15 March 2021Murat Volkan Dülger, Cansu Ceren Kahraman, Simay YalçınCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

Law No. 6698 on the Protection of Personal Data (KVKK) contains no specific provision on children’s personal data. This causes uncertainty in practice and, as a result, problems. One of the problems we encounter most often is how the obligation to inform is to be fulfilled where the data subject is a child and, where explicit consent is required, from whom and how it is to be obtained.

In this piece we first touch on the nature of the right to the protection of personal data, then turn to the protection of children’s personal data under the GDPR and to the Board’s decision in question, and finally discuss the problems in practice and the solutions we propose.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

Murat Volkan Dülger* / Cansu Ceren Kahraman* / Simay Yalçın*

Introduction

Law No. 6698 on the Protection of Personal Data (KVKK) contains no specific provision on the personal data of children. This gives rise to uncertainty in practice and, consequently, to problems. One of the problems most frequently encountered is how the obligation to inform is to be fulfilled where the data subject is a child and, in cases where explicit consent must be obtained, from whom and how that consent is to be obtained.

The Personal Data Protection Board issued a decision on the request made by the father of a person who had not yet reached the age of eighteen (a child) for the destruction of his child’s personal data. Unfortunately, however, the decision did not go beyond being one that is far from resolving the problems in practice and that contains uncertainties of its own. Yet what we expected of the Board was that it would issue more concrete decisions shedding light on the subject.

In this article, after first addressing the nature of the right to the protection of personal data, we shall deal with the protection of children’s personal data under the GDPR and with the Board’s decision in question, and lastly we shall discuss the problems in practice and our proposed solutions.

I. The Protection of Personal Data as a Right

According to the definition accepted in legal scholarship (although no precise definition is to be found in the laws), strictly personal rights are rights which cannot be transferred to another, do not pass by inheritance, relate to the personality of the right holder and, as a rule, cannot be exercised through legal representation but must be exercised by the right holder in person1. Like all other rights, these rights cannot be exercised by those who lack capacity of discernment. The real point to be discussed with regard to these rights is whether the legal representatives of persons wholly lacking capacity may exercise them.

In legal scholarship and in practice, the view has been reached that the inability of the legal representative to exercise strictly personal rights in the case of full incapacity may result not only in incapacity to act but also in incapacity to hold rights (and that an unjust outcome may thus arise), and that, in order to prevent this, at least some strictly personal rights must be exercised by legal representatives; and it has been argued that these rights must be examined by dividing them into two groups. According to the authors who defend this view in legal scholarship, these rights are divided into absolutely strictly personal rights (such as engagement, marriage and divorce, which the legal representative can in no circumstances exercise on behalf of the person wholly lacking capacity) and relatively strictly personal rights (which a person with capacity of discernment may exercise in person, whereas in the absence of capacity of discernment his or her legal representative may exercise them on his or her behalf).

Persons with limited incapacity may also exercise their strictly personal rights without the need for their legal representatives. However, the legal representative must also take part in the exercise of those strictly personal rights which the law provides are to be exercised together with the legal representative2. Art. 16(1) of the Turkish Civil Code No. 4721 provides: “Minors and persons under guardianship who have capacity of discernment may not incur obligations by their own acts without the consent of their legal representatives. This consent is not required for gratuitous acquisitions and for the exercise of strictly personal rights.” We are of the opinion that the expression “this consent is not required” used here does not lead to the conclusion that the person’s legal representative can never exercise these rights; on the contrary, legal representatives may exercise relatively strictly personal rights in the name and for the account of the person with limited incapacity.

In conclusion, while it is not possible to speak of a legal representative in the case of absolutely strictly personal rights, legal representation is permitted in respect of relatively strictly personal rights.

Personal data are defined as any information relating to an identified or identifiable natural person (KVKK Art. 3(d)). Although every natural person has the right to protect his or her personal data, the right to the protection of personal data must be regarded as a relatively strictly personal right, since, in the case of minors, the inability of their legal representatives to exercise this right could result in the minor’s incapacity to hold rights. It thus follows that, alongside the persons themselves, their legal representatives may also exercise these rights in their name and for their account. This approach produces fairer results as regards the right to the protection of personal data.

II. The Protection of Children’s Personal Data under the GDPR

The processing of personal data belonging to children is governed by a separate article in the European General Data Protection Regulation (GDPR). Under Article 8 of the GDPR, which deals with this subject, a child must be at least 16 years old for his or her personal data to be processed; if the child is below the age of 16, the permission of his or her legally appointed parent or guardian must be obtained. This article of the GDPR also provides that the Member States of the European Union may change this age in their own domestic law, but that any such change must be made in such a way that the age is not lower than 13 years. Under the article in question, the lawful processing of the personal data of children below the age of 16 is made subject to the consent or authorisation of the person holding parental responsibility over the child. The data processing activity is lawful to the extent that the parent/guardian has given or authorised consent.

The best example of how the relevant provision of the GDPR is applied is the United Kingdom. Indeed, the Information Commissioner’s Office (ICO), the data protection authority of the United Kingdom, issues very important and exemplary decisions on the protection of personal data. Under the rules in the United Kingdom, only those aged 13 and over may give their own consent in relation to the provision of information society services. As regards those under the age of 13, unless the information society service is an online preventive or counselling service, the child’s consent is provided through his or her responsible parents3. This rule means the following: if lawfulness is to be ensured by basing information society services on consent, the person giving consent must be of the age required for this. According to Article 3 of the United Nations Convention on the Rights of the Child, all actions concerning children, whether undertaken by public or private social welfare institutions, must in every case give primary consideration to the interests of the child.

The validity of the consent given is also an important matter. At the stage of obtaining the child’s consent, his or her competence is of importance. The child must have the capacity to understand the consequences of the collection and processing of his or her personal data. Since capacity is assumed to vary according to the child’s personality, it is not possible to speak of a definite age range. As far as England, Wales and Northern Ireland are concerned, there is no clear indication of the age at which a child is to be regarded as competent, whereas in Scotland those aged 12 and over are, unless the contrary is proved, deemed to have sufficient capacity to give their consent for data protection purposes. In Austria this threshold is 14 years of age.

If consent has been given on behalf of a child, the child whose data are collected must know that he or she has the right to withdraw this consent at any time. Children also have the right to know how their data will be used and what rights they have in respect of their data. This information must be explained to children in simple language appropriate to their age. Article 8(2) of the GDPR, for its part, states that the controller must make reasonable efforts, taking into consideration available technology, to verify that consent is given or authorised by the holder of parental responsibility over the child. In this sense there is also uncertainty as to what constitutes reasonable efforts. Having regard also to technology, which today is constantly changing and developing, we are of the opinion that on this matter too it would be more appropriate to interpret on a case-by-case basis.

For example, one may wish to open an e-mail address for a child who wants to receive information about his or her favourite band. Provided that this e-mail address is used only to send e-mails concerning the content about which the child wishes to receive information, the risk for the personal data collected here may be said to be lower. In such a situation, the reasonable efforts to be made by the controller might be simply to place a tick box for a declaration that the user is old enough to give his or her own consent, or for a declaration by his or her parent, or to obtain confirmation by e-mail. It may be said that these steps in the process concerned are sufficient in view of the low risks at the data processing stage.

To change the example, as regards online services that enable persons to share their personal data through chat rooms, the participation of children in such a service may be riskier. More stringent methods must therefore be adopted to verify the permission obtained. One of the methods that may be applied could be to obtain confirmation from third parties that the child is sufficiently mature to give his or her consent. Another method could be to verify the relationship with the child by checking the identity of the person said to be the child’s parent.

In conclusion, as information technologies develop, the meaning of reasonable efforts will also change; but the approach of calculating the risk and making reasonable efforts to ensure that valid consent has been obtained in the light of the possible risks must always remain the same4.

In this connection, there is an action brought in the USA against Google and YouTube5. It is known that YouTube is nowadays a platform which children prefer to television. Indeed, the application contains many channels addressed to child users. In this case too, it was found that the data of children under the age of 13 had been collected unlawfully while they were using the application, and it was accordingly decided that Google and YouTube, which had collected data without obtaining the consent of the children and their families, had to pay compensation to the families. Following this case, Duncan Mccan6, who in England likewise made a claim concerning the unlawful use of his children’s data as a result of their use of YouTube, stated that his children loved YouTube and that it was not possible for him to prevent them from using it, but that a platform such as YouTube must without fail act in accordance with the law.7 In this claim Mccann also stated that there is a great imbalance of power between families and technology platforms and that data protection laws are not being complied with8.

As is also apparent from the case, in the context of present-day technological developments, controllers must, taking account of use by children, take the necessary measures in connection with the collection of their data and obtain their consent in a lawful manner.

In conclusion, Article 8 of the GDPR offers two options in practice: either consent is obtained directly from the data subject’s parents, or the parents authorise the data subject to give consent himself or herself. Unless one of these two options is applied, it is not possible to process a child’s personal data under the GDPR9.

III. The Position in Turkish Law and the Board’s Decision No. 2020/ 622 of 11/ 08/ 2020

A. Summary of the Decision

In the case giving rise to the complaint, the controller, to which the person’s father had applied for the destruction from the records of a medical report belonging to the data subject, who had not yet reached the age of 18, and alleged to have been drawn up untruthfully, did not reply to this request. Following the failure to reply, the father lodged a complaint with the Personal Data Protection Board (Board).

In its decision the Board first referred to Article 12 of the Constitution, which is found in Chapter One of Part Two, headed “Fundamental Rights and Duties”, and which sets out the nature of fundamental rights and freedoms, and then to paragraph 3 of Article 20, which governs personal data, and to the purpose of Law No. 6698 on the Protection of Personal Data.

It then stated that our legislation, Law No. 4721 in particular, contains no definition of a strictly personal right or of the right of personality; that the right of personality is, nevertheless, a strictly personal right which a person has over his or her material and non-material assets, economic integrity and sphere of secrecy; that, by reason of this nature, this right, which may be asserted against everyone, cannot be transferred to another, cannot be waived and is not subject to a limitation period; that, on account of these characteristics, strictly personal rights do not pass to the heirs by inheritance and are extinguished of themselves on the death of the holder of the right; that, in this sense, the rights which data subjects have in connection with the processing of their personal data are also strictly personal rights; and that strictly personal rights are divided in legal scholarship into absolute and relative ones.

It was stated that, in the exercise of absolutely strictly personal rights such as becoming engaged, marrying, acknowledging a child born out of wedlock, concluding a matrimonial property agreement, becoming a member of an association and making a testamentary disposition, the power of decision is vested in the right holder, subject to the consent of the parent; that relatively strictly personal rights, such as bringing actions for the protection of personality and actions for the correction of age and name, may be exercised by the minor in person and may also be exercised by the parent in the name and for the account of the minor; that, in this sense, the rule in Art. 16(1) of Law No. 4721, according to which the consent of their legal representatives is not required for minors with capacity of discernment to exercise strictly personal rights, is a rule conferring power on the child but not a rule of prohibition for the parent; and that the parent may exercise relatively strictly personal rights in the name and for the account of the minor.

In this respect the Board concluded that, having regard also to the best interests of the child, the right to the protection of personal data must likewise, as far as the case at hand is concerned, be treated in the category of relatively strictly personal rights. It further observed that Art. 5(6) of the “Regulation on Personal Health Data” states that everyone may exercise the rights set out in Article 11 of Law No. 6698 in relation to himself or herself by applying to the controller; that paragraph 1 of Article 8 of the Regulation lays down that parents may access the health records relating to their children via e-Nabız without needing any approval, and that children with capacity of discernment may make their parents’ access to their health history via e-Nabız subject to permission; that it is understood that, under the provisions of the said Regulation, persons with limited incapacity may also exercise in person the rights set out in Article 11 of the Law, provided that they have capacity of discernment, and that, in addition, as regards access to e-Nabız data, both the minor and his or her parent are authorised unless the minor provides otherwise; and that this arrangement is also consistent with the assessment that, as far as the case at hand is concerned, the right to the protection of personal data is a relatively strictly personal right , since in both situations the minor with capacity of discernment may exercise the right in question in person, and its exercise by the parent in the minor’s name and for the minor’s account is also permitted. On the basis of this assessment, the Board reached the conclusion that, provided that the minor has capacity of discernment (and also taking into account that the intentions of the data subject minor and of his or her parent coincide with regard to the application), the data subject and his or her father were entitled to exercise the right of complaint in question, both as regards the application made to the controller and as regards the complaint brought before the Board.

B. Assessment of the Decision

The Turkish Civil Code (as the Board noted in its decision) contains no definition of strictly personal rights. Nor is there any provision as to whether the protection of personal data has the character of a strictly personal right. For this reason, in order to determine how the rights under Law No. 6698 are to be exercised in respect of persons who have not reached the age of eighteen, it must first be determined whether the protection of personal data is a strictly personal right. The Board, too, carried out an examination to this effect in its decision.

Capacity of discernment is a person’s ability to grasp the legal consequences of the acts which he or she performs. In respect of persons with capacity of discernment, the consent of their legal representatives is not required as a condition for the exercise of strictly personal rights. Indeed, according to Article 16 of the Turkish Civil Code, “Minors and persons under guardianship who have capacity of discernment may not incur obligations by their own acts without the consent of their legal representatives. This consent is not required for gratuitous acquisitions and for the exercise of strictly personal rights”.

In this respect, as we have explained above, it must be accepted that children with capacity of discernment may, because personal data are a strictly personal right, exercise their rights arising from the Personal Data Protection Legislation on their own, without their parent/guardian. Here too, however (as we shall explain in more detail below), information must be given as to the ages at which and the circumstances in which the existence of capacity of discernment is to be accepted. For even in the absence of a decision of the Board, when the Personal Data Protection Legislation, the purpose of that legislation and the other provisions are assessed, the conclusion follows that personal data are a strictly personal right.

The matter which the Board ought in particular to emphasise and clarify here is who, for the purposes of the KVKK, are to be regarded as persons with capacity of discernment. In deciding that “since, provided that the minor has capacity of discernment, and taking into account also that the intentions of the data subject minor and of his or her parent coincide with regard to the application, it is considered that both parties may be accepted as entitled to exercise the right, both as regards the application made to the controller and as regards the complaint brought before the Board, the data subject and his or her father are, in the present case, entitled to exercise the right of complaint in question”, the Board has at the same time raised the question of what is to happen where those intentions do not coincide. To continue with the same example, what will happen where the parent/guardian wants the child’s photographs to be shared on social media but the child does not want this? How is this problem to be resolved? In trying to shape practice, the Board has in fact (rightly) raised other problems as well.

In fact, this question is a complex problem that also involves socio-cultural issues. For the answers to it vary from society to society and even according to the family relations of the sub-groups within a single society. In our view, where the wishes of the parent/guardian and those of the child conflict, weight should, save in exceptional cases, be given to the will of the child. For it is the child himself or herself who will have to live with that photograph in adult life and who may not wish to be remembered as he or she appears in it. Of course, it is not right for the law to interfere in every relationship within the family. It therefore cannot be said that the parent/guardian must obtain the child’s explicit consent for every photograph to be shared on social media. However, where the child expressly objects, the photographs in question should not be published and, if they have been published, should be removed. This matter must without fail be regulated and clarified by statute.

IV. Problems in Practice Concerning Children’s Personal Data and Their Solutions

Under Article 10 of the Law on the Protection of Personal Data, the controller is under an obligation to inform. The controller must provide information on the identity of the controller and of its representative, if any, the purpose for which the personal data will be processed, to whom and for what purpose the processed personal data may be transferred, the method of and legal ground for collecting the personal data, and the rights listed in Article 11. According to the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform, the burden of proving that the obligation to inform has been fulfilled also lies with the controller.

The information must be given to the data subject in clear and plain language. In other words, it must be in a language and style that the data subject can understand. Where the information is provided in a manner that the data subject cannot understand, the obligation to inform has not been fulfilled. What, then, if the data subject is under the age of 18? It is precisely at this point that a number of problems arise:

1- How is the obligation to inform to be fulfilled in respect of persons under the age of 18 and (where required) how is their explicit consent to be obtained? 2- Is the parent/guardian to be the addressee of the information and of the explicit consent? 3- Where the data subject is a person under the age of 18, by whom are the rights listed in Article 11 of the Law to be exercised? 4- What language and style are to be used in fulfilling the obligation to inform in respect of persons under the age of 18?

5- Is a distinction to be drawn between ages, as in the GDPR, with regard to the obligation to inform, the obtaining of explicit consent and the rights of the data subject?

The fact that persons under the age of 18, in other words children, are data subjects gives rise to problems in practice. For example, a high school wishes to share photographs of its pupils aged 15 to 17 via the school’s social media account. In order for the pupils’ photographs to be shared on the social media account for promotional purposes, the pupils must be informed and their explicit consent obtained. Let us alter the example somewhat. A nursery school wishes to share photographs of its pupils aged 5 to 6 via the nursery school’s social media account. For both age groups, should the parent/guardian be the addressee of the obligation to inform and of the explicit consent? Is a distinction between ages, as in the GDPR, possible? In order to answer these questions, the concept of capacity of discernment must first be considered.

In legal scholarship, capacity of discernment is defined as a person’s ability to understand and grasp the legal consequences to which his or her acts give rise10. According to Article 13 of the Turkish Civil Code, “Everyone who is not deprived of the ability to act reasonably on account of minority of age or by reason of mental illness, mental weakness, drunkenness or similar causes has capacity of discernment under this Code”. However, the Code makes no provision as regards minority of age. In other words, while stating that persons of minor age do not have capacity of discernment, the Code has not specified what age is to be understood by minority of age. Whether a person has capacity of discernment must be determined by looking at the circumstances of the particular case and for that particular case alone. Indeed, there are decisions of the Swiss Federal Supreme Court to the same effect. On the other hand, there are also countries, such as Germany (where persons who have not completed the age of seven are deemed not to have capacity of discernment), that have regulated this matter11.

It must be accepted that, for the purposes of personal data protection law, a child who has capacity of discernment can exercise the rights arising from the relevant legislation, that the obligation to inform can be fulfilled towards the child, and that explicit consent can be obtained from the child himself or herself. However, having controllers determine in each individual case whether capacity of discernment exists is not a workable solution if their activities are to proceed without disruption. For instance, in the example given above, persons aged 15 to 17 may be regarded as having capacity of discernment with regard to the sharing of their photographs on social media. But if we take into account the fact that we live in the age of technology, can a 12-year-old also be regarded as having capacity of discernment with regard to the sharing of his or her photographs via social media accounts?

This uncertainty causes major problems in practice. In our opinion, by way of an update to the personal data protection legislation (in order to clarify matters such as the fulfilment of the obligation to inform), express provision should be made for a specific age group or groups, and an age should be fixed, as in the GDPR. Since persons who have completed the age of 15 are also of significance in terms of criminal law (even though that field has legislation of its own), it would be acceptable for them to be the addressees for the purposes of personal data protection law. In other words, the obligation to inform may be fulfilled directly towards persons who have completed the age of 15, and explicit consent may be obtained directly from them. As regards persons who have not completed the age of 15, these acts may be carried out by their parent/guardian. In addition, with regard to the consent that persons between the ages of 15 and 18 give to the processing of their personal data, a differentiation may be made by taking various criteria into account. For certain declarations of consent, the joint consent of both the minor and the parent/guardian may be required. In this way, a middle course and a solution may be found that protects the rights of minors while also giving weight to their will.

It must be reiterated that in practice it is very difficult for controllers to determine, in each individual case, whether the child has capacity of discernment. The criterion of having completed the age of 15 is also consistent with the GDPR and is important in that it ensures parallelism with it. Indeed, as mentioned in the 11th Presidential Development Plan, the GDPR will be taken as a model in the amendments to be made to the personal data protection legislation, and the amendments will be made within that framework. However, since there is at present no statutory provision, the age criterion of 15 is no more than a proposal. For it is not possible to fix a particular age in practice without any statutory provision having been enacted.

So what do we do in practice? In practice we resolve this problem by applying the criterion of having completed the age of 18. We recommend that, for persons who have not completed the age of 18, the information be given to those exercising parental authority on their behalf and that explicit consent be obtained from their parents/guardians. In this way we eliminate both the problem of determining capacity of discernment, which puts controllers in a difficult position in practice, and the possibility that the wills concerned do not coincide. We recommend this because the age of 18 is the solution that is safe and most compatible with the existing statutory provisions.

Conclusion

In order to examine the protection of personal data in relation to children, the legal nature of the protection of personal data as a right must first be determined. Strictly personal rights are divided (according to legal scholarship) into two categories, absolute and relative. As the Board also stated in its decision, the protection of personal data is a relative strictly personal right, and not regarding it as absolute is more in keeping with the purpose of the legislation.

For the exercise of relative strictly personal rights, it is also important to determine whether the person has capacity of discernment. Our legislation mentions minority of age as one of the circumstances that exclude capacity of discernment; however, it contains no specific provision as to what is to be understood by minority of age. Legal scholarship has sought to resolve the question of what is to be understood by minority of age (in terms of capacity of discernment). According to the prevailing view in legal scholarship, capacity of discernment in relation to minority of age must be assessed in each individual case. Where the protection of personal data is concerned, however, it is not possible for controllers (given that they carry out a very wide variety of activities) to assess, for each of their activities, whether children have capacity of discernment. For this reason, it would be appropriate to fix an age by means of a statutory provision.

According to the GDPR, if the child is below the age of 16, the authorisation of the child’s legally appointed parent or guardian is required. It is also possible for the Member States of the EU to provide for an age lower than 16, provided that it is not below 13. Although it might be argued that the GDPR approach could also be applied in Turkey, the age of 16 laid down in the GDPR cannot be used, because there is no provision on this matter in the other legislation either (legislation other than the personal data protection legislation), first and foremost the Turkish Civil Code. Under Turkish law, the only age relating to the exercise of rights is 18 (apart from situations relating to marriage). An age bracket other than the age of 18 exists in our legislation in criminal law. A statutory provision on the protection of children’s personal data must without fail be enacted. In such a provision, the consent given by children between the ages of 15 and 18 may also be rendered valid for the purposes of personal data protection. Considering that ours is an age of technology (and that they are able to marry and divorce), persons between the ages of 15 and 18 may be regarded as having capacity of discernment in this matter.

Since there is at present no provision on the protection of children’s personal data, we resolve the problems arising in practice by taking the age of 18 as the criterion. We recommend that, for persons under the age of 18, the information be given to those exercising parental authority on their behalf, that explicit consent be obtained from their parents/guardians, and that the rights be exercised by their parents/guardians.

The Personal Data Protection Board, for its part, correctly characterised the protection of personal data in its decision as a relative strictly personal right. As regards the exercise of rights by children, it decided that, provided that the minor has capacity of discernment and that the minor’s will coincides with that of the parent/guardian, both the parent/guardian and the child are entitled to exercise the rights. However, this decision not only falls short of resolving the problems encountered in practice but has also given rise to a number of uncertainties. It is our hope that the Board, in adopting its decisions, will focus on resolving the problems encountered in practice, will give better reasons for its decisions and share them with the public, and will not cause further uncertainty.

Footnotes

  1. Attorney-at-Law, Assoc. Prof. Dr., Istanbul Aydın University Faculty of Law, Department of Criminal Law, Criminal Procedure Law and IT Law, [email protected]. ↑
  2. Attorney-at-Law, Istanbul Bar Association; Master’s student, Department of Public Law, Institute of Social Sciences, Marmara University, [email protected], ORCID No: 0000-0003-4642-2687. ↑
  3. Trainee Attorney-at-Law, Istanbul Bar Association, [email protected]. ↑
  4. Mustafa Dural/Tufan Öğüz, Türk Özel Hukuku Cilt II Kişiler Hukuku, 16. Baskı, Filiz Kitabevi, İstanbul 2015, s. 79. ↑
  5. Dural/Öğüz, s. 93. ↑
  6. https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/children-and-the-gdpr/what-are-the-rules-about-an-iss-and-consent/ Erişim Tarihi: 02.10.2020. ↑
  7. https://ico.org.uk/media/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/children-and-the-gdpr-1-0.pdf Erişim Tarihi: 05.10. 2020. ↑
  8. https://www.ftc.gov/news-events/press-releases/2019/09/google-youtube-will-pay-record-170-million-alleged-violations Erişim Tarihi: 06.10.2020. ↑
  9. Digital researcher. ↑
  10. https://www.dataguidance.com/news/uk-youtube-faces-legal-action-allegedly-breaching-childrens-privacy Erişim Tarihi: 05.10.2020. ↑
  11. https://www.forbes.com/sites/emmawoollacott/2020/09/14/lawsuit-accuses-youtube-of-violating-childrens-privacy/#35b8b4a713fe, Erişim Tarihi: 07. 10.2020. ↑
  12. https://www.iubenda.com/en/help/11429-minors-and-the-gdpr Erişim Tarihi: 05.10.2020 ↑
  13. Vehbi Umut Erkan/İpek Yücer, Ayırt Etme Gücü, Ankara Üniversitesi Hukuk Fakültesi Dergisi, C. 60, S. 3, 2011, s. 486. ↑
  14. Erkan/Yücer, s. 489, 490. ↑

Download PDF (in Turkish)

Related publications