Protection of Personal Data

Policy on the Protection, Processing, Retention and Destruction of Personal Data

This Policy establishes the principles governing the processing of personal data obtained by Sabancı University, the protection of the fundamental rights and freedoms of data subjects, and the protection, processing, retention and, where necessary, destruction of the personal data obtained.

I. Introduction

1.1. Purpose of the Policy

Pursuant to Article 20 of the Constitution titled “Privacy of Private Life”, Law No. 6698 on the Protection of Personal Data (“Law”), and the provisions of the regulations and communiqués currently in force, the purpose of this Policy is to establish the principles governing the processing of personal data obtained by Sabancı University (“University”), the protection of the fundamental rights and freedoms of data subjects (visitor, entrepreneur, applicant, participant, business partner, etc.), particularly the privacy of private life, the lawful conduct of data processing activities by the data controller processing personal data, and the protection, processing, retention and, where necessary, destruction of the personal data obtained.

1.2. Scope of the Policy

Considering that any operation performed by the University, acting in its capacity as data controller, on any information relating to an identified or identifiable natural person, including obtaining, recording, storing, retaining, altering, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the use of such data, by fully or partially automated means or by non-automated means provided that such processing forms part of a data recording system, constitutes a data processing activity, the scope of this Policy is to establish the procedures and principles applicable to the data processing activities carried out by the University.

1.3. Application of the Policy and Relevant Legislation

This Policy has been prepared in accordance with the applicable legislation in force, including primarily Law No. 2547 on Higher Education, Law No. 2914 on Higher Education Personnel, the Regulation on Foundation Higher Education Institutions, Law No. 6098 Turkish Code of Obligations, the Regulation on State Archive Services, the Higher Education Council Archive Regulation, Law No. 6698 on the Protection of Personal Data, the Regulation on the Data Controllers Registry No. 30286, the Regulation on the Deletion, Destruction or Anonymization of Personal Data No. 30224, and the Regulation on the Processing of Personal Health Data and Protection of Privacy, as well as the rules set forth in the regulations, communiqués, decisions and guidelines published by the Board.

If, following the publication date of the Policy, the Law or any other relevant legislation is amended and the Policy becomes inconsistent with such amendments, the amended provisions and rules shall apply. All communiqués, decisions and guidelines published by the Board are monitored by the University, and the rules set forth under the Policy are kept up to date.

1.4. Entry into Force of the Policy

The Policy has been published on the University’s website at sucool.sabanciuniv.edu and entered into force on the date of its publication.

II. Matters Relating to the Protection of Personal Data

2.1. Ensuring the Security of Personal Data

Pursuant to Article 12 of Law No. 6698, the data controller is obliged to take all necessary administrative and technical measures to ensure an appropriate level of security for the purposes of;

  • Preventing the unlawful processing of personal data,
  • Preventing unlawful access to personal data,
  • Ensuring the safeguarding of personal data.

Accordingly, the University implements security measures in order to prevent the unlawful processing, transfer and disclosure of personal data to third parties, unauthorized access, and security vulnerabilities arising through other means. Explanations regarding the administrative and technical measures adopted are set out under VI. Administrative and Technical Measures Taken for the Protection of Personal Data.

2.2. Protection of Special Categories of Personal Data

Data which, due to their nature, are considered sensitive and which, if obtained by third parties, may cause data subjects to suffer harm or discrimination are classified as special categories of personal data under the Law. Special categories of personal data consist of data relating to a person’s race, ethnic origin, political opinion, philosophical belief, religion, religious sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. As a rule, the processing of special categories of personal data is prohibited and may only be carried out in the limited circumstances permitted by law.

The University takes all necessary measures for the protection of special categories of personal data, and as a principle, aims to avoid the collection and processing of such data to the greatest extent possible.

III. Matters Relating to the Processing of Personal Data

3.1. Processing of Personal Data in Accordance with the Principles Prescribed by Legislation

Pursuant to Article 4 of the Law, the principles applicable to the processing of your personal data are as follows:

  • Processing lawfully and fairly,
  • Being accurate and, where necessary, kept up to date,
  • Processing for specified, explicit and legitimate purposes,
  • Being relevant, limited and proportionate to the purposes for which they are processed,
  • Being retained for the period prescribed by the relevant legislation or required for the purpose for which they are processed.

3.2. Conditions for Processing Personal Data

Personal data obtained by the University may not be processed without the explicit consent of the data subject, except in the circumstances expressly provided for under the Law.

3.3. Exceptions to the Requirement to Obtain Explicit Consent

a) Expressly provided for by law

One of the conditions for processing personal data is that such processing is expressly provided for by law. Provisions contained in laws permitting the processing of personal data may constitute a legal basis for processing. In such cases, the explicit consent of the data subject is not required.

b) Physical impossibility

Where it is necessary to protect the life or physical integrity of the person who is unable to express consent due to physical impossibility or whose consent is not legally valid, or of another person, the personal data of the relevant data subject may be processed without obtaining explicit consent.

c) Being directly related to the establishment or performance of a contract

Where the processing of personal data is necessary for the establishment or performance of a contract to which the data subject is a party, such personal data may be processed without obtaining explicit consent.

d) Fulfillment of the University’s legal obligations

Personal data may be processed without obtaining explicit consent where such processing is necessary for the University, acting in its capacity as data controller, to fulfill its legal obligations.

e) Having been made public by the data subject

Personal data that have been made public by the data subject, in other words, personal data that have in any manner been disclosed to the public, may be processed without obtaining explicit consent. Even in such cases, publicly disclosed personal data may not be used for purposes other than those for which they were made public.

f) Being necessary for the establishment, exercise or protection of a right

Personal data may be processed without the explicit consent of the data subject where such processing is necessary for the establishment, exercise or protection of a right.

g) Being necessary for the legitimate interests of the data controller, provided that the fundamental rights and freedoms of the data subject are not prejudiced

Where the processing of personal data is necessary for the data controller and such processing does not prejudice the fundamental rights and freedoms of the data subject, personal data may be processed without obtaining explicit consent.

The legitimate interest of the data controller refers to the interest and benefit to be obtained as a result of the relevant processing activity. The benefit to be obtained by the data controller must relate to a legitimate, sufficiently effective, specific and currently existing interest capable of being balanced against the fundamental rights and freedoms of the data subject. The relevant processing activity must be connected with the data controller’s current activities and be capable of providing a benefit to the data controller in the near future.

3.4. Processing of Special Categories of Personal Data

The processing of special categories of personal data is subject to Article 6 of the Law. Personal data relating to race, ethnic origin, political opinion, philosophical belief, religion, religious sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data, constitute special categories of personal data. The categories of data falling within this scope are exhaustive and may not be expanded by interpretation. By their nature, special categories of personal data are data which, if disclosed, may result in the data subject being subjected to discrimination or suffering harm. Therefore, they must be afforded a significantly higher level of protection than other personal data.

Special categories of personal data may be processed where the data subject has provided explicit consent; where processing is expressly provided for by law; where processing is necessary for the protection of the life or physical integrity of the person who is unable to express consent due to physical impossibility or whose consent is not legally valid, or of another person; where processing relates to personal data made public by the data subject and is consistent with the data subject’s intention in making such data public; where processing is necessary for the establishment, exercise or protection of a right; where processing by persons subject to an obligation of confidentiality or by authorized institutions and organizations is necessary for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, or the planning, management and financing of healthcare services; where processing is necessary for the fulfillment of legal obligations in the fields of employment, occupational health and safety, social security, social services and social assistance; or where processing is carried out by foundations, associations and other non-profit organizations or formations established for political, philosophical, religious or trade union purposes, provided that such processing complies with the legislation and purposes to which they are subject, is limited to their fields of activity, does not involve disclosure to third parties, and relates to their current or former members and constituents or to persons who are in regular contact with such organizations and formations. In addition, the processing of special categories of personal data is subject to the implementation of the adequate measures determined by the Personal Data Protection Board.

3.5. Clarification and Information of the Data Subject

At the time personal data are obtained, the University, acting in its capacity as data controller, or persons authorized by the University, provide information to data subjects. The procedures and principles regarding such information are set out in the relevant Clarification Texts published by the University in relation to the processing of personal data, and such information generally includes the following:

  • The identity of the data controller and, if any, its representative,
  • The purposes for which personal data will be processed,
  • The persons to whom personal data may be transferred and the purposes of such transfer,
  • The method and legal basis of collecting personal data,
  • The rights of the data subject as set out under Article 11 of the Law.

a) Purposes of processing personal data

Personal data are processed for specified, explicit and legitimate purposes, based on the principle of informing data subjects. The purposes pursued by the University in processing personal data obtained from data subjects are set out, for each relevant data subject category, in the relevant sections of the Clarification Texts available on our website.

b) Persons to whom personal data are transferred and purposes of transfer

Within the scope of the data controller’s obligation to provide clarification, the persons to whom personal data are transferred and the purposes of such transfer must be clearly specified. Personal data may not be transferred to third parties without the explicit consent of the data subject. The recipient groups to whom personal data are transferred by the University and the purposes of such transfers are set out under IV. Transfer of Personal Data.

c) Method and legal basis of collecting personal data

In accordance with Articles 5 and 6 of the Law, the data controller must clearly specify the condition for processing personal data on which the relevant processing activity is based. The method and means used to collect personal data are determined by the data controller. The conditions for processing personal data, in other words the circumstances establishing lawfulness, are exhaustively enumerated under the Law (Articles 5-6) and may not be expanded.

The University, acting as data controller, first assesses whether the purpose of the personal data processing activity can be based on one of the processing conditions other than explicit consent. Where such purpose does not satisfy at least one of the conditions stipulated under the Law other than explicit consent, the explicit consent of the data subject is obtained in order for the relevant data processing activity to continue.

IV. Transfer of Personal Data

4.1. Domestic Transfer

Personal data may not be transferred without the explicit consent of the data subject. However, where one of the conditions specified in the second paragraph of Article 5 or, provided that adequate measures are taken, in the third paragraph of Article 6 is satisfied, personal data may be transferred without obtaining the explicit consent of the data subject.

Information regarding the recipient groups to whom your personal data processed by the University are transferred is set out in Annex 3 – Third Parties to Whom Personal Data Are Transferred and Purposes of Transfer of this Policy.

4.2. Transfer Abroad

Personal data may be transferred abroad where an adequacy decision as specified under Articles 8 and 9 is in place, where one of the appropriate safeguards is provided, or in other circumstances permitted thereunder.

V. Categorization of Personal Data Processed by the University and Purposes of Processing

The categories of data obtained by the University from data subjects and the purposes pursued in processing such personal data are set out, for each relevant data subject category, in the relevant sections of the Clarification Texts available on our website.

VI. Administrative and Technical Measures Taken for the Protection of Personal Data

The University takes administrative and technical measures to ensure the secure retention of personal data and to prevent the unlawful processing of and unauthorized access to personal data.

Pursuant to subparagraphs (b) and (d) of paragraph 2 of Article 4 of the Law, personal data must, where necessary, be accurate and kept up to date and must be retained for the period prescribed by the relevant legislation or required for the purposes for which they are processed. Within this scope, the data processed are processed in accordance with the principles and rules applicable to data processing activities and are retained for the period necessary for the purposes for which they are processed. Information regarding the retention and destruction procedures and retention periods applicable to personal data processed by the University is set out under VIII. Retention and Destruction of Personal Data of this Policy.

For the purposes of ensuring personal data security, the University identifies all personal data processed by it and assesses the likelihood of risks arising in relation to the protection of such data. In identifying such risks, consideration is given to whether the personal data constitute special categories of personal data (1), the level of confidentiality required due to the nature of the data (2), and the nature and extent of the potential harm that may arise for the data subject in the event of a security breach (3). Following the identification and prioritization of such risks, control and solution alternatives aimed at mitigating or eliminating the relevant risks are evaluated in light of the principles of cost, practicability and effectiveness, and the necessary technical and administrative measures are planned and implemented within the framework of the Law.

Within this scope, the following administrative and technical measures are taken by the University for the protection of personal data:

  • An authorization matrix has been established for employees.
  • User account management and authorization control systems are implemented and regularly monitored.
  • Access logs are regularly maintained.
  • Network security and application security are ensured.
  • Encryption is applied.
  • Penetration tests are conducted.
  • Personal data are backed up, and the security of the backed-up personal data is also ensured.
  • The security of personal data stored in cloud environments is ensured.
  • Firewalls are used.
  • Up-to-date anti-virus systems are used.
  • Log records are maintained in a manner that prevents user intervention.
  • Intrusion detection and prevention systems are used.
  • Key management measures are implemented.
  • Necessary security measures are taken with respect to entry to and exit from physical environments containing personal data.
  • The security of environments containing personal data is ensured.
  • Personal data are deleted, destroyed or anonymized in accordance with the applicable legislation.
  • Cybersecurity measures have been adopted, and their implementation is continuously monitored.
  • Special categories of personal data transferred via e-mail are always sent in encrypted form using a registered electronic mail (KEP) account or a corporate e-mail account.
  • Security measures are taken within the scope of the procurement, development and maintenance of information technology systems.
  • Disciplinary regulations containing data security provisions are in place for employees.
  • Executed agreements contain data security provisions.
  • Confidentiality undertakings are executed.
  • The relevant authorizations of employees whose duties have changed or whose employment has terminated are revoked.
  • Personal data security policies and procedures have been established.
  • Personal data security incidents and issues are promptly reported.
  • Personal data are minimized to the greatest extent possible.
  • Periodic and/or random internal audits are conducted and/or commissioned.

VII. Personal Data Processing Activities Conducted at Building Entrances and Within the Building

Camera Surveillance Activities at Building Entrances and Within the Building

Camera surveillance activities are carried out for the purposes of ensuring security at the entrance, surrounding areas and interior of the building, and protecting the interests relating to the security of the University and other persons. Camera surveillance activities are conducted in compliance with the Law and within the scope of the personal data processing conditions set forth both under the Law and this Policy.

VIII. Retention and Destruction of Personal Data

8.1. Retention and Destruction of Personal Data

Your personal data retained by the University are stored for the period during which the relevant data processing activity is necessary; where an obligation to delete, destroy or anonymize personal data arises, such personal data are deleted, destroyed or anonymized within the first periodic destruction period following the date on which such obligation arises. The deletion, destruction or anonymization of your personal data is carried out in accordance with the general principles set forth under Article 4 of the Law and the technical and administrative measures specified under Article 12 of the Law.

The interval for periodic destruction is limited to a maximum of 1 year. All operations relating to the deletion, destruction or anonymization of personal data carried out by the University are recorded and retained for at least 3 years in accordance with the applicable legal obligations.

The personal data specialist appointed by the University in relation to the retention and destruction of data is responsible for the implementation and supervision of the personal data retention and destruction policy.

8.2. Obligation to Delete, Destroy and Anonymize Personal Data

Personal data processed by the University are deleted, destroyed or anonymized ex officio or upon the request of the relevant data subject where the reasons requiring their processing cease to exist, in accordance with Article 7 of the Law and the provisions of the “Regulation on the Deletion, Destruction or Anonymization of Personal Data” published by the Personal Data Protection Board in the Official Gazette dated 28 October 2017 and numbered 30224.

Deletion of personal data

Deletion of personal data means rendering personal data inaccessible and unusable in any manner whatsoever for the relevant employees. All necessary technical and administrative measures are taken to ensure that deleted personal data remain inaccessible and cannot be reused.

Destruction of personal data

Destruction of personal data means rendering personal data inaccessible, irretrievable and unusable by anyone in any manner whatsoever. All necessary technical and administrative measures are taken to ensure that personal data cannot be accessed, recovered or reused by anyone in any manner whatsoever.

Anonymization of personal data

Anonymization of personal data means rendering personal data incapable of being associated with an identified or identifiable natural person in any manner whatsoever, even when matched with other data. All necessary technical and administrative measures are taken for the anonymization of your personal data, and such data are anonymized by applying methods in accordance with our personal data retention and destruction policy.

8.3. Personal Data Recording Environments

A personal data recording environment refers to any environment in which personal data processed by fully or partially automated means, or by non-automated means provided that such processing forms part of a data recording system, are stored.

Personal data relating to data subjects are securely stored by the University, in accordance primarily with the provisions of the Law and other applicable legislation and within the framework of international data security principles, in the following data recording environments:

  • Technical recording environments: Computer environments, central servers, removable storage media (USB drives, memory cards, etc.), information security devices and software.
  • Non-technical data recording environments: Paper documents, manual data recording systems, written, printed and visual media.

8.4. Reasons Requiring the Destruction of Personal Data

Personal data relating to data subjects are destroyed by the University for purposes and reasons including, but not limited to, the following; the general principles set forth under Article 4 of the Law,

  • Amendment of the relevant legislative provisions forming the basis for the processing,
  • Withdrawal of explicit consent by the data subject where the processing of personal data is based solely on explicit consent,
  • Submission by the data subject of a request for the destruction of personal data,
  • Expiry of legal obligations relating to the retention of personal data,
  • Cessation of the purpose requiring the processing or retention of personal data,
  • Expiry of the maximum retention period applicable to personal data and the absence of any justified reason requiring continued retention.

8.5. Techniques for the Deletion, Destruction and Anonymization of Personal Data

The techniques applied by the University for the deletion, destruction or anonymization of processed personal data are set out below, and the technique to be applied may vary depending on the nature of the personal data concerned.

During the deletion, destruction or anonymization of personal data, necessary administrative and technical measures are taken, including informing employees regarding information security and destruction processes, selecting the most appropriate method according to the nature of the data recording environment in which personal data are stored, conducting regular and periodic maintenance and monitoring activities relating to data security, using the most up-to-date destruction systems required from a technological and technical perspective, issuing automatic deletion commands, and revoking authorization to access, reuse or restore deleted data.

For this purpose, the following methods are applied: (1) first identifying the personal data subject to deletion, destruction or anonymization, (2) identifying the relevant employees for each category of personal data by using an access authorization and control matrix or a similar system, (3) identifying the relevant employees’ access, restoration and reuse authorizations and methods, and (4) disabling and eliminating the relevant employees’ access, restoration and reuse authorizations and methods in relation to the relevant personal data.

Within this scope, depending on the requirements of the circumstances;

  • For the deletion of personal data: methods such as (i) issuing deletion commands in cloud-based or application-based solutions, (ii) redacting, cutting out or otherwise rendering invisible data contained in paper records, and (iii) deleting data stored on portable media by using appropriate software;
  • For the destruction of personal data: methods such as (i) de-magnetizing data by processing the relevant media through specialized devices, (ii) melting, burning or pulverizing optical and magnetic media, (iii) overwriting magnetic media and rewritable optical media by using specialized systems, and (iv) other destruction methods applied to paper-based or electronic media;
  • For the anonymization of personal data: methods such as (i) removing variables from data that may be associated with the data subject, (ii) removing data records containing unique characteristics from the data set, and (iii) applying generalization techniques by converting the relevant personal data from a specific value into a more general value.

IX. Rights of the Personal Data Subject and Exercise of Rights

9.1. Rights of the Personal Data Subject

Pursuant to Law No. 6698, as a data subject, you have the right to;

  • Learn whether your personal data are being processed,
  • Request information if your personal data have been processed,
  • Learn the purpose of the processing of your personal data and whether such data are used in accordance with such purpose,
  • Know the third parties to whom your personal data are transferred domestically or abroad,
  • Request the correction of your personal data where such data have been processed incompletely or inaccurately,
  • Request the deletion or destruction of your personal data within the framework of the conditions set forth under Article 7,
  • Request that the correction of incomplete or inaccurate processing and the deletion or destruction of personal data be notified to third parties to whom the personal data have been transferred,
  • Object to the occurrence of a result against you arising from the analysis of your processed personal data exclusively through automated systems,
  • Claim compensation for damages suffered as a result of the unlawful processing of your personal data.

9.2. Exercise of the Rights of the Personal Data Subject and Our University’s Response to Applications

If, as personal data subjects, you submit your requests regarding your rights through the Data Subject Application Form published at sucool.sabanciuniv.edu or by using the methods specified in the Communiqué on the Procedures and Principles of Application to the Data Controller, the University shall conclude your request free of charge, depending on the nature of the request, as soon as possible and in any event within thirty days at the latest. This period may not exceed 30 days from the date on which your application is served upon the University. Where additional information is requested due to deficiencies or unclear statements in your application, the response period shall be suspended until the relevant additional information and documents are served upon us. If the processing of your application requires any cost, a fee may be charged in accordance with the tariff determined by the Personal Data Protection Board.

Data Controller Information

Data Controller Sabancı University (Tax Identification No: 7360078450)
Address Orta Mahalle, Üniversite Caddesi No: 27, 34956 Tuzla / İstanbul
Contact info@sabanciuniv.edu

Annex 1: Definitions

Explicit Consent Consent relating to a specific matter, based on being informed and expressed with free will.
Anonymization Rendering personal data incapable of being associated with an identified or identifiable natural person in any manner whatsoever, even by matching such data with other data.
Recipient Group The category of natural or legal persons to whom personal data are transferred by the data controller.
Data Subject The natural person whose personal data are processed.
Destruction The deletion, destruction or anonymization of personal data.
Redaction Operations such as crossing out, masking, obscuring or blurring all or part of personal data in a manner that prevents such data from being associated with an identified or identifiable natural person.
Recording Environment Any environment in which personal data processed by fully or partially automated means, or by non-automated means provided that such processing forms part of a data recording system, are stored.
Personal Data Any information relating to an identified or identifiable natural person.
Processing of Personal Data Any operation performed on personal data, such as obtaining, recording, storing, retaining, altering, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, by fully or partially automated means or by non-automated means provided that such processing forms part of a data recording system.
Law / Law on the Protection of Personal Data (“KVKK”) Law No. 6698 on the Protection of Personal Data, which was published in the Official Gazette and entered into force on 7 April 2016.
Board The Personal Data Protection Board.
Authority The Personal Data Protection Authority.
Data Processor The natural or legal person who processes Personal Data on behalf of the data controller, based on the authority granted by the data controller.
Data Recording System The recording system in which personal data are processed by being structured according to specific criteria.
Data Controller The natural or legal person who determines the purposes and means of processing personal data and who is responsible for the establishment and management of the data recording system.

Annex 2: Personal Data Subjects (Data Subjects)

Data Subject Categories Description
Business Partners Refers to natural persons and employees of legal entities with whom the University conducts business, transactions and collaborations for the purpose of carrying out the University’s SuCool activities.
Applicant Refers to natural persons who apply to programs organized by the University.
Entrepreneur Refers to natural persons who apply to programs organized by the University and whose applications are accepted by the University, thereby participating in the relevant program.
Participant Refers to natural persons who apply to participate in the SuCool Entrepreneurship and Incubation Center Community within the University and whose applications are accepted by the University, thereby participating in the program.
Visitor Refers to third parties who visit the University and the University’s website.
Other Relevant Third Parties Refers to natural persons, other than the relevant persons described above, whose personal data are processed by the University.

Annex 3: Third Parties to Whom Personal Data Are Transferred and Purposes of Transfer

Recipient Person/Unit Scope Purpose of Transfer
Legal Advisors / Financial Advisors Parties from whom the University procures services for support in legal and financial matters Transfer of personal data limited to the purpose of procuring services within the scope of establishing, exercising and protecting the University’s legal and financial rights.
Business Partners Domestic and foreign parties with whom business partnerships are established within the scope of the activities conducted by the University Transfer of personal data limited to the purposes of ensuring the performance of activities carried out with business partners and conducting the University’s activities.
Suppliers Parties from whom the University procures services for the purpose of maintaining its activities Transfer of personal data limited to the purpose of procuring services from suppliers providing services such as operation of the technical infrastructure of the website, analysis of visitor usage statistics, e-mail infrastructure and archiving services.
Authorized Public Institutions and Organizations Legal relations between the University and public institutions and organizations authorized by law Transfer of information and documents requested from the University by the relevant public institutions and organizations, limited to the purpose for which such information and documents are requested.