This policy covers all units of Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi, employers of the companies which provide support services, apprentices and contract personnel.
Notices
This policy applies to all units of, employees of the companies which provide support services to, apprentices and contracted personnel of Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi. The disciplinary rules of Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi shall be applied to all acts violating the KVKK or this policy and if the violation constitutes an offense or misdemeanor, the relevant authorities shall be informed as soon as possible.
All solution partners of and third parties that work with Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi which have actual or potential access to the personal data are invited to read and comply with this policy. No third party may have access to personal data processed by Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi without a written confidentiality agreement that includes obligations and auditing rights that are as strict as those of Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi in the protection of personal data.
“Explicit consent” means the consent given on a specific matter based on information and free will.
“Anonymization” means converting personal data to such form that cannot be associated with an identified or identifiable person under any circumstances by even matching the personal data with other data.
“Data subject” means natural person whose personal data is processed,
“Personal data” means any information relating to an identified or identifiable natural person.
“Personal data of special (sensitive) nature” means the personal data relating to the race, ethnic origin, political opinion, philosophical belief, religion, sect or other belief, clothing, membership to associations, foundations or trade unions, health, sexual life, convictions, and security measures, and the biometric and genetic data of individuals.
“Processing personal data” means any operation performed upon personal data such as collection, recording, storage, retention, alteration, re-organization, disclosure, transferring, taking over, making retrievable, classification or preventing the use thereof, fully or partially through automatic means or provided that the process is a part of any data registry system, through non-automatic means.
“KVKK” means the Law on Protection of Personal Data No. 6698.
“KVKK Board” means the Personal Data Protection Board.
“KVKK Authority” means the Personal Data Protection Authority.
“Data processor” means a natural person or legal entity which processes personal data on behalf of and based on the authority given by the data controller.
“Data recording system” means the recording system where personal data is structured and processed according to specific criteria.
“Data controller” means the natural person or legal entity that determines purposes and means of the processing of personal data and that is responsible for establishment and management of a data recording system.
The KVK Committee consists of 1 chairman and 5 members. The Committee holds ordinary meetings once every six months or extraordinary meetings whenever deemed necessary.
Objective: Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi is aware of the risks associated with the processing of certain types of personal data.
Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi has a procedure in place to assess the risks the processing of personal data may impose on individuals. This assessment is performed taking into consideration the third parties that process the data on behalf of Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi, which manages the risks determined as a result of the assessment in a way that does not constitute a violation of this policy.
If a particular type of data processing activity is likely to pose a high risk to personal rights and freedoms due to its structure, context, and objectives, Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi shall manage potential risks by conducting an impact analysis prior to the data processing activity. A single assessment can be used for multiple data processing activities with similar risks.
If the impact analysis shows that Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi is about to start a data processing activity that may pose a high risk to personal rights and freedoms, the approval of the KVK Committee is sought regarding this issue. The KVK Committee, if deemed necessary, shall obtain an opinion from the KVK Board on the matter.
The systems and controls implemented in accordance with the system adopted by Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi pursuant to the Information Security Policy are applied in risk management.
All personal data processing activities must be performed in accordance with the following data protection principles. The policies and procedures of Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi intend to ensure compliance with these principles:
Accordingly, Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi shall include confidentiality notices in the data collection channels and related forms regarding the personal data processing activities it performs. The KVK Committee shall determine the areas where these notifications which include clear and understandable information about the type of data to be processed by Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi, the data subjects and the purpose of processing shall be posted and announced. These notifications include:
Data subjects shall have the following rights with respect to data processing activities and records at the Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi facilities:
Data subjects are entitled to submit their claims regarding their abovementioned rights to Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi in accordance with the application procedures provided for in the Communiqué on the Procedures and Principles of Application to the Data Controller. In this context, the requests can be submitted by completing the “Application Form” published on the website, personally confirming identification and mailing the application form to “Ferko Signature Büyükdere Cad. No:175/100 34394 Şişli İstanbul” via registered letter or notary public or e-mail the application form to sarten@hs03.kep.tr with confirmed identity.
In this case, Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi shall conclude the request as soon as possible depending on the nature of the request or within no later than 30 (thirty) days. However, if the operation necessitates additional cost item, Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi shall be entitled to claim the fee listed in the tariff designated by the Personal Data Protection Board. The processes for receiving, forwarding and finalizing the requests are carried out in accordance with the Request Management Procedure.
Data access rights and contact information of the data subjects shall be provided in the privacy statements and the web site of Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi for data subjects to send their requests.
Regardless of the job descriptions, all personnel of Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi shall be obliged to guide the data subjects about the correct application method for data subject access requests made to them. The KVK Committee shall inform and train all Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi personnel on what to do about the requests received from data subjects.
Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi considers the consent given in the form of written/verbal statement or explicit verification action of the data subject as explicit consent provided that it is given on a specific data processing activity based on information and free will and provided that it shows the free will for processing of his personal data. The explicit consent is obtained in writing or systematically in such a way that can be proved. The data subject is entitled to revoke the explicit consent at any time.
Explicit consent can be obtained by having the data subject sign the explicit consent form template or by including the elements contained in this template in the agreement to be executed with the data subject or electronic form used for this purpose.
In case the data processing activity based on an explicit consent is to be continuous or to be repeated, the relevant unit keeps the list of the persons whose explicit consents have been obtained. The explicit consent forms or other relevant means of evidence for data processing based on explicit consent shall be stored by the relevant unit.
All personnel are responsible for ensuring that the data processed by Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi which is under their responsibility is kept safe and not disclosed to a third party unless a confidentiality agreement is signed.
Personal data shall be accessible only by those who need to access such data. The access is provided in accordance with the Access Management Procedure.
Data security shall be provided in accordance with the Information Security Policy of Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi and the related documents.
The information security incidents related to personal data shall be notified to the KVK Board and the data subject as soon as possible and no later than within 72 hours after the incident is identified by the KVK Committee.
Where personal data is transferred abroad, the KVK Committee shall obtain the necessary permits from and give the necessary notifications to the KVK Board in accordance with KVKK and the relevant legislation.
The data disclosure agreements / protocols are submitted to the KVK Committee for approval.
Personal data may not be retained for longer than necessary for processing purposes. The classification of records containing personal data and their storage periods are determined in accordance with the [Labeling and Processing Procedure and Storage and Disposal procedure].
Upon expiry of the period necessary for processing purposes or the rightful request of the data subject, relevant personal data is anonymized or deleted or destroyed in such a way that the data subject cannot be identified and in accordance with the Storage and Destruction Procedure.
The Personal Data Protection Committee shall ensure that regular audits are performed on the procedures of personal data processing. Accordingly, an in-house audit team or an external audit firm assigned for this purpose shall perform auditing services.
The audit activities shall be carried out annually and the audit results shall be submitted to the Personal Data Protection Committee and the Committee shall make necessary improvements on the outcome of the audit report.
Document Ownership and Approval
The KVK Committee is the owner of this document and responsible for regular review of this policy in accordance with the review requirements set out above.
The current version of this document is made available to all Sarten Ambalaj Sanayi ve Ticaret Anonim Şirketi personnel via QDMS or Intranet system and published via www.sarten.com.tr address.