15 April 2020Murat Volkan Dülger, Yavuz Selim DicleCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

This article will examine, with examples, the problems that have arisen with the Covid-19 outbreak in connection with the processing of personal health data by employers acting as data controllers, together with the problems that have arisen in the processing of personal health data since the date on which the Law entered into force. In this connection, it will also include a number of our comments, intended as a contribution to and a deepening of the debate on the article written by Assoc. Prof. Dr. Mesut Serdar Çekin on 6 April 2020 under the title “We Could Not Save the Life of the Deceased, but at Least We Protected His Personal Health Data!!! An Assessment of the KVKK Provisions on the Processing of Personal Health Data in the Face of the Covid-19 Pandemic in the Context of Employment Relations” (“Rahmetlinin Hayatını Kurtaramadık Ama En Azından Kişisel Sağlık Verilerini Koruduk!!! Covid-19 Pandemisi Karşısında Kişisel Sağlık Verilerinin İşlenmesine Dair KVKK Hükümlerinin İş İlişkileri Kapsamında Değerlendirilmesi”).

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

Murat Volkan Dülger* / Yavuz Selim Dicle*

SCOPE

This paper addresses, with examples, the problems that have arisen from the processing of personal health data by employers acting as controllers, a matter brought onto the agenda by the Covid-19 pandemic, together with the problems that have arisen in connection with the processing of personal health data since the date on which the Law entered into force.

In this vein, the paper will also contain a number of comments of ours, offered as a contribution to the article written by Assoc. Prof. Dr. Mesut Serdar Çekin on 6 April 2020 under the title “We Could Not Save the Life of the Deceased, but at Least We Protected His Personal Health Data!!! An Assessment, in the Context of Employment Relationships, of the KVKK Provisions on the Processing of Personal Health Data in the Face of the Covid-19 Pandemic” and with a view to deepening the debate1.

1. THE PROBLEM OF THE PROCESSING OF PERSONAL HEALTH DATA

As is well known, personal health data are regulated in Article 6(3) of Law No. 6698 on the Protection of Personal Data (KVKK) in the following terms: “Personal data relating to health and sexual life, however, may be processed without seeking the explicit consent of the data subject only by persons under an obligation of confidentiality or by authorised institutions and organisations, for the purposes of protecting public health, carrying out preventive medicine, medical diagnosis, treatment and care services, and planning and managing health services and their financing.” Accordingly, it is clear that personal health data cannot be processed even on the legal ground of being “expressly provided for by laws”, and that they may be processed only and exclusively for the reasons specified in the text of the Law and by persons under an obligation of confidentiality.

In the context of the Covid-19 pandemic, employers have certain obligations to fulfil. In order to prevent the Covid-19 pandemic and to protect public health, employers process a number of personal data such as “the state of health of persons, whether they have a chronic illness, their body temperature, when they last travelled abroad, whether they have been in contact with someone who has travelled abroad, whether they have visited a region affected by the virus, and the details of persons at risk of carrying the disease with whom they have interacted” . Employers thus process certain health data of persons, or information through which they can arrive at health data.

What obligations, then, will arise for employers under Law No. 6698 when they process this information? Personal data must be processed in line with the announcement made by the Personal Data Protection Authority under the title “What Needs to Be Known under the Law on the Protection of Personal Data in the Course of the Fight against Covid-19”, which Dr Çekin has also explained in detail in his article. Accordingly, where controller employers have the health data processed by the workplace physician, who is under an obligation of confidentiality within the meaning of Article 6(3) of Law No. 6698, or by other health personnel to be authorised by the workplace physician (a nurse, health officer, emergency medical technician or environmental health technician), personal health data may be processed without explicit consent being obtained2.

When the current situation in our country is assessed, it is a known fact that many employers do not employ a full-time workplace physician and that some are under no obligation to employ a workplace physician at all. Moreover, even where a workplace physician is employed, in undertakings with thousands of employees it is not feasible for these examinations to be carried out by one or a few workplace physicians. Consequently, the most reasonable method for processing personal data in the context of the Covid-19 pandemic appears to be to obtain the explicit consent of the persons concerned. However, explicit consent is not as sound a method as is thought either. As is well known, explicit consent must be obtained on the basis of free will. First and foremost, it is a matter of debate whether the explicit consents that employers obtain from their employees are given of their own free will, and whether these consents are valid. What is more, individuals are not only free to give explicit consent but also have the right to withdraw their explicit consent whenever they wish. In that case, will the health data of individuals who do not give explicit consent, or who withdraw their explicit consent, not be processed?

The answer to this question has to be “no”; we must also state that in the present situation of a pandemic the answer ought to be no. For in our view the right to life of persons takes precedence over the right of individuals to the protection of their personal data. In this situation an interpretation to this effect is required in order to protect the right to life of the indeterminate number of persons who make up society. However, this solution is contrary to the positive regulation of Law No. 6698. It is at this very point that Çekin has proposed the method of “restrictive interpretation”. Yet its applicability with regard to legal persons governed by private law remains open to debate (let us state, however, that this kind of method of interpretation is what ought to be applied). And it would be overly optimistic to expect the Board, in a complaint, or a court, in a concrete dispute, to decide by using this method of interpretation. Consequently, as regards the processing of personal data on the basis of explicit consent, there are very serious doubts as to whether the explicit consents obtained from the persons concerned are given of their own free will.

2. THE IDENTIFICATION OF PERSONAL HEALTH DATA AND THEIR PROCESSING UNDER THE LAW

Determining the nature of personal data is one of the problems we encounter most frequently in practice. Accordingly, it must first of all be established which data are personal data and which data are personal health data.

Since our subject is the processing of health data, it will be more appropriate for us to make an assessment specific to health data. In this context, information such as “information on medical diagnosis and treatment, information on medication used, information on prostheses used” is regarded directly and without hesitation as health data, whereas it may be a matter of debate whether information such as “information on alcohol and tobacco use, information on employment status, information on accidents suffered, information on journeys made, location information” is health data.

As the Article 29 Working Party has also stated in its opinions, and as we too do because it makes application easier, when the categories of personal data are determined the purposes of use must be taken into account3. We are of the view that, when personal data are processed, account must be taken of the purpose for which the personal data are collected and of which personal data it is intended to obtain when they are brought together.

In this vein, a useful assessment has been made with regard to “information on alcohol and tobacco use”. It has been stated that, if the information on alcohol and tobacco use is processed for the purpose of making an assessment of the state of health, it will fall within the category of “health information”, but that, where the purpose is not to make an assessment of the state of health, it will not be health data4. In short, if information on alcohol and tobacco use is being assessed in the context of a medical condition, this information must be accepted as “health data”. If, however, “information on alcohol and tobacco use” is requested at the recruitment stage in connection with the employment of a driver, then the information on alcohol use will not fall within the category of health information.

If the situation is assessed specifically with regard to Covid-19, there will be no hesitation in regarding information obtained directly by “taking the person's temperature, asking about his or her chronic illnesses” as personal health data. But will information such as “when the person last travelled abroad, whether he or she has been in contact with someone who has travelled abroad, whether he or she has visited a region affected by the virus” be regarded as health data? Our interpretation here is that, because the information in question is processed for the purpose of detecting the Covid-19 disease, it will be personal health data.

Moreover, if we are to cross-check this conclusion, let us suppose that we process personal data such as “taking the person's temperature, asking about his or her chronic illnesses” as health information on the legal ground of explicit consent, and that we process a person's personal data such as “when he or she last travelled abroad, whether he or she has been in contact with someone who has travelled abroad, whether he or she has visited a region affected by the virus” on the basis of one or more of the legal grounds in Article 5 of the Law. On this hypothesis, where the person withdraws his or her explicit consent, it will be systematically possible to destroy the data processed on the basis of explicit consent while continuing to process the person's other personal data, which are not processed on the basis of explicit consent. In that case, however, the possibility of arriving at the likelihood that the person has Covid-19, that is, of arriving at health data, will still not have been removed.

It can therefore be seen that these personal data processed on account of the Covid-19 pandemic also fall within the category of “health information”.

If we are to make an assessment outside the context of Covid-19: where, as we frequently encounter in practice and as we recommend, the health data are processed by the workplace physician and the latter shares with the human resources department his or her opinions on working conditions that do not contain health data, we consider that opinions in the form “can/cannot work at height, can/cannot wear a protective mask, there is no obstacle to his or her working, is on sick leave” will not fall within the category of health data. When, as we have explained in detail above, a purposive interpretation is made, the purpose here is not to arrive at health data but for the employer to minimise the risks of persons who present a risk, or to identify employees who are on sick leave so as to make the statutory notifications and, where required, not to pay wages for the days of sick leave. Even though the information that the person has not come to work, or the information that he or she has obtained a medical report, has been acquired, the information as to which illness the persons have suffered or for which health reason they have not come to work is not processed. Exceptional situations may arise, albeit to a limited extent; but it is also a fact that in such situations health data cannot be arrived at by bringing the items of information together5.

In conclusion, the interpretations made must be made by taking into account the purpose sought to be achieved by the data processing, and preference should be given to interpreting these purposes narrowly. Otherwise it would be possible to argue that health information is processed by means of the photograph of a person wearing glasses, that biometric data are processed in handwritten signatures, or that information such as political opinion, philosophical belief or religion can be arrived at from persons' names. In this context, the true situation can be brought to light only when the purpose for which these personal data are processed is taken into account.

3. THE PROBLEM OF THE PROCESSING OF HEALTH DATA BELONGING TO THIRD PARTIES

In some cases the information obtained in the context of the Covid-19 pandemic may also constitute personal data of third parties other than the employees. In this case we recommend, first of all, that in line with the principle of processing that is limited to the purpose and proportionate, personal data belonging to third parties should not be processed unless this is necessary.

However, because Covid-19 is a disease of an epidemic nature, the details of third parties who are part of persons' private lives are also important for the taking of measures. In this context, in order that certain measures may be taken in respect of a person whose relative living in the same household has contracted Covid-19, it may be necessary for the employer to obtain this information. In that case, if it is not possible to process the personal data anonymously, a situation may also arise in which health data belonging to third parties are processed. Consequently, the obligation to inform these persons or to obtain the explicit consent of these persons will again rest on the employer. However, for the reasons explained above, it is extremely difficult in the current situation for controller employers to fulfil the obligation to obtain explicit consent from these persons or to inform them.

4. SOME EXAMPLES OF OTHER PROBLEMS IN CONNECTION WITH THE PROCESSING OF PERSONAL HEALTH DATA

Although it has become more conspicuous on account of the Covid-19 pandemic, the processing of personal health data involves problems in many respects, and the inadequacy of the existing statutory regulation and its failure to meet needs force controllers into unlawful methods of data processing where personal health data are concerned. We would like to explain this situation by means of an example.

As you know, Article 24 of the Labour Law No. 4857 grants the employee, and Article 25 the employer, the possibility of terminating the employment contract for just cause on health grounds. Let us suppose that in a given case the employee's employment contract has been terminated on health grounds and that the employee has brought an action on that basis. Let us also assume that the employer receives legal services from a law office. As our fellow attorneys know very well, in such a situation, in order for a statement of defence to be written or an action to be brought, the health information of the opposing party will have to be processed by the attorney and even submitted to the court.

When we assess this example under the Law on the Protection of Personal Data, even though attorneys are considered to be under an obligation of confidentiality under the Attorneys' Act No. 1136, it is clear that the personal data are not processed by attorneys “for the purposes of protecting public health, carrying out preventive medicine, medical diagnosis, treatment and care services, and planning and managing health services and their financing” . It is also a fact that attorneys do not come within the exception in sub-paragraph “d” of paragraph 1 of Article 28 of the Law: “d) The processing of personal data by judicial authorities or execution authorities in connection with investigation, prosecution, trial or execution proceedings.” For although attorneys are counted, under Art. 6(1)(d) of the Turkish Criminal Code (TCK), among the persons “performing a judicial function”, they do not have the status of a “judicial authority”, that is, of a “judge”. Consequently, only one way remains: to obtain the explicit consent of the opposing party (the claimant or the defendant, as the case may be) whose health data are being processed. Theoretical debates aside, these data may be transferred and processed on the basis of explicit consents that have been duly obtained from employees. However, where an employee who is aware of the matter withdraws his or her explicit consent or gives no explicit consent at all, the processing of these personal data by attorneys will become contrary to the Law. And under the provisions of both the Code of Criminal Procedure (CMK) and the Code of Civil Procedure (HMK), it is not possible for evidence that is contrary to the Law, and therefore unlawful, to be used as a means of proof in proceedings. For instance, pursuant to Art. 289 of the CMK, the use of unlawfully obtained evidence of this kind is an absolute ground for reversal at both the stage of appeal on facts and law and the stage of appeal on points of law.

To give another example, under Article 30 of the Labour Law No. 4857 some workplaces are under an obligation to employ a certain proportion of staff with disabilities. Accordingly, the notifications and queries concerning staff with disabilities are carried out through the systems of the Social Security Institution (SGK). The data processing activity in question may be carried out on the basis of the legal ground of being “expressly provided for by laws”. However, information on disability, which falls within the category of health information, may under Law No. 6698 on the Protection of Personal Data be processed without explicit consent only in accordance with paragraph 3 of Article 6. Consequently, where the employee with a disability withdraws his or her explicit consent or gives no explicit consent at all, the controller employer will be unable to fulfil its statutory obligation and will be unable to process the information on disability. In this situation the controller will be crushed between two different statutory regulations and will in any event have acted contrary to the laws and unlawfully.

5. PROPOSAL FOR A PARTIAL SOLUTION

Under the existing statutory regulation, as regards the personal data processed on account of the Covid-19 pandemic, it will, as discussed in detail above, be sufficient merely to provide the information where the personal data are processed by workplace physicians, who are under an obligation of confidentiality, or by other health personnel whom they authorise. If this is not possible, however, there is no solution other than to obtain explicit consent from the persons concerned, however debatable this may be.

Accordingly, we are of the opinion that a separate information notice and explicit consent text specific to this subject has to be drawn up, taking into account the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform published by the Personal Data Protection Authority. Consequently, owing to this plain and flawed provision of the Law, it is in fact not possible to devise a solution in this matter.

6. PROPOSALS FOR A FUNDAMENTAL SOLUTION

The explanations given show that the existing regulation on the processing of personal health data compels controllers to process data contrary to the Law, or forces them to collect explicit consents that are not given of the person's own free will, which is likewise contrary to the Law.

In this vein, specifically with regard to Covid-19, the scope of the exceptions in Article 28 of the Law could be widened and it could be provided, in a manner that also encompasses employers, that personal data may be processed for the purpose of “protecting public health”. However, such a provision would solve only the problems arising in the context of the Covid- 19 pandemic and would produce no solution for the many objectionable situations such as those given as examples above.

We are of the opinion that the most effective solution can be achieved by means of an amendment to be made to the Law on the Protection of Personal Data. Ensuring, as was the case when the Law was still a draft, that data relating to health and sexual life may also be processed on the legal ground of being “expressly provided for by laws” would provide a solution in many respects. Yet amendments made to the Law on the Protection of Personal Data alone would not be sufficient either. In the example we gave above concerning the processing of health data, there would be no question of personal health data being processed by attorneys on the legal ground of being “expressly provided for by laws”. Since, in the context indicated, the personal data would be processed under sub-paragraph “e” of paragraph 2 of Article 5 of Law No. 6698, on the legal ground that “data processing is necessary for the establishment, exercise or protection of a right”, the need would also arise for a special statutory provision specific to this matter so that health data may be processed as being “expressly provided for by laws”. Consequently, the other laws will have to be brought into line with the Law on the Protection of Personal Data, which has the character of a general law.

7. THE PROCESSING OF LOCATION DATA IN THE CONTEXT OF THE COVID- 19 PANDEMIC

In its public announcement published on 9 April 2020 under the title “What Needs to Be Known about the Processing of Location Data and the Monitoring of the Mobility of Persons in the Fight against Covid-19”, the Personal Data Protection Authority stated, in summary, that in order to prevent the spread of the coronavirus pandemic throughout the world, personal data of the persons concerned, such as health, location and contact information, may be processed by means of various mobile applications and similar methods for purposes such as identifying those who have been in contact with persons who carry this disease or are at risk of carrying it, mapping the spread of the virus and applying treatment and quarantine, monitoring those placed in quarantine, enforcing the curfew, and identifying crowded places.

In this vein it was announced that, in line with the exception in sub-paragraph “ç” of paragraph 1 of Article 28 of Law No. 6698, namely “the processing of personal data within the scope of preventive, protective and intelligence activities carried out by public institutions and organisations that have been assigned duties and powers by law for the purpose of ensuring national defence, national security, public security, public order or economic security”, Law No. 6698 on the Protection of Personal Data (KVKK) will not apply to the data processing activities to be carried out by the competent public institutions and organisations, in situations which, like an epidemic disease, threaten public order and public security and with the aim of eliminating that threat, in order to ensure the isolation of persons (diagnosed with the epidemic disease) during the period in which they remain contagious, to identify crowded areas by processing the location data of the general population, and to develop measures in this context. The Board announced that location data, too, may be processed in line with the said exception provision for the purpose of preventing the pandemic.

At the same time the Board emphasised that, even though an exceptional situation exists with regard to the processing of personal data, the institutions and organisations concerned must safeguard the security of personal data, and that the personal data in question have to be erased or destroyed once the reasons that require the processing of these data cease to exist.

A. Personal data may be processed only by public institutions and organisations and for the stated purposes

For sub-paragraph “ç” of paragraph 1 of Article 28 of the Law to be applicable, three different conditions must be met together. These are:

• that the personal data are processed for the purpose of ensuring national defence, national security, public security, public order or economic security,

• that the personal data are processed by public institutions and organisations that have been assigned duties and powers by law,

• that the personal data are processed within the scope of preventive, protective and intelligence activities.

When the text of the announcement is examined, it is first of all stated that personal data falling within the categories of “health, contact and location information” may be processed for the purposes of preventing the spread of the pandemic, protecting public health and thereby ensuring public security. In this respect the Board's view is well founded. In addition, it must not be forgotten that the exception provision of the Law can be relied on where the data processing activity in question is carried out by public institutions and organisations that have been assigned duties and powers by law and within the scope of preventive and protective activities.

It is therefore clear that the statutory exceptions cannot be relied on in cases other than that in which the personal data are processed solely by institutions or organisations that have public legal personality and have been assigned duties or powers by laws. Accordingly, controllers that do not have the character of a public institution or organisation will not be able to benefit from the exception in Article 28 of the Law, even if they process data for the stated purposes.

B. At the stages of obtaining, analysing and transferring personal data, it must be ensured that the personal data are processed anonymously as far as third parties are concerned

Having regard to practices around the world and to the approach in our country, it is thought that the data of persons who are ill or carry a risk of illness can be obtained from companies that are legal persons governed by private law. First of all, at the stage of obtaining the personal data in question, care must be taken to ensure that the personal data are obtained in anonymous form, and it must be ensured that private-law legal persons do not gain access, even indirectly, to persons' health or epidemic-risk information. To this end, preference should be given to obtaining personal data in bulk or to another method that ensures the provision of anonymous data.

It is also thought that analyses relating to persons who carry a risk or have been placed in quarantine will have to be carried out by means of the system to be applied. Since these analyses will be carried out on the basis of individual persons, a personal data processing activity will be involved. These personal data, too, must be processed by the public institutions or organisations themselves.

In addition, it is stated that the data subjects will be contacted where necessary, and that messages may be sent to these persons or they may be called by telephone. Accordingly, the personal data of the persons contacted must not be processed by the private-law legal persons concerned. To this end, preference should be given to methods whereby personal data in the category of “identity, contact and location information” are not shared with third parties that do not have public legal personality, or are shared anonymously.

In sum, at every stage of the data processing activities it must not be forgotten that the exception in the Law applies only to the data processing activities of public institutions and organisations, and that third parties outside the sphere of public legal personality cannot benefit from the exception provisions of the Law if they process personal data. Accordingly, third parties that do not have public legal personality should not process the personal data in question or, if they are to process them, should process them anonymously.

C. Determining the nature of the personal data and the measures to be taken

When the purpose of the personal data processing is taken into account, it is understood that personal data in the category of “contact and location information” are processed in order to prevent the pandemic and to identify probable patients. The purpose of processing personal data in the category of “contact and location information” that are processed in order to identify probable patients is to obtain health data. It must therefore not be forgotten that the personal data in question may be assessed as falling within the category of “health information”.

Where the personal data are processed in order to prevent the pandemic, on the other hand, other personal data belonging to a person whose health information has already been obtained will have been processed. In this case, even if the purpose of processing the other personal data is not to obtain health data, the processing of health data will again be at issue, since the data processed belong to persons who are ill or carry a risk of illness . In conclusion, it is thought that the processing of personal health data is probable in both cases. Consequently, third parties that cannot benefit from the exception with regard to the processing of personal data must take the necessary technical and administrative measures in line with the decision of the Personal Data Protection Board of 31/01/2018 No. 2018/10 entitled “Adequate Measures to Be Taken by Controllers in the Processing of Special Categories of Personal Data”.

D. The need for personal data to be processed also by parties that do not have public legal personality

Having regard to the explanations we have given above, although it is necessary to have public legal personality in order to be exempt from the Law, situations may arise in which a public legal person, in order to carry out its activities, shares personal data with third parties or procures data or services from third parties. In such situations, however, private-law legal persons will not be able to benefit from the exception in the Law. It is also thought that legal persons governed by public law are not in a position to carry out all activities within their own organisation. Consequently, when legal persons governed by public law come to need support for the purpose of preventing the pandemic, it will be possible for them to obtain this support from third parties that do not have public legal personality only if the personal data are processed anonymously. We are of the opinion that it will not be possible to ensure this in every case.

Where parties that do not have legal personality under public law process the personal data, on the other hand, they will have to process personal health data, and obligations such as that of obtaining explicit consent from the persons concerned will therefore arise for them. This in turn will mean that the intended aim is not achieved, will constitute an obstacle to the measures that have to be taken, or will make the processes more difficult.

E. The need to widen the scope of the Law

That the measures referred to must be taken on account of Covid-19 is an indisputable necessity. The practices in question are carried out first and foremost for the health and protection of each of us as individuals. The fact that the Law confers the power to process data for the purpose of ensuring public security on legal persons governed by public law alone brings to light, at this point, a different reflection of the problem that exists with regard to employers. Thus the fact that the provisions of Law No. 6698 on the Protection of Personal Data that govern the exceptions offer an exemption limited solely to legal persons governed by public law brings a number of problems with it.

For this reason the provision has to be framed in such a way that, where personal data are processed for the purposes of protecting public health and ensuring public security, third parties commissioned by bodies that have legal personality under public law also benefit from the exception in Article 28 of the Law.

While this would be capable of solving the problems arising in the context of Covid-19, we consider that a more comprehensive revision, taking the provisions of the GDPR into account, also has to be carried out for the other problematic data processing activities mentioned above.

F. Problems that may be caused by the processing of data on the basis of the GSM number

It may also be said that tracking persons' location information on the basis of their GSM numbers may give rise to certain problems in practice. As explained in detail above, the personal data of the persons concerned must be processed only by public institutions and organisations and only for the purpose of preventing the pandemic.

As is well known, in our country there are situations such as GSM lines that are active but not in use and several GSM lines being registered in the name of one person. In that case, if location tracking is to be carried out on the basis of the GSM line, it must be confirmed that the persons who present a risk or have the disease actually use that line. Otherwise, not only will the result expected for the prevention of the pandemic not be achieved, because personal data belonging to the wrong persons are processed, but also, because the data of third parties other than the person concerned are processed, it will not be possible to rely on the exception provision of the Law and a data processing activity contrary to the Law will be at issue. It is therefore important that the technical and administrative measures necessary for the persons concerned to be correctly identified are taken.

CONCLUSION

Personal health data may be processed only under paragraph 3 of Article 6 of the Law and, in order to be processed without explicit consent, must be processed by persons under an obligation of confidentiality. When present conditions are assessed, controllers with hundreds or even thousands of employees are not in a position to have personal health data processed through a workplace physician or other health personnel. For this reason controller employers are compelled to obtain explicit consent in order to process the personal data.

It would not be correct to say that the explicit consents obtained in this context are given of the person's own free will. What is more, the processing of these personal data is absolutely necessary in order to prevent the pandemic. Consequently, where personal health data are processed on the basis of explicit consent, the element of being given of one's own free will, which is one of the minimum elements of explicit consent, will be vitiated.

When the categories of personal data are determined, the focus must be on the purpose sought to be achieved, and the data category must be determined in line with this purpose. If personal data are processed in order to reach persons who have the Covid-19 disease or are at risk of the disease, it must not be overlooked that the personal data processed in that case may be “health information”. When a purposive interpretation is made, however, the interpretation should as far as possible be a narrow one, limited to the purpose, and the data categories should be determined in this way.

In the context of the pandemic, the processing of personal data belonging to third parties with whom persons who are at risk or have contracted the disease have been in contact may also be at issue. Where health information belonging to third parties is processed, the obligation to obtain explicit consent will arise in respect of the third parties as well, and this obligation will rest on the controller employer. Since it is not possible to process the personal data by obtaining explicit consent from the third parties, controller employers will, on this hypothesis too, find themselves processing data unlawfully.

Although the issue of the processing of personal health data has come to light on account of the Covid-19 pandemic, a number of problems arise with regard to the processing of health data owing to the narrow scope of the Law. Accordingly, the amendment of the Law must be made with a wider scope in mind, and solutions must be devised after the situations in which controllers are forced to process personal data contrary to the Law have been correctly identified. In the solutions to be devised the provisions of the GDPR must without fail also be taken into account.

Under the existing statutory regulation, with regard to the personal data processed on account of Covid-19, explicit consent should be obtained from employees for the processing of personal health data, even though there are debates about free will; and, if there are employees who do not give explicit consent, it should be ensured that the workplace physician and other health personnel, who are under an obligation of confidentiality, merely provide the information to these persons without obtaining explicit consent from them. Although this is not a method that complies fully with the Law, we are of the opinion that it is the most appropriate solution.

In the context of the Covid-19 pandemic it has been stated that certain personal data may be processed for the purpose of preventing the pandemic and that preventive and protective measures will be taken by analysing these personal data. The Board has also announced that the personal data may benefit from the exception provisions pursuant to sub-paragraph “ç” of paragraph 1 of Article 28 of the Law. However, these exception provisions will come into play only where the personal data are processed by institutions and organisations that have public legal personality. For this reason it must not be forgotten that third parties that do not have public legal personality cannot benefit from the statutory exception.

When the data processing activities are carried out, it must be ensured that these third parties do not process the personal data or process them anonymously. This, however, may not be possible in every case. On that hypothesis, when account is also taken of the fact that the personal data processed by third parties contain “health information”, it is thought that they will be subject to onerous statutory obligations (explicit consent etc.) and that they will not be in a position to fulfil these obligations. This will result in the unlawful processing of personal data.

Even though parties that have legal personality under public law may benefit from the statutory exception, the need to take the necessary technical and administrative measures in respect of the personal data processed must not be overlooked either. Only the necessary and sufficient data belonging to persons who are at risk of infection or have the disease should be processed. Furthermore, taking into account that the personal data are processed for the purpose of preventing the pandemic, the destruction of the personal data should be considered when the pandemic comes to an end or the persons concerned recover, and the personal data should be destroyed immediately once the purpose of the processing ceases to exist.

Where location information is established on the basis of GSM numbers, it must be correctly established which GSM number the persons concerned use. That these findings are made correctly is an important element for the personal data to be processed within the scope of the statutory exception. The necessary technical and administrative measures must be taken in this regard. Otherwise, since personal data would be processed disproportionately and contrary to the purpose of the Law, the exception provisions would have to remain inapplicable.

For a lasting solution to be created, however, the Law must without fail be amended. In particular, with regard to the processing of health data, the widening of the conditions for processing is an absolute necessity. Accordingly, both, in order to solve the problems arising in the context of the Covid-19 pandemic, the provision must be framed in such a way that, where personal data are processed for the purposes of protecting public health and ensuring public security, third parties commissioned by bodies that have legal personality under public law also benefit from the exception in Article 28 of the Law; and the existing legal grounds for the processing of personal health data must be reframed with regard also being had to the provisions of the GDPR and to sectoral needs.

Footnotes

  1. Assoc. Prof. Dr., member of the teaching staff of the Department of Criminal Law, Criminal Procedure Law and IT Law, Faculty of Law, Istanbul Aydın University; Attorney-at-law, Istanbul Bar Association, [email protected]. ↑
  2. Attorney-at-law, Istanbul Bar Association, [email protected]. ↑
  3. In fact, we decided to write this article on the basis of the ideas that emerged while we were discussing the article in question. Much as in Karl Marx's works “A Contribution to the Critique of Political Economy” and “The Poverty of Philosophy”, this article came into being in the course of the questions that occurred to us about another work and the search for solutions. We take this opportunity to thank our esteemed colleague Assoc. Prof. Dr. Mesut Serdar Çekin, who occasioned these questions and this article. ↑
  4. Mesut Serdar Çekin, Rahmetlinin Hayatını Kurtaramadık Ama En Azından Kişisel Sağlık Verilerini Koruduk!!! Covid-19 Pandemisi Karşısında Kişisel Sağlık Verilerinin İşlenmesine Dair KVKK Hükümlerinin İş İlişkileri Kapsamında Değerlendirilmesi, https://blog.lexpera.com.tr/covid-19-pandemisi-karsisinda-kisisel-saglik-verilerinin-islenmesine-dair-is-iliskileri-kapsaminda-degerlendirme/, Erişim Tarihi: 07.04. 2020. ↑
  5. Murat Volkan Dülger, Kişisel Verilerin Korunması Hukuku, 2. Baskı, Hukuk Akademisi, İstanbul, 2019, s. 110. ↑
  6. https://www.hldataprotection.com/2015/10/articles/health-privacy-hipaa/mobile-health-in-the-eu-part- 2-personal-data-and-sensitive-information-in-mhealth-businesses/, Erişim Tarihi: 07. 04. 2020. ↑
  7. Çekin, https://blog.lexpera.com.tr/covid-19-pandemisi-karsisinda-kisisel-saglik-verilerinin-islenmesine-dair-is-iliskileri-kapsaminda-degerlendirme/, Erişim Tarihi: 07.04. 2020. ↑

Download PDF (in Turkish)

Related publications