13 November 2019Murat Volkan DülgerCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

As awareness of personal data protection grows, we see that data subjects’ curiosity about their data grows in parallel. Individuals now want to know by whom and why their data are held, for what purposes they are processed and whether they are transferred to third parties. For this reason they apply to the data controller and, in effect, call it to account by asking “which of my data are you processing, why, and to whom are you transferring them?”. Indeed, most of the decisions recently published by the Board arise where the data subject first exercises the right to apply to the data controller and then, being dissatisfied with the reply received or having received no reply at all, lodges a complaint with the Board. The decision summaries most recently published on 6 November 2019 are the best example of this.

In these decisions the Board gives data controllers very important pointers as to what they must pay attention to when a data subject exercises the right of application. It appears that data controllers have considerable difficulty in responding properly to the data subject, and the Board finds the remedy in clarifying the procedure and principles of responding in the context of concrete cases as well. It should not be forgotten, however, that the data subject’s right to apply to the data controller is one of the foundations of data protection law. For this reason, first the legal bases of this right, and then the kind of response that must be given to the data subject when the right is exercised, need to be made clear. Otherwise, as we have seen, the result is administrative sanctions imposed by the Board.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

Assoc. Prof. Dr. Murat Volkan Dülger

As the level of awareness regarding the protection of personal data rises, we see that data subjects’ curiosity about their data is increasing in parallel. Individuals now wonder by whom and why their data are held, for what purposes they are processed and whether they are transferred to third parties. For this reason they apply to the controller and, as it were, call it to account, saying “which of my data are you processing, why, and to whom are you transferring them?”

Indeed, the decisions recently published by the Board mostly arise where the data subject first exercises the right to apply to the controller and then, being dissatisfied with the reply received or having received no reply at all, lodges a complaint with the Board. In particular, the decision summaries most recently published, on 6 November 2019, are the best example of this.

In these decisions the Board gives the controller very important pointers as to what it must pay attention to when the data subject exercises the right of application. It appears that controllers have considerable difficulty in replying to the data subject properly, and the Board finds the remedy in clarifying the procedure and principles of replying in the context of concrete cases as well.

It should not be forgotten, however, that the data subject’s right to apply to the controller is one of the foundations on which data protection law is built. For this reason, first the legal bases of this right and then the manner in which the data subject must be answered when the right is exercised need to be clarified. Otherwise, as we see, the result is administrative sanctions imposed by the Board.

I. Why Should the Data Subject Have the Right to Apply to the Controller?

Understanding the subject depends in particular on clarifying the reason why this right has been provided for. In fact this is an important point that must be explained by reference to the need felt for the right to the protection of personal data itself. Accordingly, it must first be asked why there was a need to grant the individual a right of protection over his or her data and why this right was regulated by law.

Data protection law, while laying down the rules relating to data processing operations, fundamentally aims at ensuring that individuals’ data are secure. The aim, in this era in which the individual’s private sphere is in danger and under threat, is to leave the individual a private sphere nonetheless, in spite of everything, so that individuals can live in a manner befitting human dignity. The only way to do this is to create an environment in which the individual discloses his or her own data to whomever he or she wishes, does not disclose them to whomever he or she does not wish, and transfers them to whomever he or she wishes; that is, to ensure that individuals have control over their data.

For the individual to have control over his or her data, in our day, when one can hardly take a step without sharing one’s data in some way, requires that the individual be informed about the fate of those data, in other words that he or she be informed about every kind of process relating to his or her data, such as by whom and why the data are held, for what purposes they are processed and with whom they are shared. Only in this way does the individual feel that control over the data lies with him or her, and hence that the data are secure and that he or she will also determine the future of the data. Accordingly, in the context of data protection law, the necessary mechanisms must be established for the individual to have access to his or her data and to be informed about them.

II. In Which Legal Provisions Is the Right of Application Laid Down?

For the reasons briefly explained above, almost every piece of legislation providing for the right to data protection has provided for avenues of application by which the data subject, by applying to the controller, may obtain information about his or her data.

Individuals’ access to their personal data is first and foremost a constitutional right

The most fundamental provision on the subject is found in the 1982 Constitution of the Republic of Turkey. Under Article 20 of the Constitution, entitled “privacy of private life”, after it has been stated that everyone has the right to request the protection of his or her personal data, the next sentence is very clear: “This right also includes being informed of the personal data concerning oneself, having access to such data, requesting their rectification or erasure, and learning whether they are used in accordance with their purposes.”

The explanatory memorandum to the article also explains that the rights and freedoms which persons have over the data concerning them are set out, and the individual’s right to the protection of personal data and, within the scope of this right, the right to be informed and to have access to one’s data have thus also been guaranteed as a constitutional right1.

This has found more detailed expression in the Law on the Protection of Personal Data (KVKK). Article 11 of the Law, entitled “Rights of the data subject”, regulates which rights the data subject has in the application he or she makes to the controller and what information he or she may request from the controller. Thereafter, Article 13, entitled “Application to the controller”, lays down the rules governing this application.

The rules governing this application were set out more clearly by the “Communiqué on the Procedure and Principles of Application to the Controller”, issued by the Personal Data Protection Authority, which entered into force upon its publication in the Official Gazette No. 30356 of 10 March 2018.

In the GDPR, too, the subject is regulated in Chapter III, which governs the rights of the data subject.

III. The Decision Summaries Published by the Board on 6 November 2019 and Application to the Controller

It is in this context that the three decision summaries published by the Personal Data Protection Board on 6 November 2019 are extremely important and illuminating. These decisions must therefore be examined carefully.

1. The procedure for the data subject’s application: does the controller have the power to make any arrangement on this point?

How the data subject is to convey the requests concerning his or her personal data to the controller is the first stage of the right of application. Decision no. 2019/2962, published by the Board on 6 November 2019, contains important statements regarding the procedure for this application. Before turning to it, let us recall Article 5 of the Communiqué, which regulates how the application is to be made:

“The data subject shall convey his or her requests within the scope of the rights set out in Article 11 of the Law to the controller in writing, or by using a registered electronic mail (KEP) address, a secure electronic signature, a mobile signature or the electronic mail address previously notified to the controller by the data subject and registered in the controller’s system,

or by means of a software program or application developed for the purpose of the application.”

We understand from this article, which regulates the application procedure, that the controller may, apart from the methods specified in the Communiqué, develop any software program or application for the purpose of such applications and may operate it provided that it notifies data subjects of this application. The conclusion that seems to follow is therefore that the method by which this right of application is to be exercised has in one respect been left to the controller. The decision in question has, however, established conclusively that this is by no means the case.

The controller in the decision publishes a Privacy Policy on its website and gives notice that “applications to be made by the data subject must be sent to the company’s address by completing the KVKK request form, through a notary or by similar means”. The data subject nevertheless submits an application by means of a form sent electronically to the company’s customer services. The controller, in turn, rejects this application on the ground that it was unable to verify identity.

In its examination of whether the controller was justified in rejecting this application, the Board first draws attention to the point that “a further control mechanism, in addition to the methods specified in the Communiqué, was created” by the controller in respect of the applications to be made to it. Although the data subject’s application did not contain the mandatory elements set out in the continuation of Article 5 of the Communiqué, such as the Turkish identity number and the address, the controller’s “notification that applications may be made only through a notary or with an e-signature for the purpose of verifying identity” is, according to the Board, unlawful on the following grounds:

• The imposition of a financial burden not provided for in the Law or in the Communiqué,

• The obstruction of the data subject’s right to make a procedurally proper application by completing the KVKK request form in question, through his or her being misdirected in this way,

• Breach of lawfulness and of the rule of fairness.

The GDPR, drawing also on the experience of many years, has directly regulated the unlawfulness that may arise in connection with identity verification. Accordingly, requesting additional information in order to verify identity is possible only “where there are reasonable doubts”. Although the Board’s decision contains no information as to the existence of any doubt, the interest of controllers in verifying the identity of the requester when a request is addressed to them should not be disregarded either. For a reply given without verifying identity would this time lead to the conclusion that the data have been shared with a person other than the data subject and that the controller has not taken the necessary measures in this regard. Accordingly, the controller should have the right to set up additional control mechanisms in cases where, faced with a request addressed to it, it objectively has a reasonable doubt as to the identity of the requester. I think that this matter too needs to be clarified in the time ahead.

In conclusion, although it may be inferred from the provision of the Communiqué referred to above that the controller has the power to determine the procedure for the application made to it, the decision published by the Board has made it clear that this power has limits. In fact, this can already be derived from the fundamental principles relating to the processing of personal data. For there can be no question of the controller being entitled to use a power conferred on it in this area as it pleases, in a manner contrary to the individual’s right to the protection of personal data. Nevertheless, it is very important that the position has been clarified: although the controller may, for the applications made to it, provide for a practice other than the provisions of the Law or the Communiqué, this practice must not be in the nature of “an additional burden” . In conclusion, the Board is saying: “set up the necessary mechanisms for the exercise of this right, but do not make the exercise of the right more difficult beyond the rules introduced by the legal provisions”.

That said, as I stated above, the provision of the Communiqué was open to different interpretations. I suppose that it is for this reason that this situation, which was assessed as an infringement, did not come back to the controller directly as an administrative fine, and that the Board decided, as in my view too it should have, that the controller be instructed to show the utmost care and diligence in complying with the provisions of the Communiqué.

2. What the controller must pay attention to when replying to the application

Once the data subject has exercised the right of application, the manner in which this application is to be answered by the controller is the problem most frequently encountered in practice. For serious responsibilities have been placed on the controller in this regard, and most controllers are unfortunately not sufficiently equipped to reply properly to the requests addressed to them.

In this regard, controllers must first of all accept these obligations of theirs, just like every obligation introduced by the Law. It is not possible to evade this obligation by methods such as rejecting applications on various grounds, trying not to reply, or giving incomplete or incorrect replies without carrying out sufficient inquiry. This right of the data subject is first and foremost under constitutional protection, and at the end of the day the controller must answer lawfully the requests addressed to it, provided that they have been made in accordance with the procedure.

How the controller is to reply to the application is in fact regulated in detail by Article 6 of the Communiqué3. However, it is of course not possible for the answer sought in the context of every concrete case to be found in this article. Whether the methods used by controllers in replying are lawful will become clearer over time through concrete cases and Board decisions. Here too it is possible for us to draw conclusions, from the decisions most recently rendered by the Board, as to which methods of replying are unlawful.

• Is a reply by the controller such as “if you call this number, we will respond to your request”

an acceptable reply?

In the case that was the subject of the Board’s decision no. 2019/2274, published on 6 November 2019, a bank employee telephoned a customer and, in connection with the company of which the customer’s spouse was the manager, said that they had been unable to reach the spouse and requested help in reaching him or her. The customer claims that he or she applied to the bank, which had accessed for other purposes the contact details given for use in transactions concerning the customer, in order to obtain information, and that the bank did not give a written reply. In the examination carried out, however, it is understood that the complainant was informed, by an e-mail sent to him or her, in the following terms: “… in order to provide detailed information regarding your submission, we tried to reach you on your contact number but received no answer. You can learn the details regarding your transaction by calling the … Service Line”

What is at issue here is in fact a reply given by the controller to a question addressed to it by the data subject. The data subject conveyed the request to the bank in question by e-mail, and the bank responded by e-mail. Although it cannot be understood from the decision whether the data subject made a procedurally proper application, it appears that the Board did not regard this part as important. Irrespective of whether the data subject’s application was procedurally proper, the Board, faced with the notification by the controller that the details relating to the application could be learned from the Service Line, is of the opinion that this “cannot be regarded as a reply by the controller, in writing or in electronic form, explaining the matters requested by the Complainant in the application”.

Although it does not follow from the decision that the data subject made a procedurally proper application, it is clear that, if this is assumed, this reply by the controller would be contrary to the provisions of the Communiqué. For, instead of such a notification, information explaining the matters requested could have been provided. By contrast, I think that a reply to this effect given by the controller to an application by the data subject that is not procedurally proper should be assessed differently. I suppose that in that case too what the Board wants is that information be given to the effect that the application is not procedurally proper and that the request is therefore rejected. In conclusion, it is clear that what is sought in the reply given is “not the notification of some other channel for replying”, for in the concrete case the Board decided that no reply in conformity with the provisions of the Communiqué had been given and “that the Bank be reminded to show the utmost care and diligence in complying with the provisions of the Law and the Communiqué”.

Accordingly, instead of methods similar to the e-mail message that was the subject of the decision, controllers must in any event reply within the time limit if the request is procedurally proper; and if it is not, or if there is any other circumstance in which the request cannot be met, they must reject the application made, but only by stating the reasons.

• When an application is made to it, the controller must carry out sufficient inquiry

and reply only after that; it must be sure that it is not giving incomplete or incorrect

information.

One of the most important points in the controller’s reply is also that the information provided must not be incomplete or incorrect. Answering an application without the necessary inquiry being carried out within the controller’s organisation may result in incomplete and incorrect information being given to the data subject. Indeed, this is exactly what happened with regard to the application to the controller in the Board’s decision no. 2019/2945, likewise published on 6 November 2019.

The subject of the decision is the complaint of a person using the loyalty programme offered by an airline company. In response to the data subject’s request to change his or her user name and password, the controller requested an image of the front and back of the identity card on the ground of identity verification; the data subject, who at that time sent the image of the identity card electronically in order to access his or her information, subsequently requested that these data be erased and that, if they had been transferred to third parties, those persons also be notified. Having been informed in response to this request that the data were in any event not kept in the system, the data subject thereafter applied to the Board.

Although in the reply given by the controller to the data subject by e-mail it was stated that, for security reasons, the identity document in question had in any event not been recorded and had not been shared with third parties either, the examination carried out by the controller following the Board’s request showed that this was not the case. First of all, it was established that the identity verification process conducted by the call centre in contact with the data subject, by obtaining a photocopy of the front and back of the identity card, had in any event not been carried out in accordance with the company rules.

We see that, as regards the reply given by the controller to the complaint made concerning the taking of the identity card image, the Board dwells on the following points:

• According to the Board, the content of the complaint concerning the taking of the identity card images was not analysed correctly. For, contrary to the written working rules, the data subject’s complaint was answered without the request evaluation, opinion and support units having sufficient information, and as a result incorrect information was given to the effect that the identity card images had not been recorded and had not been shared with third parties.

• In the examination carried out, it was established that the data subject’s identity card image was kept on the servers of the complaint-module software company. The Board treated this incorrect information regarding the places where the data are stored and the third parties with whom they are shared as an indication that “the controller did not respect the data subject’s right of application”.

• In addition, according to the Board, the incorrect reply to the effect that no record had been made means that the controller

“was not transparent and did not reply in conformity with the law and the rules of fairness”

as was stated in the decision.

• Furthermore, it was decided that the controller’s failure to state in its reply which processing condition it relied on was contrary to the principle of “being processed for specified, explicit and legitimate purposes”.

As can be seen, the failure to give the data subject a correct answer and the controller’s lack of full command of the processor’s data processing methods were assessed as an infringement by the controller as regards the taking of the necessary technical and administrative measures, and it was decided that this at the same time constituted a breach of a large number of data processing principles.

Finally, attention should be paid to the assessment made by the Board in the decision concerning the identity verification procedure. In this decision the Board has revealed, at least to some extent, its opinion on the question on which I also dwelt above, namely whether additional information may be requested for identity verification. The wording used in the decision, “While it is considered appropriate for the controller to request additional information for the purpose of confirming the identity of the data subject in order to be able to reply to his or her application under the Law”, makes it clear that the controller may request additional information. Nevertheless, uncertainty persists as to whether a request for additional information may be made only on the basis of some reasonable doubt, as in the GDPR.

On the other hand, it is also noteworthy that a limitation has been placed on the additional information to be requested, having regard to the nature of the data. While accepting the request for additional information as appropriate, the Board finds it unlawful to request the data subject’s special categories of personal data, such as religion and blood group. According to the Board, this is contrary, first and foremost, to the principle of “being relevant, limited and proportionate to the purposes for which they are processed” and, in addition, to the conditions for the processing of special categories of personal data.

Footnotes

  1. The right to the protection of personal data was added to Article 20 of the Constitution by Article 2 of Law No. 5982. ↑
  2. “Bir operatör şirketinin, ilgili kişinin internet sitesi üzerinden yapmış olduğu başvurusunu kimlik teyidi yapamadığı gerekçesiyle reddetmesine ilişkin olarak Kurula yapılan başvuru” hakkında Kişisel Verileri Koruma Kurulunun 01/10/2019 Tarihli ve 2019/296 Sayılı Karar Özeti, www.kvkk.org.tr. ↑
  3. ARTICLE 6 – (1) The controller is obliged to take all necessary administrative and technical measures in order to conclude the applications to be made by the data subject within the scope of this Communiqué effectively and in accordance with the law and the rule of good faith. (2) The controller shall accept the application or shall reject it, stating its reasons. (3) The controller shall communicate its reply to the data subject in writing or by electronic means. ↑
  4. The written reply must contain: a) the information concerning the controller or its representative; b) the applicant’s name and surname, for citizens of the Republic of Turkey the Turkish identity number, for foreigners the nationality, the passport number or, if any, the identity number, the address of residence or of the workplace for the purposes of service, the electronic mail address for the purposes of notification, if any, and the telephone and fax number; c) the subject of the request; ç) the controller’s explanations concerning the application. ↑
  5. The controller shall conclude the requests contained in the application free of charge as soon as possible, depending on the nature of the request, and within thirty days at the latest. However, where the operation entails a separate cost, the fee specified in Article 7 may be charged. Where the application has been caused by an error of the controller, the fee charged shall be refunded to the person concerned. ↑
  6. Where the data subject’s request is accepted, the controller shall carry out what the request requires as soon as possible and shall inform the data subject. 4 “Bir bankanın, ilgili kişinin cep telefonu numarasını bankaya veriliş amacı dışında kullanması” hakkında Kişisel Verileri Koruma Kurulunun 18/09/2019 Tarihli ve 2019/227 Sayılı Karar Özeti, www.kvkk.gov.tr. 5 “Bir havayolu taşımacılık şirketinin (veri sorumlusu) sunduğu sadakat programını kullanan ilgili kişinin kullanıcı adı ve parola bilgilerini değiştirme talebi karşısında ilgili kişiden arkalı önlü kimlik görüntüsü talep eden veri sorumlusu” hakkında Kişisel Verileri Koruma Kurulunun 01.10.2019 Tarihli ve 2019/294 sayılı Karar Özeti, www.kvkk.gov.tr.

Download PDF (in Turkish)

Related publications