Last updated · 21 May 2026
1. Purpose
Kaptanoğlu & Partners Law Firm adopts the following principles to ensure Information Security for its clients, employees and other relevant individuals. This Policy is prepared in compliance with the Law on Attorneyship, the Code of Professional Conduct of the Union of Turkish Bar Associations and Law No. 6698 on the Protection of Personal Data (KVKK).
2. Confidentiality Obligation
The attorneys and personnel of Kaptanoğlu & Partners hold all information and documents learned in the course of their professional activity under a duty of confidentiality pursuant to Article 36 of Law No. 1136 on Attorneyship. This obligation continues after the termination of the client relationship.
3. Information Security Principles
- Confidentiality:A “need-to-know” principle is applied so that only authorised persons can access information.
- Integrity: Technical and administrative measures are taken to prevent unauthorised alteration of data.
- Availability: Access is provided only to authorised users when needed.
4. Technical Measures
- TLS / HTTPS encryption in transit and on servers
- Firewalls and intrusion detection/prevention systems
- Authorisation and multi-factor authentication (MFA)
- Regular security patches and system updates
- Regular backups and disaster recovery tests
- Access logging and audit
5. Administrative Measures
- Confidentiality agreements for personnel
- Regular information security and KVKK training
- Authorisation matrices and separation of duties
- Data inventory and records of processing (VERBİS)
- Incident management and reporting procedures
- Data processor agreements with vendors and partners
6. Breach Notification
Where personal data is found to have been obtained by unauthorised persons, Kaptanoğlu & Partners shall notify the Personal Data Protection Authority and affected individuals as soon as possible (and no later than 72 hours) pursuant to KVKK Art. 12/5.
7. Retention and Destruction
Personal data is retained for the period prescribed by applicable legislation or required for the purpose of processing. At the end of such period, it is destroyed by deletion, destruction or anonymisation in accordance with the Kaptanoğlu & Partners Data Retention and Destruction Policy.
8. Review
This Policy is reviewed and updated at least annually or upon changes in legislation.
Contact
For questions regarding information security or KVKK, you may reach us at info@kaptanoglu.av.tr.
