Our Privacy and Security Policy

 

 

PERSONAL DATA PROTECTION POLICY 

 

OBJECTIVE

The senior management of Burda Bebek Ürünleri San. ve Tic. A.Ş. (hereinafter referred to as the “COMPANY” or “BURDA BEBEK”) is committed to complying with the principles and rules established by the Constitution of the Republic of Türkiye, the Personal Data Protection Law No. 6698 (PDPL), and other relevant legislation, and  pledges to safeguard the rights and freedoms of individuals whose personal data is processed. With this objective in mind, the Senior Management has established and embraced a written personal data protection policy and system, committing to its ongoing execution and improvement.

 

SCOPE

The provisions of this Policy apply to all information systems, sub-information sets, contracts, physical environments, and corporate premises involved in data processing activities across the Company's operations, as well as all systems and regulations developed for these areas.

This Policy encompasses all business units of the Company, support service provider personnel, visitors, third parties, interns, and contracted staff.

 

DATA PROTECTION PRINCIPLES

The Company operates in strict compliance with personal data protection legislation and established data protection principles. The core data protection principles adopted by the Company include:

a.       Processing personal data exclusively when explicitly necessary for legitimate corporate purposes;

b.       Processing personal data only to the minimum extent required for these purposes, avoiding excessive data processing;

c.       Providing individuals with clear, transparent information regarding how and by whom their personal data are used;

d.       Processing only relevant and necessary personal data;

e.       Processing personal data fairly and lawfully;

f.        Maintaining an up-to-date inventory of all personal data categories processed by the Company;

g.       Keeping personal data accurate and updated whenever necessary;

h.       Retaining personal data only for the duration required by legal regulations, the Company's statutory obligations, or legitimate corporate interests;

i.         Fully respecting individuals' rights regarding their personal data, including their right of access;

j.         Keeping all personal data secure;

k.       Transferring personal data abroad only if adequate data protection measures are guaranteed in the destination country;

l.         Applying exceptions strictly in accordance with applicable legislation;

m.      Establishing and running a dedicated personal data protection system to ensure policy compliance;

n.       Identifying internal and external stakeholders involved in the personal data protection system and defining the scope of their involvement when necessary;

o.       Appointing specific personnel with designated authority and responsibilities regarding the management of the data protection system.

 

 

RIGHTS OF DATA OWNER

Data owners possess the following rights regarding their personal data processed or recorded by the Company:

           The right to learn whether their personal data have been processed,

           The right to request information if their personal data have been processed,

           The right to learn the purpose of the data processing and whether the data are being used in accordance with the intended purpose,

           The right to know the third parties to whom personal data are transferred, whether domestically or abroad,

           The right to request the correction of personal data in case of incomplete or inaccurate processing,

           The right to request the deletion or destruction of personal data if there is no longer a lawful ground or justification for its processing under the PDPL or this policy,

           The right to request that any correction, deletion, or destruction of data be notified to the third parties to whom the personal data were transferred,

           The right to object to any automated processing of their data that results in a decision or outcome to their detriment,

           The right to claim compensation for damages suffered as a result of the unlawful processing of personal data.

Data owners may submit their requests to access their personal data or exercise any of the rights listed above. All inquiries must be directed to the Contact Person / Personal Data Protection Committee. The Committee will review and respond to all requests within 30 days. The receipt, transfer, and finalization of these requests are handled systematically in accordance with the Company’s Request Management Procedure.

Data owners may submit their requests by filling out the PDPL Application Form by means of filling out the PDPL Application Form and delivering it to the address of “Burda Bebek Ürünleri San. ve Tic. A.Ş. | Headquarters, Merdivenköy Mh. Dikyol Sk. No:2/1 B Blok Kat:17 (D.170-171-172) Business Istanbul 34732 Kadıköy, İstanbul” through a notary public or via registered mail with return receipt by means of confirming their identity, or to the address of “kvkk@burdabebek.com” via email.

All Company personnel, regardless of their title, are obligated to guide data owners toward the correct application method regarding data owner access requests directed to them. Company personnel shall be informed and trained on how to handle incoming requests from data owners.

To enable data owners to submit their requests, the Contact Person/Committee information shall be explicitly featured within the disclosure texts/privacy notices and on the Company’s website.

 

OBTAINING EXPLICIT CONSENT

The Company recognizes explicit consent as an informed, freely given, and unambiguous indication of the data owner's wishes concerning specific data processing activities, expressed either through a written or oral statement, or by a clear affirmative action. For sensitive data, explicit consent must always be obtained in writing. Explicit consent may be revoked by the data owner at any time.

Explicit consent can be obtained by having the data owner sign a standard consent form, or by embedding the required consent clauses directly into contracts or electronic forms. With respect to the personal data routinely processed for employees, job applicants, and customers, explicit consent shall be obtained through their respective contracts or forms.

In cases where data processing activities relying on explicit consent are of a continuous or repetitive nature, the relevant department shall maintain a single, consolidated list of individuals who have provided their consent. The relevant department is responsible for ensuring that this list remains accurate and up to date. The responsible department must also securely store all explicit consent forms and associated proofs of consent for these processing activities.

 

DATA SECURITY

           All personnel are responsible for maintaining the security of the personal data they process on behalf of the Company.

           Access to personal data must be strictly limited to individuals whose duties require such access. Authorization shall be granted exclusively in accordance with the Access Management Procedure.

           The security of personal data shall be maintained in strict alignment with the Company’s Personal Data Protection (PDP) Policy and its associated documentation.

           Any information security incidents concerning personal data shall be reported by the Personal Data Protection Committee to the Personal Data Protection Board and the affected individuals at the earliest possible opportunity.

 

DATA SHARING

           Personal data may only be disclosed to third parties in compliance with legal requirements and the principle of fairness. Accordingly, personal data may be shared only where at least one of the following conditions is satisfied:

§  Explicit consent of the data owner is obtained.

§  The data sharing is expressly permitted by applicable law.

§  The data sharing is necessary to protect the life or physical integrity of the data owner or another individual where the data owner is unable to provide valid consent.

§  The sharing is necessary for the conclusion or performance of a contract to which the Company is, or will become, a party.

§  The sharing is necessary for the Company to comply with its legal obligations.

§  The personal data has been made public by the data owner.

§  The data processing is necessary for the Company to establish, exercise, or protect its rights.

§  The data processing is necessary for the legitimate interests pursued by the Company, provided that such interests do not override the fundamental rights and freedoms of the data owner.

           Personal data may only be transferred abroad when the above conditions are met, and there is sufficient protection in the relevant party and when the data owner provides explicit consent for such transfer.

           A list of countries with sufficient protection, provided by the Personal Data Protection Board shall be taken as basis for transferring personal data abroad.

           Regarding the cross-border transfer of personal data, the Personal Data Protection Committee manages the necessary permissions and notifications before the Personal Data Protection Board, in compliance with the Personal Data Protection Law (PDPL) and relevant legislation.

           In the absence of an adequacy decision, personal data may only be transferred abroad if one of the following assurances is provided:

§  Standard Contract: A contract must be executed with the recipient party in the country to which the personal data will be transferred, and it must be notified to the Personal Data Protection Board within five business days after being signed by the data controller or data processor.

§  Binding Corporate Rules: Data security measures must be defined through intra-company agreements and subsequently approved by the Personal Data Protection Board.

§  Letter of Commitment: The data transfer must be authorized by the Personal Data Protection Board based on a letter of commitment that guarantees an adequate level of protection.

• A PDPL Letter of Commitment shall, at a minimum, include the following:

§  The purpose or purposes of the data sharing;

§  Potential third-party recipients or categories of recipients, along with the conditions for access rights;

§  The categories of personal data to be shared (which must be limited to the minimum necessary to achieve your purposes);

§  General principles regarding data processing;

§  Data security measures;

§  The retention period of the shared data;

§  Data owner's rights, access requests, and procedures for responding to applications and complaints;

§  Reviewing the termination or expiration of the data sharing agreement; and

§  Liabilities and sanctions resulting from non-compliance with the agreement or individual breaches by personnel.

 

RECORDS MANAGEMENT

Personal data shall not be retained for longer than is necessary for the purposes for which they are processed. The Retention and Destruction Policy guides the categorization of records containing personal data and their respective retention periods.

 

Personal data whose processing purpose has expired, or upon the data owner's justified request, shall be erased, destroyed, or anonymized in accordance with the Destruction Procedure and in such a manner that the data subject can no longer be identified.

 

 

POLICY FOR PROTECTING SENSITIVE PERSONAL DATA

 

OBJECTIVE

The objective of this Policy for Protecting Sensitive Personal Data (the “Policy”) is to determine the principles for all types of data processing activities such as the transfer, storage, destruction, and retention of sensitive personal data belonging to the existing and potential customers, business partners, visitors, shareholders, company directors, job applicants, employees, and officials of Burda Bebek Ürünleri San. ve Tic. (hereinafter referred to as the “COMPANY” or “BURDA BEBEK”), as well as related third parties in accordance with the procedures and principles set forth in the Personal Data Protection Law No. 6698 (the “Law”) and the Personal Data Protection Board’s Decision No. 2018/10, dated January 31, 2018, regarding the “Adequate Measures to be Taken by Data Controllers in the Processing of Sensitive Personal Data”.

 

 

SCOPE

The provisions of this Policy apply to all information systems, sub-information sets, contracts, physical environments, and corporate premises involved in data processing activities across BURDA BEBEK's operations, as well as all systems and regulations developed for these areas.

This policy applies to any third party working on behalf of BURDA BEBEK, its existing and potential customers, business partners, visitors, shareholders, BURDA BEBEK directors, employees, job applicants, relevant third parties, third-party personnel, and officials.

 

DEFINITIONS

Explicit consent: Consent regarding a specific subject matter, based on information and expressed with free will.

Anonymization: Rendering personal data impossible to associate with an identified or identifiable natural person under any circumstances, even when matched with other data.

PDC (Personal Data Committee): The Personal Data Protection Committee appointed by the General Manager to audit the company organization.

Data owner: The natural person whose personal data are processed.

Personal data: Any information relating to an identified or identifiable natural person.

Sensitive personal data: Data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and dress, membership in associations, foundations, or trade unions, health, sexual life, criminal convictions, and security measures, as well as biometric and genetic data.

Processing of personal data: Any operation performed on data such as obtaining, recording, storing, retaining, altering, reorganizing, disclosing, transferring, taking over, making available, classifying, or preventing the use of personal data by fully or partially automated means, or by non-automated means provided that it forms part of a data filing system.

PDP: Personal data protection.

PDPL: The Personal Data Protection Law No. 6698.

PDPB: The Personal Data Protection Board.

PDPA: The Personal Data Protection Authority.

PDP Representative: The Personal Data Protection Representative appointed by the General Manager to audit the company organization.

Data processor: The natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the data controller.

Data filing system: Any structured system where personal data are processed according to specific criteria.

Data controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data filing system.

 

DATA SECURITY

All the staff are obliged to securely store the data processed by BURDA BEBEK under their responsibility and not disclose such data with any third party unless a PDP Letter of Commitment is signed.

Access to personal data must be strictly limited to individuals whose duties require such access. Authorization shall be granted exclusively in accordance with the Access Management Procedure.

Data security is ensured in accordance with BURDA BEBEK's PDP Policy (KV.PO.01 Personal Data Protection Policy) and affiliated documents.

Any information security incidents concerning personal data shall be reported by the Personal Data Protection Committee to the Personal Data Protection Board and the affected individuals at the earliest possible opportunity.

When processing sensitive personal data, the adequate security measures determined by the PDPL must also be implemented by BURDA BEBEK in its capacity as the data controller.

 

IMPLEMENTING SECURITY MEASURES FOR PERSONNEL

Regarding personnel working in business units whose workflows involve processing sensitive personal data—such as Human Resources and Administrative Affairs:

a.       a. Confidentiality agreements must be executed with such personnel, and the Sensitive Personal Data Protection Policy must be attached to these agreements.

b.       b. Training on personal data security must be provided annually to the business units specified above.

c.       c. Access privileges for users authorized to handle sensitive personal data must be clearly defined by scope and duration, with regular access reviews conducted periodically.

d.       d. The authorization of personnel who undergo a change of role or leave the company must be revoked immediately, and their existing accounts must be closed without delay. Within this scope, all company assets holding personal data (such as computers, hard drives, files, folders) must be handed back upon their departure or role change.

DATA SECURITY MEASURES FOR ELECTRONIC MEDIA

Where data are processed, stored and /or accessed digitally, the following security measures must be taken:

a.       a. Data must be stored using strong cryptographic encryption methods.

b.       b. Cryptographic keys must be kept secure and isolated in distinct environments.

c.       c. All activity  involving the data must be securely logged.

d.       d. Security updates for the media holding the data must be continuously monitored; required vulnerability and security testing must be regularly conducted internally / via third parties, and the test results must be documented.

e.       e. Data access via software requires managed user authorization and regular software security testing, with all findings documented.

f.         f. Any remote access to the data must be secured via at least a two-tier authentication system.

 

DATA SECURITY MEASURES FOR PHYSICAL MEDIA

Where data are processed, stored and /or accessed physically, the following security measures must be taken:

a.       a. Depending on the nature of the environment where sensitive personal data are stored, adequate security measurements must be taken (against risks such as electrical leakage, fire, flooding, theft, etc.).

b.       b. The physical security of these environments must be maintained to prevent unauthorized access.

 

DATA SHARING

Sensitive Personal Data may only be shared with third parties in accordance with the law and the principle of fairness, provided that the explicit consent of the data owner is obtained or within the scope of the exceptions set forth in paragraph 3 of Article 6 of Law No. 6698.

Accordingly, the sharing of sensitive personal data requires the fulfillment of at least one of the following conditions:

           • The explicit consent of the data owner is obtained.

           • It is mandatory for the protection of the life or bodily integrity of a person, or of another person, who is personally unable to express their consent due to actual impossibility or whose consent is not granted legal validity.

           • It concerns personal data manifestly made public by the data owner, provided the use aligns with their original intent.

           • It is mandatory for the establishment, exercise, or protection of a right.

           • It is required for medical purposes—such as public health, preventive medicine, diagnosis, treatment, care, or managing and funding healthcare services—and is handled by authorized bodies or professionals bound by confidentiality.

           • It is mandatory for the fulfillment of legal obligations in the fields of employment, occupational health and safety, social security, social services, and social assistance.

           • Sensitive data may be shared if it concerns current members, former members, affiliates, or individuals in regular contact with non-profit organizations (such as political, philosophical, religious, or trade unions).This is permitted on the conditions that it complies with their governing legislation and objectives, is strictly limited to their field of activity, and is not disclosed to third parties.

When sharing sensitive personal data, the following measures must be taken to execute the transfer safely:

Sensitive Personal Data must be:

a.       a. encrypted and sent using an official corporate email address or a Registered Electronic Mail (KEP) account, if they are to be transferred via email.

b.       b. encrypted using cryptographic methods, and the decryption key must be stored in a separate environment, if they are to be transferred via removable media such as USB flash drives, CDs, or DVDs.

c.       c. transferred by setting up a VPN between the servers or by using the sFTP method, if they are transferred between servers in different physical locations.

d.       d. protected against risks such as theft, loss, or unauthorized viewing if transferred in paper format, and the documents must be sent under a "classified/confidential" status.