Introduction
This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.
The Personal Data Protection Board, which is charged with performing the duties and exercising the powers conferred on it by Law No. 6698 on the Protection of Personal Data (KVKK) and other legislation on the subject, is accordingly also empowered to decide on the complaints of those who claim that their rights concerning personal data have been infringed. In addition, the Board will examine, upon complaint or of its own motion where it learns of an alleged infringement, whether personal data are being processed lawfully in matters falling within its remit, and will take measures in this regard where necessary.
Now that a general framework for personal data protection law has been drawn with the entry into force of the KVKK and the adoption of the other legal instruments on the subject, the Board, relying on these duties and powers, decides concrete cases and shares with the public, in summary form, those it considers necessary. The subject of this article is the Board’s decisions of various dates published on 17 July 2019. I will consider the decisions particularly in terms of the questions and problems in the concrete case and the Board’s perspective on them, and will conclude with an assessment setting out my views and proposals.
Full text
This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.
Assoc. Prof. Dr. Murat Volkan Dülger*
The Personal Data Protection Board, which is charged with performing the duties and exercising the powers conferred on it by Law No. 6698 and the other legislation on the subject, is accordingly also competent to decide on the complaints of those who claim that their rights relating to personal data have been infringed. In addition, upon a complaint, or of its own motion where it learns of an alleged infringement, the Board will examine whether personal data are being processed lawfully in matters falling within its remit and, where necessary, will take measures in this regard.
Now that a general framework for the law on the protection of personal data has been drawn with the entry into force of the Law and the creation of the other legal instruments on the subject, the Board, relying on these duties and powers, decides concrete cases on the matter and shares with the public, in summary form, those which it considers necessary. The subject of this article is the decisions of various dates which the Board published on 17 July 2019. I shall examine the decisions in particular in the light of the questions and problems arising in the concrete case and the Board’s perspective on them, and shall finally assess them and conclude with my views and suggestions.
1. Summary of Decision No. 2019/157 of 31/05/2019 of the Personal Data Protection Board on whether a corporate e-mail service may be used via Google (gmail) while retaining the same extension
As cloud computing services have, with advancing technology, become more economical, more secure and easier to use, particularly in the private sector and in large institutional structures such as foundation universities, information technology infrastructure, the backing-up of data and communication by means such as e-mail have all come to be provided through cloud computing services.
One of the most important features of cloud computing is that those who provide this service are generally global companies such as “Google” or “Microsoft”. As a consequence of this structure, both the products through which they provide the service, such as servers, and their employees may be located in various centres around the world. For example, when an e-mail address with the extension “gmail” or “hotmail” is used, the e-mail in question (which in all likelihood also contains a large amount of personal data) may be hosted on a server which belongs to, or is leased by, this company and which operates anywhere in the world. This mode of operation stems from the particular structure of global information technology companies and of cloud computing services.
Until Law No. 6698 entered into force, there was no problem in our country with regard to this mode of operation. For, since there were no rules at all, every kind of personal data could be recorded, processed and transferred. Once the Law entered into force, question marks began to arise in people’s minds because Article 9 made transfers abroad subject to certain strict conditions. The first of these questions was whether the use of cloud computing services, in particular obtaining corporate electronic mail accounts from foreign companies providing cloud computing services, would be regarded as a transfer of data abroad. In various discussions held with the KVK Board and in response to questions addressed to it, it had been stated that the Board had no discretion in this matter, that the wording of the Law was clear and that uses of this kind had to be regarded as a transfer of data abroad.
The second question was how, if this were regarded as a transfer abroad, the use of these services could be continued. For these services were structures to which the user companies had become thoroughly accustomed, on which the entire corporate operation had been built and which yielded extremely favourable results in cost-benefit analyses.
At the time when these questions were being asked and the debates were taking place, I too said repeatedly that cloud computing would be regarded as a transfer abroad, that companies had to take precautions against this, and in particular that the companies offering these services made a considerable profit from this business and absolutely had to take measures in this regard in order not to lose those earnings. However, nothing was done in this regard, and the expectation arose that the Board would either not regard cloud computing as a transfer abroad or, if it did, would announce the list of safe countries, so that a solution to this problem would somehow be found by obtaining cloud computing services from countries on the list of safe countries.
And at last “doom day” arrived! Not only was the Board unable to announce the list of safe countries “for reasons beyond its control”, but it also regarded the procurement of an electronic mail service, which is a part of the procurement of services over cloud computing, as a transfer of data abroad. The Board decided:
“that, since where the infrastructure of the G-mail e-mail service belonging to the Google company is used the e-mails sent and received will be kept in data centres located in various parts of the world, in such a case personal data will have been transferred abroad, and that controllers shall carry out the practice in question in accordance with the provisions of Article 9, entitled “Transfer of personal data abroad”, of Law No. 6698 on the Protection of Personal Data (the Law)”.
Although the application made to it concerned electronic mail only, the Board also slipped in its view on the hosting of data and clarified this matter as well:
“that storage services procured from controllers/processors whose ‘servers’ are located abroad shall likewise be carried out in accordance with the provisions of Article 9 of the Law”.
By so deciding, it has, for the time being, put an end to this debate.
Accordingly, where an electronic mail and/or data storage service is obtained by making use of cloud computing services, this is, according to the KVK Board, regarded as a transfer of data abroad, and in order for this to be done the conditions for the transfer of data abroad set out in Article 9 of Law No. 6698 must be complied with. In that case, either explicit consent must be obtained one by one from the data subjects who use these services, or an undertaking must be obtained from the company providing the service and an application for authorisation made to the KVK Board. Frankly, I think that obtaining explicit consent from the data subjects one by one is very difficult, and that it is not really possible in the short term for the Board to grant approval, since the principle of reciprocity cannot be satisfied.
I therefore think that this decision will have significant effects on companies and organisations in terms of corporate operation (a change of infrastructure), in economic terms (the emergence of additional and higher costs) and in terms of efficiency (the loss of productivity that will arise while employees get used to the new systems). And I cannot foresee how this burden is to be borne.
From the standpoint of the law, however, a rule is a rule! Indeed, the Board applied the rule, which was the material it had to hand; in any case, with the rule being what it is, it would frankly have been naive to expect anything different. What, then, is to be done? To produce, in the popular phrase of recent days, “domestic and national” solutions in the globalising field of information technologies. Yet I think that producing such a product is not at all easy either, particularly in terms of cost. If we look at the full half of the glass, although this situation may strain the business world at the outset, in the medium term it may enable our country to develop in this field and an economic value to emerge.
A solution that can be produced in the short term in this matter is to make the ending of the electronic mail address the corporate name and to obtain this from a domestic company; this is a situation that we frequently encounter. However, the domestic companies which sell this service generally in fact sell the products of large global companies in return for a certain commission and do not themselves provide a real service or product. The existence of such an arrangement therefore does not affect the outcome: the institutions are given the right to use an extension in this way, but the operations are in fact carried out over the servers of the foreign company in the background which provides the service. It is also clear that resorting to methods of this kind is an attempt to circumvent the law and is unlawful.
In conclusion, it appears that this decision will shake things up in our country’s IT sector. This decision is therefore bound to give rise to much further debate and criticism.
2. Summary of Decision No. 2019/159 of 31/05/2019 of the Personal Data Protection Board on the sending by an asset management company of multiple messages on the same subject to the data subject
The decision which the Board has given on debt collection by “sms” by an asset management company is quite interesting. The conclusions that emerge from the decision are, in outline, as follows:
• A request received from the data subject must without fail be answered by the controller within 30 days, satisfactory answers must be given to all of the questions asked, and the controller must document that the reply was given within the time limit and that its content was complete. Indeed, since these points had been complied with in full in the application, the Board decided that there was no matter on which action was to be taken in this respect.
• In the event of the assignment of a claim under the Code of Obligations, the debtor’s personal data may, pursuant to Article 5(2)(e) of Law No. 6698, be processed without the explicit consent of the data subject in order for the new creditor to collect the claim. Accordingly, in the event of the assignment of a claim, the processing of the debtor’s data falls within the scope of the ground of justification that the processing of data is necessary for the establishment, exercise or protection of a right.
• However, as is well known, in debt collection, or even where there is no collection proceeding, in reminders of debts such as loans, credit cards and so on, messages are sent or calls made to debtors continually and through every channel, even before the due date has arrived. In some cases this even reaches a level amounting to harassment. The Board, too, identified this situation and found that it was an abuse of a right and therefore constituted a breach of the principle, laid down in Article 4(2)(a) of the Law, that the processing of personal data must be in conformity with the law and the rules of good faith.
• An important detail of the decision is that, proceeding from this, the Board decided, on account of the failure to take the measures laid down in Article 12(1)(a) of the Law for preventing the unlawful processing of personal data, namely the necessary technical and
administrative measures, to impose an administrative fine of TRY 20,000 on the controller. What this means is that the Board considers the processing of debtors’ personal data by an asset management company or by a law office engaged in debt collection to be lawful. However, this processing must not reach the level of harassment. Particularly in institutional structures such as asset management companies, these calls and the sending of messages are carried out by information systems in accordance with a certain system. The Board, taking precisely this point into account, found that the fact that the automatic sending of “sms” was carried out with this frequency was attributable to the failure to take the necessary technical and administrative measures. Accordingly, in this or similar matters, controllers or processors who send notifications to individuals are obliged to take the necessary administrative and technical measures to ensure that this is done with reasonable frequency.
I think that this decision constitutes an important example of the cases in which data may be processed without the explicit consent of the data subject pursuant to Article 5(2)(e) of Law No. 6698, and that it is, on the other hand, an important decision in that it shows that, not only with regard to debt collection but in many areas of daily life, and especially in the matter of advertising, the sending of “sms” or e-mails and the like very frequently, in a manner amounting to harassment, may constitute a violation of the Law even where it is based on a right.
3. Summary of Decision No. 2019/162 of 31.05.2019 of the Personal Data Protection Board on the sending by a joint-stock company (the controller) of commercial electronic messages without the explicit consent of the data subject
This decision, too, concerns a matter which we frequently encounter in our daily lives, on which the Board has ruled before and which has given rise to debate. In its decision the Board rightly stated that the use of a person’s mobile telephone number for the sending of messages for advertising purposes is a personal data processing activity. It stated that, in order for this data processing to be carried out, one of the grounds for data processing in Article 5 or Article 6 of the Law, depending on the nature of the data, must be present.
The first conclusion that emerges from this is that, where data are processed in order to send advertising, the existence of explicit consent is not necessarily required for this. It will be recalled that, in the decision it had previously given on this matter, the Board based the unlawfulness on the absence of explicit consent. Now, however, it neither refers to its earlier decision nor goes beyond a general expression, merely indicating the article numbers. This makes me wonder whether a way has been opened for the sending of commercial advertising to be regarded as lawful where one of the conditions for processing other than explicit consent is present. Indeed, in the GDPR there are cases in which the sending of commercial advertising without obtaining the consent of the data subject is regarded as lawful in certain circumstances.
In fact, as those concerned with the subject know, the matter of sending commercial electronic messages is contained in the Law on Electronic Commerce and is regulated by the Ministry of Trade in a separate regulation. However, in the resolution of principle which it adopted in 2018, the KVK Board, too, stated that, from the standpoint of the law on the protection of personal data, explicit consent must be obtained in accordance with Article 5(2) of the Law in order for the sending of commercial advertising to be carried out lawfully. The reason for this is that Directive 2002/58/EC, which is the instrument on commercial advertising messages in the EU, was issued in line with Directive 95/46/EC and after that Directive. In Turkey, on the other hand, the TTK provisions and the regulation drawn up on the basis of the Directive in question entered into force, and only afterwards did the KVKK become law. These are therefore not instruments that differ from one another but instruments that complement one another. Indeed, the approach of the KVK Board is to the same effect.
Ultimately, however, the Board needs to clarify, with regard to the processing of personal data for the purpose of sending commercial advertising, (i) whether only the condition of the explicit consent of the data subject contained in Article 5(2) of the Law is required or (ii) whether the other conditions for data processing contained in Articles 5 or 6 of the Law are also accepted as a ground of justification in this respect. In this respect the matter still remains ambiguous.
4. Summary of Decision No. 2019/81 of 25/03/2019 and Decision No. 2019/165 of 31/05/2019 of the Personal Data Protection Board on the performance by controllers offering gym services of entry and exit checks on their members by processing biometric data
The collection of certain information by establishments offering a particular service and by workplaces at the time of entry to and exit from the premises is an increasingly widespread practice. Although this is done by almost every controller, whether the information is indispensable for the controller, whether it requires the explicit consent of the data subject and, lastly, whether the establishment in question may be entered if the data subject does not give explicit consent is in itself a contentious matter. This point is undoubtedly of even greater importance with regard to special categories of personal data. To take the simplest example, although it may be acceptable to take identity and contact information such as name, surname and telephone number for the issue of a visitor’s card on entry to a workplace, it is not possible to take information on health or religion.
In this decision, the practices of collecting and processing biometric data, which are becoming increasingly widespread even though such data are a special category of data, were addressed. The disclosure of personal data that are not of a special category without being based on any purpose was also assessed. In the concrete case there are two separate controllers offering gym services which had switched to a hand and palm scanning system for the entry and exit checks on their members. As if that were not enough, information such as the passport-style photograph and the time of the last visit of the registered members was also displayed on a TV screen which everyone could see. The doubts felt as to whether this information was being kept securely were finally brought before the Authority.
By first endeavouring to arrive at a definition of biometric data, which is not regulated comprehensively in the Law, the Board did something very apt from the standpoint of the logic of building case law. The first point to which I wish to draw attention here is that the Board has, for the first time in the decisions it has given, referred to the provisions of the GDPR. We thus understand that the Board also takes the provisions of the GDPR into account and draws on those provisions when reaching its decisions.
It is clear that, compared with the data protection legislation of the European Union and of European countries, national legislation is deficient as regards rules on personal data which have emerged with the development and spread of technology, such as biometric data. This situation must improve as the use of technologies for the collection and processing of biometric data becomes widespread here too. I think that this decision is important in these respects as well.
a. Biometric data
• From the standpoint of the GDPR:
The GDPR defines biometric data as “personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data”. As in the Law, the processing of these data has been made subject to stricter conditions. It is also stated that the Member States may introduce additional conditions.
The Board also referred to Recital 51. According to this, the processing of photographs is not directly classified as the processing of biometric data; it will be regarded as the processing of biometric data when they are processed through a specific technical means allowing the unique identification or authentication of a natural person. What is touched upon here, therefore, is the certainty of biometric data when it comes to identifying and authenticating a person. Although this certainty cannot, for the present, be directly criticised, I think that technology will reach a level at which even biometric data can be copied. Naturally, biometric data technology will develop along the same lines as well. Accordingly, every piece of information that makes us who we are is contained in biometric data and inevitably enables us to be identified.
• From the standpoint of the Council of State:
The Board referred to the decision of the Council of State on the stay of execution of the relevant statutory provision which made it compulsory to undergo biometric identity verification1.
In the decision by which it stayed execution, the Council of State described biometric data as “identity verification techniques which are carried out by means of measurable physiological and individual characteristics and which can be verified automatically”. It also stated that methods such as fingerprint recognition, palm scanning, hand geometry recognition, iris recognition, facial recognition, retina recognition and DNA recognition fall within this scope.
Accordingly, the identity verification practice carried out by the gym in the concrete case by scanning the hand and fingerprints must be regarded as falling within the scope of the processing of biometric data.
b. Application of the principle of “being relevant, limited and proportionate to the purposes for which personal data are processed”
to the concrete case
Article 4 of the Law lays down the procedures and principles with which controllers must comply, without any exception whatsoever, in the personal data processing activities they carry out. As far as is relevant to the concrete case, the personal data involved in the processing must be relevant, limited and proportionate to the purpose of the processing.
According to the Board, what is to be understood from this principle is the following:
• that the data processed must be suitable for achieving the purposes determined,
• that it requires the avoidance of the processing of personal data which are not related to the achievement of the purpose or which are not needed,
• that data must not be processed with a view to meeting needs which may possibly arise later.
Accordingly, a reasonable balance must be struck between the processing activity and the purpose which the controller wishes to achieve: data processing must be to the extent that will achieve the purpose! It must not be forgotten that this purpose must in any case, according to another principle, be “specified, legitimate and explicit”. In this context, the controller will not be able to process personal data which are not necessary for the processing activity to be carried out; the personal data which it processes must be limited and proportionate to the purpose.
The fact that compliance with the general principles is not subject to exceptions means, in turn, that no other circumstance present in the concrete case can render non-compliance with the principles lawful. Moreover, having regard to the fact that the conditions for the processing of special categories of personal data are determined exhaustively by the Law and that there is no condition which could constitute a legal basis for such processing at the entrances to a gym, the explicit consent of the data subject will not legitimise a processing activity which is not provided for in the Law either. For example, the controller’s defence at this point that the explicit consent of the data subject was obtained will be of no significance whatsoever. For the general principles relate, far beyond individual interest, to the societal dimension of data protection law, and they constitute the philosophy of the protection of data.
Besides, in such a situation it is not always possible to say that the conditions for explicit consent have been met. The explicit consent of the data subject must relate to a specific matter and be based on information, and must also have been declared of his or her own free will. The data subject must be certain that he or she will not be exposed to any sanction or different treatment if he or she does not give explicit consent, and the consequences of the choice made must not restrict the freedom of choice. For this reason, as is also apparent from the decisions which the Board has previously given, making the provision of a product or service conditional on the giving of explicit consent vitiates the declaration of explicit consent.
The fact that the controller provided in the membership contract that a failure to give explicit consent to the hand and finger scanning system was a just cause for termination means that the explicit consent to be given to the processing of personal data was made subject to a condition and was expressly made subject to a sanction.
On this matter the Board referred to the decision of the Council of State concerning an administrative authority using a facial scanning system2 and to its decisions3 to the effect that biometric data such as those of a fingerprint or facial scanning system fall within the scope of the right to respect for private life even if they are in the public sphere, and that there must be a safeguard that they will not be used in another way in the future.
In addition, mention was made of the example, relating directly to the concrete case, given in the report4 prepared on the subject by the Article 29 Working Party. According to this, the storing and processing of the fingerprints of all members and staff for the entry of gym members to the gym and their access to the related services is processing that is disproportionate to the need to facilitate access to the club and to manage memberships. It is possible to meet the need in question by using different methods instead.
In the light of the information and decisions set out above, the Board assessed the use of a hand and fingerprint scanning system for entry to the gym as contrary to the principle that personal data must be relevant, limited and, in particular, proportionate to the purpose for which they are processed. Indeed, when the checking of members and the provision of security could be ensured by practices such as drawing up a list of members, using an electronic card system and having an adequate security system at the entrances and exits, recourse to the members’ biometric data is unlawful. In a data processing activity, whichever types of personal data and purposes of processing mean a lesser interference with the data subject’s right to the protection of personal data in order to meet the purpose which the controller wishes to attain, those data and that purpose of processing must be used. Every item of data taken and every purpose stated beyond this is contrary to the principles of data protection law and amounts to an unjustified interference with the fundamental rights and freedoms of the data subjects.
c. Decision
In conclusion, the sanctions on which the Board decided are as follows:
• an administrative fine on account of the unlawful acts relating to the principle that personal data must be relevant, limited and proportionate to the purposes for which they are processed and to the processes for obtaining explicit consent,
• an administrative fine on the controller for failing to take the necessary technical and administrative measures within the framework of the Board’s Decision No. 2017/62 of 21/12/2017 on “the Protection of Personal Data in Service Areas such as Counters, Ticket Windows and Desks”,
• the instruction of the controller to the effect that the gym is to provide alternative means and that the biometric data practice is to be stopped as a matter of urgency,
• the instruction of the controller to the effect that the biometric data which have been processed and retained to date, including those transferred to third parties, are to be disposed of as a matter of urgency in accordance with the provisions of the Law and of the Regulation on the Erasure, Destruction or Anonymisation of Personal Data.
5. Summary of Decision No. 2019/166 of 31/05/2019 of the Personal Data Protection Board on the sending, to the telephone number belonging to the data subject, of content not belonging to him or her
The last decision concerns the sending, to the telephone number belonging to the data subject, of content which does not belong to him or her. In the concrete case, the complainant, to whom content not belonging to him had been sent, applied to the controller in this regard, and in its reply the controller explained that the sending in question was due to an error by a member of staff and that the content had been sent to him as a result of an error in 1 digit when an entry was being made for another subscriber. In response, the complainant stated that he had realised that the content in question belonged to his nephew but that his nephew’s number was not similar to his own. In the application made in this context, the data subject requested that the necessary action be taken against the controller.
In the examination which it carried out accordingly, the Board reached the conclusion that, by a single act, a violation had been committed as a result of two different data processing activities. According to this, “the sending to the complainant of the name, surname and service number belonging to the complainant’s nephew” and “the processing of the information on the telephone number belonging to the complainant without relying on the conditions for processing” are contrary to the obligation to prevent the unlawful processing of personal data.
In this context, the Board ruled that an administrative fine of TRY 50,000 be imposed on the controller.
The conduct to which this decision relates was carried out by a lawyer who calls debtors in order to collect a claim. Unfortunately, lawyers who specialise in the field of debt collection make use of every piece of information they can obtain about the debtor and, without regard to who the principal debtor is, may use all the personal data they obtain belonging to the relatives of the person concerned in order to collect the claim. It was upon just such a complaint that the Board, very rightly, gave the decision in question. Lawyers engaged in debt collection must therefore be more careful in this regard. Indeed, following this decision, the Union of Turkish Bar Associations notified the decision by “sms” to all lawyers who are its members and warned them that they must be careful in this regard.
Conclusion
As I have also repeated in my assessments of the decisions published previously, I very much welcome every step taken with regard to the protection of personal data, above all because it will bring development and improvement in the matter. The decisions examined above, for their part, go far beyond being useful merely by virtue of being a step; they are important in terms of quality and outcome.
In order not to repeat what has been stated above, I shall not set out in this part, one by one, the content of the decisions under assessment. I must state, however, that, in terms both of its decision-making technique and of the publication of the decisions given, the Board has put its name to decisions which offer more guidance to us practitioners. The fact that the stage of assessing complaints is carried out comprehensively and that the case has begun to be addressed in detail helps the formation of case law on the subject. In addition, the attempt to support the conclusion reached by also referring in the decisions to the decisions of national and international authorities is important from the standpoint of the quality of the legal assessment. In this way a more detailed assessment can be made and, with previous concrete cases also being taken into consideration, what is right or wrong can be seen better.
That said, I await with interest how the decision on cloud computing in particular will be received in the sector and whether it can be applied without exception.
Footnotes
- Academic / Attorney-at-law. ↑
- 15. Danıştay Dairesi, 2014/4562 E. ↑
- 11. Danıştay Dairesi, 2017/816 E. 2017/4906 (13 Haziran 2017) ↑
- Danıştay İdari Dava Daireleri Kurulu, 2014/2242 E. 2015/4991 K. (19 Temmuz 2018). ↑
- Article 29 Data Protection Working Party, 00720/12/EN, WP193, Opinion 3/2012 on developments in biometric Technologies., 27 Nisan 2012. ↑
Related publications
Dülger, Murat Volkan / Gümüş, Gülçin, Personal Data Protection Law (Kişisel Verilerin Korunması Hukuku), 4th ed., Seçkin Publishing, Ankara, 2026.
Dülger, Murat Volkan, Legislation on Information Technology, Personal Data Protection and Internet Communication (Bilişim, Kişisel Verilerin Korunması ve İnternet İletişimi Mevzuatı), 7th ed., Seçkin Publishing, Ankara, 2021.
Dülger, Murat Volkan, “The Use of Bulk Data and Metadata in Preventive Policing and Intelligence Work from the Standpoint of Human Rights, Personal Data Protection and Criminal Procedure Law” (İnsan Hakları, Kişisel Verilerin Korunması ve Ceza Muhakemesi Hukuku Açısından Önleyici Kolluk Hizmetleri ve İstihbari Çalışmalarda Toplu Veri ve Metadata Kullanımı), conference presentation, 2026.
Dülger, Murat Volkan, “Lawyers' Obligations under the KVKK in the Light of the Board's Decisions” (Kurul Kararları Işığında Avukatların KVKK Yükümlülükleri), conference presentation, 2025.
Dülger, Murat Volkan / Gümüş, Gülçin, “The Right to Be Forgotten”, Essays in Honour of Prof. Dr. Yadigar İzmirli (Prof. Dr. Yadigar İzmirli'ye Armağan), 2024.
