15 October 2020Murat Volkan DülgerCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

Can the judicial authorities, whose task is to apply the law, go a little further and require the application of legal rules that have not yet entered into force? Can they find a violation against those who did not act in conformity with a statutory rule that will enter into force one day? Can persons, institutions or organisations be made subject to a sanction for an act that took place at a time when the rule in question was not in force? Can a person who, under the conditions of that day, did not bear the obligation introduced by that rule really be expected to act in conformity with it? The Constitutional Court has given a decision in which it states that the answer to all these questions is “Yes”. But what has happened to the principles and rules taught in the very first year of law school in the “Introduction to Law” course?

In this piece I examine that decision of the Constitutional Court in the light of the general principles and rules of law and of national and international legislation on the protection of personal data, above all the Law, and I set out findings on the question of the scope and limits of employers’ inspection of their employees’ e-mails.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

Murat Volkan Dülger*

May the judicial authorities charged with applying the law go a step further and demand that legal provisions which have not yet entered into force be applied as well? May they find a violation on the part of those who fail to comply with some statutory provision that will enter into force one day? May persons, institutions or organisations be subjected to a sanction on account of an act that took place at a time when the provision in question was not in force? Can a person who, under the conditions of that day, did not bear the obligation introduced by that provision really be expected to act in accordance with it? The Constitutional Court has delivered a judgment in which it states that the answer to all of these questions is “Yes”. But what, then, has become of the principles and rules taught in the very first year of law school in the “Introduction to Law” course?

By its judgment (the Judgment) in “Application of E.Ü.”1, published in the Official Gazette of 14 October 2020, No. 31274, the Constitutional Court (the Court) held that an employer was required to apply a statutory provision that had not yet entered into force, and thereby delivered a decision that calls for serious discussion from the standpoint of the most fundamental principles and rules of law. According to the Constitutional Court, the fact that in 2015 an employer, seeking to restore order in the face of the disruption of order and of work that followed a dispute at the workplace, examined the corporate e-mails used by its employees in the context of a work-related dispute amounts to acting contrary to the obligations introduced by the Law on the Protection of Personal Data (the Law), which entered into force on 7 April 2016. The key question to be asked here is this: Could the employer really have foreseen that such an obligation would later be imposed on it? Or, to put it more accurately and comprehensively, can persons be expected to be soothsayers in a state governed by the rule of law?

In this article I shall examine the judgment in question delivered by the Constitutional Court in the light of the general principles and rules of law and of national and international data protection legislation, first and foremost the Law, and make findings on the problem of the scope and limits of employers’ examination of employees’ e-mails.

I. The Facts Underlying the Judgment

The subject of the Judgment is the application of an attorney whose corporate e-mail address was examined by the employer, an attorney partnership (the employer), on account of problems the attorney had had with the manager and the teammates. The employer received written complaints concerning the manager and the attorney, in a five-person team which included the attorney in question, alleging that they had had various disputes with the other three (3) members of the team, had lost their objectivity, had disrupted the order of work and had thereby caused the loss of the environment necessary for the projects to proceed properly.

The employer, whose duty and power it is to examine complaints reaching it about the order of the workplace and to ensure corporate order and industrial peace, thereupon, in the inquiry it conducted, examined the corporate e-mails of its employee and found that the complaints concerning that employee were well founded. Having concluded, as a result of the e-mails examined, that it was not possible to continue the employment relationship with the attorney in question, the employer terminated its employment relationship with the applicant.

The following points should be noted in the events up to this point:

• The computer in the employee’s possession was a work computer allocated to the employee by the employer; the correspondence examined by the employer was correspondence conducted through the corporate e-mail.

• As will be explained in detail below, the employer has a right of management under the relevant provisions of Labour Law No. 4857 (Labour Law) and Turkish Code of Obligations No. 6098 (TBK), and within the framework of this right of management it is empowered to establish and maintain the necessary order at the workplace, to ensure industrial peace, to examine and resolve the problems and disputes arising at the workplace and, to that end, to use personal data belonging to employees. What is more, beyond being a power, these matters at the same time constitute obligations of the employer.

• The employer carried out its examination solely in line with the complaint it had received and examined only the e-mail correspondence between the employee and the other employees with whom the employee was alleged to have had problems.

• The other parties to the e-mails examined by the employer were not persons outside the workplace; they were, again, the employer’s own employees.

The employee, who upon being dismissed brought a declaratory action seeking reinstatement, claimed not to have started the dispute and asserted that the e-mail correspondence in question consisted of personal conversations with the team manager which had been uttered under the strain of the work at the time and had not been reflected to the outside. The employee further added that, were retrospective examinations to be carried out, it could be established that similar e-mails had also passed between other employees.

The employer, for its part, replied that more than one written complaint had been submitted to it; that it had been compelled to examine the corporate e-mails because the difficulties in the working team were rooted not in events but in statements, and because they involved momentary acts that were almost impossible to prove; and that as a result of this examination it had indeed found messages containing threats, psychological harassment and insults.

The court of first instance held that the termination by the employer constituted termination for just cause and dismissed the action, on the grounds that the employee had had disputes verging on quarrels with the other employees in the team, that these disputes stemmed from the employee’s attitude and conduct, and that the e-mail address in question was one that had been given to the employee for carrying out the work required by the employee’s duties and that the employee knew could be examined by the employer at any time.

As regards the proceedings before the local court, the following points should be underlined:

• The employee stated that the events were normal and that, if a retrospective examination were carried out, similar correspondence would be found. The employee has an attitude and conduct capable of regarding e-mail correspondence containing threats and harassment as normal. Moreover, as is also apparent from the employee’s own statement, the employer has no process such as the continuous and regular examination of employees’ e-mails as a matter of routine in the absence of any complaint.

• The complaints addressed to the employer are, by their nature, based on statements made among the employees and on momentary acts, that is, on events that are almost impossible to prove.

• The court of first instance found that the employee knew that the e-mail address given to the employee could be examined by the employer at any time.

The employee, claiming that the e-mail correspondence in question was private correspondence between two persons, appealed on points of law against the judgment of the court of first instance; the employer, for its part, stated that the correspondence had been conducted through corporate e-mail accounts, that all correspondence from these communication addresses was kept on a server belonging to the employer and that, in accordance with the decisions rendered by the Court of Cassation at the time, it had the power to monitor these e-mails. The judgment of the court of first instance was upheld, with its reasoning being amended on the ground that the employee had engaged in conduct of a nature disrupting industrial peace and with the characterisation of the termination being changed to termination for valid reason.

Of the claims and defences at the Court of Cassation stage, the following points should be noted:

• The employee claims that the correspondence with another person working at the same workplace, conducted through the corporate e-mail address, was personal and related to the employee’s private life.

• The Court of Cassation decisions from the period in which the employer carried out the monitoring express the view that an employer may monitor its employees’ e-mails.

After the judgment was upheld by the Court of Cassation, the matter came before the Constitutional Court by way of the application lodged by the employee (the Applicant) on 15 July 2016.

II. The Employee–Employer Relationship in the Context of the Protection of Personal Data

1. In General

Today, when working life occupies an important place and a large share of time in people’s lives, the employee–employer relationship is also of importance with regard to personal data. At the stage of the formation of the employment contract and throughout its duration, the employee is in a position of economic and legal dependence on the employer, while the employer is under a duty to protect and look after its employee. This reciprocal relationship between employee and employer makes it necessary for the employer to process the personal data of its employee. In addition, the possibilities afforded by developing information technologies have made it necessary to approach the connection between this relationship and personal data from a different perspective. Personal data are therefore of particular importance in the employment relationship, including the establishment of the employment relationship, the working process, departure from the job and even the period after departure.

For this reason, the entry into force on 7 April 2016 of Law No. 6698 on the Protection of Personal Data undoubtedly had its greatest impact on the relationship between employee and employer. Since then, employers have been made subject to numerous obligations in the process of processing the personal data of their employees. Before the entry into force of this Law, too, there was undoubtedly an obligation to protect personal data, since the protection of personal data had been placed under a constitutional guarantee as something to be protected within the scope of the right to respect for private life. However, which information constituted personal data, how such data were to be protected and which concrete obligations had to be fulfilled were not regulated by norms of positive law. Indeed, in the projects for compliance with the Law that we have carried out in companies since the Law entered into force, the obligations of employers, who are in the position of controller vis-à-vis their employees, occupy a large place; in this framework, the drawing up of information notices explaining in detail how employees’ personal data are processed, of explicit consent texts obtaining the employee’s approval where necessary, of retention and destruction policies and tables indicating when the data will be destroyed, and of the other necessary policies is carried out as a statutory requirement. For the Law had imposed on the controller a serious compliance phase and a documentation obligation. But was this also the case before the Law?

With the entry into force of the Law in 2016, the processes relating to the processing of personal data, which had previously been subject to no norm of positive law and to no condition, were all at once made subject to rules which both cover all business processes from beginning to end and impose serious obligations. Did the concept of the protection of personal data not exist before that date? Of course it did. But no concrete obligation whatsoever had been imposed in connection with this concept. Did there, then, have to be a concrete obligation for personal data to be protected? In my view there did not; personal data had to be protected all the same. Under those conditions, however, all you can expect of a company processing data is that it does not directly interfere, through personal data, with the fundamental rights and freedoms of individuals; you cannot expect it to fulfil the concrete obligations introduced by a Law that would enter into force later.

I think that precisely this point has become a major impasse in Türkiye. Although, through the projects for compliance with the Law that we carry out, we organise the processes for the processing of personal data so that they are subject to specific rules and conditions, it has unfortunately not been understood that this subject is not, by itself, a matter for a project. It is not a realistic view to expect companies in Türkiye which, since their foundation, have been subject to no rule whatsoever when obtaining, collecting, storing and transferring personal data to fulfil — and, what is more, to internalise — within a few years or by means of a project of 6-8 months the very serious obligations that were imposed all at once. In this respect it must be said that even companies that make every effort within their power find themselves in a very difficult position despite these efforts.

2. The Problem of the Examination of Employees’ E-mails by Employers

The examination by employers of employees’ corporate e-mail addresses ranks first among the problems encountered in this field. What were the employer’s powers and limits in this regard before the entry into force of the Law, and what happened after the Law? Although more than four years have passed since the Law entered into force, this matter has still not been set out in concrete terms. For in every question and in every search for a solution, the employee’s right to the protection of personal data comes up against the employer’s right of management, the need to ensure order at the workplace and the realities of practice.

The question whether the employer may examine employees’ e-mail correspondence must, from the standpoint of the law, be divided into two — the period before and the period after the entry into force of Law No. 6698 — so that it can be determined in the light of the provisions in force. Rather than drawing this distinction here, I prefer to explain it below, in connection with the case at hand, when assessing the reasoning of the Court’s judgment.

III. The Constitutional Court’s Finding of a Violation and the Reasoning of the Judgment

On the grounds it set out, the Constitutional Court concluded that the courts of instance had not conducted a careful trial observing the constitutional guarantees it referred to and that the positive obligations had therefore not been fulfilled; it held that the right to request the protection of personal data guaranteed by Article 20 of the Constitution and the freedom of communication guaranteed by Article 22 of the Constitution had been violated.

The Court’s reasoning for its finding of a violation should be addressed.

1. In General

First of all, I must state that the examination carried out by the Constitutional Court is highly inadequate and incomplete for a judgment of such importance, one that will affect almost all employers, and that, moreover, it rests in places on statements that create a false impression. While this is the general character of the Judgment, I must stress emphatically that the situation is even graver as regards the basic grounds relied on for the finding of a violation, and that at this point what was carried out goes far beyond an incomplete and inadequate examination: it is an examination contrary to the fundamental principles and rules of law.

First, it is seen that in the legislation section of the Judgment the Constitutional Court included the KVKK, which in terms of time could not be applied to the dispute, and Regulation (EU) 2016/679, the European Union General Data Protection Regulation (GDPR), which in terms of place does not have the character of legislation before the Turkish courts. Against this, it must be recalled that in a state governed by the rule of law legal certainty is fundamental and that, in this context, the “Principle of the Non-Retroactivity of Laws” applies. Accordingly, the fact that the provisions of Law No. 6698, which did not exist at the time, were taken into account in the Court’s judgment is, in itself, a violation of the principle of legal certainty. Likewise the GDPR, as I have stated in my earlier assessments, could at most be regarded as a proposition in the nature of a recommendation; it has no binding force and no applicability whatsoever. Indeed, that the provisions of the GDPR are not directly applicable is also established by the decisions published by the Personal Data Protection Board (the Board). For the Board, in response to requests for opinions submitted to it on various matters, has rendered decisions showing that it regards the provisions of the GDPR as having the character of suggestions.

For the Court examined an event that took place on 10 January 2015 not according to the conditions and the statutory provisions in force on that day (ex ante) but according to today’s statutory provisions (ex post), and determined what the employer should have done on the date of the event by reference to today’s statutory provisions. Yet it is a matter going to the very foundation of legal logic that a judicial body assessing the lawfulness of an event must carry out this examination according to the norms of positive law in force at the moment the event took place. An examination of the past carried out according to the law existing at the time of the examination is in itself unlawful.

Does the Constitutional Court, then, as I stated in the introduction to this article, expect an employer to foresee the obligations that will be imposed on it by a statutory provision that has not yet entered into force and to act accordingly? My hope is that the Court harbours no such expectation and that it ruled in this way “as the result of an error”, which could at least be described as less grave. In truth, the Constitutional Court does not have the luxury of making so grave an error. I think there is nothing excusable in the disregard of the general fundamental principles of law by the Constitutional Court, whose task it is to review compliance with the European Convention on Human Rights and the Constitution.

I would like to draw attention to the fact that the problem here goes far beyond an ordinary employee–employer dispute. This error concerns the temporal application of norms. Just as is taught in introduction to law courses, in the introductory chapters of the basic courses such as civil law, criminal law and administrative law, too, when and how the norms of the branch of law concerned enter into force and are applied is written in the textbooks and taught to law students. The problem here is therefore not a problem of labour law or of data protection law but one of the general theory of law. Moreover, this erroneous interpretation made today with regard to the employee–employer relationship may be made tomorrow with regard to rulers and ruled, government and opposition, law enforcement and citizens, and so on. Beyond the specific dispute, therefore, there is here a problem of principle and an error concerning the application of legal norms. The basic aim of this article is to expose this mistake.

In order to expose this mistake of principle, we shall discuss, on the basis of the reasons the Court gave for its finding of a violation in the present situation, whether the employer really had an obligation to foresee.

2. Article 20 of the Constitution, Headed “Privacy of private life”, and Law No. 6698 on the Protection of Personal Data

In its examination in the Judgment, the Court carried out an assessment within the scope of Article 20 of the Constitution and of the Law and concluded that Article 20 had been violated2.

The protection of personal data was placed under constitutional protection by the paragraph added to Article 20 of the Constitution, headed “Privacy of private life”, by Article 2 of Law No. 5982 of 7 May 2010. This paragraph provides that everyone has the right to request the protection of his or her personal data, and an attempt was made to draw a general framework as to what the right covers. The right to the protection of personal data thus began to be protected as a constitutional right.

It should be noted, however, that this paragraph does not impose any positive obligation on persons. Indeed, the last sentence of the paragraph contains the phrase “The principles and procedures regarding the protection of personal data shall be laid down by law”. Thus, by the addition made to the Constitution, the protection of personal data was in fact recognised as a fundamental right and freedom, but no rules concerning this right were introduced. How this right is to be protected, to which principles and procedures it is subject — in other words, in which cases this right will have been violated — is uncertain. In essence, this provision imposed on the State an obligation to regulate the matter by means of a norm of positive law. This uncertainty was undoubtedly removed when Law No. 6698 entered into force on 7 April 2016.

But how is this right to be protected in the intervening six-year period? This is where a great dilemma lies. The paragraph added to the Constitution in 2010 introduced none of the concrete obligations introduced by the Law that entered into force in 2016. This does not of course mean that the provision made in 2010 had no effect at all. It must be accepted, however, that the effect of this provision lay to a large extent not in practice but in theory. The article took effect in practice through Law No. 6698. In the period before that, it is not possible to expect those processing data in practice to fulfil a positive obligation. For to hold otherwise would mean that, as from 2010, all persons and organisations processing data violated Article 20 of the Constitution on the ground that they acted contrary to Law No. 6698.

This is also the basic problem in the case at hand: the date of the event underlying the Judgment falls within this interval, and the provisions of the Law cannot be applied. Nevertheless, in its review of the lawfulness of an event that took place in 2015, the Constitutional Court regrettably carried out an examination within the framework of the Law that entered into force in 2016, and thus put its name to a judgment that calls for serious discussion:

“However, considering that there is no obstacle to applying, in labour law disputes, the guarantees concerning the rights to respect for private life and to request the protection of personal data and the freedom of communication enshrined in Articles 20 and 22 of the Constitution, together with Law No. 6698 and the general provisions existing in our legal system…3”

By this statement the Court is plainly saying “since the specific rules on the subject were introduced by Law No. 6698, there is nothing to prevent me from applying this Law in disputes relating to labour law too”. It appears, however, that the date of entry into force of the Law, to whose application the Court saw no obstacle, was overlooked. For this judgment of the Court at the same time means “I shall carry out my examination within the framework of the provisions of this Law in all labour disputes predating the entry into force of the Law, and I may also find a violation under Article 20”. And since the addition to the said Article 20 was made in 2010, will the Court henceforth, in all disputes from the years 2010 to 2016 that come before it, require that employers have acted in accordance with the rules introduced by the Law?

Proceeding from this viewpoint of the Court, are we, at a time when the concrete obligations introduced by the Law still cannot be fully met, to turn to controllers and say “you should have foreseen the obligations that would enter into force in 2016 and acted accordingly”? And are we to cite Article 20 of the Constitution as the basis for this? Is law really such a thing? How can the judicial authorities charged with applying the law go further still and expect the positive obligations that a law not yet in force will impose to be performed in advance? For this is exactly what the Constitutional Court has done.

Law is a social science in which the rules of logic apply, which springs from life itself and which uses the methods of scientific inquiry. No proposition, rule or decision that is contrary to reason, logic and science has any place in law. Just as people cannot be expected to refrain today from an act that may be made an offence in the future — or, conversely, just as criminal norms cannot be applied with retroactive effect — this universally valid rule holds for the other legal disciplines as well. Legal norms are applied prospectively from the moment they enter into force. The sole exception to this is the retroactive application of the criminal norm that is more favourable to the perpetrator. No such norm exists in labour law or in data protection law.

Furthermore, in order to be able to hold people responsible for something, they must know that thing, or must at least have some knowledge of it, even if not in detail, as to its existence. For example, even if the perpetrator has no detailed knowledge of the criminal norm, he must have some knowledge that the act he commits constitutes a wrong; in criminal law we call this awareness of wrongdoing. Where this awareness is lacking, we say that no penalty should be imposed on the perpetrator because there is no culpability.

As for the case at hand, although a general provision was made by Article 20 of the Constitution, there is no provision whatsoever to the effect that controllers must provide information or as to the circumstances in which and the manner in which this must be done. To expect all controllers to know a rule that, at that date, not even the makers of the Constitution and the Constitutional Court knew is not something that can be explained by logic.

3. Article 22 of the Constitution, Headed “Freedom of communication”, and Law No. 6698

on the Protection of Personal Data

In addition to Article 20 of the Constitution, the applicant claimed that Article 22, headed “Freedom of communication”, had also been violated; the Court accepted this claim and held that the freedom of communication had been violated. I must point out, however, that the Court did not give reasons for this decision. No further examination was carried out in this respect; the Court contented itself with merely citing the relevant article and stated in the operative part its conclusion that the article had been violated. Consequently, as far as this article is concerned, there are no statements or conclusions of the Court that could be assessed.

Nevertheless, I must state that, independently of the Court’s judgment, my views on whether the freedom of communication was violated in the case at hand run along the same lines as the explanations I have given with regard to Article 20 of the Constitution. For the confidentiality of communication is closely related to the protection of personal data, and the protection of personal data brings with it the protection of the rights relating to the freedom of communication. The reason for this is that the information covered by the freedom of communication — first and foremost the content of the communication, the names and telephone numbers of the parties, the connections established between the parties and the duration of the conversations, together with all other information — constitutes personal data to the extent that it can be linked to a natural person. Accordingly, the applicant, who was in a position to know that personal data could be obtained through the examination of the e-mails, must likewise have been able to know that the communication could be examined. Nor can the applicant, who was using a system provided and controlled by the employer, have had any expectation that this system could not be monitored.

In conclusion, I must first of all voice my criticism that, although the Court found a violation with regard to Article 22, it cannot be discerned from the Judgment that it carried out an adequate examination in this respect. As regards the Court’s conclusion that Article 22 was violated, the explanations I have given for Article 20 apply, for the reasons set out above.

4. Is There Really an Expectation of Privacy?

In order to determine whether there is an expectation of privacy, it must first be established whether the correspondence was personal or work-related. When the event underlying the application is examined, it is seen that, as the Court also stated, the correspondence consisted “of e-mail messages that passed between the applicant and the team manager, dialogues in which, in general, thoughts about each other and about the workplace were expressed and which at times took the form of arguments”.

The correspondence is therefore “personal” in so far as it concerns the disputes the applicant had with a person and the threats the applicant made, and “work-related” in so far as that person was the applicant’s team manager at the workplace and the correspondence was about the workplace itself and the other employees.

I must state at the outset that, since work-related correspondence concerns the employer as much as the employee, no expectation of privacy can be accepted as reasonable and legitimate. Personal correspondence, on the other hand, may as a rule be regarded as falling under privacy. However, in paragraph 68 of its judgment of 24.03.2016, No. 2013/4825, concerning the application of Ömür Kara and Onursal Özbek, the Court held that there can be no reasonable expectation of privacy as regards the protection of personal correspondence conducted from a corporate e-mail address either:

“It cannot be concluded that the applicants had a reasonable expectation as to the protection of the personal correspondence they conducted through their corporate e-mail accounts.”

As can be seen, in respect of another applicant who had conducted personal correspondence by means of a workplace computer and through a corporate e-mail account, the Constitutional Court held that there could be no reasonable expectation that such correspondence would be protected. In paragraph 75 of the judgment under review, by contrast, it made the exact opposite assessment. This can be explained only by the concept of the surprise decision, and it infringes the “prohibition of surprise decisions”. The relevant part of the decision of the 9th Civil Chamber of the Court of Cassation of 14.09.2020, E. 2016/26476, K. 2020/7547, which I find highly apposite on this principle and prohibition, is so clear as to make any further comment unnecessary:

“The principle of legal certainty or security, which is among the essential elements of the rule of law, ensures a certain stability in legal situations and contributes to public confidence in the courts. The persistence of conflicting court decisions may reduce confidence in the judicial system and lead to judicial uncertainty (ECtHR, Nejdet Şahin and Perihan Şahin v. Turkey, Application no. 13279/05, 20.10.2011, § 57). A change in case law must also be assessed within the framework of the prohibition of surprise decisions. A surprise decision is one where the person concerned is confronted with an unexpected decision which, in view of the course of the proceedings up to that point, he or she was justifiably not expecting. The prohibition of surprise decisions, in turn, means that, where the proceedings are conducted fairly and equitably, the parties should not be confronted with a decision they could not foresee…”

5. The Constitutional Court’s Statements on the Case Law of the ECtHR: Were the ECtHR’s Judgments Interpreted Correctly?

In its examination the Constitutional Court referred to judgments of the European Court of Human Rights (ECtHR) and based its finding of a violation in particular on the judgment in “Bărbulescu v. Romania”, delivered by the ECtHR in 2016, concerning the monitoring of e-mail addresses.

The Court recalled that in that judgment the ECtHR had held that Article 8 of the European Convention on Human Rights (the Convention), headed “Right to respect for private and family life”, had been violated on account of the employer’s monitoring of the employee’s e-mail account4. However, the judgment cited by the Court differs from the judgment under review.

• In the ECtHR’s judgment in “Bărbulescu v. Romania” the account that was examined by the employer, and whose examination gave rise to the finding of a violation, was the employee’s personal e-mail account.

In the case underlying the ECtHR’s judgment, the applicant, who worked for a private company, had both a Yahoo Messenger account he used for work purposes and, in addition, one of his own. Under the internal regulations of the workplace where the applicant worked, it was forbidden to use for personal purposes equipment allocated for office use such as computers, telephones, photocopiers and fax machines. The regulations did not, however, contain any provision to the effect that the employer could monitor the operations and acts performed on that equipment. The applicant’s communications via Yahoo Messenger were recorded for nine days, and he was dismissed for using the internet for personal purposes during working hours. Having been unsuccessful before the courts of first instance and of appeal, the applicant took the matter to the ECtHR.

It should be noted that the account which was examined by the employer in the ECtHR judgment, and whose examination gave rise to the finding of a violation, was the Yahoo Messenger account, which was in the nature of a personal account of the employee. There, the employer examined the private correspondence the employee had conducted through his Yahoo Messenger account and terminated the employment contract on the basis of that private correspondence. In the case that came before the Constitutional Court, by contrast, the account examined was a corporate e-mail address, and the content accessed was correspondence with other employees at the workplace, which therefore did not have the character of private correspondence. Hence, in that case there is no legitimate processing activity even if the employer informs its employee. For an employer to inform its employee that it may examine the employee’s personal e-mail address is undoubtedly not an acceptable interference. For this reason, the question whether the employer had an obligation to inform in the light of the existing provisions was not examined, and the employer’s access to private correspondence by examining the personal e-mail address was treated directly as an interference.

• In “Libert v. France”, its most recent judgment on the subject, the ECtHR referred to the national laws

in force at the time of the events and concluded that the monitoring

carried out by the employer did not constitute a violation.

Yet there is the judgment in “Libert v. France”, which is both far more recent than the ECtHR judgment relied on by the Constitutional Court and exactly the same as the specific case before it. The Grand Chamber decided to adjourn its examination of that case until judgment had been given in Bărbulescu v. Romania and, although a violation was found there, attached great importance to the existing statutory provisions of France and held that there had been no violation.

In addition to misinterpreting the judgment discussed above, the Constitutional Court also overlooked this very important judgment. For this is the ECtHR’s most recent judgment on whether employees’ computers may be examined. The Constitutional Court ought, above all, to have considered this judgment and made its assessment accordingly.

The case concerns the dismissal of an employee of the SNCF (the French national railway company) after the seizure of his work computer had revealed that he had stored on it pornographic files and forged certificates drawn up for a third person. Relying on Article 8 (right to respect for private and family life), the applicant complained that his employer had opened, in his absence, personal files stored on the hard drive of his work computer, and, after the Court of Cassation, took the matter to the ECtHR. At the time Libert’s computer was seized, French law provided that employers could open files on employees’ work computers unless they were identified as personal. The interference in question therefore had a legal basis similar to our law as in force at that date.

The Court stated that the interference had been intended to guarantee the protection of “the rights of others”, which in such a situation were the rights of employers, who might legitimately wish to ensure that their employees used the computer facilities they had placed at their disposal in a manner consistent with their contractual obligations and the applicable regulations. French law contained a mechanism to protect private life: the employer could open the professional files stored on the hard disks of the computers it had given its employees for the performance of their duties. It was found that the domestic courts had applied this principle and had taken the view that, in the case in question, this principle did not prevent the employer from opening the files in question because they had not been duly identified as private.

The Court assessed the situation as follows: an employee could not use for private purposes the whole of a hard drive intended for recording professional data; the generic term “personal data” would also cover work files handled personally by the employee; and there were therefore no items clearly identified as relating to private life. It was accordingly concluded that, in a case where the employee’s computer had been examined and he had been dismissed on the basis of the data obtained as a result of that examination, the employer’s interference had been justified and legitimate and the right to respect for private life had not been violated.

Similarly, the case at hand concerns a corporate e-mail account set up — again by the employer — on a computer provided by the employer. Moreover, at the time the examination was carried out, the provisions of Law No. 6698 were not in force. The statutory provisions existing at that time also provided that an examination of this kind could be carried out.

Article 419 of the Turkish Code of Obligations regulates the employer’s power to monitor and makes no mention of any obligation to inform: “The employer may use personal data concerning the employee only to the extent that they relate to the employee’s suitability for the job or are necessary for the performance of the service contract.”

Moreover, the decisions of the Court of Cassation rendered in 2016 and 2015, at the time the event took place, also set out the employer’s power very clearly:

“The employer is at all times entitled to monitor the computers and e-mail addresses belonging to it and the e-mails received at those addresses.5”

While I do not in any way argue that the decision is right from today’s perspective, such were the powers and obligations existing for an employer of that day.

The Law that entered into force on 7 April 2016 regulates this matter clearly and comprehensibly. From that date onwards, by virtue of the obligation to inform laid down in Article 10 of the Law, and having regard also to the transitional periods contained in the Law, data subjects must without fail be informed by controllers, whether or not explicit consent is required (save for the exceptions). Apart from the exceptions specified in the Law, any data processing carried out without information having been provided is unlawful. Accordingly, had this event, which occurred in 2015 and was the subject of the proceedings, occurred in the second half of 2016, the employer would definitely have acted unlawfully and the judgment of the Constitutional Court would have deserved a standing ovation. Unfortunately, however, the most fundamental principles of law were forgotten and so erroneous a judgment was delivered.

6. The Employer’s Obligation to Inform

One of the grounds on which the Constitutional Court based its finding of a violation is that the employer had not provided information6. Does the employer have an obligation to inform in this regard? If so, by which legal norm are its principles and procedures regulated?

First of all, as stated above, the examination carried out by the employer dates from 2015, and at that time the “obligation to inform” introduced by Article 10 of Law No. 6698 did not exist in concrete form. By the Law, however, the provision of information by employers was regulated by a norm of positive law. So much so that a transitional period was provided for this purpose and employers were granted a certain time in which to fulfil their obligations. For the situation that existed before the application of the Law had changed and a new era had begun in the processing of personal data.

After the obligation to inform had been introduced by the Law, the relevant Communiqué was also published, and the Board has published numerous guides and decisions. The principles and procedures of the information to be provided by the employer were determined in this way, and today it is known what kind of information must be provided. Nowadays an Information Notice in conformity with those principles and procedures is prepared and brought to the attention of employees.

In its judgment the Constitutional Court spoke of the absence of information of the kind laid down under data protection legislation7. In other words, it required the employer to foresee that the Law would enter into force in 2016, that the Board would publish a Communiqué on the subject and would announce decisions and guides clarifying the matter, and to inform the employee with a content to be drawn up within that framework. But is this possible — and, never mind the ordinary course of life, is it consistent with the ordinary course of the universe?8

Would it, then, have been acceptable before 2016 for the employee to have no information at all about how his or her personal data would be processed and for the employer to conceal this by refraining from giving any explanation on the subject? In my view it would of course not have been acceptable. First of all, the right to respect for private life is one of the most fundamental rights and freedoms, and it is settled both by the case law developed by the judicial authorities and by the views of legal scholarship that it is not only information in the nature of secrets that falls within private life. Nevertheless, it is not possible to expect the employer to have provided its employee with information of the kind understood today. What must be understood in this context is that the employer must not mislead its employee as to the personal data it processes, must not deliberately refrain from giving information and must not decline to give information on the subject if the employee enquires. To expect a positive obligation to be performed by a separate effort, however, is contrary to equity, for no such obligation had been laid down.

I therefore think that these are the points that should have been examined in the case at hand as well: Did the employer deliberately conceal that corporate e-mails could be examined? Did the employer refrain from giving information on the subject even though the employee wished to obtain it? Formal notification should not be required here; rather, it should be asked whether the employee was, both objectively and subjectively, “in a position to know”, and a finding should be made accordingly.

When an assessment of this kind is made in the case at hand, and bearing in mind that the employer in question is an attorney partnership, one can readily conclude that those working as a team were also attorneys. Viewed objectively, an attorney partnership that gives its employees personal computers for their use and provides them with corporate e-mail accounts, and which therefore has a server used by the partnership, is evidently, in terms of its volume of business, its nature and its number of employees, a medium-sized or larger attorney partnership. Seen from the outside, therefore, it can readily be said that such an organisation provides all corporate digital solutions and keeps them under its control. Indeed, this point is also noted in the Court’s judgment. It is thus apparent that, objectively and irrespective of who the person is, an attorney working there possessed this knowledge.

Although a subjective assessment in respect of the applicant is hardly possible since we have had no opportunity to see the case files, if a guess is to be ventured, a person working in 2015 as an associate attorney in an attorney partnership of this size must, subjectively too, have known that both the computers and the corporate e-mails could be examined when necessary. Indeed, in corporate digital solutions this is, in all sectors, a known fact and an unwritten rule both before and after 2016.

It can therefore be said that the applicant possessed this knowledge both objectively and subjectively. That being so, under the law in force at that date and the settled decisions of the Court of Cassation on the subject, the employer was not required to provide separate information. It must be accepted that an employee at this level already knew this.

IV. Conclusion

In conclusion, the Constitutional Court has committed a grave error by this judgment. The judgment should in fact be read from two angles: 1) from the standpoint of the law as it ought to be, 2) from the standpoint of the law as it is.

Had the Court made its findings from the standpoint of the law currently in force and of the law as it ought to be, and then, by an ex ante method, given its decision according to the law applicable at that date, it would have put its name to a judgment of principle that truly deserved praise and was in conformity with the law.

The Court did not do so, however; by an ex post method, applying today’s legal norms and today’s understanding of law, it delivered an extremely erroneous judgment in the field of data protection law, an extremely dynamic and changeable field.

This judgment is so erroneous that its error lies not in data protection law or labour law: it contains an error of basic knowledge and logic concerning the temporal application of legal norms. The Court should therefore abandon this mistaken viewpoint as soon as possible and correct this error at the first opportunity, when a similar dispute comes before it.

Footnotes

  1. Assoc. Prof. Dr., Head of the Department of Criminal Law and Criminal Procedure Law and of IT Law, Faculty of Law, Istanbul Aydın University, [email protected]. ↑
  2. Anayasa Mahkemesi, Başvuru No: 2016/13010, Karar Tarihi: 17.09.2020 (R:G. Tarih – Sayı: 14.10.2020 – 31274) ↑
  3. Para. 63 vd. ↑
  4. Para. 72. ↑
  5. Para. 43-48. ↑
  6. 22. HD. 01.09.2016, E. 2016/6321, K. 2016/13143, 22. HD. 10.03.2015, E. 2013/36288, K. 2015/9548. ↑
  7. Para. 75, 76. ↑
  8. Para. 76 ↑
  9. As it lies outside the subject of this article, I shall not deal here with the views of the theoretical physicists who have put forward ideas on time travel, Einstein and Hawking first among them. ↑

Download PDF (in Turkish)