EFG ELECTRIC ENERGY INC.
PERSONAL DATA
RETENTION AND DISPOSAL POLICY
PURPOSE
EFG Electricity Energy Inc. has established this Personal Data Retention and Destruction Policy (“Retention and Destruction Policy”) to ensure the technical and administrative protection of personal data in accordance with the Law on the Protection of Personal Data No. 6698 (“Law”) and, in the event that the conditions for processing personal data no longer exist, the provisions of the Regulation on the Erasure, Destruction, or Anonymization of Personal Data (“Regulation”), published in the Official Gazette on October 28, 2017.
STORAGE MEDIA FOR PERSONAL DATA
Personal data belonging to data subjects is securely stored by Efg Elektrik Enerji A.Ş. in the media listed below, in compliance with the provisions of the Law and other relevant legislation:
Electronic media:
- CRM
- MS SQL Server
- Email Inbox
- Microsoft Office Programs
- Video Recording Devices
Physical Environments:
- Unit Cabinets
- Folders
- Archive
EXPLANATIONS REGARDING THE REASONS FOR RETENTION
Personal data belonging to data subjects is retained by Efg Elektrik Enerji A.Ş. specifically:
- To ensure the continuity of operations,
- To fulfill legal obligations,
- To plan and fulfill employee rights and benefits,
- To manage employment relationships,
and are stored securely in the physical or electronic environments listed above, within the limits specified by the Law and other relevant legislation.
Reasons for retention:
- Personal data is directly related to the conclusion and performance of contracts,
- Personal data being necessary for the establishment, exercise, or protection of a right,
- The existence of a legitimate interest of Efg Elektrik Enerji A.Ş., provided that such processing does not infringe upon the fundamental rights and freedoms of individuals,
- Personal data is necessary for Efg Elektrik Enerji A.Ş. to fulfill any legal obligation,
- The retention of personal data is expressly provided for by law,
- The existence of the data subjects’ explicit consent for retention activities that require such consent.
In accordance with the Regulation, personal data belonging to data subjects shall be deleted, destroyed, or anonymized by Efg Elektrik Enerji A.Ş. either on its own initiative or upon request in the following cases:
- Amendment or repeal of the relevant statutory provisions forming the basis for the processing or storage of personal data,
- The purpose requiring the processing or storage of personal data ceases to exist,
- The conditions requiring the processing of personal data under Articles 5 and 6 of the Law no longer exist.
- In cases where the processing of personal data is based solely on the condition of explicit consent, the data subject’s withdrawal of consent,
- The data controller’s acceptance of the data subject’s request for the erasure, destruction, or anonymization of their personal data within the scope of their rights under Article 11(2)(e) and (f) of the Law,
- In cases where the data controller rejects a request submitted by the data subject for the erasure, destruction, or anonymization of their personal data; where the response provided is deemed insufficient; or where the data controller fails to respond within the timeframe prescribed by the Law; A complaint is filed with the Board and the Board deems the request valid,
- Even though the maximum period for retaining personal data has expired, there are no circumstances that would justify retaining the personal data for a longer period.
MEASURES TAKEN REGARDING THE PROTECTION OF PERSONAL DATA
Efg Elektrik Enerji A.Ş., in accordance with Article 12 of the Law, takes the necessary technical and administrative measures to ensure an appropriate level of security to prevent the unlawful processing of personal data it processes, to prevent unlawful access to such data, and to ensure the protection of the data; within this scope, it conducts or has conducted the necessary audits. In the event that personal data being processed is obtained by third parties through unlawful means despite all technical and administrative measures having been taken, Efg Elektrik Enerji A.Ş. will notify the relevant units of this situation as soon as possible.
4.1 Technical Measures
- Network security and application security are ensured.
- A closed-system network is used for the transmission of personal data over the network.
- Key management is implemented.
- Security measures are implemented in the procurement, development, and maintenance of information technology systems.
- The security of personal data stored in the cloud is ensured.
- Disciplinary regulations containing data security provisions for employees are in place.
- Training and awareness programs on data security are conducted for employees at regular intervals.
- An authorization matrix has been established for employees.
- Access logs are maintained regularly.
- Data masking measures are implemented as needed.
- Corporate policies regarding access, information security, use, storage, and disposal have been developed and implemented.
- Confidentiality agreements are signed.
- The access privileges of employees who change roles or leave the company are revoked.
- Up-to-date antivirus systems are used.
- Firewalls are in use.
- Signed contracts include data security provisions.
- Personal data security policies and procedures have been established.
- Personal data security issues are reported promptly.
- Personal data security is monitored.
- The necessary security measures are taken regarding access to and from physical environments containing personal data.
- The security of physical environments containing personal data against external risks (fire, flood, etc.) is ensured.
- The security of environments containing personal data is ensured.
- Personal data is minimized as much as possible.
- Personal data is backed up, and the security of the backed-up personal data is also ensured.
- A user account management and authorization control system is in place, and these are monitored.
- Periodic and/or random internal audits are conducted and commissioned.
- Log records are maintained without user intervention.
- Current risks and threats have been identified.
- Protocols and procedures regarding the security of special-category personal data have been established and are being implemented.
- If special-category personal data is to be sent via email, it is always sent in encrypted form using KEP or a corporate email account.
- Intrusion detection and prevention systems are in use.
- Cybersecurity measures have been implemented, and their enforcement is continuously monitored.
- Encryption is used.
- Sensitive personal data transferred via removable storage devices, CDs, or DVDs is encrypted before transfer.
- Data processors are audited at regular intervals regarding data security.
- Data security awareness is promoted among data-processing service providers.
- Data loss prevention software is used.
4.2 Administrative Measures
- Employees are trained on the technical measures to be taken to prevent unlawful access to personal data.
- Access and authorization processes for personal data within Efg Elektrik Enerji A.Ş. are designed and implemented in accordance with legal compliance requirements for the processing of personal data at the business unit level. When restricting access, consideration is given to whether the data is sensitive and its level of importance.
- All documents containing personal data that govern the relationship between Efg Elektrik Enerji A.Ş. and its employees must be handled in accordance with the obligations set forth by law to ensure the lawful processing of personal data; personal data must not be disclosed, that personal data must not be used in violation of the law, and that the confidentiality obligation regarding personal data continues even after the termination of the employment contract with Efg Elektrik Enerji A.Ş.
- Employees are informed that they may not disclose personal data they have learned to others in violation of the provisions of the Law, nor may they use such data for purposes other than those for which it was processed, and that this obligation continues even after they leave their positions; accordingly, the necessary commitments are obtained from them.
- Contracts entered into by Efg Elektrik Enerji A.Ş. with parties to whom personal data is lawfully transferred include provisions stipulating that such parties shall take the necessary security measures to protect personal data and ensure compliance with these measures within their own organizations.
- In the event that processed personal data is obtained by others through unlawful means, the company notifies the relevant parties and the Board of this situation as soon as possible.
- Where necessary, the company employs knowledgeable and experienced personnel regarding the processing of personal data and provides its personnel with training on personal data protection legislation and data security.
- Efg Elektrik Enerji A.Ş. conducts and commissions the necessary audits to ensure compliance with the provisions of the Law. It addresses any privacy and security vulnerabilities identified as a result of these audits.
MEASURES TAKEN REGARDING THE DESTRUCTION OF PERSONAL DATA
Efg Elektrik Enerji A.Ş. may delete or destroy personal data—even if it has been processed in accordance with the relevant provisions of the law—at its own discretion or upon the request of the data subject, should the reasons necessitating its processing no longer exist. Following the deletion of personal data, the relevant individuals will under no circumstances be able to access or use the deleted data again. Efg Elektrik Enerji A.Ş. will manage an effective data tracking process regarding the definition and monitoring of personal data destruction procedures. The process will proceed in the following order: identification of the data to be deleted, identification of the relevant individuals, determination of the individuals’ access methods, and immediate deletion of the data.
Efg Elektrik Enerji A.Ş. may use one or more of the methods listed below to destroy, delete, or anonymize personal data, depending on the medium on which the data is stored:
Methods for the Deletion, Destruction, and Anonymization of Personal Data
- Deletion of Personal Data
The deletion of personal data is the process of rendering personal data inaccessible and unusable by relevant users in any way. As a method for deleting personal data, Efg Elektrik Enerji A.Ş. may use one or more of the following methods:
- Personal data on paper will be processed by blacking out, painting over, cutting out, or erasing it.
- For office files stored in the central file system, the user(s)’ access rights will be revoked.
- Rows or columns containing personal information in databases will be deleted using the “Delete” command.
When necessary, a specialist will be consulted to ensure secure deletion.
Destruction of Personal Data
The destruction of personal data is the process of rendering personal data inaccessible, irrecoverable, and unusable by anyone in any way through the following methods.
- Physical Destruction
- Destruction Using a Paper Shredder
- Demagnetization: This method involves passing magnetic media through specialized devices that expose it to high magnetic fields, thereby corrupting the data on it to the point where it becomes unreadable.
Anonymization of Personal Data
Anonymization of personal data refers to the process of rendering personal data incapable of being associated with any identified or identifiable natural person, even when combined with other data. Efg Elektrik Enerji A.Ş. may use one or more of the methods listed below to anonymize personal data:
- Masking: Masking is a method of anonymizing personal data by removing its key identifying information from the dataset.
- Record Removal: In the record removal method, data rows containing unique identifiers are removed from the dataset, thereby rendering the stored data anonymous.
- Regional Masking: In the regional masking method, if a single piece of data has identifying characteristics due to creating a very rare combination, masking that data ensures anonymization.
- Global Encoding: Using the data derivation method, a more general content is created from the content of the personal data, ensuring that the personal data can no longer be linked to any specific individual. For example, specifying ages instead of birth dates; specifying the region of residence instead of a full address.
- Noise Addition: The method of adding noise to data—particularly in datasets dominated by numerical data—anonymizes the data by adding deviations in the positive or negative direction at a specified rate to the existing data. For example, in a dataset containing weight values, applying a deviation of ±3 kg prevents the actual values from being identified and anonymizes the data. The deviation is applied equally to each value.
In accordance with Article 28 of the Law, anonymized personal data may be processed for purposes such as research, planning, and statistics. Such processing falls outside the scope of the Law, and the explicit consent of the data subject will not be required.
Efg Elektrik Enerji A.Ş. may make its own decision regarding the deletion, destruction, or anonymization of personal data and may freely determine the method to be used according to the category it has selected. Furthermore, under Article 13 of the Regulation, if the data subject selects one of the categories—deletion, destruction, or anonymization—of their personal data during the application process, Efg Elektrik Enerji A.Ş. will retain discretion regarding the methods to be used within the selected category.
RETENTION AND DISPOSAL PERIODS FOR PERSONAL DATA
Efg Elektrik Enerji A.Ş. retains personal data for the purposes for which it is processed for the periods specified in Appendix 1. If legislation stipulates a specific retention period for the personal data in question, that period will be adhered to. In the absence of a period specified by law, personal data will be retained for the maximum period set forth in the table in Appendix 1. These periods are determined based on an assessment of Efg Elektrik Enerji A.Ş.’s data categories and data subject groups; and were determined to ensure compliance with legal obligations and in accordance with the maximum statute of limitations period (10 years) set forth in the Turkish Code of Obligations.
In the event that the obligation to delete, destroy, or anonymize personal data arises upon the expiration of these periods, Efg Elektrik Enerji A.Ş. will delete, destroy, or anonymize the personal data during the first periodic data destruction process following that date.
All operations related to the erasure, destruction, and anonymization of personal data are recorded, and such records are retained for at least three years, except where other legal obligations apply.
PERIODIC DISPOSAL SCHEDULES
Pursuant to Article 11 of the Regulation, the periodic destruction period has been set at 6 months. Accordingly, periodic destruction is carried out in June and December of each year. In these systems, data will be permanently deleted in such a way that it cannot be recovered from any media on which it was stored, such as documents, files, CDs, floppy disks, or hard drives.
PERSONNEL
Under the Law, Efg Elektrik Enerji A.Ş., acting as the data controller, pursuant to Article 11, Paragraph 1 of the Regulation, the titles, departments, and job descriptions of the personnel responsible for fulfilling the obligations regarding the implementation of the data retention and destruction process under the Law are specified in the table in Appendix 2 of the Retention and Destruction Policy.
These designated individuals are responsible for the transactions and actions carried out within their respective authority limits under the Turkish Commercial Code, the Turkish Code of Obligations, and the Turkish Penal Code. In particular, the Chair of the Efg Elektrik Enerji A.Ş. Personal Data Protection Committee has been appointed as the authorized representative of Efg Elektrik Enerji A.Ş. to appear and testify before law enforcement agencies, public prosecutor’s offices, public institutions, and courts. Each department head is responsible for monitoring whether the relevant users within their departments are acting in accordance with the Retention and Destruction Policy and the Personal Data Policy, which were prepared in accordance with the Law and Regulations. All department heads shall report to the Chair of the Efg Elektrik Enerji A.Ş. Personal Data Protection Committee on the actions they have taken in accordance with this Retention and Destruction Policy within the specified periodic destruction timeframes. The decisions resulting from the analysis of these reports shall be implemented.
REVISION AND REPEAL
In the event of any amendment or repeal of this Retention and Destruction Policy, the new regulation will be announced on the Efg Elektrik Enerji A.Ş. website.
ENTRY INTO FORCE
This Retention and Destruction Policy enters into effect on the date of its publication.
APPENDICES
APPENDIX 1—Data Retention and Destruction Periods
APPENDIX 2—Table of Personnel Responsible for Personal Data Retention and Destruction
APPENDIX 1—Data Retention and Destruction Periods
| Data Category | Retention Period | Destruction Period |
|---|---|---|
| Identity | 10 years from the transaction date or the termination of the legal relationship | During the first periodic destruction period following the end of the retention period |
| Communication | 10 years from the transaction date or the termination of the legal relationship | During the first periodic destruction period following the expiration of the retention period |
| Location | 10 years from the transaction date or the termination of the legal relationship | During the first periodic destruction cycle following the expiration of the retention period |
| Personnel Records | 10 years from the termination of employment | During the first periodic destruction cycle following the expiration of the retention period |
| Legal Proceedings | 5 years from the date the court decision becomes final | During the first periodic destruction period following the expiration of the retention period |
| Legal Proceedings | 10 years from the date of the transaction or the termination of the legal relationship | During the first periodic destruction period following the expiration of the retention period |
| Customer Transaction | 10 years from the transaction date or the termination of the legal relationship | During the first periodic destruction cycle following the end of the retention period |
| Physical Premises Security | 30 days | During the first periodic destruction cycle following the end of the retention period |
| Transaction Security | 10 years from the transaction date or the termination of the legal relationship | During the first periodic destruction period following the end of the retention period |
| Risk Management | 10 years from the transaction date or the termination of the legal relationship | During the first periodic destruction cycle following the end of the retention period |
| Finance | 10 years from the transaction date or the termination of the legal relationship | During the first periodic destruction cycle following the end of the retention period |
| Professional Experience | 10 years from the termination of employment | During the first periodic destruction period following the end of the retention period |
| Marketing | 10 years from the end of employment | During the first periodic destruction period following the end of the retention period |
| Visual and Audio Recordings | 10 years from the transaction date or the termination of the legal relationship | During the first periodic destruction period following the expiration of the retention period |
| Union Membership | 10 years from the termination of employment | During the first periodic destruction cycle following the expiration of the retention period |
| Health Information | 15 years | During the first periodic destruction period following the end of the retention period |
| Criminal Convictions and Security Measures | 10 years from the termination of employment | During the first periodic destruction period following the expiration of the retention period |
| Family Information | 10 years | During the first periodic destruction period following the end of the retention period |
| Work Data | 10 Years | At the first periodic destruction date following the end of the retention period |
| Website Usage Data | 2 years | At the first periodic destruction date following the expiration of the retention period |
| Request/Complaint Management Information | 2 Years | During the first periodic destruction period following the expiration of the retention period |
| Reputation Management Information | 10 Years | During the first periodic destruction period following the end of the retention period |
| Incident Management Information | 2 Years | During the first periodic destruction period following the end of the retention period |
| Signatures | 10 years | During the first periodic destruction period following the expiration of the retention period |
| Insurance Information | 10 years from the end of employment | During the first periodic destruction period following the end of the retention period |
| Vehicle Information | 10 years | During the first periodic destruction period following the end of the retention period |
| Compliance Information | 10 Years | During the first periodic destruction period following the end of the retention period |
| Audit and Inspection | 10 Years | During the first periodic destruction period following the end of the retention period |
| Foreign Residence Permit Information | 10 years from the end of employment | During the first periodic destruction period following the expiration of the retention period |
APPENDIX 2—Table of Personnel Responsible for Personal Data Retention and Destruction
| Staff | Position | Responsibility |
|---|---|---|
| Personnel Supervisor | Implementation Officer | Ensuring that processes within their scope of responsibility comply with retention periods and managing the personal data destruction process in accordance with periodic destruction schedules |
| Administrative and Financial Affairs Officer | Application Officer | Ensuring that processes within the scope of their duties comply with retention periods and managing the personal data destruction process in accordance with periodic destruction schedules |
| Data Protection Officer | Ensuring that processes within the scope of the role comply with retention periods and managing the personal data disposal process in accordance with periodic disposal schedules |