7 April 2020Murat Volkan Dülger, Cansu Ceren KahramanCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

When Law No. 6698 on the Protection of Personal Data (KVKK) entered into force, the business activities of no sector complied with it, and how compliance with the KVKK was to be achieved gave rise to debate. This was because the provisions of the KVKK were themselves inadequate as guidance for solving the problems encountered in practice. It was at this point that the decisions and guidelines of the Personal Data Protection Board (the Board) came into play as guidance for shaping practice. The decisions are real-life examples of how personal data protection legislation is to be applied to a specific case. In addition, since they include decisions imposing administrative fines, they also have a deterrent effect. The subject of this study is the Board’s decisions published on 2 April 2020.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

Murat Volkan Dülger* / Cansu Ceren Kahraman*

Introduction

When Law No. 6698 entered into force, the business activities of no sector were compliant with this Law, and how compliance was to be achieved once the Law was in force gave rise to debate. This was because the provisions of the Law, too, proved insufficient as guidance in resolving the problems arising in practice.

It was at this point that the decisions and guidelines of the Personal Data Protection Board came into play as guidance for the shaping of practice. The decisions constitute real-life examples of how data protection legislation is to be applied to a concrete case. Moreover, since they also include decisions imposing administrative fines, they have a deterrent effect as well. The subject of this study is the Board’s decisions published on 02.04.2020.

I. Decision No. 2019/ 138 of 16. 05. 2019

A. Summary of the Decision

In the case forming the subject of the decision, an employee’s WhatsApp conversations, which were open on the employee’s work computer, were read by the employer, the controller, photographed and shared with third parties. The employee thereupon lodged a complaint with the Personal Data Protection Board.

In its decision the Board stated that, pursuant to Article 17 of Law No. 6698, the offence provisions in Articles 135 to 140 of the Turkish Criminal Code (TCK) apply as regards offences; that, pursuant to Article 15(1), the Board carries out the necessary examination in matters falling within its remit upon complaint or, where it learns of an alleged violation, of its own motion; and that, pursuant to Article 15(2), reports and complaints concerning the matters specified in Article 6 of Law No. 3071 of 1/11/1984 on the Exercise of the Right of Petition are not to be examined. The matters in question are the following:

• reports or complaints that do not contain a specific subject,

• that concern matters falling within the jurisdiction of the judicial authorities,

• that fail to meet any one of the conditions set out in Article 4 (the petitioner’s forename, surname and signature and business or residential address).

Pursuant to the above provisions, the Board decided that the reading, photographing and sharing with third parties of the WhatsApp conversations on a person’s workplace computer did not fall within the scope of Law No. 6698 and concerned the relevant provisions on personal data in the Turkish Criminal Code.

B. Assessment of the Decision

The question whether work computers may be inspected has been a source of confusion ever since the Law entered into force. For work computers may not always be used for work purposes. In that case, when the employer wishes to inspect the computer, it encounters the employee’s sphere of private life, and objections are raised. It may be said that this problem has in fact been resolved by the case law of the Court of Cassation and as data protection legislation has begun to take root in practice. It is possible for the employer to check the employee’s work computer on the legal ground of legitimate interest in Article 5(2)(f) of Law No. 6698. For this, however, it must inform its employee beforehand.

The case forming the subject of the Board’s decision is a good illustration that the employer may not carry out every kind of inspection. Whatever the content of the conversations, and even though the employee was using the work computer (including in cases where the employee has been informed), it is not right for the employee’s computer to be checked secretly in the employee’s absence. The employee’s computer should be taken after the employee has been told that an inspection will be carried out, and reports of the inspections carried out should be kept. Indeed, the Board, too, did not regard the employer’s act in this case as falling within the scope of inspection.

Although this is not stated in the decision, it is also important whether the WhatsApp account relates to the employee’s workplace line or personal line. For conversations relating to a person’s private life conducted via his or her personal line may lead us to the provision on the offence of violation of privacy. But of course the determination of this lies with the judicial authorities and not with the Board.

Since the employer’s act was not within the scope of business activity and the employer acted entirely within its personal sphere, the decision given by the Board is lawful. However, while the Board’s decisions are important for the shaping of practice, we think that the Board needs to be clearer in its decisions. When decisions on cases containing details are published, even if only in summary form, the points that are distinctive for practice must without fail be included and emphasised.

Another point in this decision of the Board which calls for attention and is open to debate is its statement that it will not carry out an examination in matters “concerning matters falling within the jurisdiction of the judicial authorities”. In our view the conclusion the Board draws from this provision is mistaken. The provision in Article 15(2) of the Law on the Protection of Personal Data (KVKK), to the effect that reports and complaints concerning the matters specified in Article 6 of Law No. 3071 on the Exercise of the Right of Petition are not to be examined, means that the Board cannot act in matters “falling exclusively within judicial activity”. Otherwise, in a political system in which there is a separation of powers, there would be a usurpation of authority, and a case that has to be resolved within the judicial power would be sought to be resolved by the administrative power. This matter, however, does not concern the judicial power alone. As is also stated in the Board’s decision, the matter not only involves a violation of the relevant provisions of the TCK but at the same time also violates KVKK No. 6698. There is therefore no obstacle to the Board’s addressing and examining the matter from the administrative angle as well and, if it sees fit, taking an administrative measure such as issuing instructions. If the aim is for data protection law to develop in our country and for everyone to comply with the protection of personal data, the article in question must not be interpreted narrowly; a purposive interpretation must be adopted and the article applied within the framework of the solution we have reached above. Otherwise, almost every dispute that comes before the Board is in any event of a nature that violates Articles 136 to 140 of the TCK.

While on the subject, we consider it useful to give a warning once again. Where the Board also sees, in a case that comes before it, that an offence has been committed, its failure to take action in this regard by using expressions such as “informing the person concerned, etc.”, as in its decisions to date, is unlawful and constitutes an offence. For according to the offence of “Failure of a public official to report an offence” provided for in Article 279 of the TCK, “A public official who, having learned in connection with his or her duties that an offence requiring investigation and prosecution on behalf of the public has been committed, neglects to notify the competent authorities or delays in doing so … shall be punished”. The members of the Board are public officials and, pursuant to Article 279 of the TCK, if they learn in a case before them that an offence has been committed, they are under an obligation to report this without delay to the competent public prosecutor’s office. This reporting is not a matter left to their own initiative, and they have no discretion. Conduct to the contrary will give rise to their criminal liability.

II. Decision No. 2019/ 206 of 08. 07. 2019

A. Summary of the Decision

In the case forming the subject of the decision, the complainant alleged that, on entering the website through which the controller provides its services, a mandatory field appeared for logging in and an e-mail address was requested; that there was no possibility of proceeding to the home page without providing the personal data requested, and that in this respect the provision of the personal data in question was demanded as a condition of service; and that the text presented under the obligation to inform at the time the personal data were requested did not clearly set out the personal data processed and the legal grounds for processing them. When the Board examined the website in question, it found that, rather than the provision of a product or service or the enjoyment of a product or service being made conditional on explicit consent, additional advantages were being granted to members, and it decided that there was no action to be taken in this respect.

Another point on which the Board dwelt is the text entitled “Our Privacy and Personal Data Protection Policy” on the website. On the ground that this text had not been drawn up in conformity with the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform, because it did not clearly state whether personal data were processed on the legal ground of explicit consent or on the basis of one of the other legal grounds set out in the Law, the Board decided that the Company be instructed to update the text in question having regard to the provisions of the Communiqué and, in addition, that the obligation to inform and the obtaining of explicit consent must be carried out separately.

B. Assessment of the Decision

In its decision the Board essentially dwelt on the minimum elements of two concepts: explicit consent and the information notice.

In the case forming the subject of the decision, people’s personal data are obtained for membership of the website. It is possible that certain personal data are processed for membership and that, if the personal data are not provided, membership does not come about. The important point here, however, is whether membership is the main condition for the provision of a product or service or for the enjoyment of a product or service. If, as in the case forming the subject of the decision, membership is not a condition for the provision of the service and merely affords certain discounts and advantages, it may be said that the requirement of being based on free will, which is one of the minimum conditions of explicit consent, is satisfied. This situation is similar to that of a loyalty card.

Another matter on which the Board dwelt concerns the information notice. In practice, on the view that it is convenient, a single checkbox is provided for information and explicit consent, or the information notice and the explicit consent are intertwined. These are foremost among the mistakes that are still frequently made in practice. Yet the minimum conditions of the information notice are set out in the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform. In the Board’s guidelines and decisions it is frequently emphasised that the information notice and explicit consent must be separate, and it is stated that their not being separate vitiates the explicit consent. It was likewise a mistake for the company in the decision to provide information and obtain explicit consent within the same checkbox.

A further point we wish to make here is that preparing “a single information notice” and using it in all processes does not mean that the controller has fulfilled its obligation to inform. The more the operational processes in an enterprise and their sub-processes differ from one another in terms of the purpose of data processing, the more information notices and, where necessary, explicit consent forms are required. Even though this makes operations more difficult and increases bureaucracy, both the letter and spirit of the Law and the Board’s interpretation support this view and practice of ours.

Although the information notice did not satisfy the minimum conditions, the Board, also taking into account the effort the company had made towards compliance, decided that instructions be given for the necessary updates to be made. The purpose of imposing administrative fines is not to obtain money but to ensure that the statutory provisions are applied correctly and to prevent practices contrary to the statutory provisions. For this reason we think that the decision given by the Board is correct.

We would also like to point out that the fact that the effort made towards compliance was taken into account in this way, even though the Board had found a clear violation, is both a very positive stance on the part of the Board and an important point that controllers should bear in mind in achieving compliance.

III. Decision No. 2019/ 273 of 18. 09. 2019

A. Summary of the Decision

In this matter, the spouse of a deceased person stated that, as the legal heir of the deceased spouse, a request had been made to the clinic in Istanbul where the deceased had received treatment for all of the deceased’s medical and other information; that a letter containing this request had been sent to the clinic in question by registered post; that the post had been received by the other party but no reply had been given; that an e-mail containing the requests in question had thereupon been sent to the clinic’s electronic address; and that the reply received was that data could not be shared with the applicant through unofficial channels; and on that basis requested access to the spouse’s data referred to in the application.

The Board, for its part, considered that the Law defines the data subject as “the natural person whose personal data are processed”; that Article 28 of the Turkish Civil Code No. 4721 provides that personality begins at the moment the child is fully born alive and ends with death; and that, under Article 11 of the Law, the data subject may request information about the personal data relating to himself or herself; and it decided that, since the personal data requested did not relate to the natural person making the request and belonged to a deceased person, the request would not be regarded as a request within the scope of Article 11 of the Law.

B. Assessment of the Decision

The data subject is the natural person whose personal data are processed. Personality, as the Board also stated in its decision, ends with death. And since personality ends with death, data relating to deceased persons are not personal data. At this point, however, it must also be assessed whether data relating only to the deceased person are related to the relatives of the deceased person. For data that relate, in terms of content, to the relatives of the deceased person may be personal data in terms of purpose or result. It is particularly here that the fact that the Law opted for the concept of the “data subject” makes itself felt. In this context, the personal data of the deceased person must be regarded as personal data in connection with the heirs. Although personality ends with death, the heirs are the subjects of those data and may benefit from the protection.

It is not correct for the Board, in the decision, to have excluded the data from the scope of Law No. 6698 on the ground that they belong to the deceased person, without dwelling on the purpose or results of the personal data. The decision given is compatible neither with the fact that the concept of data subject rather than data owner was chosen in the law nor with the general logic of the Law.

IV. Decision No. 2019/ 297 of 01. 10. 2019

A. Summary of the Decision

The data subject lodged a complaint with the Board, stating that the controller had sent the data subject an SMS with advertising content; that the data subject had applied to the controller on the ground that his or her personal data had been processed without explicit consent; that the controller had replied to the application in writing; and that the data subject did not find this reply sufficient and accordingly considered that the personal data had been processed without explicit consent.

The Board based its decision on two statutory grounds. The first of these is the provision in Provisional Article 1(3): “Personal data processed before the date of publication of this Law shall be brought into conformity with the provisions of this Law within two years of the date of its publication. Personal data found to be contrary to the provisions of this Law shall be erased, destroyed or anonymised immediately. However, consents lawfully obtained before the date of publication of this Law shall be deemed to be in conformity with this Law unless a declaration of intent to the contrary is made within one year.” The second statutory ground is the provision in Provisional Article 1(2) of the Regulation on Commercial Communication and Commercial Electronic Messages of 15/07/2015: “Databases created, before the date of entry into force of the Law, by the recipient providing his or her electronic contact address in the course of transactions between the service provider and the recipient directly aimed at the supply of goods or services shall be deemed to have been approved. Where approval deemed to have been given in this way was given for an agent, exclusive dealer or dealer business, it shall be deemed to have been given for the other party to the contract as well.”

The Board stated that it was seen that, according to the controller, the data subject had in 2012 called the company’s head office from the telephone number indicated in the application and requested an English user manual for the data subject’s motorcycle, and with this request had given permission to be contacted personally by e-mail, SMS and telephone; that the data subject had moreover purchased spare parts and servicing from the firm for the motorcycle in 2013 and that there was a current-account invoice record of this; that, in reply to the data subject’s application, the firm had submitted screenshots showing the invoice details of the product and service purchased in order to substantiate its claims; and that the data subject’s application petition contained no statement to the effect that the firm’s claims were untrue.

Having examined the two provisions in question, the Board decided that there was no action to be taken under the Law on the Protection of Personal Data, because it had been declared that the data were processed on the basis that the data subject had called the company’s head office in 2012 and requested an English user manual for the motorcycle and, with this request, had given permission to be contacted personally by e-mail, SMS and telephone, and that the data subject had also purchased spare parts and servicing from the firm for the motorcycle in 2013; because the applicant had not claimed otherwise; and because the purchase in question had also taken place before the date of entry into force of Law No. 6698.

B. Assessment of the Decision

On the date Law No. 6698 entered into force, none of our statutory provisions was in conformity with the Law, because we were unfamiliar with the concept of personal data. With every passing day, amendments are being made to statutory provisions in line with Law No. 6698.

An important piece of legislation from the standpoint of the protection of personal data is the Regulation on Commercial Communication and Commercial Electronic Messages. An important amendment was made this year to this Regulation, which was issued before Law No. 6698, and the Message Management System was introduced. It has thus been made easier for people to give or withhold approval for commercial messages, in other words to consent or not to the processing of their personal data.

The most important point of this decision of the Board is that it shows that the Law on the Protection of Personal Data is not isolated from other fields. First, it was taken into consideration that Law No. 6698 allowed a period of two years for bringing personal data processed before its entry into force into conformity; then, in order to determine whether they were in conformity, the Regulation relevant to the matter was examined.

In the case in question, too, it was decided that there was no action to be taken, because the provision of the Regulation was satisfied, that is to say, because this was a database created, before the date of entry into force of the law, by the recipient providing his or her electronic contact address in the course of transactions between the service provider and the recipient directly aimed at the supply of goods or services, and because this database is deemed to have been approved.

When achieving compliance with data protection legislation, the provisions of Law No. 6698 must be considered together with the provisions of other laws. The decision is an important and correct one in that it emphasises both this and the Regulation on Commercial Communication and Commercial Electronic Messages.

V. Decision No. 2019/ 333 of 07. 11. 2019

A. Summary of the Decision

A complaint was lodged in which it was stated that the complainant used the e-mail address ……[email protected] under an e-invoice subscription for a line registered with a telecommunications firm; that, since August 2018, the invoices of another subscriber had also been sent to the complainant by e-mail together with the complainant’s own invoices because of a similarity of names; that the complainant had made an application by sending the controller an e-mail containing requests for the correction of this error, which had arisen in the course of the processing of the complainant’s personal data, and for information on the purposes for which the personal data were processed and on the third parties, in Turkey and abroad, to whom the data were transferred; that, although the e-mail sent to the complainant on the same day stated that a reply to the request would be given within one working day, no reply was given; and that, moreover, the erroneous sending of e-invoices occurred again following the application.

The Board requested the controller’s defence. In its defence the controller stated that both persons had given the same e-mail address; that invoices had been sent to the e-mail address because of the obligation to send invoices; that, in the interests of customer satisfaction and in order to keep the contact details of the persons concerned up to date, numerous attempts had been made to contact the other person, who was a subscriber of the company and had declared the same e-mail address, but that it had initially not been possible to reach that person because of a restriction on the line; that, in the calls which continued thereafter, it had been possible to reach the person in question once, and that the situation complained of regarding the e-mail address had been conveyed and the person informed of the need to make an update in accordance with the legislation; that, as no update was made, the e-mail address was removed from the system and the sending of e-mails to the complainant was stopped; that, in the application made to it, the data subject had not provided any information that would serve to verify his or her identity, such as, first and foremost, the Turkish identity number, and the residential or workplace address for service, the e-mail address for notification, if any, and the telephone and fax number, which must mandatorily be included in accordance with Article 5 of the Communiqué on the Procedures and Principles of Application to the Controller, and that in this context identity could not be confirmed; that it had been considered that replying by e-mail would pose a risk for data security because e-mail is not secure in technical terms; and that, since more than one subscriber may use the same e-mail address, as in the present case, it had not been possible to respond to the application, in order to ensure data security.

In its decision the Board stated that, since it is not possible for two persons to obtain the same e-mail address, it was probable that a typing error had been made; that no information had been given as to when the other customer was contacted and when the e-mail address was removed from the system; that it had reached the conclusion that, because the system in which registration is made gave no warning that the e-mail address registered in the system was being used by another customer, the controller had not taken the necessary technical measures regarding data security, that the data in its system were not accurate and, where necessary, up to date, and that, since it was capable of sharing its customers’ data with other customers, it was unable to ensure the security of the personal data it held; that the ground that identity could not be confirmed for the application made via the e-mail address was not acceptable; that, although it had been concluded that confusion might arise because both subscribers were registered with the same e-mail address, it was considered that identity could have been confirmed, without causing hardship to the citizen, by a reply to the complaint application reminding the applicant of the application requirements in conformity with the Communiqué on the Procedures and Principles of Application to the Controller; that it had reached the conclusion that the controller’s defence – that, since the complaint application had been made by e-mail address, no reply was given because receiving and replying to complaint requests arriving by e-mail would entail a risk for data security – was not, in the light of the information given, a realistic defence; and that failing to reply on the ground of non-conformity with the Communiqué on the Procedures and Principles of Application to the Controller was incompatible with the rule of lawfulness and good faith in Article 6 of the Communiqué; and, on the ground that the sending of another person’s invoice to the complainant was contrary to Article 12(1), it imposed a fine of TRY 50,000.

In addition, it decided that the controller be instructed to exercise the utmost care and diligence in complying with the provisions of the “Communiqué on the Procedures and Principles of Application to the Controller” and, within the framework of this decision, to take all necessary administrative and technical measures regarding the security of subscribers’ personal data.

B. Assessment of the Decision

The recording in a system of one person’s personal data as if they belonged to another person is one of the problems frequently encountered in practice. Courier companies in particular frequently receive applications because of duplicate records in their systems. Courier companies, telecommunications companies and indeed all controllers must design their systems in such a way as to prevent erroneous records and must take the necessary measures to forestall such records. The sending of one person’s personal data to another is a risky situation capable of producing irreversible consequences for the data subject. Controllers must therefore exercise the necessary care.

In the case forming the subject of the decision, it can be seen that the same e-mail address was registered in the name of two persons because the controller had not taken the necessary measures. The controller did not inform the Board when, following the complainant’s application, it took action to stop the violation and when it stopped sending the invoices. Accordingly, it is clear that the controller did not fulfil its obligation to take the necessary technical measures.

Another point in the decision is the contention that the application was not accepted as a valid application because the data subject had not provided sufficient information to enable the controller to verify identity, and that the controller did not reply for that reason.

The Communiqué on the Procedures and Principles of Application to the Controller lays down the minimum conditions that an application to the controller must meet. Applications meeting these minimum conditions will be accepted as valid applications. In this part of its decision the Board refers to an important point. It stated that leaving an application made by an existing customer unanswered on the ground that the information necessary for identity verification had not been provided, in other words that it did not satisfy the minimum conditions, is incompatible with the rule of good faith. One reason why an application to the controller must meet the minimum conditions is to enable identity verification to be carried out in order to determine whether the applicant is the data subject. In the case of an application made by its existing customer, it is possible for the controller to carry out identity verification by other means as well.

This decision of the Board shows that the main approach of controllers should be to assess applications and to make the effort necessary for assessing them. They must not refrain from replying to an application on the ground that the minimum conditions are lacking (although this does not hold for every situation); for this purpose they must set up a system capable of making use of the necessary means at their disposal, and must structure their compliance projects accordingly.

VI. Decision No. 2020/ 34 of 16. 01. 2019

A. Summary of the Decision

The complainant data subject stated that the complainant had received a telephone call on behalf of a food company; that the complainant had made an application via the “contact us” section of the company’s website as to how the personal data had been obtained, but had received no response; that the complainant had thereupon also applied in writing to the commercial enterprise with the same request; that the letter of reply received from a natural person engaged in the call-centre business stated that that person had since 2008 been engaged in call-centre work for the products of firms from which authorisation had been obtained; that in 2013-2014-2015, under the authorisation given by a sports club, that person had provided a calling service aimed at extending the subscription period of persons who were magazine subscribers; that the telephone details were held in the server system because the data subject was a subscriber to the sports magazine in question; that the data subject’s telephone details had, at the date the magazine subscription was taken out, been stored in accordance with Article 10 of Law No. 6563 on the Regulation of Electronic Commerce; that the controller had since 2017 been carrying on the business of selling and marketing various natural food products over the internet under a food brand; that it had been established that, as a result of an error in the server calling system used by the controller, the system had called the number even though the data subject’s number had been deleted; and that, following the mistake, a written reply of apology had been given to the data subject, with the information that the personal data had been irreversibly destroyed pursuant to Article 7 of the Law; and that the complainant had thereupon lodged a complaint with the Board.

The Board imposed an administrative fine of TRY 18,000 on the following grounds: that the personal data had been used for a purpose different from the original purpose of processing, that is, that the principle in Article 4 of the Law that data must be relevant and limited to the purposes for which they are processed had been breached; that, within the scope of the provision in paragraph 3 of Provisional Article 1 of the Law, concerning Transitional Provisions, according to which “Personal data processed before the date of publication of the Law shall be brought into conformity with the provisions of this Law within two years of the date of its publication” , and with a view to bringing the data in question into conformity with the Law within the two years following the date of publication of the Law, the data ought to have been erased, since the purposes for which they were processed had ceased to exist once the contract signed between the controller and the sports club concerned for the provision of call-centre services for the sports magazine subscription ended in 2015; that, if the intention was to continue processing the data for different purposes, the data subject’s explicit consent to those processing purposes ought to have been obtained, but that these steps had not been carried out; that, although it was declared that the system had called the number as a result of an error, the fact that the data subject’s number was called showed that the erasure had not been duly carried out; and that the controller had thus acted in breach of the provision in Article 12(1)(a) of the Law, “to prevent the unlawful processing of personal data”.

B. Assessment of the Decision

The decision concerns a typical occurrence which was frequent before the Law on the Protection of Personal Data (KVKK) and which still continues (albeit less than before).

It is possible for the purposes for which personal data are processed to change over time. Since commercial life, like human life and the universe itself, is in a constant state of change and motion, the processing of personal data may also need to be adapted to the new situations that arise. Where such a need arises, the data may be processed in line with the new purpose or purposes by obtaining the data subject’s explicit consent. Otherwise, that is, where personal data are processed outside the purpose for which they were provided without explicit consent being obtained, it is clear that the result aimed at by data protection legislation will be departed from. To accept the contrary would mean a return to the old order in which, once personal data had been provided, they could be processed for any purpose as desired. Consequently, one of the most important principles of data protection law and one of the most important rules introduced by the Law is that personal data be processed in conformity with, and for, the purpose for which they were obtained. This is a very important rule laid down both in our Law and in the GDPR.

In the case forming the subject of the decision, too, whereas personal data processed before the Law entered into force ought to have been brought into conformity within two years, the data subject’s personal data were not erased despite the end of the contract in 2015, were not brought into conformity with the Law and continued to be processed for other purposes as well. It is clear that there is here a breach of the obligation to prevent the unlawful processing of personal data. In this respect the Board’s decision is entirely appropriate.

VII. Decision No. 2020/ 41 of 16. 01. 2020

A. Summary of the Decision

In the case forming the subject of the decision, an application was made to the Board for the necessary action to be taken, stating that the data subject owed a debt to a bank and had been unable to pay it for various reasons; that the bank had thereupon initiated legal proceedings for recovery; that in the second half of 2018 the data subject had taken up insured employment and that, as soon as the insurance began, the bank called the workplace even though the data subject answered when called on his or her mobile telephone, and enquiries were made about family details; that the workplace secretary was repeatedly asked whether the data subject would make payment; that, after the calls, the employment contract was terminated by the firm within the same year; and that the data subject had applied to the bank on the matter by e-mail and claimed TRY 100,000 in pecuniary and non-pecuniary damages.

In its decision the Board, for its part, decided that there was no action to be taken under Law No. 6698, on the ground that it was seen that the data subject’s application to the controller did not contain a request within the scope of Article 11 and that no document substantiating the allegations had been submitted with the complaint to the Authority either, and that, if the data subject had suffered damage and there was a claim for compensation in that respect, that claim had to be pursued before the general courts within the framework of the provision in Article 14(3) of the Law that “The right to compensation under the general provisions of those whose personality rights have been violated is reserved.”

B. Assessment of the Decision

The right, provided for in Article 11 of Law No. 6698, to claim compensation for damage where damage is suffered as a result of the unlawful processing of personal data is in fact a right that already exists under the general provisions on compensation in the law of obligations. The intention was to reinforce the right which the data subject has under the general law of liability by regulating it as an independent right. Article 11(1)(ğ) of the Law states that the data subject has the right “to claim compensation for the damage where damage is suffered as a result of the unlawful processing of personal data”. However, the addressee of this claim, as is also stated at the beginning of the same article, is “the controller”. Indeed, this is made clear in Article 14(3), entitled “Complaint to the Board”, which states: “The right to compensation under the general provisions of those whose personality rights have been violated is reserved.” In other words, if the data subject has suffered pecuniary and/or non-pecuniary damage arising from the unlawful processing of his or her data, he or she must claim this from the controller either directly or through the courts. If the request in the application forming the subject of the decision was confined to this, the Board’s decision is appropriate in terms of method.

On the other hand, if the data subject’s allegation reflects the truth, the act carried out by the bank is entirely unlawful. In our view, had the data subject been able to substantiate this request with documents and had he or she framed the request not as a claim for compensation but as a request for the necessary investigation to be carried out, the decision might have been different. But this brought the following question to our minds: if the allegation had been true and had been substantiated by documents, but the data subject had requested that the necessary action be taken together with a claim for compensation, would the Board have given the same decision? In other words, is the Board bound by the applicant’s request? Can it decide not to take action in this way on the ground that a wrong or incomplete request has been made?

In our view the answer to this question is no. Although the Board is an autonomous body, it is attached to the Presidency of the Republic and forms part of the administrative organisation. Accordingly, as regards the procedure to be applied by the Board, it is not the Code of Civil Procedure (HMK) but the Law on Administrative Judicial Procedure (İYUK) that must be taken into account. On that basis the Board is not bound by the request as far as examination and administrative sanction are concerned, and must be able to carry out the necessary inquiry and reach a decision even where it learns of the violation in this way. In this particular case, too, the fact that the matter was decided in this way without the allegations being put to the controller bank constitutes, in our view, a deficiency and indeed an unlawful act.

VIII. Decision No. 2020/ 43 of 16. 01. 2020

A. Summary of the Decision

In the application it was stated that data belonging to the data subject had been shared by a bank with the data subject’s father without consent; that, in the document drawn up by the controller bank, the father was given a letter to the effect that he formed a risk group with the data subject and that credit was not being extended to him because the data subject had defaults on credit; that the data subject sent an application petition to the controller stating that TRY 30,000 was to be paid into the relevant bank account as compensation for the non-pecuniary damage caused, failing which legal action would be taken to recover the claim; that nevertheless no reply to the application was received from the Bank within 30 days; and that the application had been made for that reason.

Upon the application, the Board requested a defence from the controller bank. In its written defence the bank stated that the credit intelligence enquiry carried out by the branch concerned had produced a negative result because of credit defaults on the part of the son, who resides in the same household as the person concerned and is in the same risk group as the aforementioned within the meaning of Article 49 of Banking Law No. 5411; that the customer had been informed orally that his loan request had not been approved because of the negative intelligence result; that, pursuant to the provision in Article 49 of Banking Law No. 5411, entitled “Risk Group”, which reads “A natural person and his or her spouse and children, and the partnerships in which they are members of the board of directors or general manager, or which they or a legal person control, jointly or individually, directly or indirectly, or in which they participate with unlimited liability, constitute a risk group. … For the purposes of this article, natural and legal persons between whom there are relationships of suretyship, guarantee or the like of such a magnitude that the payment difficulties of one of them would result in payment difficulties for one or more of the others shall be included in the relevant risk groups.”, it had been considered that the reason for the rejection of the loan request of the data subject’s father was the defaults on the loans of his son, who resides in the same household and is in the same risk group, and that it was mandatory to indicate the general default information concerning the son as the reason for the rejection of the father’s loan request; and that, as stated in Art. 5(2)(a) of Law No. 6698 on the Protection of Personal Data, personal data may be processed without seeking the explicit consent of the data subject where this is expressly provided for by law. The controller further stated that the section entitled “Special Case concerning the Identification and Assessment of Risk Groups” of the “….. Bank Information (Notification) Notice on the Protection and Processing of Personal Data”, made public via the bank’s website, also expressly stated and announced that the personal data of persons falling within a risk group – even if they are not customers – may be processed for the purpose of identifying, monitoring, reporting and controlling the risk group in which they are to be included, so that the limits of the credit to be extended to a risk group under banking legislation can be determined, and that the persons concerned had thus been informed on this point as well; and that it considered that providing default information on those in the same risk group, without detail and limited to the information forming the basis for the rejection of the customer’s loan, did not constitute a data breach under Law No. 6698.

The Board,

• considering that, within the framework of Banking Law No. 5411 and the other relevant legislation, the processing of the personal data of persons in a “Risk Group” falls within the legal ground of compliance with banks’ legal obligations laid down in Art. 5(2)(ç) only where the data are processed within the scope of banking activities, for the purpose of being used within the bank itself and of being transferred to the Risk Centre,

• considering that Art. 12(4) of Law No. 6698 provides that controllers and processors may not disclose to others, in breach of the provisions of this Law, the personal data they have come to know, and may not use them for purposes other than the purpose of processing,

• considering that it would not be appropriate to regard the bank’s sharing of the debt information in question as the performance of its statutory obligation to notify its customers of information relating to the service,

• given that paragraph (3) of Article 73 of the Banking Law provides that “Those who, by virtue of their capacities and duties, learn secrets belonging to banks or their customers may not disclose those secrets to anyone other than the authorities expressly empowered by law in this regard.”, and that the same matter is also regulated in Article 159 of the Banking Law in the following terms: “Those who fail to comply with the obligation specified in the first and third paragraphs of Article 73 of this Law shall be sentenced to imprisonment from one year to three years and to a judicial fine from one thousand days to two thousand days. The same penalties shall apply to third parties who disclose secrets belonging to banks and customers”,

• considering that, at the same time, Additional Article 1 of the Banking Law provides that “The provisions of Article 159 shall apply to those who disclose confidential information held by the Risk Centre to anyone other than the authorities empowered by law in this regard, or who unlawfully use it for their own benefit or that of another, disseminate it, give it, transfer it or obtain it. Where the offences defined in this paragraph are committed within the framework of the activity of a legal person, the security measures specific to legal persons under the Turkish Criminal Code shall be imposed on the legal person concerned.”,

• considering that, where the data in question are shared with third parties contrary to the law, the offence of unlawfully giving personal data under Article 136 of the Turkish Criminal Code will be made out in respect of the persons who commit that act, and that, moreover, pursuant to the provision in Art. 239(1) of the Turkish Criminal Code that “A person who gives or discloses to unauthorised persons information or documents in the nature of a commercial secret, banking secret or customer secret of which he or she has knowledge by virtue of his or her capacity or duties, profession or trade shall, upon complaint, be punished with imprisonment from one year to three years and a judicial fine of up to five thousand days.”, the disclosure of a customer secret will also be at issue in the present case, and proceeding on that basis, decided that the claim for non-pecuniary damages must be brought before the general courts; that, although the application referred only to the failure to respond to the compensation claim, action be taken under Article 18 on the ground that the obligations laid down in Article 12 had been breached; and that, since the allegation that the debt information was shared with third parties without the data subject’s consent and knowledge concerns an unlawful act and these acts are also regulated in the relevant provisions of the Banking Law and the Turkish Criminal Code, the matter be referred to the Banking Regulation and Supervision Agency (BDDK) so that it may assess whether action should be taken against the bank concerned and its staff under the Banking Law and the Turkish Criminal Code.

B. Assessment of the Decision

I agree with the Board’s decisions both to point to the general courts for the claim for non-pecuniary damages and to refer the matter to the BDDK for assessment. The decision is an important one in that it shows that the applications lodged by the data subject do not determine the scope of the Board’s examination.

In the case underlying the decision, the rule that confidential information held by the Risk Centre may not be passed on to anyone other than those authorised was breached. Indeed, in view of the express provisions of the Banking Law that are also cited in the decision, it is not possible to regard the sharing of the debt information in question as the performance of the statutory obligation to notify customers of information relating to the service. In the case at hand, too, they acted contrary to Art. 12(4) of Law No. 6698 and disclosed to another person, in breach of the provisions of this Law, the personal data they had come to know. In order to transfer personal data to someone else, explicit consent or one of the other conditions for data processing in Article 5 or 6 of the Law is required. It should not be forgotten that giving information orally also amounts to transferring personal data, that is, to processing personal data. Particularly in companies such as banks, data breaches are committed by employees even though all the necessary technical measures have been taken. Employees must without fail be given training on the protection of personal data.

It should also be noted that the fact that the Board keeps the scope narrow where the data subject has applied to the controller should not put controllers at ease. It should not be forgotten that the Board also has the power to carry out an on-site inspection where necessary. For this reason, the data subject’s application must be answered with the utmost care, any non-compliance concerning personal data must be remedied, and full compliance with the personal data protection legislation must be achieved as soon as possible.

As regards the Turkish Criminal Code (TCK), in order to avoid repetition we refer to the explanations we gave above in relation to Decision No. 2019/ 138 of 16. 05. 2019.

IX. Decision No. 2020/ 58 of 27. 01. 2020

A. Summary of the Decision

In the report submitted to the Authority it was stated that an insurance agency had shared personal data belonging to its customers on publicly accessible social media platforms for advertising purposes without the customers’ knowledge and that the policyholders had not given permission for this, and it was requested that the necessary legal action be taken. In its written defence the controller company stated that personal data belonging to customers had been shared via publicly accessible social media accounts, but that when these posts were made an attempt had been made to conceal the personal data by means such as a software feature or paper, although in some posts this had been overlooked for reasons such as carelessness and haste; that, after the warning letter had been received, the relevant posts that had been overlooked were deleted; that, in the system in which the policy records are kept, identity numbers are masked owing to a feature of the system used, so that no post containing identity numbers had ever been made; and that the shortcoming in this matter stemmed from lack of knowledge and that they could make the necessary corrections if these were pointed out.

The Board, for its part, stated in its decision that personal data may be processed without explicit consent pursuant to Art. 5(2)(a), (b), (c), (ç), (d), (e) and (f) of Law No. 6698 and that the controller is obliged to take all kinds of technical and administrative measures; proceeding from the finding that personal data had been processed without explicit consent and that the obligation to take technical and administrative measures had been breached, it decided to impose an administrative fine of TRY 22,500.

B. Assessment of the Decision

Although the controller says that identity details were not shared, it was established that names, addresses and identity numbers in masked form were included and that, apart from these, details such as licence plate numbers – which may in some cases constitute personal data – together with the colour, make and model of the vehicle, the premium payable by the customer and the total premium were also given.

The only distinction among personal data is that between data of special categories and data that are not; apart from this distinction, all personal data are equal. For this reason, the fact that the identity details cannot be seen is not a factor that mitigates the data breach committed by disclosing the other data.

Moreover, all the periods granted by the Law for compliance have expired, and everyone who has obligations under the Law must be in compliance with it. In other words, the fact that the breach stemmed from lack of knowledge is not a reasonable justification. While I agree with the Board’s decision, administrative fines unfortunately appear to be the only remedy for bringing into compliance those who persist in non-compliance.

X. Decision No. 2020/ 65 of 27. 01. 2020

A. Summary of the Decision

The complainant data subject learned that the journeys made through a platform offering transport services were rated by the drivers; the ratings relating to the complainant’s own journeys could not be accessed by the complainant, and the controller’s information notice contained no information to the effect that a rating of this kind would be carried out. As a result, relying on the right “to request information where personal data have been processed” laid down in sub-paragraph (b) of paragraph 1 of Article 11 of Law No. 6698 on the Protection of Personal Data (the Law), the data subject applied under Article 13 of the Law to the platform offering transport services, which has the status of controller. After the matter had been brought before the Board, the controller stated in its written defence that the user’s data were collected at the time of registration with the application and were processed because they were directly related to the conclusion and performance of the membership contract; noting that requests could be sent by data subjects to the e-mail address given at http:/www…...com/gizlilik-politikası, the controller stated that such requests were answered as quickly as possible, that the data subject had asked what the average rating out of 5 was in the application used, and that, “although the request was inadvertently not answered within the time limit”, a written reply had subsequently been given.

The Board decided:

• that – noting that paragraph (1) of Article 6 of the “Communiqué on the Principles and Procedures for Applications to the Controller” provides that “The controller is obliged to take all necessary administrative and technical measures in order to finalise the applications made by the data subject under this Communiqué effectively and in accordance with the law and the rule of good faith.” – the controller, which failed to answer within the time limit the data subject’s request based on the provisions contained in its document entitled “Terms of Use”, be instructed to answer the applications addressed to it under the Law in a timely, full and complete manner, both pursuant to paragraph 5 of Article 15 of this Law and in accordance with the terms announced by the controller itself,

• that it must be examined whether the rating of data subjects is directly related to the conclusion or performance of the contract,

• that, since the data processing activity based on the rating by drivers of the journeys made by customers/passengers and on the averaging of those ratings is not, within the scope of the condition that “processing of personal data of the parties to a contract is necessary, provided that it is directly related to the conclusion or performance of the contract”, a principal constitutive element of the performance of the contract, or has no

direct relationship with the performance of the contract, and having regard to the fact that this data processing activity is not based on any of the other data processing conditions set out in the same article, the conclusion was reached that the controller had acted contrary to the provision in sub-paragraph (a) of paragraph 1 of Article 12 of the Law that “the controller is obliged to take all necessary technical and administrative measures to ensure an appropriate level of security in order to prevent the unlawful processing of personal data”, and that an administrative fine of TRY 100,000 therefore be imposed on the controller pursuant to sub-paragraph (b) of paragraph (1) of Article 18 of the Law,

• that, as regards the data subject’s allegation that the controller’s information notice contained no information whatsoever to the effect that customers/passengers were being rated, the document entitled “Information on the Protection of Personal Data” had been examined; that the processing purposes contained no statement to the effect that passengers would be rated and that this could be seen by drivers; that neither the information notice (Information on the Protection of Personal Data) nor the user agreement (Terms of Use) contained any information on the rating of customers; that the data processing activity based on the rating of customers was therefore contrary, first of all, to the principle of “Compliance with the Law and the Rules of Good Faith” among the general principles governing the processing of personal data set out in Article 4 of the Law; that, when the matter was assessed from the standpoint of the principle of “Processing for Specified, Explicit and Legitimate Purposes”, the purposes stated in the controller’s information notice and in the text on the terms of use failed to explain what the real purpose of the personal data processing activity based on the rating of customers was; and that, the conclusion having been reached in this context that the controller had not fulfilled the “Controller’s Obligation to Inform”, an administrative fine of TRY 10,000 be imposed on the controller under sub-paragraph (a) of paragraph (1) of Article 18 of the Law,

• that the controller be instructed, in order to be able to continue the rating-based data processing activity, to determine an appropriate data processing condition under Article 5 of the Law, entitled “Conditions for the Processing of Personal Data”, to update its information notice accordingly, and to submit to the Board within 30 days, pursuant to paragraph 5 of Article 15 of the Law, supporting documents and records showing that it has completed the matters listed.

It was so decided.

B. Assessment of the Decision

In this decision, too, we are faced with the issues of failure to fulfil the obligation to inform and of the unlawful processing of personal data. Personal data must without exception be processed on the basis of explicit consent or of the other processing conditions in the Law. Whether personal data are processed on the basis of explicit consent or under the other conditions, the data subject must be informed in intelligible language and in a transparent manner. Information notices that do not reflect reality are nothing more than an apparent fulfilment of the obligation. For this reason, in training on the protection of personal data we also frequently dwell on the importance of the inventory obligation. Since drawing up a personal data inventory lays business processes bare, it makes it easier to fulfil the other obligations in the Law. Once business processes have been examined, it is possible to provide the appropriate information, to determine the legal grounds for data processing and to take the necessary technical and administrative measures.

In addition, the legal grounds must be properly identified. In practice, one also frequently encounters cases in which the legal grounds are wrongly determined because advisory services are obtained to an insufficient degree or not at all. Generally, no care is taken over the question of which legal ground the data are processed on; indeed, attempts are made to base almost all data processing activities on explicit consent. Although this looks like a safe course, it gives rise to an abuse of right that is contrary to the rule of good faith. It must also be said that from the outset the Board has worked very well and has used its decisions to inform people. Here, too, a good and correct decision touching on important points has been given.

Finally, let us note that the application in question is also used by us. That drivers rate passengers, just as passengers rate drivers, lies at the core of the logic of this application. In this way the artificial intelligence software running beneath the application matches the right passenger with the right driver on the next journey and, over time, pushes passengers and drivers who constantly receive negative ratings out of the system. However, the fact that the application has such a positive and attractive side does not constitute an excuse for the controller’s failure to comply with its statutory obligations.

XI. Decision No. 2020/ 67 of 27. 01. 2020

A. Summary of the Decision

The complainant stated that no explicit consent had been given for the advertisements and notifications sent to the complainant via SMS by a real estate company, and requested that the necessary action be taken in this regard.

The controller, for its part, stated in its defence that:

• the personal data kept in its records were the first name, surname and mobile telephone number,

• the personal data kept in its records were processed for the purpose of contacting the data subject for advertising, campaign and promotional purposes,

• the personal data had been obtained from publicly accessible information sources on the internet,

• the information sources in question could no longer be accessed and it assumed that these links were no longer active and had been removed; and, following the application made by the data subject, the personal data had been deleted from the system immediately and the data subject had not been contacted again.

The Board,

• considering that personal data may be processed without explicit consent only where the legal grounds in Art. 5(2)(a), (b), (c), (ç), (d), (e) and (f) of the Law are present,

• considering that, in the present case, it is understood from the reply given by the controller to the Authority’s request for information and documents that the personal data of the data subject were obtained from publicly accessible information sources and that the data subject had not given explicit consent,

• considering that, in accordance with the principle of making public contained in Art. 5(2)(d) of the Law, personal data that have been made public by the data subject himself or herself – in other words, that have been disclosed to the public in any manner – may be processed; that, for there to be a making public, regard must be had to what the intention behind making the data public was; and that, in the present case, even if the data have been made public, the personal data processing activity to be carried out would not be lawful if the data subject did not make the personal data in question public for the purpose of being contacted in connection with advertising activities,

• considering that, in the present case, the explicit consent of the data subject was not obtained for the personal data processed and none of the other cases in which explicit consent is not required was present, so that there was a breach of sub-paragraph (a) of paragraph 1 of Article 12 of the Law,

decided, on these grounds, to impose an administrative fine of TRY 50,000.

B. Assessment of the Decision

Once again we are faced with a decision concerning the unlawful processing of personal data. Under Article 5 of the Law on the Protection of Personal Data, personal data may be processed with explicit consent and, where one of the following conditions is met, without explicit consent:

a) it is expressly provided for by law,

b) it is necessary for the protection of the life or physical integrity of the person himself or herself or of another person, where that person is unable to express consent owing to actual impossibility or his or her consent is not recognised as legally valid,

c) processing of personal data of the parties to a contract is necessary, provided that it is directly related to the conclusion or performance of the contract,

ç) it is necessary for the controller to be able to comply with its legal obligation,

d) the data have been made public by the data subject himself or herself,

e) data processing is necessary for the establishment, exercise or protection of a right,

f) data processing is necessary for the legitimate interests of the controller, provided that it does not harm the fundamental rights and freedoms of the data subject.

Because of its importance for the decision, I wish to touch on the condition of making public.

The making public of personal data should not be understood to mean that the personal data may henceforth be processed for any purpose. For some reason such an understanding has taken hold in practice, and data that have been made public have begun to be used in particular for advertisements and campaigns. As the Board also correctly states in its decision, where data have been made public the personal data must be used in line with the purpose for which they were made public. The most typical example of this is the practice of us lawyers. On some days in particular we hand out countless business cards. But our purpose in handing out these business cards is not to have advertising directed at us with a view to selling us a product. It is so that people may contact us in order to seek advice on legal matters. In this context, while there is nothing unlawful in a person who has received our business card processing our personal data by passing them on to a friend who needs legal advice, it is unlawful for a printing house to process the contact details on these cards for the purpose of announcing its campaigns and to reach us in order to advertise.

In the law of personal data protection, purposive interpretation is a method to which recourse must frequently be had. Both the Board and the European Data Protection Board frequently underline purposive interpretation.

Conclusion

The decisions published by the Board are important for the shaping of practice. The points that stand out in the decisions which it published on 02.04.2020 and which form the subject of this study are: that personal data may be processed without explicit consent only pursuant to Art. 5(2)(a), (b), (c), (ç), (d), (e) and (f); that explicit consent must be based on free will; that the information notice must satisfy the minimum requirements in the relevant Communiqué; that the use of a single information notice in all processes cannot be regarded as fulfilment of the obligation to inform; that claims for compensation must be brought before the general courts; that it is important to distinguish whether or not a data breach is connected with the business activity; that an application to the controller should not in every case be left unanswered on account of a failure to meet the minimum requirements; that, where it is possible to verify identity by other means, the application must be answered; and that the legal ground forming the basis for the processing of personal data must be correctly determined.

Another point that must be emphasised, apart from these, is that the provision to the effect that reports and complaints concerning the matters specified in Article 6 of the Law on the Exercise of the Right of Petition will not be examined must not be interpreted restrictively. Since almost every dispute that comes before the Board is in any event of such a nature as to violate Articles 136-140 of the Turkish Criminal Code (TCK), a contrary interpretation (such as the interpretation made by the Board) will lead to the protection of personal data being hindered and to compliance not being achieved. The Board, whose purpose is to protect personal data, must also make its interpretations with a focus on that purpose.

A further point that attracts attention in the decisions is that the Board learns, in a case that comes before it, that an offence has been committed, yet takes no action. Under Article 279 of the TCK, it is an offence for public officials to fail to report, or to delay in reporting, an offence of which they have become aware by reason of their duties, and the sanction is imprisonment. The Board (where it learns that an offence has been committed) is required to report the offence and has no discretion in this matter.

Finally, it must also be underlined that the Board is not bound by the request as regards examination and administrative sanctions. The Board must conduct its inquiry without remaining bound by the request and must decide in line with that inquiry.

There have been decisions published earlier that are similar to those which the Board published on the date in question. These decisions are important for shaping practice and for demonstrating the Board’s consistency. The decisions must be followed regularly. For although all the periods granted by Law No. 6698 for compliance have expired, it is still not possible to say that full compliance has been achieved. Controllers should exercise the utmost care required in this matter before they incur an administrative fine.

Footnotes

  1. Assoc. Prof. Dr., member of the academic staff in Criminal Law, Criminal Procedure Law and IT Law, Istanbul Aydın University Faculty of Law / Attorney-at-Law, [email protected], ORCID: 0000-0003-4034-5436 ↑
  2. Trainee Attorney-at-Law, Istanbul Bar Association; Master’s student, Department of Public Law, Institute of Social Sciences, Marmara University, [email protected] ↑

Download PDF (in Turkish)

Related publications