SPECIALIST DOCTOR TUBA CELEBI KAYHAN DERMATOLOGY CLINIC
STORAGE AND PROTECTION POLICY OF SPECIAL NATURE PERSONAL DATA
- Introduction
- PURPOSE AND SCOPE OF THE POLICY
The Law on the Protection of Personal Data No. 6698 entered into force on April 7, 2016; this policy aims to ensure compliance of Specialist Dr. Tuba Çelebi Kayhan Dermatology Clinic (hereinafter referred to as the ‘’Clinic’’) with the Law on the Protection of Special Personal Data and to determine the principles to be followed by the Clinic in fulfilling its obligations regarding the protection and processing of special personal data.
The Policy determines the processing conditions of special personal data and sets out the main principles adopted by the clinic in the processing of personal data. In this context, the Policy covers all personal data processing activities of the clinic within the scope of the Law, the owners of all personal data processed within the scope of the clinic and all personal data processed.
- ENFORCEMENT AND AMENDMENT
The policy has been published on our website and made available to the public. In case of conflict between the current legislation, especially the Law, and the regulations included in this Policy, the provisions of the legislation shall apply.
The Clinic reserves the right to make changes to the Policy in line with legal regulations. The current version of the Policy can be found on the clinic website. https://drtubacelebikayhan.com It can be accessed at.
- SPECIAL NATURE PERSONAL DATA
It refers to data regarding race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or unions, health, sexual life, criminal convictions and security measures and biometric data.
- PROCESSING OF SPECIAL NATURE PERSONAL DATA
Our clinic meticulously complies with the regulations stipulated in the Law in the processing of personal data determined as “special” by the Law. In Article 6 of the Law, a number of personal data that carry the risk of causing victimization or discrimination to individuals when processed unlawfully are determined as “special”. These data are; data related to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, association, foundation or union membership, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data.
In accordance with the law, our clinic processes special personal data in the following cases, provided that adequate measures are taken, as determined by the Personal Data Protection Board:
- If the personal data owner has given explicit consent, or
- If there is no explicit consent of the personal data owner;
Personal data of a special nature, other than the health and sexual life of the personal data owner, are processed in cases prescribed by law, and personal data of a special nature, regarding the health and sexual life of the personal data owner, are processed only by persons or authorized institutions and organizations that are under a confidentiality obligation for the purposes of protecting public health, providing preventive medicine, medical diagnosis, treatment and care services, and planning and managing health services and their financing.
- TRANSFER OF SPECIAL NATURE PERSONAL DATA
Our clinic may transfer the personal data owner's special personal data to third parties in the following cases, in line with legitimate and lawful personal data processing purposes, by showing the necessary care, taking the necessary security measures and taking the sufficient measures prescribed by the Personal Data Protection Board.
- If the personal data owner has given explicit consent, or
- If there is no explicit consent of the personal data owner;
Personal data of a special nature other than the health and sexual life of the personal data owner (data related to race, ethnic origin, political opinion, philosophical belief, religion, sect or other belief, appearance and dress, association, foundation or union membership, criminal conviction and security measures, and biometric and genetic data), in cases prescribed by law,
Sensitive personal data regarding the health and sexual life of the personal data owner can only be transferred by persons or authorized institutions and organizations that are under a confidentiality obligation for the purposes of protecting public health, providing preventive medicine, medical diagnosis, treatment and care services, and planning and managing health services and their financing.
- TRANSFER OF SPECIAL NATURE PERSONAL DATA ABROAD
Our clinic may transfer the personal data owner's special data to Foreign Countries Where Data Controllers Have Sufficient Protection or Promise Sufficient Protection, in line with legitimate and lawful personal data processing purposes, by showing due care, taking the necessary security measures and taking the sufficient measures prescribed by the Personal Data Protection Board, in the following cases:
- If the personal data owner has given explicit consent, or
- If there is no explicit consent of the personal data owner;
Personal data of a special nature other than the health and sexual life of the personal data owner (data related to race, ethnic origin, political opinion, philosophical belief, religion, sect or other belief, appearance and dress, association, foundation or union membership, criminal conviction and security measures, and biometric and genetic data), in cases prescribed by law,
The personal data of a personal data owner, which is of a special nature, regarding his/her health and sexual life, may only be processed by persons or authorized institutions and organizations that are under a confidentiality obligation for the purposes of protecting public health, providing preventive medicine, medical diagnosis, treatment and care services, and planning and managing health services and their financing.
- PROTECTION OF SPECIAL NATURE PERSONAL DATA
Our clinic is meticulous about protecting personal data of a special nature, which is determined by the Law as "special nature" and processed in accordance with the law. In this context, the technical and administrative measures taken by our clinic to protect personal data are meticulously implemented in terms of personal data of a special nature, and the necessary inspections are carried out within our clinic.
In addition, technical and administrative measures are taken to ensure the appropriate level of security, as determined by the Personal Data Protection Board, regarding special personal data.
The general principle of our clinic is not to process special personal data unless there are reasons arising from the law.
Unnecessary special personal data are deleted or blacked out. Based on this, systematic rules for the security of special personal data are determined in this policy;
- MEASURES FOR EMPLOYEES INVOLVED IN PROCESSING SPECIAL NATURE PERSONAL DATA
- Regular training is provided on special personal data security issues in accordance with the law and related regulations.
- Confidentiality agreements are signed.
- The authorization scopes and authorization processes of users with access authority to data are defined by the authorization matrix.
- Authorization checks are performed periodically.
- The authority of employees who change their duties or leave their jobs is immediately revoked in these areas.
- FOR ELECTRONIC ENVIRONMENTS WHERE SPECIAL NATURE PERSONAL DATA IS PROCESSED AND STORED
- Security updates for the environments where the data is located are constantly monitored.
- If data is accessed via software, user authorization for this software is performed.
2.4.3. FOR PHYSICAL ENVIRONMENTS WHERE SPECIAL NATURE PERSONAL DATA IS PROCESSED AND STORED
- Necessary security measures are taken regarding entry and exit to physical environments containing sensitive personal data.
- The security of physical environments containing sensitive personal data is ensured against external risks (fire, flood, etc.).
- PRECAUTIONS REGARDING THE TRANSFER OF SPECIAL NATURE PERSONAL DATA
- When transferring documents via paper, necessary precautions are taken against risks such as theft, loss, or viewing by unauthorized persons, and documents are sent in sealed envelopes in the format of “classified documents”.