11 April 2020Murat Volkan Dülger, Cansu Ceren KahramanCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

As is well known, ever since Law No. 6698 on the Protection of Personal Data (KVKK) entered into force on 7 April 2016, the transfer of personal data abroad has been a complete mystery. This is because, in order to transfer data to countries that are not safe, it is necessary to apply to the Personal Data Protection Board (the Board) with a written undertaking that the personal data are and will be protected, and to obtain its permission. However, no result has so far been obtained from the applications made to the Board (it is known that some data controllers, though not many, have applied to the Board for permission). Not only has no result been obtained; the Board has also still not announced the list of safe countries. In this situation, data controllers wishing to transfer personal data abroad have been left with a single option, and that is explicit consent.

Unfortunately, while this route is possible in theory, it is close to impossible in practice (for reasons such as the difficulty of obtaining employees’ explicit consent of their own free will and the fact that explicit consent can be withdrawn at any time). These sentences should of course not be taken to mean that the Board is working poorly. It must be acknowledged that the Board has worked intensively and successfully to establish personal data protection legislation in Türkiye. It should also not be forgotten, however (bearing in mind that the KVKK entered into force four years ago), that the great majority of the transfers abroad currently taking place are being carried out unlawfully. There are points on which the Board deserves praise, just as there are points on which it deserves criticism.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

Murat Volkan Dülger* / Cansu Ceren Kahraman*

Introduction

As is well known, ever since Law No. 6698 on the Protection of Personal Data (KVKK) entered into force on 7 April 2016, the transfer of personal data abroad has been a complete enigma. This is because, in order to transfer data to countries that are not safe, it is necessary to apply to the Personal Data Protection Board with a letter of undertaking to the effect that the personal data are and will be protected, and to obtain its permission. However, no result has so far been obtained from the applications made to the Board (it is known that some controllers, albeit not many, have applied to the Board for permission). Not only has no result been obtained; the Board has also still not announced the list of safe countries. In such a situation, controllers wishing to transfer personal data abroad have been left with a single option, namely explicit consent. Unfortunately, while this route is possible in theory, in practice it is close to impossible (for reasons such as the problem of obtaining employees’ explicit consent of their own free will and the fact that explicit consent can be withdrawn at any time).

Of course, the conclusion should not be drawn from these sentences that the Board is doing its work badly. It must be acknowledged that the Board is working intensively and successfully to establish data protection legislation in Turkey. Nevertheless, it should also not be forgotten (bearing in mind that the Law entered into force four years ago) that the great majority of the transfers abroad currently being made are being carried out unlawfully. Just as there are points on which the Board deserves appreciation, there are also points on which it deserves criticism. Frankly, we think that constructive criticism of this kind is also necessary (since we believe that it contributes to data protection legislation and to the resolution of the problems arising in practice).

Although it may be acceptable that the announcement of the safe and unsafe countries takes time because of the principle of “reciprocity”, the fact that no responses are given to the letters of undertaking and that controllers are shown no way (other than explicit consent) of making a lawful transfer abroad runs counter to the purpose of the Law.

The fact that, in its most recent announcement, the Board declared that “Binding Corporate Rules” had been adopted relates precisely to our last criticism. Belatedly though it may be, the Board has taken action on transfers abroad and has shown controllers an alternative route. The subject of this study is, accordingly, the version adapted to Turkey of the “Binding Corporate Rules” that have existed for many years in EU data protection legislation.

I. Binding Corporate Rules in EU Law

Before discussing binding corporate rules in Turkey, we think it necessary to discuss the binding corporate rules contained in the data protection legislation of the EU, which is the source provision.

In the EU, binding corporate rules were created during the period when Directive 95/46/EC was in force. Under the Directive, multinational companies, when transferring data to their group companies, had to fulfil simultaneously the obligations arising from the legislation of more than one country. This slowed down the business processes of multinational companies. In order to overcome this obstacle, multinational companies drew up their own privacy policies and tried to have them accepted by the data protection authorities.

The policies which they sought to have accepted were policies that enabled personal data to be transferred abroad with ease but did not fully protect personal data. To prevent this, the European Commission’s Article 29 Working Party determined the minimum requirements which these privacy policies had to meet and called rules meeting the minimum requirements “Binding Corporate Rules”.

These rules, created as a result of the work of the Article 29 Working Party, were subsequently included in the GDPR together with the minimum requirements they must meet. Under the GDPR, too, binding corporate rules must meet the following minimum requirements:

• the structure and contact details of the group of undertakings, or group of enterprises engaged in a joint economic activity, and of each of its members,

• the data transfers or set of transfers, including the categories of personal data, the type of processing and its purposes, the type of data subjects affected and the identification of the third country or countries in question,

• their legally binding nature, both internally and externally,

• the application of the general data protection principles, in particular purpose limitation, data minimisation, limited storage periods, data quality, data protection by design and by default, legal basis for processing and processing of special categories of personal data, the measures to ensure data security, and the requirements in respect of onward transfers to bodies not bound by the binding corporate

rules,

• the right not to be subject to decisions based solely on automated processing, including profiling, in accordance with Article 22,

• the rights of data subjects in regard to processing and the means to exercise those rights, including the right to lodge a complaint with the competent supervisory authority and before the competent courts of the Member States in accordance with Article 79 and to obtain redress and, where appropriate, compensation for a breach of the binding corporate rules,

• the acceptance by the controller or processor established on the territory of a Member State of liability for any breaches of the binding corporate rules by any member not established in the Union,

• how the information on the binding corporate rules, in particular on the provisions referred to in points (d), (e) and (f), is provided to the data subjects in addition to Articles 13 and 14,

• the tasks of any data protection officer designated in accordance with Article 37 or of any other persons or entities in charge of monitoring compliance with the binding corporate rules within the group of undertakings, or group of enterprises engaged in a joint economic activity, as well as of monitoring training and complaint-handling,

• the complaint procedures,

• the mechanisms within the group of undertakings, or group of enterprises engaged in a joint economic activity, for ensuring the verification of compliance with the binding corporate rules,

• the mechanisms for reporting and recording changes to the rules and for reporting those changes to the supervisory authority.

II. Binding Corporate Rules in Turkish Law

In its announcement the Board stated that the existing routes for transferring data abroad could prove insufficient to provide a workable practice as regards data transfers to be made between multinational groups of companies, and that binding corporate rules had been adopted for this reason. It also published the “Application Form on Binding Corporate Rules for Controllers” and the “Auxiliary Document on the Basic Matters that Must Be Included in Binding Corporate Rules for Controllers”.

Before turning to the details of the application, the question of by whom the application is to be made must be answered.

If the group1 has headquarters established in Turkey, the headquarters, and if the group has no headquarters established in Turkey, a group member2 established in Turkey must be authorised in respect of the protection of personal data, and the application must be made by this “Authorised Group Member”. The person authorised to make the application must submit to the Board, by hand or by post, together with the application form, the binding corporate rules and all other information and documents considered relevant to the application. Applications are assessed and decided by the Authority within one year of the date of the official application. Where necessary, this period may be extended by periods of six months. If the application is approved by the Board, the Authority notifies the person concerned of this and, where necessary, also announces it publicly.

In the application form the applicant is asked to provide information on the following matters:

• the applicant’s details,

• information on the binding corporate rules (the binding element, effective implementation, coordination with the Authority, the processing and transfer of personal data, mechanisms for reporting and recording changes, data security, accountability and other principles/tools, supporting information and documents).

The application form also contains general provisions on binding corporate rules. It is stated there that clear and intelligible language must be used in the binding corporate rules; that the group and each of the group members agree to act in accordance with the Authority’s instructions on the interpretation and application of the binding corporate rules; that, as regards the application of the rules, the person authorised to make the application is the point of contact; that the group will process the personal data transferred under the rules in accordance with Law No. 6698 and with the rules; that, if conformity with the Law and the Undertaking cannot be ensured for any reason, the Authority will be informed of the matter immediately; that in such a case the Authority will have the right to suspend the data transfer and to terminate the Rules; that, where personal data processed under the rules are obtained by others by unlawful means, this will be notified as soon as possible to the person authorised to make the application, and that these persons will in turn notify the person concerned and the Board of the situation as soon as possible; that the Board may, where necessary, announce this situation on its own website or by any other method it deems appropriate; that personal data may not be transferred under the rules to persons other than group members; that the route of the letter of undertaking must be used where a transfer to persons other than group members is intended; that, in cases such as the severance of any group member’s ties with the group or the termination of the rules for any reason, the personal data subject to the transfer will be sent, together with their backups, to the group’s headquarters established in Turkey or, if the group’s headquarters are not in Turkey, to a Group member established in Turkey that has been authorised in respect of the protection of personal data, or will be destroyed completely together with their backups; that, if there are provisions in national legislation that prevent the fulfilment of this obligation under the rules, the data processing activity will be restricted by taking the administrative and technical measures necessary to safeguard the confidentiality of the personal data subject to the transfer; and that the group and the group members may not disclose the personal data they process to others in breach of the provisions of Law No. 6698 or use them for purposes other than the purpose of processing, and that this obligation is not limited to any period of time.

Another document published is the “Auxiliary Document on the Basic Matters that Must Be Included in Binding Corporate Rules for Controllers”. In this document the differences and similarities between the binding corporate rules and the application form, together with explanations concerning binding corporate rules, are set out in the form of a table.

It is understood from the table that the following matters must be included both in the binding corporate rules and in the application form: the obligation to comply with the binding corporate rules; the rights and legal claims of the data subject; acceptance by the group’s headquarters established in Turkey, by a group member established in Turkey that has been authorised in respect of the protection of personal data, or by the controller transferring the data, of the obligation to pay compensation arising from the rules and to remedy breaches; the burden of proof lying with the company; the existence of appropriate awareness and training, of a complaint mechanism and of a compliance audit; the duty to work in coordination with the Authority; the requirement to describe the content of the rules; a description of the territorial scope of the rules; the reporting and recording of changes to the rules and their notification to the Authority; a description of the data protection principles covering transfers from Turkey or onward transfers; and accountability and other tools.

It can be seen, on the other hand, that easy access to the rules for data subjects and the ensuring of transparency, the existence of a staff structure charged with the application of the rules, and transparency in cases where national legislation prevents the group from complying with the rules are matters that are included in the rules but not in the application form.

III. Assessment of the Binding Corporate Rules

It can be seen that the documents published on binding corporate rules consist of a slightly modified translation, with additions, of the documents previously published by the Article 29 Working Party. In particular, the table published is, apart from a few minor points, a translation of the working document3 of the Article 29 Working Party adopted on 24 June 2008. Unfortunately, here too, as with our other regulations, we are faced with a problem of originality. Although unoriginal regulations may at first seem sufficient to solve certain problems, they later begin to give rise to further problems. Many examples of this could be given.

Although it may be accepted that, both because our trade relations with the EU are intensive and because the source provision of the Law is Directive 95/46/EC, the similarity of the rules on binding corporate rules is functional for achieving harmony with the EU, we think that where the similarity is too great (an almost word-for-word translation) it may damage the Board’s reputation. A somewhat greater focus on originality is needed, in terms of both content and form. At the very least, information should be provided with original content.

Turning to an assessment beyond the question of originality, the application form may be regarded as a summary of the binding corporate rules and/or as a document on how the security of personal data is ensured. The table may be said to be functional in that it sets out the differences and similarities between the application form, which requires a great deal of information in terms of content, and the binding corporate rules (since at first they give the impression of being the same document). It should also be noted that, as with the binding corporate rules regulated in the GDPR, the binding corporate rules adopted by the Board likewise fulfil the functions of enabling data transfers and of accountability.

Conclusion

Binding corporate rules are arrangements that provide great convenience, particularly for multinational companies, when transferring personal data abroad. The Board’s adoption of such an arrangement for Turkish data protection legislation is a very important step. For this step to retain its importance, it is necessary (unlike in the case of the letters of undertaking submitted for transfers abroad) that the outcomes of the applications made be announced and that the public be told what the deficiencies in the binding corporate rules are. Otherwise it will be no different from the letters of undertaking for transfers abroad. Unlawful data transfers will continue in practice and full compliance will never be achieved. We must point out that, since the periods for responding to applications are also long, transfers abroad will continue to be unlawful until a response is given. Responses should therefore be given as quickly as possible.

In addition, care should be taken to make the regulations more original in terms of both content and form. If attention is paid to this, damage to the reputation of the Board, which has carried out successful work in the protection of personal data, will have been prevented. The similarities are easily noticed, particularly by us (lawyers working on data protection legislation).

Finally, it must be pointed out that, just as the Board has duties incumbent upon it, so too do controllers. In order for this important step to achieve its purpose, we think that multinational controllers should draw up their binding corporate rules and apply to the Board as soon as possible, and should put an end as soon as possible to the unlawful data sharing (which, unfortunately, the present situation renders almost unavoidable).

Footnotes

  1. Assoc. Prof. Dr., faculty member in Criminal Law, Criminal Procedure Law and IT Law, Istanbul Aydın University Faculty of Law / Attorney-at-Law, [email protected], ORCID: 0000-0003-4034-5436 ↑
  2. Trainee Lawyer, Istanbul Bar Association; Master’s student, Department of Public Law, Institute of Social Sciences, Marmara University, [email protected] ↑
  3. “It means all of the companies and undertakings operating as part of a group of companies and the controllers that are engaged in a joint economic activity or have a joint decision-making mechanism concerning data processing activities.” ↑
  4. “It means the controllers in a group that are engaged in a joint economic activity with a company or undertaking belonging to a group of companies or that have a joint decision-making mechanism concerning data processing activities.” ↑
  5. Çalışma Grubu 29, Working Document setting up a table with the elements and principles to be found in Binding Corporate Rules, 24 Haziran 2008. ↑

Download PDF (in Turkish)

Related publications