parties, considering the record-keeping environment and the relevant field of activity.
Regarding personal data processed by the Company within the scope of its activities:
The personal data destruction process is carried out by the Company in accordance with the retention periods determined by the Company for each relationship, considering the relevant legislation. Personal data whose retention periods have expired are deleted, destroyed, or anonymized by the Company within the determined periodic destruction periods.
Table 5: Process-Based Storage and Destruction Periods Table
| Process | Storage Period | Destruction Period |
|---|---|---|
| Execution of human resources employee processes | 15 years from the employee's departure | In the first 6-month periodic destruction period following the end of the storage period |
| Execution of employee candidate processes | 10 years from the date of application rejection | In the first 6-month periodic destruction period following the end of the storage period |
| Execution of contract processes | 10 years after the contract ends | In the first 6-month periodic destruction period following the end of the storage period |
| Execution of management relationships | 15 years from the end of the legal relationship | In the first 6-month periodic destruction period following the end of the storage period |
| Execution of legal relationships | Finalization + 15 years | In the first 6-month periodic destruction period following the end of the storage period |
| Execution of insurance relationships | 15 years from the end of the policy | In the first 6-month periodic destruction period following the end of the storage period |
| Vehicle Inspection and Customer Acceptance Procedures | 10 years after recording | In the first 6-month periodic destruction period following the end of the storage period |
| Camera Recordings | 60 days after recording | Automatically destroyed at the end of the recording period |
| Execution of Accounting and Finance Processes | 10 years after recording | In the first 6-month periodic destruction period following the end of the storage period |
The ex officio deletion, destruction, or anonymization process for personal data whose retention periods have expired is carried out by the departments listed under the heading "2. RESPONSIBILITIES AND DUTIES."
Pursuant to Article 11 of the Regulation, the periodic destruction period has been determined by the Company as [6] months. Accordingly, the Company performs periodic destruction operations every June and December.
The Policy is published in two different environments: with a wet signature (printed paper) and in electronic form, and it is made public on the Company's website. The printed paper copy is stored in the Human Resources Department's file.
The Policy is updated when necessary and when there are changes in processes.
This Policy is considered to have entered into force upon its publication on the Company's website.
If it is decided to abrogate the Policy, the old wet-signed copies of the Policy will be canceled (by stamping "canceled" or writing "canceled") with the company stamp and signature of the company official, and stored by the Human Resources Department for a minimum of 5 years.