5 October 2020Murat Volkan DülgerCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

The transfer of personal data from Türkiye to a foreign country is becoming a bigger problem by the day. Indeed, as matters stand, a lawful transfer of personal data abroad within the framework of Law No. 6698 on the Protection of Personal Data (KVKK; the Law) has become almost impossible. For, as is also explained in the decisions published by the Personal Data Protection Board (the Board), under the current rules the only method of transferring personal data to a foreign country is to obtain the explicit consent of the data subjects. How workable this method is, however, is very much open to question. Indeed, the Board gives no guidance on this point and says only that what must be done is to obtain explicit consent.

Nevertheless, because the existing methods are unworkable and the matter has turned into a problem, other solutions are being sought. With the most recent decision published by the Board on the matter, which is also the subject of this article, the search for a solution within the framework of the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention No. 108) has lost its meaning. So what is the Board trying to do? In this article we will discuss the problem of transferring personal data abroad and what the Board is trying to do in the light of its most recent decision on the matter, and we will try to look for other solutions for data controllers. The transfer of personal data from Türkiye to a foreign country is a personal data processing activity.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

INTRODUCTION

The transfer of personal data from Türkiye to a foreign country is becoming a greater problem with every passing day. Indeed, in the present situation a lawful transfer of data abroad within the framework of Law No. 6698 on the Protection of Personal Data (the Law) has become almost impossible. For, as is also explained in the decisions published by the Personal Data Protection Board (the Board), the only method of transferring personal data to a foreign country under the existing regulations is to obtain the explicit consent of the data subjects. How workable this method is, however, is very much open to question. Indeed, the Board itself offers no guidance on this matter and merely says that what has to be done is to obtain explicit consent. Nevertheless, because the existing methods cannot be applied and the matter has turned into a problem, other solutions are being sought. As for the decision most recently published by the Board on the matter, which is also the subject of this article, it has deprived of its meaning the search for solutions within the framework of the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention No. 108).

What, then, is the Board trying to do? In this article we shall discuss the problem of transferring data abroad and, in the light of the most recently published decision on the matter, what the Board is trying to do, and we shall try to look for other solutions for controllers.

A. Transfer of Personal Data Abroad

The transfer of personal data from Türkiye to a foreign country is a personal data processing activity. Such a transfer may take the form of personal data being directly communicated / sent / transferred to a foreign country, and the storage of personal data on servers located in a foreign country is likewise regarded as a transfer activity.

What does this mean? It means that, in personal data processing operations carried out by means of any application, program, software or system whose servers are located abroad, personal data are at the same time being transferred abroad.

1. Is the Transfer of Data Abroad a Problem?

If one looks at the scope of the concept of the transfer of personal data, it becomes apparent that international companies in particular, or companies that engage intensively in commercial activity with foreign countries, at the same time carry out a transfer of personal data in almost every process. It should also be noted that this is not confined to companies of the kind described. Every company which, although a Turkish company, keeps its servers in a foreign country or uses a program whose servers are located in a foreign country is likewise engaged in transfers abroad. Consequently, nowadays, first and foremost as regards the countries of the European Union, it has become almost impossible to conduct commercial activity without transferring data from Türkiye to a foreign country.

But is it possible not to do so? Is the transfer of personal data abroad a problem in itself?

The transfer of personal data abroad cannot, of course, be regarded as a problem on its own account. This, however, resembles the question “Is the processing of personal data a problem in itself?” Indeed, the concern most frequently encountered in the first stages of compliance projects is “whether the processing of personal data is now prohibited”. In response to this concern it must be pointed out that the processing of personal data is neither a problem nor prohibited, but that data processing constitutes a risk in itself and that, for this reason, this processing activity must be carried out within certain rules.

The transfer of personal data abroad must be viewed in the same way. Although the transfer of personal data to a foreign country is not a problem on its own account and has not been directly prohibited, it is in essence a great risk. For the view that prevails in every national body of legislation is that, where personal data move within borders outside the country, the ability of data subjects to exercise their right to the protection of personal data is at greater risk. And this is indeed so: when you transfer an item of data out of the country, the data subject’s control over that data diminishes, and securing the right to the protection of personal data is therefore placed at greater risk. At that point the protection of the personal data transferred in fact becomes subject to the national legislation of the country in question. For this reason countries try to forestall these dangers and risks by incorporating into their own domestic law requirements such as that the countries to which the data are to be transferred must meet certain standards.

A similar view has been adopted in the General Data Protection Regulation – the EU General Data Protection Regulation (GDPR) as well. Recital 116 recognises that, when personal data move beyond the borders of the European Union, the ability of natural persons to exercise their data protection rights, in particular in order to protect themselves from the unlawful use or disclosure of that information, is put at increased risk. At the same time, it is stated that supervisory authorities are unable to pursue complaints, or will be unable to conduct investigations, relating to activities outside their borders. Accordingly, international cooperation mechanisms need to be developed in order to provide and facilitate international mutual assistance for the enforcement of legislation for the protection of personal data. To that end the European Commission and the supervisory authorities should exchange information and cooperate with the competent authorities in third countries in activities related to the exercise of their powers, on the basis of reciprocity and in accordance with the GDPR.

We therefore understand that personal data may be transferred abroad, but that, because such a transfer creates a great risk, it must be made subject to different rules. For, as stated above, in today’s world it is not possible to expect that personal data will not be transferred to a foreign country; such an expectation in fact means that companies would be unable to do business. For this reason, the most reasonable solution is to lay down, having regard to the nature of the activity of transferring data abroad, procedures and principles under which the right to the protection of personal data will suffer the least interference. It should be noted that, for these rules to achieve their purpose, they must be determined in the light both of the national characteristics of the countries and of the cooperation to be established with the supervisory authorities of third countries.

2. Why Has the Transfer of Data Abroad Become a Problem?

In national and international legislation the position is as stated above. No legislation on the protection of personal data prohibits the transfer of personal data to a foreign country; it merely lays down additional rules for it that are appropriate to the nature of the processing. Indeed, in Türkiye too, Article 9 of the Law similarly lays down the procedures and principles governing transfers abroad.

Pursuant to Article 9 of the Law, entitled “Transfer of personal data abroad”, while the transfer of data abroad

a) is a processing activity that cannot be carried out without the explicit consent of the data subject (Art. 9(1)),

b) such a transfer may be carried out where any one and/or several of the legal grounds set out in Articles 5 and 6 of the Law are present (Art. 9(2)).

However, in cases where a transfer is carried out on the basis of conditions for processing other than explicit consent, certain conditions must, pursuant to paragraph 2 of the said Article 9, be met in respect of the countries to which the personal data are to be transferred. Accordingly, for the transfer of personal data in this context without the explicit consent of the data subjects to be lawful, one of the following conditions must be fulfilled in the foreign country to which the personal data are to be transferred: “a) there is adequate protection” or “b) where there is no adequate protection, the controllers in Türkiye and in the foreign country concerned undertake in writing to provide adequate protection and the authorisation of the Board has been obtained”.

• Transfer of data to countries where there is adequate protection

In order to be able to transfer data to countries where there is adequate protection without obtaining the explicit consent of the data subjects, any one and/or several of the legal grounds set out in Art. 5(2) of the Law must be present; and in order to be able to transfer special categories of personal data, the conditions set out in Art. 6(3) of the Law must be met. Thus, once the existence of these conditions has been established, one will look at the country to which the transfer is to be made, and if that country is among the countries where there is adequate protection, the transfer may be carried out without obtaining the explicit consent of the data subject. It should be noted that, as regards the lawful transfer of personal data to a foreign country, this is the most reasonable method both for the protection of the right and for the workability of practice. For the transfer rests on a specific legal ground and, at the same time, it has been established that the country to which the transfer is to be made is a country with an adequate level of protection.

However, in the four (4) years that have passed since the entry into force of the Law, the Board has still not announced the countries where there is adequate protection, and this is a matter of severe criticism. On 11 June 2019 the Board published, by its decision of 02/05/2019 No. 2019/125, the form drawn up for use in designating the countries where there is adequate protection, together with the criteria to be taken as the basis in determining those countries, but it has taken no step since then.

Consequently, there is at present no country that is regarded as safe. Yet, in the context of a compliance project, explaining to a company that transfers data to any one of the countries of the European Union that it needs explicit consent in order to do so is, unfortunately, the task not of the Board but of the compliance consultants. For, in my view, it makes no sense that the countries of the European Union, which are subject to the provisions of the GDPR and are regarded as safe among themselves, should not be safe as far as Türkiye is concerned. Given that the Board itself bases its decisions on the provisions and recitals of the GDPR and, in this sense, follows EU personal data protection law in terms of legislation and practice, declaring as safe the EU countries, which can readily be said to ensure an adequate level of protection, would greatly ease practice in our country.

It must be stated, however, that, since the countries where there is adequate protection have not yet been announced by the Board, it is at present not possible to carry out a transfer on the basis of the countries where there is adequate protection.

• Absence of adequate protection / Undertaking by the controller to provide adequate

protection

Another method for the transfer of personal data abroad is for the controller to undertake to provide adequate protection. Accordingly, for a controller to be able lawfully to transfer data to a foreign country where there is no adequate protection, the following conditions must all be met:

• One of the conditions specified in paragraph 2 of Article 5 and paragraph 3 of Article 6 of the Law is fulfilled,

• The controllers in Türkiye and in the foreign country concerned undertake in writing to provide adequate protection,

• The authorisation of the Board has been obtained.

The minimum elements to be included in such undertakings were published by the Board on 16 May 2018, and the way was thereby opened for controllers to obtain authorisation from the Board in order to be able to transfer data abroad. It is known, however, that no result has so far been obtained from the applications made to the Board on the matter. At first it was presumed that the reason for this lay in incomplete or erroneous applications by controllers. Indeed, by its “Announcement on the Points to Be Taken into Consideration in the Undertakings to Be Prepared for the Transfer of Personal Data Abroad”, published on 7 May 2020, the Board explained certain points of procedure and substance that need to be observed. It is not known whether, since then, the Board has granted authorisation following an application made by means of an undertaking prepared in the manner indicated.

The fact that, although so much time has passed, no decision has been taken on the undertakings either gives the impression that this is being deliberately delayed or that a policy consisting in not taking a decision on this matter is being pursued.

• Obtaining the explicit consent of the data subjects

Since the methods described above are at present not applied in practice, the controller has in fact been left only with the possibility of obtaining explicit consent in order to be able to transfer data abroad. Indeed, the Amazon Decision (of 27/02/2020, No. 2020/173), published by the Board on 7 May 2020, also stated expressly that, in the light of the existing regulations, the only method that can be resorted to in order to transfer data abroad is to obtain the explicit consent of the data subjects. What is more, that decision noted that the controller had submitted its letters of undertaking to the Board in order to obtain the Board’s approval; yet, on the ground that the Board had not taken any decision on the matter, it stated that the only method for transferring personal data abroad was to obtain the explicit consent of the person concerned. The Board ruled that a high administrative fine be imposed because the explicit consent of the data subjects had not been obtained. This decision also put an end to the belief that the Board would not impose penalties on account of transfers abroad because it had itself failed to announce the countries where there is adequate protection. Thus the Board has both severely restricted the options open to controllers by reason of a duty which it has itself failed to perform and, despite this, imposed a sanction on the controller.

But is this in keeping with the realities of life? How reasonable is it really to expect an international company such as Amazon to obtain explicit consent for every item of personal data it transfers abroad? Does the Board not also know that this is impossible? Although this seems more feasible in small companies or in countries where transfers abroad are rarely carried out, it is not a workable method for companies that are large, or have a large number of employees, or have a direct connection with other countries and transfer almost all data abroad. It is therefore clear that there must also be methods other than obtaining explicit consent for the transfer of personal data abroad.

3. Are there other methods for transferring personal data abroad lawfully?

At this point it is also useful to recall, with regard to the problem of transferring data abroad, the step the Board took in adopting binding corporate rules by the announcement it published on 10 April 2020. Binding corporate rules are, in the Board’s definition, “data protection rules which are used in the transfer of personal data abroad for multinational groups of companies operating in countries where there is no adequate protection and which enable adequate protection to be undertaken in writing”. However, considering that binding corporate rules will apply to multinational groups of companies, it will be understood that they cannot by themselves be a solution to the issue of transfers abroad.

First of all, very few companies meet the criteria needed to comply with these rules. Beyond that, drawing up binding corporate rules requires a great deal of effort and time. Therefore, making rules on binding corporate rules before the basic steps on the matter have been taken can be a remedy for only a very limited number of controllers, but will not suffice to resolve the greater part of the problem.

Nor is it comprehensible why, when there are, as explained above, many methods that could be applied as a solution in the transfer of data abroad, the solution that ought to have been adopted last and that is the narrowest in scope was regulated first.

4. Where does the idea come from that personal data may be transferred within the framework of Convention No. 108?

As stated above, because the transfer of personal data to a foreign country has become a problem in Türkiye, other solutions to the matter are being sought. Transfer within the framework of Convention No. 108 is one of them, and it rests on valid legal grounds.

Convention No. 108 is the only internationally binding multilateral convention in the field of the protection of personal data. Türkiye too is a party to this Convention and is therefore subject to its provisions. Article 12 of the Convention, entitled “Transborder flows of personal data and domestic law”, reads as follows:

“The following provisions shall apply to the transfer across national borders, by whatever medium, of personal data undergoing automatic processing or collected with a view to their being automatically processed.

A Party shall not, for the sole purpose of the protection of privacy, prohibit or subject to special authorisation transborder flows of personal data going to the territory of another Party.

Nevertheless, each Party shall be entitled to derogate from the provisions of paragraph 2:

Insofar as its legislation includes specific regulations for certain categories of personal data or of automated personal data files, because of the nature of those data or those files, except where the regulations of the other Party provide an equivalent protection;

When the transfer is made from its territory to the territory of a non-Contracting State through the intermediary of the territory of another Party, in order to avoid such transfers resulting in circumvention of the legislation of the Party referred to at the beginning of this paragraph.”

It should first be noted that all the provisions of Convention No. 108, including Article 12 set out above, have the force of law pursuant to Art. 90(4) of the Constitution. Moreover, since it is a convention concerning fundamental rights and freedoms, where national laws contain conflicting provisions, the provisions of the Convention must prevail.

According to this article, transfers to States Parties may not be prohibited or made subject to special authorisation for the sole purpose of the protection of personal data. Certain exceptions to this provision have also been laid down. The first of these exceptions is the absence of equivalent protection. Accordingly, where Türkiye is subject to a specific regulation on the protection of personal data, it is entitled to prohibit, or to make subject to authorisation, a transfer to a country that does not have equivalent protection. That being so, where a country which the Board has not specifically stated to lack equivalent protection has protected the right to the protection of personal data by means of a specific regulation and is a party to the Convention, is there still any need for it to be declared a safe country by the Board?

In the light of these explanations, it may be possible to point to Article 12 of the Convention as the legal basis for transfers of data to countries that are parties to Convention No. 108. Unless the exceptions set out there apply, it ought to be possible to transfer data between the countries that are parties to the Convention without the conditions laid down in Article 9 of the Law being required1. This means that controllers located in Türkiye would be able to transfer data to the other 54 countries that are parties to the Convention.

Although this appears possible in theory, there were hesitations in practice about transferring data on the basis of Convention No. 108, since there had been no official statement or announcement by the Board on the matter. In its most recently published decision on the matter the Board dispelled these hesitations and said in plain terms: “you cannot transfer data on the basis of Convention No. 108”.

B. The Board’s Decision of 22/07/2020 No. 2020/559 “on the transfer of personal data abroad on the basis of Convention No. 108”

Having dealt with the basic regulation on the transfer of personal data abroad and with the problems involved, we shall under this heading examine the Board’s most recent decision on the matter and try to identify the points to which controllers need to pay attention.

1. The facts underlying the decision

The procedure by which the Board examined the matter was, in sequence, as follows:

Complaint by the data subject : The data subject lodged a complaint with the Board concerning a short message (SMS) for advertising / information purposes sent to him or her by the controller, which operates in the automotive sector.

The Board’s : Following the data subject’s complaint, an examination by the Board

examination

being opened was begun.

Controller’s defence : As a result of the examination opened, the controller was requested being obtained to submit its defence. In its defence the controller made contradictory statements regarding the legal ground of the processing activity by which it transferred data abroad. Thus the controller both claimed that it was obliged to do so by virtue of its “legitimate interest”

and stated that this transfer was carried out “on the basis of the explicit consent of the data subjects”.

Ex officio examination : On that basis the Board decided, in respect of the controller being opened and with regard to its storing its customers’ personal data in databases abroad, to open an ex officio examination under paragraph (1) of Article 15 of the Law. Accordingly, the controller was requested to send its explanations as to the legal ground on which the transfer of personal data abroad was based, together with all information, documents and records relating to the matter.

2. The controller’s defence and submissions

The controller’s defence and submissions concerning the transfer activity carried out are as follows:

The transfer activity carried out: A web-based software is used in the digital marketing communications conducted by the company; because the system is web-based, the personal data of customers are transferred, using SFTP, to a cloud database (Outsourcing Firm) whose servers are located in an EU Member State, so that e-mails / SMS can be sent to customers via the software.

Personal data transferred: The (i) customer information, (ii) marketing information and (iii) contact information relating to customers are transferred to the outsourcing firm. No special categories of personal data are transferred.

Legal grounds: The controller stated that, in the case underlying the decision, it relied on the legal grounds of explicit consent, legitimate interest and Convention No. 108.

• Explicit consent is obtained by means of the “Information and Consent Notice on the Processing of Customers’ Personal Data”, as updated since 2018.

• Legitimate interest Personal data are transferred to the outsourcing firm, which is in the position of processor, on the basis of the condition laid down in Art. 5(2)(f) of the Law that the processing of data is necessary for the legitimate interest of the controller.

• Convention No. 108 Convention No. 108 has been transposed into domestic law, and all EU countries are parties to this Convention. Pursuant to Article 90 of the Constitution of the Republic of Türkiye, in the event of conflicts between Convention No. 108 and other laws, the provisions of Convention No. 108 must prevail. According to Article 12 of the Convention, transfers to the parties to the Convention may not, unless one of the exceptions laid down

is met, be prohibited or made subject to special authorisation. In this context, having regard to Article 9 of the Law, there is no legal restriction and/or obstacle to carrying out a transfer on the basis of Article 12 of the Convention.

On the other hand, Art. 2(1) of the Additional Protocol to the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, regarding supervisory authorities and transborder data flows (Additional Protocol) provides, with regard to transborder transfers of personal data, that in the case of transfers to non-parties an assessment is to be made of whether adequate protection is ensured. Accordingly, it follows by an argumentum a contrario from that article that no assessment of adequate protection may be made in the case of a transfer to countries that are parties to the Convention.

In conclusion, the controller company claims that, within the scope of Art. 9(5) and (6) of the Law and Article 12 of Convention No. 108, and relying on the legal ground in Art. 5(2)(f) of the Law that “the processing of data is necessary for the legitimate interests of the controller, provided that it does not harm the fundamental rights and freedoms of the data subject”, it lawfully transferred data to the outsourcing firm, which is in the position of processor, having taken all the necessary administrative and technical measures.

3. The Board’s opinion and assessments

The points to be noted in the assessment made by the Board on the matter and the main findings are as follows:

• Does the controller company have a legitimate interest in respect of the transfer activity it

carried out?

As stated above, the controller company claims to rely on the ground that the transfer it made to the outsourcing firm was necessary for its legitimate interest. The Law sets out the cases in which personal data may be processed without the explicit consent of the data subjects, and “the processing of data being necessary for the legitimate interests of the controller, provided that it does not harm the fundamental rights and freedoms of the data subject” is one of those legal grounds.

As the Board has stated in its previous decisions, as well as in the decision under examination, certain conditions must be met for this legal ground to apply. Accordingly: (i) the basic principles on the protection of personal data must be complied with; (ii) the legitimate interest of the controller and the fundamental rights and freedoms of the data subject must be taken into account; and (iii) it must be decided, as the outcome of the assessment to be made between the competing interests, whether the personal data may be processed under the paragraph in question.

Accordingly, the controller must first establish the existence of its legitimate interest and, if it exists, establish whether that interest harms the fundamental rights and freedoms of the data subject. It is not lawful to engage in data processing on the basis of legitimate interest without carrying out a balancing test.

It must be stated that the determination of whether the controller has a legitimate interest must be made with great care and diligence. An assessment made in this context must not rest on generic and formulaic reasons, and the existence of the controller’s legitimate interest must be based on concrete reasons. This legal ground should not be treated as a provision in which the controller can take refuge where it is unable to rely on any of the other exceptions introduced by the Law in order to be able to process personal data.

The assessment made by the Board is a good example on this point. Although the controller claimed that the transfer it made was necessary for its legitimate interest, it was unable to demonstrate this in concrete terms. Indeed, the Board stated that, because no explanation whatsoever had been given as to what the legitimate interest was and as to whether a balancing test had been applied between that interest and the fundamental rights and freedoms of individuals, it had not been persuaded that there was a valid legitimate interest in the processing of the personal data by the controller company by way of their transfer abroad.

The reason for the transfer made by the controller is that it uses a web-based software in order to be able to send its customers e-mail / SMS notifications for advertising / marketing purposes. However, the company’s use of a web-based software was not regarded by the Board as necessary for the company’s legitimate interest. In other words, the Board is saying: “using a web-based software is your choice; this therefore cannot be a necessary transfer”. This proposition of the Board has no place in the ordinary course of the IT world. For today many companies, in particular multinational companies, prefer web-based software because it is both effective and less costly. I must say that decisions of this kind by the Board have fallen behind the possibilities and requirements of our age.

On the other hand, the sending of notifications by the company for advertising and marketing purposes is in any case not regarded as falling within legitimate interest. Controllers should bear in mind that they must without fail obtain the explicit consent of the data subjects for the personal data processing activities they carry out in sending such notifications.

In conclusion, the controller company’s claim that it carried out the transfer on the basis of its legitimate interest was not accepted by the Board.

• The controller must determine clearly and precisely on which legal ground/grounds

it processes data in the processes it carries out

In the case underlying the decision, one of the greatest problems for the controller is that it is not clear and precise on what grounds, in other words on the basis of which legal grounds, the processing and the transfer were carried out. Yet one of the basic aims of the Law is to ensure that the purpose for which personal data are processed is made apparent. For, with the Law, the processing of personal data without any purpose has now become unlawful. Indeed, this is also one of the basic objectives of projects for compliance with the Law. In these projects, once all the processes carried out by the controller have been identified, a legal ground has to be determined for each process. To put it more plainly, the Law wants a controller to be aware of which data it processes and why.

In the present case, although the controller relied on the legal ground of legitimate interest for the processing of personal data, the information and consent notice it presented to the data subjects contains a statement to the effect that “… may, for the purposes of the products and services offered by our Company being recommended and promoted to you in a manner customised to your tastes, usage habits and needs, of commercial electronic messages such as advertisements, promotions etc. being sent to the contact details you have shared within the scope of your acceptance, of being stored and … of being shared with the third parties from which it obtains services in order to ensure delivery, be processed within the scope of the explicit consent you will have given if you accept this text.” This statement, however, gives the impression that the personal data processing activity is carried out primarily and solely on the basis of the explicit consent of the data subjects.

Moreover, while more than one condition for processing may be relevant in a single process, it is unlawful for other conditions for processing and explicit consent to exist side by side. The controller must first establish whether any one of the conditions for processing laid down by the Law is present; if it is, the controller must on no account resort to obtaining explicit consent. According to the Board, basing a data processing activity on explicit consent when it could be carried out on a basis other than explicit consent would be misleading and would be contrary to the law and to the rule of good faith.

As far as can be understood from the defence submitted by the controller company, the processing of customers’ contact data for advertising/marketing purposes was based on the explicit consent of the data subjects, whereas the transfer of these data to the outsourcing company was based on the legal ground of legitimate interest. Thus, in order for e-mails / SMS to be sent to persons who had given permission for marketing communications, customer data were transferred to a cloud database whose servers are located in an EU Member State, and a transfer abroad was thereby carried out.

However, the validity of a declaration of explicit consent has been made subject to various conditions. Since explicit consent must relate to a specific matter, a declaration of explicit consent must have been given in relation to matters such as which data will be processed for which purposes. Therefore, a controller cannot use an explicit consent obtained for one processing activity as the basis for another operation. In the present case there is an unlawfulness in this respect. The controller company ought to have obtained explicit consent also for the secondary operation it carried out, namely the transfer abroad. Yet, as will be seen above, the statement in the information notice contains no indication whatsoever that the personal data would be transferred abroad. For this reason, the Board found in this respect that it had not been clearly stated which of the personal data in question were processed within the framework of legitimate interest and which on the basis of the explicit consent of the data subjects.

• According to the Board, being a party to Convention No. 108 is merely a criterion to be taken into account

in the adequacy assessment

With regard to Convention No. 108, the Board first underlined that Article 12 of the Convention, explained above, applies only to “transfers of personal data made on the ground of the protection of private life”. On the other hand, paragraph 2 of the Explanatory Report to Convention No. 108 (Explanatory Report) explains the purpose of that provision as being to facilitate the flow of data between the States Parties, proceeding from the presumption that the countries party to the Convention provide an adequate level of safeguards for the protection of personal data.

The Board is of the opinion that, in accordance with this explanation, the possibility of making the flow of data between States Parties subject to notification, or of the parties’ enacting rules in their domestic law to prohibit transfers within the country or across borders in certain circumstances, is not removed. As regards the application of the Explanatory Report in the EU, the Board stated that, under the provisions both of Directive 95/46/EC and of the GDPR, countries that are parties to Convention No. 108 are not classified as countries having adequate protection without any further assessment, and that being a party to the Convention is accepted merely as a criterion to be taken into account in the adequacy assessment.

In this context, the Board stated that the transfer of personal data abroad without explicit consent may be carried out only where the conditions laid down by the Law are present, the parties undertake in writing to provide adequate protection and the Board authorises the transfer.

• The Board is of the opinion that Article 9 of the Law is compatible with Convention No. 108.

Art. 9(4) of the Law sets out the criteria which the Board must take into account in deciding whether there is adequate protection in the foreign country and whether authorisation is to be granted in respect of undertakings. Having regard to the international conventions to which Türkiye is a party is also listed among these criteria, but it is not laid down as a ground on its own. Indeed, this point was also mentioned among the criteria to be taken into account in the decision of 02.05.2019 No. 2019/125 published by the Board. In addition, under the said provision of the Law and decision of the Board, matters aimed in particular at ensuring the effective protection of personal data, such as the nature of the personal data to be transferred and the purpose and duration of their processing, the data protection legislation and practice in the country to which the transfer is to be made, and the measures to be undertaken by the controller or processor in that country, are also criteria that must be taken into account. Furthermore, the state of reciprocity concerning data transfer between Türkiye and the country to which the transfer is to be made is laid down as another matter to be considered in the Board’s assessment.

The Board is of the opinion that this regulation is compatible with the provisions of Convention No. 108. For, as stated above, the Board concluded, on the basis of the explanations in the Explanatory Report, that States Parties may enact rules in their domestic law prohibiting the transfer of data abroad in certain circumstances. According to the Board, therefore, there is no contradiction between Convention No. 108 and the provisions of the Law.

• The Board decided that Article 90 of the Constitution could not find application.

Before turning to the reasons for this assessment by the Board, it is necessary to discuss whether it has the power to make such an assessment at all. Can the Board make an assessment to the effect that any article of the Constitution does not find application?

It appears overly ambitious for the Board, which was established to be responsible for the application of the Law on the Protection of Personal Data, to make an assessment as to where the provisions of the Constitution do or do not find application. Although making decisions and assessments on the protection of personal data often requires discussion of other legislation, the fact that the Board interprets the provisions of the Constitution and their explanatory memoranda without any other court decision or scholarly opinion to rely on gives rise to doubt and looks like self-proclaimed knowledge. It would have been a more appropriate approach, in order to dispel the doubts that have arisen, for the Board to discuss this by reference to various sources and to form its decision on the basis of those sources. Above all, we think that the Board ought to be more careful and diligent in this matter.

To turn to the reasons for this finding by the Board, they may be summarised as follows:

• Art. 9(6) of the Law contains the provision that “The provisions of other laws concerning the transfer of personal data abroad are reserved.”

• Pursuant to Article 90 of the Constitution, international treaties duly put into effect have the force of law. In this context, Convention No. 108 also has the character of a law for the purposes of Turkish law. On the other hand, by the addition made to Article 90 of the Constitution it was provided that, where international treaties concerning fundamental rights and freedoms and laws provide for different rules on the same subject, the provisions of the international treaty shall prevail.

• The Board referred to the explanatory memorandum of the addition made: “A provision is being added to the last paragraph of Article 90 in order to remove the hesitations as to which is to be given priority where, in practice, a dispute arises because international treaties on human rights duly put into effect conflict with statutory provisions”.

• The Board recalled at this point that, for the provisions of an international treaty to be applied, those provisions must be directly applicable; in other words, the treaty provision must be “sufficiently clear, precise, unconditional and of such a nature as not to require the State to take an additional measure for its application”2.

• In accordance with these principles, the Board first drew the inference that “a discrepancy arising between a more abstract and general provision of an international treaty which is not directly applicable and a provision of a law will not constitute a conflict in the context of the rule contained in the fifth paragraph of Article 90 of the Constitution”, and for that reason reached the conclusion that “the said provision of the Constitution will not find application and, consequently, where a provision of an international treaty of a general nature conflicts with a provision of a law, the conflicting provision of the law must be taken as the basis and applied”.

• This assessment is based largely on Article 4 of the Convention and on the Explanatory Report. For, according to these, the provisions of the Convention are not directly applicable; the States Parties must take the necessary measures to give effect to the basic principles for the protection of data.

We do not agree with this reasoning of the Board. Although Article 4 of the Convention provides that the provisions must additionally be incorporated into domestic law in order to take effect, it does not provide that something contrary to the provisions of the Convention may be incorporated into domestic law. Therefore, incorporating into domestic law a provision that is not compatible with Article 12 of the Convention, together with an interpretation to the effect that Article 12 cannot be applied on the ground that it has not been incorporated into domestic law, is in fact contrary to the rules of the convention which the country, by signing it, bound itself to apply. The result would then be that “countries may sign any international treaty as they please but, despite having signed it, may introduce rules that are not compatible with the provisions of that treaty and, what is more, may refrain from applying the provisions of the treaty they have signed on the ground that they have not incorporated them into domestic law”. Türkiye has in any case acted contrary to the Convention by not incorporating into domestic law the provisions of the Convention it signed and by introducing provisions that are not compatible with them. This breach, however, cannot be put forward as a justification.

That said, we agree with the Board on the point that the rules introduced by Article 12 of the Convention are provided for only in respect of “transfers of personal data made on the ground of the protection of private life”, and we think that this could be a justification. Therefore, instead of skirting round the provisions of the Constitution and, by interpreting as broadly as possible, arriving at the erroneous finding that the article in question cannot find application, it could have been far more correct to rely solely on the reasoning that this article can find application for transfers made on the ground of the protection of private life. However, it would have followed, by an argumentum a contrario, from an explanation based on this alone that Article 12 of the Convention can be applied to transfers made on the ground of the protection of private life. We therefore think that the other reasons were put forward in order to prevent this.

Likewise, we also share the Board’s view that Article 12 of the Convention remains general and abstract and, in this respect, does not create a conflict of norms with Article 9 of Law No. 6698 on the Protection of Personal Data (KVKK). Reliance on Convention No. 108 alone does not constitute a direct legal ground for the transfer of data abroad; it will be possible to transfer data abroad when the conditions in Article 9 of the KVKK, which is in the nature of its complement, are complied with. That said, our assessment that the Board has in fact (de facto) blocked a data processing activity that is possible in terms of the legislation (de jure) must also be reiterated at this stage.

• In conclusion, the Board came to the opinion that being a party to Convention No. 108 does not by itself permit the transfer of personal data abroad. The Board stated that, as in EU practice, it treats being a party to the Convention as “a positive factor” for the purposes of designating safe-country status under the Law.

As a result of the explanations set out above, the opinion was reached that the controller company had carried out an unlawful transfer.

4. The decision

As a result of the opinions and assessments formed by the Board and explained in detail above, the following was decided:

• That, with regard to the controller’s transfer of personal data abroad, since being a party to Convention No. 108 is not by itself a sufficient ground in this respect and the transfer activity was therefore carried out without the necessary conditions being met, and the opinion having accordingly been reached that the controller failed to fulfil the obligation “to prevent the unlawful processing of personal data” laid down in Art. 12(1)(a) of the Law, entitled “Obligations Concerning Data Security”, an administrative fine of 900,000 TL be imposed on the controller pursuant to Art. 18(1)(b) of the Law,

• That, since the opinion was reached that there was unlawful data processing by way of transferring data abroad, because the controller did not obtain a lawful explicit consent from the data subjects for the transfer of data abroad, because, as regards the conditions for processing other than explicit consent, no balancing test was carried out to show that there was a valid legitimate interest, and because, moreover, no undertaking was prepared in accordance with Article 9 of the Law for the transfer abroad and submitted to the Board in order to obtain its authorisation, the controller be instructed to erase or destroy the personal data in accordance with Art. 7(1) of the Law and the relevant Regulation and to inform the Board of the outcome,

• That the controller be instructed to update its information notice so that it complies with Article 10 of the Law and with the provisions set out in Article 5 of the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform, issued on the basis of that article, and to carry out the fulfilment of the obligation to inform and the obtaining of explicit consent as separate operations.

Conclusion

The world economy has become globalised, and it expands and advances to the extent that it globalises. One of the most important means that have made globalisation possible is undoubtedly advanced technology. When the issue of transferring data abroad is assessed in this broad context, we are confronted with the fact that for a great many controllers it is a necessity, indeed an imperative. It may be that, as a matter of our country’s personal data policy, “data localisation”, that is, personal data in Türkiye remaining in Türkiye, has been adopted. Indeed, traces of such a policy can also be followed in the amendments made to Law No. 5651 with regard to “social network providers”. However, leaving aside the correctness and realism of such a policy, this will not alter the fact that a method of data processing recognised by law (KVKK Art. 9) is being prevented in practice.

I agree in the result with the Board’s decision that data cannot be transferred abroad on the basis of Convention No. 108, even though I do not share some of its reasons. Indeed, I am not of the opinion that there is a conflict of norms between Convention No. 108 and Article 9 of the KVKK. Article 9 of the Law is not inconsistent with or contrary to Article 12 of the Convention, which may be regarded as general and abstract. On the contrary, it may be seen as a complement to it.

That said, it must be seen that what underlies all these searches for a solution is, specifically, the fact that the “safe countries” have not been announced and, generally, the aim of overcoming data localisation policies. Invoking Article 12 of Convention No. 108 is also one of the efforts in this direction. It is apparent, however, that these efforts are not sufficient to remove the passive obstacle consisting in the Board’s failure to take the necessary steps under Article 9 of the Law. It may be possible to attribute this inaction of the Board, in not taking this step, to various reasons. What stands out here in particular is the possibility that, given that the EU Member States and various other countries have not yet included Türkiye in their lists of safe countries, a step is deliberately being avoided as a matter of political stance and of the principle of “reciprocity”. In my view, however, those who have to pay the price of this legal-political problem ought not to be the controllers who, by keeping up with the technological revolution, are trying to keep the wheels of the Turkish economy turning. The transfer of data abroad should also, as I stated above, be assessed in this context.

The last point may concern what the Board will do and can do in this matter. First, in the current circumstances, I think that safe countries will be possible only once the political problems in this area have been resolved. Indeed, while the European Commission has, on the basis of Article 45 of the GDPR, adopted adequacy decisions in the last 10 years in respect of countries such as Andorra, Argentina, Canada (commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, Switzerland and Uruguay, this has not yet happened in the case of our country. In this respect, the necessary steps must first be taken on the diplomatic side of the problem. Yet, considering that more than four years have passed since Law No. 6698 came into being, it also follows that these steps are long overdue. Apart from this, there is another step that the Board ought to take in order to make Article 9 on the transfer of data abroad operative, and I do not understand why this path has still not been opened. That step is for the Board, while the list of safe countries has not yet been announced and while there exist standard undertakings for the transfer of data abroad, every clause of which the Board itself has determined and drafted (see: https://kvkk.gov.tr/Icerik/2053/Yurtdisina-Aktarim), now to begin assessing and accepting them. At the very least this could, as a temporary solution, make the activity of transferring data abroad possible.

Footnotes

  1. For the list of the 55 countries that are parties to the Convention, see: https://www.coe.int/en/web/conventions/full-list/- /conventions/treaty/108/signatures, (Çevrimiçi 25 Eylül 2020). ↑
  2. For detailed information on the subject, see: Ahmet Murat Bilgin, “AİHS ve Diğer Uluslararası Anlaşmaların İç Hukuktaki Yeri Bağlamında 2004 Değişikliğinin Beraberinde Getirdiği Sorunlar ve Bazı Çözüm Önerileri”, Marmara Üniversitesi Hukuk Fakültesi Hukuki Araştırmalar Dergisi, C. 22, S. 1, s. 135, 136. ↑

Download PDF (in Turkish)

Related publications