LEGAL SUPPORT AND CONSULTİNG FOR NATURAL AND LEGAL PERSONS İN THE FİELD OF PERSONAL DATA PROTECTİON
General Overview
With the development of technology and the transformation in the social and economic spheres, personal data related to individuals are increasingly being collected by both natural and legal persons as a result of services provided, tasks performed, and various interactions. As personal data has been processed for many years in the social and economic realms, various efforts have been made in the legal field to regulate the processing and protection of personal data, resulting in the establishment of a legal framework. The T urkish Personal Data Protection Law (Law No. 6698), which was published in the Official Gazette on April 7, 2016 (No. 29677), regulates how personal data collected from individuals can be processed. This law aligns with the 95/46/EC Directive on the protection of personal data, the General Data Protection Regulation (GDPR) adopted by the European Union on April 27, 2016 (Regulation No. 2016/679), and the Convention No. 108 on the protection of individuals with regard to automatic processing of personal data, signed in Strasbourg on January 28, 1981.
Who is the “Data Controller” and the “Data Processor”?
With the enactment of Law No. 6698, the concepts of “data controller” and “data processor” were introduced into the context of personal data protection. The law clearly defines who qualifies as a data controller and who qualifies as a data processor, leaving no room for ambiguity. According to the law, the data controller is defined as “a natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.” On the other hand, the data processor is defined as “a natural or legal person who processes personal data on behalf of the data controller, based on the authority given by the data controller.”
These two roles may be held by the same person or entity in some cases, but more commonly, they are separate. The key distinction is that the data controller has the authority to make decisions regarding any operation or action concerning personal data from its collection to the expiry of its storage period. In contrast, the data processor acts under the authority of the data controller, carrying out the instructions provided by the data controller.
For example, a company “X” operating in the sales and marketing sector may collaborate with a research company to assess the impact of a newly released product on the target customer base and how this affects sales figures. In such a case, the data concerning the targeted customer group, which will be collected during the field research, including the type of personal data and the duration of its processing and storage, will be under the control of the company “X,” which would be the data controller. The research company, however, would be processing the data on behalf of company “X” and would therefore be considered the data processor.
What Services Can Be Provided in the Context of Personal Data Protection?
Following the enactment of the law, one of the significant consequences for legal entities is the obligation to register with the Data Controllers’ Registry. However, depending on objective criteria, such as the nature of the personal data processed, the volume of data, whether the processing arises from legal obligations, or the transfer of data to third parties, the Personal Data Protection Authority may exempt certain data controllers from the registration requirement.
For legal entities, the compliance process with the Turkish Personal Data Protection Law (TPDPL) initiated in 2016 involves several procedures that must be followed. The first decision to be made is determining the scope of the compliance project, considering the company’s size, and identifying the individuals who will be responsible for executing the project. For data controllers, processing personal data is not a one-time task, but rather an ongoing process that must be continuously managed within the scope of their activities. To ensure that all actions comply with the law, it would be prudent to seek guidance from legal experts and data security specialists.
Developing a Comprehensive Strategy in Compliance with the Personal Data Protection Law
Individuals and legal entities, as well as their employees and customers, will be able to process personal data within their systems only within the boundaries set by the Turkish Personal Data Protection Law. In this context, there are certain principles that must be taken into account when processing personal data. Accordingly, personal data processing must be carried out in accordance with the law and the principle of honesty; the data processed must be accurate and up-to-date; the data must be processed for specific, clear, and legitimate purposes; it should be processed in a manner that is limited and proportional to the purpose for which it was collected; and the processed data should be stored for no longer than the period prescribed by the relevant regulations or necessary for the purpose for which it was processed. If data processing is carried out contrary to these principles, the data controller (the company) will be held administratively and financially responsible. To avoid such harm and to carry out a data processing process in compliance with the law, it would be advisable to work with an expert lawyer and determine an appropriate data processing strategy for the data controller company. It is important to note that the strategy for processing personal data should not be a quick fix to avoid sanctions but should be the first step in establishing a tradition of data processing for the legal entity.
Preparation of Necessary Documents Regarding the Confidentiality Agreements, Consent, Data Access Procedures, and Disclosure Obligations Related to Customer Data
Although the law does not differentiate between natural and legal persons as data controllers, individuals whose personal data are protected under the law—referred to as “data subjects”—can only be natural persons. In this context, there are certain obligations that must be fulfilled regarding natural persons who are either employees of the legal entity or interact with the legal entity. First and foremost, the explicit consent of the natural persons whose data will be processed must be obtained. Article 20, paragraph 3 of our Constitution stipulates that personal data can only be processed in cases provided by law or with the explicit consent of the individual. Data can only be processed without explicit consent in the circumstances enumerated by law.
Explicit consent is an informed and freely given statement of will regarding a specific subject. In this sense, the first step in obtaining explicit consent is the information phase. The person whose personal data will be processed must be informed about the process before their consent is sought. Although there is no formal requirement for obtaining explicit consent, for evidentiary purposes, it would be advisable for the data controller to obtain consent in writing or electronically.
The obligation to inform is not dependent on the request of the data subject, and in any dispute regarding this matter, the burden of proof that the obligation to inform has been fulfilled lies with the data controller.
In addition to the explicit consent obtained as a result of fulfilling the obligation to inform, a contract will be signed with the data subjects within the framework of the confidentiality policy, stating that the personal data obtained will not be shared with third parties. This is of paramount importance in terms of the fundamental rights and freedoms of the individual, and to avoid violations of rights, this must be carefully considered by data controllers on behalf of their clients.
Notification to the Personal Data Protection Authority and Preparation of Other Applications
The natural and legal persons referred to as data controllers in the law are those who determine the purposes and means of processing personal data and are responsible for establishing and managing the data recording system. Natural and legal persons must register with the Data Controllers Registry before making any data notifications. Data controllers who are registered in this registry with the Personal Data Protection Authority are required to notify the Authority regarding the personal data they hold about their customers and employees. Additionally, data controllers must apply to the Authority for any statements, complaints, or other transactions regarding personal data. It is essential that these notifications and applications are carried out in compliance with the procedure. Therefore, having lawyers specialized in this area manage the process will help prevent potential losses of rights.
Consultancy for Protecting Employees’ Data, and Organizing Training Programs for Companies and Institutions
The compliance process project we implement in the context of personal data protection should not be limited to notifications and applications to the Authority. The issue of personal data, which has only recently started to develop in our country, is gradually being shaped by regulations and decisions issued by the Personal Data Protection Authority. The scope and framework of this area are still evolving and should be closely monitored to ensure that companies are in full compliance with the latest requirements.
Lawyers operating in this field should be open to continuous self-development and must share relevant information with their clients regarding the subject matter while providing representation and consulting services. In this context, written clarification and information texts can be prepared for the individuals whose personal data is processed, training seminars can be organized to inform clients and employees about the protection of personal data, and regular meetings can be held with employees involved in the process of personal data processing to share decisions that may affect the company’s data policy, as well as updates on regulations and legal changes. It should be remembered that the process of personal data processing is not a short-term activity, but an ongoing project that needs to be continuously updated. Ensuring that all stakeholders involved in the process are aware of and conscious of the data processing procedures will contribute to the successful implementation of the data strategy.
Assisting Companies in Developing Procedures to Handle Data Security Breaches
A data controller who processes personal data in compliance with the legislation and stores this data in their data systems will also be responsible for ensuring the security of the personal data within their organization. Article 12 of the Law stipulates that the data controller must take all necessary technical and administrative measures to ensure an appropriate level of security to prevent unlawful processing of personal data, prevent unlawful access to personal data, and ensure the safekeeping of personal data.
In this context, data controllers can prevent potential risks by developing security procedures with technical and legal support. Administratively and legally, measures such as identifying existing risks and threats, training employees and conducting awareness campaigns, and reducing personal data as much as possible can be implemented. Technically, ensuring cybersecurity, monitoring the security of personal data, and taking measures such as storing personal data in the cloud will help protect personal data.
Determining the Most Suitable Method for Data Transfers Abroad within the Company
Article 9 of the Personal Data Protection Law regulates the transfer of personal data abroad. According to this provision, the explicit consent of the data subject is required for the transfer of data abroad. However, if the conditions set forth in Articles 5 and 6 of the law are met, personal data can be transferred abroad without the explicit consent of the data subject, provided that there is adequate protection in the country to which the data is being transferred, or if there is no adequate protection, the data controllers in both Turkey and the relevant foreign country commit to providing adequate protection in writing and obtain the approval of the Board. The countries with adequate protection are determined by the Personal Data Protection Authority.
Considering the legislative provisions, data can be transferred abroad and centralized in accordance with the procedure. To determine the most suitable method, legal, technical, and financial conditions must be evaluated together. Establishing a procedure that is low-cost, offers high-level data security, and complies with both national and international regulations will be beneficial for the client.
The Development of Personal Data Protection Law and Data Protection Lawyering
The issue of personal data protection, which has been a separate area of expertise in Europe for more than thirty years, especially in recent years, has transformed from a niche field to a broad working area, particularly after the tremendous growth of electronic commerce in the last five years. With the recent efforts in Turkey regarding the Personal Data Protection Law, the implementation of the EU General Data Protection Regulation (GDPR) (2016/679) of the European Parliament and Council, adopted on April 27, 2016, and the 108th “Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data,” signed in Strasbourg on January 28, 1981, the Turkish Personal Data Protection Law No. 6698 and relevant regulations have come into force in compliance with these international agreements.
At the same time, following decisions made by the Personal Data Protection Authority, a case law on personal data law is gradually being established. Until recently, the processing of personal data was seen as a regional and national issue. However, as mentioned above, with the widespread use of the internet and the growth of electronic commerce, it has become an international matter. This situation has expanded the consulting and service activities conducted by lawyers and law firms in the field of Personal Data Protection Law beyond national borders. This development has not only created a new area of expertise for lawyers but also brought the necessity of being familiar with the laws of various jurisdictions. At this point, the fundamental role of lawyers working in this field is to provide their clients with the legal and technical support they need in the fastest and most practical way, no matter at which stage of the personal data processing process they are.
Av. Yalçın TORUN
Web sitemizde yayımlanan yukarıdaki yazılı metnin, eser sahipliği hakları Av.Yalçın TORUN’a aittir. Bu yazılı metin hak sahipliğinin tespiti amacıyla zaman içerikli elektronik imza ile muhafaza edilmektedir. Sitemizdeki yazılı metinler avukat meslektaşlarımız tarafından dilekçelerinde serbestçe kullanılabilir, fakat metinlerin tamamının, bir kısmının veya özetinin atıf yapılmaksızın başka web sitelerinde yayınlanmasına iznimiz yoktur.
