Personal Data Protection Policy
Effective date: 16 July 2026
This policy explains the core principles applied by CCPB Control and Certification (CCPB IMC) to protect personal data in accordance with Turkish Law No. 6698 and related legislation.
Our principles
- Lawful, fair and transparent processing
- Accuracy and keeping data up to date where necessary
- Specific, explicit and legitimate purposes
- Data minimisation and proportionality
- Retention only for the necessary period
Data categories
Depending on the activity, CCPB may process identity and contact details; client and applicant records; professional, commercial and operational information related to certification and inspection; legal and financial records; job applicant information; and transaction security and website access logs.
Legal conditions
Data is processed where necessary for contract performance, legal obligations, establishment or protection of a right, legitimate interests, express statutory requirements and, only where required, explicit consent. Consent is not made a condition where another lawful processing condition applies.
Transfers
Personal data may be shared only for specified purposes and under a lawful condition with competent authorities, contracted service providers, audit or certification programme organisations and other legally authorised recipients. International transfers follow Article 9 of Turkish Law No. 6698 and applicable safeguard mechanisms.
Security, retention and deletion
Access is restricted, records are protected and confidentiality obligations are applied to service providers. Data whose retention period has ended is periodically deleted, destroyed or anonymised.
Data subject requests
Requests under Article 11 may be submitted to [email protected] or Tacettin Veli Mah. Deliklitaş Cad. Kahraman Plaza No:24 Floor:1, Melikgazi/Kayseri, Türkiye. Requests are answered within the statutory period after identity verification.