Master'sOpen Access

Obligations of Turkish commercial companies pursuant to Law No. 6698 on the Protection of Personal Data

2023
0 views
0 downloads
Advisor: Prof. Dr. Mehmet Erdem

Abstract (EN)

The first law of general regulation regarding the protection of personal data in Turkey is the Law No. 6698 on the Protection of Personal Data. The law was published in the Official Gazette on 07.04.2016. In accordance with the system envisaged by the law, the Personal Data Protection Authority was established, and certain duties and power were granted to this authority. The decisions of the Personal Data Protection Authority have an impact on the widespread adoption of personal data protection law in our country. The revision of the Personal Data Protection Board decisions indicated that the data controller subject to administrative enforcement is usually a company Besides certain foreign companies, the majority of the companies subjected to administrative enforcement are Turkish commercial companies. Therefore, we preferred to address the liabilities that a data controller must fulfill within the scope of the law on the protection of personal data with a special focus on Turkish commercial companies rather than discussing public institutions, individuals, and foreign companies to avoid diluting the topic. Consequently, we determined the subject of our thesis as "Obligations of Turkish Commercial Companies Pursuant to Law No. 6698 on the Protection of Personal Data." While we frequently use the concept of data controller in our study, we have attempted to provide the examples primarily based on a company. Likewise, in a significant portion of the decisions we discuss, we strive to use a company that has been subjected to sanctions as an example. The introduction part of our study, deals with the historical background of personal data protection law, national and international sources. In particular, since different approaches have been adopted in the world in the field of personal data protection, we first addressed the emergence of personal data protection law, followed by its the development in our country and other countries, and finally its development in international law.The first part of our study deals with the fundamental concepts, basic principles and the personal data processing conditions under the law. We have tried to review the fundamental concepts comprehensively. Because we have identified that most of the defenses submitted by companies at risk of administrative fines under the Personal Data Protection Law were based on these fundamental concepts. For example, the company that is likely to be imposed a penalty may claim that it is not a data controller, that the action carried out to avoid the penalty did not involve processing personal data because there was no data recording system in place. Particularly, identity of the data controller and data processor has been addressed in many decisions, guidelines and announcements published by the Personal Data Protection Board. In some disputes, the very existence of personal data can be subject to debate. Therefore, a good understanding of the fundamental concepts in the field of personal data protection law is essential. A clear understanding of the fundamental concepts will also provide the answer to the questions of who will fulfill the obligations under the law and whether such obligations exist. For instance, when an action is not considered as a personal data processing activity, there is no need to rely on any data processing condition specified in the law. Conversely, when there is a data processing activity, it would be necessary to rely on a data processing condition. Therefore, the first issue to be evaluated is whether the action performed will be considered as processing of personal data. Otherwise, when the Personal Data Protection Board intends to impose an administrative fine in a dispute that comes to its attention, the respondent is the data controller. Hence, the first thing that the Personal Data Protection Board needs to determine is the identity of the data controller. In certain cases, identifying the data controller can indeed be quite challenging. Therefore, unlike other laws, the fundamental concepts have a great importance in the context of the Personal Data Protection Law. Therefore, we have attempted to address these concepts in as much detail as possible. The other topic addressed in the first section is the general principles. General principles have been the subject of many decisions of the Personal Data Protection Board and have caused many companies being subjected to administrative fines. One of the reasons for the importance of the subject is that, even if a data controller relies on a data processing condition specified in the law, if the data processing activity does not comply with the general principles, the data processing activity performed is unlawful. Moreover, since the general principles are required to be considered in every process within the scope of personal data processing activity, a data controller should constantly ask whether the transaction is in compliance with the general principles. In this section of the study, we have attempted to address the general principles, especially in the light of the decisions of the Personal Data Protection Board. Since the issue of principles is generally an abstract subject, many cases that have been the subject of many decisions have been discussed in this part of our study to make the study more concrete. The final issue in the first section is the conditions for processing personal data. The legislator has regulated the conditions for the processing of personal data of general nature and the conditions for the processing of personal data of special nature separately by adopting a binary distinction. In this part of our study, we have addressed the issue based on the basic distinction made by the legislator. We have also attempted to present the issue with examples based on the decisions of the Personal Data Protection Board. In particular, in many decisions of the Personal Data Protection Board, we have observed that one of the most challenging issues for companies in practice is determining the correct personal data processing condition. The issues such as the data controller processing personal data without relying on any data processing conditions or processing personal data without obtaining explicit consent even when explicit consent should be obtained, are constantly repeated. In practice, I would like to point out that the questions I encounter both from the companies that I have had the opportunity to work with and from my colleagues who provide consultancy services on this issue often revolve around whether obtaining explicit consent is necessary or whether the data processing activity can be considered within the scope of legitimate interest. Therefore, a correct understanding of the conditions for personal data processing is the first step in determining the correct data processing condition. Accordingly, in this part of our study, we have attempted to proceed with examples as much as possible and to include the decisions of the Personal Data Protection Board. In the second section of our thesis, we discussed the obligations of Turkish trading companies under Law No. 6698 on the Protection of Personal Data, which also constitutes the title of our thesis. In this section, we addressed the obligations related to the obligation to inform, VERBİS registration, obligations regarding data security, the obligation to respond to applications made by data subjects, the obligation to comply with board decisions, and the obligation to destroy data. Finally, we evaluated these obligations in the light of Articles 1524, 64, 82, 55, 366, and 375 of the Turkish Commercial Code No. 6102. One of the first obligations we addressed in this section is the obligation to prevent the unlawful processing of personal data.. The fundamental basis of the obligation to prevent the unlawful processing of personal data lies in the data controller's responsibility to correctly determine the data processing condition and conduct data processing activities based on that condition. In this respect, we have first explained the expectations of the legislator from Turkish commercial companies and the obligations that should be fulfilled, and then, we have addressed the cases in which this obligation is deemed to be violated based on the decisions of the Personal Data Protection Board. In addition, in this section, we have also comprehensively covered the obligation to prevent unauthorized access to personal data. In particular, this issue has been addressed by specifying the administrative and technical measures which may be adopted within the scope of the Law on the Protection of Personal Data, since the company is required to take certain administrative and technical measures. It should be noted that the Personal Data Protection Board imposes administrative fines on the grounds that this obligation is not fulfilled in any case if a personal data is accessed illegally. Therefore, we have attempted to determine what has been done incomplete in the cases subject to the decisions and to offer solutions. The Personal Data Protection Board often determines only the violation of the law, but does not provide a solution to the case. Generally, the points where the Board determines the violation of the law are the procedures and methods frequently employed by Turkish commercial companies. Consequently, in this section of our study, we have also included our recommendations for the fulfillment of the obligation. Although the basis of our study focuses on the obligations, of course, it is an individual who is responsible for fulfilling this obligation in terms of Turkish commercial companies. In addition, the data controller is always the respondent of the administrative fine that may be imposed by the Personal Data Protection Board. Even if the violation is solely due to the fault of an employee, the company will be the respondent of the fine, and as a consequence, the issue of recourse is frequently encountered. In such circumstances, it is very clear that the company may seek recourse from the employee. Furthermore, the company may have not taken any action within the scope of compliance with the Law on the Protection of Personal Data even if there is no obvious data violation, a study may have been conducted but remained incomplete, or the most common scenario where compliance efforts have been made but remained on paper. We also attempted to address the issue of who would be responsible in this section of the study, without straying from the scope of the study. We endeavored to evaluate the issue in line with the dynamic structure of Turkish commercial companies and the requirements of business life. It should be noted that the possibility of non-compliance with the Law on the Protection of Personal Data is quite high within the scope of the law. It is relatively easy to determine when a violation results from an employee's fault, but it is relatively more challenging to determine who is responsible for negligence or deficiencies rather than a clear violation of the law. Therefore, at the end of this section, I also provided my own opinions to contribute, even if it's just a drop in the ocean compared to the knowledge of those dedicated to this field. Throughout the study, we frequently referred to the guidelines published by the Personal Data Protection Board and the decisions of the Personal Data Protection Board. We have tried to do this in all sections. Because the law that constitutes the subject of our study is a law with a history of only seven years. Considering the judicial decisions on the protection of personal data, it is understood that evaluations and determinations are often made in accordance with the general principles rather than the Law on the Protection of Personal Data No. 6698. Considering that the Law entered into force only seven years ago and the trial process takes a very long time in our country, the area we work in is not an area that has been the subject of many judicial decisions. On the other hand, the Personal Data Protection Authority considers all its decisions within the scope of the law and publishes many guides, announcements and videos to make the law understandable. As such, the source we used most in our study was the printed and digital resources of the Personal Data Protection Authority. As a result, we have tried to deal with the obligations of Turkish commercial companies within the scope of the Personal Data Protection Law, which is very new for our country, with our practical solution proposal in the light of the theoretical explanations, then the opinions in the doctrine and finally the decisions of the Personal Data Protection Board

Author

Dr. Yasin Üstün

How to Cite

Yasin Üstün (Master Thesis). Obligations of Turkish commercial companies pursuant to Law No. 6698 on the Protection of Personal Data, 2023, Galatasaray University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Galatasaray University