Retention and Disposal Policy for the Deletion, Destruction, and Anonymization of Personal Data
PURPOSE OF THE DISPOSAL POLICY
This Policy outlines the procedures for the deletion, destruction, or anonymization of personal data by Miss Diamond, either ex officio or upon request, in accordance with the Personal Data Protection Law when the conditions for processing personal data regulated in Articles 4, 5, and 6 of the Law cease to exist.
DEFINITIONS
- Explicit consent: Consent that is related to a specific subject, based on information and expressed with free will,
- Anonymization: Rendering personal data impossible to be associated with an identified or identifiable real person under any circumstances, even by matching them with other data,
- President: The President of the Personal Data Protection Authority,
- Relevant person (Data Subject): The real person whose personal data is processed,
- Personal data: Any information relating to an identified or identifiable real person,
- Processing of personal data: Any operation performed on data such as obtaining, recording, storing, retaining, altering, re-arranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of personal data by fully or partially automated means or by non-automated means provided that it forms part of any data filing system,
- Board: The Personal Data Protection Board,
- Authority: The Personal Data Protection Authority,
- Data processor: The real or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller,
- Data filing system: The recording system where personal data is structured and processed according to specific criteria,
- Regulation: The Regulation on the Data Controllers Registry,
- Data controller: The real or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data filing system.
RECORDING MEDIA WHERE PERSONAL DATA IS STORED
Personal data belonging to data subjects is securely stored by Miss Diamond in the following environments in accordance with the provisions of the KVKK Law and relevant legislation:
Electronic environments:
- CRM
- ENTİ
- Email Inbox
- Microsoft Office Programs
- Image and Audio Recording Devices
Physical environments:
- Unit Cabinets
- Folders
- Archive
REASONS REQUIRING RETENTION AND DISPOSAL
Personal data belonging to data subjects is securely stored by Miss Diamond in the physical or electronic media listed above, within the boundaries specified in the KVKK Law and other relevant legislation, specifically for the purposes of (i) maintaining commercial activities, (ii) fulfilling legal obligations, (iii) planning and executing employee rights and fringe benefits, and (iv) managing customer relationships.
The reasons requiring retention are as follows:
- Retention of personal data due to its direct relevance to the establishment and performance of contracts,
- Retention of personal data for the purpose of establishing, exercising, or protecting a right,
- Retention of personal data being mandatory for the legitimate interests of Miss Diamond, provided that it does not harm the fundamental rights and freedoms of the individuals,
- Retention of personal data for the purpose of Miss Diamond fulfilling any of its legal obligations,
- Retention of personal data being explicitly prescribed by legislation,
- The presence of the explicit consent of the data subjects regarding retention activities that require explicit consent.
Pursuant to the Regulation, personal data belonging to data subjects shall be deleted, destroyed, or anonymized by Miss Diamond ex officio or upon request under the following circumstances:
- Amending or repealing the relevant legislative provisions that form the basis for processing or storing personal data,
- The disappearance of the purpose requiring the processing or storage of personal data,
- The disappearance of the conditions requiring the processing of personal data in Articles 5 and 6 of the Law,
- The relevant person withdrawing their consent in cases where processing personal data occurs solely based on the explicit consent condition,
- The data controller accepting the application made by the relevant person regarding the deletion, destruction, or anonymization of their personal data within the framework of their rights in paragraphs 2 (e) and (f) of Article 11 of the Law,
- In cases where the data controller rejects the application made to them by the relevant person requesting the deletion, destruction, or anonymization of their personal data, or if the answer given is found insufficient, or if no answer is provided within the period prescribed by the Law; a complaint is filed with the Board and this request is approved by the Board,
- The passing of the maximum period requiring the storage of personal data, and the absence of any condition that would justify storing the personal data for a longer period.
MEASURES TAKEN REGARDING THE PROTECTION OF PERSONAL DATA
In accordance with Article 12 of the KVKK Law, Miss Diamond takes the necessary technical and administrative measures to provide the appropriate level of security in order to prevent unlawful processing of the personal data it processes, prevent unlawful access to data, and ensure data retention. In this regard, necessary audits are carried out or commissioned by our Company. All technical and administrative measures taken are specifically regulated in the Personal Data Policy. In the event that processed personal data is acquired by third parties through unlawful means despite all technical and administrative measures taken, Miss Diamond will report this situation to the relevant units as soon as possible, immediately take urgent measures to rectify the situation, and review the safeguards.
1. Technical Measures:
- Taking into account conscious or unconscious threats that may be posed by individuals within the organization, necessary security controls have been implemented via log reporting through software and hardware devices in all relevant areas to control access to information and prevent unauthorized access.
- Technical measures matching technological developments are taken, and the measures taken are periodically updated and renewed.
- Access and authorization technical solutions are deployed in accordance with legal compliance requirements determined on a business unit basis.
- Access authorizations are restricted, and authorizations are regularly reviewed.
- Technical measures taken are periodically checked, risk-posing matters are re-evaluated, and mandatory technological solutions are produced.
- Software and hardware containing virus protection systems and firewalls are installed.
- Personnel knowledgeable in technical matters are employed, and internal trainings are conducted.
- Regular security scans are performed to detect vulnerabilities in applications where personal data is collected. Detected vulnerabilities are closed.
- When a need arises, penetration testing services are obtained to check system vulnerabilities.
- Destruction of personal data is ensured in a way that is irreversible and leaves no audit trail.
2. Administrative Measures:
- Employees are trained on the technical measures to be taken to prevent unlawful access to personal data.
- Personal data access and authorization processes within Miss Diamond are designed and implemented in line with legal compliance requirements for data processing on a business unit basis. Whether the data is of a special category and its degree of importance are also taken into account when restricting access.
- Records have been added to all kinds of documents regulating the relationship with Miss Diamond personnel and containing personal data, stating that obligations prescribed by the KVKK Law must be followed for personal data to be processed lawfully, personal data must not be disclosed, personal data must not be used unlawfully, and the confidentiality obligation regarding personal data continues even after the termination of the employment contract with Miss Diamond; failure of personnel to comply with these obligations requires the application of sanctions that may extend to the termination of the employment contract.
- Employees are informed that they cannot disclose personal data they learn to others in violation of the provisions of the KVKK Law and cannot use it outside the scope of processing purposes, and that this obligation will continue after they leave office, and necessary commitments are obtained from them accordingly.
- Provisions are added to contracts concluded with persons to whom personal data is lawfully transferred by Miss Diamond, stating that the persons to whom personal data is transferred will take necessary security measures to protect personal data and ensure compliance with these measures within their own organizations.
- In the event that processed personal data is obtained by others through unlawful means, it notifies the data subject and the Board as soon as possible.
- It employs personnel knowledgeable and experienced in personal data processing and provides its staff with necessary training within the scope of personal data protection legislation and data security.
- It carries out or commissions necessary audits within its own legal entity to ensure the implementation of the provisions of the Law. It resolves confidentiality and security vulnerabilities resulting from audits.
- Miss Diamond is responsible under Article 12 of the KVKK Law for ensuring that third parties to whom it transfers personal data fulfill their obligations to process and protect data lawfully and access data lawfully in line with this Policy and the provisions of the KVKK Law. Therefore, Miss Diamond must secure commitments including the provision of these conditions and the granting of audit authority to itself in contracts and all kinds of arrangements made while transferring data to third parties. Likewise, Miss Diamond must specifically inform all its personnel about responsibilities arising from personal data transfer processes to third parties.
METHODS OF PERSONAL DATA DISPOSAL
Although processed in accordance with the provisions of the relevant law, Miss Diamond may delete or destroy personal data based on its own decision or upon the request of the personal data owner if the reasons requiring its processing cease to exist. An effective data tracking process will be managed by Miss Diamond for defining and tracking personal data disposal workflows.
a. Deletion of Personal Data
Deletion of personal data is the process of rendering personal data inaccessible and non-reusable for the relevant users in any way. Miss Diamond may use one or more of the following methods:
- Personal data located on paper media will be processed by scratching, painting, cutting, or erasing using the black-out method.
- For office files located in the central directory, the access right(s) of the user(s) will be revoked.
- Rows or columns containing personal details in databases will be deleted using the 'Delete' command.
- When necessary, it will be securely deleted by obtaining assistance from an expert.
b. Destruction of Personal Data
Destruction of personal data is the process of rendering personal data inaccessible, irretrievable, and non-reusable by anyone in any way.
- Physical Destruction
- Destruction with a Paper Shredder
- Degaussing: A method of corrupting data on magnetic media in an unreadable manner by passing it through special devices where it will be exposed to high magnetic fields.
c. Anonymization of Personal Data
Anonymization of personal data refers to rendering personal data impossible to be associated with an identified or identifiable real person under any circumstances, even by matching them with other data. Miss Diamond may use one or more of the following methods to anonymize personal data:
- Masking: A method of anonymizing personal data by removing the primary identifying information of the personal data from the dataset. Example: Transforming it into a dataset where identifying the personal data owner becomes impossible by removing info such as name, T.R. Identity No, etc., which allows the data subject to be identified.
- Removing Records: In the record removal method, the stored data is anonymized by removing the data row containing uniqueness from among the records.
- Regional Hiding: In the regional hiding method, if a single data point possesses an identifying characteristic due to creating a rare combination, hiding the relevant data ensures anonymization.
In accordance with Article 28 of the KVKK Law, anonymized personal data may be processed for purposes such as research, planning, and statistics. Such processing falls outside the scope of the KVKK Law, and the explicit consent of the personal data owner will not be sought.
PERSONAL DATA RETENTION AND DISPOSAL PERIODS
Miss Diamond stores personal data for the duration required for the purpose for which it is processed. In the event that the primary purpose of collecting personal data or the basis for secondary processing specified in this Policy disappears, personal data may continue to be stored for the periods specified in ANNEX-1.
If a period is prescribed in the legislation regarding the storage of the said personal data, this period is complied with. In the absence of a period prescribed in the legislation, personal data will be stored for the maximum period for keeping personal data listed in the table in ANNEX-1. These periods have been determined by evaluating Miss Diamond's data categories and data subject groups; ensuring that the data obtained as a result of this evaluation will enable the fulfillment of obligations located in the laws, and considering the maximum statute of limitations (10 years) located in the Turkish Code of Obligations.
When the obligation to delete, destroy, or anonymize arises due to the expiration of these periods, Miss Diamond deletes, destroys, or anonymizes the personal data in the first periodic disposal operation following this date.
MISS DIAMOND PERIODIC DISPOSAL PERIODS
Miss Diamond's periodic disposal window is 6 months. Personal data whose storage period has expired is disposed of in 6-month periods in accordance with the procedures outlined in this Policy, within the framework of the disposal periods located in ANNEX-1 of this Policy. Information in the said systems will be deleted in a way that cannot be recovered, and from tools such as documents, files, CDs, diskettes, and hard disks on which data is recorded, if any, in a non-recyclable manner.
All operations performed regarding the deletion, destruction, and anonymization of personal data are recorded, and the said records are stored for at least three years, excluding other legal obligations.
PERSONNEL
Within the scope of the KVKK Law, Miss Diamond, in its capacity as data controller, has provided the necessary personnel training on the Protection of Personal Data and informed its employees and responsible officers about the disposal processes. In this context, each department manager will be obliged to monitor whether the Relevant Users in their departments act in compliance with this Policy and the Personal Data Policy prepared within the framework of the Law and Regulation.
APPLICATION AND RIGHTS OF THE RELEVANT PERSON
Pursuant to Article 13 of the KVKK Law, the relevant person may apply to Miss Diamond and request the deletion or destruction of personal data belonging to them.
- If all conditions for processing personal data have disappeared, the data controller deletes, destroys, or anonymizes the personal data subject to the request. The data controller concludes the request of the relevant person within thirty days at the latest and informs the relevant person.
- If all conditions for processing personal data have disappeared and the personal data subject to the request has been transferred to third parties, the data controller notifies the third party of this situation and ensures that the necessary operations are carried out within the scope of the Regulation before the third party.
- If all conditions for processing personal data have not disappeared, this request may be rejected by the data controller by explaining its justification, and the rejection response is notified to the relevant person within thirty days at the latest, in writing or electronically.
Data owners will be able to convey their requests to Miss Diamond free of charge along with information and documents confirming their identity, using the following methods:
- By sending an email to the [email protected] email address,
- By submitting an Application Form in person or via a notary public to the address Mesihpaşa Mah. Sait efendi Sok. No: 9 Fatih / İstanbul.
In order for third parties to make an application request on behalf of personal data owners, a special power of attorney issued through a notary public by the data owner in the name of the person making the application must be present.
ANNEXES
ANNEX 1: Data Retention and Disposal Periods Table
| TRANSACTION OR PROCESS CONTAINING PERSONAL DATA |
RETENTION PERIOD |
DISPOSAL PERIOD |
| General Assembly Transactions and Company Shareholder Information |
10 years from the termination of the company's legal entity |
Within 180 days following the end of the retention period |
| Financial Information |
10 years from the termination of the legal relationship |
Within 120 days following the end of the retention period |
| Professional Experience |
10 years from the termination of the legal relationship |
Within 120 days following the end of the retention period |
| Marketing Activities |
10 years from the termination of the legal relationship |
Within 120 days following the end of the retention period |
| Health Information |
10 years from the termination of the employment contract |
Within 120 days following the end of the retention period |
| Criminal Record Data |
10 years from the termination of the employment contract |
Within 120 days following the end of the retention period |
| Answering court/execution information requests regarding personnel |
10 years following the termination of the working relationship |
Within 180 days following the end of the retention period |
| Contact |
10 years from the termination of the legal relationship |
Within 180 days following the end of the retention period |
| Contractual Transactions |
10 years following the termination of the contractual relationship |
Within 180 days following the end of the retention period |
| Identity Details |
10 years from the termination of the legal relationship |
Within 180 days following the end of the retention period |
| Risk Management |
10 years from the termination of the legal relationship |
Within 180 days following the end of the retention period |
| Job applications (resulting negatively) |
5 years from the negative conclusion of the application |
Within 180 days following the end of the retention period |
| Personnel files |
10 years following the termination of the employment contract |
Within 180 days following the end of the retention period |
| Occupational Health and Safety practices |
10 years following the termination of the business relationship |
Within 180 days following the end of the retention period |
| Board of Directors and Representative Information |
10 years from the termination of the company's legal entity |
Within 180 days following the end of the retention period |
| Payment Transactions/Accounting |
10 years following the termination of the business/legal relationship |
Within 180 days following the end of the retention period |
| Personnel Financing Processes |
10 years following the termination of the working relationship |
Within 180 days following the end of the retention period |
| Filing of training records |
10 years following the termination of the employment contract |
Within 180 days following the end of the retention period |
| Security Camera Footage and Audio Recordings |
40 days from the date the image and audio recording was taken |
Within 180 days following the end of the retention period |
| Request/Complaint Management Information |
2 years from the recording of the Request/Complaint |
Within 180 days following the end of the retention period |