Patient information guide

Privacy Notice Under Türkiye's Personal Data Protection Law (KVKK)

English information on how personal and health data may be processed by Dr. Cem Özlük MD. under Türkiye's Personal Data Protection Law (KVKK).

This notice explains how personal data may be processed by Dr. Cem Özlük MD., Urologist, as data controller in connection with the private practice, website and related communications. The governing legal obligations arise primarily under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and related legislation.

1. Data controller

Data controller: Dr. Cem Özlük MD. — Urologist
Practice: Dr. Cem Özlük MD. Muayenehanesi
Address: Çağlayan Mahallesi, 2055 Sokak No:31/1, Muratpaşa, Antalya, Türkiye
Phone: +90 535 463 53 33
Email: info@cemozluk.com
Website: https://cemozluk.com/en/

2. Who may be covered by this notice?

Depending on the interaction, data subjects may include:

3. What categories of personal data may be processed?

The categories depend on the purpose and the relationship with the practice. They may include:

Identity and contact data

Name, surname, date of birth or other identity information where legally or clinically required; phone number, email, address and communication preferences.

Health and sexual-life data

Medical history, symptoms, examination findings, diagnoses, laboratory and imaging results, prescriptions, reports, previous treatments or procedures, reproductive-health information and sexual-health information where relevant to care.

Health and sexual-life information may constitute special categories of personal data under Turkish law and requires the safeguards applicable to that category.

Information necessary for lawful billing, accounting, tax, reimbursement, legal obligations, formal requests or the establishment/exercise/protection of legal rights.

Communication and transaction data

Appointment records, messages, call or correspondence records where retained for a lawful purpose, requests, complaints and follow-up communications.

Visual or audio data

Photographs, video or audio are not automatically required. Where such data are medically or legally relevant, their processing must have an appropriate purpose and legal basis. Separate rules may apply to any use of patient images for public communication.

Website and technical data

Depending on the website configuration, server logs, device/browser information, security logs, cookie preferences and similar technical data may be processed for operation, security, compliance and—where permitted—analytics or service functionality.

4. Why may personal data be processed?

Personal data may be processed, where a valid legal basis exists, for purposes such as:

The purpose should be specific and proportionate to the data being processed.

5. How may data be collected?

Depending on the interaction, data may be collected through:

Not every channel is appropriate for every type of information. Sensitive data should not be shared unnecessarily through ordinary messaging channels.

Processing is carried out only where a legal basis under Law No. 6698 and other applicable Turkish legislation exists. The legal basis can differ according to the data category and the purpose.

Health and sexual-life information are special-category personal data. Their processing must comply with the conditions and safeguards applicable under Article 6 of Law No. 6698 and related rules.

An information notice and consent are not the same legal concept. Where explicit consent is actually required for a specific activity, it should be obtained separately rather than being assumed simply because this notice has been read.

7. To whom may data be transferred?

Where legally permitted and necessary for the stated purpose, data may be shared with relevant recipients such as:

Only data relevant to the purpose should be transferred.

8. International transfers

Some digital services—such as email, messaging, cloud infrastructure, hosting, maps, video, security or analytics tools—may involve the storage of or access to data outside Türkiye depending on the provider and configuration.

Any international transfer must be assessed under Article 9 of Law No. 6698 and the current Turkish rules for transfers abroad, including the applicable adequacy, safeguard or other lawful-transfer mechanism.

The existence of a foreign service provider does not by itself explain which data are transferred. The actual provider, configuration, purpose and legal mechanism should be documented in the relevant implementation records.

9. Retention

Personal data are not kept for one universal period. Retention depends on factors including:

When the legal grounds and purposes for processing end, data should be deleted, destroyed or anonymised in accordance with applicable law and the relevant retention/destruction rules.

Withdrawing consent, where consent is the relevant legal basis, does not require deletion of data that must still be retained under another legal obligation.

10. Confidentiality and information security

Reasonable administrative and technical safeguards should be applied according to the nature of the data and the risks involved. Access to sensitive information should be limited to persons and service providers who need it for a lawful purpose.

No electronic system can be described as having zero risk. The purpose of security measures is to reduce foreseeable risks and meet applicable legal obligations, not to make an absolute security promise.

11. Your rights under Article 11

Subject to the conditions and scope of Turkish law, a data subject may have rights including the right to:

These rights are subject to the legal conditions and exceptions that apply to the specific request.

12. How to apply to the data controller

A request relating to data-subject rights may be submitted through a method permitted by applicable Turkish law and the relevant secondary legislation. The request should identify the applicant sufficiently and explain the right being exercised.

Depending on the formal application method, requested information may include:

Identity documentation should be minimised to what is needed to verify the applicant. Unnecessary identity data should not be collected simply because a request concerns privacy.

13. Response time and possible fees

Under the applicable KVKK application framework, the data controller should respond to a valid application as soon as possible and no later than 30 days, depending on the nature of the request.

Applications are generally handled without charge, but where the process creates an additional cost, a fee may apply within the tariff/rules determined by the Personal Data Protection Board.

14. Children and represented persons

Where the data subject is a child or a person acting through a legal representative, authority and identity should be verified in a manner proportionate to the request and applicable law. Health information should not be disclosed to a person merely because that person claims to be a relative or companion.

15. WhatsApp, email and social-media privacy

When contacting the practice, do not send more sensitive information than necessary. In particular, avoid sending unsolicited:

If a particular document or image is clinically needed, the appropriate method for providing it should be clarified first.

16. Cookies and third-party services

Non-essential cookies and third-party technologies should be addressed separately according to their actual purpose, provider, duration and data-transfer characteristics. Where consent is required, it should not be inferred merely from continued browsing.

Users should be given the appropriate ability to accept, reject or change preferences for non-essential technologies according to the site’s implemented consent framework.

17. Changes to this notice

This notice may be updated when legislation, data-processing activities or technical services change. The current review date is shown with the page information.

Cookies required for site functions are always on. You can choose the other categories.

CallWhatsAppAppointment