{"id":593,"date":"2022-02-13T12:38:00","date_gmt":"2022-02-13T12:38:00","guid":{"rendered":"https:\/\/muratemiroglu.com\/?p=593"},"modified":"2022-02-13T12:40:33","modified_gmt":"2022-02-13T12:40:33","slug":"personal-data-storage-and-destruction-policy","status":"publish","type":"post","link":"https:\/\/muratemiroglu.com\/?p=593","title":{"rendered":"Personal Data Storage and Destruction Policy"},"content":{"rendered":"\n<p>entry<br>THE NATURE, PURPOSE AND SCOPE OF THE DESTRUCTION POLICY<br>THIS IS THE DISPOSAL POLICY (POLICY) , THE MEDICAL SERVICE OFFICE (PRACTICE)<br>No. 6698 of the personal data obtained from the operator as the DATA OFFICER PHYSICIAN (DATA OFFICER)<br>Deletion, destruction and \/or destruction of Personal Data in accordance with the Law on the Protection of Personal Data and relevant legislation<br>it has been prepared in order to determine the procedures and principles to be applied in relation to anonymization.<\/p>\n\n\n\n<p>In this context, the employees of the OFFICE, candidates for employees, patients, patients<br>escorts\/guardians-personal data of their parents and within the OFFICE for any reason<br>personal data of all natural persons found; within the framework of this Personal Data Storage and Destruction Policy<br>It is carried out in accordance with the Constitution and laws.<\/p>\n\n\n\n<p>definitions<\/p>\n\n\n\n<p>Data Officer<\/p>\n\n\n\n<p>Determining the purposes and means of processing personal data, data<br>responsible for the establishment and management of the registration system<br>a natural or legal person who has<br>The contact person is the real person whose personal data is processed,<br>Any kind of Personal Data related to a specific or identifiable natural person<\/p>\n\n\n\n<p>information<\/p>\n\n\n\n<p>Personal Data of a Special Nature<\/p>\n\n\n\n<p>Race, ethnicity, political thought, philosophical belief, religious,<br>sect or other beliefs, disguise and outfit, association, foundation or<br>his\/her union membership, health, sexual life, criminal conviction and<br>biometric and genetic data related to security measures<br>the data<\/p>\n\n\n\n<p>Processing of Personal Data<\/p>\n\n\n\n<p>Your personal data is fully or partially automated or<br>provided that you are part of any data recording system<br>obtaining, saving by non-automatic means,<br>storage, storage, replacement, reuse<br>regulation, disclosure, transfer, acquisition, acquisition<br>making it acceptable, classifying or using it<br>any kind of blocking performed on data such as<br>process<\/p>\n\n\n\n<p>Based on the authority granted by the data Processor, the data controller<\/p>\n\n\n\n<p>a natural or legal person who processes personal data on behalf of<br>Destruction Deletion, destruction or anonymization of personal data<\/p>\n\n\n\n<p>execution<\/p>\n\n\n\n<p>annihilation<\/p>\n\n\n\n<p>Your personal data cannot be accessed by anyone in any way,<br>making it irretrievable and unusable again<br>the process<\/p>\n\n\n\n<p>Deleting Personal data is in no way accessible to the relevant users and<\/p>\n\n\n\n<p>it is the process of making it unusable again<\/p>\n\n\n\n<p>Anonymization<\/p>\n\n\n\n<p>In no case should your personal data be matched with other data, even if<br>with an identified or identifiable natural person<br>making it unassociable<\/p>\n\n\n\n<p>Law \/ KVKK published in the Official Gazette dated 07.04.2016 and numbered 29677<\/p>\n\n\n\n<p>Law No. 6698 on personal data protection,<\/p>\n\n\n\n<p>Regulation<\/p>\n\n\n\n<p>published in the Official Gazette dated 28.10.2017 and numbered 30224<br>Personal data deletion, destruction or become anonymous<br>The Regulation on the Introduction of<br>The Board established the Personal Data Protection Board<br>The Institution has established the Personal Data Protection Authority<\/p>\n\n\n\n<p>Recording media<\/p>\n\n\n\n<p>Any data that is fully or partially automated or<br>non-automatic, provided that you are part of the registration system<br>any environment where there is personal data processed by means of<br>Data recording system is a system where personal data is processed by configuring it according to certain criteria<\/p>\n\n\n\n<p>the registration system<\/p>\n\n\n\n<p>expresses.<\/p>\n\n\n\n<p>DISTRIBUTION OF RESPONSIBILITIES AND DUTIES<br>THE DATA OFFICER is responsible for the preparation, development, execution of the POLICY in the relevant environments<br>publication and updating of the Policy, compliance of employees with the policy, compliance with the POLICY<br>he is responsible for providing the technical solutions needed in its implementation.<\/p>\n\n\n\n<p>As required by the technical and administrative measures taken within the scope of the POLICY, the employees of the OFFICE<br>implementation, prevention of unlawful processing of personal data, compliance of personal data with the law<br>preventing illegal access and ensuring that personal data is stored in accordance with the law<br>in order to ensure data security in all environments where personal data is processed, technical and administrative<br>follow the precautions.<\/p>\n\n\n\n<p>METHODS OF COLLECTION OF PERSONAL DATA<br>Personal data, natural or legal persons who process data authorized by the DATA CONTROLLER<br>in accordance with the Law on the Protection of Personal Data No. 6698 and in accordance with this law, issued by<br>within the terms and purposes specified in the secondary regulations;<br>application and initial notification, opening the registration and creating a patient file, paper and<br>online through the SSI system, through means such as forms and minutes kept electronically<br>as a result, in case of benefiting from a private insurance company, the shared records are referred to the OFFICE<br>if it has been done through the records of other medical institutions, with the submission of a CV or work<br>contact the OFFICE for any purpose as received from the supplier\/service, with applications<br>when it is passed and the service is received, it can be done orally, in writing or by automated and non-automated methods<br>it is provided electronically. jul.<\/p>\n\n\n\n<p>RECORDING MEDIA<br>Personal data are collected by the OFFICE in accordance with the law in the environments listed in Table 2<br>it is stored safely.<\/p>\n\n\n\n<p>3.1. DATA STORED IN ELECTRONIC MEDIA<br>Servers (Domain, backup, email, database, web, file sharing, etc.) \uf0fc<br>Software (office software, portal, medical programs) *<br>Information security devices (firewall, intrusion detection and blocking, log file, antivirus<br>etc.)<br>For personal computers (Desktop, laptop)<br>Mobile devices (phone, tablet, etc.) \uf0fc<br>Optical discs (CD, DVD, etc.) \uf0fc<br>Removable memory cards (USB, Memory Card, etc.) \uf0fc<br>Printer, scanner, copier<\/p>\n\n\n\n<p>3.2. NON-ELECTRONIC ENVIRONMENTS<br>Paper<br>Manual data recording systems (patient files, protocol book, inspection and audit book, working<br>keeping documents in accordance with the visitor&#8217;s logbook and private medical enterprises that provide medical services<br>other books that are mandatory)<br>Written, printed, visual media<\/p>\n\n\n\n<p>EXPLANATIONS ON STORAGE AND DISPOSAL<\/p>\n\n\n\n<p>By the DATA OFFICER; employees, prospective employees, patients, patient companions\/parents-guardians and<br>personal data of all natural persons who have personal data within the OFFICE for any reason<br>the data is stored and destroyed in accordance with the Law. In this context, detailed information about storage and disposal<br>the explanations are given below, respectively.<\/p>\n\n\n\n<p>4.1. EXPLANATIONS RELATED TO STORAGE<br>3 Of the Act.the article defines the concept of processing personal data, 4. personal data processed in the article<br>the data must be linked, limited and measured for the purpose for which they are processed, and provided for in the relevant legislation or<br>it is stated that they should be kept for the required period of time for the purpose for which they were processed, 5 and 6. in the articles<br>the terms of processing of personal data are considered. Accordingly, within the framework of the activities of the OFFICE<br>personal data, the DATA CONTROLLER for as long as the period stipulated in the relevant legislation or in accordance with the purposes of processing<br>are stored.<\/p>\n\n\n\n<p>4.1.1. LEGAL REASONS REQUIRING STORAGE<br>Personal data processed in the OFFICE within the framework of activities, as required by the service provided and related<br>it is maintained for as long as stipulated in the legislation. In this context, personal data;<br>Law No. 6698 on the Protection of Personal Data,<br>Law No. 1219 on the Style Execution of Tababet and \u015euabat\u0131 Arts<br>Turkish Code of Obligations No. 6098,<br>Turkish Criminal Code No. 5237,<br>Social Insurance and General Health Insurance Law No. 5510,<br>Basic Law of Health Services No. 3359,<br>Occupational Health and Safety Law No. 6361,<br>Labor Code No. 4857,<br>Occupational Health and Safety Services Regulation<br>Patient Rights Regulation,<br>Regulation of Medical Deontology<br>In accordance with other relevant laws and other secondary regulations in force in accordance with these laws<br>it is stored up to the prescribed storage periods.<\/p>\n\n\n\n<p>4.1.2. PROCESSING PURPOSES THAT REQUIRE STORAGE<\/p>\n\n\n\n<p>Personal data processed within the framework of the activities of the OFFICE are used for the following purposes<br>it is stored.<br>To be able to perform work and operations as a result of signed contracts and protocols.<br>Obligation to prove as evidence in legal disputes that may arise in the future<br>Fulfilling legal obligations as required or required by legal regulations<br>ensuring the fulfillment of<\/p>\n\n\n\n<p>4.2. REASONS THAT REQUIRE DESTRUCTION<br>Personal data;<br>Amendment or change of the provisions of the relevant legislation, which is the basis for its processing,<br>Elimination of the purpose that requires its processing or storage,<br>In cases where the processing of personal data occurs only on the condition of explicit consent, the relevant person&#8217;s explicit<br>taking back consent,<br>11 of the Law. according to the article, deletion and destruction of personal data within the framework of the rights of the relevant person<br>acceptance of his application for admission by the OFFICE,<br>The OFFICE is subject to deletion, destruction or anonymization of its personal data by the person concerned<br>if he rejects the application made to him with a request to be brought, he finds the answer he has given insufficient, or<br>In case of non-response within the period stipulated by the law; he must submit an application to the Board and this<br>approval of the request by the Board,<br>The maximum period that requires the storage of personal data has passed, and the personal data is longer<br>there are no conditions that justify storing for a while,<br>In their case, they are deleted, destroyed or re&#8217;sen by the OFFICE at the request of the relevant person<br>they are deleted, destroyed or anonymized.<\/p>\n\n\n\n<p>TECHNICAL AND ADMINISTRATIVE MEASURES<br>Secure storage, unlawful processing and access of personal data<br>12 of the Law on the prevention and destruction of personal data in accordance with the law. article<br>6 Of the Act. article 4. for personal data of a special nature in accordance with the paragraph determined by the Board and announced<br>within the framework of the adequate measures taken, technical and administrative measures are taken by the OFFICE.<\/p>\n\n\n\n<p>5.1. TECHNICAL MEASURES<br>The following are the technical measures taken by the DATA CONTROLLER in relation to the personal data it processes<br>has been counted:<br>All personal data, including personal data of a private nature, stored electronically<br>necessary measures are being taken for its safety. In this context; firewalls, network access control,<br>systems that block malware, security patches are used. Information systems are up to date<\/p>\n","protected":false},"excerpt":{"rendered":"<p>entryTHE NATURE, PURPOSE AND SCOPE OF THE DESTRUCTION POLICYTHIS IS THE DISPOSAL POLICY (POLICY) , THE MEDICAL SERVICE OFFICE (PRACTICE)No. 6698 of the personal data obtained from the operator as the DATA OFFICER PHYSICIAN (DATA OFFICER)Deletion, destruction and \/or destruction of Personal Data in accordance with the Law on the Protection of Personal Data and&hellip; <a class=\"more-link\" href=\"https:\/\/muratemiroglu.com\/?p=593\">Continue reading <span class=\"screen-reader-text\">Personal Data Storage and Destruction Policy<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_joinchat":[],"footnotes":""},"categories":[16],"tags":[],"class_list":["post-593","post","type-post","status-publish","format-standard","hentry","category-kvkk","entry"],"_links":{"self":[{"href":"https:\/\/muratemiroglu.com\/index.php?rest_route=\/wp\/v2\/posts\/593","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/muratemiroglu.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/muratemiroglu.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/muratemiroglu.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/muratemiroglu.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=593"}],"version-history":[{"count":2,"href":"https:\/\/muratemiroglu.com\/index.php?rest_route=\/wp\/v2\/posts\/593\/revisions"}],"predecessor-version":[{"id":596,"href":"https:\/\/muratemiroglu.com\/index.php?rest_route=\/wp\/v2\/posts\/593\/revisions\/596"}],"wp:attachment":[{"href":"https:\/\/muratemiroglu.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=593"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/muratemiroglu.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=593"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/muratemiroglu.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=593"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}