
Transkript
Tamam, bu bizim ilk İngilizce podcastımız.
Değil mi arkadaşlar? Evet Fatih.
Ve şu an ne yapacağımızı bilmiyoruz.
Ama başlayacağız.
Umarım iyi bir şey bulacağız.
Tamam, mükemmel. Podcastın ismini başlayalım.
Podcastın ismi Selam Ekip, değil mi?
Evet, Selam Ekip. Ve İngilizce'de hi team, hello team demek.
Böyle bir şey. Ama iyi bir Türk kelimesi.
Ve bence bunu tutacağız. Selam Ekip iyi.
Selam Ekip. Hi. Gizem, yeniden buradayız.
Nasılsın? Evet, iyiyim.
Teşekkürler. Sen? Bu, Türk okullarında en ünlü Türk kelimesi.
Çok iyi, teşekkür ederim.
Bu yüzden burada başka bir podcast kaydettik ve Fatih Bayındır ve Abdülhamit Çavdar'la birlikteyiz.
Onlar da Data Protection ve InfoSec ekibindeler.
Merhaba arkadaşlar ve podcast'a hoş geldiniz.
Sizinle ilgili bir şey söyleyebilir misiniz?
Ben Trendyol InfoSec ekibimim.
İlk 2 yıldır Trendyol'da çalışıyorum.
InfoSec ekibim olarak, özellikle güvenlik ve risk kontrolü konusunda sorumluyuz.
İzlediğiniz için teşekkür ederim.
inside technology teams and help the data protection teams on technical developments to cope with data protection risks actually.
These are our main responsibility areas.
For data protection sites, we especially work for like to comply with GDPR and Turkish GDPR, KVKK.
So thank you for having me in your podcast.
I'm super happy to be here. Thank you.
Thank you Fatih. Maybe also a few words from my side.
My name is Abdulhamid but actually no one but my mom calls me Abdulhamid and only when...
Altyazı M.K. Bu
konuda size bir soru sormak istiyorum.
Sizin çalıştığınız domen nedir?
Bilgisayar protekşi ile başlayalım.
İlk olarak, adımda söylediğim gibi, ben bilgisayar protekşi alanında çalışıyorum.
Bu anlamda ne demek? İnsanlar her zaman düzgün düşünüyorlar ki, tüm işçiler, tüm hukuk işleri yapıyorlar, her şey hukuk ve hukuk.
Hayır, bu değil. Bilgisayar protekşi, çok çok farklı şeylerden oluşuyor.
Bilgisayar protekşi, tabi ki hukuk, Avrupa'da ve Türkiye'de hukuk konusunda oluşuyor.
Altyazı M.K. İzlediğiniz için teşekkür ederim.
Altyazı M.K.
İzlediğiniz için teşekkürler.
that are related to our technology, that are our code bases.
And these risks are basically like defined on data actually.
So the data protection and the personal data and sensitive data is very important for us.
That's why we work closely with Optus team, like data protection office.
We are also working closely with legal teams and also risk management teams there as well.
So we get the requirements of the laws and also like the best implementation standards from them.
And then we work with product teams, technology teams.
ürünleri geliştirmeye başladık.
Ve data proteksi dışında, aslında diğer güvenlik alanlarından da sorumluyuz.
Güvenlik anlamı.
Devletlerimizin, analitik ekibimizin, diğer ekibimizin de güvenlik anlamını artırmaya çalışıyoruz.
Hr ekibimizde de.
O yüzden, onların sosyal veri ve kişisel veriyle çalıştıkları zaman, onların güvenlik anlamını artırmanın bazı riskleri var.
Bu yüzden, onların güvenliğini artırmaya çalışıyoruz.
Bazı eğitimlerle.
İzlediğiniz için teşekkür ederim.
I couldn't remember the word. Mesai.
Our work hours mainly consist of working with Optus team actually.
Like 40%, 50% of the time we work with them because data protection is our main common topic.
So we should work closely with them.
Yeah, these are domains we work as information security team actually.
Thanks for the detailed answers.
When I was working on the custom experience team, we worked with Fatih about data protection and breach risk.
And I know that you are mostly working with every team.
But I want to ask you that are...
All the teams you work with in Berlin or you work with in Turkey?
Yeah, as you just said, we work closely with so many teams actually but our main shareholders or maybe peers are data protection team.
Data protection team is actually based in Berlin and Abdül can talk about their team, their structure.
And also we work with legal teams like GDPR legal team and also KVKK legal team.
GDPR legal team is based in Berlin as well and we have legal counsel there.
He is living in Netherlands.
İzlediğiniz için teşekkür ederim.
...office and also legal team for GDPR and also for legal team KVKK.
For the protection stuff we work with them and also as I said we work with dev teams like international storefront team that we work with for the international site.
We work with them for the developments that are related to German website, our German website trendyol.de and these teams are based in Berlin actually like international storefront team, international checkout team
as well. So yeah, these are the product development.
altyazı M.K.
Altyazı M.K. İzmir'de bu stüdyoyu açıklayabilir misin?
Evet, kesinlikle. Sizin de söylediğiniz için çok fazla eklemem lazım.
Evet, normalde Almanya'dayım.
Şu an İzmir'deyim ve hava beni öldürüyor.
Ama genel olarak Almanya'dayım ve Berlin'den çalışıyorum.
Ama şirket stüdyosu nedeniyle, çoğu şirketin Türkiye'de yaşıyor ve çalışıyor.
Bu yüzden Türkiye'deki arkadaşlarımızla çok yakın çalışıyoruz.
Ve çeşitli departmanlar.
Ve tabii ki en önemli departmanlar ve en önemli takımımız KVKK.
İzlediğiniz için teşekkür ederim.
İzlediğiniz için teşekkürler.
İzlediğiniz için teşekkür ederim.
İzlediğiniz için teşekkür ederim.
İzlediğiniz için teşekkür ederim.
Örneğin, bir webinar olabilir, farklı, pre-recorded video sesleri olabilir, farklı ekiblerle live sesler yapabiliriz.
Belki de bu, ne diyebiliriz, town hall'a girebiliriz, privacy aspektlerinden bahsedebiliriz, vs.
Bu yüzden, genellikle, bazı bilgilerle iletişim yapıyoruz.
Örneğin, bir data breach olduğunda, çok ciddi bir konu olduğunda, sonra bu bölgeye sorumluluklu bir key stakeholder ile birlikte geliyoruz ve bazı şeylerle alınıyoruz.
Örneğin, bu podcast ile ilgili.
Bu yüzden, beni bu konuda davet ettiğiniz için çok teşekkür ederim.
Bence bu, çok güzel bir inisiyatif.
Ve bu kanalı da kullanabiliriz.
İzlediğiniz için teşekkür ederim.
İzlediğiniz için teşekkür ederim.
Well, since we are moving in English in all trends, but we are now on the process.
Is the language barrier a problem for you and your colleagues?
For me personally not. I mean, I've been working with English, you know, since a while.
But my Turkish is not as good as yours, of course, because, you know, we moved to Germany when I was one.
So this means my Turkish level is kind of, I don't know, on a level of five years old.
But we do see sometimes issues in the meetings, right?
I know we have so many smart people in this meeting.
And I see in their eyes they have to answer to the question.
But they're hesitating to speak in English because they don't feel comfortable with their English level.
And maybe just, you know, just a message to all people, right?
Please don't hesitate, right? There's this one stand-up from Cem Yılmaz, probably you know that, right?
Where he says Turkish people go to, I don't know, to UK and try to speak in a native language.
That's absolutely not necessary. We can all mistakes and we should all make mistakes.
It's more important to deliver the message what you have in your mind and, you know, help us by solving the problem than trying to speak.
İzlediğiniz için teşekkür ederim.
way to deliver solutions and don't hesitate to make mistakes guys.
Very good point. Yeah, thank you.
Okay, thank you.
What about your team's biggest challenge?
What is your biggest challenge as a team of different cultures?
Yeah, let me go. First year maybe.
Like as you know like the security topics and also the data protection topics are like seeing people to a barrier actually.
So when they want to do something they want to do their work and then some teams pops up and says you are lacking this kind of measures in your work.
You should do this and you may sometimes seem to them like a barrier to their like deadline.
But that's not the thing actually.
So we try to communicate with them like if we work on these measures our customers will be happy.
İzlediğiniz için teşekkür ederim.
So we will have more customer success actually since our main focus as a company is to make our customer happy.
So we try to give this awareness to our stakeholders actually.
And also these are the topics, the private topics we'll be coming with Abdul actually like from the DPO team.
So yeah, these are the challenges actually.
But inside Trendyol, since as a team we have a very good communication between us, we can easily convey our message to the teams, the people and they are very keen on.
İzlediğiniz için teşekkür ederim.
Karriere, farklı şirketler arasında, bir konsültör olarak bile.
Her zaman iki sorun var. İlk sorun, organizasyon içerisinde data protection ekibinin imajıdır.
Bazı organizasyonlar, ve ben de tepki aldım, evet, data protection ekibine çalışmak istemiyorum, çünkü onlar teknolojilerimizi, fikirlerimizi, bizi desteklemek istiyorlar.
Ve bu benim için bir çılgınca olacaktır, eğer bu benim imajım olsaydı, ya da trenciler içerisinde ekibimizin imajı olsaydı.
Biz blocker değiliz, biz enableriz.
Genellikle nasıl çalışırız? İzlediğiniz için teşekkür ederim.
I don't know. We want to implement this project and this idea.
And our job as a data protection team is to help them to implement it in a compliant way.
It's not to block them something or to say no.
You will never hear no from us.
You will always hear, well we should do that, you know.
And then we will come up with the controls which need to be implemented.
That's the first challenge but that's totally normal.
And the second challenge is, this is more dangerous than the first one, is if the company and the organization has the perception that privacy is just a legal requirement.
İzlediğiniz için teşekkür ederim.
Ve size bir örnek verebilirim.
Düşünün, biz büyük bir veri kaybımız var ve şirketin reputasyonunu kaybediyoruz.
Kullanımcılar, satıcılar bizi artık güvenmiyorlar.
Onlar sadece hesaplarını deletiyorlar ya da diğer platformlara girebiliyorlar.
Bu reputasyon kaybından kurtulmak çok zaman ve çok daha fazla para ihtiyacı var.
Daha fazla para ve zaman ve çalışmalar ödenebileceğine göre daha fazla para ödenebiliyoruz.
Özellikle Ozan'la bir sorun yaptık.
Ve o bizimle çok güzel bilgiler paylaştı.
Bu yüzden 98 %'lik müşteriler privacy'ye çok önemli bir konu olduğunu düşünüyor.
Ve bu konuların müşterilerin bizim platformumuzda çalışma yolu olduğunda bu konulara dikkat ediliyorlar.
Bu demek ki, işe ulaşmanız gerektiğinde, müşterilerimize transfer edemeyiz ve onlara hissediyoruz ki, bu sizin için güvenli bir yer.
Bizle iletişim ederseniz, bu, bu şirketin içerisinde kalır.
Bu anlayış çok önemli bir şirket için.
But we are moving the right way and I think we will become one of the best organizations from a privacy point of view.
Not only in Turkey but I think globally.
And this is my personal goal, my personal objective to achieve over the next few years.
I really like how you phrase it that you are not blockers, you are enablers.
Well we are all in one team and we are thinking about every aspect.
But with your help I believe none of us would want data breach problem.
And with your help I believe we are moving to the same page.
From here I am moving to can you share the technology?
İzlediğiniz için teşekkür ederim.
Ayrıca antivirüs programlarını engellemek için kullanıyoruz.
Bu teknolojiler bizim güvenlik ekibimizden kullanılıyor.
Ama InfoSec ekibimizde özellikle risk değerlendirme uygulamaları gibi teknolojileri kullanıyoruz.
Ve ayrıca, ben de söylediğim gibi, Trendyol'un içerisinde güvenlik bilgisayarını çalışmaya çalışıyoruz.
O yüzden biz de güvenlik bilgisayarını yaratan şirketin içerisinde fake phishing e-mails gönderdiğimiz bir simülasyon uygulamalarımız var.
Ayrıca diğer uygulamalarımız var.
İzlediğiniz için teşekkür ederim.
Trenzyol'un içerisinde yayınladığı bir ürün. Bu ürün, Infosec'in siteinde kullanıldığı ürünlerdir.
Ayrıca, daha önce, Infosec ve DPO Team'ler arasındaki başka ürünlere sahip olduk.
Bu ürün, Trenzyol'un içerisinde yayınladığı ürün.
Bu ürün, Trenzyol'un içerisinde yayınladığı ürün.
Bu ürün, Trenzyol'un içerisinde yayınladığı ürün.
Bu ürün, Trenzyol'un içerisinde yayınladığı ürün.
Bu ürün, Trenzyol'un içerisinde yayınladığı ürün.
Bu ürün, Trenzyol'un içerisinde yayınladığı ürün.
Bu ürün, Trenzyol'un içerisinde yayınladığı ürün.
Bu İzlediğiniz
için teşekkür ederim.
İzlediğiniz için teşekkür ederim.
So this is the one thing and the second one is OneTrust.
OneTrust is a privacy tool which you all will be using so the whole audience who is listening to this one because you need to document your processing tweets where you process personal data and this is one requirement of the law, right?
The GDPR says you need to have a repository of processes where you process personal data and the purpose and the reason behind that is basically know your data.
We all know the concept of know your customers so this means you need to do proper due diligence process, you need to check if the person who says that this person Evet, evet.
Altyazı M.K.
I think these are so deeply valuable.
And I want to ask your metrics.
What kind of metrics are you tracking?
Just from a privacy point of view, there are a lot of metrics, right?
So you have, of course, metrics, outside going metrics, like how many customers requested deletion and how much time did it take to perform the deletion?
How many customers asked for their personal information?
And what else do we track?
How many customers unsubscribed from news centers and still get news centers, right?
Do we have a technical issue here?
Internal interesting metrics would be for instance what is the percentage of employees trained for data privacy?
How many data breaches did we have?
What is the percentage of data breaches often within human error?
So where did a human make a mistake?
And what is the percentage of data breaches with a technical issue?
So just out of experience using these metrics you can detect certain trends.
Just to give an example and this is something what I've seen in many organizations as well.
This is a usual trend. 99% of the data breaches are caused by human beings.
İzlediğiniz için teşekkür ederim.
İzlediğiniz için teşekkür ederim.
Evet, biz de aynı metriklerimiz var.
Abdül çok çabuk açıklamıştı.
Ayrıca teknoloji infrastruktürümüzde risklerimizi ölçüyoruz.
Yani risk etkileşimi kabul edilebilecek nesilleri azaltıyoruz.
Yani risk nesillerini azaltıyoruz ve kabul edilebilecek nesilleri azaltıyoruz.
Ayrıca, Abdül'ün söylediği gibi, çoğunlukla insanlık sorunlarından dolayı data kısımları görüyoruz.
İzlediğiniz için teşekkür ederim.
Ayrıca, Trandall'ın işçilerimizin güvenliği ve güvenliğe sahip olduğundan bahsetmeye çalışıyoruz.
Yıllardır güvenliğe sahip olduğundan bahsediyoruz. Bu güvenliğe sahip olduğundan bahsediyoruz.
Evet, bu da Trandall'ın içerisindeki metriklerden biri.
Her zaman değişen bir alanımızda, kişisel gelişim için zaman almanın önemli bir kısmı var.
Bu konuda zamanınız var mı?
Evet, aslında.
Çok fazla şey yapmamız gerekiyor.
Bazen işlerimizi tamamlamak için daha çok çalışma saatini bulabiliriz.
Ama bu bizim için bir sıkıntı değil.
Kişisel gelişim için zamanlar da bulunuyoruz.
Ve Trendyol çok geniş bir çevre.
Burada çok fazla teknoloji bulabiliyorsunuz.
Çok farklı arkeolojiler, çok farklı...
Altyazı M.K.
Altyazı M.K. İzlediğiniz
için teşekkür ederim.
İzlediğiniz için teşekkür ederim. İzlediğiniz
için teşekkür ederim.
You know, what are the learnings of the last year?
Where should I focus on the next year?
What are the weaknesses I've detected?
Or what are my strengths I should especially focus on?
You know, what I could leverage for me and for my team to be better as an organization.
So these are the things what I'm looking at.
And one of the things what is also super interesting at Trentual is...
Altyazı M.K.
Thank you.
And according to what you mentioned earlier, you care a lot about communication and soft skills.
Mistakes are not punishing but instructive for you.
And what do you think is the most important soft skill that...
Team members should have.
So in the data protection team, I think that's similar also to InfoSec.
I'm not sure if you heard about the Howard concept.
So what the Howard concept says is actually, you know, be very kind and soft to people but be very hard with the message you want to deliver, right?
So if you have a legal opinion and if you think that what the organization is doing or what the team is doing is wrong, then you should stay to your opinion.
Altyazı M.K.
Maybe the most important rule for communication within the data protection team.
Yeah, so Harvard concept. I really encourage everyone to read it.
Thank you, Abdul. Similar goes for us actually.
Like as security team and as an infosec team, we talk to our team leads like Sibel and also with Çağlar abi, Çağlar Çakıcı.
We all learn by our mistakes actually.
So this is actually the culture of Tranjo and this is also the culture of information security team for us.
So yeah, when we do make mistakes, we all hear most, we will all do make errors, we will all do make...
İzlediğiniz için teşekkür ederim.
Ama yanlış yaparken onlardan öğrenmeye çalışıyoruz.
İnsanlardan kapatmamızı istemiyoruz.
Kalsın on our side actually.
Ve bakıyorum ki bu ilginç, bu bir hata değil.
Ve sonra sadece sizin yaptığınızı izlemek için, iyi ya da kötü olup, ben öğretiyorum.
Bu yüzden, tüm hatalarımızı yaptığımız için çok mutlu olmalıyız.
Bir organizasyon olsaydık, hatalar yapmamız mümkün değildi.
Bu çok toksik bir organizasyon olsaydı.
Ve ben de böyle organizasyonlar için çalışıyordum.
Yani insanlar, herkes konvort zonunu bırakmak istemediler.
Sadece korkudan. They could make mistakes.
This is the death for an organization, right?
So we should make mistakes but the mistake shouldn't repeat itself, right?
So we should try to learn from what we have done wrong in the past and stop doing that in the future.
Totally agree, Abdül. So we'll have data breaches like because of the human errors or maybe with technical errors.
This may be a message to the team.
Please come to us like to discuss the details.
Don't hesitate. We are all humans.
We can work together to fix it actually.
Yeah. Well, we are finishing this great podcast.
I really want to thank you again.
And we have a tradition that Bilmiyorum biliyormusunuz ama birinizin favori şarkılarınızı şarkı söylemeniz iyi olur.
Sanırım Fatih de bunu yapacak.
Bilmiyorum, sen de şarkıların var mı?
En büyük sorunum şarkı sözlerini hatırlayamıyorum.
Her zaman sadece bir şarkı söyleyemiyorum ve o kadar.
Bilmiyorum. Düşünün, düşünün.
Aslında ben çok eski bir insanım, o yüzden hatırlamıyorum.
Şu anda pop müziği dinlemiyorum.
İbrahim Tatlıses'in ya da Fati'nin gibi bir şarkısına şarkı söylemek isterdim.
Fati'ye ilk gelin, sonra yeni bir şarkı söylemeye çalışacağım.
Tamam. Belki Fenerbahçe'nin fan şarkısını söyleyebilirim.
Çünkü ben Fenerbahçe'nin fanıyım.
Maziinde bir tarih yatar, yaşa Fenerbahçe.
Teşekkürler Fatih, teşekkürler.
Mutluluğunu sevene. Bu kadar.
Çünkü ben bir Galatasaray fanıyım, bunu izlememeliyim, üzgünüm.
Hiçbir sorun yok.
Çok güzel bir sesiniz var Fatih abi.
Daha çok şarkı söylemelisiniz. Tebrikler.
Sadece aklıma gelen tek şey bu.
Oynama şıkıdım şıkıdım.
Oynama şıkıdım şıkıdım.
Oynama şıkıdım şıkıdım.
Oynama şıkıdım şıkıdım. Oynama şıkıdım şıkıdım. Oynama şıkıdım şıkıdım. Oynama şıkıdım şıkıdım.
Oynama şıkıdım şıkıdım şıkıdım.
Oynama şıkıdım şıkıdım şıkıdım.
Oynama şıkıdım şıkıdım şıkıdım.
Oynama şıkıdım şıkıdım şıkıdım.
Oynama şıkıdım şıkıdım şıkı Çok teşekkürler.
Hoşçakalın.
Bu transkript otomatik olarak çıkarıldı; kayıtla küçük farklar olabilir.
