Dr. Abdurrahman Efem — Personal Data Security Directive
1. Introduction
This Personal Data Security Directive (the “Directive”) has been prepared for Efem Clinic, operated by Dr. Abdurrahman Efem, taking into account the scope of personal data security and the associated risks.
The purpose of this Directive is to establish and regulate the measures and implementation processes arising from the Clinic’s data security policies, to support compliance with the obligations set out under the Turkish Personal Data Protection Law No. 6698 (“KVKK”), and to provide further detail regarding the administrative and technical measures referred to in the “Abdurrahman Efem Personal Data Processing, Protection and Destruction Policy.”
2. Scope
This Directive applies to the business operated by Dr. Abdurrahman Efem and covers all information technology hardware used within the business, including computers, servers, laptops, network equipment and network-connected data storage devices; software, including operating systems; portable hardware, including external storage devices and mobile phones; communication channels, including email, written and voice messaging and digital voice communication; and the management of social media accounts.
It also covers the responsibilities of employees in relation to these systems and the technical and administrative measures required to protect personal data in all activities and operational processes involving the processing of personal data.
3. Risk Analysis
The following risks relating to data security at Efem Clinic have been identified. The measures set out in this Directive are intended to reduce and manage these risks:
-
Physical security
-
Unauthorised access to computers
-
Data backup and recovery
-
Cyber intrusion and unauthorised digital access
-
Attacks targeting social media accounts
-
Unauthorised access to information stored on smartphones
-
Email security and use
-
Compliance with the legal conditions applicable to personal data processing
-
Unauthorised transfer or disclosure of personal data to third parties
-
Employee training and data security awareness
4. Personal Data Security Measures
I. Technical Measures
-
User access controls are applied to computers belonging to Efem Clinic. Passwords assigned to computers are kept securely and are not shared between employees. Passwords are recommended to contain at least eight characters and include uppercase and lowercase letters, numbers and special characters. “Remember me” functions are not used where this may create a security risk. Passwords are changed at approximately six-month intervals.
-
A hardware and software inventory is maintained for all information technology hardware and software used by Efem Clinic (“Annex 1 — Hardware and Software Inventory”). Reasonable care is taken to keep this inventory up to date.
-
Automatic screen-locking functions are enabled on computers, with the automatic lock timer set to one minute. A clear-screen principle is applied to reduce the risk of unauthorised access to information displayed on unattended devices.
-
Data processed within the Clinic is stored in the Estesoft Stella system. Data stored on the server is automatically backed up outside Efem Clinic. Server backups are transferred to a cloud-based system supporting SSL/TLS encryption. An automatic email notification system is used to support monitoring of the backup process.
-
As individual employee computers are not separately backed up, employees are required to save and regularly maintain their work files in the designated storage area provided for this purpose.
-
Files, internet browsing histories and saved web portal credentials on employee computers are reviewed and cleared at regular intervals where appropriate for data security.
-
Operating systems and antivirus software are kept up to date. Update status is reviewed at least every six months.
-
Social media account credentials are not stored on computers. Except for specifically authorised employees, Clinic social media accounts are not installed or configured on employees’ personal mobile phones. Social media account passwords are updated every six months.
-
Email communications are conducted through Gmail using SSL/TLS-supported connections. Teleconferencing and digital voice communications may be conducted through services supporting SSL/TLS or equivalent secure transmission protocols, including WhatsApp, Google Meet, Zoom, Jitsi or Skype.
-
Digital written and verbal communications conducted internally within Efem Clinic or with third parties are carried out using communication methods that provide appropriate transport-layer security.
II. Administrative Measures
-
The implementation of personal data security measures is supported by Dr. Abdurrahman Efem, and the resources reasonably required for their implementation are provided. This Directive is communicated to employees and made accessible within the Clinic. Information security and personal data security awareness training is organised at regular intervals.
-
Personal data is processed, protected, retained and destroyed in accordance with KVKK, applicable legislation and the Clinic’s relevant personal data policies.
-
Employees receive annual awareness training, normally during December, regarding KVKK, the Clinic’s personal data policies and the scope, principles and implementation of this Directive.
-
Where use contrary to this Directive or a personal data security incident occurs, a root-cause analysis is conducted with the aim of preventing recurrence. Where necessary, the relevant measures under this Directive are reviewed and revised in order to address the identified root cause.
-
All employees are informed of the measures they are required to follow regarding the confidentiality and security of personal data, together with their confidentiality obligations. Employment arrangements for employees commencing work after the effective date of this Directive contain appropriate provisions relating to data security obligations and disciplinary requirements.
-
Upon termination of employment, all access rights of the departing employee are revoked without undue delay, including access to documents containing personal data and to physical or electronic locations in which such documents are stored.
-
Personal data is processed only to the extent necessary for the activities of Efem Clinic and, where possible, data processing is limited in accordance with the principle of data minimisation.
-
Service agreements and other relevant contracts entered into by Efem Clinic include provisions relating to the confidentiality and security of personal data where appropriate.
-
Periodic and/or random internal audits may be carried out by an authorised person in order to assess compliance with personal data protection and data security requirements.
-
Templates for explicit consent and informed consent, prepared in accordance with applicable personal data processing requirements, are used by employees involved in relevant data processing activities. Explicit consent and informed consent documents obtained from data subjects are classified according to their subject matter and retained in accordance with applicable requirements.