Introduction
This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.
On 18 July 2022 the Personal Data Protection Board (the “Board”) published twelve (12) new decision summaries. As the decision summaries contain views that data controllers need to take into account, we believe it would be useful to assess these decisions in detail in line with Law No. 6698 on the Protection of Personal Data (KVKK) and the other relevant legislation.
Full text
This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.
Murat Volkan Dülger* & Gülçin Gümüş*
On 18 July 2022 the Personal Data Protection Board (“Board”) published twelve (12) new decision summaries. Since the decision summaries contain findings to which controllers need to pay attention, we believe that it will be useful to assess these decisions comprehensively in the light of Law No. 6698 on the Protection of Personal Data (“Law No. 6698”) and the other legal rules on the subject.
1. Unlawful processing of the data subject’s personal data by the controller within the scope of a loyalty programme (dated 05/07/2019 and numbered 2019/198)
The carrying out of data processing activities by controllers within the scope of loyalty card programmes is one of the important issues in the field of the protection of personal data. That is to say, in practice the controller generally asks the data subject for a telephone number or e-mail address and thereby enrols the data subject in the loyalty card programme it has set up. In a data processing activity carried out in this way, the concept of explicit consent is of the utmost importance. In the case that came before the Board on this subject, the data subject claimed that a loyalty card had to be used in order to benefit from special discounts applicable to certain products in the controller’s shop, that personal data were requested for membership of the loyalty programme and for obtaining the card, and that explicit consent was imposed as a condition.
The controller, whose defence was obtained following the report made against it, stated that persons wishing to join the loyalty programme were presented with an explicit consent text in conformity with the legislation and that the obligation to inform had been fulfilled. Stating that persons who did not wish to give explicit consent for the loyalty programme were also able to shop in the shop and on the website, the controller argued that, because the special discounts applicable to loyalty card holders are below the market price of the product or service and constitute an additional benefit, obtaining the person’s explicit consent did not constitute a precondition for benefiting from a product or service.
Maintaining its view that the offering of an additional benefit, by way of discounted prices specific to campaigns and the loyalty programme in respect of the products and services offered in the controller’s shop and on its website, does not make explicit consent a precondition for benefiting from a service or product, the Board decided that there was no action to be taken against the controller.
An important point to be noted in the decision summary is that the Board, referring to European Union legislation, did not treat the question “whether or not negative consequences will arise if it is not given” as a criterion in determining whether explicit consent had been duly obtained. Indeed, in the period when the Law was first published, the idea that negative consequences would arise for the data subject if explicit consent was not given was a source of hesitation. Yet this point cannot be accepted as a criterion in itself for finding that explicit consent was not duly obtained.
As far as loyalty programmes are concerned, a controller may wish, within the framework of its commercial activities, to offer additional benefits to some of its customers. While a supermarket chain does this by means of a store card which it matches with the data subject’s telephone number, a company selling on a website may grant an additional discount on condition that the customer subscribes to the newsletter. Since this processing activity does not fall within any of the legal grounds but is nevertheless in conformity with the data protection principles, it may be carried out on the basis of the data subject’s explicit consent. However, the data subject may not wish to benefit from these additional discounts and may not give explicit consent. In that case the possibility of benefiting from the services offered by the controller will continue. The adverse consequence arising for the data subject is the additional benefit offered by the controller. And not benefiting from the additional benefit does not mean that explicit consent has been made a precondition of the service. An important step has therefore been taken in that the Board’s decision has established that, when the data subject’s explicit consent is requested, there is no need for the reservation that “no negative consequence will arise whatever happens”.
2. Unlawful processing of the data subject’s personal data by the controller company with which his or her employment contract had ended (dated 16/12/2021 and numbered 2021/1258)
This decision of the Board is extremely important as regards which obligations controllers must not neglect, particularly in relation to employees. These points need to be identified, and controllers with the same shortcomings need to remedy them. In the case giving rise to the decision, the data subject, who had left the controller company, wished to make an application to the controller company concerning his or her personal data, but stated that there was no application form on the subject and that he or she had not been informed of the means of applying either. In addition, the data subject claimed that the controller company, which had no privacy policy on its website, had not lawfully fulfilled its obligation to inform, had processed his or her special categories of personal data without obtaining explicit consent, had transferred his or her personal data abroad without his or her explicit consent, and had not taken sufficient technical and administrative security measures for personal data.
In its written defence the controller stated that the means of applying in relation to personal data and the manner of making an application were shown in the information notice on the social network address used by the company’s employees; that questions amounting to applications had been answered in conformity with Law No. 6698; that the obligation to inform had been fulfilled by means of the employment contract; and that the personal data of the company’s employees were also protected in conformity with the Law. The company further stated that the fingerprint and facial recognition system was used for company security in conformity with the Law and that technical and administrative security measures were in place for the protection of the personal data of both employees and customers.
Although the controller, in respect of each of the data subject’s complaints, defended itself to the effect that the situation was in reality not as alleged and that it had acted lawfully, these defences were to a large extent not accepted by the Board, in particular because they had not been proved. These points may be summarised as follows:
• The obligations to inform and to obtain explicit consent cannot be fulfilled by a clause added to the employment contract: This is one of the mistakes we encounter very frequently in practice. The controller company thinks that, by a clause which it adds to the employment contract, it will have fulfilled its obligations of information and explicit consent towards the data subject. Yet the minimum requirements of these obligations are laid down by the legislation, and the fact that a clause to this effect has been added to the contract does not mean that the clause is valid. It is therefore extremely important, above all, that employers avoid this course of conduct. The Board stated that, whereas under Art. 5(1)(f) of the Communiqué on the Principles and Procedures to be Followed in Fulfilling the Obligation to Inform (“Communiqué”) the obligation to inform and the obtaining of explicit consent must be carried out separately from each other, in the case at hand a mixed text had been prepared which did not satisfy the minimum elements that must be contained in information notices and explicit consent texts, and that the obligation to inform had not been fulfilled in the proper manner.
• The processing of biometric data at workplace entrances and exits amounts to disproportionate processing of personal data: One of the matters on which the Board has ruled consistently from the outset is whether biometric data may be processed at workplace entrances and exits. The Board is of the opinion that the inclusion in the employment contract of the explicit consent text required for the controller to be able to process biometric data does not satisfy the requirement that explicit consent be obtained by free will, given that the data subject cannot start work without signing the employment contract. Moreover, according to the Board, while company security can be ensured by other lawful means than the processing of biometric data, the processing of special categories of personal data is a disproportionate interference. Indeed, in its earlier decisions it had stated that this security could also be provided by means such as electronic cards. Similarly, for employees to enter the workplace using passwords assigned to them individually
is a reasonable method. Indeed, it must not be forgotten that the right to the protection of personal data is a fundamental right and freedom; that each processing activity is in essence an interference for which a ground of justification is required; and that, consequently, in activities involving the processing of personal data, processes must be applied in the manner that interferes least with this right. Accordingly, even if the controller employer has obtained lawful explicit consent, the processing activity to which the explicit consent relates is contrary to the principle of proportionality in Art. 4 of the Law. Indeed, the Board decided to this effect and resolved that the controller be instructed, in addition to putting an end to the unlawful processing of biometric data, to destroy the data in question pursuant to Art. 7 of the Law and the Regulation on the Erasure, Destruction or Anonymisation of Personal Data (“Destruction Regulation”) and to inform the Board thereof.
• The controller employer must prove by concrete information and documents that it has fulfilled its obligations in the field of the protection of personal data: We see that this is one of the most important reasons why the Board did not give credence to the controller employer. On reading the text of the decision, it is seen that the controller was unable to submit documents supporting any of its defences. For example, it attached an information notice, claiming that it had been signed by employees, but this information notice had not been signed by the data subject. Similarly, although it was stated that the documents which must appear on websites had been published on the website, the examination carried out by the Board established that these obligations had not been fulfilled. While we do not know whether the company concerned in the case at hand had really carried out work in order to fulfil its obligations under Law No. 6698, this is an extremely important matter in that controllers must be in a position to defend themselves in the face of any report or complaint. It is always possible for data breaches to occur in various ways; either the human factor or information technology tools play a part in this. What matters, however, is that, when faced with such data breaches, companies are able to demonstrate that they have taken all the measures in their power and have fulfilled all the statutory obligations incumbent on them. Indeed, the Board decided to impose an administrative fine of TRY 125,000 on the controller company, which in the case at hand had breached the obligation to take the technical and administrative measures required for the protection of personal data.
3. Processing of the data subject’s bank data by an insurance company (dated 16/12/2021 and numbered 2021/1262)
This decision of the Board is extremely important in that it clarifies whether an application to the controller may be made through a representative and whether a special authorisation may be required in that relationship of representation. In fact, there was no doubt that an application could be made to the controller by means of a power of attorney. However, there was a tendency, particularly on the part of companies attaching great importance to data security, to require a special authorisation in that power of attorney. By this decision of the Board, the way has been clearly closed to requiring a special authorisation for applications to the controller. In the case giving rise to the decision, after the data subject’s bank details had been unlawfully processed by the controller insurance company even though they had not been shared with it, the data subject, through his or her representative, requested information on the matter from the controller. The data subject also requested the controller to erase or destroy his or her personal data, but this application was left unanswered on the ground that the power of attorney contained no special authorisation.
In its written defence the controller stated that, for the rights set out in Art. 11 of the Law to be exercised by a representative, there must be a power of attorney containing a special authorisation. It argued that, because the data subject’s representative held a general power of attorney, the complaint lodged with the Board had to be rejected on the ground that a complaint cannot be lodged with the Board before the remedy of applying to the controller has been exhausted. On the other hand, the controller stated that the sharing of information in question had taken place for the policies issued for the data subject by the Bank acting as agent, and that the data subject’s bank details held in the company’s records had been processed in order to comply with the decision of the Consumer Arbitration Committee that payment be made to the data subject for losses covered by the motor own-damage insurance policy.
The debate in practice and in legal scholarship over a power of attorney containing a special authorisation or a general authorisation as a requirement for a third party to be able to make a request on behalf of the data subject has been clarified by this decision of the Board.
The Board decided that the controller be warned not to require a special authorisation in the powers of attorney of legal representatives, and that an instruction be issued to the controller to remove the wording requiring a special authorisation in the legal representative’s power of attorney from the application form, the information notice and the other documents on the protection of personal data prepared by the controller and to inform the Board thereof, and, pursuant to Art. 6 of the Communiqué on the Principles and Procedures for Applications to the Controller, to reject applications with a statement of reasons.
As regards the fact that the data subject’s personal data are being processed, on the other hand, the Board is of the opinion that the bank details were processed in accordance with the conditions for data processing. For, apart from the fact that the insurance contract between the data subject and the controller continues, the controller is required to retain the personal data by virtue of its obligation. Since, in accordance with Art. 7 of the Law, the reasons requiring the processing of the data subject’s data continue to exist, no unlawfulness was found in the failure to comply with the data subject’s request for the erasure or destruction of the personal data.
Under Art. 504(3) of the Turkish Code of Obligations, the acts which a representative cannot perform in the absence of a special authorisation are listed exhaustively. The cases in which a special authorisation is required for a transaction to be carried out on behalf of a person are specified in the relevant legislation in Turkish law. Nor does Law No. 6698 contain any rule to the effect that a special power of attorney is required for data subjects to make an application through their representatives. Indeed, in the announcement it had previously published on the subject, the Board used only the expression “by power of attorney” for the application and gave no explanation concerning a special authorisation. That being so, leaving the data subject’s application without result on the ground that the power of attorney contains no special authorisation would amount to “making it more difficult for the data subject to apply to the controller and to exercise his or her rights”. For this reason, unless the Board makes some further statement on the subject, applications made with a general power of attorney must be accepted.
4. Processing of data subjects’ data by companies developing and selling car rental software, and the creation of a blacklist programme enabling these data to be shared among car rental companies (dated 23/12/2021 and numbered 2021/1303)
The data processing activities carried out by car rental companies are for the most part controversial. The question whether or not such companies are controllers and the processing of a very large amount of personal data belonging to a great many different persons are the basic reasons for this. In this decision too the Board made a detailed assessment. The subject of the decision is the creation, by producers and sellers of car rental software, of a blacklist programme that makes it possible for data subjects’ personal data to be shared among car rental companies. Different companies using the same software are also able to learn the personal data of the customers concerned from this blacklist pool without their explicit consent. Following the report in question, the Board opened an examination of its own motion.
The defences sent to the Board in response to the information requested by the Board from the controllers stated, in general, that the companies producing car rental software had written the software programmes in question so that car rental firms could carry out their activities, and that the information required for car rental contracts and the mandatory information requested by public institutions and organisations were recorded in the software.
In this decision, as in its other decisions concerning car rental companies, the Board examined the matter in detail and from different angles. These examinations may be summarised as follows:
• Assessment of whether car rental companies and car rental software companies are controllers: In the examination it carried out in this respect, the Board drew on the criteria as to which matters in a data processing activity may be decided by the controller and which by the processor. For this reason, the decisions to be taken by the controller and by the
processor were set out, and it was stated that the controller would be determined accordingly. It must be said, however, that the Board is not clear in its assessments concerning the making of this determination and is in some respects inconsistent. Nevertheless, the Board’s assessments on the subject are, in summary, as follows: (i) within the framework of a data processing activity, car rental companies and car rental software companies are joint controllers. It should be noted at this point that, as in its earlier decisions, the Board accepts the institution of the “joint controller”, which is not directly regulated in Law No. 6698 but is found in the GDPR (ii) the Board is further of the opinion that it is again the car rental firms that will be responsible for the fact that the data which car rental firms are obliged to keep have been entered incorrectly or incompletely or have not been entered at all, (iii) the software companies, which may be regarded as joint controllers together with the car rental firms in this process, bear no responsibility.
In conclusion, the Board did not rely solely on the criterion of who first obtained the data in determining the controller, and announced its decision that a person who, in the later stages of the processing activity, acts like a controller in relation to the personal data in question will be bound by the obligations of the controller under the Law. Although by this assessment the Board has created an area whose boundaries are not defined, we must state that we agree with this stance, given that the matter varies according to the specific circumstances of each individual case.
• On software companies providing their services by means of a cloud technology infrastructure: Under this heading a number of findings were made concerning the online service which the software companies provide to the car rental companies. Accordingly, the software companies provide their service to the car rental companies as a platform and, as is inherent in SaaS, the type of cloud service used, the management of the database and of the software lies with the software company. The software companies assign users with “admin” (administrator) rights so that technical support and development can be provided at the car rental companies where necessary. The car rental companies have no authority to interfere with the software code (to change its functions); they have only an administrative authority limited to content.
• On objecting to an adverse outcome and on profiling: The automated processing of personal data in order to predict an individual’s subsequent behaviour by monitoring his or her conduct has given rise to the concept of “profiling”. What is meant here is that a profile of the monitored individual is drawn up and that his or her subsequent behaviour can be predicted to a large extent. For example, it may be predicted that an individual who, on certain days of the week, goes from Beşiktaş to Fulya to exercise at 17:30 after work will set out for exercise again on Wednesday, and a profile to that effect may be drawn up. In this way, before the individual has even entered a destination, the application on his or her telephone will, at this hour of traffic, automatically
display a notification on the quickest way to get to Fulya. It must therefore be accepted that, as a result of profiling, the individual’s personal data are processed intensively.
Since the present case involves a program that makes it possible to create a blacklist, the concept of profiling must necessarily be addressed as well. Indeed, the Board gave a very detailed explanation under this heading. According to the Board, although an individual’s personal data are processed through profiling, this does not always have negative consequences; the creation of individuals’ profiles up to a certain point, in a manner that does not threaten their fundamental rights and their security, should be regarded as reasonable. The two fundamental points requiring attention here are that special categories of the individual’s personal data may be accessed through profiling, and that, as a result of an erroneous analysis, the individual may be unable to benefit from a particular service and may be exposed to discrimination. It would therefore not be correct to say that the processing of personal data in the context of profiling is unlawful.
The Board is of the opinion that, for a personal data processing activity of this nature, an assessment must be made under the legal ground of the controller’s legitimate interest, and that it must be determined by means of a balancing test which of the competing interests prevails. According to the Board, the mere fact that an individual has been entered on a blacklist does not mean that his or her rights have been interfered with; however, considering that the data which may be entered in the field in question are not limited, it is no longer possible to speak of a proportionate interference where general data and special categories of data are included which would cause the person to suffer discrimination and which go beyond matters of conduct.
On the other hand, the limits of profiling must also be addressed at this point. For example, the fact that a car rental company keeps a list of its customers who return the vehicle damaged or late does not give rise to profiling, since this is not in essence regarded as fully automated processing. However, where the data entered into the software are subjected to automated processing and produce a result, it must be accepted that profiling is taking place. For example, it is profiling where the data entered produce a result such as “do not rent a vehicle to this person”. In conclusion, all of these matters must be taken into account when assessing the lawfulness of a profiling activity.
When the car rental companies and the software companies are assessed in relation to one another, the Board takes the view that, since the party entering data into the software is the car rental company, the controller as regards the question whether the data entered were obtained lawfully must again be the car rental company.
Finally on this subject, although it may be accepted that profiling may be carried out by car rental companies, it must be noted that, according to the Board, it is not regarded as a lawful activity for the
results arising from this activity to be seen by another company. By contrast, it is compatible with the legitimate interest criterion for branches and agencies to see the data belonging to the company.
• On making personal data accessible to other users by means of the blacklist application: According to the Board, the recording in a common database of the assessments made by car rental companies about their customers, the fact that other companies can see them and that comments made by those companies can also be added to this field amount to the disclosure of both trade secrets and personal data. It was stated that, in line with the legitimate interest criterion, these data may be shared only with “business partners, branches and agencies”. It should be noted that the concept of business partners referred to here is very broad and that its use was not appropriate. We are therefore of the opinion that controllers should, in the first place, treat only sharing with branches and agencies as lawful.
In the light of the explanations given above, the decision reached by the Board may be summarised as follows:
• While the car rental company is the controller as regards the data entered into the software, the software companies are also controllers as regards the transfer, since the data entered are first transferred to the software and subsequently shared with other companies. In the present case, therefore, the car rental companies and the software companies act as joint controllers.
• Since the personal data processed in this manner are contrary to the Law, they must be destroyed within the framework of Article 7 of the Law and the Destruction Regulation.
First of all, we are of the opinion that the Decision provides guidance for the practices of car rental companies. Although no clear conclusion could be reached in many respects, we presume that the main reason for this is that each individual case on the subject differs considerably from the others. It should be noted that it would be useful for car rental companies to review their practices in line with this decision.
5. Unlawful sharing of the data subject’s personal data at the internet address displaying the registry information of the company of which he or she is a former shareholder (dated 06/01/2022 and numbered 2022/6)
It is noteworthy that the controller in this decision of the Board is the Istanbul Chamber of Commerce (“İTO”). As is known, the İTO processes personal data on a very large scale. However, since the great majority of these processing activities derive from statute, they rest on the legal ground that processing is “necessary for compliance with a legal obligation”. The case underlying the decision concerns the allegation of the data subject who, on seeing that his or her first name and surname appeared under the heading of former shareholders on the web page containing the registry information of the company of which he or she had been a shareholder in the past, claimed that, since he or she no longer had any connection with the company, his or her personal data had been shared with third parties without his or her consent.
In its written defence, the İTO stated that, since the shareholding structure of the company must be registered and announced pursuant to Art. 35 of the Turkish Commercial Code (“TTK”) and Art. 15 of the Trade Registry Regulation, the data subject’s appearing as a shareholder or former shareholder was public information, and that personal data such as the identity number and address were concealed.
Starting from the provisions of the TTK and the Trade Registry Regulation, the Board stated that changes relating to the transfer of shares in the company are registered in the trade registry gazette and that the trade registry directorates responsible for these trade registries are attached to the chambers of commerce, and thus pointed out that the information in question is in any event already held by the chamber of commerce. In addition, the Board stated that the purpose of making the information in the trade registry gazette available on the page of the chamber of commerce is to provide easier access to information on trade registry transactions, and that the principle of “being relevant, limited and proportionate to the purposes for which they are processed” laid down in Article 4 of the Law had thus also been complied with. As a result of the examination, it was concluded that the personal data processing activities carried out by the İTO on its web page fall within the obligations of chambers of commerce under the Constitution of the Republic of Türkiye and Law No. 5174 on the Union of Chambers and Commodity Exchanges of Türkiye and on Chambers and Commodity Exchanges, that the processing activity in question is therefore “necessary for the İTO to comply with its legal obligations”, and that, in accordance with Art. 7 of the Law, the reasons requiring the processing of the personal data still exist.
6. Sending of a commercial electronic message by a controller operating in the health sector without obtaining explicit consent (dated 18/01/2022 and numbered 2022/31)
Because a personal data processing activity carried out by sending a commercial electronic message is an operation subject both to personal data protection legislation and to electronic commerce legislation, the question of which legislation’s obligations the controller would be subject to was highly controversial, particularly in the years when Law No. 6698 was first published. Subsequently, however, it became clear from the decisions of the Board that, in the Board’s view, the obligations arising from electronic commerce legislation aside, the obligations arising from personal data protection legislation must also be fulfilled without fail. Thus a person sending a commercial electronic message will fulfil the obligations arising from Law No. 6698 and the related legislation wearing the hat of controller, and the obligations arising from electronic commerce legislation wearing the hat of service provider. The Board has maintained the same view in its other decisions on the subject.
In the case underlying the decision too, there is a data processing activity consisting in the sending of a message with commercial content to the data subject’s e-mail address by a controller operating in the health sector. The data subject alleges that his or her personal data were processed without reliance on any of the conditions for data processing laid down in Law No. 6698 and that the obligation to take all necessary technical and organisational measures to prevent the unlawful processing of personal data was breached.
The controller, for its part, argued in its defence that the data processing activity in question was based, first and foremost, on the legal ground of performance of the contract between the data subject and the hospital. In addition, it stated that, having regard to the provisions of Law No. 2219 on Private Hospitals and the Fundamental Law No. 3359 on Health Services, the processing of data was necessary for the controller to be able to comply with its legal obligation. As regards the content of the commercial e-mail that is the subject of the decision, it stated that the situation had arisen from a temporary lack of coordination between departments and that the e-mail had been sent by mistake, without the data subject’s approval.
As a result of its examination, the Board, starting from the fact that the personal data at issue had been provided by the data subject when the patient record was created at the controller’s branch, found that the conditions for data processing were satisfied and stated that there was no unlawfulness as regards the way in which the personal data had been obtained. The data subject’s allegation of a breach, however, relates to the commercial electronic message sent by the controller. In this respect the Board is of the opinion that the general principles laid down by Law No. 6698 were breached because the data subject’s contact details were used not for a medical purpose but, on the contrary, for commercial purposes, in order to carry out marketing activities. For, according to the Board, even though the controller obtained the personal data in question lawfully, it subsequently used them in a manner unconnected with the purpose for which they had been obtained and thereby acted contrary to the principle of “being relevant, limited and proportionate to the purposes for which they are processed”. On this basis, it was decided to impose an administrative fine of 100,000 TL on the controller pursuant to Art. 18(1)(b) of Law No. 6698.
We see that in this latest decision on commercial electronic messages too, the Board has adopted the same view, consistently with its previous decisions. Accordingly, in all personal data processing activities which it carries out by sending commercial electronic messages, the controller must without fail act in conformity with all the obligations imposed by Law No. 6698. The controller must not forget that it cannot dispose as it wishes of the personal data which it holds and that, in particular for commercial electronic messages sent for commercial purposes, it must have recourse to obtaining the data subject’s explicit consent.
7. Sharing on social media of the content of the file relating to enforcement proceedings initiated against a company whose trade name contains the data subject’s name (dated 10/02/2022 and numbered 2022/103)
As is known, data belonging to legal persons are not protected under Law No. 6698. There is, however, some uncertainty as to whether situations such as e-mail addresses containing the first name and surname of persons working within the legal person, or a first name and surname contained in a trade name, may be regarded as falling within the scope of the Law. First of all, it must be noted that with this decision the Board has clearly closed the door on the view that data of this kind can in no way be regarded as personal data. For the Board referred to Opinion No. 4/2007 of 04.06.2007 of the Article 29 Data Protection Working Party, prepared on the basis of the Data Protection Directive 95/46/EC. According to that opinion, “whether information about legal persons ‘relates to’ natural persons must be considered in the light of the specific case and, where the name of the legal person derives from the names of natural persons, whether it constitutes personal data must be assessed according to the criteria of content, purpose and result”.
In the case underlying the decision, the controller, a textile company, initiated enforcement proceedings against a spare parts company whose name contains the data subject’s name, on the ground that it had not made payment; and a third person known to the controller company posted, in a public group on Facebook, a statement about the company to the effect that it was a fraudster. The data subject alleges that, although he or she has no commercial relationship with the third person who made the post, his or her personality rights were violated by the sharing with third parties of his or her personal data contained in the enforcement file.
As a result of its examination of the matter, the Board reached the conclusion that the elements of personal data were not met in the present case. Accordingly, although the trade name appearing in the enforcement documents contains the data subject’s first name and surname, the post and the comments made target the legal person. Moreover, the company’s name or its debt information, address and tax identification number have no effect on the rights and interests of the natural person, nor are they used for the purpose of treating the natural person in a particular way. On this basis the Board decided that the present case did not fall within the scope of Law No. 6698.
8. Request for special categories of personal data from candidates in the recruitment process by the liaison office in Türkiye of a controller established abroad (dated 24/02/2022 and numbered 2022/172)
There is uncertainty as to how protection of the personal data processed by liaison offices is to be ensured. For although liaison offices process personal data intensively, they have no legal personality because they are attached to a company established in a foreign country. Indeed, liaison offices do not engage in any commercial activity and merely provide “communication and the transfer of information”. In this situation it may not always be easy to determine who the controller is and by whom the obligations in respect of these data are to be fulfilled. In the case underlying this decision of the Board too, it is alleged that the data subject, on being hired, handed over the special categories of personal data requested by the liaison office but that his or her explicit consent was not obtained for the processing of these data; that the civil registry information of family members was also requested from him or her, which, however, conflicted with the general principles; and that, moreover, his or her personal data may have been transferred abroad. It was stated that the controller did not reply within the statutory period of 30 days to the application made by the data subject on the matter.
In the defence submitted by the liaison office, it was stated that, since the data subject was an employee of the controller located abroad, the personal data at issue had been given by the data subject with consent, in the context of the workplace personnel file; and, further, that the liaison office did not have legal personality because it had no commercial activities.
The Board stated that the status of employer belongs to the controller with its seat abroad and that the employment contract exists not between the employees and the liaison office but with the controller; and that there is therefore no unlawfulness in the transfer of the data subject’s personal data by the liaison office to the controller located abroad. Stating that the personal data at issue had to be processed abroad for the performance of the employment contract and that this could take place only with the data subject’s explicit consent, it held that the explicit consent obtained from the data subject was lawful. The Board decided only that the controller be instructed to show the necessary care and diligence with regard to applications received from data subjects.
The important consequences of this decision are as follows:
• As regards the personal data collected by liaison offices, the controller is the company established abroad. For the liaison office has no legal personality, since it has no commercial activities. It is the foreign controller itself that employs the staff of the liaison office.
• However, a notification made by the data subject to the liaison office may be valid. In the present case the notification is valid because the manager of the liaison office is at the same time the employer’s representative of the controller, and the controller must reply.
While we agree with the assessment concerning the liaison office, we think that the Board was unable to offer a clear solution as to how the security of personal data collected in this way is to be ensured. In the present case, very important personal data of the data subject are being processed, such as special categories of personal data and the civil registry information of family members. Yet very clear answers could not be given to the questions whether the obligations arising from Law No. 6698 in respect of these personal data were fulfilled and by whom they ought to be fulfilled. In fact, according to the Board’s decision, since the party to the employment contract is the controller itself, the conclusion is reached that all obligations, in particular those of informing and of obtaining explicit consent, must be fulfilled by the foreign controller. The extent to which this is actually done in practice is, however, debatable. It must therefore be said that, for the time being, the right to the protection of personal data is not applied very effectively to the personal data processed by liaison offices. At this point, the Board’s view that the notification made to the liaison office is valid and that a reply must be given to the data subject is an important step towards averting this danger.
9. Sharing of the data subject’s debt information with third parties by a receivables management company (dated 04/03/2022 and numbered 2022/184)
Ever since the Board first began to publish summaries of its decisions, we have frequently come across decisions concerning the sharing of the data subject’s debt information with third parties. Unfortunately, this matter is not treated with sufficient sensitivity in practice. Yet, however much sensitivity is shown, there are also numerous concrete examples in which this information has inevitably been disclosed in one way or another. For it is obvious that the data subject will be contacted through communication channels so that he or she pays the debt. These communication channels were provided by the data subject himself or herself. Where the data subject provides incomplete or incorrect information, or provides the contact details of a relative, disclosure of the debt information is likely. The fact that the person in whose name a telephone line is registered and its user are not always the same produces similar results. It must therefore be said that this is a matter in which both parties must exercise care so that no harm is suffered in relation to personal data.
In the case underlying this decision, an SMS concerning the data subject’s debt to a telecommunications company was sent, under the name of the controller receivables management company, to lines registered in the names of the data subject’s sibling and spouse.
In its written defence, the controller stated that, by reason of the assignment of receivables agreement between it and a telecommunications company, information such as the enforcement file details and the contact details given to the telecommunications company had been forwarded to it by that company. The crucial defence here, however, is that it was in fact the data subject who had first called the controller from the lines belonging to his or her sibling and spouse. The controller stated that the data subject had called it from the numbers in question in order to enquire about the debt and that its call centre systems had automatically recorded these numbers, and it also submitted concrete evidence of this.
Although the Board was persuaded that the data subject had first called the controller’s call centre line from these numbers, it found it contrary to Law No. 6698 that, where the controller’s call centre is called and information is requested, the telephone details of callers are automatically recorded in the system and processed without any information being given to the caller and without the conditions for processing personal data in Article 5 of the Law being met, and that information relating to other persons’ personal data is shared with these callers. Finding that the necessary technical and organisational measures aimed at ensuring the level of security in order to prevent the unlawful processing of personal data had not been taken as required by Art. 12(1) of the Law, it decided to impose an administrative fine of 50,000 TL on the controller pursuant to Art. 18(1)(b) of the Law. In addition, the controller was instructed to cease automatically recording in its system the telephone numbers of persons calling for information and to notify the Board of the outcome.
The problem in the case underlying this decision is that the controller gave no information to the effect that the numbers from which it was called were being recorded in its systems. In fact, there are no personal data that were obtained unlawfully by other means. However, the controller, failing to exercise the necessary care, neglected to provide information to this effect. Consequently, the obligation to inform that applies under Art. 10 of the Law and Art. 4 of the Communiqué was not fulfilled. Of course, whether the person’s explicit consent is needed in this process must be determined separately according to the circumstances of the specific case. Although the Board did not make any assessment on this point, we are of the view that recording in the system information belonging to the debtor’s relatives is a process subject to explicit consent.
10. Sharing of the data subject’s telephone number with third parties by a bank’s call centre (dated 10/03/2022 and numbered 2022/224)
Another important matter that is frequently the subject of Board decisions is the sharing of data by banks. Banks outsource many services and share personal data in order to be able to obtain those services. However, the sharing of these data in a disproportionate manner can have extremely dangerous consequences, such as the unlawful use of the data by the company providing the service. For this reason banks must, first and foremost, select carefully the companies from which they obtain services and attach importance to the clauses on the protection of personal data in the contracts which they conclude with those companies. Similarly, the data processing activities carried out by different units within their own organisation must be conducted with great care.
Indeed, in this decision of the Board too we see that data were shared by the bank’s call centre. In the case underlying the decision, the data subject contacted the call centre of the controller Bank about a card belonging to a third person which he or she had found at the Bank’s ATM. The call centre agent proposed sharing the data subject’s telephone number with the third person using the card so that the third person could collect the card from the data subject, but the data subject did not consent to this. Thereupon the call centre agent told the data subject to hand the card to the security officer at the airport, and the data subject complied with this request. Subsequently, after the third person using the card sent a message to the data subject’s personal telephone number, the data subject lodged a complaint, stating that he or she had not been informed about the processing of his or her first name, surname and telephone number and had not given explicit consent to the transfer of the data to a third person.
In its written defence, the controller stated that the KVKK information notice had been presented to the data subject through the call centre but that the data subject had chosen not to listen to it, and that, in the application which the data subject made through the call centre and the Contact Us section of the Bank’s website, the obligation to inform regarding the processing of his or her data had been fulfilled in accordance with Art. 10 of the Law. Furthermore, in the conversation between the call centre and the data subject, when the customer representative said that he or she would tell the cardholder that the card had been found by the data subject, the data subject replied “okay”. As a result of this, the data subject’s personal data were shared orally with the card user. The recording of the conversation with the call centre was submitted to the Board on CD.
The Board, finding that the KVKK information notice had been presented to the data subject during the conversation with the call centre and that the box “I have read and understood the information provided under the law on the protection of personal data” had been ticked when the application was created on the controller’s website, stated that the controller Bank had fulfilled its obligation to inform. However, it concluded that there was no legal ground under Law No. 6698 for the sharing of the data subject’s telephone number. For although it can be understood from the CD submitted by the controller bank that the data subject answered “okay” to the sentence “I will pass on that it was you who found the card”, the call centre did not use any explicit statement to the effect that the telephone number would be shared. Moreover, at the beginning of the conversation the data subject had not given explicit consent to the sharing of the telephone number with the third person using the card; indeed, it was precisely for that reason that he or she handed the card to the security officer. It is therefore not possible to accept, from the content of the recording submitted, that the data subject gave explicit consent to the sharing of his or her telephone number. The Board found that the element of explicit consent was absent in the processing of the data subject’s personal data and decided that, since the controller, by processing personal data contrary to the Law, had therefore breached its obligations under Art. 12 of the Law to prevent unlawful access to personal data and to ensure the protection of personal data, an administrative sanction be imposed on the controller pursuant to Article 18 of the Law.
Indeed, having regard to the elements of explicit consent, and in particular the element of “being based on information”, it cannot be accepted that the data subject was clearly informed about the sharing that is the subject of the explicit consent. For this reason we consider this decision of the Board to be correct. It is a fact that banks frequently encounter situations of this kind, particularly on account of conversations conducted at the call centre. Employees must therefore without fail be given regular training on such situations.
11. Processing of the data subject’s personal data through the sending of the invoice to the data subject after a person with the same name used the data subject’s e-mail address when placing an order on the internet (dated 17/03/2022 and numbered 2022/243)
In the case underlying the decision, a person with the same name as the data subject used the e-mail address belonging to the data subject when registering as a member with, and placing an order from, the controller, which provides services over the internet. The controller carried out the membership registration without checking the accuracy of the e-mail address and without its being confirmed, and sent the invoice for the order to the data subject.
In its statement of defence, the controller stated that e-mail verification was not carried out for guest log-ins to the website so that users could carry out transactions as they wished and so that transactions would be made easier, and that technical development work was under way to make it possible to verify cases in which, in purchases made without membership, a person with the status of guest customer mistakenly enters data belonging to others when entering his or her own e-mail address or telephone number. It was stated that, in the dispute at hand, a sender had mistakenly logged into the system with the data subject’s e-mail address and created an order, that the data subject’s e-mail address had not been matched with any data belonging to the data subject and that the person’s identity information had not been processed, and that for these reasons the personal data had not been unlawfully obtained by others.
The Board decided to impose an administrative fine of 100,000 TL on the controller because this processing activity was not based on any of the conditions for processing laid down in Art. 5 of the Law and was contrary to the principle of “being accurate and, where necessary, kept up to date”.
The sending of an e-invoice by the controller is a statutory requirement; it is a data processing activity that is necessary for the controller to comply with its legal obligation. Nevertheless, having regard to the evidential value of the e-invoice and to the personal data it contains, the accuracy and currency of the address to which it is to be sent are important. The problem in the present case is that the person placing the order (i) created the order as a guest and (ii) there was in any event no membership account for the e-mail address which the person placing the order entered into the system. It is therefore difficult for the controller in this scenario to verify the accuracy of the data entered. The Board nevertheless stated that the controller must develop mechanisms for this purpose.
In such situations we generally see that verification is carried out by sending a verification code or link to the contact address entered into the system. Although it is a fact that this verification mechanism will slow down the ordering process, considering that such situations frequently occur in orders placed online, the conclusion follows that establishing a verification mechanism is necessary for the protection of personal data.
12. Processing by the controller, without obtaining explicit consent, of the data subject’s “hand geometry” information for the purpose of entering the service building of an undertaking (dated 07/07/2022 and numbered 2022/662)
Although the Board’s decisions on providing entry to and exit from buildings and workplaces by processing biometric data are very clear, we see that, unfortunately, controllers still do not show the necessary sensitivity in this regard. The matter underlying this decision of the Board is the controller’s claim that “hand geometry” information does not constitute a special category of personal data. The controller takes the view that hand geometry information should not be regarded as biometric data on the ground that it is not infallible. However, in its examination in this respect the Board found that the information collected by the controller was in the nature of biometric data. The reasons for this are as follows:
• The name of the device used by the controller is “biometric data terminal”.
• This device scans the hand and fingers in three dimensions and analyses all the characteristic features of the hand. For this reason it was also found that the margin of error is lower than 1 in one hundred trillion.
• In decision no. 2014/4562 E. of the 15th Chamber of the Council of State, hand geometry was accepted as biometric data.
• In the GDPR, the definition of biometric data uses the phrase “physical, physiological or behavioural characteristics”.
• Although the judgment of the European Court of Human Rights in Marper v. the United Kingdom does not refer directly to hand geometry, it emphasised that provisions affording adequate safeguards in respect of biometric data must be made in domestic law.
• In the Constitutional Court’s decision on application no. 2018/11988, the following wording was used for biometric data: “a special category of personal data, on account of its importance, because it contains biological or behavioural information belonging to a person which enables that person to be distinguished from other individuals and to be personally identified”.
On the basis of the reasons set out above, the Board concluded that hand geometry information is biometric data because it is a measurable physiological characteristic. Accordingly, it was decided to impose an administrative fine on the controller, which had processed biometric data of the data subjects without any condition for processing being met, and to halt the practice of granting entry by means of the collection of biometric data.
Since the Board’s decisions on this subject are also highly consistent, controllers must show sensitivity in this matter and review their practices accordingly. Indeed, because biometric data fall within the special categories of personal data and are subject to stricter conditions, compelling circumstances must exist for data of this kind to be used. If the purpose pursued can be achieved by processing personal data that are not of a special category, that method must be preferred without exception and recourse must not be had to the processing of special categories of personal data. In situations such as entry to and exit from the workplace, sports halls, entry to a service area and the like, the processing of biometric data must be avoided, since ensuring the security of the building or workplace is also possible by methods such as an electronic card, a personal password, barcode scanning and the like. For in such a case there would be a data processing activity contrary to the principle of proportionality.
Footnotes
Related publications
Dülger, Murat Volkan / Gümüş, Gülçin, Personal Data Protection Law (Kişisel Verilerin Korunması Hukuku), 4th ed., Seçkin Publishing, Ankara, 2026.
Dülger, Murat Volkan, Legislation on Information Technology, Personal Data Protection and Internet Communication (Bilişim, Kişisel Verilerin Korunması ve İnternet İletişimi Mevzuatı), 7th ed., Seçkin Publishing, Ankara, 2021.
Dülger, Murat Volkan, “The Use of Bulk Data and Metadata in Preventive Policing and Intelligence Work from the Standpoint of Human Rights, Personal Data Protection and Criminal Procedure Law” (İnsan Hakları, Kişisel Verilerin Korunması ve Ceza Muhakemesi Hukuku Açısından Önleyici Kolluk Hizmetleri ve İstihbari Çalışmalarda Toplu Veri ve Metadata Kullanımı), conference presentation, 2026.
Dülger, Murat Volkan, “Lawyers' Obligations under the KVKK in the Light of the Board's Decisions” (Kurul Kararları Işığında Avukatların KVKK Yükümlülükleri), conference presentation, 2025.
Dülger, Murat Volkan / Gümüş, Gülçin, “The Right to Be Forgotten”, Essays in Honour of Prof. Dr. Yadigar İzmirli (Prof. Dr. Yadigar İzmirli'ye Armağan), 2024.
