Processing and Protection of Personal Data Policy
This Personal Data Processing and Protection Policy (“Policy”) has been established by Panacea Sigorta ve Reasürans Brokerliği A.Ş. to regulate the principles set to ensure compliance with applicable legislation regarding the processing, protection, and disposal of personal data.
2- Definitions
The terms used in this Policy, which start with a capital letter and are not defined within the Policy, shall have the meanings ascribed to them below:
| Terms | Explanation |
|---|---|
| Explicit Consent | The consent expressed based on information and freely given regarding a specific matter. |
| Anonymization | Refers to the process of rendering Personal Data impossible to associate with an identified or identifiable person, even when matched with other data. |
| Secondary Legislation | Refers to any regulation, circular, notification, principle decision, or similar administrative decision or general view issued or adopted by the Personal Data Protection Authority under the Law. |
| Relevant Users | Refers to individuals or units within the data controller organization who process personal data under authorization and instruction, except for persons responsible for the technical storage, protection, and backup of data. |
| Law | Refers to the Law on the Protection of Personal Data No. 6698. |
| Personal Data | Refers to any information relating to an identified or identifiable natural person. |
| Processing of Personal Data | Refers to any operation performed on personal data such as collecting, recording, storing, keeping, altering, rearranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of such data, wholly or partially, through automatic or non-automatic means as part of any data recording system. |
| Board | Refers to the Personal Data Protection Board. |
| Authority | Refers to the Personal Data Protection Authority. |
| Special Categories of Personal Data | Refers to data related to a person’s race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance, association, foundation or union membership, health, sexual life, criminal record, and biometric and genetic data. |
| Registry | Refers to the Data Controllers Registry, a registration system in which data controllers are required to register and declare information related to their data processing activities. |
| Deletion | Refers to rendering personal data inaccessible and non-reusable by Relevant Users. |
| Deletion and Destruction Policy | Refers to the policy regulating the principles and procedures for the deletion and destruction of personal data as prepared by the Company in accordance with the Regulation on Deletion, Destruction, or Anonymization of Personal Data. |
| Company | Refers to Panacea Sigorta ve Reasürans Brokerliği A.Ş. |
| Data Processor | Refers to a natural or legal person who processes personal data on behalf of the Data Controller based on the authority granted. |
| Data Protection Commission | Refers to the Company’s Personal Data Protection Commission. |
| Data Subject | Refers to the natural person whose personal data is processed, as defined in the Law as the “Related Person.” Data subjects include customers, internet users, individuals in communication, email, and marketing databases, employees, contractual parties, and suppliers. |
| Data Controller | Refers to the natural or legal person responsible for determining the purposes and means of processing personal data and managing the establishment and operation of the data recording system. |
| Regulation on Data Controllers Registry | Refers to the Regulation on the Data Controllers Registry, which came into effect on January 1, 2018. |
| Destruction | Refers to rendering personal data inaccessible, irrecoverable, and non-reusable by anyone. |
3- Scope
As Panacea Sigorta ve Reasürans Brokerliği A.Ş., we commit to adhering to the confidentiality and security requirements of personal data within the scope of the Law and have adopted this Policy to establish the principles of processing and protecting personal data.
This Policy applies to all full-time and part-time employees, subcontractors, employees of the Company’s affiliates, employees of joint ventures, and all suppliers and vendors who access, provide information to, or receive personal data from Panacea Sigorta ve Reasürans Brokerliği A.Ş. In cases of conflict with the provisions of the Law, the Law will prevail.
4- Principles
4.1 Principles to Be Followed in Processing Personal Data
4.1.1 Personal Data Is Processed in Compliance with the Law and Integrity
Panacea Sigorta ve Reasürans Brokerliği A.Ş. processes personal data in compliance with the law and integrity. The Company processes personal data in accordance with the rules set forth by the Law. Furthermore, the Company monitors and implements necessary improvements in accordance with regulations issued by the Board.
4.1.2 Personal Data Must Be Accurate and Up-to-Date When Necessary
Panacea Sigorta ve Reasürans Brokerliği A.Ş. takes the necessary measures to ensure that the personal data it processes is accurate and up to date.
4.1.3 Personal Data Must Be Processed for Specific, Explicit, and Legitimate Purposes
The Company determines its data processing purposes clearly and processes personal data for legitimate purposes only. The Company informs Data Subjects about the purposes of data processing in advance.
4.1.4 Personal Data Must Be Retained for the Period Required by the Relevant Legislation or for the Purpose of Processing
Panacea Sigorta ve Reasürans Brokerliği A.Ş. retains personal data for the period required by the relevant legislation and deletes the data after this period has expired.
4.2 Conditions for Processing
4.2.1 Processing of Personal Data
The Company processes personal data in accordance with the conditions specified in the Law. The Company may process personal data without obtaining the explicit consent of the Data Subject in the following cases:
- It is expressly provided for by the laws,
- It is necessary for the performance or establishment of a contract,
- It is necessary for the fulfillment of the legal obligations of the Data Controller.
4.2.2 Data Protection Commission
The Company has established a Data Protection Commission to monitor and protect personal data processing procedures. This Commission ensures that personal data is processed lawfully.
4.3 Processing of Special Categories of Personal Data
Panacea Sigorta ve Reasürans Brokerliği A.Ş. processes personal data in accordance with the conditions specified in the Law. In addition, special measures may be imposed by the Board for processing Special Categories of Personal Data. The Company will comply with these regulations and take necessary precautions in line with the measures taken by the Board following the publication of this Policy.
4.3.1 Conditions for Processing Special Categories of Personal Data
Special Categories of Personal Data may be processed under the following conditions:
- With the explicit consent of the Data Subject: The Company processes personal data only with the explicit consent of the Data Subject.
- Processing of Special Categories of Personal Data: Special Categories of Personal Data other than the Data Subject’s health and sexual life may be processed without explicit consent in cases prescribed by law.
- Health and sexual life data: Personal data relating to health and sexual life may be processed for purposes such as protecting public health, preventive medicine, medical diagnosis, treatment, and management of healthcare services.
4.4 Consent
4.4.1 Obtaining and Managing Explicit Consent
The explicit consent of the Data Subject is obtained and managed as follows:
- Obligation to inform: The Data Subject is informed before obtaining consent.
- Clear and understandable consent: Explicit Consent should be clear and understandable, relating only to a specific process.
- Free will: Explicit Consent must be given freely without any pressure.
- Separate consent: Explicit Consent is obtained separately for each purpose of data processing.
The Data Subject can withdraw their consent at any time. This process will be managed in accordance with the Company’s regulations.
4.5 Transfer of Personal Data
4.5.1 Transfer of Personal Data to Third Parties
Personal data may be transferred to third parties under the following conditions:
- Explicit consent: With the explicit consent of the Data Subject,
- Legal obligation: If the transfer is expressly provided for by law,
- Protection of life or bodily integrity: If the transfer is necessary for the protection of individuals who cannot express their consent due to physical impossibility,
- Contractual requirement: If the transfer is necessary for the performance of a contract,
- Legal obligation: For the fulfillment of legal obligations of the Company,
- Public disclosure: If the data is already publicly disclosed by the Data Subject,
- Legitimate interests: If the transfer is necessary for the legitimate interests of the Data Controller.
4.5.2 Transfer of Personal Data Abroad
Panacea Sigorta ve Reasürans Brokerliği A.Ş. transfers personal data abroad in compliance with the Law, only to countries with adequate protection or where adequate protection is guaranteed. This process is subject to the Board’s approval. Systems used for international transfers include CRM and mass email services.
4.6 Monitoring of Visitor and Customer Activities
4.6.1 Closed-Circuit Camera Recording
The Company uses closed-circuit camera systems to fulfill its obligations under security and R&D legislation. Camera recordings are retained for a maximum of 30 days to avoid infringing on the personal rights and freedoms of individuals.
4.6.2 Internet Access Logs
When providing internet access at the workplace, the Company records log files related to access in compliance with Law No. 5651 and relevant legislation and keeps them available for submission to competent authorities upon request.
4.7 Website Visitors
The Company may monitor website visitor activities through cookies to provide personalized services. Details regarding the use of cookies are provided in the “Cookie Policy” on the Company’s website.
4.8 Obligation to Inform
The Company is obliged to inform the Data Subject in every case where personal data is collected. The notification must include the following elements:
- The identity of the Data Controller,
- The purposes of data processing,
- The data transfer and recipient groups,
- The methods and legal reasons for data collection,
- The rights of the Data Subject (access, correction, deletion, etc.).
4.9 Data Subject’s Rights
Data Subjects may apply to Panacea Sigorta ve Reasürans Brokerliği A.Ş. under Article 11 of the Law to exercise the following rights:
- To learn whether their personal data is processed,
- To request information if it has been processed,
- To learn the purpose of the processing,
- To request correction of inaccurate or incomplete data,
- To request the deletion of data if the reasons for processing no longer apply.
Requests can be submitted by sending an email to kvk@panaceasigorta.com.
4.10 Retention, Deletion, and Anonymization of Personal Data
The Company determines the procedures for the retention, deletion, or anonymization of personal data and implements these processes within the framework of the “Personal Data Retention and Destruction Policy.” Data Retention Periods are determined in accordance with legal obligations, and personal data is deleted, destroyed, or anonymized when necessary.
4.11 Principle of Proportionality
All processes regarding the processing and protection of personal data must ensure proportionality between the measures taken and the objectives pursued. The purpose of data processing and the methods used must be balanced.
5. Registration with the Data Controllers Registry
Panacea Sigorta ve Reasürans Brokerliği A.Ş. registers with the Data Controllers Registry and submits its processing activities to the Registry when required by law.
6. Use of Third-Party Data Processors
The Company ensures that third parties processing personal data on its behalf comply with data security standards by establishing contracts and implementing audit mechanisms.
7. Data Security
7.1 Physical, Technical, and Organizational Security Measures
The Company takes physical, technical, and organizational security measures to ensure the protection of personal data, considering technological advancements. These measures are regularly reviewed and updated.
7.2 Employee Confidentiality Agreements
All employees involved in the processing of personal data sign confidentiality agreements to ensure the protection of such data.
8. Dispute Resolution
Complaints and requests from Data Subjects regarding their personal data are first resolved by the Data Protection Commission. Unresolved cases are addressed following the Company’s internal regulations and applicable legislation.
9. Compliance Audits
The Company regularly audits its compliance with data protection legislation and rectifies any deficiencies. Annual data protection audits are conducted.
10. Implementation
10.1 Publication and Enforcement
This Policy comes into force upon its publication by Panacea Sigorta ve Reasürans Brokerliği A.Ş. and is implemented across all Company departments.
10.2 Amendments
Any significant changes to this Policy will be communicated to employees and other relevant individuals through appropriate methods.
11. Severability
If any provision of this Policy is declared invalid, the remaining provisions will remain in effect.
Let me know if any adjustments or further details are required.
