Legal
PDPL Information Security Policy
APV Hemisan’s corporate policy on personal data protection, information security and Authorised Economic Operator compliance requirements.
Definitions
- Explicit Consent
- Consent relating to a specific subject, based on information and declared with free will.
- Personal Data Subject
- The natural person whose personal data is processed.
- Personal Data
- Any information relating to a natural person that makes their identity determined or determinable.
- Special Categories of Personal Data
- Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, together with biometric and genetic data.
- Processing of Personal Data
- Any operation performed on personal data, such as obtaining, recording, storing, retaining, altering, reorganising, disclosing, transferring, taking over, making retrievable, classifying or preventing the use of such data, by wholly or partly automated means, or by non-automated means provided that it forms part of a data filing system.
- Data Processor
- The natural or legal person who processes personal data on behalf of the data controller upon its authorisation (e.g. a cloud computing provider).
- Data Controller
- The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.
- Information Security
- The physical, technical and administrative measures taken to protect the confidentiality, integrity and availability of information.
- Authorised Economic Operator Status (YYS)
- The status that allows companies meeting the criteria set by the Ministry of Trade to benefit from certain facilitations in foreign trade operations.
Scope
This Policy covers the following matters within the fields of activity of HEMİSAN GIDA VE MAKİNA DEMİR ÇELİK SANAYİ TİCARET ANONİM ŞİRKETİ:
- Protection of Personal Data
- Processes relating to the processing, retention, sharing and security of personal data.
- Information Security
- Securing the Company’s information assets (digital and physical), authorising access, and the measures taken against information leakage and breaches.
- AEO Compliance Requirements
- Information systems relating to customs and foreign trade processes, and the security of those systems.
The elements covered by the Policy:
- Information Systems
- All digital infrastructure, software, databases and their subsystems.
- Physical Areas
- Working environments, archives and other physical areas controlled by data security measures.
- Legal Relationships
- The Company’s employees, consultants, support service providers, visitors and the third parties with which it has commercial relations.
Implementation of the Policy and Responsibilities
Personal data processing principles:
- Processing in compliance with the law and the rules of good faith.
- Keeping data accurate and, where necessary, up to date.
- Processing for specified, explicit and legitimate purposes.
- Being connected with, limited to and proportionate to the purpose of processing.
- Retaining data in accordance with statutory retention periods.
Information security measures:
- Regulating system access and applying encryption methods.
- Physical access controls and data backup procedures.
- Monitoring and reporting mechanisms for security breaches.
AEO-compliant processes:
- Monitoring and recording the operations of authorised personnel.
- Information security practices integrated with customs processes.
- System management in compliance with Ministry of Trade requirements.
Explicit Consent Processes
Where a personal data processing activity does not rely on one of the processing conditions set out in the Law, explicit consent is obtained from the data subject. Explicit consent is obtained by the following means:
- written explicit consent forms;
- approval via an electronic form or digital platform;
- the inclusion of explicit consent elements within contracts.
In data processing based on explicit consent, the relevant units fulfil the following obligations:
- maintaining and keeping up to date a list of the persons whose explicit consent has been obtained;
- securely retaining explicit consent forms or the relevant means of proof;
- providing access to information regarding explicit consent where the data subject so requests;
- for repeated or continuous processing activities, explicit consent may be obtained once, but its validity is reviewed throughout the process.
Notifications Made
APV HEMİSAN keeps confidential the categories of personal data it processes in its capacity as data controller. The notification process is conducted in accordance with the following principles:
- Personal and company data is retained and kept up to date.
- Where legislation or business processes change, the current process is stored and coded as a revision so that versions are not confused.
Breaches of the Policy: APV HEMİSAN applies its disciplinary procedure to employees who act contrary to the Policy and, where the breach constitutes a criminal offence, reports the matter to the competent authorities.
Data Sharing with Third Parties and Confidentiality Obligation
All solution partners, subcontractors and other third parties wishing to access the personal data processed by APV HEMİSAN must:
- read and understand the Policy;
- act in compliance with the Policy;
- accept APV HEMİSAN’s audit rights;
- maintain confidentiality standards at least at the level set out in the Policy.
No third party may access personal data without signing a written confidentiality agreement or being authorised by APV HEMİSAN.
The Principles We Apply When Processing Personal Data
APV HEMİSAN acts in accordance with the principles set out in Article 4 of Personal Data Protection Law No. 6698 (the “Law”) when processing personal data. In addition, the decisions of the Personal Data Protection Board are followed regularly and company procedures are aligned with those principles. Accordingly, APV HEMİSAN processes personal data in line with the following principles:
- Compliance with the law and the rules of good faith
- Personal data is processed in accordance with legislation and the general principles of law. Where the reason for processing ceases to exist, processing activities are stopped immediately and the data subject is informed through updated information notices.
- Being accurate and, where necessary, up to date
- Communication channels are kept open so that personal data remains accurate and up to date. Data subjects are given the means to easily exercise their rights to update, correct and erase data through the application form.
- Processing for specified, explicit and legitimate purposes
- The purpose of every personal data processing activity is determined in advance and notified to data subjects through the information notice. No processing is carried out beyond that purpose.
- Processing that is connected with, limited to and proportionate to the purpose
- Personal data is processed solely for the stated purposes and data unrelated to those purposes is not processed. The principles of limitation and proportionality are observed during processing activities.
- Retention for the necessary period
- Personal data is erased, destroyed or anonymised when the purpose of processing ends or the statutory retention period expires. Where changes are required, processes and notices are updated.
Conditions for Processing Personal Data
APV HEMİSAN processes personal data solely on the legal grounds set out in Articles 5 and 6 of the Law. The legal basis for processing activities is clearly notified to data subjects through the information notice. The legal grounds for personal data processing activities are as follows:
- the explicit consent of the personal data subject;
- express provision in the law;
- necessity for the protection of the life or physical integrity of the data subject or of another person, where consent cannot physically be obtained;
- direct relation to the conclusion or performance of a contract;
- necessity for the data controller to fulfil a legal obligation;
- the data having been made public by the data subject themselves;
- necessity of processing for the establishment, exercise or protection of a right;
- necessity of processing for the legitimate interests of the data controller, provided that this does not harm the fundamental rights and freedoms of the data subject.
Processing of special categories of personal data: because the unlawful processing of special categories of personal data may give rise to a risk of victimisation or discrimination, such data is kept under special protection within the framework of Article 6 of the Law. APV HEMİSAN processes special categories of personal data only in the following cases:
- Special category data other than health and sexual life is processed with the explicit consent of the data subject or where expressly provided for in the law.
- Data relating to health and sexual life may be processed through the workplace physician as required by occupational health and safety legislation, or where explicit consent exists.
Special category data processing: employees’ criminal conviction and health data is processed only for the purposes stipulated in the relevant legislation. The health data of job candidates may be processed to determine suitability for the role.
Where processing is based on explicit consent, the data subject may withdraw that consent at any time. Once the withdrawal has been notified to APV HEMİSAN, processing activities are stopped and the statutory destruction procedures are applied.
Transfer of Personal Data
APV HEMİSAN acts in accordance with Personal Data Protection Law No. 6698 (the “Law”) and the principles set out in the relevant legislation when transferring personal data. In line with the conditions set out in Articles 8 and 9 of the Law, data transfers may be carried out without obtaining the explicit consent of data subjects where the relevant exceptions apply. Those exceptions are:
- express provision in the law;
- necessity for the protection of the life or physical integrity of a person who is unable to express consent due to actual impossibility, or whose consent is not legally valid, or of another person;
- necessity of processing, provided that it is directly related to the conclusion or performance of a contract;
- necessity for the data controller to fulfil a legal obligation;
- the data having been made public by the personal data subjects;
- necessity of processing for the establishment, exercise or protection of a right;
- necessity of processing for the legitimate interests of the data controller, provided that this does not harm the fundamental rights and freedoms of the data subject.
Transfer of data abroad: when personal data is transferred abroad, the following matters are observed in addition to the conditions above:
- Data may be transferred to countries declared by the Board to have adequate protection.
- Where adequate protection is not available, the data controllers in Türkiye and in the relevant foreign country must undertake adequate protection in writing and the permission of the Board must be obtained.
- Where no list of safe countries exists, transfers are made by obtaining the explicit consent of data subjects.
- Note: as the list of safe countries had not yet been published as at the date of this policy, transfers of data abroad are conducted within the framework of explicit consent procedures.
Groups to Which Data Is Transferred
- Legally authorised public institutions and organisations
- Data is transferred to public institutions such as the Social Security Institution, the Tax Office and the Ministry of Trade within the framework of legislative requirements. The necessary data is also shared in the course of audit activities.
- APV HEMİSAN business partners, consultants and suppliers
- For the purpose of fulfilling legal obligations, data is shared with third parties such as consultants (lawyers, financial advisers), cloud service providers, software providers, principal employers, customers, suppliers, banks and insurance companies.
- Shareholders
- APV HEMİSAN shareholders may access data within the company only within the framework of their legal rights.
PDPL undertaking: where regular data sharing is required without a legal basis, a PDPL undertaking is signed with the parties with which the data will be shared. That undertaking contains at least the following elements:
- the purpose of the data sharing;
- third-party recipients or types of recipient and their access rights;
- the categories of data to be shared;
- data processing principles;
- data security measures;
- the retention period of the shared data;
- procedures relating to the rights of the data subject (access, application, complaint);
- termination of the agreement and review of that process;
- liability and sanctions in the event of non-compliance with the agreement or individual breaches.
These procedures are applied meticulously in line with APV HEMİSAN’s aims of ensuring data security and strengthening legal compliance.
Procedure for Retaining and Destroying Personal Data
Under the Law on the Protection of Personal Data, the relevant secondary legislation and the Turkish Penal Code, personal data is erased, destroyed or anonymised where the reasons requiring its processing cease to exist or the maximum retention period stipulated in legislation expires. The procedures for retaining and destroying personal data are set out in detail, and all employees are held responsible for carrying out those procedures in cooperation with the Personal Data Protection Committee.
Data Security — Administrative and Technical Measures
APV Hemisan ensures data security within the scope of its information security management system by establishing corporate policies and procedures for the protection of personal data. All data actors, business partners and contracting parties are obliged to take at least these measures.
Access to data is limited to personnel who need it according to their job description. Such access is regulated taking into account the nature of the data (Personal Data, Special Categories of Personal Data).
Should unlawfully processed personal data be obtained by others, the members of the Personal Data Protection Committee will inform the Board and the relevant person as soon as possible.
The necessary security measures have been taken to secure personal data in physical environments (archives, cabinets and similar). In addition, periodic awareness training has begun to be provided to employees and confidentiality undertakings have been signed.
Data processing undertakings have been made with the third parties to which data is transferred. Access logs are kept in the Company’s information systems, and all event logs are collected so that data such as users, servers, network devices, IP addresses, applications and firewalls is monitored by security systems.
Network security, application security and intrusion detection and prevention systems are used to ensure data security, and data is backed up daily. Data security is further strengthened through the use of firewalls and advanced antivirus systems. Data classification, encryption and authorisation software is also used.
For special categories of personal data, a separate policy has been established in line with the decision issued by the Board on … , and that policy is taken into account in processing and transfer procedures. The security of personal data is ensured in accordance with APV Hemisan’s PDP Policy and its Policy on the Protection of Special Categories of Personal Data.
Data Categories and Processing Purposes
APV Hemisan classifies personal data systematically by processing purpose, legal ground and category, and the data categories processed in the relevant processes, together with their processing purposes, are determined in accordance with the PDP Law. The data categories below are matched with their processing purposes.
- Identity data
- Processing purpose: conducting employee recruitment processes, identity verification, fulfilling legislative obligations, organising training activities and similar.
- Contact data
- Processing purpose: conducting communication activities, emergency management, and fulfilling employment contract and legislative obligations.
- Financial data
- Processing purpose: financial transactions, organising accounting and finance operations, and following up payment processes.
- Professional experience data
- Processing purpose: conducting the application processes of job candidates, and planning employment contract and training activities.
- Health data
- Processing purpose: collecting information on the health status of employees and conducting occupational health and safety activities.
- Physical premises security data
- Processing purpose: ensuring the physical security of the Company, entry and exit control, camera recordings and similar.
Rights of the Data Subject
Under Article 11 of the PDP Law, data subjects have the following rights:
- to learn whether their personal data is processed;
- to request information if it has been processed;
- to learn the purpose of processing and whether the data is used in accordance with that purpose;
- to learn the third parties to whom their personal data is transferred;
- to request the correction or erasure of their personal data;
- to object to decisions taken through automated systems in relation to the processing of their personal data;
- to claim compensation for damage suffered as a result of the unlawful processing of their personal data.
Data Subject Application Procedure
The data subject may submit the application form in writing, wet-signed, to the Company’s registered commercial address, or send it to hemisan@apvhemisan.com with a secure electronic signature or mobile signature. The Company will conclude the application as soon as possible depending on the nature of the request and will provide information in accordance with the relevant provisions of the PDP Law. The secure submission of data subjects’ requests concerning their personal data and the timely provision of responses are monitored meticulously as part of data security processes.
Breach Notifications
A “Data Protection Breach” is the accidental or unlawful destruction, loss or alteration of personal data, its unauthorised disclosure, or unauthorised access to personal data transmitted, stored or processed. Where such a breach occurs, the APV Hemisan Information Security Management Procedure is activated. The procedure is made available on a shared server accessible to employees in order to ensure the effectiveness of internal security and information processes. The breach notification is submitted immediately to the Personal Data Protection Board and the relevant person or persons are contacted as soon as possible.
Keeping the Policy Up to Date
Document ownership and approval: the owner of this policy is the Quality Management unit, which is responsible for reviewing it regularly in accordance with the review requirements set out above. The current version of the policy is made available to all personnel on the APV Hemisan intranet and is also published on the Company’s official website.
The most recent update of the policy was made and published in March 2023 with the approval of the General Manager. The aim of that update was to align the Company’s data security and personal data protection processes with best practice.
The original of this text is in Turkish. The English version is a translation provided for information purposes; in the event of any discrepancy, the Turkish text prevails.
