Sensitive Personal Data
This policy sets additional rules for the processing, transfer, protection and destruction of sensitive personal data such as health, biometric/genetic data and other categories deemed sensitive by law.
Purpose and Scope
It applies to all sensitive personal data processed by the school in physical or digital environments. Where there is a conflict between this policy and applicable law, the law prevails.
Processing Principles
- Lawfulness, fairness, accuracy and keeping data up to date.
- Processing for specified, explicit and legitimate purposes in a relevant and proportionate manner.
- Retention only for the necessary period.
- Applying specific security measures determined by the Personal Data Protection Board.
Processing Sensitive Personal Data
Sensitive personal data is processed only under the conditions permitted by KVKK and applicable law. Access to highly sensitive data such as health information is more strictly restricted; where required, explicit consent and authorized persons/institutions subject to confidentiality duties are involved.
Transfer
For domestic or international transfers, adequate security measures are required in addition to a valid legal basis. Appropriate methods such as encryption, SFTP/VPN, registered electronic mail (KEP) or confidentiality markings may be used for email, portable media, server-to-server transfers or physical documents.
Retention, Deletion and Anonymization
When the processing purpose ends and the legal retention period expires, sensitive personal data is deleted, destroyed or anonymized. The official policy states that periodic destruction reviews are carried out every six months.
Technical and Administrative Measures
- Clearly defining authorization and access periods and removing permissions when roles change.
- Employee training and confidentiality agreements.
- Cryptographic protection, logging, updates and security testing for electronic data.
- Protecting physical environments against unauthorized entry, fire, flooding and similar risks.
- Using strong authentication for remote access.
Rights of Data Subjects
Data subjects may exercise their rights under KVKK, including obtaining information about the processing of sensitive data, requesting correction of inaccurate data and requesting deletion, destruction or anonymization when processing conditions no longer apply.
