Data Subject Application Policy

KALESERAMİK ÇANAKKALE KALEBODUR SERAMİK SAN. A.Ş. DATA SUBJECT APPLICATION POLICY

Contents

  1. PURPOSE AND SCOPE
  2. DEFINITIONS
  3. RESPONSIBLE UNITS AND ALLOCATION OF DUTIES
  4. VALIDITY REQUIREMENTS FOR DATA SUBJECT APPLICATIONS
    • 4.1. Persons Entitled to Apply
    • 4.2. Application Procedure
  5. INFORMATION REQUIRED IN AN APPLICATION
  6. RECEIPT OF APPLICATIONS
  7. APPLICATION REVIEW PERIOD
  8. CONCLUDING APPLICATIONS
  9. FEES
  10. ENTRY INTO FORCE AND AMENDMENTS

1. PURPOSE AND SCOPE

This Data Subject (Data Owner) Application Policy ("Policy") has been prepared by KALESERAMİK ÇANAKKALE KALEBODUR SERAMİK SAN. A.Ş. (hereinafter the "Company"), acting as data controller, to set out the responsible units and their duties in relation to data subject applications, together with the procedures to be followed, under Personal Data Protection Law No. 6698 and the "Communiqué on the Procedures and Principles of Applications to the Data Controller".

2. DEFINITIONS

TermDefinition
"Data Subject", "Data Owner"Natural persons whose personal data is processed by the Company or persons/institutions authorised on its behalf.
"Contact Person"The natural person notified by the Company upon registration in the Data Controllers Registry for communication with the Personal Data Protection Authority regarding the Company's obligations under Personal Data Protection Law No. 6698 and secondary regulations issued under that Law.
"Personal Data"Any information relating to an identified or identifiable natural person.
"Processing of Personal Data"Any operation performed on personal data, wholly or partly by automated means or, provided it forms part of a data filing system, by non-automated means, including obtaining, recording, storing, retaining, altering, rearranging, disclosing, transferring, taking over, making available, classifying or preventing its use.
"Personal Data Processing Inventory"The inventory created by data controllers by linking the personal data processing activities carried out in their business processes to the purposes of processing, data categories, recipient groups and data subject groups. It details the maximum retention period necessary for the purposes of processing, the personal data intended to be transferred abroad and the measures taken to ensure data security.
"Board"Personal Data Protection Board
"Authority"Personal Data Protection Authority
"Law", "Personal Data Protection Law"Personal Data Protection Law No. 6698
"Policy"Personal Data Retention and Disposal Policy
"Responsible Unit"The unit established to ensure full compliance with the Personal Data Protection Law and other relevant legislation, administrative decisions, court decisions, and the policies and other workplace regulations adopted by the Company regarding personal data protection, and responsible for achieving these objectives within the Company.
"Company"KALESERAMİK ÇANAKKALE KALEBODUR SERAMİK SAN. A.Ş.
"Data Controller"A natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.
"Communiqué"The Communiqué on the Procedures and Principles of Applications to the Data Controller

3. RESPONSIBLE UNITS AND ALLOCATION OF DUTIES

The Company's units responsible for data subject application processes and their duties are set out below:

TitleUnitDuties
Chair and Members of the Personal Data Protection CommitteePersonal Data Protection CommitteeResponsible for preparing, developing, implementing, publishing in the relevant media, and updating the Policy.
Personal Data Protection ManagerPersonal Data Protection CommitteeResponsible for accepting the application, checking its validity and verifying the applicant's identity; reviewing its content, conducting the research needed for assessment and gathering findings; and legally reviewing the application and finalising the response.
Contact PersonPersonal Data Protection CommitteeResponsible for communication with the data subject following the application, referring the application to the relevant unit(s), and sending the prepared response.

4. VALIDITY REQUIREMENTS FOR DATA SUBJECT APPLICATIONS

4.1. Persons Entitled to Apply

All natural persons have the right to apply to the Company regarding the requests listed in Article 11 of the Law, provided that their applications are made in Turkish.

4.2. Application Procedure

Data subjects (data owners) must apply in Turkish using one of the methods below. The Company is not obliged to assess applications made by other methods, such as verbally.

  • In writing.
  • By using a registered electronic mail (KEP) address, secure electronic signature, mobile signature, or an email address previously provided by the data subject to the Company and registered in the Company's system.
  • Through software or an application developed for this purpose.

5. INFORMATION REQUIRED IN AN APPLICATION

The data subject must provide all the following information in their application.

  • Name, surname and, for written applications, signature.
  • Turkish Republic identity number for Turkish citizens; nationality, passport number or identity number, if any, for foreign nationals.
  • Residential or business address for service of notices.
  • Email address, telephone and fax number for notification, if available.
  • The subject of the request and any other relevant information and documents, to be attached to the application.

6. RECEIPT OF APPLICATIONS

Applications meeting the validity requirements above are received by the Contact Person appointed by the Company. If an application is delivered to another employee or a third party, that employee/third party must forward it to the Contact Person without delay.

If a person or unit has been assigned responsibility for personal data protection within the Company, the application is referred directly to that person/unit, who carries out the other necessary steps in the process.

If the application is unclear, the Company may request additional information from the data subject on the following matters:

Your Relationship with the Company:

☐ Visitor

☐ Business Partner

☐ Employee

☐ Other___________

☐ Job Applicant

☐ Customer/Customer Employee

☐ Supplier/Supplier Employee

Has Your Relationship with the Company Ended?:

After establishing the data subject's relationship with the Company, the Contact Person identifies the relevant department from the Personal Data Processing Inventory and forwards the application to it.

Example: If the applicant is a job applicant, the data subject categories in the Personal Data Processing Inventory are consulted to establish that job applicant data is processed by the Human Resources department, and the application is forwarded to Human Resources.

7. APPLICATION REVIEW PERIOD

Data subject applications are concluded as soon as possible, depending on the nature of the request, and no later than 30 (thirty) days. This period is calculated:

  • For written applications, from the date the document is served on the Company as data controller.
  • For applications made by other methods, from the date the application reaches the Company as data controller.

8. CONCLUDING APPLICATIONS

The Company assesses data subject applications effectively, lawfully and in accordance with the rules of good faith, and either accepts the application or rejects it with an explanation of the reasons.

The Company communicates its response to the data subject in writing or electronically. The response must contain the following:

  • Details of the data controller or its representative.
  • The applicant's name and surname; Turkish Republic identity number for Turkish citizens; nationality, passport number or identity number, if any, for foreign nationals; residential or business address for service of notices; and email address, telephone and fax number for notification, if available.
  • The subject of the request.
  • The Company's explanations regarding the application.

If the data subject's request is accepted, the Company fulfils it as soon as possible and informs the data subject.

9. FEES

As a rule, the Company concludes data subject (data owner) applications free of charge. However, if a written response is provided, no fee is charged for up to 10 pages; a processing fee of 1 (one) Turkish Lira may be charged for each page exceeding 10 (ten) pages. If the response is supplied on a recording medium such as a CD or flash drive, any fee charged by the Company may not exceed the cost of that medium.

If the application arises from an error by the Company, the fee charged is refunded to the applicant.

10. ENTRY INTO FORCE AND AMENDMENTS

This Policy is published on the Company's website and enters into force on its publication date. The Company may amend this Policy at any time. Such amendments take effect from the date the new Policy is published.


This message/document is classified as CONFIDENTIAL.

Compare

Compare
Compare