Introduction
This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.
Although health data fall within the special categories of personal data, they are frequently the subject of processing activities. The examples we encounter most often are the medical report requested when starting a job or for membership of a sports club’s swimming pool, the data collected and recorded by a health institution to which we go for examination or treatment, and the health information kept in an employee’s personnel file.
It is therefore important that the principles and procedures for the processing of health data be clearly determined: who may collect health data, and for what purposes? In what environment and under which administrative and technical measures must these data be stored? What rules must be followed when health data are processed? Having definite answers to all these questions makes it possible to prevent the breaches likely to occur during the processing of health data.
Full text
This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.
Assoc. Prof. Dr. Murat Volkan Dülger*
Although health data belong to the special categories of personal data, they are frequently the subject of processing activities. The medical report requested on taking up a job or for membership of the swimming pool of a sports club, the data collected and recorded by a healthcare institution to which we turn for examination or treatment, and the health information kept in an employee’s personnel file are the examples we come across most often. For this reason it is important that the principles and procedures for the processing of health data be determined clearly: Who may collect health data, and on the basis of which purposes? In what environment and under which administrative and technical measures must these data be kept? What are the rules that must be complied with during the processing of health data? Having definite answers to all of these questions makes it possible to prevent the violations that are likely to occur during the processing of health data.
Unfortunately, however, the collection and processing of health data have been the subject of a long-running debate and, so to speak, have never been put on the right track. The latest development on the subject has been the “Regulation on Personal Health Data” published in Official Gazette No. 30308 of 21 June 2019. I hope that this Regulation has been drawn up in such a way as to put an end to the debates on the subject. In this article I shall try to explain what the Regulation introduces, the points on which it differs from the regulations previously published and annulled, and whether or not it will be able to put an end to the debates. Before doing so, however, I consider it useful to recall briefly the stages through which the rules on personal health data have passed:
• On 7 April 2016, Law No. 6698 on the Protection of Personal Data was published.
• On 20 October 2016, the “Regulation on the Processing of Personal Health Data and Ensuring Their Privacy” was published in Official Gazette No. 29863 and entered into force. On the date on which it was published, this Regulation, too, was criticised on the grounds that, because the Law was still new, the Board had not taken office and, consequently, opinions on the subject could not be obtained and the subject had not become clear, the matter of health data likewise could not be regulated in conformity with the legislation on the subject.
• On 12 January 2017, the members of the Personal Data Protection Board took their oath and took office.
• On 6 July 2017, a decision staying the execution of the Regulation on the Processing of Personal Health Data and Ensuring Their Privacy was given1.
• On 24 November 2017, taking into account the said decision staying execution, the Regulation Amending the Regulation on the Processing of Personal Health Data and Ensuring Their Privacy was published in No. 30250 of the Official
Gazette and entered into force2. The Regulation was republished as amended. Although an attempt was made, by means of the amendments, to lay down rules compatible and in line with the legislation on the protection of personal data, even in this form it gave rise to serious misgivings as regards ensuring the protection of personal health data. I had set out my criticisms in this respect in my article assessing the Regulation. Indeed, because in this form too it failed to bring satisfactory innovations, the Regulation in question was challenged in court by the Turkish Medical Association and the Turkish Dental Association.
• On 9 October 2018, a decision staying the execution of the Regulation Amending the Regulation on the Processing of Personal Health Data and Ensuring Their Privacy was given3. As a result of the application referred to above, the execution of the Regulation was finally stayed. The main reasons for this are that a decision staying execution had already been given by the Council of State in respect of the original Regulation, that an attempt was made to put the same Regulation back into force with a few amendments made thereafter, and that the measures to be taken in the processing of personal health data had not been determined by the Board4.
• Finally, as stated above, the Regulation on Personal Health Data was published on 21 June 2019 and the previous Regulation was repealed.
Innovations Introduced and Amendments Made by the Regulation
1. Article 1 of the Regulation, entitled “Purpose”
The first point that draws attention under the heading of purpose is the change as to which processing activities it lays down rules for. Whereas the previous instrument spoke of “the procedures relating to notification to the Ministry of Health”, the expression now preferred is “the processes and practices carried out by the units of the central and provincial organisation of the Ministry of Health, by the healthcare providers operating under them and by its affiliated and related bodies”. In this way the purpose has been framed in language more consistent with the relevant legislation and has been defined more clearly.
On the other hand, by including the words “within the scope of the provisions of the Law” at the very beginning when explaining the purpose of the newly published Regulation, an attempt has been made to show that the procedures and principles to be complied with in the processing of personal health data have been determined in conformity with the Law. This is a positive development in that it shows that the criticisms levelled at the previous instrument, to the effect that it was not in conformity with the Law, have been taken into account and that an attempt has been made to turn back from the mistake made.
2. Article 2 of the Regulation, entitled “Scope”
The scope of the Regulation has been determined as “the activities, relating to the processes and practices being carried out by the Ministry of Health, of natural and legal persons governed by private law and of legal persons governed by public law who process personal health data”. The paragraphs contained in the previous Regulation, namely a) healthcare providers, b) natural persons whose personal health data are processed, and c) natural and legal persons who provide services such as the software and hardware of the information processing systems and the filing system belonging to healthcare providers, have been removed.
Although at first sight this might suggest that the scope of the Regulation has been narrowed, I do not think that there has in fact been any such narrowing. For the fact that the purpose section of the previous Regulation already contained the expression “the procedures relating to notification to the Ministry of Health” showed that the scope, too, would relate to the processing activities carried out within the Ministry. Accordingly, trying to make the scope appear wider than it was by including other expressions was in any case a flawed way of regulating. I think that the scope has not been narrowed by this amendment, and that the aim has merely been to arrive at a more accurate provision by stating what is actually the case.
3. Article 4 of the Regulation, entitled “Definitions”
Compared with the previous Regulation, some new concepts have been added to the definitions in Article 4 of the Regulation, while some definitions that already existed have been amended or retained unchanged.
a. Newly added concepts
• Open data,
• Open health data,
• E-nabız: In the previous regulation this concept had been dealt with as the personal health record system. Accordingly, although the concept has been newly added, the definition is essentially the same. The only change is that, by adding the word “physicians” to the persons who may have access, it has been stated that physicians also have access to the e-nabız systems. In fact, physicians were able to access the e-nabız system as well. By Circular No. 2016/6 of the General Directorate of Health Information Systems, service providers had sent individuals’ health data to the system. Physicians were able to access the patient’s health data over the e-nabız system by means of the Physician Sharing Service via the Hospital Information Management System (HBYS) and the Family Medicine Information System (AHBS). A patient who had an e-nabız profile was able to determine, from the access options, who could access his or her health data. He or she will be able to approve access by his or her family physician, by the physician by whom he or she is examined, by all physicians at the hospital where he or she is examined, or by all physicians at the Ministry of Health. As for the personal data of patients who do not have an e-nabız profile, the physician by whom the patient is examined can gain access to them by sms activation. By the Regulation, a normative basis has been created for data processing and transfers of this kind
• Relevant user: This concept, too, is one which was present in the old regulation with a similar definition but which was dealt with under the heading “processor”. The new definition has been drawn up along the same lines as the “Regulation on the Erasure, Destruction or Anonymisation of Personal Data”, in which the concept of relevant user is used.
• KamuNET: The aim of this project is to carry out data communication between public institutions and bodies and, in particular, to ensure that the necessary administrative and technical measures are taken to protect health data in the course of this.
• De-identification: This concept has its source in “the use of pseudonyms” (pseudonymisation) in the GDPR. Here the expression de-identification has been preferred, and the definition has likewise been drawn up along the same lines as the GDPR.
• Personal data,
• Disposal of personal data,
• Erasure of personal data,
• Destruction of personal data,
• Authority,
• Masking: This denotes rendering personal data incapable of being associated with a natural person by methods such as crossing out or painting over.
b. Paragraph newly added to the article
Alongside the concepts defined in Article 4 of the Regulation, another point that draws attention is that paragraph 2 has been added. According to this: “For definitions not contained in the Regulation, the definitions in the Law and the definitions contained in the secondary legislation issued by the Authority shall apply.” In this way an attempt has been made to ensure consistency with data protection legislation.
4. Article 5 of the Regulation, entitled “General Principles and Rules in the Processing of Personal Health Data”
a. General principles
The Regulation first of all, by referring to the Law, states that in the processing of personal data all of the rules contained in the Law, and above all the general principles contained in Article 4 thereof, shall be complied with.
b. Security measures
Article 5 of the Regulation, which contains the general principles and rules, in fact lays down the rules to be complied with and the security measures to be taken in the processing of personal data. When we make a comparison in this respect with the original version of the Regulation, we can say that clearer and more concrete rules have been included. It is also apparent that, by means of the amendments made, an attempt has been made to ensure consistency both with the legislation on the subject and with the decisions of the Board.
The rules and measures introduced by the article may be summarised as follows:
• Registration and notification system:
The expressions concerning the personal health record system which were contained in the original version of the Regulation have been changed. In their place, the Regulation has brought the system in which the data are to be recorded together under a single paragraph and has set out in comparatively greater detail the registration and notification system to be established so that everyone can follow his or her state of health and so that health services can be carried out more effectively and quickly.
• Reference to the general principles:
By the article in question, the Regulation has stated that no one may be compelled to present or show a record of his or her past health data except in situations where this is necessary for the provision of healthcare. It has thus laid down
the rule that health data may be processed only in a manner limited to the purpose. By referring in this way to the general principles to be complied with in the processing of personal data which are set out in the Law, the Regulation has felt the need to state specifically, with regard to health data as well, the principle that personal data may be processed within the scope of specified, explicit and legitimate purposes.
• Taking of physical, technical and administrative measures:
Paragraph 4 of the article provides that healthcare providers must take the necessary physical, technical and administrative measures in such a way as to prevent the presence of unauthorised persons in areas such as counters, ticket windows and desks. This provision is in essence a direct reference to the Board’s resolution of principle to this effect. Pursuant to the Board’s “Resolution of Principle No. 2017/62 of 21/12/2017 on the Protection of Personal Data in Service Areas such as Counters, Ticket Windows and Desks”, the necessary technical and administrative measures must be taken in the areas mentioned in accordance with Article 12 of the Law and, in this connection, by preventing the presence of unauthorised persons in these areas, those receiving service at the same time in close proximity to one another must be prevented from hearing, seeing, learning or obtaining the personal data belonging to one another. By the said provision of the Regulation, an attempt has been made to ensure the direct application of the Resolution of Principle in question with regard to health data.
• De-identification and masking practices:
The Regulation has provided that healthcare providers must apply de-identification and masking measures to printed material containing personal health data belonging to the patient, such as the results of tests and examinations. It goes on to speak of making it more difficult to determine to whom the material belongs in the event that it falls into the hands of unauthorised persons. The essential aim here, therefore, is that, against the danger of a document containing personal health data falling into the hands of unauthorised persons, the person who obtains it should not be able to identify the natural person to whom the data belong, and that such identification should be made as difficult as possible. De-identification and masking measures have been cited as examples of methods capable of achieving this. That being so, the healthcare provider is also free to take other measures that will achieve this aim; it must not be forgotten, however, that in every case identification must be made more difficult.
• Rights of the data subject:
By stating that everyone may exercise the rights contained in Article 11 of the Law by applying to the controller, the Regulation has clarified, with regard to personal health data, the concepts of application to the controller and of the exercise of the data subject’s rights.
• Application to the controller:
In addition, by stating that Article 13 of the Law and the provisions of the Authority’s “Communiqué on the Procedures and Principles for Application to the Controller”, published in Official Gazette No. 30356 of 10.03.2018, shall apply to this application, a course consistent with the relevant legislation has been charted.
• Obligation to inform:
Lastly, again with the aim of being consistent with the relevant legislation, it is provided that, in fulfilling the obligation to inform, Article 10 of the Law and the provisions of the Authority’s communiqué published in No. 30356 of 10.03.2018 of the Official
Gazette, the “Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform”, shall apply.
5. Chapter Three of the Regulation, entitled “Access to Personal Health Data” (Articles 6 – 11)
a. Access of healthcare personnel to the data
The article contains provisions which do not go beyond repeating the matters determined by the Law but which are more comprehensive and detailed than its previous version. Rather than reproducing the article as it stands here, the noteworthy points should be summed up as follows:
• Access is limited solely to what the healthcare service requires.
• Access to the e-nabız account depends on the data subject’s own privacy preference. In determining these preferences, the data subject must bear in mind whether the fact that past health data cannot be viewed will lead to disruptions and harm. For the liability that may arise in this context does not lie with the Ministry.
• Access to the health data of persons who do not have an e-nabız account has been confined to the conditions for processing contained in Article 6 of the Law, and it has been determined in detail by whom, for which purposes and subject to which time limits access may be effected. This provision is highly appropriate in that it constitutes a major obstacle to one of the greatest problems concerning health data, namely that everyone within healthcare providers is able to access the data of all data subjects.
• Although the access rules mentioned may be re-evaluated by the General Directorate of Health Information Systems according to needs, in such a case the obligations falling within the scope of the obligation to inform must be fulfilled.
• It is provided that special protective measures may be taken by the Ministry with regard to those personal health data which have a high level of confidentiality and which carry the risk of adversely affecting individuals’ social life and mental health if they are seen and known by others. In all probability, data on a person’s sexual health and psychiatric data are of this nature. However, leaving such enhanced protection to the initiative of the Ministry will be meaningful only if this is done in compliance with the principles of openness and transparency.
b. Access of the Ministry’s units to the data
Article 7 of the Regulation, which governs the access of the Ministry’s units to health data, first of all states that the Ministry is authorised to designate the persons who will match the health data sent in de-identified form by healthcare providers to the central health data system with the persons to whom they belong by means of the relational database, and it has limited the persons to be authorised to a maximum of three persons from each unit. A limitation has thus been introduced as regards the persons authorised to have access.
In addition, it is noteworthy that, compared with the Law, a limitation has also been introduced as regards the matter for which the authority is to be used. The article has laid down that the persons authorised may use this authority only within the scope of the planning and management of health services and their financing and of the tasks of supervision and regulation. Moreover, in every case, this use must be in conformity with personal data protection legislation.
The fact that Article 6 of the Law, which has been criticised on the ground that it confers a broad power on the Ministry, is restricted in this way by a special provision is important in that it has been stated expressly that health data may not be processed for every purpose desired, even by the Ministry. I think that this article of the Regulation is particularly noteworthy in this respect. The express statement that, even within the Ministry, not everyone may access health data and that those who can access them may not use these data for every purpose is an extremely positive development from the standpoint of data subjects having confidence with regard to their health data and being able to know who can access their data and to what extent.
c. Access to the health data of children
According to the article, parents may access the health data of their children over the e-Nabız system without needing any permission. The limit to this is that children who have capacity of discernment can regulate access to their health history over e-Nabız. In the repealed Regulation, by contrast, it was provided that parents could access the health data without any distinction being drawn as to whether or not the children had capacity of discernment. For parents’ access to the child’s health data there was the criterion of the right of custody, and the mother or father who did not hold the right of custody could access the health data of a child under the age of fifteen provided that the custodial parent consented. If both spouses held the right of custody, they could access the child’s personal data with each other’s approval. The new Regulation, however, has first of all provided, without introducing an age criterion, that a child who has capacity of discernment may make his or her parents’ access to his or her health history subject to permission. In my opinion this is a step forward, as respect for a person’s self-determination requires. Where the child does not set a limit on access, the parents will be able to access the child’s health data without needing each other’s approval.
In the event of divorce, the party who does not hold the right of custody may access the data of his or her children, provided that this is for the benefit of the child and the custodial parent, in conformity with the legislation on the protection of personal data and within the limits determined by the General Directorate.
d. Access of patients’ relatives
The access of patients’ relatives to health data is determined in accordance with Article 18, paragraph 3, of the Regulation on Patients’ Rights, on condition that it is effected in conformity with the principles of the Law. According to this, the rule is that the patient himself or herself is to be informed. If the patient requests that another person be informed, this request is recorded in writing with the person’s signature, and information is given only to the persons whom the patient wishes to be informed.
e. Access of lawyers
The article states expressly that lawyers may not access the health data of their clients on the basis of a general power of attorney5. A lawyer can access health data belonging to his or her client only if, “in the power of attorney drawn up for the transfer of the health data to the lawyer”, there is “a special provision containing the explicit consent” of the data subject to the processing and transfer of his or her special categories of data.
f. Access to the health data of the deceased
Article 11 of the Regulation provides that health data belonging to the deceased shall be kept for a period of at least 20 years and that the statutory heirs of the deceased are individually authorised to access these data upon presenting the certificate of inheritance.
6. Chapter Four of the Regulation, entitled “Concealment, Rectification, Disposal and Transfer of Personal Health Data” (Articles 12 – 15)
a. Concealment of personal health data
Article 12 of the Regulation lays down the procedure for access to the health data of persons in respect of whom a confidentiality order has been issued. Alongside the procedure determined, the fact that it has been laid down that every kind of measure necessary must be taken to ensure that confidentiality orders are known only to those persons who need to know them by reason of their duties is again important from the standpoint of conformity with the general principles.
b. Rectification of personal health data
The article determines the procedure for keeping personal health data accurately. The accurate keeping of personal data is a fundamental element which is safeguarded both by the Law’s principle of “being accurate and, where necessary, kept up to date” and by the data subject’s right to request the rectification of his or her data.
While there is no problem in this respect, I think that the procedure introduced by the article is open to debate. For the right to request the rectification of personal data which the Law confers on the data subject may be exercised by means of an application to be made to the controller. The article in question, however, provides for a route whereby application is to be made to the provincial directorate of health.
In this situation, which route will apply? In my view, the data subject’s application to the controller is an avenue of application which is regulated comprehensively by the Law, which admits of no doubt and which cannot be disregarded by means of another legal instrument. For this reason it is not possible to say that this right has been abolished by the relevant article of the Regulation. In such a situation it can only be said that an alternative route has been introduced with regard to health data. Accordingly, I think that, where the data subject addresses the request for the rectification of his or her health data to the controller, it would be unlawful for the request to be refused on the basis of this article. At the same time, an application made to the provincial directorate of health must also be accepted.
In this situation too, however, the fact that a procedure not envisaged by the Law has been introduced and regulated for the first time by a provision of a regulation ought to be debated. Had this right been reserved by the Law and had such a procedure then been regulated by a provision of a regulation, there would have been no problem. As matters stand, however, I think that the provision is in need of clarification.
Lastly, the fact that the article has been framed in relation to health data kept “inadvertently” raises the question whether data which were kept accurately and subsequently ceased to be up to date will also fall within this scope. For keeping personal data accurate also requires keeping them up to date. The article must therefore be clarified in this respect as well.
c. Disposal of personal health data
The disposal of personal health data has been made subject to Article 7 of the Law and to the provisions of the Authority’s “Regulation on the Erasure, Destruction or Anonymisation of Personal Data”, published in Official Gazette No. 30224 of 28.10.2017.
d. Transfer of personal health data
For both domestic and cross-border transfer activities, reference has first of all been made to the provisions of the Law.
For the transfer of personal health data to public institutions and bodies, on the other hand, a protocol to this effect must be drawn up. This protocol must contain the general principles of data protection legislation and the provisions on data security, and must specify which data are to be transferred. Where the technical infrastructure is suitable, the transfer will be made over KamuNET.
It has also been laid down that requests concerning transfer will be assessed by the unit of the Ministry.
7. Chapter Five of the Regulation, entitled “Processing for Scientific Purposes and Open Health Data” (Articles 16, 17)
a. Processing for scientific purposes
The article finds its basis in Article 28 of the Law, which governs the cases of full exemption. According to this, scientific work may be carried out within this scope with data that have been anonymised. Again within the scope of the same article, personal health data may be processed for scientific purposes in line with the measures to be taken, provided that this does not violate the privacy or personality rights of the data subjects and does not constitute an offence.
b. Open health data
Article 17 of the Regulation lays down the circumstances in which open health data may be at issue. According to this, for there to be open health data:
• The data must be contained in the systems used, by the General Directorate, in the central and provincial organisation of the Ministry and in its affiliated and related bodies.
• In order for data to be open health data, the rules on data privacy and data security must be taken into consideration.
• The purpose must be limited to ensuring transparency and accountability in the health system, giving direction to policies and strategies on the provision of healthcare, supporting scientific research to be carried out in the field of health, and enabling the development of health-related products and services.
• Where the conditions mentioned are met, data made accessible to everyone over the website constitute open health data, and the procedures and principles in this regard are likewise determined by the Ministry.
8. Chapter Six of the Regulation, entitled “Data Security” (Articles 18 - 20)
a. Obligations relating to data security
No new rule has been introduced on ensuring the security of personal health data; for ensuring this security, reference has been made to Article 12 of the Law and to the Personal Data Security Guide prepared by the Authority.
With regard also to the notification to be made to the Board by the controller where there is a breach or a security vulnerability relating to the protection of personal data, the provisions of the Law and the Board’s rules will again be taken as the basis.
b. Information security
The information security processes carried out by the relevant bodies are determined by the Information Security Policies Directive prepared by the Ministry of Health. The date on which the said Directive was last updated is 2 May 2018; it needs to be updated in line with developing technology.
c. Adequate measures
As regards the adequate measures to be taken in the processing of personal health data, reference has been made, in a manner consistent with the relevant legislation, to Article 6 of the Law and to the Board’s decision No. 2018/10 of 31.01.2018 on “the Adequate Measures to be Taken by Controllers in the Processing of Special Categories of Personal Data”.
9. Sanction
With regard to offences and misdemeanours relating to the personal data protected by the Regulation, liability under Articles 17 and 18 of the Law continues to apply.
For public officials who fail to comply with the requirements of the Regulation, the provisions on disciplinary investigation laid down within the framework of administrative law are applied. In that case the question may come to mind as to what kind of sanction will be applied to health sector employees who are not public officials. For health sector employees who are not public officials, the sanctions and the disciplinary procedure to be applied where personal health data are not protected in conformity with Law No. 6698 and this Regulation need to be determined and communicated by means of an internal policy by healthcare institutions which have the status of legal persons governed by private law.
The article in question also provides for a sanction procedure in respect of healthcare providers which do not send data to the central health data system in accordance with the procedures and principles determined by the Ministry. The sanction to be applied in this context is imposed in accordance with Additional Article 11, paragraph 3, of the Basic Law on Health Services No. 3359. According to this, health institutions and bodies which act in breach of the obligations to send data to the central health data system are warned twice, and an administrative fine amounting to one per cent of the gross service revenue of the preceding month is imposed on those which do not comply with the warning. In addition, the sanctions to be applied if this breach continues or is repeated are set out in the remainder of the article.
The question that will come to mind here is which provisions will apply where a violation falls within the scope of both Law No. 6698 and the Basic Law on Health Services. In such a situation, if, depending on the circumstances of the concrete case, different parts of the incident amount to a violation both of the Law and of Law No. 3359, there is no problem; the two Laws are each applied separately. If, however, the incident cannot be separated into parts and a violation of both Laws is at issue, which provisions are to be applied is open to debate. In my opinion, in such a situation the heaviest administrative fine is applied in accordance with Article 15, paragraph 1, of the Misdemeanours Law. However, the different administrative sanctions other than a fine which Law No. 3359 envisages will be applied where the violation continues or is repeated must be applied in any event.
Conclusion
The Regulation under assessment has been assessed above with reference to each individual article. Although, in order to avoid repetition, I shall not go into the articles one by one here, a general conclusion on the Regulation must be reached.
First and foremost, I hope that the issue of the legal framework to be applied in the processing of personal health data, which has long been contentious, will be resolved by the Regulation in question. Having regard to the assessments made above, I can say that the Regulation is capable of meeting this need, first because it is consistent with the relevant legislation and secondly because it contains more specific and detailed provisions than its previous version.
From the standpoint of method, however, I must also state that I do not regard as lawful the hasty issuing of this Regulation at a time when there were two separate decisions of the Council of State staying the execution of the previous Regulation and when the merits of the case had not yet been addressed. It would have been more consistent with the principle of the rule of law if the issuing of this Regulation had been left until after the reasoned decision to be given by the Council of State and if the points contained in that decision had been taken into consideration.
I confine myself, moreover, to recalling my criticisms concerning the articles which I stated above to be in need of clarification.
Footnotes
- Academic/Attorney-at-law. ↑
- 15 D., 2016/10488, 2016/10500 YD. T. 06.07.2017. ↑
- For an article assessing the Regulation see: Murat Volkan Dülger, “Kişisel Sağlık Verilerinin İşlenmesi ve Mahremiyetinin Sağlanması Hakkında Yönetmelikte Değişiklik Yapılmasına Dair Yönetmelik’in Getirdikleri ve Dikkat Edilmesi Gereken Hususlar”; www.academia.edu.tr. ↑
- 15 D., 2018/1490, YD T. 09.10.2018. ↑
- For an article assessing the decision of the Council of State see: Murat Volkan Dülger, “Kişisel Sağlık Verileri Yönetmeliğinin Yürütmesinin Durdurulmasına İlişkin Danıştay’ın 9.10.2018 Tarihli Kararına İlişkin Değerlendirme”; www.academia.edu.tr. ↑
- This article of the Regulation has been heavily criticised, and the Istanbul Bar Association has brought an action for its annulment. ↑
Related publications
Dülger, Murat Volkan / Gümüş, Gülçin, Personal Data Protection Law (Kişisel Verilerin Korunması Hukuku), 4th ed., Seçkin Publishing, Ankara, 2026.
Dülger, Murat Volkan, Legislation on Information Technology, Personal Data Protection and Internet Communication (Bilişim, Kişisel Verilerin Korunması ve İnternet İletişimi Mevzuatı), 7th ed., Seçkin Publishing, Ankara, 2021.
Dülger, Murat Volkan, “The Use of Bulk Data and Metadata in Preventive Policing and Intelligence Work from the Standpoint of Human Rights, Personal Data Protection and Criminal Procedure Law” (İnsan Hakları, Kişisel Verilerin Korunması ve Ceza Muhakemesi Hukuku Açısından Önleyici Kolluk Hizmetleri ve İstihbari Çalışmalarda Toplu Veri ve Metadata Kullanımı), conference presentation, 2026.
Dülger, Murat Volkan, “Lawyers' Obligations under the KVKK in the Light of the Board's Decisions” (Kurul Kararları Işığında Avukatların KVKK Yükümlülükleri), conference presentation, 2025.
Dülger, Murat Volkan / Gümüş, Gülçin, “The Right to Be Forgotten”, Essays in Honour of Prof. Dr. Yadigar İzmirli (Prof. Dr. Yadigar İzmirli'ye Armağan), 2024.
