Personal Data Protection Policy
- Policy, Scope and Purpose
- The Board of Directors and management of Cesur Ambalaj ("Company") are committed to comply with the principles and rules introduced by the Constitution of the Republic of Turkey, the General Data Protection Regulation No. 6698 (GDPR) and other legislation regarding the protection of personal data and to protect the rights and freedoms of individuals whose data are processed by the Company. To this end, the Board of Directors has adopted a written personal data protection policy and system to be implemented and developed.
- Scope
The provisions of the Policy cover all information systems and sub-information, contracts, environmental and physical areas, and the systems and regulations produced for all these, which are involved in the processing of personal data in the Company's fields of activity and fields of activity.
This policy covers the Company's units, support company personnel, visitors, third parties, interns and contracted personnel.
- Purposes of the General Data Protection Regulation and System
The purpose of the General Data Protection Regulation and System is to ensure that the Company establishes and realizes its own standards in the management of personal data; to determine and support organizational goals and obligations, to establish control mechanisms in accordance with the acceptable risk level; to fulfill its obligations in accordance with international conventions, the Constitution, laws, contracts and professional rules in the field of personal data protection and to protect the interests of individuals in the best way.
- The Company will comply with personal data protection legislation and data protection principles. The data protection principles adopted by the Company include the following:
- Process personal data only if it is clearly necessary for legitimate corporate purposes;
- To process the minimum amount of personal data necessary for these purposes and not to process more data than necessary;
- Providing individuals with clear information about how and by whom their personal data is used;
- Process only relevant and appropriate personal data;
- To process personal data in accordance with equity and law;
- Keeping an inventory of the categories of personal data processed by the Company;
- Keeping personal data accurate and updated when necessary;
- To store personal data only for as long as required by legal regulations and the Company's legal obligations or legitimate corporate interests;
- Respect the rights of individuals in relation to their personal data, including the right of access;
- Keeping all personal data secure;
- To apply the exceptions permitted under the legislation;
- Establish and implement a personal data protection system for the implementation of the Policy;
- When necessary, to determine the internal and external stakeholders who are parties to the personal data protection system and the extent to which they are involved in the Company's personal data protection system;
- Identify the personnel/s with special authorizations and responsibilities related to the personal data protection system.
Declarations
- The Company informs the General Data Protection Board ("GDP Board") that it is the data controller and which categories of personal data it processes in this capacity, and determines all categories of personal data it processes in the personal data inventory.
- The notification shall be made in accordance with the procedure and method to be determined by the GDP Board and a copy of the notification shall be kept by the General Data Protection Committee (GDP Committee) .
- Notifications are periodically repeated and updated if deemed necessary by the relevant legislation or the GDP Board.
- The GDP Committee reviews the Company's data processing activities and changes in them annually in order to identify potential changes that may occur in the notification made to the GDP Board and informs the GDP Board if necessary.
The Company's disciplinary legislation will be applied to any actions of all units of the Company, support company personnel, interns and contracted personnel that violate this policy, and if the violation in question constitutes a crime or misdemeanor, the situation will be reported to the relevant authorities as soon as possible.
The Company's solution partners and all third parties working with the Company who have access or potential access to personal data are invited to read and comply with this policy. No third party may gain access to personal data processed by the Company without a written confidentiality agreement that includes obligations with standards at least as strong as the Company on the protection of personal data and the Company's right to audit them.
- Definitions
Explicit consent: Consent on a specific subject, based on information and expressed with free will,
Anonymization: Making personal data impossible to be associated with an identified or identifiable natural person under any circumstances, even by matching with other data,
Relevant person: The person whose personal data is processed
Personal data: Any information relating to an identified or identifiable person,
Sensitive personal data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership to associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data,
Processing of personal data: All kinds of operations performed on personal data such as obtaining, recording, storing, retaining, modifying, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data by fully or partially automatic means or by non-automatic means provided that it is part of any data recording system,
GDPR Law No. 6698 on the Protection of Personal Data,
GPDR Board Personal Data Protection Board,
GPDR Authority: Personal Data Protection Authority,
Data processor: A natural or legal person who processes personal data on behalf of the data controller based on the authorization granted by the data controller,
Data recording system: The recording system in which personal data are structured and processed according to certain criteria,
Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system
- Duties and Responsibilities
- The Company is the data controller in accordance with KVKK.
- All personnel, especially those in senior management, executive and auditor positions, are responsible for developing and promoting the right practices in the processing of personal data within the Company, as well as other obligations related to this issue included in their individual job descriptions.
- The GDP Committee has been established as the unit in charge of managing the personal data protection system and ensuring and documenting compliance with the GDP Law and other relevant legislation and is responsible to the Board of Directors in these matters.
- GPD Committee
The members of the GDP Committee are appointed by the Board of Directors, taking into account their expertise and experience in personal data protection legislation and practices, and report directly to the Board of Directors.
The GDP Committee consists of the Information Security Unit, Human Resources Unit and other unit employees assigned in this field.
The meetings are also attended by the legal advisor who provides consultancy to the Company in the field of GPDR.
The Committee meets at least once every 3 (three) months to discuss risks and make assignments.
The e-mail address of the Company GPDR Committee is 'kvkk@cesur.com.tr'.
- Duties and Responsibilities of the GDP Committee
- The Committee should inform the Board of Directors on Personal Data Protection legislation and developments.
- The Committee is responsible for ensuring that the Company's policies and procedures are up to date and that data processing audits are carried out in accordance with the planned schedule and that they comply with the relevant legislation.
- The Committee acts together with all relevant personnel on personal data protection issues.
- The main duties and responsibilities of the Committee are as follows:
- Providing information and advice to relevant partners and support service providers on personal data protection legislation and compliance issues.
- Providing information and advice to its personnel on their obligations under personal data protection legislation.
- Monitor compliance of data processing activities with personal data protection legislation.
- Contribute to the development and maintenance of a personal data protection policy and related procedures and processes.
- To assign responsibilities within the Company in the context of compliance with personal data protection legislation.
- To ensure that all personnel involved in personal data processing processes are provided with the necessary training and awareness.
- To observe compliance with the Personal Data Protection legislation by conducting regular audits and reporting to the Board of Directors.
- To act in cooperation and liaison with the PDP Board.
- To determine the responsible persons who will function as the contact point and representative of the Company before the PDP Board.
- Develop a formal procedure for reporting personal data breach incidents and investigations to the Board.
- Providing information and advice on the retention of corporate records.
- To ensure the extent to which personal data is collected, kept and used within the Company and the conditions of their storage in accordance with the relevant legislation.
- To carry out oversight and assessments regarding compliance, reasonableness, security practices and other controls that may be necessary for the protection of personal data.
- Identify and implement controls to ensure the confidentiality, integrity and accessibility of personal data, and recommend additional controls that may be necessary.
- To present the issues that pose potential risks in terms of personal data within the Company and the related suggestions to the agenda of the Board of Directors.
- The PDP Committee is authorized to audit the Company in all systems related to the collection, processing and storage of personal data. While fulfilling its duties, the PDP Committee may request cooperation from all personnel, including access to systems and records. If this cooperation is not provided, the Committee reports the situation to the Board of Directors.
- All personnel of the Company who process personal data are responsible for acting in accordance with the Personal Data Protection legislation.
- The Human Resources unit is responsible for the realization of the necessary notifications and trainings so that all personnel are aware of their responsibilities in the field of personal data protection and have the necessary awareness.
- Company personnel are obliged to ensure the accuracy and currency of all personal data provided to the Company by or relating to them.
- Data Protection Principles
All personal data processing activities must be carried out in accordance with the following data protection principles. The Company's policies and procedures aim to ensure compliance with these principles:
- Compliance with the law and good faith.
- Being accurate and up to date when necessary.
- Processing for specific, explicit and legitimate purposes.
- Being relevant, limited and proportionate to the purpose for which they are processed.
- Retention for the period stipulated in the relevant legislation or required for the purpose for which they are processed.
- Personal data is processed in accordance with the law and good faith and in a transparent manner.
In this direction, the Company includes disclosure text/privacy notices in data collection channels and related areas regarding the personal data processing activities it performs. The PDP Committee determines the areas where these notifications, which contain clear and understandable information about which data about whom and for what purposes are processed by the Company, will take place and be announced. The following issues are included in these notifications:
- Identity and contact information of the Company as the data controller,
- KVK Committee and contact information,
- Types of personal data processed,
- Purposes of processing personal data,
- The envisaged retention period of the personal data,
- Rights of the data subject,
- Third parties with whom the data may be shared.
- Personal data may only be processed for specific, explicit and legitimate purposes.
- In the personal data inventory, the reasons/purposes for processing personal data are determined and personal data cannot be used for purposes other than the stated purpose without any other legal justification or the explicit consent of the data subject.
- In the event that conditions arise that require the use of personal data for purposes other than those specified in the personal data inventory, this situation is notified to the Liaison Officer / KVK Committee by the relevant personnel / unit. The PDP Committee checks the suitability of the new purpose and, if necessary, ensures that the data subject is informed about the new purpose and the new data processing activity.
- Personal data must be appropriate and relevant and processed to a limited extent for the purpose.
- The PDP Committee is responsible for ensuring that personal data that is not clearly necessary for the purpose of processing is neither collected nor processed.
- All electronic and physical data collection forms and the data collection mechanisms in information systems are used only after approval by the PDP Committee.
- The PDP Committee periodically checks, through the personal data inventory, that the data processed is appropriate and relevant.
- The PDP Committee checks annually that all data processing methods are appropriate and relevant.
- The PDP Committee is responsible for stopping the processing of personal data it finds to be inappropriate, irrelevant or excessive for the purpose of processing, and for securely destroying the processed data in accordance with the retention and destruction procedure.
- Personal data must be accurate and up to date.
- The accuracy and currency of data kept for a long time must be reviewed.
- The manager of the Human Resources unit is responsible for training all personnel on collecting and keeping personal data accurately and up to date.
- Personnel are responsible for the accuracy and currency of the data kept about them. Managers will inform employees about this.
- Personnel, customers and other relevant persons must inform the Company so that the personal data processed about them can be updated.
When such a notification is made, the relevant unit is responsible for correcting and updating the record. A unit manager who does not make the update will be held responsible under the Disciplinary Procedure.
- Based on its review of the type, retention period and volume of the data processed in the data inventory, the PDP Committee may instruct the relevant unit to review the accuracy or currency of certain data.
- Personal data may only be processed if necessary for the purpose of processing.
- If personal data is kept beyond the necessary period for reasons such as back-ups, it must be encrypted or anonymised/masked to protect the rights and freedoms of individuals in the event of a data security breach.
- Processing personal data after the periods set in the retention and destruction tables and procedures requires the written approval of the PDP Committee.
- Rights of Data Subjects
Data subjects have the following rights regarding the data processing activities and records about them at the Company:
- To learn whether their personal data is processed,
- To request information if their personal data has been processed,
- To learn the purpose of processing their personal data and whether it is used in line with that purpose,
- To know the third parties in Turkey or abroad to whom their personal data is transferred,
- To request the correction of personal data that is incomplete or processed incorrectly,
- To request the deletion or destruction of personal data for which there is no lawful reason or basis for processing under the KVKK or this policy,
- To request that corrections or deletions made at their request be notified to third parties to whom the personal data was transferred,
- To object to a result against them arising from the analysis of the processed data exclusively through automated systems,
- To claim compensation for damages if they suffer loss due to unlawful processing of personal data.
Data subjects may request access to their personal data and exercise the rights listed above. These requests are forwarded to the Liaison Officer/PDP Committee, and the Committee responds within 30 days. The processes for receiving, forwarding and concluding requests are carried out in accordance with the request management procedure.
Data subjects may submit their requests by filling in the KVKK Application Form and sending it, with identity verification, by notary or registered mail with return receipt to Cumhuriyet Mah. Yüzyıl Cad. No:64 34876 Kartal Istanbul Türkiye, or via cesur.tr or to kvkk@cesur.com.tr.
All Company personnel, whatever their job description, must direct data subjects to the correct application method for access requests addressed to them. Company personnel must be informed and trained on how to act on requests from data subjects.
- Obtaining Explicit Consent
The Company accepts as explicit consent a consent that relates to specific data processing activities, is based on information, is given with free will, expresses the data subject's wish regarding the processing of their data, and is declared in writing, orally or by a clear affirmative act. For sensitive data, explicit consent is always obtained in writing. The data subject may withdraw explicit consent at any time.
Explicit consent may be obtained by having the data subject sign the explicit consent form template, or by including the elements of this template in a contract with the data subject or in an electronic form. For personal data routinely processed about personnel, candidates and customers, explicit consent is obtained through the relevant contracts or forms.
Where a data processing activity based on explicit consent is continuous or repeated, the relevant unit keeps a single list of the persons whose explicit consent has been obtained. The relevant unit is responsible for keeping this list current and accurate. Explicit consent forms or other evidence relating to processing based on explicit consent are kept by the relevant unit.
- Data Security
All personnel are responsible for keeping secure the personal data processed by the Company that is under their responsibility.
Only those who need access to personal data should have access to it.
The security of personal data is ensured in accordance with the PDP Policy and related documents.
Information security incidents involving personal data are reported by the PDP Committee to the PDP Board and the data subject as soon as possible.
- Data Sharing
- Personal data may be shared with third parties only lawfully and fairly. Accordingly, one of the following conditions must be met for personal data to be shared:
- The explicit consent of the data subject has been obtained.
- It is expressly provided for by law.
- It is necessary to protect the life or physical integrity of the person, or of another person, who is unable to give consent due to actual impossibility or whose consent is not legally valid.
- Processing the personal data of the parties to a contract is necessary, provided that it is directly related to the conclusion or performance of that contract.
- It is necessary to fulfil a legal obligation.
- The data has been made public by the data subject.
- Data processing is necessary for the establishment, exercise or protection of the Company's rights.
- Data processing is necessary for the Company's legitimate interests, provided that it does not harm the fundamental rights and freedoms of the data subject.
- Personal data may be transferred abroad only if the above conditions are met, adequate protection exists in the destination country and the data subject has given explicit consent to the transfer. As of the publication date of the Policy, no safe countries have been announced. Accordingly, unless the undertakings of the recipients are approved by the Board, the Company does not transfer data abroad without explicit consent.
- All personal data sharing transactions must be recorded in writing together with their reasons. The PDP Committee ensures that these records are audited periodically.
- Where there is a regular data sharing relationship without a legal basis or legal obligation, a KVKK Undertaking setting out the conditions of data sharing is signed with that party. At a minimum, the KVKK Undertaking includes:
- The purpose or purposes of the sharing;
- Potential third-party recipients or types of recipient and the conditions of access;
- The categories of data to be shared (kept to the minimum necessary for these purposes);
- General principles for processing the data;
- Data security measures;
- The retention period of the shared data;
- Procedures for data subject rights, access requests, applications and responding to complaints;
- Review of the termination of the sharing agreement; and
- Liability and sanctions for non-compliance with the agreement or individual breaches by personnel.
- Purposes of Processing, Data Subjects, Personal Data Categories and Recipient Categories in the Personal Data Processing Activities Carried Out by the Company
- Purposes of Processing Personal Data
The data processing purposes within the personal data processing activities carried out by the Company under the Data Controllers Registry Information System (VERBİS) are as follows:
- Conducting emergency management processes
- Conducting information security processes
- Conducting candidate / intern / student selection and placement processes
- Conducting application processes of job candidates
- Fulfilling obligations arising from employment contracts and legislation for employees
- Conducting training activities
- Conducting activities in compliance with legislation
- Conducting finance and accounting work
- Conducting company / product / service loyalty processes
- Ensuring the security of physical premises
- Conducting assignment processes
- Following up and conducting legal affairs
- Conducting communication activities
- Conducting / auditing business activities
- Planning human resources processes
- Conducting occupational health and safety activities
- Receiving and evaluating suggestions for improving business processes
- Conducting business continuity activities
- Conducting logistics activities
- Conducting goods / services procurement processes
- Conducting after-sales support services for goods / services
- Conducting goods / services sales processes
- Conducting goods / services production and operation processes
- Conducting customer relationship management processes
- Conducting customer satisfaction activities
- Conducting marketing activities
- Conducting storage and archive activities
- Conducting contract processes
- Ensuring the security of movable property and resources
- Conducting supply chain management processes
- Conducting marketing processes for products / services
- Conducting the remuneration policy
- Work and residence permit procedures for foreign personnel
- Creating and tracking visitor records
- Data Subjects
| DATA SUBJECT CATEGORY | DESCRIPTION |
| Job candidate | Natural persons who have applied for a job in any way or have made their CV and related information available for the Company's review. |
| Employee | Employees whose personal data is processed within activities carried out by the Company such as events, employee satisfaction, human resources, audit, information technology security and infrastructure, and legal compliance. |
| Shareholder | Natural persons who are shareholders of the Company |
| Intern | Interns whose personal data is processed within activities carried out by the Company such as events, employee satisfaction, human resources, audit, information technology security and infrastructure, and legal compliance. |
| Supplier employee | Employees of a party that provides services to the Company on a contractual basis in line with the Company's orders and instructions while the Company carries out its commercial activities. |
| Supplier representative | Authorised representatives of a party that provides services to the Company on a contractual basis in line with the Company's orders and instructions while the Company carries out its commercial activities. |
| Customer (person receiving products or services) | Natural persons whose personal data is obtained through business relationships within the operations of the Company's business units, whether or not they have a contractual relationship with the Company. |
| Potential buyer of products or services | Natural persons whose personal data is obtained through business relationships within the operations of the Company's business units without any contractual relationship with the Company. |
| Visitor | Natural persons who have entered the Company's physical premises for various purposes or who visit our websites |
| Other (third party) | Natural persons who are in some relationship with the Company but do not fall within the definitions above |
- Personal Data Categories
| PERSONAL DATA CATEGORY | DESCRIPTION |
| Identity information | Data containing information about a person's identity: name and surname, Turkish ID number, nationality, place of birth, date of birth, gender, workplace, registry number, tax number, title, biography and similar information, and documents such as a driving licence, professional ID, identity card and passport |
| Contact information | Telephone number, address, e-mail address, fax number and similar information |
| Transaction security information | Personal data processed to ensure our technical, administrative, legal and commercial security while carrying out our activities (for example log records, IP information, authentication information) |
| Customer transaction information | Information such as invoices, promissory notes, cheques, bank receipts, order information and request information |
| Personnel file information | Data such as an employee's payroll information, disciplinary investigations, employment entry and exit records, declarations of assets, CV information and performance evaluation reports |
| Legal transaction information | Personal data processed to determine and pursue our legal receivables and rights, to perform our debts, and to comply with our legal obligations and Company policies |
| Financial information | Personal data in information, documents and records showing any financial outcome created according to the type of legal relationship the Company has established with the data subject, and data such as bank account number, IBAN, income information and debt/receivable information |
| Physical premises security information | Personal data relating to records and documents taken when entering and while staying in physical premises: camera recordings, vehicle records, records taken at security points and similar |
| Professional experience | Information such as diplomas, courses attended, in-service training, certificates and transcripts |
| Visual and audio data | Photographs and camera recordings (except those covered by physical premises security information) and voice recordings |
| Health information | Information on disability, blood group, personal health information, devices and prostheses used, etc. |
| Criminal convictions and security measures | Information on criminal convictions and security measures |
- Recipient Categories
| RECIPIENT CATEGORY | DEFINITION | PURPOSE OF SHARING |
| Natural persons or private legal entities | Private law persons authorised under the relevant legislation to obtain information and documents from the Company | Limited to the purpose requested by the relevant private law persons within their legal authority |
| Public | All natural and legal persons | Limited to the purpose of public disclosure by the Company |
| Affiliates and subsidiaries | Companies in which the Company is a shareholder | Limited to ensuring the conduct of commercial activities that require the participation of the Company's affiliates |
| Suppliers | Parties that provide services to the Company on a contractual basis in line with the Company's orders and instructions within the conduct of its commercial activities | Limited to ensuring the provision to the Company of services it procures externally from the supplier and that are necessary to carry out its commercial activities |
| Shareholders | Natural persons who are shareholders of the Company | Limited to the powers of shareholders |
| Authorised public institutions and organisations | Public institutions and organisations authorised under the relevant legislation to obtain information and documents from the Company | Limited to the purpose requested by the relevant public institutions and organisations within their legal authority |
- Records Management
Personal data may not be kept longer than necessary for the purposes of processing. The classification of records containing personal data and their retention periods are determined in accordance with the Retention and Destruction Policy.
Personal data whose retention period for the purposes of processing has expired, or upon a justified request of the data subject, is anonymised so that the data subject cannot be identified, or is deleted or destroyed.
- Audit
- Keeping the Policy Up to Date
[…………….]
Document Ownership and Approval
The owner of this document is the PDP Committee, which is responsible for reviewing this policy regularly in line with the review requirements set out above.
The current version of this document is made available to all COMPANY personnel through the shared area and published on the company website.
This policy was approved by the Board of Directors on […………….] and published with the signature of the General Manager.
Signature: Date:
Revision History
| No. | Revision | Approval | Publication date |
| 1 | First publication | September 2021 | |
| 2 | Update |