RECEP TAYYİP ERDOĞAN UNIVERSITY AND TURKISH-GERMAN UNIVERSITY TECHNOLOGY DEVELOPMENT ZONE MANAGEMENT JOINT STOCK COMPANY PERSONAL DATA PROTECTION UNIT DIRECTIVE
PART ONE
Introductory Provisions
Purpose and Scope
Article 1- (1) This Directive has been prepared to govern the establishment, duties, powers and working principles of the Personal Data Protection Unit, which was created to carry out the work needed to ensure that all of the Company’s personal data processing complies with Personal Data Protection Law No. 6698.
Legal Basis
Article 2- (1) This Directive has been prepared on the basis of the Company’s Board of Directors resolution No. 2024/035 dated 31.07.2024.
Definitions
Article 3- (1) In this Directive:
- Privacy Notice: the documents prepared to inform the data subject about the conditions under which personal data is processed,
- Unit: the Personal Data Protection Unit established within the Company,
- Head of the Unit: the Company employee selected by the Company’s General Manager to head the Unit,
- General Manager: the General Manager of Recep Tayyip Erdoğan University and Turkish-German University Technology Development Zone Management Joint Stock Company,
- Data subject: the natural person whose personal data is processed,
- Destruction: the erasure, destruction or anonymization of personal data,
- Law: Personal Data Protection Law No. 6698,
- Board: the Personal Data Protection Board,
- Authority: the Personal Data Protection Authority,
- Personal data: any information relating to an identified or identifiable natural person,
- Company: Recep Tayyip Erdoğan University and Turkish-German University Technology Development Zone Management Joint Stock Company,
- VERBIS: the Data Controllers’ Registry Information System,
- Data Inventory: the table setting out, by category, the Company’s data processing activities and the technical and administrative measures taken for the protection of personal data,
- Data Breach: any unauthorized access to the personal data processed by the Company,
- Data processor: the natural or legal person who processes personal data on behalf of the data controller, on the authority granted by the controller,
- Data Subject Request Form: the form submitted to the Company by the data subject containing a request for information about the processing of their personal data,
- Data controller: Recep Tayyip Erdoğan University and Turkish-German University Technology Development Zone Management Joint Stock Company, which determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system,
- Data contact person: the Company employee selected by the Company’s General Manager to handle communication between the Company and the Personal Data Protection Authority,
- Compliance Process: the work carried out by the Company to bring all of its processing activities into compliance with the Law,
means.
PART TWO
Establishment, Duties, Powers and Working Principles of the Unit
Selection of Unit Members and Decision-Making
Article 4- (1) The Unit was established by the Company’s Board of Directors resolution No. 2024/035 dated 31.07.2024, in order to fulfil the Company’s obligations under the Law.
(2) The members of the Unit and the Head of the Unit are selected by the General Manager from among the Company’s staff. The Unit consists of five (5) members in total.
(3) The data contact person is selected by the General Manager and is an ex officio member of the Unit.
(4) The Unit meets with at least one more than half of its total membership and takes decisions by a majority of those attending. In the event of a tie, the decision supported by the Head of the Unit shall prevail.
(5) The Unit reports directly to the General Management and obtains the General Manager’s approval before implementing any decision it takes or any action it proposes to carry out.
Duties and Powers of the Unit
Article 5- (1) The Unit organizes the processes for bringing personal data processing into compliance with the Law. Within this scope, the Unit is responsible for ensuring that the Company’s privacy notices, its personal data protection and processing policy, its personal data retention and destruction policy, its cookie policy, staff data security undertakings, any supplementary agreements and undertakings the Company signs with third parties in relation to data security, and all other documents prepared during the Compliance Process, including but not limited to those listed here, are used in accordance with the Law, and for tracking their updating where necessary.
(2) The Unit is responsible for making the updates required at ordinary meetings to keep the Company Data Inventory current. The Data Contact Person is responsible for updating the VERBIS registration in line with the updates made to the Data Inventory.
(3) The Unit meets in ordinary session every three months. Before each meeting it also carries out periodic and random internal audits of the Company’s data processing, and records the outcome of the meeting and the audit in a written minute.
(4) At its ordinary meetings, the Unit identifies any Personal Data for which the purpose of processing no longer applies under the Personal Data Retention and Destruction Policy. The Personal Data that must be destroyed accordingly is destroyed after the written approval of the General Manager has been obtained, and a record is drawn up of the destruction. Personal Data Destruction Records are retained for three (3) years from the date of destruction.
(5) In the event of a Data Breach, each member of the Unit is authorized and obliged to convene the Unit for an extraordinary meeting under an emergency code. In the event of a Data Breach the Unit shall immediately inform the General Manager in writing and orally. It shall also meet within 24 hours at the latest of becoming aware of the situation, make its findings regarding the Data Breach and take initial measures. Following that meeting, the Unit shall also carry out the steps required to notify the Authority of the Data Breach, as required by the obligation set out in the Law.
(6) Where a Data Subject makes an application to the Company using the Data Subject Request Form, the Unit shall meet within three (3) calendar days at the latest of the application being made. It shall make the necessary findings regarding the Data Subject’s application, inform the General Manager of the matter orally and in writing, and organize the request for advice from the Company’s legal counsel and the other internal processes required to respond to the application.
(7) As part of the compliance process, it tracks the completion of personal data protection awareness training by all Company staff, and at each ordinary meeting checks whether any newly recruited staff have yet to receive this training and addresses any gaps.
(8) At each ordinary meeting, the Unit assesses whether any technical and administrative measures need to be taken to ensure data security in the Company’s personal data processing. It submits a report on this to the General Manager and follows up on the completion of those measures.
(9) Where the Board issues any instruction to the Company, it carries out the steps required to comply with it.
PART THREE
Miscellaneous and Final Provisions
Entry into Force
Article 6- (1) This Directive enters into force on the date it is approved by the Company’s Board of Directors.
Effective Date: 01.08.2024
