Data Security and Personal Data Management Policy
Our organization adopts as a fundamental principle the protection of the confidentiality, integrity and availability of information assets and the confidentiality and privacy of personal data; the management of information security and personal data management as an integral part of business processes; and the management of risks in these areas at acceptable levels.
Our organization, in accordance with the ISO/IEC 27001:2022 Information Security Management System and the ISO/IEC 27701 Privacy Information Management System;
- To ensure that information and personal data are accessed only by authorized persons in line with business requirements and defined authorizations,
- To protect the confidentiality, integrity and availability of information, and the confidentiality and privacy of personal data,
- To systematically identify, assess, treat and manage at acceptable levels the risks related to information security and personal data processing activities,
- To establish a framework for defining, monitoring and reviewing information security and personal data management objectives, taking into account the organization’s strategic direction, business requirements, applicable obligations and risk assessment results,
- To ensure that personal data are processed lawfully and fairly; are accurate and, where necessary, kept up to date; are processed for specified, explicit and legitimate purposes; are relevant, limited and proportionate to the purposes for which they are processed; and are retained only for as long as necessary,
- To meet applicable legal, regulatory, contractual and other requirements relating to information security and the protection of personal data,
- To ensure the protection of data subjects’ rights regarding their personal data and the management of their requests in accordance with applicable legislation and established processes,
- To ensure the prevention, detection, reporting, assessment and response to information security incidents and personal data breaches, and the implementation of necessary improvement activities,
- To maintain and improve controls and processes for information security and the protection of personal data in line with changing threats, business requirements and risks,
- To reduce the impact of information security and personal data protection risks that may affect business and service continuity,
- To enhance employees’ awareness and competence regarding information security and the protection of personal data,
- To continuously improve the Information Security Management System and the Privacy Information Management System
hereby commits.
Management Representative