Mevzuat Kategorileri
Hukuksal Düzenlemeler
Türkiye’de Kişisel Verilerin Korunması Kanunu, Sosyal Güvenlik Hukuku, Vergi Hukuku, İş Sağlığı ve Güvenliği Mevzuatı, Borçlar Hukuku, İş Hukuku, Ticaret Hukuku, Türk Parası Kıymetini Koruma Mevzuatı, Kambiyo Mevzuatı ve Vatandaşlık ve Göçmenlik Mevzuatı ile ilgili en güncel bilgilerin yer aldığı makalelere buradan ulaşabilirsiniz.
İkili Anlaşmalar
Türkiye ve diğer ülkeler arasında yapılan en güncel uluslararası ikili sosyal güvenlik ve vergi anlaşmalarının tarihlerine ve dokümanlarına buradan ulaşabilirsiniz.
05 Ağustos 2024
Yazar Semih Er, Kategori KVKK - GDPR
As is known, with the 8th Judicial Package accepted in the Grand National Assembly of Türkiye on March 2, 2024, and the Law No. 7499 published in the Official Gazette No. 32487 on March 12, 2024, titled the Law on Amendments to the Criminal Procedure Code and Certain Laws, several amendments were made to the Law on the Protection of Personal Data No. 6698 (the Law).
Accordingly, in order to address the difficulties experienced in the implementation of the Law, and taking into account the General Data Protection Regulation (GDPR) of the European Union, comprehensive amendments have been made especially in the conditions for processing special categories of personal data and the conditions for transferring personal data abroad. In this article, we have summarized the amendments made to the Law on the Protection of Personal Data No. 6698.
Sensitive Personal Data is specified in the 6th article of the Law, and data related to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, disguise and dress, membership to associations, foundations or unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data are qualified as sensitive personal data.
With the amendment made in the Law, no change has been made in the definition of sensitive personal data above, only the conditions for processing such data have been expanded.
In the previous regulation, as a general rule, special categories of personal data could not be processed without the explicit consent of the data subject, and the exceptions to this were quite limitedly regulated in the Law. Accordingly, there was a binary distinction:
This situation created difficulties in practice, especially regarding the processing of health data. On one hand, employers are required to process the health data of their employees due to occupational health and safety regulations, but on the other hand, under the Law, these data could only be processed by workplace physicians. In workplaces without a workplace physician, explicit consent from the employee was required to keep these data in personnel files. Consequently, employers had to direct employees to give explicit consent in order to fulfill their legal obligations, which was not compatible with the principle that consent should be given "freely."
First of all, the above-mentioned binary distinction between the types of sensitive personal data has been abolished and the way has been paved for the processing of such data without the explicit consent of the data owner in the following cases, which are stipulated in a limited number in the Law.
In addition to explicit consent, sensitive personal data may be processed without explicit consent from the data owner in the cases listed below:
Considering the established practice of the Personal Data Protection Authority ("KVKK"); only in cases where any of the above conditions are not present, the processing of sensitive personal data should be sought by obtaining the explicit consent of the data owner.
Although the Law stipulates that, if the legal conditions for processing data are met, data can be transferred to countries with adequate protection without the explicit consent of the data subject, the countries with adequate protection had not yet been announced by the Personal Data Protection Board (the "Board"). This left data controllers who wanted to transfer data abroad with two options:
However, as stated in the rationale for the amendment, to date, only eighty applications have been made to the Board, and only a few of these have been approved. As a result, in practice, the only option for data controllers wishing to transfer data abroad was to obtain explicit consent from the data subjects.
With the amendments made to the Law, the conditions for transferring data abroad have been simplified. Additionally, a regulation outlining the procedures and principles for data transfers abroad has been issued.
First, the Board has been granted the authority to make a decision on the presence of adequate protection not only concerning the country to which the data will be transferred but also specific sectors within a country or an international organization (adequacy decision). For example, it is now possible to make an adequacy decision for the automotive sector in a foreign country, rather than for the entire country, if the Turkish automotive sector has significant commercial relations with that sector. The Board will reassess its adequacy decisions at least every four years and may revoke, suspend, or amend these decisions as necessary.
If the legal processing grounds outlined in Article 5 (and for special categories of personal data, Article 6) of the Law are met, personal data can be transferred without the explicit consent of the data subject to countries, international organizations, or specific sectors within countries for which the Board has issued an adequacy decision.
In cases where there is no adequacy decision, data controllers may transfer personal data abroad without the explicit consent of the data subject, provided the following conditions are met:
In some cases where there is no adequacy decision and one of the appropriate assurances listed above cannot be provided, data may be transferred abroad on a single or several occasions and on a continuous basis. However, such a data transfer may only be possible in the presence of one of the following situations:
Until September 1, 2024, data transfer abroad can continue based on explicit consent obtained in advance or after the amendment of the Law. However, after this date, it will not be possible to transfer data abroad with these explicit consent texts and it will be lawful to transfer with one of the above-mentioned transfer methods.
In cases where data is transferred abroad by signing the standard contract announced by the Board, the data controller or data processor must notify the KVKK within five working days from the signing of the standard contract, as a separate obligation. It is envisaged that administrative fines ranging from TRY 90,308 to TRY 1,806,377 (valid for 2026) will be imposed on data controllers or data processors who violate the notification obligation.
Another issue that has been amended in the KVKK Reform is the issue of judicial remedy against the decisions of the Board. With the third paragraph added to Article 18 of the KVKK, it is stipulated that "A lawsuit can be filed in the administrative courts against the administrative fines imposed by the Board." Considering the nature of the administrative fines imposed by the Board, it was ensured that these decisions were supervised by the administrative judicial authorities. Before the amendment, there was a dual supervision application against the decisions of the Board, and while the administrative fines of the Board were applied to the criminal courts of peace, the part other than the administrative fine was applied to the administrative judiciary. With the amendments made, a more effective procedure has been established in terms of the supervision of the decisions of the Board. It can be said that a more secure system has been established for individuals as legal certainty will increase and uniformity will be ensured.
In conclusion, these sweeping amendments to the Personal Data Protection Law No. 6698 have taken important steps towards modernizing the data protection regime in Türkiye and bringing it in line with international standards. Expanding the conditions for processing sensitive personal data and facilitating the procedures for data transfer abroad will enable data controllers to fulfill their legal obligations more flexibly and effectively. At the same time, new regulations on administrative fines and uniformity in the judicial remedy will increase legal certainty and create a safer environment for the protection of personal data. These amendments are expected to provide a more effective regulation on data security by protecting the rights of both individuals and data controllers. You can find the detailed information article on the subject here.
Should you have any queries or need further details, please contact us.
About The Author
https://www.cottgroup.com
Standard Contract Notification Obligation and Penalties
Ecem Kumsal Başyurt
18 Kasım 2024
Clarification on the Application Principles of VERBİS Registration Exemptions
13 Ocak 2026
Relationship Between ISO 27001 & KVKK
CottGroup Hukuk ve Mevzuat Ekibi
9 Şubat 2022
Consent of the Consumer in Processing Personal Data
Semih Er
16 Temmuz 2024