Summary
The Personal Data Protection Law No. 6698 was published in the Official Gazette dated April 7, 2016, and entered into force. This law, as a whole, defines personal data, its processing, and protection, outlining the general framework for how personal data will be processed and protected. It also determines the sanctions for non-compliance with processing and protection rules and serves as the fundamental regulatory law in this field. The text of the law contains provisions explaining the transition period until April 7, 2018, when all its articles will enter into force. This article aims to provide our colleagues, who represent the defense independently of the judiciary, with information about the implementation process of this law, which will have significant impacts on citizens’ lives.
Introduction
The Personal Data Protection Law No. 6698 was adopted by the Turkish Grand National Assembly on March 24, 2016, and was published in the Official Gazette on April 7, 2016, with issue number 29677, entering into force. Today, with the help of modern communication tools such as computers, the internet, and mobile phones, personal data belonging to individuals can be easily accessed and shared rapidly among individuals, companies, and countries. This situation has reached a level that threatens the legal security of individuals and violates the privacy of their private lives.
Individuals who interact with the state in many areas of their lives have their personal data more easily obtained, processed, and used by public administrations through technological advancements. One of the main effects of technological developments on individuals is the concern of being constantly monitored.
As stated in the preamble of the law, it is important to have an institution in our country to control and supervise the process of personal data processing. Otherwise, personal data may be used by many individuals or institutions without adequate regulation and supervision, leading to certain violations of rights.
Personal Data Protection Law (PDPL)
This law was prepared based on the Council of Europe’s Convention No. 108 dated January 28, 1981, on the “Protection of Individuals with regard to Automatic Processing of Personal Data,” the “Additional Protocol to the Convention” dated 2001, and Directive 95/46/EC on the “Protection of Personal Data.”
The protection of personal data was recognized as a constitutional right within the scope of the last paragraph added to Article 20 of the Constitution of the Republic of Turkey by Article 2 of the Law No. 5982 on the Amendment of Certain Articles of the Constitution, dated September 12, 2010.
Article 3/d of the PDPL defines “personal data” as “any information relating to an identified or identifiable natural person.” Within this definition, examples of personal data include the person’s name, address, date of birth, marital status, nationality, profession, image, opinions, photograph, email address, bank details, computer IP address, identity number, pension, institutional registration and tax number, fingerprints, education information, health data, text messages, phone contacts, and content shared on social media platforms like Facebook and Twitter.
Article 6/2 of the law also covers “special categories of personal data” that are prohibited from being processed without the explicit consent of the data subject. These include race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and attire, membership in associations, foundations, or unions, health data, sexual life, criminal convictions, and security measures, as well as biometric and genetic data.
Special categories of personal data, excluding health and sexual life, can be processed without the explicit consent of the data subject if stipulated by law. Health and sexual life data may be processed without explicit consent only by persons or institutions authorized by law for purposes provided in the legislation and under the obligation of confidentiality.
As can be seen, compiling personal data from different sources can result in the creation of personality profiles that may endanger fundamental rights and freedoms. The dignity and personality rights of the individual require the protection of personal data.
Technological developments, especially in communication technologies and the expanding communication networks, have increased the possibilities of data exchange and collection. However, they have also brought about threats to legal security. Personal data of individuals, whether or not the entity is a data controller, are recorded, processed, and used. For example, personal data is requested during online shopping, obtaining an email address, or using electronic banking services. Paying for a meal by credit card means the individual accepts that their purchasing habits are recorded. Internet companies can store detailed user information about interests, stores, and products based on both shopping and browsing activity.
From the perspective of the legal profession, examples include requesting custody examination reports from lawyers, name change lawsuits, social media posts, sending judicial reports to the Social Security Institution, identification checks at hotels, fingerprint or retina scans at hospitals and prisons, and providing personal data when purchasing airline tickets.
An individual who internalizes the right to personal data protection will demand that their data remain confidential, not be recorded, and not be processed in such situations.
Purpose and Scope of the Law
Article 1 of the law, titled “Purpose,” states: “The purpose of this law is to protect the fundamental rights and freedoms of individuals, particularly the privacy of private life, in the processing of personal data, and to determine the obligations of real and legal persons who process personal data and the procedures and principles they will follow.” Article 2, titled “Scope,” explains that “the provisions of this law apply to natural persons whose personal data are processed and to legal and natural persons who process personal data, wholly or partially, automatically or non-automatically, provided they are part of any data recording system.”
Workflow in Processing Personal Data
The processing of personal data, from collection to deletion, must follow the flow stipulated in the law.
1. Registration in the Data Controllers Registry: The person, institution, or organization that will process personal data must register in the “Data Controllers Registry” before collecting and processing the data. Procedures and principles regarding registration are regulated by regulation.
2. Preparation for data collection: Only after registration can the environment for collecting personal data be opened for access. The system must record the explicit consent of individuals.
3. Informing individuals: Individuals whose personal data will be collected must be informed about the identity of the data controller, the purposes of data use, and whether the data will be shared. Their consent must be obtained, and they must be informed about their rights over the data.
Explicit consent: Consent must be given clearly and without doubt, recorded for proof, and relate to a specific subject with sufficient information. Special categories of personal data can only be processed with explicit consent, and the burden of proof lies with the collector.
4. Processing of personal data: Data processing includes storing information in paper form, such as job applications, as well as digital processing. In some cases, informing and obtaining explicit consent is not required, as outlined in Article 5/2 of the law.
5. Changes: If there are changes in data, purposes, or recipients after registration, the registry must be updated. If circumstances differ from when consent was obtained, consent must be renewed.
6. Deletion or anonymization of data: When processing is complete, or consent is withdrawn, data must be deleted or anonymized. Procedures and principles are regulated by regulation.
Rights of the Data Subject
The data subject has the right to request information and compensation in case of unlawful processing of personal data. The application process is as follows:
1. Application to the data controller: The data subject applies to the controller to obtain information or correct a violation.
2. Response from the data controller: The request is finalized free of charge within 30 days at the latest. The controller either accepts and corrects the issue or rejects it with reasons, notifying the data subject in writing or electronically.
3. Complaint to the Personal Data Protection Board: If the application is rejected, deemed insufficient, or not answered within the time limit, the data subject may complain to the Board within 30 days from learning the response or within 60 days from the application date. The right to compensation according to general provisions is reserved for those whose personality rights are violated.
Examination by the Personal Data Protection Board: The Board examines complaints or initiates an investigation ex officio if it learns of a violation. The Board responds within 60 days of the complaint; otherwise, it is deemed rejected. The data controller must provide requested documents, except state secrets, within 15 days and allow on-site inspections if necessary.
4. Notification to the data controller: If a violation is found, the Board requests its elimination. The controller must comply without delay and within 30 days at the latest. In cases of irreparable harm or clear illegality, the Board may decide to suspend processing or transfer of data abroad.

Copyright © 2023 ARNPROXY Limited Company. All right reserved.