Storage and destruction of personal data
In a digitizing world, personal data has become the most important commodity. Accessing and processing personal data is of critical importance for both companies wanting to reach consumers and for fraudsters. This makes the storage and destruction of personal data indispensable. Attorney Öykü Ergün wrote about the laws and regulations prepared on this subject for 12punto.
When shopping, browsing the internet, or downloading applications, we always provide our personal data to the other party, whether intentionally or unintentionally. The data we provide is processed and presented to us either as advertising or as a method of fraud. For this reason, the storage and destruction of personal data is of great importance for personal security. Attorney Öykü Ergün wrote about the laws and regulations regarding the KVKK for 12punto.
Ergün's article is as follows:
The primary source regarding the storage and destruction of personal data is the Personal Data Protection Law No. 6698 (“KVKK”), followed by the Regulation on the Erasure, Destruction or Anonymization of Personal Data (“Regulation”) published in the Official Gazette dated 28.10.2017 and numbered 30224, and the Guide on the Erasure, Destruction or Anonymization of Personal Data (“Guide”) prepared by the Personal Data Protection Authority (“Authority”). In line with the aforementioned legislation, it can be determined how an employee's personal data will be stored and how it should be destroyed when necessary.
In order to determine the details of how and in what manner the destruction of personal data will take place and to ensure procedural uniformity, the Regulation on the Erasure, Destruction or Anonymization of Personal Data was published in the Official Gazette dated 28.10.2017 and numbered 30224.
Article 4 of the Regulation uses the terms erasure, destruction, or anonymization of data when explaining the destruction of personal data.
The erasure of personal data refers to the process of making personal data inaccessible and unusable for relevant users in any way. The issue of how the erasure process will be carried out is not regulated in the Regulation. It is only stated that the data controller must take the necessary technical and administrative measures for the erasure process. For this reason, the employer can ensure that the data is erased by using a deletion method chosen in accordance with the procedure in which it is stored. As stated in the Guide, if the data is saved in a cloud system, a delete command must be given, and if it is in paper format, it must be erased by applying a redaction process.
For the destruction of personal data, the physical destruction of the document or hardware containing the data is required.
The anonymization of personal data is slightly different from the other two concepts. In the Regulation, the anonymization of personal data is defined as making personal data impossible to be associated with an identified or identifiable natural person under any circumstances, even if it is matched with other data. According to the Guide, anonymization is the process of preventing the identification of the relevant person by removing or changing all direct and/or indirect identifiers in a data set, or losing the feature of being distinguishable within a group or crowd in a way that cannot be associated with a natural person. In other words, anonymous data is data that has been completely disconnected from the person. Statistical information published by TURKSTAT every year can be cited as an example of this, as can the results of studies known in the public as election polls, which reflect the political preferences of the public, which are also in the nature of anonymous data.
Although Article 7 of the KVKK given below is a general provision regarding the destruction of personal data, there are different regulations in different laws, especially for destruction periods.
“Erasure, destruction or anonymization of personal data”
ARTICLE 7- (1) Even if it has been processed in accordance with the provisions of this Law and other relevant laws, personal data shall be erased, destroyed or anonymized by the data controller ex officio or upon the request of the relevant person in the event that the reasons requiring its processing disappear.
(2) The provisions in other laws regarding the erasure, destruction or anonymization of personal data are reserved.
(3) The procedures and principles regarding the erasure, destruction or anonymization of personal data are regulated by regulation.”
For example; pursuant to Article 7/1 of the Regulation on Occupational Health and Safety Services, “The employer shall keep the personal health files of employees for at least 15 years from the date of termination of employment”, and pursuant to Article 17 of the Regulation on Health and Safety Measures in Working with Carcinogenic or Mutagenic Substances, the updated list of employees working in jobs that are risky in terms of health and safety, records indicating their exposure status, and health surveillance records “shall be kept for at least 40 years after the exposure ends.”
Again, in this regard, for the purpose of being more general, regarding the storage of employee personnel files; the 2nd paragraph of Article 86 of the Social Insurance and General Health Insurance Law states: “Employers and workplace owners are obliged to keep workplace books, records and documents for ten years starting from the beginning of the year following the year to which they relate, public administrations for thirty years, and liquidation and bankruptcy administration officers for the duration of their duties, and to present them within fifteen days if requested by the officers assigned with the audit and control of the Institution.” If the employer acts contrary to this provision, an administrative fine is imposed on them.
Within the framework of the Labor Law (“LL”), the statute of limitations can be used as a criterion for the period during which the employee's personal data will be stored. Considering that the statute of limitations for disputes that may arise between the employee and the employer after the termination of the employment relationship and based on the receivables listed in Additional Article 3 of the LL is 5 years, it would be appropriate to store the employee's data during this period. For receivables not listed in Additional Article 3 of the LL, the general statute of limitations of 10 years is applied.
Another issue that should be mentioned regarding the storage of employee data is what happens to the collected data if the recruitment process does not result positively. Here, it is necessary to talk about purpose-appropriateness. If there is no law-based purpose for storing the data of the person applying for a job after the job application results negatively, the data must be deleted immediately. However, there may be some reasons that require the storage of this data here. For example; if the person applying for a job thinks that they have been discriminated against and wants to use their legal rights for this reason, it will be necessary to store the data. In this case, permission will be granted for the data to be stored by observing the statutes of limitations for legal applications.
If the job application process results positively, it will be discussed which of the employee's data should be stored during the performance of the work. There may be no reason left to process some of the data processed during the job application process during the work; in this case, the destruction of the data will be required.
Personal data must be destroyed in cases where the reasons requiring their processing disappear, even if they have been processed in accordance with the law. This can happen ex officio or in line with the request of the person whose data is processed. With the disappearance of the situation requiring processing, the responsibility for the destruction of this data arises for the data controller. The owner of the personal data may request the destruction of their data in case of negligence by the data controller.
A similar right to the right of rectification and the right to erasure, also known as the right to be forgotten, regulated in Articles 16 and 17 of the European Union General Data Protection Regulation, is also regulated in Articles 11/e and 7 of the KVKK. Accordingly; in the event that the reasons requiring the processing of data disappear, the data controller erases the personal data ex officio or upon the request of the relevant person.
According to Article 5 of the Regulation, data controllers who are obliged to register with the Data Controllers Registry pursuant to Article 16 of the KVKK are obliged to prepare a personal data storage and destruction policy in accordance with the personal data processing inventory. Who will be obliged to register with the Data Controllers Registry is regulated in Article 16/2 of the KVKK.
“Natural and legal persons who process personal data are obliged to register with the Data Controllers Registry before starting data processing. However, an exception to the obligation to register with the Data Controllers Registry may be brought by the Board, taking into account objective criteria to be determined by the Board, such as the nature and number of the personal data processed, the fact that data processing stems from the law, or the situation of transfer to third parties.”
Article 6 of the Regulation regulates what the scope of the policies will be. According to this article, the elements that should be included in the policies can be listed as follows; the purpose of preparing the policy, the recording environments regulated by the policy, the definitions of legal and technical terms included in the policy, the explanation of the legal, technical and other reasons requiring the storage and destruction of personal data, the measures taken to ensure the secure storage of personal data and to prevent unlawful processing and access, the measures taken for the lawful destruction of personal data, the titles, units and job descriptions of those involved in the storage and destruction stages of personal data, the table showing the storage and destruction periods of personal data, the periodic destruction periods of personal data, and information regarding the change if an update has been made to the current policy. It should be noted that the fact that the employer has prepared the policy in accordance with the procedure does not mean that they have destroyed the personal data in accordance with the law.
Regarding the periods determined for the destruction process, the employer who is obliged to prepare a Personal Data Storage and Destruction Policy will destroy this data in the first periodic destruction process following the date on which the responsibility to erase, destroy or anonymize personal data arises, and the periodic destruction time interval specified in the policy cannot exceed six months.
Employers who are not obliged to organize a Personal Data Storage and Destruction Policy are obliged to destroy personal data ex officio within three months from the moment the destruction of this data is required. These periods may be shortened by the Personal Data Protection Board in case of irreparable or impossible damages and clear illegality.
In the case of the destruction of data upon the request of the person, according to Article 12 of the Regulation, if the relevant person, i.e., the person whose job application was rejected or whose employment contract was terminated, applies to the employer and requests the destruction of their data, the employer is obliged to conclude this application within 30 days at the latest and inform the employee. If the conditions for processing personal data have not disappeared, the employer will be able to reject the employee's request, provided that they state the justification. The rejection response is notified to the employee in writing or electronically within thirty days at the latest. It is useful to examine the decision of the Personal Data Protection Board given below regarding the subject.
“…Upon the negative result of the job application made by the relevant person to the data controller, the request for the erasure of the personal data processed by the data controller was first partially accepted by the data controller and the processing of name, surname and identity information continued, and then, as a result of the evaluation made following the second application made by the relevant person to the data controller in the same context, the notification that the decision was made that the data in question would be destroyed in the first periodic destruction process to be carried out within the framework of the data controller's destruction policy, therefore, despite the request of the relevant person, the fact that their personal data was not erased within 30 days in accordance with Article 12 of the Regulation on the Erasure, Destruction or Anonymization of Personal Data, and the continued processing of the relevant person's personal data without relying on any processing condition included in Article 5 of the Law, led to the conclusion that the data controller did not take the necessary technical and administrative measures to ensure an appropriate level of security to prevent the unlawful processing of personal data within the scope of the first paragraph of Article 12 of the Law, therefore, it was decided to impose an administrative fine on the data controller in accordance with subparagraph (b) of the first paragraph of Article 18 of the Law…” (Decision dated 06.07.2021 and numbered 2021/670)
In the event subject to the decision, a candidate whose job application resulted negatively applied to the employer for the erasure of their personal data, but the employer replied that they would not erase the data immediately, but at the time of the first periodic destruction. Upon this, the Personal Data Protection Authority decided that an administrative fine should be imposed on the data controller.
Attorney Öykü Ergün
News Source: 12punto
Most Read
Historic words from Özgür Özel at the CHP group meeting
Air Force Academy student Veli Bilgin has died
Tuncer Bakırhan calls for a framework law
How did the newspapers view Özgür Özel's farewell to the CHP?
He killed his wife by slitting her throat: Their children witnessed the moments
The PKK opening and Özgür Özel’s path!..
Here are the names that will be in Özgür Özel's new party!
AKP mayor held responsible
Kılıçdaroğlu's 'controlled' shopkeeper visit
Güler leaves questions regarding Özgür Özel unanswered