GDPR Compliance for Clinics and Medical Centers (Registration to VERBIS)

Handling complex data protection compliance processes that require constant monitoring using traditional methods is very challenging for both you and your consultant. We understand that your time is limited and valuable.

Share Blog
The choice of thousands of physicians and millions of patients #callendoc

GDPR Compliance for Clinics and Medical Centers (Registration to VERBIS)What is GDPR?

The Personal Data Protection Law, which came into force in 2016, regulates the obligations of personal data processors in the processing of personal data, and sets out the principles and procedures they must comply with. The law aims to protect the fundamental rights and freedoms of individuals, starting with the privacy of private life.

The addressee of the law includes all natural and legal persons engaged in personal data processing activities. Therefore, clinics and medical centers must process personal data in compliance with the law.

 

What Should Be Done?

Clinics collect and process the personal data of patients and employees. Therefore, they must conduct their activities in accordance with GDPR.  You can summarize what needs to be done, the legal obligations, in 9 main categories: GDPR Compliance for Clinics and Medical Centers (Registration to VERBIS)

  1. Information Obligation
  2. Data Security Obligation
  3. Audit Obligation
  4. Data Destruction Obligation
  5. Confidentiality Obligation
  6. Breach Notification Obligation
  7. Registration Obligation
  8. Responding to Applications Obligation
  9. Compliance with Personal Data Processing Conditions and Principles Obligation

 

What are the GDPR Sanctions?

  • Administrative Penalties for Violations*

    • Violation of the Information Obligation: Administrative fine ranging from 9,834 TL to 196,686 TL

    • Violation of Data Security: Administrative fine ranging from 29,503 TL to 1,966,862 TL

    • Failure to Comply with Board Decisions: Administrative fine ranging from 49,172 TL to 1,966,862 TL

    • Failure to Register: Administrative fine ranging from 39,337 TL to 1,966,862 TL

  • Penalties in Case of Violation

    • Illegal Recording of Personal Data: Imprisonment from 6 months to 3 years

    • Illegal Sharing and Disclosure: Imprisonment from 1 year to 6 years

    • Failure to Delete Data: Imprisonment from 6 months to 1 year

    • Compensation: Compensation for material damage and moral compensation claim

The registration obligation, also known as the obligation to register with VERBIS, has a registration deadline of March 31, 2021. Therefore, clinics and medical centers whose main activity is handling health personal data must complete their registration procedures by March 31.

For Detailed Information, Contact Bulutklinik Call Center: 0850 711 0258

Choose Your Cookie Preferences

Cookies are used on our site to provide you with the best service. For details Our Privacy Policy you can review or customize cookies.