Introduction
This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.
The public disclosure of legal persons that breached the obligations imposed by Law No. 6698 on the Protection of Personal Data (KVKK), together with the start of the imposition of fines whose upper limit, as it then stood, reached one million Turkish lira, set all sectors in motion; owing to the increases applied to administrative fines in line with the revaluation rates, that upper limit now approaches two million Turkish lira. All at once, sectors whose customers are directly natural persons in particular began to look for persons and institutions that would bring their companies into compliance with the law. They wanted two things: to become compliant while spending little, and to avoid administrative fines.
To achieve this, data controllers were faced with two actors working in two different fields, and with two options: in order to become compliant with the KVKK and fulfil their legal obligations, either to engage IT companies and work with IT specialists, or to engage law offices and work with lawyers. In these days, when the deadline for registration with the Data Controllers’ Registry (VERBİS) has just been extended, the conflict between IT companies and specialists on the one side and law offices and lawyers on the other over the running of compliance projects continues to appear frequently, particularly on social media. As I myself work in a law office that runs compliance projects, I have until now not wished to enter this debate, in order to avoid the criticism that I am voicing a subjective view. I confined myself to following the developments and the debate closely. I now wish, however, to put in writing the views on this debate that we have so far expressed only orally.
Full text
This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.
Murat Volkan Dülger*
Introduction
With the entry into force of Law No. 6698 on the Protection of Personal Data (KVKK) in 2016, we as a society became acquainted with the concept of personal data, which had in fact existed in Europe for more than thirty years. In the days that followed, the subject took its place in Turkish law as a distinct field of law in its own right.
Although in the first period after its entry into force the Law was for the most part a subject of study for lawyers, data protection law was not taken very seriously in the other sectors. This situation lasted until 7 April 2018, the deadline for bringing personal data processed before the Law’s entry into force into compliance, had passed and 30 September 2019, which was (at that time) the deadline for registration with VERBİS (the Data Controllers’ Registry), was approaching (at present the deadline is 30 June 2020 for legal persons under private law). The reason why the awakening took so long was the prevailing belief that no institution would be able to have such a Law enforced in Turkey; for, if the Law were applied in full, business life would reach a deadlock, and the Law would thus somehow become, through inspections not being carried out and sanctions not being imposed, a statute that is in force but not applied, in other words a “dead letter”.
The Personal Data Protection Authority (the Authority), however, woke the sectors up one by one, so to speak, once the period granted by the Law had come to an end. Acting in particular on the complaints lodged with it and on breach notifications, it imposed sanctions; indeed, in many of its decisions it also affected the commercial reputation of the legal persons that had infringed Law No. 6698 by disclosing their trade names. In short, the Authority (and, of course, the Board) clearly showed, and continues to show, that the Law will be applied in full.
The exposure of the legal persons that breached the obligations imposed by the KVKK, together with the fact that fines began to be imposed whose upper limit, as it stood at that time, reached one million Turkish liras – although, owing to the increases made in administrative fines in line with the revaluation rates, the upper limit of the fines now approaches two million Turkish liras – set all sectors in motion. All of a sudden the sectors, particularly those whose customers consist directly of natural persons, began to look for persons and institutions that would bring their companies into compliance with the law. There were two things they wanted: to become compliant while spending little money and to avoid administrative fines. To achieve this, controllers found themselves faced with two actors operating in two different fields, and with two options: in order to become compliant with the KVKK and to fulfil their statutory obligations, either to contract with IT companies and work with IT specialists, or to contract with law firms and work with lawyers.
In these days, when the deadline for VERBİS registration has just been extended, the conflict between IT companies and specialists on the one hand and law firms and lawyers on the other over the conduct of compliance projects continues to feature frequently, and particularly on social media. As I myself in fact work in a law firm that carries out compliance projects, I have until now not wished to enter this debate, in order to avoid the criticism that I am reflecting subjective views. I confined myself to following the developments and the debate closely. Now, however, I wish to put into writing my views on this debate, which we have so far expressed orally.
1. The Reason Why the Problem Arose
I must first state that the great majority of these debates (with some important exceptions) consist of an effort to grab a share of the pie of earnings on the table. When the legislature regulates a particular field, especially if that field had not been touched at all until the regulation was made, this becomes an important source of income for consultancy companies and lawyers. There is nothing unlawful, unethical or abnormal in this. For, in an economic order that claims to be capitalist, everyone is in pursuit of earning money and making a profit, and there is neither anything shameful nor anything unethical in that. The reason for the conflict in this field, however, is that the subject matter regulated touches almost every area of life and concerns both the field of law and that of data security (digital data in particular). And this is where the conflict begins: to whom will the pie belong, or who will get how large a share of the pie?
Of course, one point should be made at the outset. Because of the prohibition of advertising to which they are subject and the habits it has engendered, lawyers generally prefer to remain silent on this matter. An important factor here is also that they are not in the habit of engaging in direct marketing or of defending their own field. I observe, however, that they discuss it among themselves in digital and face-to-face settings. IT companies, by contrast, owing to their habits in this regard and to the fact that they are in any event commercial companies established for the purpose of making a profit, express (rightly, from their own point of view) everything that crosses their minds, both on social media and in their consultancy/product presentations.
For my part, I shall try here to find a rational answer to this problem I have identified, without taking sides and, as far as possible, without losing my objectivity (for, while practising as a lawyer, it is not possible to be and to appear entirely impartial).
The first point that strikes me in this regard is that there are very great differences between projects that are in fact carried out for the same purpose. Why, then, when there is a single statute, does the approach to this matter diverge in practice along the lines of these two separate actors? What is the reason for this divergence in perspective? In the remainder of this article we shall seek the answers to these questions and try to set out the role of lawyers in the protection of personal data. To that end, it is first necessary to examine the approach of IT companies and specialists to the subject.
2. The Role of IT Companies / IT Specialists
First of all, since I too carry out these projects in practice together with my team, am personally involved in them, and carry out the great majority of these projects (particularly where there is no request to the contrary) as joint projects with IT companies providing consultancy in the field of data security, I consider it necessary to address the difference between the perspectives of IT companies and law firms on the projects, and the role of each side.
When one looks at the projects carried out by IT companies, it is seen that the projects focus more on the point of data security and that these companies help controllers to take the action steps relating to “technical measures”. Given the training of IT specialists, this is entirely normal; it is also what is expected of them. Moreover, companies that specialise in providing consultancy for the implementation of standards such as “27001”, rather than in selling and deploying products, are more knowledgeable and experienced than lawyers as regards how a project should be run, what its phases will be, what the inputs and outputs should be, how the process will be operated, the timing of the project and how adherence to the timetable will be ensured, the correct pricing and auditing of the project and, most importantly, motivating the company employees involved in the project to carry it through. As far as we have seen, in project development and management only lawyers who have specialised in fields such as “project finance” can have as much accumulated knowledge as the IT specialists in question. For conducting a lawsuit from start to finish and conducting a project from start to finish are different matters. I can readily say that this is the area in which lawyers who begin working on the KVKK have the greatest difficulty, and that it is one of the questions most frequently put to me. Of course, I must state that I do not in any case expect of lawyers the technical knowledge and skills possessed by IT specialists (apart from lawyers who, exceptionally, have worked in both fields).
That said, I can readily say this: after two or three different projects have been carried out together with a company that knows well how to run projects, how a project should be structured and conducted can easily be learned (just as debt enforcement proceedings are learned after being carried out two or three times in a master–apprentice relationship). Nevertheless, this does not mean that lawyers can take on a role on their own, particularly in large projects with many technical requirements. But running a project is a process that can be learned in a short time and that lawyers entering this line of work need to learn (even if they do not themselves assume the project management, then for the purpose of control). For I must state that carrying this knowledge and experience over into the classic legal work of a law firm also has many positive aspects, and that I have experienced this.
On the other hand, a lawyer (unless he or she has also studied in a field such as computer engineering and has worked in that field), however well he or she may know technology or however interested he or she may be in this field, cannot have as much accumulated knowledge and experience as an IT specialist who personally carries out data security projects and/or provides consultancy in this field. Of course there are exceptions to this, but exceptions do not break the rule; on the contrary, they reinforce it. Lawyers should therefore not attempt to undertake work on technical matters, and should obtain support in this field.
It is precisely at this point that the important difference between IT companies and lawyers emerges. As I see in practice, and as I also know the lawyers who do this work, the lawyers involved in KVKK projects, even where they have knowledge and experience of the technical dimension of data security, do not assume this responsibility; they either take on the projects together with data security companies or refer their clients to these companies. Why, then, do lawyers prefer to share in this way the money they would earn? It is an undeniable fact that one of the most important sources of motivation in the legal profession is earning money; many of us make our living solely from the income we earn from practising law, and we therefore strive to earn as much as possible. The reason is simple: lawyers, who throughout their professional lives constantly see problematic cases entailing liability and the damage to which they lead, rightly do not take risks in a matter in which they are not experts and (as should be the case) hand over the responsibility in this matter to the expert in the field. I must also state that I have not come across any exception to this.
Again as I see in practice, some IT companies and specialists unfortunately do not show the same sensitivity. I know that IT specialists reading this article will say “we are not like that”. And indeed many companies that do serious work in this field and set their fees accordingly without fail work with a lawyer in this field. However, a certain number of IT companies and IT specialists, few though they may be, do not do so and set themselves up as lawyers. The great majority of lawyers, by contrast (perhaps apart from a few exceptions, though I have never experienced any), for the reasons I have explained above, “stay out of this game”, if the expression may be permitted. Yet I have learned from persons who personally witnessed this and similar incidents that some IT companies marketing KVKK compliance projects also explain the legal part of the work and that, when asked by the legal counsel of the company to which they were making their presentation, who was present there, whether they were lawyers, they even said “we too have now become IT lawyers”. I must say that this is overstepping the line in every sense and entering a very dangerous area. This is a situation that entails not only ethical but also civil and criminal liability.
Why, then, on the other side of the coin, that is, on the demand side, do companies prefer a project in which no lawyer is involved? There is more than one answer to this: 1. Lack of knowledge and of awareness, since this subject is quite new. 2. Misdirection, which is directly connected with the first point. 3. The fact that everyone in any case thinks that he or she knows legal matters in his or her own way (a thought that passes once a fine has been incurred), 4. Cost. In fact the most important reason is the problem of cost. Companies (controllers), which in an already tight market have to operate with limited capital, rightly wish to fulfil this obligation (or to get this problem off their backs) at the lowest cost. I think that an important reason for consulting an IT specialist instead of consulting lawyers when it comes to compliance with the Law is that many IT companies work for a lower fee than that for which law firms work.
This difference in fees stems from a difference in both quality and quantity. To begin with, lawyers’ fees are, as throughout the world, high compared with many other sectors (in our country I can say that they are very low, indeed rock-bottom, compared with the USA and Europe; what an American or European lawyer asks for one hour of advice is around 300 or 400 US dollars or euros, and in these projects not even a lawyer’s man-day fee can come close to these figures); this stems from the fact that the profession, just like medicine, requires a demanding undergraduate education, in-service training and long experience, and indeed the greater part of the fee is made up of this experience imbued with knowledge. On the other hand, in these projects the number of tailor-made (more precisely, controller-specific) tasks to be performed by lawyers is also very large in quantitative terms. For in these projects lawyers bring companies into compliance as a whole from the legal point of view and, as it were, change from scratch all the legal practices that the controllers have had up to that time. This requires a command of all the details and the restructuring of all processes down to the finest detail.
In practice we see and hear that, in the projects they carry out, some IT companies, although this does not lie within their field of expertise, as it were set themselves up as lawyers and even attempt to give legal advice. Controllers who have no knowledge of data protection law, for their part, act on the inadequate and sometimes incorrect advice given by IT specialists and come to the conclusion that they have escaped administrative fines “thanks to” the consultancy they obtained for low fees. I must state that this is nothing more than an illusion.
In some of the projects in which I have been involved to date, consultancy services had been obtained before us only from IT companies. I thus had the opportunity to learn the content of projects carried out directly by IT companies. For example, in a compliance process conducted by an IT company, rather than mapping the company’s business processes by talking one by one to all the units within the controller Company, a description of one or two sentences had been given of each department’s process; as the relevant processes had not been broken down, the personal data processed had been written down in bulk; and, what is more, it had not been shown which personal data were collected / processed / stored in each individual process. Following these “findings”, reports had been delivered in which locked-cabinet measures, for ensuring the security of documents, papers, files etc. containing personal data, and measures such as access logging, encryption, an authorisation matrix, penetration testing and data loss prevention software, for the protection of personal data held in electronic form, were listed in bulk, avoiding the route of writing them out one by one for ensuring the security of the personal data contained in each individual process. I must state that these are necessary but insufficient for a proper project.
Even more serious than the fact that projects are carried out incompletely in this way are the recommendations given on legal matters. Another point taken lightly by IT companies is that they maintain that information notices can be written and inventories drawn up merely by looking at the guides published by the Board on its website, and that, since most companies have processes that resemble one another in certain respects, different information notices can be written by adapting the same texts to the company concerned. The confusion of information notices with explicit consent texts constitutes a separate issue again.
But the following conclusion should not be drawn from this either: “lawyers’ projects are very good; do not go to IT companies and conduct these projects only with lawyers.” The conclusion to be drawn is that the most correct method is for everyone to do the work he or she knows best, to work on matters relating to his or her own field and to give recommendations on matters relating to his or her own field. Accordingly, IT specialists should not set themselves up as lawyers, nor lawyers as IT specialists; everyone should approach the project from his or her own perspective and, if possible, cooperate.
3. The Role of Lawyers
As I have mentioned above, the directions from which the actors approach the subject and their perspectives differ from one another. While IT specialists focus on ensuring data security, lawyers focus on legal structuring. It is here that the need to determine the position of lawyers in the protection of personal data arises.
We lawyers, particularly through the compliance projects we carry out in the field of data protection, examine all of the companies’ business processes, contracts, policies and procedures. In these processes we identify the areas that are not compliant with the law and need to be corrected, as well as the deficiencies, and we carry out the necessary arrangements within the scope of the project. Where necessary we create new policies and procedures, add annexes to contracts and even rewrite some contracts from scratch. To be able to do these things, one needs to be a lawyer, not an IT specialist. For in our day, when even a lawyer who is a law faculty graduate cannot have a command of all the legislation, it would be meaningless to expect a person specialised in technical fields to have such a command.
This point is extremely important. As I have also stated above, the KVKK is a piece of legislation that touches every area of law, and data protection is a branch of law of that kind. Therefore, in order to be able to express an opinion in this branch of law or to manage processes such as a compliance project, one needs to have knowledge of almost every area of law and to be able to reason in those areas. It is precisely this characteristic that differentiates lawyers from specialists in other fields. For at the law faculty courses are taken in all the fundamental fields of law, from constitutional law to criminal law, from administrative law to human rights law, from the law of persons to the law of obligations, from labour law to private international law, and in order to graduate one has to pass all of these and the other courses. Even though in practice lawyers specialise in different fields (as, for example, I have specialised in criminal law and IT law), this lawyer’s perspective acquired at the law faculty and the knowledge of where one can find what, but most importantly the knowledge of how the norms of law are to be interpreted and applied, make the difference of lawyers in the interpretation and application of the Law plainly apparent and put them one step ahead.
This important difference stems from an accumulation of knowledge that cannot be found in IT specialists (unless they have studied at a law faculty) or in a person who has studied in another field of the social sciences. For at the law faculty it is not only what the rules are that is taught, but also how these rules are to be applied to an abstract dispute and the method for doing so. Therefore one or two introductory-level law courses taken at any faculty other than a law faculty, or a few law books that have been read, do not remedy this lack of grounding.
In their professional lives, too, lawyers are constantly resolving disputes or, foreseeing disputes likely to arise in the future, taking precautions in that regard such as contracts, formal notices and the like. The KVKK, too, is a law built upon carrying out work aimed at minimising the risks likely to arise in the future with regard to personal data, alongside technical measures and, even more so, under the heading of administrative measures, and upon proving that this has been done. At this point the past experience of lawyers and their reflexes for preventing legal risks come into play and perform an important function in the taking and implementation of administrative measures.
The need for this will be better understood by means of an example. Under Law No. 6698, controllers must establish a personal data retention and destruction policy. In order for the policies to be established, however, all the legislation to which the controller’s activities are subject must be examined with regard to limitation periods and preclusive time limits, and, with the controller’s business processes also being assessed, maximum periods for the retention and destruction of personal data must be determined and the relevant procedure established. Only we lawyers, who act within the framework of the laws in line with the wishes of the client, are able, by virtue of the legal education received and of professional experience, to meet the needs of the companies, being controllers, to which consultancy services are provided. As a result of assessments made and decisions taken without a command of the legislation, companies may well face sanctions and lawsuits arising from other legislation, or their commercial activities may reach a deadlock. This is exactly where lawyers come in.
That is one dimension of the matter; another dimension is that the persons legally authorised to give legal advice are lawyers and that IT specialists do not fall within this scope.
According to Article 35 of the Attorneys’ Law No. 1136, “Giving opinions on matters of law and on legal issues, bringing actions for and defending the rights of natural and legal persons before courts, arbitrators or other bodies vested with judicial power, following up judicial proceedings and drawing up all the documents relating to these matters belong solely to lawyers registered with the bar”. In other words, legal advice may be given only by lawyers. Conduct to the contrary is unlawful. Therefore, even if they are law faculty graduates, “persons who have not obtained the title of lawyer by being entered on the bar roll” should not venture into such a business as giving legal advice.
At this point controllers too must be warned. Lawyers, being aware of the responsibilities of the profession they practise, give their legal advice and carry out their legal acts properly and in good time, and act in the knowledge that they themselves will also incur liability (civil and criminal) as a result of wrong advice or a deficient act; indeed, by taking out professional liability insurance for this, they secure their clients against losses due to possible errors. In short, they protect the controllers who are their clients in every respect. It is not possible for the same to be provided by another person who does not bear the title of “lawyer”, whatever his or her knowledge and experience may be.
Where a company (controller), which under the Turkish Commercial Code is required to act as a “prudent merchant”, fails to act in this way and obtains legal advice not from a lawyer but from a third party whose business and expertise this is not, it will also not be possible for it to obtain compensation for the losses that may arise, because it did not act in that capacity.
4. What Should the Ratio of the Actors in Compliance Projects Be?
A distinction must be made here. What should the ratio be in terms of workload, and what should it be in terms of the nature of the work?
In terms of workload (quantity), although the situation varies according to the nature of the controller for which the project is carried out, the ratio varies within a band ranging from half-and-half to 70% - 30%, with the sides changing. I can demonstrate with mathematical data (number of man-days) that the picture emerging in the projects we have carried out has always been of this kind.
As regards the nature of the work, on the other hand, there is a great difference. For in this part decision-making and direction come into play. We can also explain this by the following example. In the construction of a building, the labour of the workers and the time they spend are many times greater than those of the civil engineer. Yet it is the civil engineer who, in a much shorter span of time, makes the structural calculations, decides how the building is to be constructed and supervises it. Accordingly, in qualitative terms the importance of the civil engineer in a construction is many times greater than that of a worker.
IT companies / specialists identify the technical gaps relating to data security (doing so at the stage of drawing up the personal data inventory), take part in the preparation of the gap report and subsequently, in the compliance process, put into effect the technical matters necessary for ensuring data security (in the form of having products purchased / producing / implementing them). The performance of all the rest (delivering the training, drawing up the personal data inventory, structuring the contracts, developing the procedures, etc.) and the responsibility for it fall to lawyers. Moreover, whenever an application or a question is received from any data subject or from the Authority, support is always obtained from lawyers in preparing the replies as well. In particular, the fact that in most projects consultancy services continue to be obtained from lawyers even though the project has ended is one of the most important proofs that, in qualitative terms, the weight lies with lawyers. I can therefore say that the ratio here is 80% law and 20% IT expertise.
I know that IT specialists will immediately object to this. However, I wish to underline once more, and emphatically, that the second ratio relates to the nature of the work and is not a ratio relating to workload or to the sharing of earnings.
We can explain this qualitative difference as follows: there is no point in keeping a rotten tomato in the freezer. When it is thawed, it is still an unusable and harmful rotten tomato. Therefore, before the tomatoes are frozen, they must be checked by an expert in the matter and it must be decided which of them is to be kept and which is not. The same holds true for personal data. Before data security is ensured by the IT specialist, it must be determined by a lawyer whether the data in question were obtained and processed lawfully, what the purpose and the legal basis of the data processing are, and what the final retention and processing period is. Otherwise, however good a security system may be set up, the stored data themselves will in any event be unlawful. And this is a point that can be soundly determined only by a lawyer.
The reason for this is that, on the technical side, measures are taken against data security risks that are in any event already known. Proceeding from examples such as past cyberattacks, data leaks and data losses, a projection for the future is made and an attempt is made to take hardware and/or software measures accordingly. On the legal side, by contrast, lawyers are, as it were, making their way through fog. For the Law is new, the Board decisions rendered on it are very few, and there are no court decisions at all. Technology, which develops every day, gives rise to new legal problems, while controllers seek urgent answers to their problems. And where a sanction is imposed on account of a personal data breach, it is again lawyers who are asked to respond to it and to find a solution. It can therefore readily be said that, in qualitative terms, the weight of the work lies on the legal side.
Conclusion
At this stage both actors carry out their projects within the framework of their own fields of expertise; the real problem, however, begins at the point where both actors claim that compliance can be achieved entirely through structuring in their own fields alone. Data protection law is a multidisciplinary field. Particularly with a view to fulfilling the obligations under the statute, companies need to be restructured in the fields of both IT and law.
This matter was also the subject of the announcement published by the Personal Data Protection Authority on 6 November 2019: “In the examinations it carries out upon complaint or of its own motion, it assesses from a broad perspective encompassing many legal and technical elements whether controllers have fulfilled these obligations, and decides accordingly. At this point it must be stated that the Board takes into consideration only compliance with the obligations set out in the Law and in the secondary legislation, and makes no assessment as to whether this compliance work is carried out within the controller’s own organisation or by obtaining external support. Finally, it should also be borne in mind that, given the diversity of the obligations to which controllers are subject, these obligations can be fulfilled only as the result of joint interdisciplinary work”.
As the Authority also emphasised in its announcement, full compliance can be achieved only through joint work and cooperation. That is to say, the result aimed at in the protection of personal data will be attained if IT specialists, using their knowledge and experience in the fields of IT, provide the technical measures that need to be taken with regard to data security, and lawyers provide the necessary consultancy by assisting with administrative measures and legal matters. Otherwise, companies will remain deficient in one respect as regards the protection of personal data.
Footnotes
- Assoc. Prof. Dr., Attorney-at-Law, Faculty Member. ↑
Related publications
Dülger, Murat Volkan / Gümüş, Gülçin, Personal Data Protection Law (Kişisel Verilerin Korunması Hukuku), 4th ed., Seçkin Publishing, Ankara, 2026.
Dülger, Murat Volkan, Legislation on Information Technology, Personal Data Protection and Internet Communication (Bilişim, Kişisel Verilerin Korunması ve İnternet İletişimi Mevzuatı), 7th ed., Seçkin Publishing, Ankara, 2021.
Dülger, Murat Volkan, “The Use of Bulk Data and Metadata in Preventive Policing and Intelligence Work from the Standpoint of Human Rights, Personal Data Protection and Criminal Procedure Law” (İnsan Hakları, Kişisel Verilerin Korunması ve Ceza Muhakemesi Hukuku Açısından Önleyici Kolluk Hizmetleri ve İstihbari Çalışmalarda Toplu Veri ve Metadata Kullanımı), conference presentation, 2026.
Dülger, Murat Volkan, “Lawyers' Obligations under the KVKK in the Light of the Board's Decisions” (Kurul Kararları Işığında Avukatların KVKK Yükümlülükleri), conference presentation, 2025.
Dülger, Murat Volkan / Gümüş, Gülçin, “The Right to Be Forgotten”, Essays in Honour of Prof. Dr. Yadigar İzmirli (Prof. Dr. Yadigar İzmirli'ye Armağan), 2024.
