SPECIAL CATEGORIES OF PROCESSING OF PERSONAL DATA

HOME PAGE

ARTICLE 1- PURPOSE

Special quality personal data processing policy has been prepared in order to determine the procedures and principles regarding the processing, storage and transfer of special quality personal data processed by Art&Smile Dental Clinic “Company”.

ARTICLE 2- SCOPE AND BASIS

Special categories of personal data processed by the data controller are within the scope of this policy.

This policy text has been prepared by taking into account the principles determined in the decision of the Personal Data Protection Board dated 31/01/2018 and numbered 2018/10 on “Adequate Precautions to be Taken by Data Controllers in the Processing of Special Quality Personal Data”.

ARTICLE 3- DEFINITIONS

Worker

Company staff

Electronic environment

Environments where personal data can be created, read, changed and written with electronic devices

Elektronik olmayan ortam

All written, printed, visual etc. other than electronic media. other environments

İlgili kişi

Natural person whose personal data is processed

Kanun

Law No. 6698 on the Protection of Personal Data

Kişisel veri

Any information relating to an identified or identifiable natural person

Personal data processing inventory

Personal data processing activities carried out by data controllers depending on their business processes; The inventory they have created by associating the personal data with the processing purposes and legal reason, the data category, the transferred recipient group and the data subject group, explaining the maximum storage period required for the purposes for which the personal data is processed, the personal data planned to be transferred to foreign countries and the measures taken regarding data security.

Processing of personal data

Obtaining, recording, storing, storing, changing, rearranging, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data by fully or partially automatic or non-automatic means provided that it is a part of any data recording system Any operation performed on data such as

Board

Personal Data Protection Board

Special categories of personal data

Data about race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, clothing, association, foundation or union membership, health, sexual life, criminal conviction and security measures, and biometric and genetic data of individuals

Policy

Special Categories of Personal Data Security Policy

Company

Artnsmile Oral and Dental Health Polyclinic Limited Company

Product and service buyer

Patient

Data controller

The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system

ARTICLE 4- PROCESSED SPECIAL QUALIFIED PERSONAL DATA

The following are special categories of personal data processed within the company. While it is always possible to process other sensitive personal data in addition to these data, the policy text will be updated as the number of sensitive personal data processed increases:

  • Health information
  • Sexual life
  • Data on criminal convictions and security measures
  • Philosophical belief and religious beliefs

ARTICLE 5- RESPONSIBILITIES AND DUTIES

All employees and units of the company; It provides full and active support to the responsible units for the legal acquisition, processing and storage of sensitive personal data. All employees and units support the responsible units in the implementation of the administrative and technical measures taken within the scope of the policy, in the training of the unit employees, in raising, increasing and monitoring the awareness of the employees, in the prevention of unlawful access to personal data and in the preservation of personal data in accordance with the law.

ARTICLE 6- RULES FOR EMPLOYEES IN PROCESSING SPECIAL QUALITY PERSONAL DATA

Employees; They are obliged to comply with the provisions of the confidentiality undertaking they have signed and the rules that they must comply with under the Law, even if they are not included in this undertaking.

Access to special quality personal data is only possible through printed documents and in the archive section. Special quality personal data available in the computer environment can only be possible by defining a user session and password specific to the employee. This identification can only be made by the company official.

In the event that the employee leaves the job, he/she must return all the sensitive personal data information that he/she can access in printed form or that is under his/her control to the data controller. In addition, the authorizations granted to the employee in the computer environment are immediately revoked.

ARTICLE 7- SPECIAL QUALITY PERSONAL DATA STORED IN ELECTRONIC ENVIRONMENT

While the sensitive personal data processed by the data controller is kept in printed media as much as possible, it is also possible to keep it in electronic environment as a result of technical necessities and work. In this case, the measures taken by the data controller are as follows:

  • Access to computers is possible with password entry
  • Continuous updating of applications in computers and other electronic media
  • Using anti-virus programs on computers

ARTICLE 8- SPECIAL QUALITY PERSONAL DATA STORED IN PHYSICAL ENVIRONMENT

The measures taken for sensitive personal data stored in the physical environment are as follows:

  • Keeping the personal data archive in administrative units away from general use
  • Keeping personal data, including sensitive data, in a locked cabinet and keeping the key only to the authorized personnel of the company
  • Use of security cameras for theft prevention and deterrence

ARTICLE 9- TRANSFER OF SPECIAL QUALITY PERSONAL DATA

The following rules are complied with in the transfer of special categories of personal data:

  • Encrypting transfer of special quality personal data that needs to be transferred via media such as Portable Memory, CD, DVD
  • If it is necessary to transfer the data via paper media, taking the necessary precautions against the risks such as theft, loss or viewing of the documents by unauthorized persons and sending the documents in the form of “confidential documents”

ARTICLE 10- PUBLISHING, STORING AND UPDATING THE POLICY

The policy is published with a wet signature (printed paper) and the printed copy is kept within the company. The policy is reviewed as needed and the necessary sections are updated.

ARTICLE 11- EFFECTIVENESS

The policy is deemed to have entered into force after it is signed by the authorized person of the company.

../../2022

Artnsmile Oral and Dental Health Polyclinic Limited Company