Open menu
29April2022

Two-Factor Authentication Requirement in Payment Services of Municipalities

Two-Factor Authentication Requirement in Payment Services of Municipalities

It has been stated that accessing the real estate information of the citizens by entering only the Turkish Republic ID number on the real estate tax payment/fast payment and debt inquiry pages submitted online by the municipalities in various notices conveyed to the Turkish Data Protection Authority ("Authority") causes a problem in terms of protection of personal data and it has been requested to be examined within the scope of Turkish Data Protection Law No. 6698 ("KVKK").

Referring to Article 12 of the KVKK and the Personal Data Security Guide (in Turkish) published by the Authority, the Authority stated that the implementation of two-factor authentication control in case of remote access to personal data when necessary is among the measures to be taken to ensure the security. In this respect, in case of remote access to personal data, it is necessary to use two-factor inquiry system so that third parties cannot easily access the personal data, for example systems that allow access by querying the person's Turkish Republic ID number and birthday information are determined as one-factor authentication, while systems provide access with the person's Turkish Republic ID number as well as creating a password specially or an SMS code sending to person's previously informed phone number are accepted as two-factor authentication.

Accordingly, it has been stated that it would be important to implement inquiries with two-factor authentication methods, which will significantly reduce or eliminate the risk, instead of one-factor authentication systems that carry the risk of easy accessing to personal information and in line with these complaints/notifications to be sent about the municipalities that do not take the aforementioned measures, action will be taken against the relevant municipality within the scope of penalty provisions of the KVKK by the Authority.

Details of the decision can be found here (in Turkish).

Should you have any queries or need further details, please contact your customer representative.

Author CottGroup Hukuk ve Mevzuat Ekibi, Category Personal Data Protection Law

  • Notification!

    The content in this article is for general information purposes only and belongs to CottGroup® member companies. This content does not constitute legal, financial, or technical advice and cannot be quoted without proper attribution.

    CottGroup® member companies do not guarantee that the information in the article is accurate, up-to-date, or complete and are not liable for any damages that may arise from errors, omissions, or misunderstandings that the information may contain.

    The information presented here is intended to provide a general overview. Each specific case may require different assessments, and this information may not be applicable to every situation. Therefore, before taking any action based on the information provided in the article, it is strongly recommended that you consult a competent professional in the relevant fields such as legal, financial, technical, and other areas of expertise. If you are a CottGroup® client, do not forget to contact your client representative regarding your specific situation. If you are not our client, please seek advice from an appropriate expert.

    To reach CottGroup® member companies, click here.

About The Author

/tr/mevzuat/item/belediyelerin-odeme-ve-borc-sorgulama-hizmetlerinde-cift-kademeli-dogrulama-zorunlulugu

Other Legislation

Lets start
Get a quote for your service requirements.

Would you like to know more
about our services?