6 Tips for Sensitive Personal Data Compliance

Nowadays, the use of the Internet has increased considerably, especially during the pandemic period. Personal data compliance became even more important during this period. The collection and processing of sensitive personal data is of great importance for the process of adaptation of enterprises to KVKK.

What is sensitive data?

Personal data is any information that belongs to specific or identifiable natural persons. Sensitive personal data, on the other hand, are data that are specifically categorized by kvkk and gdhpr.

If we define special category data;

  • Personal data related to race or ethnicity
  • personal data relating to political views
  • personal data relating to religious or philosophical beliefs
  • personal data relating to trade union membership
  • genetic data
  • biometric data (where used for identification purposes);
  • data on health
  • data on the sexual life of a person and
  • data on the sexual orientation of a person.

What are the terms of processing sensitive personal data?

Sensitive data is generally data that can lead to bullying between individuals. In such cases, data owners may be victimized. Legal rights and laws give more importance to this data. Sensitive personal data has more specific obligations and sanctions than normal personal data.

Personal data of a special nature may be processed in accordance with legal obligations after obtaining the consent of the data subjects by third parties. Otherwise, they have huge penalties. Data other than personal data related to health and sexual orientation may be processed without the consent of the person in accordance with the regulations made by law. Personal data related to health and sexual orientation can only be processed without the consent of the person by institutions and organizations that are obliged to keep secrets in order to protect public health and carry out medical treatments. The personal data protection board has competence in this regard. Transactions can take place after the person has examined the data to be processed without seeking consent.

Consequences of misuse of data subject to special category
In our country, the famous sharing site facebook was fined 1 million 650 thousand TL for committing a data breach in cookie management. Facebook had collected sensitive data from individuals without their consent and shared it with third parties. He was subject to criminal proceedings because he did not fulfill his obligations regarding data security.

In Turkey alone, 1286 people were affected and 155 people were fined a total of 550,000 TL by Cathay Pacific, the Hong Kong-based airline that obtained the passport numbers and health information of 155 people.
Tips for sensitive personal data compliance

make sure which data is in the sensitive data category. Special category data is usually data related to race or ethnicity, religious or political beliefs, health, sex life or sexual orientation within the scope of kvkk. However, sensitive data also includes genetic and biometric data.
Gather information. Find out what sensitive data is collected from the website of your business or business you own. At the same time, make sure that you are doing data protection in accordance with the law.

Evaluate how you protect data. We are all obliged to protect the privacy of data holders. Data owners, whose rights and freedoms are at stake, are of great importance. The data you obtain can cause victimization to individuals. If you do not process personal data in accordance with legal obligations, you may face legal sanctions. In such cases, it will be useful for you to first consult with a data controller.

Health data is the most important! Among the given, which falls into the special category, the most sensitive point is health data. The health data of individuals should never be processed and shared unless they have their consent.

Learn about criminal sanctions and the law on the protection of personal data. Consulting with a lawyer about criminal sanctions related to the data you use and their place in various data protection laws will allow you to conduct data management in the most correct way.

Paying attention to personal data has now become a necessity. If you want to manage cookies in accordance with kvkk and obtain consent, contact us! [email protected]

Disclaimer: All rights to any articles and content published belong to Efilli Software. All or part of any content, such as text, audio, video, and even if the source is shown or the active link is provided, cannot be used, published, shared or modified.