What is KVKK?
The Law No. 6698 on the Protection of Personal Data (KVKK) became effective after its publication in the Official Gazette on April 7, 2016, issue 29677. The aim of the law is to protect the fundamental rights and freedoms of individuals, particularly the privacy of private life, during the processing of personal data. It also establishes the responsibilities of real and legal persons who process personal data and outlines the procedures and principles that must be followed.
What is Personal Data?
Personal data refers to any information relating to an identified or identifiable person.
Processing of personal data is possible in the presence of at least one of the circumstances listed in Article 5 of the Law. Accordingly, it is possible to process the personal data of the data subject in the presence of one of the following situations:
- Explicit consent of the person concerned,
- Processing is explicitly stipulated in the law
- It is necessary for the protection of the life or physical integrity of the person who is unable to disclose his/her consent due to actual impossibility or whose consent is not legally valid,
- It is necessary to process personal data belonging to the parties to the contract, provided that it is directly related to the establishment or performance of a contract,
- It is mandatory for the data controller to fulfill its legal obligation,
- It has been made public by the person concerned,
- Data processing is mandatory for the establishment, exercise or protection of a right,
- Data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.
The conditions for the processing of personal data, i.e. the conditions of lawfulness, are listed in a limited number in the law and these conditions cannot be expanded.
If personal data processing is based on any condition listed in the KVKK other than explicit consent, obtaining explicit consent from the data subject is still necessary. While it is possible to process data without explicit consent, doing so may be considered deceptive and an abuse of right. Moreover, if the data subject withdraws their explicit consent, the data controller's continued processing of the data based on any other conditions listed in the KVKK would be a transaction contrary to the law and good faith.
In this context, the data controller should evaluate whether the primary purpose of the personal data processing activity is based on any of the processing conditions listed in KVKK other than explicit consent. If the purpose does not meet at least one of the conditions specified in KVKK, then the data controller must obtain explicit consent from the person to continue the data processing activity.
Who is the Data Controller?
The term 'data controller' refers to the natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system. Legal entities are themselves data controllers within the scope of their personal data processing activities, and the legal liability specified in relevant regulations will arise for the legal entity. There is no difference in this regard between public law legal entities and private law legal entities.
According to the Law, the data controller is the person or entity who determines the purposes and means of processing personal data. In other words, they are responsible for answering the questions of why and how the processing activity will be carried out.
Obligations Regarding Data Security
Data controller according to Article 12 of the Law on data security is responsible for;
- To prevent unlawful processing of personal data,
- To prevent unlawful access to personal data,
- It is obliged to ensure the protection of personal data.
To fulfill these obligations, the data controller must take all necessary technical and administrative measures to ensure an appropriate level of security. The Board has the power and duty to determine the obligations regarding data security, and the data controller must comply with these regulations. Additionally, sector-specific measures may be necessary based on the nature of the personal data processed, according to minimum criteria determined by the Board.
In the event that personal data is processed by another natural or legal person on its behalf, the data controller is jointly responsible with these persons for taking the necessary measures .
Therefore, data processors are also obliged to take measures to ensure data security. For instance, if a data controller's company records are being kept by an accounting company, the data controller will share responsibility with the accounting company to take measures specified in the first paragraph regarding the processing of data.
The Law also imposes an obligation on the data controller to conduct audits on data security. The data controller is required to carry out or have conducted the necessary audits to ensure compliance with the provisions of the Law in their institution or organization. The data controller can conduct this audit themselves or through a third party.
KVKK Consultancy Service
As ADEO Bilgi Danışmanlık Hizmetleri A.Ş., we have a unique approach to KVKK projects compared to existing practices in the market. Our focus is on professional project management principles, and we have fully comprehensive, result-oriented legal, technology, and process teams working together in synchrony, rather than relying on a single center. As the team that carries out Turkey's largest KVKK projects, we understand the uniqueness of each system infrastructure and customize our solutions to meet the needs of our customers.