9 March 2020Murat Volkan Dülger, Merve BakdurCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

Article 10 of Law No. 7222 Amending the Banking Law and Certain Other Laws, published in the Official Gazette on 25 February 2020, made an amendment to Banking Law No. 5411 that also closely concerns the rules of data protection law. Although we read in the explanatory memorandum that the aim of the amendment is to overcome difficulties encountered in practice, we are of the view that it carries the risk of giving rise to new questions and problems, and even to certain gaps. Because the legislature has lost confidence in its own rules, “explicit consent” and the “obligation to inform” are at risk of losing their function, and the reliability of the law is being undermined.

Accepting that consent texts have lost their function and creating additional procedures that work around them carries the risk of producing the same problems again and again. Although secrets are information that is already interpreted in case law and in practice in a way that protects the customer, the changes to their definition and exceptions in the new rules carry the risk of creating new opportunities for institutions to circumvent these laws. This is because the additions concerning which information banks may treat as not being a secret and share, and with whom they may share it by law even where it is a secret, contain gaps that may cause problems in practice.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

Murat Volkan Dülger* / Merve Bakdur*

By Article 10 of Law No. 7222 “on the Amendment of the Banking Law and Certain Other Laws”, published in the Official Gazette on 25 February 2020, an amendment has been made to Banking Law No. 5411 that also very closely concerns the rules of personal data protection law.

Although we read in the explanatory memorandum to the amendment that its aim is to overcome the difficulties encountered in practice, we are of the view that it carries the risk of giving rise to new questions and problems, and even to certain gaps. As a result of the legislature’s loss of confidence in its own rules, “explicit consent” and the “obligation to inform” are at risk of losing their function, and the reliability of the law is being undermined. Accepting that consent texts have lost their function and creating additional procedures that work around them carries the risk of producing the same problems again and again. Although secrets are already information that is interpreted in case law and in practice in a manner that protects the customer, the changes to their definition and to the exceptions in the provision entail the risk of creating new opportunities for institutions to circumvent these laws. For the additions concerning which information banks may decline to treat as a secret and thus share, and with whom they may lawfully share it even where it is a secret, contain gaps that may cause problems in practice.

I. The New Provisions Added to Article 73 of the Banking Law

The amendment was made in Article 73 of the Law, which bears the marginal heading “keeping of secrets”, so as to follow the second sentence of paragraph 3. The provision already began as follows: “Those who, by virtue of their capacities and duties, learn secrets belonging to banks or their customers may not disclose those secrets to anyone other than the authorities expressly empowered by law in this regard. This obligation continues after they have left office”. The addition made so as to follow this text reads as follows:

“Data belonging to natural and legal persons that come into being after a customer relationship has been established with banks, specifically in relation to banking activities, become customer secrets. Without prejudice to the mandatory provisions of other laws, information in the nature of a customer secret

may not, except in the cases exempted from the obligation of confidentiality set out in this Article, even if the customer’s explicit consent has been obtained pursuant to Law No. 6698 of 24/3/2016 on the Protection of Personal Data,

be shared with or transferred to third parties in Turkey or abroad in the absence of a request or instruction

from the customer. The Board is authorised, following an assessment it will make with regard to economic security, to prohibit the sharing with or transfer to third parties abroad of any data in the nature of a customer secret or bank secret, and also to decide that the information systems which banks use in carrying on their activities, and the backups of those systems, must be kept in Turkey. Information in the nature of a customer secret or bank secret, including where it is shared in the cases exempted from the obligation of confidentiality set out in this Article, may be shared only on condition that the sharing is limited to the stated purposes and, in accordance with the principle of proportionality, contains only as much data as those purposes require.”

The legislature did not stop there, however, and in the text of the amending Law provided for a further provision to be added to the same Article. Accordingly:

“With regard to the sharing and transfer of information in the nature of a secret under paragraphs three and four, the Board is authorised to determine their scope, form, procedures and principles or to impose restrictions on them” has been added to the Article as paragraph 5.

II. “Explicit Consent” after the Amendment

At first glance, the particularly striking point in the provision is the phrase “..even if explicit consent has been obtained..” in the part added to paragraph three.

First of all, it is necessary to consider what is to be understood by explicit consent within the meaning of the Law on the Protection of Personal Data. Under Law No. 6698 (KVKK), the processing of data is prohibited unless there is a ground for processing, that is, a ground of justification; the consent of the data subject, however, constitutes – in the words of the Law – a general exception and, in our view, a further ground of justification.1 In the repealed Directive 95/46/EC2, the data subject’s consent was defined as “consent obtained freely and after information has been provided, signifying the data subject’s agreement to the processing of personal data relating to him or her”. The same matter is also regulated in the GDPR, under which consent is defined as “a freely given, specific, informed and unambiguous indication by which the data subject, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her”. Under this definition, for the explicit consent that banks obtain from their customers to be regarded as valid:

i. the data subject must be informed about the processing of the personal data before consent is requested from him or her,

ii. the consent given by the data subject must relate to the matter about which the customer has been informed,

iii. the consent must have been given of the person’s own free will, without being made subject to any condition.3

It can thus be seen that explicit consent is, by its very nature, already an approval that a person gives in accordance with his or her own wishes, based on his or her free will and on having been informed. This approval is at the same time a strictly personal right and may be withdrawn at any time. Consequently, “explicit consent”, which is given willingly and may be withdrawn on request, has been rendered functionless by the requirement of a request inserted into the provision, as though it had no meaning at all. In the explanatory memorandum to the amending article, the legislature stated the reason for this as being “to dispel any doubts that may exist in practice”.4 This shows that “explicit consent” has begun to lose its reliability in the eyes of the legislature.

In practice, encountering situations in which the purpose of processing personal data in the context of banking services is the promotion of the bank’s products and services to the customer, and in which it is claimed that the service cannot be provided if this information is not given, will vitiate the declaration of intent.5 The legislature, too, appears to be concerned that explicit consent does not reflect the person’s true will, on account of consents given with a will vitiated by situations encountered in practice in which consent is made conditional or obtained under compulsion – for example, where a customer’s refusal to give explicit consent would be likely to have adverse consequences for the customer in the relationship established between bank and customer, or where customers who do not give explicit consent would lose the right to take out low-interest loans6.

It is highly objectionable that the legislature itself should disregard, and regard as unreliable, the particular standards introduced by the KVKK and one of the important elements of the processes and principles which it has been sought to standardise for institutions and organisations. A law that, instead of the root causes being addressed so as to remedy misapplications and shortcomings, is constantly patched with new provisions and even has one of its fundamental principles disregarded loses its reliability.

Likewise, the “obligation to inform” is regulated both in Articles 13 and 14 of the GDPR and in Article 10 of the KVKK.7 Accordingly, controllers that process or transfer data are under an obligation to inform the data subject of the identity of the party processing the data, the purpose for which the data will be processed, to whom and for what purpose the data will be transferred, the method of and legal ground for collecting the personal data, and the other rights listed in Article 11 of the KVKK. If any of the matters set out in this Article is missing, the information given to the person and the operation subsequently carried out will in any event be invalid.8

Where both the “obligation to inform” and “explicit consent” have been fulfilled in accordance with the law, still to wait for an express request or instruction is, in our view, contrary both to logic and to the KVKK.

However, under the rules of the Banking Regulation and Supervision Agency (BDDK), banks are prohibited from keeping the data they hold on servers abroad or in a cloud service. Accordingly, all data belonging to banks must be hosted on servers located in Turkey. The aim of the present provision is thus to prevent a bank from transferring data abroad by obtaining the explicit consent of its customer, that is, of the data subject. But the provision in question is not needed for that purpose. This transfer is already prohibited in the banks’ own sectoral rules, that is, in what are “special norms” in relation to the KVKK. It is therefore unnecessary to enact a special provision in the Law for a situation that can be resolved by a very simple comparison of “general norm” and “special norm”. Moreover, “should doubts arise” in this regard, such doubts can very easily be dispelled by a decision of the BDDK or of the Personal Data Protection Board. Unfortunately, we see here yet another example of the technique, used in our country in recent years, of legislating by omnibus laws for every problem that arises and of making law by the casuistic method.

Having made this finding from the standpoint of the law as it ought to be, we must point out the following: under the law as it is, that is, the law as applied, banks are prohibited from transferring their customers’ data abroad even if they obtain the customers’ consent! Such a transfer can take place only on a transaction-by-transaction basis, where a request or instruction is received from the customer. In other words, a transfer of data abroad by a bank that has informed the customer in advance and obtained explicit consent for a particular process – that is, in conformity with Law No. 6698 – has been prohibited by Law No. 7222, and such an operation is deemed unlawful.

III. The Relationship between “Explicit Consent” and “Customer Secret” after the Amendment

With the “secret” that it defines at the beginning of the provision, the legislature has elaborated on the fact that it regards explicit consent as insufficient, and on the situation that has thus arisen, by addressing them within the framework of secrecy. Accordingly, the explanatory memorandum to the Law states:

“On the other hand, banks, which are the parties bound by the duty of confidentiality, are prohibited from piercing this obligation, in the absence of any exception recognised by the laws or of any compulsion, for purposes and by methods which they themselves determine under Law No. 6698 and by means of consent texts which they themselves draw up; in this context, the provision is being introduced in order to ensure that the obligation of confidentiality can be lifted not by the method of the consent text, in which the bank plays the active role, but by the method of the “customer’s request or instruction”, in which the customer who is the owner of the secret plays the active role. In addition, the Article aims to prevent the parties exempted from the obligation of confidentiality under paragraph 4 of Article 73 of Law No. 5411 from abusing this facility and sharing information in the nature of a secret in a manner that is not proportionate to the purposes stated in that paragraph.”

Here too it is stated that the consent-text method is a process in which individuals do not play an active role. Yet, as mentioned above, if steps are followed such as the conditions that consent must satisfy in banking in order to be regarded as explicit, the basic principles with which the information notices drawn up must comply9, the basic principles governing the forms in which consent is obtained (in writing or orally) and refraining from obtaining consent of a general nature that is not limited to the transaction concerned – described as “blanket consent” – it will be possible to say that the data subject, too, plays an active role. In this way the legislature itself adversely affects the workability of procedures such as the “consent text” and “explicit consent”.

IV. The Definition of “Secret” before and after the Amendment

In making the amendment, the legislature also added a definition of secret. Under it, a secret is defined as data belonging to natural and legal persons that come into being after a customer relationship has been established with banks, specifically in relation to banking activities. In its general sense, a secret is a matter that carries the danger of harming its owner’s personality rights and whose remaining confidential is of importance both personally and socially; and since it may comprise confidential information relating to any situation whatsoever, the types and classifications of secrets are also very numerous.10

At this point, before turning to the definition of secret that the legislature has added to the text of the Article, it is appropriate to look at the definition given under the main heading of “trade secret” as regards the meaning of the banking secret. For this purpose, according to the definition of customer secret in the bill11 which lapsed on 21.10.2011 and whose renewal was approved by the Council of Ministers:

“Customer secret means all information and documents which commercial enterprises and companies, banks, insurance companies and intermediary institutions operating in the capital market and the financial markets acquire, directly or indirectly, in their relations with the customer in connection with their own fields of activity, concerning the customer’s personal, economic, financial, cash and credit situation.”

As we understand from this definition, every kind of information concerning the customer falls within the scope of the interests sought to be protected – those not of the commercial enterprise, that is, in the present context, the bank, but of the customer. No limitation is laid down here; the wording is every kind of information that they acquire in their relations with the customer in connection with their own fields of activity. Beyond this, although there is no single common definition in legal scholarship or in judicial decisions, interpretation proceeds according to the specific case.12 In all these interpretations, however, the protection of the customer as a general principle, and the inclusion within that scope of every kind of information obtained from the customer, are to be found for commercial enterprises of every kind.

Turning now to the definition of secret added by the amendment: with the legislature’s provision that “Data belonging to natural and legal persons that come into being after a customer relationship has been established with banks, specifically in relation to banking activities, become customer secrets”13, a second point concerning the amendment strikes us: with the new addition, the customer secret has been confined to data that come into being “after” the banking activity. In other words, secrets cover not all the customer information collected but only the data that “come into being”. Yet no such temporal distinction is drawn in the definition we have quoted above or in the definitions found in many laws and judicial decisions.

Although we do not yet know exactly how bodies such as the Banking Regulation and Supervision Board will interpret this new situation, it appears that situations may arise in which, for example, data that came into being within other banks before the relationship between the bank and the customer in the specific case was established are not regarded as customer secrets for that bank. At the same time, the definition of “customer secret” is thereby applied to all personal data obtained by banks. Consequently, as stated above, the process of providing information notices for all data and of obtaining explicit consent for data processing operations already covers customer secrets as well. It is only natural that the provision should reflect the legislature’s distrust and give rise to question marks.

V. The Transfer of Secrets Abroad and the Authority of the BDDK

If we turn to the third noteworthy point, in the final part of the provision, the BDDK has been given, on grounds of economic security, the power to prohibit the sharing with, or transfer to, third parties abroad of any data in the nature of a customer secret or bank secret.

In fact, this provision furnishes a statutory basis for the rules laid down in the “Regulation on the Information Systems and Electronic Banking Services of Banks14”, namely the rule in paragraph 2 of Article 45, which bears the marginal heading “Confidentiality of Data”, that “...even if the customer’s explicit consent has been obtained, the sharing of customer information with, or its transfer to, foreign countries is subject to the Board’s permission” and the rule in paragraph 3 that “Apart from the conditions in the first and second paragraphs, the sharing with foreign countries of any data covered by secrecy, including any customer data, and of traffic data is prohibited”.15

In the explanatory memorandum to Law No. 7222, too, the legislature stated with regard to this provision that, although Law No. 6698 provides that the provisions of other laws concerning the transfer of personal data abroad are reserved, there is no express provision in Law No. 5411 on the transfer of personal data abroad, and that its aim was therefore to ensure that, where data in the nature of a secret are transferred abroad, the provisions of Law No. 5411 are treated as special statutory provisions.16

As a result, in a matter as sensitive as the transfer of personal data, a similar power has been conferred, alongside the Personal Data Protection Authority, on the BDDK, which is likewise an administrative (and semi-autonomous) body, thereby placing it in a decisive position with regard to the transfer of personal data.

We hope that all the questions raised by the amendment will in time be answered by the approaches adopted by the BDDK. For one of the questions that come to mind is whether the powers relating to the sharing and transfer of the personal data of bank customers, which under the KVKK lay with the Personal Data Protection Board, now lie with the BDDK.

VI. The Exceptions to the Obligation of Confidentiality and Circumvention of the Law

In addition to the points addressed above, the expression “except in the cases exempted” in the provision in paragraph 1 refers to the exceptions to the prohibition on transfer and sharing by banks, that is, to the situations in which the obligation of confidentiality may be breached. These are specified as sharing with official bodies in the context of employment contracts, valuation work, risk management, internal/external audits of the institution, and so on.

One of the exceptions listed, “meeting requests for information and documents to be used in the procurement of valuation, rating or support services, in independent audit activities and, provided that the necessary measures are taken, in transactions relating to the procurement of services”, may – not least as an effect of the new provision – lend itself to being used by banks as a pretext; they may tend to circumvent the provision by beginning to treat those with whom they share data as falling within this exception.

The other exceptions are as follows:

• Where, within the framework of the employment contract provided for in various laws, the wages, premiums, bonuses and all entitlements of that nature payable to workers, seafarers and journalists are paid into a specially opened bank account, the provision of documents and information relating to those accounts to the Social Security Institution (SGK), the Ministry of Labour and Social Security, the Ministry of Finance and the Undersecretariat of the Treasury; the provision of information and documents relating to the carrying out of the means test to the Social Security Institution; and their provision to the General Directorate of Social Assistance of the Ministry of Family and Social Policies for the purpose of identifying those entitled to social assistance granted by provincial or district social assistance and solidarity foundations and of conducting means-test procedures,

• The meeting by the Agency of requests from authorities that are competent to supervise under the laws of foreign countries and are counterparts of the Agency, concerning institutions subject to the Agency’s supervision and audit and their shareholders, or the activities or customers of their subsidiaries, associates and jointly controlled undertakings; and any exchange of information and documents which banks and financial institutions carry out among themselves, directly or through the risk centre or through companies to be established by at least five banks or financial institutions, provided that a confidentiality agreement is concluded and the exchange is confined solely to the stated purposes,

• Valuation work to be carried out by prospective buyers for the purpose of the sale of shares representing ten per cent or more of their capital through direct or indirect shareholding,

• The work of preparing consolidated financial statements carried out by parent undertakings, including credit institutions and financial institutions established in Turkey or abroad, that hold ten per cent or more of the capital of banks,

• Risk management and internal audit practices,

• Valuation work to be carried out for the purpose of the sale of their assets, including loans, or of securities based on those assets.

Conclusion

The priority in the protection of personal data is to ensure that people trust the law and feel secure. But whereas standards and control mechanisms ought to be introduced for legislation and practice, which must be shaped in accordance with the fundamental principles, the admission – in the words of the law itself – that the existing laws do not work takes us a long way from this priority.

So long as institutions’ compliance with the laws and their supervision cannot be ensured, nothing will change even if we follow a “ten”-stage practice of written or oral request and consent. The range of supervisory authorities, which is widened with every passing day as powers are conferred on yet another administrative (semi-autonomous) body, now also makes it harder to keep track of who is to be held responsible. Rather than dispersing matters in this way and complicating the order of powers and duties, it is more important that proper supervision be exercised from a single hand, in parallel with the judiciary and the laws.

The law as it stands today – and what the banking sector is required to observe – is that the transfer of a customer’s data abroad in any manner whatsoever is prohibited unless a request or instruction has been received from the customer. By virtue of the principle of the unity of the legal order, this prohibition binds both the BDDK and the KVKK. In other words, in the contrary case the bank concerned will have come within the range of both institutions and will have infringed both legal disciplines. Banks must therefore pay great attention to this point.

On the other hand, it is apparent that powers in matters of the KVKK will continue to be conferred on many more institutions in respect of their own sectors. This, in turn, is likely to create difficulties for practitioners in keeping track of the system. As we have always said, the adventure of personal data protection law in our country is only just beginning. As the dust cloud of VERBİS, fines and the like settles, many more details and problem areas of this and a similar kind will come to light. In other words, this matter has a long way to run yet!

Footnotes

  1. Assoc. Prof. Dr., faculty member, Department of Criminal Law, Criminal Procedure Law and IT Law, Faculty of Law, Istanbul Aydın University, [email protected]. ↑
  2. Trainee Lawyer, LL.M. (University of Bonn), [email protected]. ↑
  3. Murat Volkan Dülger, Kişisel Verilerin Korunması Hukuku, 2. Baskı, İstanbul, Hukuk Akademisi Eğitim ve Yayıncılık, 2019, s. 138 vd. ↑
  4. Directive 95/46/EC of the European Parliament and of the Council. ↑
  5. Göknil Özcan, Bankacılık İş ve İşlemlerinde Kişisel Verilerin Korunması, İstanbul, Onikilevha Yayıncılık, 2020, s. 48. ↑
  6. Explanatory Memorandum of Law No. 7222, No. 98, submitted on 6/2/2020. ↑
  7. Özcan, s. 51. ↑
  8. Özcan, s. 52; on the point that offering additional advantages in return for explicit consent deprives the consent of its lawfulness, see: Dülger, Kişisel Verilerin Korunması Hukuku, s. 149. ↑
  9. Aydınlatma Yükümlülüğünün Yerine Getirilmesinde Uyulacak Usul ve Esaslar Hakkında Tebliğ, (Çevrimiçi) https://www.resmigazete.gov.tr/eskiler/2018/03/20180310-5.htm (s.e.t. 26.2.2020); Aydınlatma Yükümlülüğünün Yerine Getirilmesi Rehberi, (Çevrimiçi) https://www.kvkk.gov.tr/Icerik/5394/Aydinlatma- Yukumlulugunun-Yerine-Getirilmesi-Rehberi (s.e.t. 26.2.2020) ↑
  10. Dülger, Kişisel Verilerin Korunması Hukuku, s. 289. ↑
  11. On the manner in which explicit consent is to be obtained, see: Dülger, Kişisel Verilerin Korunması Hukuku, s. 152. ↑
  12. Hilal Üçüncü, Medeni Yargılama Hukukunda Kişisel Verilerin ve Sırların Korunması, İstanbul, Onikilevha Yayıncılık, 2019, s. 21 vd. ↑
  13. Ticari Sır, Banka Sırrı ve Müşteri Sırrı Hakkında Kanun Tasarısı, (Çevrimiçi) http://www.kgm.adalet.gov.tr/tasariasamalari/tbmmkms/tbmmkom/ticarisir.pdf (s.e.t. 26.2.2020) ↑
  14. For some examples of definitions and for an analysis, see: Üçüncü, s. 27 vd. ↑
  15. The personal data to be understood by the term “data” used here are any kind of information covered by the definition of personal data in Law No. 6698 on the Protection of Personal Data (KVKK). What comes to mind at this point, beginning with the most basic customer information, is a large body of information, both of a general nature and falling within the special categories. It includes information of a general nature such as occupation, contact details, home or business address, credit card repayment status, debt status, account number and date of opening, as well as information falling within the special categories such as the electronic signature and the digital biometric signature. For the sources from which the information is obtained and for a detailed analysis, see: Özcan, s. 12 vd. ↑
  16. For the text of the draft see: https://www.bddk.org.tr/ContentBddk/dokuman/mevzuat_0867.pdf (Çevrimiçi) https://www.bddk.org.tr/ContentBddk/dokuman/mevzuat_0867.pdf (s.e.t. 26.2.2020); the text was opened for consultation by the Banking Regulation and Supervision Agency (BDDK) on 25.12.2018, and under Provisional Art. 1 banks were also granted a transition period for compliance until 1.1.2020; as of that date the text bearing the name “draft” entered our lives as a “regulation”. ↑
  17. With the publication of the provision in the Official Gazette, many similar criticisms began to be voiced; for an example see: (Çevrimiçi) Onur Sümer, https://www.linkedin.com/posts/sumeronur_kvkk-kisiselveri-bddk-activity- 6637976210452291584-m3Gi/ (s.e.t. 26.2.2020) ↑
  18. Explanatory Memorandum of Law No. 7222, No. 98, submitted on 6/2/2020. ↑

Download PDF (in Turkish)

Related publications