REYSAŞ VEHICLE INSPECTION STATIONS MANAGEMENT INC. – PERSONAL DATA RETENTION AND DESTRUCTION POLICY

REYSAS VEHICLE INSPECTION STATIONS OPERATION JOINT STOCK COMPANY

PERSONAL DATA STORAGE AND DESTRUCTION POLICY

  1. INTRODUCTION 1.1. Purpose

This Personal Data Storage and Destruction Policy ("Policy") applies to the entirety of Reysaş Taşıt Muayene İstasyonları İşletim Anonim Şirketi (hereinafter referred to as "the Company") under the current legislation and is based on nationally accepted fundamental principles regarding personal data destruction. It outlines the framework and principles for carrying out necessary destruction activities within the scope of relevant legislation.

The third paragraph of Article 7 of the Personal Data Protection Law ("Law") states that "The procedures and principles for the deletion, destruction, or anonymization of personal data shall be regulated by a regulation." Pursuant to this provision and Article 22, paragraph 1, subparagraph (e) of the Law, the Personal Data Protection Board ("Board") prepared the Regulation on the Deletion, Destruction or Anonymization of Personal Data ("Regulation"), which was published in the Official Gazette dated October 28, 2017, and numbered 30224.

Based on the above regulation, the purpose of this Policy is to determine the procedures and principles for the deletion, destruction, or anonymization of personal data processed by the Company in the course of its operations, in accordance with the Regulation.

1.2. Scope

This Policy covers personal data belonging to employees, employee candidates, visitors, third parties with whom our Company has legal relationships, and employees of third parties. This Policy applies to all record-keeping environments where personal data owned or managed by the Company is processed, and to all activities related to personal data processing.

1.3. Abbreviations and Definitions

Term Definition
Receiver group A personal data category transferred by the data controller to a real or legal person.
Explicit Consent Consent given voluntarily, based on specific information, and without any influence.
Anonymization The process of rendering personal data in such a way that it can no longer be associated with an identified or identifiable natural person, even by matching it with other data.
Electronic Medium Environments where personal data can be created, read, modified, and written using electronic devices.
Non-Electronic Medium All written, printed, visual, etc., other environments apart from electronic environments.
Data Subject The natural person whose personal data is being processed.
Authorized User Persons processing personal data within the data controller's organization or under the authority and instruction received from the data controller, excluding the person or unit responsible for the technical storage, protection, and backup of the data.
Destruction The deletion, destruction, or anonymization of personal data.
Law Law No. 6698 on the Protection of Personal Data.
Record-keeping Environment Any environment containing personal data processed wholly or partly by automatic means or as part of a data recording system by non-automatic means.
Personal Data Any information relating to an identified or identifiable natural person.
Personal Data Owner The natural person whose personal data is processed.
Processing of Personal Data Any operation performed upon personal data, wholly or partly by automatic means or as part of a data recording system by non-automatic means, such as obtaining, recording, storing, preserving, altering, reorganizing, disclosing, transferring, acquiring, making available, classifying, or preventing the use thereof.
Personal Data Processing Inventory An inventory created by data controllers detailing their personal data processing activities based on their business processes, associating them with personal data processing purposes, data categories, recipient groups transferred, and data subject groups, and explaining the maximum duration for which personal data is processed for the intended purposes, personal data intended for transfer to foreign countries, and data security measures taken.
Board Personal Data Protection Board.
Authority Personal Data Protection Authority.
Special Categories of Personal Data Data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, dress and appearance, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
Periodic Destruction The deletion, destruction, or anonymization process carried out ex officio at recurring intervals as specified in the personal data storage and destruction policy, in cases where all personal data processing conditions set forth in the Law no longer exist.
Policy The policy adopted by data controllers as a basis for determining the maximum duration for which personal data is processed for its intended purpose, and for the deletion, destruction, and anonymization process.
Registry The data controllers' registry kept by the Personal Data Protection Authority Presidency.
Data Processor The natural or legal person who processes personal data on behalf of the data controller based on the authority granted by them.
Data Recording System The recording system in which personal data is processed by structuring it according to certain criteria.
Data Controller Refers to the natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.
Regulation The Regulation on the Deletion, Destruction or Anonymization of Personal Data, published in the Official Gazette dated 28.10.2017 and numbered 30224.

 


  1. RESPONSIBILITIES AND DUTIES

All departments and employees of the Company actively support the responsible units in properly implementing the technical and administrative measures taken within the scope of the Policy, increasing the training and awareness of departmental employees, monitoring and continuously auditing, preventing unlawful processing of personal data, preventing unlawful access to personal data, and taking technical and administrative measures to ensure the lawful storage of personal data in all environments where personal data is processed.

The distribution of titles, departments, and job descriptions of those involved in personal data storage and destruction processes is provided below.

Table 1: Storage and Destruction Process Duty Distribution

Title Department Job Description
Information Technology Officer Information Technology Ensuring the compliance of processes within their duty with the storage period, managing the periodic destruction process, conducting necessary audits and controls to respond to Data Owners' requests.
Accounting Department Manager Accounting Ensuring the compliance of processes within their duty with the storage period, managing the periodic destruction period, controlling the continuation and cessation of book and document retention obligations arising from the Turkish Commercial Code No. 6100 and Tax Legislation.
Human Resources/Personnel Manager Human Resources/Personnel Ensuring the compliance of personnel personal data with the storage period, managing the periodic destruction process, receiving and responding to personnel's requests for clarification regarding their rights specified in the Law.
Other Managers and Authorized Personnel Vehicle Inspection, Legal, Administrative Affairs, OHS, Customer Acceptance, Purchasing, Insurance Ensuring the compliance of processes within their duty with the storage period, managing the periodic destruction process, controlling the continuation and cessation of document retention obligations related to contracts and relevant legislation.

 


  1. RECORDING ENVIRONMENTS

Personal data is stored securely and lawfully by the Company in the environments listed in Table 2.

Table 2: Personal Data Storage Environments

Electronic Environments Non-Electronic Environments
Servers (Domain, backup, email, database, web, file sharing, etc.) Paper
Software (office software) Information security devices (firewall, log file, antivirus etc.) Manual data recording systems
Mobile devices (phone, tablet, etc.) Written, printed, visual media
Optical discs (CD, DVD, etc.) Folders
Removable memories (USB, Memory Card, etc.) Files
Printer, scanner, photocopy machine  
USB, hard disk and other removable storage devices  
Desktop and laptop computers  

 


  1. EXPLANATIONS REGARDING STORAGE AND DESTRUCTION

The Company stores and destroys personal data of natural persons, including employees, employee candidates, employee candidate relatives, employee relatives, auditors, business partner representatives, public institution officials, potential product or service buyers, suppliers, supplier employees, supplier officials, product or service recipients, product or service recipient employees, chairman of the board, board members, visitors, and other third parties, in accordance with the KVKK (Personal Data Protection Law).

Detailed explanations regarding storage and destruction are provided below.

4.1. Explanations Regarding Storage

Article 3 of the Law defines the concept of personal data processing, and Article 4 states that processed personal data must be connected to, limited, and proportionate to the purpose for which they are processed, and must be retained for the period stipulated in the relevant legislation or for the period necessary for the purpose for which they are processed. Articles 5 and 6 list the conditions for processing personal data.

Accordingly, within the scope of Company activities, personal data is stored for the period stipulated in the relevant legislation or for a period appropriate to our processing purposes.

4.1.1. Legal Reasons Requiring Storage

The Company retains personal data processed within the scope of its activities for the period stipulated in the relevant legislation. In this context, personal data is stored for the periods specified in, but not limited to, the following legislation:

  • Tax Procedure Law No. 213
  • Identity Notification Law No. 1774
  • Labor Law No. 4857
  • Social Security and General Health Insurance Law No. 5510
  • Law on Regulation of Publications Made on the Internet and Combating Crimes Committed Through Such Publications No. 5651
  • Turkish Code of Obligations No. 6098
  • Turkish Commercial Code No. 6102
  • Occupational Health and Safety Law No. 6361
  • Personal Data Protection Law No. 6698

as well as other secondary legislation in force.

4.1.2. Processing Purposes Requiring Storage

The Company stores personal data processed within the scope of its activities for the following purposes:

  • Executing emergency management processes
  • Executing information security processes
  • Executing employee candidate / intern / student selection and placement processes
  • Executing employee candidate application processes
  • Fulfilling obligations arising from employment contracts and legislation for employees
  • Executing employee fringe benefits and benefits processes
  • Executing audit / ethical activities
  • Executing training activities
  • Ensuring compliance of activities with legislation
  • Executing financial and accounting affairs
  • Ensuring physical space security
  • Executing assignment processes
  • Following up and executing legal affairs
  • Executing internal audit / investigation / intelligence activities
  • Executing communication activities
  • Executing human resources processes
  • Executing / auditing business activities
  • Executing occupational health/safety activities
  • Executing business continuity activities
  • Executing goods/services procurement processes
  • Executing goods/services sales processes
  • Executing goods/services production and operation processes
  • Executing customer relationship management processes
  • Executing customer satisfaction activities
  • Organization and event management
  • Executing performance evaluation processes
  • Executing risk management processes
  • Executing contract processes
  • Executing strategic planning activities
  • Following up requests / complaints
  • Ensuring the security of movable property and resources
  • Executing supply chain management processes
  • Executing wage policy
  • Executing product / service marketing processes
  • Ensuring the security of data controller operations
  • Executing investment processes
  • Providing information to authorized persons, institutions, and organizations
  • Executing management activities

4.2. Reasons Requiring Destruction

Personal data is deleted, destroyed, or anonymized by the Company, upon the request of the data subject or ex officio, in accordance with the relevant legislation, in the following circumstances:

  • Changes to or repeal of the relevant legislation provisions serving as the basis for processing,
  • Cessation of the purpose requiring processing or storage,
  • In cases where personal data processing is based solely on explicit consent, the data subject withdrawing their explicit consent,
  • Acceptance of an application for the deletion or destruction of personal data made by the data subject within the framework of their rights pursuant to Article 11 of the KVKK,
  • In cases where the Company rejects the data subject's application for the deletion or destruction of their personal data, finds the response insufficient, or fails to respond within the period stipulated in the KVKK; the data subject filing a complaint with the Board and this request being approved by the Board, and
  • The maximum period requiring the storage of personal data has passed, and there is no condition justifying longer retention of personal data.

  1. TECHNICAL AND ADMINISTRATIVE MEASURES

The Company takes technical and administrative measures for the secure storage, prevention of unlawful processing and access, and lawful destruction of personal data, in accordance with Article 12 and Article 6, paragraph 4 of the KVKK, and within the scope of adequate measures determined and announced by the Board for special categories of personal data.

5.1. Technical Measures

Measures taken by the Company regarding the personal data it processes are listed below:

  • Network security and application security are ensured.
  • Security measures within the scope of information technology systems procurement, development, and maintenance are taken.
  • An authorization matrix has been created for employees.
  • Up-to-date antivirus systems are used.
  • Firewalls are used.
  • User account management and authorization control system are implemented and monitored.
  • Log records are kept without user intervention.
  • Intrusion detection and prevention systems are used.
  • Cybersecurity measures have been taken and their implementation is continuously monitored.
  • Data loss prevention software is used.

5.2. Administrative Measures

Measures taken by the Company regarding the personal data it processes are listed below:

  • Confidentiality agreements are made.
  • Authorities of employees whose duties change or who leave employment are revoked.
  • Signed contracts include data security provisions.
  • Personal data security is monitored.
  • Necessary security measures are taken regarding entry and exit to physical environments containing personal data.
  • Security of physical environments containing personal data is ensured against external risks (fire, flood, etc.).
  • Security of environments containing personal data is ensured.
  • Personal data is minimized as much as possible.
  • Existing risks and threats have been identified.

  1. PERSONAL DATA DESTRUCTION TECHNIQUES

At the end of the retention period stipulated in the relevant legislation or required for the purpose for which they were processed, personal data is destroyed by the Company ex officio or upon the request of the data subject, in accordance with the relevant legislation provisions, using the techniques specified below.

6.1. Deletion of Personal Data

Personal data is deleted using the methods provided in Table 3.

Table 3: Deletion of Personal Data

Data Recording Environment Description
Personal data in physical environments Personal data in physical environments is deleted by using the blacking out method or by storing the document in a secure environment where it cannot be accessed by relevant users.
Personal data on servers For personal data on servers whose retention period has expired, the system administrator removes the access rights of the relevant users, thereby performing the deletion process.
Personal data in databases Access to personal data in the database is prevented by assigning roles and permissions to the relevant user.
Personal data on portable devices (USB, Hard disk, CD, DVD, etc.) The relevant user's access to the file is blocked.

 


6.2. Destruction of Personal Data

As the Company, the methods we use to lawfully destroy personal data are as follows:

Table 4: Destruction of Personal Data

Data Recording Environment Description
Physical personal data Paper personal data that has completed the retention period is eliminated by being rendered irreversible in paper shredders.
Environmental (network devices, flash-based media, optical systems, etc.) and local personal data Personal data on devices is eliminated through physical processes such as burning, fragmentation, and melting. In addition, the demagnetization method renders the personal data on the device unreadable, thereby destroying it. Furthermore, special software is used to overwrite existing data with random data, preventing the recovery of old data and performing destruction.

 


6.3. Anonymization of Personal Data

Anonymization of personal data is the process of making personal data impossible to link to an identified or identifiable natural person, even when matched with other data.

For personal data to be anonymized, it must be rendered impossible to link to an identified or identifiable natural person, even through techniques such as reversing or matching the data with other data by the data controller or third parties, considering the record-keeping environment and the relevant field of activity.


  1. STORAGE AND DESTRUCTION PERIODS

Regarding personal data processed by the Company within the scope of its activities:

  • Personal data storage periods are specified on a personal data basis within the Personal Data Processing Inventory for all personal data within the scope of activities carried out based on processes.
  • Data category-based storage periods are specified in the VERBİS (Data Controllers' Registry Information System) registration.
  • Process-based storage periods are included in this Personal Data Storage and Destruction Policy.

The personal data destruction process is carried out by the Company in accordance with the retention periods determined by the Company for each relationship, considering the relevant legislation. Personal data whose retention periods have expired are deleted, destroyed, or anonymized by the Company within the determined periodic destruction periods.

Table 5: Process-Based Storage and Destruction Periods Table

Process Storage Period Destruction Period
Execution of human resources employee processes 15 years from the employee's departure In the first 6-month periodic destruction period following the end of the storage period
Execution of employee candidate processes 10 years from the date of application rejection In the first 6-month periodic destruction period following the end of the storage period
Execution of contract processes 10 years after the contract ends In the first 6-month periodic destruction period following the end of the storage period
Execution of management relationships 15 years from the end of the legal relationship In the first 6-month periodic destruction period following the end of the storage period
Execution of legal relationships Finalization + 15 years In the first 6-month periodic destruction period following the end of the storage period
Execution of insurance relationships 15 years from the end of the policy In the first 6-month periodic destruction period following the end of the storage period
Vehicle Inspection and Customer Acceptance Procedures 10 years after recording In the first 6-month periodic destruction period following the end of the storage period
Camera Recordings 60 days after recording Automatically destroyed at the end of the recording period
Execution of Accounting and Finance Processes 10 years after recording In the first 6-month periodic destruction period following the end of the storage period

 

The ex officio deletion, destruction, or anonymization process for personal data whose retention periods have expired is carried out by the departments listed under the heading "2. RESPONSIBILITIES AND DUTIES."


  1. PERIODIC DESTRUCTION PERIOD

Pursuant to Article 11 of the Regulation, the periodic destruction period has been determined by the Company as [6] months. Accordingly, the Company performs periodic destruction operations every June and December.


  1. PUBLICATION AND STORAGE OF THE POLICY

The Policy is published in two different environments: with a wet signature (printed paper) and in electronic form, and it is made public on the Company's website. The printed paper copy is stored in the Human Resources Department's file.


  1. POLICY UPDATE PERIOD

The Policy is updated when necessary and when there are changes in processes.


  1. EFFECTIVENESS AND ABROGATION OF THE POLICY

This Policy is considered to have entered into force upon its publication on the Company's website.

If it is decided to abrogate the Policy, the old wet-signed copies of the Policy will be canceled (by stamping "canceled" or writing "canceled") with the company stamp and signature of the company official, and stored by the Human Resources Department for a minimum of 5 years.