ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. takes all necessary technical and administrative measures to ensure an appropriate level of security in order to prevent the unlawful processing of personal data, prevent unlawful access to personal data and ensure the retention of personal data.
6.1. Within the Scope of the Technical Measures Recommended by the Personal Data Protection Authority;
Ensuring Cyber Security
- Priority measures that can be taken to protect information technology systems containing personal data against unauthorised access threats from the internet;
- Ensuring that access to systems containing personal data is also restricted, granting employees limited access rights, and providing access to the relevant systems by means of a username and password,
- Additionally, to protect against malicious software, using products such as antivirus and antispam that regularly scan the information system network and detect threats.
Monitoring Personal Data Security
- In order to prevent information processing systems from being exposed to attacks from both inside and outside, to cybercrime or to malicious software, and to be able to forestall such situations;
- Checking which software and services are running on the IT networks.
- Determining whether there has been any intrusion into the IT networks.
- Keeping records of the transaction activities of all users (such as log records).
- Reporting security problems as quickly as possible.
Ensuring the Security of Media Containing Personal Data
- Ensuring the physical security of devices containing personal data (laptops, mobile phones, flash drives, etc.) where personal data security breaches may occur,
- Sending personal data to be transferred by e-mail or post with adequate measures in place.
- To ensure personal data security, keeping paper documents containing personal data, servers, backup devices and devices such as CDs, DVDs and USBs in sections/rooms with additional security measures and restricted entry authorisation.
- Also taking measures such as keeping these areas locked when not in use and keeping entry and exit records.
Storage of Personal Data in the Cloud
- Managing the risks relating to the processing of personal data by cloud storage service providers.
- Assessment and approval by the data controller of whether the security measures taken by the cloud storage service provider are also adequate and appropriate.
- In this context, knowing in detail what personal data is stored in the cloud, backing it up, ensuring synchronisation and applying authentication controls.
Backup of Personal Data
- Ensuring that backed-up personal data is accessible only by the system administrator.
- Always keeping data set backups off the network.
- Taking measures against the use of malicious software on data set backups.
- Ensuring the physical security of all backups.
Procurement, Development and Maintenance of Information Technology Systems
- If devices sent to third parties such as manufacturers, vendors or service providers because they have malfunctioned or are due for maintenance contain personal data, ensuring the security of the personal data before these devices are sent for maintenance and repair.
- Removing and retaining the data storage medium in the devices.
- Carrying out procedures such as sending only the faulty parts.
- If external personnel have come for purposes such as maintenance and repair, preventing them from copying personal data and taking it outside the organisation.
In relation to the requirement to implement these Technical Measures, ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. applies the following technical measures;
- Authorisation Matrix.
- Authorisation Control.
- Access Logs.
- User Account Management.
- Network Security.
- Application Security management.
- Encryption management.
- Log Records.
- Data Masking.
- Backup management.
- Up-to-date Anti-Virus Systems management.
- Deletion, Destruction or Anonymisation.
6.2. Within the Scope of the Administrative Measures Recommended by the Personal Data Protection Authority;
Identifying Existing Risks and Threats
- To ensure the security of personal data, what all the personal data processed by the data controller is,
- Correctly determining the likelihood of the risks that may arise in relation to the protection of this data and the losses they would cause if they materialised,
- Measures appropriate to this must be taken.
Employee Training and Awareness Activities
- Receiving training on matters such as not unlawfully disclosing or sharing personal data.
- Carrying out awareness activities for employees and creating an environment in which security risks can be identified, thereby ensuring personal data security.
- Roles and responsibilities regarding personal data security should be defined in job descriptions, and employees should be made aware of their roles and responsibilities in this regard.
- Acting in accordance with the principle of “Everything Is Forbidden Unless Permitted” when granting access rights to media containing personal data.
Determining Personal Data Security Policies and Procedures; Minimising Personal Data as Far as Possible; Managing Relations with Data Processors
In relation to the requirement to implement these Administrative Measures, ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. applies the following administrative measures;
- Preparation of a Personal Data Processing Inventory
- Corporate Policies (Antivirus, E-mail, Physical Security, Backup, etc.)
- Contracts (Data Controller – Data Controller / Data Controller – Data Processor Confidentiality Undertakings, etc.)
- Periodic and/or Random Internal Audits
- Risk Analyses
- Employment Contract, Disciplinary Regulations (Addition of Provisions Compliant with the Law, etc.)
- Corporate Communication (Crisis Management, Processes for Informing the Board and the Data Subject, etc.)
- Training and Awareness Activities (Information Security and the Law)
- Notification to the Data Controllers’ Registry Information System (VERBİS)