25 March 2024Murat Volkan Dülger, Gülçin GümüşCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

After Law No. 6698 on the Protection of Personal Data (KVKK; “the Law”) entered into force and data controllers carried out their compliance work, a number of problems emerged in practice, and a legislative amendment capable of resolving them had been awaited for quite a long time. Law No. 7499 Amending the Code of Criminal Procedure and Certain Other Laws (“Law No. 7499”), which contains that amendment, was adopted on 2 March 2024 and published in the Official Gazette on 12 March 2024. The date of entry into force of the articles amending Law No. 6698 was set as 1 June 2024.

An important point to be made here is that the existing Article 9/1 of the KVKK will remain in force, alongside its amended version, until 1 September 2024. As expected, the amendments are concentrated in Articles 6 and 9 of the Law, on the processing of special categories of personal data and the transfer of personal data abroad, but they have also affected some other articles. These amendments will be examined in detail below, article by article. The basic point to be clarified here, however, is whether the problems in practice have at last been resolved. For in practice, work on compliance with the Law has in some respects, so to speak, come to a standstill. Data controllers wish to comply fully with the rules laid down by the Law, yet they are at an impasse as to how they are to continue their commercial activities if they do so.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

Prof. Dr. Murat Volkan Dülger / Attorney Gülçin Gümüş

With the entry into force of Law No. 6698 on the Protection of Personal Data (the “Law”) and the carrying out of compliance work by controllers, a number of problems had emerged in practice, and a legislative amendment capable of remedying these problems had been awaited for quite a long time. Law No. 7499 on the Amendment of the Code of Criminal Procedure and Certain Other Laws (“Law No. 7499”), which contains that legislative amendment, was adopted on 02.03.2024 and published in the Official Gazette on 12.03.2024. The date of entry into force of the articles amending Law No. 6698 was set as 01.06.2024. An important point to be noted here is that the existing Art. 9(1) of the KVKK will remain in force, together with its amended version, until 01.09.2024.

As expected, the amendments are concentrated on Articles 6 and 9 of the Law, which concern the processing of special categories of personal data and the transfer of data abroad, but they have also affected certain other articles. These amendments will be examined in detail below, article by article. The basic point to be clarified here, however, is whether the problems in practice have at last been resolved. For in practice, compliance work under the Law has, so to speak, come to a standstill in some respects. While controllers wish, on the one hand, to comply fully with the rules laid down by the Law, they are, on the other, at an impasse as to how they would be able to continue their commercial activities if they did so. Likewise, lawyers working in this field also have difficulty in designing processes in full conformity with the Law and in advising their clients.

Will the amendments made by Law No. 7499 be able to shed light on the problems in practice and enable both controllers and practitioners to find their way? Let us try to answer this question by examining the amendments one by one.

I. The Amendments Made to Article 6 of the Law

The conditions for processing special categories of personal data laid down in Article 6 of the Law were among the points with which controllers found it hardest to comply fully. In particular, the fact that the processing of health data, which fall within the special categories of personal data, was subject to very strict conditions was frequently criticised, and a legislative amendment in this respect was eagerly awaited.

Because it is foreseen that special categories of personal data, when they become known to third parties, may cause the data subject to suffer harm or to be exposed to discrimination, they are regulated separately and placed under protection in the Law, and their processing has rightly been made subject to strict conditions. Although this is an entirely appropriate approach, the regulation should not lead controllers into an impasse that makes their activities almost impossible. In order to remedy the problems experienced in this respect, the article concerned has been amended, and we consider that the amended version of the article will to a large extent remedy the problems experienced in practice.

In line with expectations, the amendment provides for new legal grounds; however, there has been no change in the scope of the special categories of personal data or in the rule that the other security measures determined by the Personal Data Protection Board must be taken when special categories of personal data are processed.

A. Has There Been a Change in the Scope of Personal Data?

No change has been made to the first paragraph of the article, in which the special categories of personal data are listed one by one (numerus clausus – an exhaustive list that cannot be extended). In other words, there has been no change in the scope of the special categories of personal data, and the data regarded as belonging to the special categories are still the same data.

B. Are Explicit Consent and the Other Legal Grounds for Processing on the Same Footing?

The second paragraph of the article, providing that “special categories of personal data may not be processed without explicit consent”, which was the subject of debate when the article was first published, has been repealed, and the obtaining of explicit consent is now listed among the legal conditions.

It must be said first of all that, although this amendment will not bring about any change in practice, it is extremely important in that the text of the law and practice have now been made uniform. For at first sight the text of the article gave the impression that explicit consent ranked above the other legal conditions and that, even where one or more of the legal conditions required for the processing of special categories of personal data were present, explicit consent had to be, or could be, obtained. Indeed, when the Law was first published there was intense debate on this point. Subsequently, from the guides issued in the course of this process and from the Board’s statements, it became clear that explicit consent should not be obtained in every case for the processing of special categories of personal data and, indeed, that obtaining explicit consent where other processing conditions exist is unlawful. The same misunderstanding nevertheless persisted in the text of the article. In the text of the article as it stands after the amendment, it has become clearly apparent that explicit consent and the other legal grounds are on the same footing, and practice and the text of the article have been brought into line. Accordingly, from the normative standpoint too, explicit consent in the processing of special categories of personal data is now regulated on an equal level, as one of the grounds for lawful processing among the others.

C. Have the Expected Changes to the Legal Grounds for Processing Materialised?

In paragraph 3 of the article, changes have been made that were long awaited and are of the kind that will bring the greatest relief to practice. That paragraph governed the cases in which special categories of personal data could be processed without obtaining explicit consent. In this context the data were divided into two: data concerning health and sexual life, and the other special categories of personal data.

We have been voicing our criticism that the distinction between data concerning health and sexual life and the other special categories of personal data is inappropriate ever since the Law was published. For example, considering that genetic data are at the same time health data, doubts could arise as to the framework within which they could be processed. In addition, the fact that data concerning health and sexual life could be processed only by persons under an obligation of secrecy and by authorised institutions and organisations also caused great difficulties in practice. For the processing of health data by persons, institutions or organisations that are not under an obligation of secrecy is very often necessary in order to meet legal obligations. Controllers who, on the one hand, were obliged to process these data in order to fulfil their legal obligations but, on the other, were not under an obligation of secrecy and had no employee of that kind either, had difficulty in conducting their processes lawfully. Indeed, the explanatory memorandum of the amendment makes precisely this point: “Under the current provision, health data may be processed only by the Social Security Institution and the Ministry of Health and by health institutions. However, health data are needed above all in the insurance sector, labour legislation, occupational health and safety, and the field of social services”.

Taking all these points into consideration, important amendments have been made concerning the processing of special categories of personal data, and these legal grounds are addressed separately below.

1. Explicit Consent of the Data Subject

Before the amendment, it was provided that special categories of personal data could not be processed without the explicit consent of the data subject. Nevertheless, the guides prepared and the decisions published by the Personal Data Protection Board stated that explicit consent should not be obtained where other processing conditions exist, because in that case the impression would arise in the data subject that “the data processing activity will be stopped if he or she withdraws explicit consent”, “whereas in the specific case the data will in any event continue to be processed on the basis of the existing ground for processing”. With the amendment introduced by Law No. 7499, Art. 6 of the KVKK has thus been brought into line with practice.

What needs to be done in the current situation is as follows: (i) it must be determined whether the data to be processed belong to the special categories, (ii) the purpose for which the special categories of personal data will be processed must be identified, and (iii) if one or more of the processing conditions other than explicit consent are present, the processing activity must be carried out on the basis of the relevant sub-paragraph and the person’s explicit consent must not be requested. If, however, the other processing conditions are not present and the data processing activity in question is to be carried out, explicit consent may be obtained from the data subject. It should be noted at this point that, for explicit consent to be valid, the processing activity must in any event comply with the general principles.

2. Being Expressly Provided for by Laws

Where the processing of a special category of personal data is expressly provided for by laws, data may be processed under sub-paragraph

(b) of the article. The first point to be explained here is the scope of the expression “by laws”. It should be noted that, since the expression “by laws” is expressly used and since exceptions relating to fundamental rights and freedoms cannot be interpreted broadly, regulatory acts of the administration such as Presidential decrees and by-laws must not be regarded as falling within this scope, and only legal provisions in the form of a law must be taken as the basis.

Examples of this sub-paragraph are listed in the explanatory memorandum of the article. The recording in the criminal register, pursuant to the Criminal Records Law No. 5352, of final convictions handed down by Turkish courts, and the taking of persons’ fingerprints under Art. 5 of Law No. 2559 on the Duties and Powers of the Police, may be considered to fall within this sub-paragraph. For these data come under criminal convictions and biometric data and are special categories of personal data. It should be noted that in this case data may be processed only within the limits of the situation envisaged in the text of the law that provides for the processing of the personal data.

3. Being Necessary for the Protection of the Life or Physical Integrity of a Person Who Is Unable to Express Consent Owing to Actual Impossibility or Whose Consent Is Not Legally Valid, or of Another Person

For this legal ground, there must first of all be a person who is unable to express consent owing to actual impossibility or whose consent is not legally valid. An unconscious person may be given as an example of the former, and the mentally ill of the latter. For the special categories of data of these persons to be processed, the processing must be necessary for the protection of their own life or physical integrity or that of another person. Indeed, in these situations an overriding interest of the persons concerned is at stake. For example, if emergency treatment needs to be given to a person who has lost consciousness, blood group data may be processed. For in that situation it is impossible for the person to give consent.

This situation is in any case not alien to the legal order. The provision in question is the form, as regulated in the law of personal data protection, of a situation which is already regulated in criminal law under the heading of “presumed consent” as a ground of justification and which is frequently encountered in practice. In this way unity has also been ensured within the legal order.

The fact that this legal ground was regulated only in Article 5, which concerns the processing of personal data that do not belong to the special categories, is another point we have criticised since the Law was published. For although the type of data that mostly needs to be processed under this legal ground is special categories of personal data, the legislature had regulated this legal ground not in Article 6 but in Article 5. Moreover, in practice consent is in any case not sought from a person in this situation, and obtaining such consent is mostly either impossible or invalid. We consider that giving this situation a statutory basis is a most appropriate amendment.

4. Relating to Personal Data Made Public by the Data Subject and Being in Accordance with the Data Subject’s Intention in Making Them Public

If the data subject makes his or her special categories of personal data public, the processing of these data in accordance with the intention behind making them public becomes lawful. According to the Guide to the Terms Used in Law No. 6698, making public means “being made known to everyone”. The fact that the data are in a place where everyone can see them does not amount to making them public. The person must have an intention to that effect, and the controller must act in accordance with that intention of the person. On the other hand, it should not be forgotten that the general principles relating to the processing of personal data listed in Art. 4 of the KVKK must also be complied with. For these principles lay down the rules to be observed in every kind of data processing activity. Within this framework, special categories of personal data may be processed having regard to Art. 4 of the KVKK and the person’s intention in making them public.

For example, as also stated in the explanatory memorandum of the article, the information of a person who shares his or her blood group and allergy information, for emergencies, in an area accessible to everyone may be used in accordance with that purpose. Accordingly, images of a rally car on which the blood groups of its drivers are written must, as far as possible, be published on social media with the place where the drivers’ blood groups appear blurred. For these data were placed on the car in order to be used in the event of an accident. If, during a live television broadcast, blurring is not possible or would be very difficult, there will then be no data breach; but when photographs of the drivers celebrating first place, taken in front of the car, are published, these data must be blacked out. For the blood group information was not placed on the car in order to be published on social media. Publishing it would be processing data for a purpose other than the intended one.

Another point that needs to be clarified here is whether, for data that are in the public domain to be the subject of lawful processing, they must have been made public by the data subject, or whether data made public by third parties can also be regarded as falling within this scope. It is clearly apparent from the text of the article that, for this legal ground to apply, the data must have been made public by the data subject in person. Yet, particularly on social media platforms, certain health data that have not been made public by the data subject are seen to be disclosed. In such cases the data subject is generally not in a position to make his or her data public anyway. For example, person X has shared on a social media platform the blood group of his or her friend Y, who is in intensive care, and has asked for help. Z, who saw this post, has tried to help by sharing the same information on his or her own social media account. In this example, since X shared data that had not yet been made public by the data subject, the legal ground for this sharing is the legal impossibility explained in the preceding paragraph. There is, however, a question mark as to what the legal ground is for Z’s sharing of the data made public by X. For it is clear that there are no data here that have been made public by the data subject. In this case it seems more reasonable that the underlying legal ground should again be actual impossibility. However, considering that posts of this kind are made very frequently on social media platforms, it must be said that the matter needs to be given a statutory basis.

5. Being Necessary for the Establishment, Exercise or Protection of a Right

Where it is necessary for the establishment, exercise or protection of a right, special categories of personal data may be processed under sub-paragraph (d). The most common example of this situation is the personal data processing activities carried out by the parties in order to be able to prove their claims in litigation between employee and employer after the termination of the employment relationship. If it is necessary for special categories of personal data also to be processed for this purpose, this data processing activity may be carried out under Art. 6(d) of the KVKK without obtaining explicit consent. Let us note at this point that other criteria must also without fail be observed, such as that the processing of the special category of personal data must be a necessity, that the data to be shared must be directly related to the case and that the claim cannot be proved in any other way.

The explanatory memorandum of the article also gives the example that, in order for a person with a disability to be able to benefit from the right to purchase a vehicle, the disability report must be processed by the tax office. The same is true of the processing by the employer of the medical report of employees who are on sick leave on account of any illness.

6. Processing by Persons Under an Obligation of Secrecy or by Authorised Institutions and

Organisations Being Necessary for the Purposes of Protecting Public Health, Preventive Medicine, Medical Diagnosis, the Provision of Treatment and Care Services and the Planning,

Management and Financing of Health Services

In its version before the amendment, this legal ground was accepted as applying only to data concerning health and sexual life. With the amendment introduced, no such distinction is made any longer.

According to the explanatory memorandum of the article, the data processed by the Ministry of Health, the Social Security Institution and health institutions will be assessed under this sub-paragraph. The basic question to be discussed with regard to this legal ground is this: do the stated purposes apply only to public bodies or to other institutions and organisations authorised by them, or may private persons and organisations also process data in pursuit of these purposes? For “the planning, management and financing of health services”, referred to in the text of the article, are in fact activities carried out directly by the Ministry of Health or by persons and organisations authorised by the Ministry of Health. That being so, we are of the opinion that a justification put forward by private-law persons and organisations along the lines of “we are processing personal data on the legal ground of the planning of health services” would not be lawful. For the impression is that this purpose applies only to public institutions. It must be added, however, that no such impression arises with regard to every purpose referred to in the text of the article. For example, it is clear that the activity of processing personal data for the purpose of medical diagnosis is carried out by every health institution.

We are therefore of the opinion that some of the purposes referred to in the text of the article relate only to public institutions and organisations and to other institutions and organisations authorised by them, while others relate to both public and private institutions and organisations. We reach this conclusion in particular in view of the fact that the right to the protection of personal data is among the fundamental rights and freedoms and that exceptions to it must be interpreted narrowly. We nevertheless consider that this situation needs to be clarified by statutory provisions and by decisions of the Board.

7. Being Necessary for the Fulfilment of Legal Obligations in the Fields of Employment, Occupational Health and Safety, Social Security, Social Services and Social Assistance

This newly introduced legal ground is one of the amendments that will make the greatest difference in practice, and it will be of great convenience to controllers. The criterion for determining the legal grounds for the processing of personal data is, of course, not “convenience”; yet, considering that there are controllers who currently find themselves at an impasse in many of their processes, we think that this amendment will give them room to breathe.

In order to fulfil the obligations imposed on them, such as ensuring occupational health and safety, controllers need certain special categories of data. Under the existing legal regulation, however, it was almost impossible to fulfil those obligations without engaging in unlawful processing of personal data. Doing so required a very great deal of operational effort and time. For example, health data were kept only by the workplace physician, and when other units needed this information they could obtain only very limited information by applying to the workplace physician. Let us consider a concrete case in which the occupational health and safety team organises the night shifts. The workplace physician informs the OHS team that person X cannot work at night. When the OHS team asks why that person cannot work, the workplace physician must not disclose that the person is pregnant. On the other hand, however, in order to be able to arrange the night shift and the other working hours, the OHS team has to know the condition the persons concerned are in. The introduction of this legal ground is highly appropriate for resolving all these impasses.

With the amendment of the Law, employers in the position of controller will be able to process, without the need for explicit consent, the data that are necessary for fulfilling their legal obligations in the fields of employment, occupational health and safety, social security, social services and social assistance. This necessity will be assessed separately in each concrete case and for each line of business. In the explanatory memorandum to the article, the processing of the health data of dialysis patients in the course of the service of transporting them to the health-care institution is accepted as falling within this sub-paragraph. Similarly, workplaces that are under an obligation, pursuant to Art. 30 of the Labour Law (İş Kanunu), to employ persons with disabilities or former convicts may process health data and data on criminal convictions in order to fulfil those obligations. Although the explanatory memorandum to the article gives examples with regard to legal obligations, one of the greatest problems encountered in practice is the processing of special categories of personal data for the purpose of employment. Given the fact that certain jobs cannot be performed by persons with certain health problems, the processing of special categories of personal data becomes necessary in order for employment to be possible.

The point that calls for particular attention here is that, whatever the circumstances, the general principles governing the processing of data must not be infringed. Accordingly, the department concerned may retain only as much data as is necessary and only for as long as is necessary. It should therefore not be forgotten that the principles to be observed in the processing of data remain in force and that this legal ground is intended solely to remove the impasses encountered in practice.

8. Concerning Current or Former Members and Affiliates of Foundations, Associations and Other Non-Profit Organisations or Formations Established for Political, Philosophical, Religious or Trade-Union Purposes, or Persons Who Are in Regular Contact with Such Organisations and Formations, Provided That the Processing Complies with the Legislation to Which They Are Subject and with Their Purposes, Is Limited to Their Fields of Activity and the Data Are Not Disclosed to Third Parties

Under this sub-paragraph, it has become possible for foundations, associations and other non-profit organisations or formations established for political, philosophical or trade-union purposes to process special categories of data concerning their current or former members or persons who are in regular contact with these organisations and formations. For this, the processing must, first, comply with the relevant legislation and the purpose; secondly, it must be limited to the field of activity; and, lastly, the data must not be shared with third parties. Where these conditions are met, special categories of personal data may be processed.

Accordingly, for example, the health or religious data of trade-union members cannot be processed, since they are incompatible with this purpose. The explanatory memorandum to the article expresses this as follows: “For example, the processing by these organisations and formations of information on the status, as such, not only of their current members but also of their former members and of persons who are in contact with them by making regular donations will be assessed under this sub-paragraph. Likewise, a trade union will be able to process, in relation to its own field of activity and purpose, only data relating to trade-union membership. By contrast, personal data concerning the health or religion of trade-union members cannot be processed, as they are unrelated to its field of activity and purpose.”

II. Amendments Concerning Article 9 of the Law

Article 9 of the Law, which governs the transfer of data abroad, was another provision whose amendment controllers had been eagerly awaiting. For controllers transferring personal data abroad there are, in the current situation, in fact only two routes: either the explicit consent of the data subjects must be obtained, or an application must be made to the Board with an undertaking. However, since applications with an undertaking take a very long time and it is not possible to obtain explicit consent from every data subject, the transfer of personal data abroad has in practice become almost impossible. This has made the lawful use of cloud-based software whose servers are located abroad very difficult. For precisely this reason, difficulties had long been experienced with regard to this activity and an amendment of the text of the article had been awaited. In order to prevent this situation, which was also thought to hinder investment in our country, to meet the needs of commercial life and to protect the rights of the data subject, a regulation in line with the GDPR has been enacted.

Under the new regulation, the following conditions must be present for personal data to be transferred abroad lawfully:

KVKK Art. 9(1)

Legal conditions for processing listed in Articles 5 and 6 – Adequate protection – Transfer of data abroad

• • •

KVKK Art. 9(4)

Legal conditions for processing listed in Articles 5 and 6 – Adequate protection – Appropriate safeguards (KVKK Art. 9(4)(a), (b), (c) and (ç)) – Transfer of data abroad – In the country to which the transfer is to be made, the exercise of rights and the existence of the right to have recourse to effective

legal remedies

• • • •

×

KVKK Art. 9(6)

Legal conditions for processing listed in Articles 5 and 6 – Adequate protection – Appropriate safeguards – Occasional cases (KVKK Art. 9(6)(a), (b), (c), (ç), (d), (e), (f)) – Transfer of data abroad

× × × • •

A. Transfer of Data Abroad Where There Is an Adequacy Decision (Art. 9(1))

The most important change under the new regulation is the abandonment of the approach based on explicit consent. That said, what must first be established in order for data to be transferred abroad is the following:

• The existence of one of the conditions for processing in Articles 5 and 6, which lay down the conditions for the processing of data,

• The existence of an adequacy decision concerning the country, the international organisation or the sectors within the country to which the transfer is to be made.

Where one of the conditions for processing is present and there is also an adequacy decision, the transfer of data abroad has been made possible. The point to be noted here is that, with the amendment, an adequacy decision may now be given on the basis of an organisation or a sector. The requirement that an adequacy decision be given for the country as a whole has thus been removed. The explanatory memorandum to the article illustrates this as follows: “Instead of the whole of a foreign country with which the automotive sector in our country has intensive commercial relations, it becomes possible to give an adequacy decision in respect of the automotive sector in that country.”

The second paragraph of the article lays down the procedure by which the adequacy decision is to be given. Accordingly, the Board gives the adequacy decision, obtains the opinion of the relevant institutions and organisations where necessary, and the decision is published in the Official Gazette. The decision is reviewed every four years at the latest. If no review is carried out within that period, the adequacy decision remains valid. The Board also has the right to amend, suspend and revoke its decisions.

The matters to which the Board will have regard when giving an adequacy decision are listed in the third paragraph of the article as follows:

• The state of reciprocity as regards the transfer of personal data between Türkiye and the country, the sectors within the country or the international organisations to which the personal data are to be transferred,

• The relevant legislation and practice of the country to which the personal data are to be transferred and the rules to which the international organisation to which the personal data are to be transferred is subject,

• The existence of an independent and effective data protection authority in the country to which the personal data are to be transferred or to which the international organisation is subject, and the availability of administrative and judicial remedies,

• Whether the country or international organisation to which the personal data are to be transferred is a party to international conventions, or a member of international organisations, concerning the protection of personal data,

• Whether the country or international organisation to which the personal data are to be transferred is a member of global or regional organisations of which Türkiye is a member,

• The international conventions to which Türkiye is a party.

Listing the matters to be taken into account when an adequacy decision is given is an appropriate regulation in terms of transparency. That said, the text of the article does not contain an exhaustive list; it merely sets out, by way of example, the principal matters to be taken into consideration. In reaching its decision, the Board may also rely on other criteria that it considers necessary.

B. Transfer of Data Abroad Where There Is No Adequacy Decision (Art. 9(4))

Where there is no adequacy decision, the following conditions must this time be met for data to be transferred abroad:

• The existence of one of the conditions for processing in Articles 5 and 6, which lay down the conditions for the processing of data,

• The data subject having the possibility of exercising his or her rights and of having recourse to effective legal remedies in the country to which the transfer is to be made as well,

• The existence of one of the appropriate safeguards in the text of the article.

The appropriate safeguards referred to in the article are listed as follows:

• The existence of an agreement, not in the nature of an international convention, concluded between public institutions and organisations abroad or international organisations and public institutions and organisations in Türkiye or professional organisations in the nature of public institutions, and the authorisation of the transfer by the Board,

• The existence of binding corporate rules which the companies within a group of undertakings engaged in a joint economic activity are obliged to comply with, which contain provisions on the protection of personal data and which have been approved by the Board,

• The existence of a standard contract, announced by the Board, containing matters such as the categories of data, the purposes of the data transfer, the recipient and groups of recipients, the technical and administrative measures to be taken by the data recipient, and the additional measures taken for special categories of personal data,

• The existence of a written undertaking containing provisions that ensure adequate protection, and the authorisation of the transfer by the Board.

An obligation has been introduced to notify the Authority of the standard contract referred to in sub-paragraph (c) of the article. According to the explanatory memorandum to the article, “The standard contract will contain matters such as the categories of data, the purposes of the data transfer, the recipient and groups of recipients, the administrative measures to be taken by the data recipient, and the additional measures to be taken for special categories of personal data.”

The controller or the processor is obliged to notify the Authority within five working days of the signing of the contract. It will be noted that the obligation here concerns not only controllers but also processors. Indeed, as will be explained below, the obligation imposed on the processor by this article has been made subject to a sanction in Article 18. Thus, for the first time under the KVKK, an administrative fine has been introduced for processors as well.

C. Exceptional Transfer of Data Abroad Where There Is No Adequacy Decision and the Appropriate Safeguards Cannot Be Provided Either (Art. 9(6))

Provided that it is occasional, data may be transferred abroad in one of the following cases:

• The data subject gives explicit consent to the transfer, provided that he or she has been informed of the possible risks,

• The transfer is necessary for the performance of a contract between the data subject and the controller or for the implementation of pre-contractual measures taken at the request of the data subject,

• The transfer is necessary for the conclusion or performance of a contract to be concluded in the interest of the data subject between the controller and another natural or legal person

• The transfer is necessary for an overriding public interest,

• The transfer of personal data is necessary for the establishment, exercise or protection of a right,

• The transfer of personal data is necessary for the protection of the life or physical integrity of the person himself or herself, or of another person, where that person is unable to express consent owing to actual impossibility or his or her consent is not recognised as legally valid,

• The transfer is made from a register that is open to the public or to persons having a legitimate interest, provided that the conditions required by the relevant legislation for access to the register are met and that the person having a legitimate interest so requests.

The point to be noted here is that the paragraph in question is in the nature of an exception to the exception and should not be resorted to in every case. For it will be unlawful to transfer data, as under the former regulation, by obtaining the person’s explicit consent on the matter or by putting forward grounds such as that the transfer serves the performance of the contract. What is referred to here applies only to occasional situations. In other words, it is something that may be resorted to only once or a few times, where it is necessary and the relevant conditions are also present. It must not be of a continuous nature. Bearing in mind that the transfer of data abroad is, in principle, a continuous matter, it is also clear that this paragraph will not, and should not, find a very wide field of application.

It has been provided that sub-paragraphs (a), (b) and (c) of this paragraph cannot be applied to those activities of public institutions and organisations that are subject to public law. In addition, it has been stated that onward transfers of data and transfers to international organisations are also protected under this article.

No change has been made to the existing paragraphs 5 and 6 of the Law; they have been retained as they stand as paragraphs 9 and 10 of the amended article. Accordingly, where there are special provisions in other laws, the statutory provisions in the nature of special regulation will have to be applied. The Banking Law may be given as an example. This is also stated in the Banking Law Good Practices Guide. If other laws contain no provision that can be characterised as a special norm, the KVKK will have to be applied.

Lastly, it has been added to the text of the article that the procedures and principles will be laid down by regulation. That the matter will be regulated in greater detail by a regulation is a welcome development. With the regulation to be issued, it will thus become clear how data are to be transferred abroad.

III. Amendments Concerning Article 18 of the Law

By the amendments made to Article 18, which governs misdemeanours, an administrative fine has been provided for processors as well. It has been provided that an action may be brought before the administrative court against the administrative fines imposed.

With the amendment of the Law, an administrative fine has been provided for controllers and processors who fail to fulfil the obligation under Art. 9(5) to notify the standard contract. The point to be noted here is that, for the first time, a sanction under this Law is provided for processors as well. For although the Law provided that the controller and the processor are jointly responsible for the obligations relating to data security, no sanction was laid down against processors. Although the amendment of the Law makes no provision concerning data security, a sanction has been laid down for processors as well within the scope of Art. 9(5). In this context, for example, banks are regarded as processors where they act in the capacity of agent. This is stated in the Banking Sector Good Practices Guide on the Protection of Personal Data. Accordingly, banks acting in the capacity of agent are now also under an obligation to notify the standard contract.

On the other hand, an important change has also been made with regard to the legal remedy available against the sanctions. Under the new regulation, recourse may be had to the administrative court against the administrative fines imposed by the Board. This is a point that we have voiced on every platform. The criminal judgeships of peace, which were previously designated as the authority for objections against administrative fines, have neither the knowledge nor the time nor the motivation for this. For this reason, opening the path of administrative justice for the administrative sanctions imposed by the Board is an extremely important and positive development, both for a sounder review of those sanctions and for the development of the discipline of personal data protection law through the case law of the administrative courts as well. It should also be noted at this point that applications pending before the criminal judgeships of peace as at 01.06.2024 will continue to be heard there.

IV. Assessment and Conclusion

With the adoption of Law No. 6698, an important step had been taken in Türkiye towards the protection of personal data. However, it was neither in conformity with international standards nor sufficient. An attempt was made to remedy the deficiencies of the Law through the decisions of the Personal Data Protection Board and the guides published. It would not be wrong to say that, with the amendment made by Law No. 7499, the Law has become more workable without harming fundamental rights and freedoms. It is clear that the amendments made to Article 6 in particular will be of great importance in enabling controllers to organise their processes. That said, the effects of the amendment of the Law on practice will emerge more clearly once the guides and regulations to be published have appeared. Controllers, for their part, need to update their existing processes in line with the amendments to the Law.

Download PDF (in Turkish)

Related publications