Mevzuat Kategorileri
Hukuksal Düzenlemeler
Türkiye’de Kişisel Verilerin Korunması Kanunu, Sosyal Güvenlik Hukuku, Vergi Hukuku, İş Sağlığı ve Güvenliği Mevzuatı, Borçlar Hukuku, İş Hukuku, Ticaret Hukuku, Türk Parası Kıymetini Koruma Mevzuatı, Kambiyo Mevzuatı ve Vatandaşlık ve Göçmenlik Mevzuatı ile ilgili en güncel bilgilerin yer aldığı makalelere buradan ulaşabilirsiniz.
İkili Anlaşmalar
Türkiye ve diğer ülkeler arasında yapılan en güncel uluslararası ikili sosyal güvenlik ve vergi anlaşmalarının tarihlerine ve dokümanlarına buradan ulaşabilirsiniz.
In the beginning of April 2016, the question of how sensitive personal data shall be protected arose when the personal information of over 50 million Turkish citizens was released on internet. Coincidently, around the same date the Turkish state released new legislation on how to protect personal information. The legislation entitled the Protection Of Personal Data was published on April 7, 2016 in the Legal Turkish Newspaper and is based on the European Union Commission and EU Parliament’s 95/46/EC numbered, October 24, 1995 dated Directive on the protection of the free movement of personal information and its process.
One might deliberate over whether our personal data was ever protected by law in the past or if there was ever legislation that considered the sharing/storing of our personal data?
As there is no uniform legislation for the protection of personal data in Türkiye, the regulation with regards to the use and protection of the same tried to be regulated under various codes.
Several examples from Turkish Criminal Code dated 26th September 2001 are as follows:
Thus, according to Article 20 of the Turkish Constitution (Appendix: 7.5.2010 5982/2) every citizen has the right to demand for the protection of personal data. This right also consists of being informed about his/her personal data usage, rectification, demand to have it deleted etc. Personal data can only be processed by the explicit consent of the data subject. The protection of the data is set and supported by the Law.
As seen, with some verification of articles of the Turkish legislation, the usage of personal data is tried to be legalized to technological innovations and internet usage by the modification of specific articles of several laws.
With the personal data protection law, the incorporated body and its employees have to reconsider the exchange of data between themselves and regulate it, if needed. In order to achieve this, HR and IT departments of organizations have to step in. Another point which should not be overlooked is that any sort of misdemeanor act towards the law can result in fines up to 1.000.000 TRY.
Legal entities need personal data of their employees as a source in personal contact, outsource and similar usage. As stated in the Article 4 of the new Law, the following principles shall be complied within the processing of personal data:
Thus, the law brought up the concepts of data controller, data processor and data registry system.
Data Controller: The natural or legal person who determines the purpose and means of processing personal data and is responsible for establishing and managing the data registry system.
Data Processor: The natural or legal person who processes personal data on behalf of the controller upon his authorization.
Data Registry System: The registry system which the personal data is registered into through being structured according to certain criteria.
As stated in Article 4, the personal data has to be accurate and up to date since it is crucial for the employer, the employee and the third party firm involved in the process (such as; payroll outsource provider, HR consultant, accountant etc.) Thus, Human Resources Management Systems (HRMS) have to be reconfigured according to the criteria stated in the new legislation. Since the legislation is new and includes clauses taken direct from the EU Directive, definitions, concepts and responsible will be interoperable, therefore have to be arbitrated in the future.
The new legislation will be completely effective in six months. It is beneficial for HR departments to take preventative measures considering the new law and reconsider the employment contracts. Employees’ consent might be needed, if the sensitive personal data is being shared with any third party organizations for payroll outsourcing or for any other reason. To achieve this, it is necessary for the organization’s consultants, IT, and HR departments to cooperate. According to a temporary article of the new law, personal data that has been put through the system before the publish date of the law will need to be adjusted according to the regulations of the new law in two years. Data that is determined to be against the Law will have to be deleted or become anonymous. Only the data that is accepted to be compliant with the Law are the personal data which are gained lawfully, before the effective date of the Law.
Kategori Personal Data Protection Law, Social Security Law and Legislation, Labor Law
Notification!
The content in this article is for general information purposes only and belongs to CottGroup® member companies. This content does not constitute legal, financial, or technical advice and cannot be quoted without proper attribution.
CottGroup® member companies do not guarantee that the information in the article is accurate, up-to-date, or complete and are not liable for any damages that may arise from errors, omissions, or misunderstandings that the information may contain.
The information presented here is intended to provide a general overview. Each specific case may require different assessments, and this information may not be applicable to every situation. Therefore, before taking any action based on the information provided in the article, it is strongly recommended that you consult a competent professional in the relevant fields such as legal, financial, technical, and other areas of expertise. If you are a CottGroup® client, do not forget to contact your client representative regarding your specific situation. If you are not our client, please seek advice from an appropriate expert.
To reach CottGroup® member companies, click here.
About The Author
The KVKK's Public Announcement on the Processing of Biometric Data for Attendance Tracking Purposes: The Scope of the Principle Decision and the Limits of Application
Ezgi Anasız
1 Eylül 2026
Türkiye's National Artificial Intelligence Action Plan 2026–2030: A New Era for the Private Sector
Selma Kıy
21 Ağustos 2026
Five-Year Retention of Employee Emails and Conditions for Access: The Garante's Decision