Document Code: POL-DATA-PROTECTION
Title: Data Protection Policy
Version: v1.0
Date: 2025-11-30
Owner: Legal & Compliance / IT Security
Approved By: CEO
Classification: Internal
The purpose of this policy is to establish the principles for collecting, processing, storing, transferring, and deleting personal data in compliance with applicable data protection regulations, including GDPR and KVKK.
It defines the organization’s obligations and the responsibilities of all personnel when handling personal data.
This policy applies to:
The organization adheres to the following principles:
Processing activities must rely on one or more of the following legal bases:
No processing may occur without an identified legal basis.
Data subjects have the following rights:
The organization must respond to requests within legally required deadlines.
Data subjects have the following rights:
The organization must respond to requests within legally required deadlines.
Employees using BYOD devices must:
In case of suspected or confirmed data breach:
Employees:
IT Security:
HR / Legal:
v1.0 – 2025-11-30 – Initial version created