This notice explains how personal data may be processed by Dr. Cem Özlük MD., Urologist, as data controller in connection with the private practice, website and related communications. The governing legal obligations arise primarily under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and related legislation.
1. Data controller
Data controller: Dr. Cem Özlük MD. — Urologist
Practice: Dr. Cem Özlük MD. Muayenehanesi
Address: Çağlayan Mahallesi, 2055 Sokak No:31/1, Muratpaşa, Antalya, Türkiye
Phone: +90 535 463 53 33
Email: info@cemozluk.com
Website: https://cemozluk.com/en/
2. Who may be covered by this notice?
Depending on the interaction, data subjects may include:
- current patients and people considering a consultation;
- legal representatives, parents/guardians and authorised companions;
- people who contact the practice by phone, WhatsApp, email or website form;
- website visitors;
- suppliers and service providers;
- persons involved in administrative, legal or official processes connected with the practice.
3. What categories of personal data may be processed?
The categories depend on the purpose and the relationship with the practice. They may include:
Identity and contact data
Name, surname, date of birth or other identity information where legally or clinically required; phone number, email, address and communication preferences.
Health and sexual-life data
Medical history, symptoms, examination findings, diagnoses, laboratory and imaging results, prescriptions, reports, previous treatments or procedures, reproductive-health information and sexual-health information where relevant to care.
Health and sexual-life information may constitute special categories of personal data under Turkish law and requires the safeguards applicable to that category.
Financial, accounting and legal data
Information necessary for lawful billing, accounting, tax, reimbursement, legal obligations, formal requests or the establishment/exercise/protection of legal rights.
Communication and transaction data
Appointment records, messages, call or correspondence records where retained for a lawful purpose, requests, complaints and follow-up communications.
Visual or audio data
Photographs, video or audio are not automatically required. Where such data are medically or legally relevant, their processing must have an appropriate purpose and legal basis. Separate rules may apply to any use of patient images for public communication.
Website and technical data
Depending on the website configuration, server logs, device/browser information, security logs, cookie preferences and similar technical data may be processed for operation, security, compliance and—where permitted—analytics or service functionality.
4. Why may personal data be processed?
Personal data may be processed, where a valid legal basis exists, for purposes such as:
- confirming identity where necessary;
- organising appointments and patient communication;
- medical evaluation, diagnosis, treatment, care and follow-up;
- maintaining healthcare records required by law or clinical practice;
- preparing prescriptions, reports, referrals or other medical documents where applicable;
- protecting patient safety;
- coordinating laboratory, pathology, imaging or other healthcare services;
- responding to patient requests and complaints;
- financial, accounting and tax obligations;
- responding to legally authorised requests from public bodies or courts;
- information-system, website and data-security operations;
- establishing, exercising or defending legal rights;
- fulfilling legal, regulatory and professional obligations.
The purpose should be specific and proportionate to the data being processed.
5. How may data be collected?
Depending on the interaction, data may be collected through:
- in-person consultations and examinations;
- phone calls, WhatsApp, email and website forms;
- patient records and practice information systems;
- laboratory, pathology, imaging, hospital or other healthcare-provider records where lawfully shared;
- documents supplied by the patient or an authorised person;
- legally authorised public bodies and official systems;
- technical website and security logs.
Not every channel is appropriate for every type of information. Sensitive data should not be shared unnecessarily through ordinary messaging channels.
6. Legal bases and special-category data
Processing is carried out only where a legal basis under Law No. 6698 and other applicable Turkish legislation exists. The legal basis can differ according to the data category and the purpose.
Health and sexual-life information are special-category personal data. Their processing must comply with the conditions and safeguards applicable under Article 6 of Law No. 6698 and related rules.
An information notice and consent are not the same legal concept. Where explicit consent is actually required for a specific activity, it should be obtained separately rather than being assumed simply because this notice has been read.
7. To whom may data be transferred?
Where legally permitted and necessary for the stated purpose, data may be shared with relevant recipients such as:
- Ministry of Health systems and other legally authorised health authorities;
- courts, prosecutors, law-enforcement bodies and other authorised public institutions;
- tax, social-security or other competent authorities where required;
- laboratories, pathology/imaging providers, hospitals and healthcare professionals involved in lawful care coordination;
- authorised legal, accounting, IT, hosting, communication, archive or security service providers acting within their role and contractual/legal obligations;
- other recipients when required or permitted by applicable law.
Only data relevant to the purpose should be transferred.
8. International transfers
Some digital services—such as email, messaging, cloud infrastructure, hosting, maps, video, security or analytics tools—may involve the storage of or access to data outside Türkiye depending on the provider and configuration.
Any international transfer must be assessed under Article 9 of Law No. 6698 and the current Turkish rules for transfers abroad, including the applicable adequacy, safeguard or other lawful-transfer mechanism.
The existence of a foreign service provider does not by itself explain which data are transferred. The actual provider, configuration, purpose and legal mechanism should be documented in the relevant implementation records.
9. Retention
Personal data are not kept for one universal period. Retention depends on factors including:
- healthcare record-keeping obligations;
- tax, accounting and regulatory requirements;
- the purpose for which the data were collected;
- limitation periods and the establishment or defence of legal rights;
- applicable health-data and professional rules.
When the legal grounds and purposes for processing end, data should be deleted, destroyed or anonymised in accordance with applicable law and the relevant retention/destruction rules.
Withdrawing consent, where consent is the relevant legal basis, does not require deletion of data that must still be retained under another legal obligation.
10. Confidentiality and information security
Reasonable administrative and technical safeguards should be applied according to the nature of the data and the risks involved. Access to sensitive information should be limited to persons and service providers who need it for a lawful purpose.
No electronic system can be described as having zero risk. The purpose of security measures is to reduce foreseeable risks and meet applicable legal obligations, not to make an absolute security promise.
11. Your rights under Article 11
Subject to the conditions and scope of Turkish law, a data subject may have rights including the right to:
- learn whether personal data are being processed;
- request information if data have been processed;
- learn the purpose of processing and whether data are used in accordance with that purpose;
- know the third parties to whom data have been transferred in Türkiye or abroad;
- request correction of incomplete or inaccurate personal data;
- request deletion or destruction where the legal conditions are met;
- request notification of relevant correction/deletion actions to third parties to whom the data were transferred, where applicable;
- object to a result that is unfavourable to the person and arises exclusively from automated analysis, within the scope of the law;
- claim compensation where damage has been suffered because personal data were processed unlawfully.
These rights are subject to the legal conditions and exceptions that apply to the specific request.
12. How to apply to the data controller
A request relating to data-subject rights may be submitted through a method permitted by applicable Turkish law and the relevant secondary legislation. The request should identify the applicant sufficiently and explain the right being exercised.
Depending on the formal application method, requested information may include:
- name and surname;
- signature for a written application where required;
- Turkish ID number for Turkish citizens, or nationality and passport/identity details for foreign applicants where legally necessary;
- address for service;
- contact details;
- the subject of the request;
- supporting information or documents where necessary.
Identity documentation should be minimised to what is needed to verify the applicant. Unnecessary identity data should not be collected simply because a request concerns privacy.
13. Response time and possible fees
Under the applicable KVKK application framework, the data controller should respond to a valid application as soon as possible and no later than 30 days, depending on the nature of the request.
Applications are generally handled without charge, but where the process creates an additional cost, a fee may apply within the tariff/rules determined by the Personal Data Protection Board.
14. Children and represented persons
Where the data subject is a child or a person acting through a legal representative, authority and identity should be verified in a manner proportionate to the request and applicable law. Health information should not be disclosed to a person merely because that person claims to be a relative or companion.
15. WhatsApp, email and social-media privacy
When contacting the practice, do not send more sensitive information than necessary. In particular, avoid sending unsolicited:
- intimate photographs;
- full identity-document copies unless specifically and lawfully required;
- third-party health records without authority;
- bank-card security information;
- account passwords or access codes.
If a particular document or image is clinically needed, the appropriate method for providing it should be clarified first.
16. Cookies and third-party services
Non-essential cookies and third-party technologies should be addressed separately according to their actual purpose, provider, duration and data-transfer characteristics. Where consent is required, it should not be inferred merely from continued browsing.
Users should be given the appropriate ability to accept, reject or change preferences for non-essential technologies according to the site’s implemented consent framework.
17. Changes to this notice
This notice may be updated when legislation, data-processing activities or technical services change. The current review date is shown with the page information.