Privacy Hub by Wrangu –
Solution for Turkey’s LPPD

Your go-to solution for Implementing the LPPD into your organisation

Privacy Hub by Wrangu – Solution for Turkey’s LPPD
partners

Quick Look: LPPD

The Law on the Protection of Personal Data (LPPD) passed into Law in Turkey in 2016 places specific regulatory requirements on organisations operating in Turkey and organisations outside of Turkey who process personal data of individuals located in Turkey. For most organisations, these requirements have led to the introduction of new processes, systems and personnel to enable them to meet their obligations. Privacy Hub by Wrangu, is a data privacy management solution that automates and harmonises the disparate activities of various teams into one seamless outcome ensuring ongoing compliance.

A look into the details of the LPPD articles immediately reveals several requirements of interest such as the rights of data subjects which organisations are required to fulfil within 30 days. Organisations are also required to maintain a record of processing activities, send personal data breach notifications to supervisory authorities and impacted data subjects, conduct data protection impact assessments, process personal data with appropriate safeguards and a more recent requirement to enrol personal data processing details that meet certain requirements in the Registry of Data Controllers with Verbis.

How to implement LPPD with the Privacy Hub by Wrangu

The Privacy Hub by Wrangu, is a data privacy management solution that automates LPPD processes in 4 modules: Data Subject Rights Requests Module, Data Protection Impact Assessments Module, Record of Processing Activities Module and Data Breach Reporting Module.

The data subject rights module provides the ability for data privacy teams and data subjects to raise and manage data subject rights requests allowing organisations to:

  • Capture DSR request details.
  • Validate the data subjects, agents and data subject rights requests.
  • Manage 30 days SLA duration.
  • Have a consolidated view of all open and closed data subject requests received from a particular data subject over a given period of time to manage excessive request.
  • Indicate whether a DSR request should be fulfilled based on the lawful basis of processing the information.
  • Confirm with data subjects how they would like to receive information in response to right to access requests.
  • Dynamically create tasks for the notification of third parties when fulfilling a right to erasure or right to rectification request.

Relevant LPPD Articles:

  • Article #5: Conditions for the processing of personal data
  • Article #6: Conditions for the processing of personal data of special nature (sensitive personal data)
  • Article #7: Deleting, destruction or anonymization of the personal data
  • Article #10: Obligation of the data controller to inform
  • Article #11: Rights of Data Subject

The DPIA module provides the ability to perform an initial DPIA screening questionnaire to determine if a new processing is likely to result in a relevant risk or damage to data subjects and, if required, conduct a full assessment for new projects, ensuring adherence to privacy by design principles. The DPIA module also provides:

  • Automatic evaluation of DPIA responses with possible concerns raised for consideration.
  • Built-in configurable risk calculation engine with risk ratings displays based on responses.
  • Facilitate multiple users’ completion of a single DPIA assessment.
  • Configurable approval levels throughout the lifecycle of an assessment including facility to capture and monitor advice from data protection officers.

Relevant LPPD Article:

  • Article #4 – General Principles
  • Article #5: Conditions for the processing of personal data
  • Article #12 – Obligations Concerning Data Security

Detailed record documenting processing activities with the ability to relate a ROPA directly to services, processes or configuration items within the ServiceNow CMDB. The ROPA module also supports:

  • Capture of all data sets as specified by Article 16 required for enrolment in the Registry of Data Controllers.
  • Maintain version history for each ROPA record to support auditing and complaints management activities and also ensure any updates to the ROPA are immediately informed to the Presidency.
  • Flag changes in the CMDB and other sources that would suggest a need to update the ROPA including provision of adequate technical and organisational measures for the security of personal data.
  • Generate and update a ROPA from a DPIA utilising the same data set from the DPIA.
  • Automatically indicate what rights data subjects can exercise against the data collected as part of this processing.

Relevant LPPD Article:

  • Article #16 – Registry of Data Controllers

Acts as a register of all data breach incidents as they relate to personal data and facilitate the automatic determination of whether a report or notification should be sent to the National Data Protection Authority (ANPD) or affected data subjects. This module also provides:

  • Standard process to support data gathering to determine if the personal data breach is likely to cause relevant risk or damage to the data subjects.
  • Automated data breach SLA calculator to ensure regulatory stated reporting timelines are monitored and complied with.
  • Generate and assign dynamic tasks to relevant parties in addressing data breach reporting requirements.
  • Support report creation for notification to the ANPD or communication to affected data subjects.

Relevant LPPD Article:

  • Article #12 – Obligations Concerning Data Security