Skip to main content
izü

ISTANBUL SABAHATTIN ZAIM UNIVERSITY
PERSONAL DATA PROTECTION AND PROCESSING POLICY

1. INTRODUCTION

1.1. In General

Ensuring the confidentiality and security of personal data and compliance with the relevant legal regulations are among the highest priorities of Istanbul Sabahattin Zaim University (the “University”), and the utmost care is taken in this regard. In this context, the process governed by this Personal Data Protection and Processing Policy (the “Policy”) on the processing and protection of personal data, together with the other written policies within the University, and its intended purpose, is to inform our employees, job candidates, visitors, guests and other third parties (the “Data Subjects”) about the lawful processing, storage and protection of their personal data, and to reflect our institutional culture.

In preparing this Policy, our University takes as its guide the provisions set out in the relevant legal norms concerning the protection and processing of personal data and in the decisions of the Personal Data Protection Board, foremost among them the regulations contained in the Constitution of the Republic of Türkiye and the Personal Data Protection Law No. 6698 (the “KVKK”).

This policy also provides explanations regarding the following fundamental principles adopted by our University for personal data processing activities:

  • Processing personal data lawfully and in accordance with the rules of good faith,

  • Keeping personal data accurate and, where necessary, up to date,

  • Processing personal data for specific, explicit and legitimate purposes,

  • Ensuring that personal data is relevant, limited and proportionate to the purposes for which it is processed,

  • Retaining personal data for the period stipulated in the relevant legislation or required for the purpose for which it is processed,

  • Informing the data subjects,

  • Establishing the necessary processes for data subjects to exercise their rights,

  • Taking the necessary measures in the processing and retention of personal data,

  • Transferring personal data to third parties in line with the requirements of the processing purpose,

  • Exercising the necessary care in the processing and protection of special categories of personal data,

  • Erasing, destroying or anonymising personal data for which the purpose of processing has ceased to exist.

1.2. Purpose of the Policy

The primary purpose of this Policy is to provide explanations about the personal data processing activities carried out lawfully by our University and the procedures adopted for the protection of personal data, and thereby to ensure transparency by informing the Data Subjects. In addition, this PDP Policy and the other written policies aim to make our principle of compliance with the KVKK and other relevant legal regulations on personal data security sustainable.

1.3. Scope of the Policy

The scope of this policy covers natural persons whose personal data is processed by our University by automated means or by non-automated means provided that it forms part of a data recording system, and an Internal Directive on the Protection of Personal Data has been established within the scope of this Policy.

1.4. Application of the Policy and the Relevant Legislation

This Policy has been drawn up in concrete form within the principles set out by the relevant legislation. Our University undertakes and accepts that, in the event of any inconsistency between the legislation in force and this Policy, the legislation in force shall prevail.

1.5. Entry into Force of the Policy

This policy enters into force upon approval by the board of directors of our University, is published on the website (https://www.izu.edu.tr) and is thereby made available to the Data Subjects.

2. DEFINITIONS AND ABBREVIATIONS

Explicit Consent

Consent relating to a specific matter, based on information and expressed of free will

Anonymisation

Rendering personal data incapable of being associated with an identified or identifiable natural person in any way, even by matching it with other data

Employee

University employees

Job Candidate

Natural persons who have applied for a job at our University by any means or who have submitted their CV and related information for our University's review

Data Subject

The natural person whose personal data is processed

Personal Data

Any information relating to an identified or identifiable natural person

Processing of Personal Data

Any operation performed on data, such as obtaining, recording, storing, retaining, altering, reorganising, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data by wholly or partly automated means or by non-automated means provided that it forms part of a data recording system

Committee

Personal Data Protection Committee

Board

Personal Data Protection Board

Authority

Personal Data Protection Authority

PDP Policy

Personal Data Protection and Processing Policy

KVKK

Personal Data Protection Law No. 6698

Special Categories of Personal Data

Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data

Periodic Destruction Process

The erasure, destruction or anonymisation process specified in the personal data retention and destruction policy, to be carried out ex officio at recurring intervals in the event that all of the conditions for processing personal data set out in the Law cease to exist

Policy

PDP Policy

Potential Customer

Persons who have requested to use our services or who have been assessed, in accordance with commercial custom and the rules of good faith, as likely to do so

University

Istanbul Sabahattin Zaim University

Data Processor

The natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller

Data Recording System

The recording system or directory in which personal data is processed by being structured according to specific criteria

Data Controller

The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system

Application Form to the Data Controller

The application form that Data Subjects will use when exercising their rights set out in Article 11 of the KVKK

Erasure of Data

Rendering personal data in no way accessible or reusable by the relevant users

Destruction of Data

Rendering personal data in no way accessible, retrievable or reusable by anyone

Visitor

Natural persons who have entered the physical premises owned by the institution for various purposes or who visit its websites

 

3. PRINCIPLES REGARDING THE PROCESSING OF PERSONAL DATA

3.1. Processing Personal Data in Accordance with the Principles Set Out in the Legislation

3.1.1. Processing Lawfully and in Accordance with the Rules of Good Faith

Our University has adopted as a fundamental principle acting lawfully and in accordance with the rules of good faith in every operation carried out on personal data. In this context, embracing the principle of transparency, it informs the Data Subjects about the purpose for which the collected personal data is used through this Policy and other texts.

3.1.2. Ensuring that Personal Data is Accurate and, Where Necessary, Up to Date

In carrying out its personal data processing activities, our University has systems and processes in place to ensure the accuracy and currency of the personal data it processes. In this context, Data Subjects may apply to our University to have their personal data kept accurate and up to date.

3.1.3. Processing for Specific, Explicit and Legitimate Purposes

Our University clearly determines the purpose of personal data processing within legitimate and lawful limits and makes it known to the Data Subjects through this Policy and other texts before the personal data processing activity begins.

3.1.4. Being Relevant, Limited and Proportionate to the Purposes of Processing

Our University processes personal data for the purposes necessary to carry out its activities, in a manner relevant and proportionate to the subject of the activity. In this context, while carrying out its data processing activity, it carefully avoids processing personal data that is unrelated to the achievement of the purpose and that is not needed now or in the future.

3.1.5. Retaining Data for the Period Stipulated in the Relevant Legislation or Required for the Purpose of Processing

Our University retains personal data only for the period specified in the relevant legislation or limited to the period necessary for the purpose for which it is processed. In this context, it is first determined whether a period has been set for the retention of the personal data in the relevant legislation; if a period has been set, action is taken in accordance with that period, and if no specific period has been set, the period necessary for the purpose for which each item of personal data is processed is determined and the data is retained for that period.

In this context, our University prepares and implements a policy and directive on the erasure, destruction or anonymisation of personal data.

3.2. Processing Personal Data in Accordance with, and Limited to, the Personal Data Processing Conditions Set Out in Article 5 of the KVKK

Our University processes personal data only on the basis of the explicit consent of the Data Subject, or, in the cases where the KVKK states that explicit consent is not required, without explicit consent and limited to those cases and conditions.

3.2.1. Explicit Consent

Explicit consent is a declaration made by the Data Subject of free will, relating to a specific matter and based on information. Pursuant to Article 5/1 of the KVKK, our University respects and complies with the explicit consent of the Data Subject where it is required for the personal data processing activity.

3.2.2. Cases Where Explicit Consent Is Not Required

Article 5/2 of the KVKK regulates the processing of personal data in certain cases without being subject to the explicit consent of the Data Subject. Since obtaining explicit consent from the data subject where one of the specified conditions exists would be regarded as misleading the Data Subject, our University does not seek explicit consent in cases where the data processing conditions are present.

3.3. Processing of Special Categories of Personal Data

Our University exercises the utmost care in the processing and protection of personal data designated as “special category” by the KVKK due to the risk of causing greater harm or discrimination to individuals when processed, and the principles adopted regarding special categories of personal data are addressed separately in this Policy.

Where the data subject's explicit consent is not available, special categories of personal data may be processed by our University in the following cases, provided that the adequate measures to be determined by the Board are taken.

  1. Special categories of personal data other than those relating to the data subject's health and sexual life may be processed in the cases stipulated by law,

  2. Special categories of personal data relating to the data subject's health and sexual life may be processed without seeking the data subject's explicit consent only by persons under an obligation of confidentiality or by authorised institutions and organisations, for the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning and management of health services and their financing.

Our University has established additional measures and processes regarding the processing of and access to special categories of personal data. Within this framework, the environments in which special categories of personal data are stored are protected by secondary locks and secondary passwords, and such data is processed only by authorised persons within the framework of the authorisation matrix.

3.4. Transfer of Personal Data

In order to fulfil the purposes set out in this Policy, personal data may be transferred to supervisory bodies within the framework of audit activities, to our shareholders for reasons arising from auditing and shareholding rights pursuant to the relevant legal regulations, to public institutions and organisations authorised by law, to our suppliers and business partners located in Türkiye and/or abroad, to the natural persons from whom services are procured or to the third parties to whom services are provided, within the framework of the personal data processing conditions and purposes set out in Articles 8 and 9 of the KVKK.

4. PRINCIPLES REGARDING THE PROTECTION OF PERSONAL DATA

4.1. Technical and Administrative Measures Taken by Our University Regarding the Security of Personal Data

4.1.1. Technical Measures

The main technical measures taken by our University to ensure the lawful processing of personal data and to prevent unlawful access to personal data are as follows:

  • The personal data processing activities carried out within our University are monitored by means of the technical systems that have been established.

  • Personnel who are knowledgeable and experienced in technical matters are employed.

  • Relevant departments have been established for technical matters.

  • The technical measures taken are reported periodically to the authorised unit/person as required by the internal audit mechanism.

  • A lawful backup programme is used to ensure that personal data is stored securely.

  • New technological developments are monitored, technical measures are taken on the systems particularly in the field of cyber security, and the measures taken are periodically updated and renewed.

  • Technical access and authorisation measures are applied within the framework of the legal compliance requirements determined for each department within our University.

  • Access rights are restricted, authorisations are reviewed regularly and the accounts of former employees are closed.

  • Software and hardware including antivirus systems and firewalls are used.

  • The use of counterfeit software and hardware is strictly avoided. All the products we use are original and licensed.

Within this framework, our University carries out continuous and sustainable work on the following technical measures determined by the Board:

  • Authorisation Matrix

  • Authorisation Control

  • Access Logs

  • User Account Management

  • Network Security

  • Application Security

  • Encryption

  • Penetration Testing

  • Intrusion Detection and Prevention Systems

  • Log Records

  • Data Masking

  • Data Loss Prevention Software

  • Backup

  • Firewalls

  • Up-to-Date Anti-Virus Systems

  • Erasure, Destruction or Anonymisation

  • Key Management

4.1.2. Administrative Measures

The main administrative measures taken by our University to ensure the lawful processing of personal data and to prevent unlawful access to personal data are as follows:

  • Our personnel are informed and trained on personal data protection law and the lawful processing of personal data.

  • The personal data processing activities carried out by the business units of our University, and the requirements to be fulfilled in order to ensure that these activities comply with the data processing conditions set out in the KVKK, are examined specifically for each business unit and each activity carried out.

  • Provisions imposing an obligation not to process, disclose or use personal data, except in accordance with the University's instructions and the exceptions introduced by law, are included in the contracts and documents governing the legal relationship between our University and its employees, and employees' awareness of this matter is raised.

  • Awareness is created and implementation is carried out within the relevant business units in order to meet the legal compliance requirements determined on the basis of our business units. The administrative measures necessary to audit these matters and ensure the continuity of implementation are put into practice through internal policies and training.

  • Personal data access and authorisation processes are designed and implemented within our University in accordance with activity-based legal compliance requirements.

  • Work and transactions relating to the KVKK and other relevant regulations are monitored by the Personal Data Protection Committee, which has been established for ease of follow-up and compliance.

  • Provisions stating that the necessary security measures will be taken to protect the transferred personal data and that compliance with these measures will also be ensured within their own organisations are added to the contracts concluded by our University with the third parties to whom personal data is lawfully transferred.

Within this framework, our University carries out continuous and sustainable work on the following administrative measures determined by the Board:

  • Preparation of a Personal Data Processing Inventory

  • Corporate Policies (Access, Information Security, Use, Retention and Destruction, etc.)

  • Contracts (Between Data Controller and Data Controller, Data Controller and Data Processor)

  • Confidentiality Undertakings

  • Periodic and/or Random Internal Audits

  • Risk Analyses

  • Employment Contract, Disciplinary Regulations (Addition of Provisions in Compliance with the Law)

  • Corporate Communication (Crisis Management, Processes for Informing the Board and the Data Subject, Reputation Management, etc.)

  • Training and Awareness Activities (Information Security and the Law)

  • Notification to the Data Controllers Registry Information System (VERBİS)

4.2. Raising and Monitoring Our Employees' Awareness in the Field of Personal Data Protection

Our University ensures that the necessary training sessions and meetings are organised to raise awareness of preventing the unlawful processing of personal data and unlawful access to data, and of ensuring that data is retained securely.

Where necessary, professionals are engaged to raise the awareness of the current employees within our University regarding the protection of personal data.

4.3. Protection of Special Categories of Personal Data

Personal data designated as special category by the KVKK and processed lawfully is protected with the utmost care by our University. In this context, the technical and administrative measures taken by our University to protect personal data have been determined on the basis of the relevant legal regulations and the decision published by the Personal Data Protection Authority entitled “Adequate Measures to be Taken by Data Controllers in the Processing of Special Categories of Personal Data”, and are applied diligently with regard to the protection of special categories of personal data.

4.4. Procedure to be Followed in the Event of Unauthorised Disclosure of Personal Data

In the event that the personal data it processes is obtained by others through unlawful means, our University will notify the data subject and the Board of this situation within 72 hours.

If deemed necessary by the Board, this situation may be announced on the Board's website or by another method.

4.5. Personal Data Inventory

Each unit of our University maintains an up-to-date personal data processing inventory. The unit manager is responsible for the accuracy and currency of this inventory and for submitting it to the contact person when required. The accurate maintenance of the inventories, the implementation of the current institutional policy on personal data protection and current developments in the field of personal data protection are constantly monitored.

5. APPLICATION OF DATA SUBJECTS TO THE DATA CONTROLLER, OUR COMMUNICATION CHANNELS AND THE PROCESSES FOR EVALUATING APPLICATIONS

5.1. Subject of the Application

Our University attaches great importance and value to the rights of Data Subjects and enables them to exercise these rights. A “Data Controller Application Form” through which data subjects can easily submit their requests has been prepared by our University and published on our website. However, Data Subjects are not obliged to use this form. Every application made in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller will be taken into consideration.

Everyone has the right to apply to our University and, with regard to themselves;

a) To learn whether their personal data is being processed,

b) To request information if their personal data has been processed,

c) To learn the purpose of the processing of their personal data and whether it is used in accordance with that purpose,

ç) To know the third parties in Türkiye or abroad to whom their personal data is transferred,

d) To request the rectification of their personal data if it has been processed incompletely or inaccurately,

e) To request the erasure or destruction of their personal data within the framework of the conditions set out in Article 7 of the KVKK,

f) To request that the operations carried out pursuant to subparagraphs (d) and (e) be notified to the third parties to whom the personal data has been transferred,

g) To object to an outcome to their detriment arising from the analysis of the processed data exclusively by automated systems,

ğ) To claim compensation for damages in the event that they suffer damage due to the unlawful processing of their personal data,

these rights.

5.2. Application Method and Address

Application Method

Address for the Application

Subject Line of the Application

Application in person (If the applicant applies in person, a document verifying their identity must be presented; if the application is made by proxy, a notarised power of attorney must be presented.)

Halkalı Caddesi No:281, Halkalı, Küçükçekmece/İstanbul

“Information Request within the Scope of the Personal Data Protection Law” shall be written on the envelope.

Notification through a notary public

Halkalı Caddesi No:281, Halkalı, Küçükçekmece/İstanbul

“Information Request within the Scope of the Personal Data Protection Law” shall be written on the notification envelope.

E-mail with an Electronic Signature/Mobile Signature

………………………

“Information Request within the Scope of the Personal Data Protection Law” shall be written in the subject line of the e-mail.

Application via a Registered Electronic Mail (KEP) address

 

izu@hs01.kep.tr

“Information Request within the Scope of the Personal Data Protection Law” shall be written in the subject line of the e-mail.

E-mail address registered in our systems (Your e-mail address must have been previously matched with your identity in our systems.)

………………………

“Information Request within the Scope of the Personal Data Protection Law” shall be written in the subject line of the e-mail.

 

5.3. Process Following the Application

Applications submitted to us are answered within 30 (thirty) days at the latest from the date the request reaches our University, depending on the nature of the request. Our responses are sent on the basis of the notification method specified by the applicant in the Data Controller Application Form.

Pursuant to Article 14 of the KVKK, in the event that the application is rejected, the response given is found insufficient or no response is given to the application within the prescribed period, Data Subjects may file a complaint with the Board within thirty days of learning of our University's response and, in any case, within sixty days of the date of application.

5.4. Application Fee

As a rule, applications are made free of charge. However, if the transaction requested by the data subject entails an additional cost, the fee set out in the tariff determined by the Board will be charged by our University.

6. INFORMING AND NOTIFYING DATA SUBJECTS

In accordance with the provisions of Article 10 of the KVKK, our University informs data subjects about the process of obtaining personal data through this Policy and through the Disclosure Statement and other texts that are readily accessible on our website. In this context, our University informs data subjects about the identity of the data controller, the purposes for which personal data will be processed, to whom and for what purpose the processed personal data may be transferred, the method and legal basis of personal data collection, and the other rights of the data subject.

A Data Controller Application Form has been created and published on our University's website so that the Data Subject can more easily exercise the rights set out in the KVKK. This section is explained in detail under heading number 5.

7. PURPOSES OF PROCESSING PERSONAL DATA AND RETENTION PERIODS

7.1. Purposes of Processing Personal Data

Our University processes personal data limited to the purposes and conditions falling within the personal data processing conditions set out in Articles 5 and 6 of the KVKK. These purposes and conditions are;

  • The processing of personal data being expressly provided for in the laws governing the relevant activity of our University,

  • The processing of personal data by our University being directly related and necessary to the establishment or performance of a contract,

  • The processing of personal data being mandatory for our University to fulfil its legal obligation,

  • Provided that the personal data has been made public by the data subject, its processing by the University limited to the purpose of that publicity,

  • The processing of personal data by the University being mandatory for the establishment, exercise or protection of a right,

  • The processing of personal data being mandatory for the legitimate interests of the University, provided that it does not harm the fundamental rights and freedoms of the data subjects,

  • The processing of personal data by our University being mandatory to protect the life or physical integrity of the data subjects or of another person, where the data subjects are unable to give their consent due to actual impossibility or legal incapacity,

  • Special categories of personal data other than those relating to the health and sexual life of data subjects, in the cases stipulated by law,

  • Special categories of personal data relating to the health and sexual life of data subjects are processed by persons under an obligation of confidentiality or by authorised institutions and organisations, for the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning and management of health services and their financing.

7.2. Retention Periods for Personal Data

As the University, where stipulated in the relevant legislation, we retain personal data for the period specified in that legislation. In addition, our obligations arising from the relevant contracts and our administrative and legal responsibilities/obligations are also taken into account when determining retention periods.

Once the purpose of processing personal data has ceased and the retention period determined by the relevant legislation and by the University has expired, such personal data is erased and backed up solely for the purpose of serving as evidence in possible legal disputes or of asserting the relevant right attached to the personal data. In this case, the personal data is not accessed for any other purpose. Personal data is destroyed or anonymised once the periods set out in our University's Personal Data Retention and Destruction Policy have expired.

Processed personal data and personal data inventories are reviewed at six-month intervals, and personal data that must be erased/destroyed is erased/destroyed within these six-month periodic destruction periods, with the process recorded in minutes.

8. PERSONAL DATA PROCESSING ACTIVITIES CARRIED OUT WITHIN THE WORKING AREAS

8.1. Camera Monitoring Activity Carried Out at the Entrances to and Within the Working Areas

In order to ensure the safety of the Data Subjects and of our University, personal data processing activities are carried out by our University through security camera monitoring at the entrances to and within the premises and working areas where we provide and conduct our services, as well as for the tracking of entries/exits and working hours. In this context, as the University, we act in accordance with the KVKK and other relevant legislation.

8.1.1. Providing Information About the Camera Monitoring Activity

Our University informs data subjects in accordance with Article 10 of the KVKK, thereby aiming to prevent harm to the fundamental rights and freedoms of data subjects and to ensure transparency. With regard to the camera monitoring activity, the University provides disclosure both through this Policy on its website (online Policy) and through notices posted at the entrances to the monitored areas stating that monitoring will be carried out (on-site disclosure/layered disclosure).

8.1.2. Purpose of the Camera Monitoring Activity and Limitation to That Purpose

As the University, we process personal data in accordance with the KVKK in a manner relevant, limited and proportionate to the purposes for which it is processed. The purpose of conducting monitoring through video camera recording by the University is limited to the purposes listed in this Policy. Accordingly, the monitoring areas and number of security cameras and the times at which monitoring is carried out are implemented in a manner sufficient to achieve the security purpose and limited to that purpose.

8.1.3. Ensuring the Security of the Data Obtained Through the Camera Monitoring Activity

All necessary technical and administrative measures are taken by the University to ensure the security of the personal data obtained through camera recording. Detailed information is provided in the section on data security measures.

8.1.4. Who Can Access the Information Obtained as a Result of Monitoring and to Whom This Information Is Transferred

Only persons authorised in this respect can access the information obtained as a result of monitoring and the storage environment. Live camera footage can be viewed by security officers who are University employees or who are engaged through an outsourced service. The limited number of persons with access to the recordings declare, through a confidentiality undertaking, that they will protect the confidentiality of the data they access.

8.2. Visitor Entry/Exit Tracking Carried Out at the Entrances to and Within the Working Areas

Personal data processing activities for tracking visitor entries and exits in the University's working areas are carried out by the University and by the outsourced service company in order to ensure security and for the purposes set out in this Policy.

While the names and surnames of persons visiting our working areas are collected, the data subjects are informed through texts posted in the relevant areas or otherwise made available to guests. The data obtained for the purpose of tracking visitor entries and exits is processed solely for this purpose, and the relevant personal data is recorded in the data recording system in physical and/or electronic form.

8.3. Recording of Information Relating to Electronic Devices at the Entrances to the Working Areas

In connection with the care and sensitivity we show as the University towards information security and the protection of personal data, we record the MAC addresses of computers or similar electronic devices where our guests use their own personal computers or similar electronic devices. The reason for this is to ensure the security of our University and of the persons whose personal data is held within our University.

9. REVIEW

This policy enters into force upon approval by the University's Board of Trustees. The approval of the person(s) to be authorised by the Board of Trustees is obtained for any amendments to be made to the Policy. Matters relating to the implementation of this policy within the University have been systematised through internal policies, procedures and internal directives. The Policy is reviewed every 6 months and, where necessary, the relevant revisions are made with the approval of the authorised person.

10. PERSONAL DATA PROTECTION COMMITTEE

The University has appointed a contact person within the framework of personal data protection law. A Committee of five members has been formed from among the employees of the University's units. The Personal Data Protection Committee (the “Committee”) is chaired by the University contact person.

The contact person acts on the opinions and recommendations of the Committee regarding administrative and technical measures. The principles determined by the Committee regarding administrative and technical measures are taken into account. The Committee makes the necessary effort to ensure the University's compliance with personal data protection legislation. The contact person audits the University units for which they are responsible within the scope of personal data protection law. As a result of these audits, they warn the relevant units where necessary and inform senior management of the situation.

The contact person ensures coordination so that data subject applications submitted to the University are answered within the statutory periods and in accordance with the proper procedure. The contact person manages the University's relations with the Personal Data Protection Authority.

11. ENTRY INTO FORCE

This Policy enters into force as of the date on which it is adopted and announced by the authorised bodies.

01


 

ISTANBUL SABAHATTIN ZAIM UNIVERSITY

WITHIN THE SCOPE OF THE PERSONAL DATA PROTECTION LAW NO. 6698
JOB CANDIDATE DISCLOSURE STATEMENT
 

Istanbul Sabahattin Zaim University (the “University”) takes all technical and legal measures in accordance with the Personal Data Protection Law No. 6698 (the “KVKK”) in the processing of your personal data arising from the job application form. Candidates may obtain detailed information from this disclosure statement about the processing of their personal data, its transfer to third parties, the legal grounds for collecting personal data and their rights set out in the KVKK.

A. Personal Data Processed

Personal data refers to any information relating to an identified or identifiable natural person. In this context, all information identifying Candidates, such as their name, telephone number, educational background, e-mail address and health information, constitutes the Candidates' personal data.

The processing of personal data refers to any operation carried out on data, such as obtaining, examining, recording, disclosing and using personal data.

The University processes Candidates' personal data in accordance with the data processing conditions set out in the Personal Data Protection Law (KVKK).

Detailed information on the personal data processed during candidate application procedures and on the data processing condition under which each type of personal data is processed is provided in the table below.

 

Identity DataPersonal Data ProcessedData Processing Condition

Name and surname,

Place/date of birth, Gender,

Marital status, Driving licence details, Nationality,

Signature.

Provided that it is directly related to the conclusion or performance of a contract, the processing of the personal data of the parties to the contract is necessary

Processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject; processing is necessary for the establishment, exercise or protection of a right.

Contact Data

 

 

Telephone, Address, E-Mail

Provided that it is directly related to the conclusion or performance of a contract, the processing of the personal data of the parties to the contract is necessary

Processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject; processing is necessary for the establishment, exercise or protection of a right.


 

02


 

Professional Experience Data

Professional experience details, Courses,

Diploma, Educational background,

Foreign language proficiency, Computer skills, Certificate details,

Seminar details.

Provided that it is directly related to the conclusion or performance of a contract, the processing of the personal data of the parties to the contract is necessary

Processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject; processing is necessary for the establishment, exercise or protection of a right.

Visual and Audio Data

 

 

Photograph.

Processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject; processing of data is necessary for the establishment, exercise or protection of a

right.

Criminal Conviction and Security Measures Data

 

 

 

 

Criminal record details

 

 

 

 

Existence of explicit consent.

Health Data

 

Information concerning health status

 

Existence of explicit consent.

Employment Data

 

 

 

 

Employment details.

Provided that it is directly related to the conclusion or performance of a contract, the processing of the personal data of the parties to the contract is necessary

Processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject; processing of data is necessary for the establishment, exercise or protection of a

right.

Reference Data

Details of references (name, surname, institution, position and telephone number),

Details of relatives working at the

University.

 

 

Existence of the third party's explicit consent


 

03



 

B. Purposes of Processing Personal Data
 

Candidates' personal data are processed for the purposes of;

  • Assessing the competencies of the candidate and identifying the candidate to be employed,

  • Examining and verifying the candidate's suitability for the position,

  • Evaluating and managing recruitment processes,

  • Placing the candidate in the appropriate location and position,

  • Reassessing the candidate for suitable positions that may open in the future,

  • Contacting the candidate in order to manage recruitment processes and opportunities,

  • Getting to know the candidate better.

C. Transfer of Personal Data

Where necessary and upon request, personal data may be transferred to courts and to authorised public institutions and organisations for the purpose of conducting legal and other related proceedings.

D. Method of Collecting Personal Data

The personal data processed by the University to enable the Human Resources Department to manage job application processes are obtained by automated and non-automated means: through the job application form (submitted in person, by e-mail, fax and/or post), through CVs submitted by candidates in electronic and physical form, through third parties whose details are provided by the candidate, and/or through interviews conducted with candidates.

E. Important Notes on Candidate Application Processes

Among the personal data we process, we process your health information and criminal record information on the basis of your explicit consent. If you do not consent to the processing of such data, you are kindly requested not to submit this information to us.

In addition, if there are individuals you intend to give as references, we would like to remind you that you must inform them accordingly and obtain their explicit consent. As the University has no means of verifying this, we would like to state that we will not be held liable in the event of any breach that may arise.

04


F. Rights of the Data Subject

By applying to our University in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller, our Candidates have the right to;

  • Learn whether their personal data are processed,

  • Request information if their personal data have been processed,

  • Learn the purpose of processing their personal data and whether the data are used in accordance with that purpose,

  • Know the third parties in Türkiye or abroad to whom their personal data are transferred,

  • Request the correction of their personal data if processed incompletely or inaccurately, and request that the action taken in this respect be notified to the third parties to whom the personal data have been transferred,

  • Request the erasure or destruction of their personal data if the reasons requiring their processing cease to exist, even though they have been processed in accordance with the Law and other relevant legislation, and request that the action taken in this respect be notified to the third parties to whom the personal data have been transferred,

  • Object to any adverse outcome arising from the analysis of the processed data exclusively through automated systems,

  • Claim compensation for damages incurred as a result of the unlawful processing of their personal data.

Applications submitted to us are answered within a maximum of 30 (thirty) days from the date they reach our University, depending on the nature of the request. Should the assessment and decision-making process entail an additional cost, the fee set out in the tariff determined by the Personal Data Protection Board will apply.

We hereby bring this to the attention of our valued Candidates. We look forward to welcoming you among us.

G. Identity of the Data Controller

Website: https://www.izu.edu.tr

Telephone Number: 444 97 98 E-Mail Address: bilgi@izu.edu.tr

Address: Halkalı Caddesi No:281, Halkalı, Küçükçekmece/İstanbul

Application Form to the Data Controller