1. CONFIDENTIALITY COMMITMENT FOR KVKK AND ISMS

1.1.

The Personal Data Protection and Information Security Policy of PLASTAY KİMYA SAN. VE TİC. A.Ş. sets forth the principles to be followed within the Company and/or by the Company while processing Personal Data in accordance with the provisions of the Law on the Protection of Personal Data No. 6698 (KVKK) and the requirements of the Information Security Management System (ISMS).
The Policy ensures compliance with applicable legislation and defines the rules to be observed while performing Personal Data processing activities in line with the requirements of the ISO 27001 Information Security Management System, an international standard.

1.2.

The Company undertakes to comply with this Policy and all related policies and procedures applicable to the implementation of the Personal Data Protection and Information Security Policy established within its organizational structure.


2. PURPOSE OF THE POLICY

The primary purpose of this Policy is to define the principles concerning the methods and processes required by the Information Security Management System regarding the processing and protection of Personal Data by the Company.


3. SCOPE OF THE POLICY

3.1.

This Policy covers all activities related to Personal Data processed by the Company and all activities associated with the Information Security Management System, and it is applicable to these activities.

3.2.

We ensure the protection of Personal Data and corporate information at the highest level at all times by meeting the needs and expectations of Information Security objectives and targets for all information classified as Personal Data.

3.3.

We operate in full compliance with the Law on the Protection of Personal Data No. 6698, all relevant legislation, regulations, and international standards.

3.4.

We act in cooperation with and in balanced satisfaction of our employees, suppliers, business partners, society, and the environment, paying utmost attention to fulfilling the requirements of the Law on the Protection of Personal Data No. 6698 and all other applicable legal obligations.

3.5.

By meeting the needs and expectations of Information Security objectives and targets, we always ensure the highest level of information security in terms of Personal Data Protection.

3.6.

We comply with all laws, regulations, and requirements binding our organization, and we continuously improve all processes related to our success and quality, along with the requirements of the Information Security Management System.

3.7.

We ensure that our Personal Data Protection and Information Security Policy is communicated to relevant internal and external parties, ensuring full awareness of the Policy among all stakeholders.

3.8.

Where required by KVKK and ISMS regulations, or in cases deemed necessary by the Company’s Data Controller Representative or the Committee, this Policy may be amended from time to time with the approval of the Board of Directors.
In the event of any inconsistency between KVKK regulations, ISMS requirements, and this Policy, KVKK regulations shall prevail.


 
Plastay WhatsApp