Protection of Personal Data

PERSONAL DATA PROTECTION LAW NO. 6698 entered into force in 2016.

With the law, the procedures and principles of processing personal data are determined and bound to a legal basis.

The regulation on how the personal data of the data subject will be processed has given many rights to the relevant persons and accordingly, responsibilities have been imposed on the data controllers who process the personal data.

Data controller can simply be defined as any natural and legal person who processes personal data.

Who is the Data Controller? The data controller is the pharmacy where you buy medicine, your doctor, the market in the neighborhood, your school, that is, people or institutions that are touched in every aspect of life.

Data controllers should take the necessary administrative and technical measures to protect personal data and should not cause data loss.

Again, those who meet certain conditions must be registered with the DATA RESPONSIBLE REGISTRY INFORMATION SYSTEM (VERBIS). Due to the pandemic process, the deadlines for registration in the VERBIS system have been extended by the PERSONAL DATA PROTECTION INSTITUTION and the deadline has been determined as 31.12.2021 for the time being.

WHAT NEEDS TO BE DONE UNDER THE LAW ON PROTECTION OF PERSONAL DATA SHOULD BE CONSIDERED AS TWO STAGES.

1 STAGE:

COMPATIBILITY STUDIES:

In this process, the data controller should determine the work to be done within the scope of KVKK and take the necessary measures.

Professional support should be sought in this regard, as the process is a bit complicated and the procedures to be done are too many.

In order to carry out the compliance process, it is necessary to work with persons or institutions who have a good knowledge of this business both technically and administratively. Each of the administrative and technical measures to be taken should be reviewed one by one and all transactions should be carried out.

The mistake to be made at the end of the process will be a huge financial and criminal responsibility.

It is necessary to take the x-ray of the data controller, so to speak, and to determine the measures to be taken according to the result and to carry out the procedures.

At this stage, which we define as the 1st stage, necessary administrative and technical measures should be taken and the data controller should be brought into compliance with the KVKK.

From this moment on, the 2nd phase begins.

STAGE 2:

CONTINUING AND ENSURING CONTINUITY OF KVKK COMPLIANCE PROCESS:

It is very important to ensure the continuity of these measures taken after starting the KVKK compliance process and taking the necessary technical and administrative measures. Because the KVKK process is a living process.

In the event that the technical and administrative measures taken by the data controllers actually change, the previously prepared documents and the process must be updated.

For example, the employment contract has been harmonized with the KVKK, but if there is a change in the legislation later, the employment contract will need to be updated.

What will be done if a data processing committee was formed in the data retention and destruction policy, but then the people in the committee left the job?

How will the necessary applications be made in case of data loss in the enterprise?

How will the personal data stored within the required legal periods be destroyed at the end of the period and who will decide on them?

What will be done in the face of the application of the person concerned?

This second stage, which is overlooked and not explained to the data controllers, will result in detrimental consequences for the data controllers in the upcoming period.

Because, as we tried to explain above, data controllers who entrust the first stage with daily concerns to those who do not have knowledge and do it very cheaply will be alone and unsupported in the second stage.

It will become possible to be exposed to financial and penal sanctions.

Small or large, all businesses see these transactions as an additional burden and avoid their costs. Since there are no trained personnel in this field, the issue is referred to HR or an accountant. However, the HR or accounting staff will see this work as a chore besides their main job and will not be able to properly perform the KVKK process.

In order to avoid this troublesome process, data controllers need to work with serious solution partners who will stand by them in this process and stand behind their work.

Just as external support is obtained for accounting transactions, occupational safety and health transactions, professional support can be obtained from outside in order to initiate legal proceedings, take measures, perform transactions and ensure the continuity of the process within the scope of the personal data protection law.

Thus, it will be possible to bypass the KVKK compliance process without any problems and to maintain compliance.

Copyright © 2022 Masterfranchiseworld | Tüm Hakları Saklıdır. Powered by Bilgeweb