1. Purpose
The purpose of this Policy is to ensure the secure storage of personal data processed by Medicus Clinic Özel Sağlık Hizmetleri ve Tic. Ltd. Şti. (“Medicus Clinic” or “Company”) for the period required by the purposes and legal grounds for processing, and to determine the procedures, principles, responsibilities and control mechanisms for deleting, destroying or anonymizing personal data in case all processing conditions are eliminated.
2. Scope
This Policy covers the following groups of relevant persons whose personal data are processed within the scope of Medicus Clinic's activities and the electronic or physical records belonging to these persons:
- Patients, prospective patients, patient relatives and companions;
- Employees, former employees, interns and prospective employees;
- Visitors;
- Suppliers, service providers, consultants and their authorized/employees;
- Legal representatives and authorized third parties.
3. Legal Basis
The Policy has been prepared by taking into account the Personal Data Protection Law No. 6698 (“KVKK”), the Regulation on Deletion, Destruction or Anonymization of Personal Data, special legislation on health services and personal health data, and labor, social security, tax, trade, occupational health and safety and other applicable legislation. If a longer or special storage period is stipulated in special legislation, the relevant special regulation is applied first.
4. Definitions
Anonymization: Making personal data unable to be associated with an identified or identifiable natural person, even if it is matched with other data.
Destruction: Deletion, destruction or anonymization of personal data.
Relevant person: The real person whose personal data is processed.
Relevant user: The person who processes personal data within the Company or on the instructions of the Company, other than those responsible for the technical storage, protection and backup of data.
Recording environment: It is the environment in which personal data is stored by fully/partially automatic or non-automatic means, provided that it is part of the data recording system.
Periodic destruction: It is the ex officio destruction process carried out at recurring intervals specified in the Policy in case all personal data processing conditions are eliminated.
Deletion: Making personal data inaccessible and unusable for the relevant users in any way.
Destruction: Making personal data inaccessible, irretrievable and unusable by anyone.
5. Basic Principles
- Personal data is kept accurate and updated when necessary, in accordance with the law and the rules of honesty.
- Data for specific, clear and legitimate purposes; It is processed in a limited and measured manner in connection with the purpose.
- Data are retained for the period stipulated in the relevant legislation or necessary for the purpose for which they are processed.
- When all processing conditions are eliminated, the data is deleted, destroyed or anonymized in accordance with the applicable legislation.
- Stricter access, authorization and security measures are applied for health data and other special personal data.
6. Personal Data Recording Environments
- Electronic patient/clinical information systems, appointment and registration systems;
- Servers, computers, portable enterprise devices and authorized cloud/hosting environments;
- Email, corporate communication and support systems;
- Human resources, payroll, PDKS and accounting systems;
- CCTV/camera recording systems;
- Website, log records and cookie/preference records;
- Physical patient files, personnel files, contracts, forms, minutes and archives;
- Backup media and other recording media that comply with the legislation.
7. Contact Groups and Data Categories
| Contact person | Major data categories |
|---|---|
| Patient / patient relative | Identity, communication, health, appointment, examination, diagnosis, examination, treatment, prescription, finance, insurance/SGK, transaction security, visual recording and, where necessary, legal transaction data. |
| Employee / candidate | Identity, communication, personnel, payroll/finance, SGK, PDKS, training, performance, leave, OHS/health, discipline, camera and legal transaction data. |
| visitor | Entry-exit, identity/communication when necessary, camera footage and security/event records. |
| Supplier / service provider | Authorized/employee identity and contact information, contract, offer, invoice, payment/bank, correspondence, access and legal transaction records. |
8. Reasons for Storage
- Providing healthcare services, ensuring the integrity of patient records and continuity of care;
- Fulfillment of legal obligations, official notification and audit obligations;
- Obligations arising from the establishment, execution and termination of contracts;
- Labor and social security, tax, accounting, trade and OHS obligations;
- Establishment, exercise or protection of a right and management of legal disputes;
- Ensuring information and physical space security;
- In activities based on the valid explicit consent of the relevant person, the period during which the explicit consent is valid.
9. Reasons Requiring Destruction
Destruction is evaluated in cases such as the disappearance of the legal reason or purpose requiring the processing of personal data, expiration of the storage period, withdrawal of consent in processing based on explicit consent and the absence of any other processing condition, change in the relevant legislation or justified request of the relevant person. If another legal storage obligation remains, the data is blocked/restricted for use only for the relevant purpose; It is not destroyed before the mandatory storage period expires.
10. Determination of Storage Periods
Storage periods are determined based on the data category, processing purpose and legal reason. This Policy alone does not provide for a fixed number of years for all registrations. Special periods in the relevant health legislation, especially for patient and health records; labor, SSI, tax and OHS legislation in employee records; Contractual, trade and tax obligations are taken into account in supplier records. The table below shows the storage logic to be implemented with Medicus Clinic's data inventory; Lines that require a precise period are verified with the relevant legislation and the actual system inventory and recorded in the corporate storage schedule.
11. Storage and Disposal Periods Table
| Registration | group of people | Data | Storage approach | destruction |
|---|---|---|---|---|
| Patient file/medical records | sick | health, identity | Mandatory period in relevant health legislation; After the period has expired and there is no legal reason | Deletion / destruction / anonymization if appropriate |
| Examination, laboratory, imaging and prescription records | sick | health | The period determined in accordance with the relevant health legislation and clinical record integrity | Deletion / destruction / anonymization |
| Appointment and communication records | sick | communication, transaction | Until the service and dispute requirement ends and the relevant retention obligation is fulfilled. | Deletion / anonymization |
| Finance, invoice, payment, insurance/SGK records | sick | Finance | Tax, accounting, SSI and related special legislation periods | Delete/destroy |
| camera recordings | Patient/employee/visitor | visual | Short clinically determined safety period; If there is an incident/evidence, it will be kept separately until the end of the dispute or official process. | Automatic overwrite/secure erase |
| Employee personnel file | Employee | personnel | Taking into account employment, SSI, tax and statute of limitations periods | Physical destruction / digital secure deletion |
| Payroll, wages, banking and accounting records | Employee | Finance | Deadlines in tax, SSI, labor and accounting legislation | Delete/destroy |
| OHS and employee health records | Employee | Health/OHS | Special periods in OSH and health legislation | Delete/destroy |
| PDKS / input-output | Employee | Transaction security | Time required for working relationship, wage/overtime and dispute needs | Delete |
| Job application/CV records | candidate | Identity, communication, professional | Until the application process and valid candidate pool purpose, if any, ends. | Delete/destroy |
| Visitor login records | visitor | ID/transaction | Short time required for physical security and incident management; If there is an incident, throughout the legal process | Delete/destroy |
| Supplier contracts and correspondence | Supplier | Identity, communication, legal action | Relevant tax/trade/prescription periods after termination of the contract and commercial relationship | Delete/destroy |
| Invoice and payment records | Supplier | Finance | Deadlines in tax and accounting legislation | Delete/destroy |
| Web server/log records | web user | Transaction security | Time required for security, regulatory and incident investigation | Deletion / anonymization |
| Cookies and preference records | web user | digital preference | Depending on the purpose of the cookie, its validity period and revocation of the user's preference | Delete / refresh |
| KVKK application and response records | All groups | legal action | Time required for application/dispute and burden of proof | Delete/destroy |
| Destruction process records | All groups | audit trail | At least 3 years from the date of destruction; If there is a longer legal obligation, then | Safe destruction at the end of the period |
12. Periodic Destruction
Medicus Clinic's periodic destruction interval is determined as 6 months. Personal data where all processing conditions are determined to be eliminated are deleted, destroyed or anonymized in the first periodic destruction process following the date on which the liability arises. If necessary, destruction can be done at shorter intervals.
13. Destruction Methods
13.1 Deletion
In electronic systems, removal of access authorizations, secure deletion at the application/database level, closure of archive access so that relevant users cannot access the data, and other appropriate methods are used.
13.2 Destruction
Paper records are irreversibly shredded or destroyed through a secure shredding service. Unusable disks, optical/magnetic media and devices are destroyed physically or technically by secure methods that will prevent data recovery.
13.3 Anonymization
If statistical, quality or reporting purposes are to be maintained; Masking, aggregation, generalization or other appropriate anonymization techniques may be applied that irreversibly eliminate association with an identified or identifiable person. Mere use of a pseudonym alone is not considered anonymization.
14. Technical and Administrative Measures
- Role and task based access authorization; periodic authorization review;
- Increased access control and confidentiality obligations for sensitive personal data;
- Strong password, convenient multi-factor authentication, logging and secure backup;
- Up-to-date security software, patch management, network security and malware precautions;
- Keeping physical archives in controlled areas and preventing unauthorized access;
- Personnel KVKK, privacy, information security and destruction training;
- Data security and confidentiality provisions in supplier contracts;
- Execution of destruction procedures by authorized persons, creation of minutes/records and double checks when necessary.
15. Backups and Disaster Recovery Copies
If data deleted from the active system is found in backups, the normal cycle and security architecture of the backups are taken into account. If the data on the backup is returned to the active system, technical and administrative controls are applied to ensure that records that have previously been subject to destruction are not re-used.
16. Deletion/Destruction Request of the Relevant Person
The patient, employee, visitor or supplier may request the deletion or destruction of their personal data as a relevant person. If all processing conditions are eliminated, the necessary destruction is carried out; If the conditions continue, the request is concluded by explaining the legal justification. Applications are answered within the deadlines specified in KVKK.
17. Recording of Destruction Procedures
Deletion, destruction and anonymization operations are recorded. Destruction records; It is kept for at least three years, without prejudice to other legal obligations. The record includes, at a minimum, the data/record category, reason for destruction, method, date, and information about the authorized person who performed and controlled the transaction.
18. Duties and Responsibilities
| Unit/Role | Responsibility |
|---|---|
| Company Management / Data Controller | Approval of policy, provision of resources, top oversight. |
| KVKK contact/responsible unit | Up-to-dateness of the inventory-storage schedule, relevant person applications, periodic destruction coordination and records. |
| Computing / IT | Electronic deletion, access restriction, backup, log and technical security measures. |
| Human Resources | Storage/destruction tracking of employee and candidate records. |
| Patient Services / Clinical units | Processing of patient records only for authorized purposes and management in accordance with retention obligations. |
| Accounting / Finance | Keeping and destroying financial and commercial records in accordance with the legislation. |
| Security / Administrative Affairs | Management of visitor and camera records in accordance with the purpose and duration. |
| Purchasing / Contract responsible | Management of supplier and service provider records. |
19. Periodic Review
Policy and its attached storage schedule; It is reviewed regularly when there are changes in legislation, clinical activities, information systems used, data inventory or organizational structure. Before starting a new data processing activity, the relevant storage and destruction rule is determined.
20. Enforcement and Publication
This Policy comes into force with the approval of Medicus Clinic management. The public version of the policy may be published on the website; Internal procedures and destruction reports containing operational security details are not made public.
21. Consent
| Prepared by | |
|---|---|
| Controller | |
| Approved by | |
| Effective Date |
