Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad

As is known, Article 34 of Law No. 7499 on Amendments to the Code of Criminal Procedure and Certain Laws, published in the Official Gazette dated March 12, 2024 and numbered 32487, amended Article 9 titled "Transfer of Personal Data Abroad" of Law No. 6698 on the Protection of Personal Data. This amendment came into effect on June 1, 2024.

In the eleventh paragraph of the new version of Article 9 of Law No. 6698, it is stipulated that the procedures and principles for the implementation of this article will be regulated by a regulation. In this context, the "Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad" was published in the Official Gazette dated July 10, 2024 and numbered 32598, and it came into effect.

Below is a summary of the relevant Regulation.

Purpose of the Regulation

The purpose of this regulation is to determine the procedures and principles for the implementation of Article 9 of Law No. 6698 on the Protection of Personal Data concerning the transfer of personal data abroad.

General Provisions

Personal data may only be transferred abroad in accordance with the procedures and principles specified in the Law and the Regulation. The data processor acts in accordance with the instructions of the data controller and takes the necessary technical and administrative measures. Provisions in other laws remain reserved.

Transfers Based on Adequacy Decision

The first criterion to be sought for the transfer of personal data abroad is the presence of an adequacy decision regarding the country or sector. The Board may decide that certain countries or international organizations provide an adequate level of data protection. The adequacy decision is reviewed every four years and is modified, suspended, or revoked as necessary.

Transfers Based on Appropriate Assurances

In the absence of an adequacy decision, certain appropriate assurances must be provided for the transfer of personal data abroad. These assurances can be international agreements, binding corporate rules, standard contracts, or undertakings. Binding corporate rules and standard contracts must be approved by the Board. Undertakings must include issues such as the purpose, scope, and data security of the personal data transfer.

Exceptional Cases (Incidental Data Transfer)

In the absence of an adequacy decision and appropriate assurances, personal data can only be transferred abroad in exceptional cases.

This regulation aims to protect the rights of data subjects by providing detailed regulations regarding the transfer of personal data abroad.

You can access the relevant regulation here (In Turkish).

It has been stated that the explicit consent texts used for data transfers abroad under the former regulation of the Law can be used until September 1, 2024. However, after this date, it will no longer be possible to transfer data based on these consent texts. Therefore, we would like to emphasize that the data transfer methods specified in the Regulation must be followed after the mentioned date.

