29 October 2017Murat Volkan DülgerCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

One of the developments in the field of personal data protection that all stakeholders had been awaiting with interest for some time took place on 28 October 2017: the “Regulation on the Erasure, Destruction or Anonymisation of Personal Data”, issued by the Personal Data Protection Authority on the basis of Law No. 6698 on the Protection of Personal Data (KVKK), was published in Official Gazette No. 30224 of 28 October 2017. I should say straight away that, under Article 14 of the Regulation, its date of entry into force was set as 1 January 2018. Indeed, 1 January 2018 was also set as the date of entry into force in the other regulations still in draft form. This date has therefore been fixed as something of a starting date for personal data protection law. Article 3(1)(b) of the KVKK defines the concept of “anonymisation”, and Article 7 governs “the erasure, destruction or anonymisation of personal data”.

Paragraph 3 of Article 7 states that the procedures and principles for the erasure, destruction or anonymisation of personal data are to be laid down by regulation. In addition, Article 22(1)(e) of the Law provides that the Board has the duty and power to adopt the necessary regulatory acts on matters relating to its own remit and to the functioning of the Authority. The regulation in question was drawn up and published pursuant to this provision. Below, under separate headings, I will address the new rules and concepts introduced by the Regulation and the points that need explanation, without going into theoretical detail.

Related publications