2 August 2019Murat Volkan DülgerCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

The concept of the data controller is by now very familiar to us, because the data controller lies, so to speak, at the heart of Law No. 6698 on the Protection of Personal Data (KVKK) and of personal data protection law. It has a central role in securing and protecting this right. There is, however, another concept with which we are not so familiar: joint controllers. On 29 July 2019 the Court of Justice of the European Union (CJEU) delivered its judgment concerning Fashion ID and Facebook Ireland, which had been awaited for some time, and gave us the occasion to discuss this subject. Let us make the concept of joint controllership concrete with an example.

For instance, agencies that organise tours may share the data of the persons who will take part in a tour with airlines and hotels, and may carry out operations on those data together. This does not, however, show that the airline, the hotel and the tour agency are joint controllers. Here each of them carries out data processing for its own different purposes and by different means, and each has a different data filing system. There are, of course, also situations where the opposite is the case. I will set out these situations on the basis of the decisions that I examine below.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

Assoc. Prof. Dr. Murat Volkan Dülger*

The concept of the controller is by now quite familiar to us. For the controller lies, as it were, at the very heart of the Law on the Protection of Personal Data (KVKK) and of personal data protection law1. It has a central role in securing and protecting this right. There is, however, one more concept with which we are not quite so familiar: joint controllers.

On 29 July 2019 the Court of Justice of the European Union (CJEU) delivered its judgment in Fashion ID and Facebook Ireland, which had been awaited for some time, and thereby gave us an occasion to discuss this subject.

1. The Concept of Joint Controller

The concept of joint controller is intended for the situation in which, in a single data filing system and in the data processing activities carried out within that filing system, the purposes and means of those activities are determined jointly by more than one person. In such situations each controller must be made subject to the data protection obligations. In determining the obligations it is important that an agreement be concluded between the parties. In making this determination, however, what is written in the agreement should not be regarded as sufficient; the actual situation in the course of the activities must also be examined.

Nevertheless, not every joint data processing activity directly means joint responsibility, nor do persons who transfer data to one another become joint controllers. In order to be joint controllers, it is necessary to determine jointly the purpose of the data processing activity and the means to be used in that activity, that is, to proceed towards a common goal by common means.

Let us make the concept of joint controller concrete with an example. Agencies organising tourist tours, for instance, may share the data of the persons who will take part in the tour with airlines and hotels and may carry out operations on those data together. This does not, however, show that the airline, the hotel and the tour agency are joint controllers. Here each of them carries out data processing in pursuit of its own different purposes and by different means, and each of them has a different data filing system. Situations in which the opposite is the case are, of course, also encountered. I shall set out those situations on the basis of the judgments which I examine below.

2. The Place of the Joint Controller in the KVKK and the GDPR

The KVKK contains no express provision on the joint controller. On the other hand, in Art. 2, entitled “Definitions”, of Directive 95/46/EC (the Directive), which is the source legislation, the controller is defined as the person who alone or jointly with others determines the purposes and means of data processing. Whether as a result of a deliberate choice to that effect or of a careless translation one cannot tell, but no wording such as “alone or jointly” has been included in the KVKK. Nor, however, can the conclusion be drawn from the provision defining the controller (Art. 3(1)(ı) KVKK) that the joint controller is entirely excluded. For no expression such as “alone”, and hence no restriction, has been included either. Since the provision speaks of the controller only as the person who determines the purposes and means of data processing, it is unclear whether two persons will be jointly responsible when they make that determination together or, in other words, whether they will be regarded as joint controllers. I hope that this uncertainty will be removed in the amendments planned specifically for the KVKK which were announced in recent days in the Eleventh Development Plan.

When we look at the European Union's General Data Protection Regulation (GDPR), on the other hand, we see that the importance attached to the concept of joint controller has increased. The concept of joint controller is dealt with under a separate article and in a detailed provision (Art. 26 GDPR). By stating that where two or more controllers jointly determine the purposes and means of data processing they shall be joint controllers, that article has retained the definition in the Directive. An additional obligation has, however, been imposed on joint controllers, and it is stated that their obligations under the GDPR, in particular the obligation concerning the securing of the data subjects' right to be informed, must be regulated in a clear and transparent manner by an agreement to be concluded between the controllers. The GDPR attaches great importance to this agreement between joint controllers and expects it to reflect clearly the roles and relationships of the controllers vis-à-vis the data subject. According to the same article, the essence of the agreement must be made available to the data subjects.

In short, the GDPR has expressly regulated the joint controller, has attached great importance to the “Joint Controllership Agreement” to be concluded, and has not wished to leave here an area in which responsibility can be evaded and in which, so to speak, the two sides throw the ball at each other as in a game of dodgeball. On the other hand, the concept of joint controller, first mentioned in the Directive, has been clarified only by the GDPR. Consequently, the approach of the Directive and of the GDPR to the concept of joint controller and the application of the rules will be shaped by court decisions that are only now being delivered. One of these decisions is the judgment of 29 July 2019, delivered very recently by the CJEU. In my article I, for my part, shall assess the Wirtschaftsakademie and Jehovah's Witnesses judgments, likewise delivered by the CJEU last year, as well as the Fashion ID judgment which I mentioned in the preceding sentence, and shall try to set out the Court's point of view.

3. The CJEU's Judgment of 5 June 2018 in Wirtschaftsakademie and Facebook Ireland

A. The Facts

Wirtschaftsakademie offers educational services by means of a personal page (fan page) which it has set up on Facebook. These fan pages on Facebook are user accounts that can be opened by individuals or businesses.

Fan pages benefit from certain services and platforms which Facebook offers to these pages. By means of the platform called “Facebook Insights”, which the page can use free of charge, it can obtain anonymous statistical data on the visitors to its fan page. This platform is made available to the page free of charge under Facebook's non-negotiable terms of use.

These analytical data are collected, for transfer to the fan pages, by means of cookies, each of which contains a unique user code, is active for two years and is located, via Facebook, on the hard disk of the computer or in the media sections of the Facebook accounts of its other visitors. The user code, which can be matched with the connection data of users registered on Facebook, is collected and processed when the fan pages in question are loaded2.

By its decision of 3 November 2011, the data protection authority of the Land of Schleswig-Holstein in Germany (Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein) decided, first of all, that both Wirtschaftsakademie and Facebook had breached the data breach notification obligation. The court also ordered Wirtschaftsakademie to remove its Facebook page within the period specified in the decision, failing which it would face a fine. In the result, the authority regarded Facebook and Wirtschaftsakademie as joint controllers and decided that their joint obligations had been breached. Wirtschaftsakademie lodged an objection against this decision, arguing that it was not responsible for the processing of the data by Facebook or by the cookies installed by Facebook3.

In the objection proceedings the German authority decided that Wirtschaftsakademie was responsible as content provider. According to that decision, by opening a Facebook page and activating Facebook Insights, Wirtschaftsakademie benefits from the statistics provided by Facebook and makes an active and deliberate contribution to the collection by Facebook of personal data relating to the visitors to the page4.

What emerges from the court's decision is that, by engaging in these activities, Wirtschaftsakademie becomes a partner in Facebook's data processing purposes and uses the same means of data processing (Facebook Insights). Facebook, for its part, in any case makes this platform available to fan pages. Joint controllership is therefore at issue.

After the proceedings conducted before the German Administrative Court, the German Higher Administrative Court and the German Federal Administrative Court, the case came before the CJEU5.

B. The Court's Opinion and Legal Assessment

According to the CJEU, first of all, both Wirtschaftsakademie and Facebook Ireland are controllers6. The CJEU went on to hold that this controllership is a joint controllership and that Facebook and Wirtschaftsakademie are joint controllers.

This is because a fan page of this kind takes part in Facebook's data processing activity, in the determination of the purposes and means of the processing of the personal data of the visitors to the page, by defining its own parameters (depending in particular on its target audience and on its objectives of managing or promoting its own activities)7. Both Wirtschaftsakademie and Facebook collect users' information for the same purposes and under the same parameters, and do so by the same means. In this situation, according to the CJEU, the fact that the owner of a Facebook fan page uses the platform provided by Facebook in order to benefit from the associated services does not have the consequence that it need not comply with the obligations relating to the protection of personal data8.

According to the CJEU, the recognition of the joint controllership of the operator of the social network (Facebook) and the administrator of a fan page hosted on that network (Wirtschaftsakademie) provides a more robust safeguard in respect of data security9.

Nevertheless, joint controllership does not mean “equal” controllership. Joint controllers may assume obligations of varying degrees at various stages of the data processing activities. The level of responsibility of each joint controller must be considered separately in each individual case10.

4. The CJEU's Judgment of 10 July 2018 in Jehovah's Witnesses

Jehovah's Witnesses11 are the subject of another of the interesting judgments which the CJEU has recently delivered on the joint controller and on physical data filing systems12. The Jehovah's Witnesses judgment is in fact a very comprehensive and technical judgment that concerns many fundamental issues of personal data protection law. Numerous thorny issues are discussed in the judgment, such as the processing of personal data by natural persons in the course of activities relating purely to themselves or to family members living in the same dwelling (Art. 28(1) KVKK and Art. 3(2) of the Directive), whether data recorded physically form part of a data filing system, and the conflict between the right to the protection of personal data and freedom of religion and conscience and freedom of association. Another of its dimensions concerns the concept of joint controller, and, given the scope of this article, I shall deal with the judgment specifically in this respect.

A. The Facts

At their centres in Finland, as a method of religious propaganda widely used by Jehovah's Witnesses, members of Jehovah's Witnesses go from door to door and make contact with people13. In the course of their conversations with people, the members record data relating to them in the form of notes. The notes contain the names and addresses of the persons and information about their religious beliefs and family circumstances. The data are kept for the subsequent visits to be made by the members14.

The management of Jehovah's Witnesses recommends to its members working on the religious magazines which it publishes that these data be used in those magazines as well. In addition, the data are used for the purpose of mapping the area. The data of persons who refuse the request to join Jehovah's Witnesses are also kept, under a separate “refusal record”15.

The Finnish Data Protection Supervisor (Tietosuojavaltuutettu) brought the matter of these data processing activities of Jehovah's Witnesses before the Finnish Data Protection Board. The Board found that the principles of data processing had not been complied with. It was decided that the collection of personal data by the Jehovah's Witnesses Community for the purposes of that community would be prohibited for a period of six months unless the principles were observed16.

The Jehovah's Witnesses Community brought an action against the decision before the Helsinki Administrative Court. The court held that Jehovah's Witnesses was not a controller and that, for that reason, its activities did not constitute unlawful processing of personal data17. The Finnish Data Protection Supervisor lodged an appeal on points of law against the judgment18.

The Finnish Supreme Administrative Court dwelt on the question whether the Jehovah's Witnesses Community is a controller. First of all, the data processing activity referred to must be characterised, under Arts. 2(1)(c) and 3(1) of the Directive, as manual data processing that forms a data filing system. For that reason the activity in question falls within the scope of the Directive19.

The Jehovah's Witnesses Community organises door-to-door religious propaganda, coordinates and encourages these activities and, in doing so, requests its members to collect people's data and to take certain notes about them. The Community has an effective mechanism of control over the data processing activity and can restrict or terminate the data processing activities. Moreover, by making recommendations as to which data are to be processed and in what manner, and by guiding its members, it determines the purposes and means of the data processing. Furthermore, the forms which the Community has given to its members for these notes to be kept are proof that it participates actively and deliberately in the data processing. In conclusion, according to the Supreme Administrative Court the Community is a controller20.

Approaching the matter from the side of the members, the Supreme Administrative Court states that the members too can decide for themselves whether or not they will process data and for what purpose they will carry out this activity. Moreover, they can themselves determine how they will do this, that is, the means of data processing. What is more, the Community cannot gain access to these data processed by its members, with the exception of the “refusal records”.

The Finnish Supreme Administrative Court ended its assessment at this point and referred a total of four questions to the CJEU. It is the third and fourth questions that concern the issue of the joint controller.

In the third question the Finnish Supreme Administrative Court asked whether a religious community which organises a data processing activity (having regard in particular to the fact that it determines the geographical areas in which the activity will be carried out by the various members, supervises the members' data processing activities and keeps a list of the persons who have refused to join the community) may be regarded as a controller even if it claims that only the members who collect the data have access to them21. In the fourth question it asked whether, in order for the religious community to be regarded as a controller, the written instructions and orders prepared by the religious community concerning the collection of the data are sufficient to establish de facto control over the members who collect the data22.

B. The Court's Opinion and Legal Assessment

The CJEU considers the third and fourth questions together. The Court recalls that, in the proceedings before the national courts, the Jehovah's Witnesses Community and the members of that Community were characterised as joint controllers, that only the Community lodged an objection, and that the question whether the members are controllers is not being examined afresh23.

Drawing attention to the Directive's wording “alone or jointly with others”, it recalls that the concept of joint controller is provided for. The actors who take part in the data processing operation must be made subject to the data protection obligations24. It reiterates, however, that the existence of joint responsibility does not imply equal responsibility of the various controllers involved in the processing of personal data. On the contrary, it states that those controllers may be involved at different stages of the processing of personal data and to different degrees, so that the level of responsibility of each of them must be assessed on the basis of the specific case25.

The Court continues to approach the question of the controller and the joint controller from a broad perspective. Any natural or legal person who exerts influence over the processing of personal data for his or her own purposes and who participates in the process of determining the purposes and means of that processing may be characterised as a controller26. This is the sole criterion to be taken as the basis in determining joint controllership. For joint controllership to be accepted, the Court does not require that the controllers necessarily have access to every kind of data27.

On the facts of the specific case, the CJEU states that the members of the Jehovah's Witnesses Community are able to determine in which circumstances they will collect personal data relating to the persons they visit, which data will be collected and how they will subsequently process those data. On the other hand, the organisation and encouragement of this are carried out by the Community itself, and it is used for the purpose of spreading its faith28. For this reason, these persons, who act jointly in the process of determining the purposes and means of data processing, were regarded as joint controllers29.

Looking at the case, the Community draws a general line as regards the purposes and means of data processing by the written instructions which it sends to the members; the members, for their part, acting freely within this framework and collecting information on people's beliefs and ways of life in the manner which they themselves determine, take part in the aim of spreading the faith and make an active contribution. Although no such term exists, for the purposes of understanding the case the members act, as it were, in the manner of a “sub”-controller. It must also be said, however, that this would blur the boundary between processor and controller.

A further dimension of the Jehovah's Witnesses judgment is this: going from door to door to conduct religious or political propaganda, having people fill in various forms or collecting information about people in this way is a widespread method of disseminating ideas that is used in our country too. The persons who carry out these data processing activities should not think that they need not comply with the principles of data processing on the ground that they process these data manually (by non-automated means). Where these form part of a data filing system, both those who collect these data “in the field” and the management of these organisations must, as joint controllers, be made subject to the data protection obligations. Political parties have been exempted from the obligation to register with VERBİS (Data Controllers' Registry) by the decision30 taken by the Personal Data Protection Board on the basis of Art. 16(2), but it should not be forgotten that they have the obligations of a controller arising from the KVKK.

5. The CJEU's Judgment of 29 July 2019 in Fashion ID and Facebook Ireland

A. The Facts

Fashion ID is a German online retail site. Fashion ID embedded Facebook's “Like” button in its own website as a third party plug-in. When such a third-party plug-in is embedded, visitors' data are also transferred to those third parties by the browser which they use. The operator of a website who embeds a third-party plug-in in its own website has no control over whether data are transferred and which data will be transferred, nor does it have any choice in the matter.

As a result, whenever any user visits Fashion ID's website, that user's IP address and information relating to the characteristics of the user's software are transferred to Facebook. When Fashion ID's website is loaded, the transfer of personal data takes place automatically, regardless of whether the user has clicked on the Like button or has a Facebook account31.

Verbraucherzentrale NRW, a German consumer association, brought an action against Fashion ID on the ground that the use of the Facebook “Like” button on the Fashion ID website and the transfer of the data to Facebook Ireland infringed Directive 95/46/EC. Fashion ID claimed that it was unaware of this situation. Facebook Ireland, for its part, stated that the visitors' IP addresses were converted into a general, generic form and stored in that format. In the case before it, the Higher Regional Court of Düsseldorf referred the case to the Court in order to obtain its views on the application of the Directive32.

B. The Court's Opinion and Legal Assessment

Advocate General Michal Bobek of the CJEU expressed the opinion that the content provider of a website that has embedded a third-party plug-in, such as the Facebook Like button, which causes users' personal data to be collected and transferred, is, once it has embedded it, a joint controller with Facebook at this stage of the data processing. The joint responsibility of the controller should, however, be limited to those activities in respect of which it effectively decides, together with the other controller, on the means and purposes of the processing of personal data. Accordingly, the operator of the website must provide users with the necessary information regarding the data processing activities in question and must obtain their consent before the personal data are recorded and transferred33.

In its judgment the CJEU dwells on the question whether Fashion ID may be characterised as a controller even though it has no influence over the transfer of the data to Facebook. The CJEU states first of all that the aim of the provisions on the controller is to introduce a broad scope and definition of the controller, so that the rights of individuals over their data can be protected to a high degree34. The concept of controller must therefore be interpreted broadly and with a view to securing the rights of individuals.

The CJEU then goes on to provide clarification concerning the concept of joint controller as well. The joint controller has been designed, for cases in which more than one actor plays a role in the data processing activity, in order to make all of those persons subject to the obligations of a controller. It is sufficient for joint controllers to determine the purposes and means of data processing together; they need not in addition have access to those data35. The CJEU interprets the concept of joint controller broadly as well but, referring to the Wirtschaftsakademie and Jehovah's Witnesses judgments, recalls that joint controllership is not “equal” controllership36.

The CJEU deals with the question of joint controllership by assessing the stages of the data processing activities. Fashion ID plays no role in determining which data will be transferred to Facebook Ireland or in the subsequent processing operations concerning the transferred data. However, by including the third-party plug-in on its site, it plays an active and deliberate role in the collection of the data and their transfer to Facebook. Moreover, thanks to Facebook's plug-in, Fashion ID increases the publicity for its products and obtains an economic benefit for itself. For all these reasons, at this stage Facebook Ireland and Fashion ID are joint controllers37. Fashion ID must inform the data subjects with regard to these stages and obtain their consent38. At the subsequent stages, by contrast, responsibility lies with Facebook Ireland, which processes the data for its own purposes and by its own means39.

Conclusion

The first conclusion to be drawn from the CJEU's judgments is that the concept of controller is given a broad interpretation and that this is justified by reference to securing the right to the protection of personal data. In parallel with this, the concept of joint controller is also approached from a broad perspective. Natural or legal persons who take part in the process of determining the purposes and means of data processing and make an active contribution to that process may be characterised as joint controllers. At the same time, the CJEU introduces a separate assessment of the concept of joint controller on the basis of the stages and degrees of the data processing activities. Joint controllership need not extend to the whole of the data processing activity; the means and purposes may also have been determined jointly at only a particular stage of the activity. Likewise, the degrees of responsibility of the controllers do not have to be the same; joint controllership will not mean “equal” controllership. A further conclusion is that, for controllers to be characterised as joint controllers, it is not necessary that all of them have direct access to the data or derive a benefit from the activity.

I shall conclude my remarks by considering the concept of joint controller from the standpoint of the legislation in our country. The joint controller is not a concept regulated in the KVKK. There is no wording to indicate either that joint controllership is accepted or that it is not accepted. However, considering that the Directive's wording “alone or jointly with others” was not taken over into the Law, it is in my opinion not really appropriate either to say that the joint controller is applicable under the KVKK.

As you know, the Eleventh Development Plan, which covers the period 2019-2023, was published in the Official Gazette in recent days. It can be seen that line 479.1 of the Plan contains the statement “Law No. 6698 on the Protection of Personal Data will be updated taking into account the EU's General Data Protection Regulation.” The amendments to be made to the KVKK on the basis of the GDPR, which have long been talked about, should also cover the concept of joint controller. The developments in EU personal data protection law tend towards identifying each controller separately, recognising their responsibilities and, in the awareness that data processing activities are large-scale operations, apportioning responsibility. I expect the KVKK too to fill this gap concerning the joint controller in the light of current developments and approaches.

Footnotes

  1. Academic / Attorney-at-law. ↑
  2. The controller is defined as the natural or legal person who determines the purposes and means of the processing of personal data and who is responsible for the establishment and management of the data filing system (KVKK Art. 3(1)(ı)). The controller is the person who is the founder and manager of the data processing organisation, the bearer of numerous and varied data protection obligations, and the addressee of the requests of data subjects. ↑
  3. ABAD, Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein v. Wirtschaftsakademie Schleswig- Holstein GmbH, Facebook Ireland Limited, C-210/16, Başvuru T. 01/07/2016, Karar T. 5/6/2018, (Çevrimiçi), http://curia.europa.eu/juris/celex.jsf?celex=62016CJ0210&lang1=en&type=TXT&ancre= (Erişim Tarihi: 31 Temmuz 2019), para. 14-15. ↑
  4. Wirtschaftsakademie, para. 16. ↑
  5. Wirtschaftsakademie, para. 17. ↑
  6. Wirtschaftsakademie, para. 18-24. ↑
  7. Wirtschaftsakademie, para. 30-35, 55. ↑
  8. Wirtschaftsakademie, para. 36-39. ↑
  9. Wirtschaftsakademie, para. 40. ↑
  10. Wirtschaftsakademie, para. 42. ↑
  11. Wirtschaftsakademie, para. 43. ↑
  12. Jehovah’s Witnesses are a Christian denomination that departs from mainstream Christianity on account of its beliefs opposed to the Trinity (the Father, the Son and the Holy Spirit). As a matter of faith they do not smoke, and they are opposed to bearing arms and to killing. For this reason they do not perform military service, do not take part in war, do not involve themselves in politics and do not accept blood transfusions. They believe that the problems of the world will be solved only by God’s Heavenly Kingdom (Government). In order to spread their beliefs they generally make contact with people by going from door to door. They are a religious community with an estimated number of close to 8.3 million believers worldwide, and they carry on their activities in 240 countries and territories around the world. ↑
  13. ABAD, Tietosuojavaltuutettu v. Jehovan todistajat — uskonnollinen yhdyskunta, C-25/17, Başvuru T. 01/02/2018, Karar T. 10/07/2018, (Çevrimiçi) http://curia.europa.eu/juris/document/document.jsf?text=&docid=198949&pageIndex=0&doclang=en&mode =lst&dir=&occ=first&part=1&cid=5051740 (Erişim Tarihi: 31 Temmuz 2019). ↑
  14. Jehovan todistajat, para. 11. ↑
  15. Jehovan todistajat, para. 15. ↑
  16. Jehovan todistajat, para. 16. ↑
  17. Jehovan todistajat, para. 11. ↑
  18. Jehovan todistajat, para. 13. ↑
  19. Jehovan todistajat, para. 14. ↑
  20. Jehovan todistajat, para. 20. ↑
  21. Jehovan todistajat, para. 22. ↑
  22. Jehovan todistajat, para. 24. ↑
  23. Jehovan todistajat, para. 24. ↑
  24. Jehovan todistajat, para. 64. ↑
  25. Jehovan todistajat, para. 65. ↑
  26. Jehovan todistajat, para. 66. ↑
  27. Jehovan todistajat, para. 68. ↑
  28. Jehovan todistajat, para. 69. ↑
  29. Jehovan todistajat, para. 70. ↑
  30. Jehovan todistajat, para. 63. ↑
  31. Kişisel Verileri Koruma Kurulu, Veri Sorumluları Siciline Kayıt Yükümlülüğünden İstisna Tutulacak Veri Sorumluları" ile ilgili 02/04/2018 Tarihli ve 2018/32 Sayılı Karar, (Çevrimiçi) https://www.kvkk.gov.tr/Icerik/4233/2018-32 (Erişim Tarihi: 31 Temmuz 2019) ↑
  32. ABAD, Fashion ID GmbH & Co. KG, Facebook Ireland Limited v. Verbraucherzentrale NRW e.V., Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, C-40/17, Başvuru T. 24/03/2017, Mütalaa T. 19/12/2018, Karar T. 29/07/2019 (Çevrimiçi), Mütalaa: http://curia.europa.eu/juris/celex.jsf?celex=62017CC0040&lang1=en&type=TXT&ancre=, Karar: http://curia.europa.eu/juris/document/document.jsf;jsessionid=8DBD69E7AE1F7E84F2821CD64A2189A0?t ext=&docid=216555&pageIndex=0&doclang=EN&mode=req&dir=&occ=first&part=1&cid=4907333 (Erişim Tarihi: 31 Temmuz 2019), Mütalaa, para. 16-17; Karar, para. 25-27. ↑
  33. Fashion ID, Mütalaa, para. 18; Karar, para. 28. ↑
  34. Fashion ID, Mütalaa, para. 139-141. ↑
  35. Fashion ID, Karar, para. 65-66. ↑
  36. Fashion ID, Karar, para. 67-69. ↑
  37. Fashion ID, Karar, para. 70. ↑
  38. Fashion ID, Karar, para. 75-81. ↑
  39. Fashion ID, Karar, para. 106. ↑
  40. Fashion ID, Karar, para. 101. ↑

Download PDF (in Turkish)

Related publications