16 April 2020Murat Volkan Dülger, Cansu Ceren KahramanCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

On 15 April 2020 the Personal Data Protection Board published two decisions that resemble decisions it had published earlier. Before turning to our assessment of the decisions, we wish to point out that anyone who really wants to master personal data protection law should not refrain from assessing, debating and discussing decisions merely because they are similar. This is because this is a field of law in which an assessment must be made according to the specific case (one that calls for a more refined assessment of the situation than other fields of law). A correct assessment is possible only with knowledge of particular situations that differ from one another.

To explain this with a small example, information on whether a person smokes is in some cases personal data falling within the category of personnel file information, while in other cases it may be special category personal data falling within the category of health information. This can be determined only by assessing the specific case. The first of the published decisions concerns the making of a duly submitted application to the data controller and the data controller’s reply to such an application in accordance with the rules of good faith. The second concerns a breach of the obligation to take the necessary administrative and technical measures to ensure an appropriate level of security in order to prevent the unlawful processing of personal data. The subject of our study is the assessment of these two decisions.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

Murat Volkan Dülger* / Cansu Ceren Kahraman*

Introduction

On 15. 04. 2020 the Personal Data Protection Board published two decisions that resemble decisions it had published earlier. Before turning to the assessment of these decisions, we would like to point out that anyone who truly wishes to master data protection law should not shy away from assessing, debating and discussing decisions merely because they resemble one another. For this is a field of law in which the assessment has to be made according to the concrete situation (a field that calls for a more refined assessment of the situation than other fields of law). A correct assessment is possible only if one is familiar with the particular situations that differ from one another. To explain this with a small example: the information that a person smokes may in some cases be personal data falling within the category of personnel-file information, whereas in other cases it may be special category personal data falling within the category of health information. Which of the two it is can be determined only and exclusively by assessing the concrete case.

The first of the published decisions concerns the making of an application to the controller in accordance with the prescribed procedure and the controller's replying to such an application within the framework of the rules of good faith; the second concerns a breach of the obligation to take the necessary administrative and technical measures to ensure an appropriate level of security in order to prevent the unlawful processing of personal data. The assessment of these two decisions forms the subject of our study.

1. Summary of Decision No. 2020/86

In the case underlying the Board's decision of 06. 02. 2020 No. 2020/ 86, the data subject requested that the membership e-mail address recorded in the systems of the controller, a company selling airline tickets through the website “….com”, be updated; however, citing as grounds that no changes could be made to membership e-mail addresses and that a new membership could be opened with the e-mail address the data subject wished to use, the controller refused this request, whereupon the data subject applied to the Authority. In its written defence the controller stated that the data subject's application had in fact been sent from an e-mail address that was not recorded in its system and that it had been refused because it had not been made by any of the methods listed in the Communiqué. Having assessed the data subject's application together with the controller's reply, the Personal Data Protection Board, by its decision of 01/03/2019 No. 2019/48, decided as follows: proceeding from the fact that the person's identity could not be established because the data subject's application had not been made in accordance with the prescribed procedure, there was no action to be taken with regard to the conduct of the controller in refusing the data subject's request; however, since the controller had refused the data subject's application not on the ground—as stated in its explanation to the Authority—that the person's identity could not be determined because the application had been made from an e-mail address not recorded in its systems, but on the ground that no changes could be made to membership e-mail addresses, and taking into account that the controller had thus failed to conclude, in accordance with the rule of good faith, an application made by a data subject under the “Communiqué on the Procedures and Principles of Application to the Controller”, the Company was to be instructed to take, from then on, all necessary administrative and technical measures in order to conclude applications made by data subjects under the Communiqué effectively and in accordance with the law and the rule of good faith.

Subsequently, the same data subject lodged a second complaint against the same controller. In the second complaint the data subject stated that on 12.04.2019, using his or her registered electronic mail (KEP) account, he or she had sent the request for the e-mail address to be updated to the controller's KEP address; that the e-mail had been read by the controller on the same day, but that the controller had not replied to the data subject within 30 days. In its written defence the controller, for its part, stated that the data subject had applied to the controller again on 12.04.2019 by way of the KEP address, but that owing to the heavy workload the application had after a while been overlooked; that, once the data subject's request was noticed, it had been complied with and the e-mail address updated in line with the request, and that the data subject had been informed of this update; and that the data subject was able to log in to the system with the updated e-mail address he or she had requested.

The Board, having made its assessment,

• on the ground that, although the data subject is granted the right to lodge a complaint with the Board where the controller does not reply to the data subject's applications or the reply is found to be insufficient, the Law does not provide for any type of administrative sanction that could be imposed on the controller merely for failing to reply to an application,

• that the application was the second application, and that in the decision on the first application it had been decided to instruct the controller to take all necessary administrative and technical measures in order to conclude applications effectively and in accordance with the law and the rule of good faith,

• that, despite the Board's instruction, the second application made by the data subject from the KEP address had not been answered and that, since the controller in its defence explained the failure to answer the application by saying that it had been overlooked owing to the heavy workload, the controller had not taken the administrative measures necessary for applications to be answered effectively and in accordance with the law and the rule of good faith and had not complied with the instruction given by the Board,

decided, on these grounds, that an administrative fine of TRY 50,000 be imposed under Article 18(1)(c) of the Law on the controller, which had acted in breach of the provisions of Article 15(5) of the Law.

2. Assessment of Decision No. 2020/ 86

In the case, the controller told the data subject that the first application (the one made to the controller) had been refused because it was not possible to update the e-mail address, and that for this reason no reply had been given; to the Board, however, it stated that the application had been refused because it had not been made in accordance with the “Communiqué on the Procedures and Principles of Application to the Controller”.

The decision states that the controller's failure to reply to an application is not subject to any sanction. In our opinion, the fact that a failure to reply to an application is not subject to a sanction is not a major shortcoming. For where an application is not answered, the data subject has the right to lodge a complaint with the Board. And where a complaint is lodged, the mechanism of instruction comes into play. The imposition of an administrative fine stands as the last resort. If the failure to reply to an application were also to carry a sanction, the Board would turn from a Board whose purpose is to protect personal data into a punitive Board. Moreover, where the right to lodge a complaint is exercised, it is possible for the Board to impose a sanction by establishing the unlawful practices as a result of the necessary examinations.

First of all, the controller is under an obligation to keep personal data up to date and accurate. In this context the controller must take all the technical and administrative measures necessary (for personal data to be kept up to date and accurate). In other words, considering the point that technology has reached today, the justification that no changes can be made to membership e-mail addresses and that a new membership can be opened with the e-mail address the person wishes to use is not reasonable. The controller has to set up, or update, its system infrastructure accordingly. The opposite situation does not justify its failure to fulfil its obligation.

In practice we see that at least some controllers do not attach much importance to the obligation to keep personal data up to date and accurate. Regrettably, attempts are being made to perpetuate the idea that prevailed before the Law, namely (to explain it in the terms of the present Law) that the data belong to the controller. Controllers who hold this idea do not erase from their systems the data they have obtained, even though these data are incorrect or no longer in use. Indeed, this may at times lead to irreversible consequences for data subjects. As we have stated before, again and again, the aim of data protection law is not to bring commercial activities to an end. It is that, while activities continue (and not only in the commercial sphere), personal data are protected as well. In a society in which it is now known even which foods are running low in our refrigerator, it is an imperative need that the processing of personal data be subject to rules. Controllers (in the case of controllers that are legal persons, their authorised persons) must act without forgetting that they are, at the same time, data subjects themselves.

To return to the assessment of the decision: although the data subject had not made an application in accordance with the Communiqué, the controller refused the application not for this reason but because the data could not be updated. The Board, for its part, decided in its first decision that the Company be instructed to take all necessary administrative and technical measures in order to conclude applications made by data subjects effectively and in accordance with the law and the rule of good faith.

Under Article 15 of Law No. 6698 on the Protection of Personal Data (KVKK), “Where, as a result of the examination carried out upon complaint or of its own motion, it is understood that a violation exists, the Board shall decide that the unlawful practices it has identified be remedied by the controller and shall notify those concerned. This decision shall be complied with without delay and at the latest within thirty days of notification.” Article 18 of the Law in turn provides that an administrative fine shall be imposed on persons who act in breach of this provision. When the amounts of the administrative fines provided for in the Law, as updated in line with inflation, are also taken into consideration, it is plainly clear that controllers must not neglect to comply with the instructions. In fact, controllers ought to regard these instructions as a sign of good will, in terms of the protection of personal data, that precedes the sanction of an administrative fine.

In the case at hand the Board rightly imposed an administrative fine because the controller had failed to comply with the instruction. It should be noted that an attempt is first made to ensure the protection of personal data by means of instructions; only if the controller persists in not protecting personal data is an attempt made to bring about, so to speak, its reform by means of an administrative fine.

3. Summary of Decision No. 2020/ 103

In the case in question, when the data subject wished to open a deposit account at a bank branch, he or she learned that there was a commercial account in his or her name that had been opened two years earlier at a branch of the same Bank in another province, and that all of his or her identity details, including the mother's maiden name, appeared in the account at that branch; thereupon, although the data subject had never been to the place where the branch at which the account had been opened is located and, moreover, carried on no commercial activity whatsoever, he or she lodged a complaint with the Board about the opening of an account in his or her name through the unlawful processing of his or her personal data at the bank.

Upon the complaint, the Board examined the complaint together with the information and documents obtained from the bank. The controller bank declared that, in the course of a campaign carried out for the purpose of acquiring potential customers, it had obtained the data subject's details by means of a list procured from a third party and that a customer number had been created; however, since a customer number cannot become active unless the Basic Banking Services Agreement has been signed, the data subject's customer number had not become an active account either.

The Board:

• found that, although Law No. 6698 of 07/04/2016 was not in force in January 2016, when the customer number is alleged to have been created, it was clear from the content of the reply given by the bank to the data subject in 2018 that the data subject's data were still held by the controller, and that the bank had therefore engaged in data processing in breach of the Law, since the personal data processing activity relating to the data subject had been carried out without the conditions set out in Article 5(1) and 5(2) of the Law being met,

• that, contrary to Provisional Article 1(3) of the Law, the personal data of the data subject had not been immediately erased, destroyed or anonymised, and that the controller bank had therefore processed the identity and address details, which are personal data of the data subject, in a manner that was also contrary to the general principles in Article 4 of the Law,

and, taking these points into account, reached the conclusion that the bank in question had acted in breach of the obligation under Article 12(1)(a) of the Law to take the necessary administrative and technical measures to ensure an appropriate level of security in order to prevent the unlawful processing of personal data, and decided that an administrative fine of TRY 210,000 be imposed on it under Article 18(b) of the Law.

4. Assessment of Decision No. 2020/ 103

The case underlying the Board's decision is in fact a situation which we frequently encountered before Law No. 6698 entered into force and which controllers showed no hesitation in disclosing. In the case, the bank obtained the personal data of data subjects in the form of a list from a third party and subsequently also processed these personal data. Even though the events took place before the date on which the Law on the Protection of Personal Data entered into force, this does not alter the fact that the personal data were processed unlawfully and the fact that this is unlawful.

Under paragraph 3 of Provisional Article 1 of the Law, “Personal data processed before the date of publication of this Law shall be brought into conformity with the provisions of this Law within two years of the date of its publication. Personal data found to be contrary to the provisions of this Law shall be immediately erased, destroyed or anonymised. However, consents lawfully obtained before the date of publication of this Law shall be deemed to be in conformity with this Law, provided that no declaration of intent to the contrary is made within one year”.

In the case, the controller ought to have immediately erased, destroyed or anonymised the personal data of the data subject that had been processed in breach of the provisions of this Law. By failing to do so, the controller not only acted contrary to the general principles of the Law but also failed to take all the technical and administrative measures necessary to ensure an appropriate level of security in order to prevent the unlawful processing of personal data, and continued to process data unlawfully.

In a decision that is well founded, the Board imposed an administrative fine on the controller on the ground that it had not taken all the technical and administrative measures to ensure an appropriate level of security in order to prevent the unlawful processing of personal data.

However, as we have also stated in our earlier writings, where the Board sees that an offence has been committed it must file a criminal complaint. The summary of the decision does not state whether or not the bank's obtaining of the personal data from the third party was lawful. When the summaries of decisions are drawn up, such important points must not be left out. Instead, the Board, which seeks to shape practice, gives rise to further question marks through its decisions. If, in the case underlying the decision, the manner in which the bank obtained the personal data constitutes one of the offences relating to personal data regulated in Art. 135-138 of the Turkish Criminal Code (TCK), a criminal complaint must be filed. Indeed, the members of the Board are public officials and, pursuant to Article 279 of the TCK, are under an obligation, where they learn in a case that comes before them that an offence has been committed, to report this without delay to the competent office of the public prosecutor.

Conclusion

Although four years have passed since the Law entered into force, some controllers are, regrettably, waiting for the Board to impose an administrative fine on them before they comply with the data protection legislation. The process of compliance with the data protection legislation is regarded as a complete waste of time.

As in the second of the Board's decisions that we have assessed, the fact that personal data were already being processed before the date on which the Law was published does not constitute a reasonable justification for their being processed unlawfully. Both the Law and the Board require absolute compliance with the legislation. In this respect controllers must act in their activities in accordance with the law and the rules of good faith. Just as a controller must carry out data processing lawfully, it must also reply to the data subject's applications in a lawful manner. In its replies the controller must tell the data subject the truth. If it satisfies the data subject at the stage of the application, the controller will neither be the subject of a complaint nor face the risk of an administrative fine.

We must also point out that we do not regard it as a major shortcoming that the controller's failure to reply to an application made to it has not been made subject to a sanction. For in that case the data subject has the right to lodge a complaint with the Board, and it is possible for the unlawful practices to be established and a sanction to be imposed on the ground that the technical and administrative measures have not been taken.

We are of the opinion that the Board ought to be more careful when drafting the summaries of its decisions. The summaries of decisions are not always read by persons who specialise in data protection law. When decisions are read by non-specialists, ambiguities in the summaries cause further confusion and thereby give rise to further problems in practice. At times projects are carried out under the name of compliance that have nothing to do with the provisions of the Law. The second decision we have examined is yet another example of the Board's drafting the summaries of its decisions incompletely, which we have criticised before. The decision contains no assessment of whether or not the bank obtained the personal data from the third party unlawfully.

In a manner that we fail to understand, the Board refrains from filing criminal complaints. Yet the members of the Board, who are public officials, are under an obligation to report offences pursuant to Article 279 of the Turkish Criminal Code. Just as we criticised the Board's attitude in our earlier writings, we consider it necessary to criticise it in this one as well. Where the Board learns that an offence has been committed, it must file a criminal complaint with the Office of the Public Prosecutor.

It must never be forgotten that the protection of our personal data will be secured when all concerned work in cooperation. Just as controllers should not be cowed by penalties, so controllers must exercise the utmost care in complying with this legislation, which was created so that data may continue to belong to the data subject. On the other hand, the Board, which endeavours to ensure lawfulness, must not itself act unlawfully either.

Footnotes

  1. Assoc. Prof. Dr., member of the teaching staff in Criminal Law, Criminal Procedure Law and IT Law, Faculty of Law, Istanbul Aydın University / Attorney-at-law, [email protected], ORCID: 0000-0003-4034-5436 ↑
  2. Trainee lawyer, Istanbul Bar Association; Master's student, Department of Public Law, Institute of Social Sciences, Marmara University, [email protected] ↑

Download PDF (in Turkish)

Related publications