12 September 2019Murat Volkan DülgerCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

Let us touch on an important point that is often confused and wrongly applied in practice in the processing of personal data: are personal data that appear in a contract, or are processed pursuant to a contract, to be processed in every case under the processing condition in Article 5/2-c of Law No. 6698 on the Protection of Personal Data (KVKK) simply because they are stated in the contract? Or are there cases in which explicit consent must be obtained even then? I think that distinctions need to be drawn on this point, in the manner I will explain below, and that these may be effective proposals for a solution. If the personal data involved in a processing activity are based on this processing condition in every case, merely “because they appear in the contract”, this will lead to unlawful results.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

Assoc. Prof. Dr. Murat Volkan Dülger*

Let us touch on an important point in the processing of personal data that is frequently confused and misapplied in practice: are personal data that are contained in a contract or processed pursuant to a contract to be processed, in every case, on the basis of the processing condition set out in Art. 5(2)(c) of Law No. 6698 on the Protection of Personal Data (KVKK) simply because they are mentioned in the contract? Or are there cases in which explicit consent must be obtained even then? I believe that on this question the distinctions I shall explain below must be drawn and that they may offer effective solutions. If the personal data at issue in a data processing activity are in every situation based on this processing condition merely “because they are contained in the contract”, this will lead to unlawful results.

The controller may process personal data within the framework of the operations that are necessary for the performance of an existing and valid contract between it and the data subject or for the conclusion of a new contract. A contract is a legal transaction producing legal effects in which the parties declare their mutual intentions1. In order for this legal transaction to be concluded and to produce its effects properly, the processing of personal data is in most cases necessary, indeed indispensable. Data protection legislation, taking into account the needs of obligational relationships and of commercial life, has provided for the processing of personal data within the framework of a contract, subject to the other requirements being met, as one of the lawful conditions for processing. This case of data processing, which is regulated in Art. 5(2)(c) KVKK, is also found in the Directive, which is the source legislation, and in the GDPR (Art. 6(1)(b) GDPR).

This condition for processing personal data is present where the requirements are met that the necessary processing activity relates to the parties and is directly connected with the conclusion or performance of the contract.

Example: The processing of the contact and address details of a consumer who orders a product from an online shopping site, for the performance of the distance sales contract that has been concluded, is a case of this kind.

Example: “The obtaining by a bank, when a loan agreement is being concluded with it, of that person's payslip, land registry records and a document showing that he or she has no debts under enforcement proceedings will be considered to fall within this scope”2

Example: An estate agent's processing, and keeping in its file, of the parties' personal data such as identity number, bank account number, address, signature and telephone number within the scope of the contract signed between the landlord and the tenant, by virtue of the brokerage contract which it has with both of them3.

Nor is it mandatory for there to be a written contract in order for data processing pursuant to a contract to be at issue. Personal data may also be lawfully processed within the scope of the performance of a contract concluded orally or even tacitly. The question of proving the existence of the contract, however, must be assessed separately. Considered together with the principle of accountability, a controller that cannot prove that there is an existing and valid contractual relationship with the data subject must be very careful when processing data under this processing condition4. At this point my advice to controllers is that, for contracts requiring the processing of data on a large scale, they should without fail use the method of concluding these contracts in writing. In any event, the records capable of proving that the data are processed under this processing condition (for example receipts, invoices, log records etc.) must be kept meticulously.

Example: When a restaurant takes orders by telephone, a contract is in fact concluded with the customer. In this context, the activities of processing the customer's personal data, such as contact and address details in addition to the order details, fall within the performance of the contract. Since there is no written contract, the restaurant business must carefully retain the records, such as receipts and invoices, that will prove this contractual relationship and must be organised in such a way as to be able to produce them in the event of a complaint or dispute.

For this processing condition to be present, the contract must be between the “controller” and the “data subject”. With regard to data relating to third parties who are not parties to the contract but whose data are nevertheless processed in accordance with the provisions of the contract, a different processing condition is at issue, namely that the processing is necessary for compliance with a legal obligation. As I shall discuss below, this is a separate processing condition.

It may therefore be the case that, under the same contract, different data or different data processing activities are processed in accordance with different processing conditions. At first sight, drawing a distinction of this kind between the processing conditions may appear unnecessary and even pointless. It must not be overlooked, however, that the meaning and consequences of these two processing conditions, which rest on different foundations, may also differ. As the most practical difference that may be given as an example in this sense, I ask the following question: what must a controller essentially do correctly for us to be able to say that it has properly fulfilled its obligation to inform? Undoubtedly, for this the controller must have correctly determined on which concrete purpose in particular, and on which condition for processing personal data in general, the personal data that it subjects to processing are based. Otherwise the data subject cannot be properly informed and the controller will be liable for this.

Example: While data such as identity, contact and payment data relating to a customer who is in a contractual relationship with a courier company are processed by that company within the framework of the performance of the contract, the identity and contact details of the recipient, who is not a party to the contract, are processed within the framework of the legal obligation which the courier company has assumed under its contract with the sender.

Not every kind of data related to the conclusion or performance of a contract may be processed under this processing condition. The processing of the data must be directly related to the conclusion or performance of the contract. Being directly related to the conclusion of the contract means being connected with the acts of proposal, offer or acceptance directed towards concluding a contract. For example, activities for marketing or information purposes that are not of this nature do not fall within this processing condition5. Processing activities directed towards the conclusion of the contract may be carried out under this processing condition even if the contract is not subsequently concluded.

What is to be understood by being “directly” related to the performance of the contract? First and foremost, it is a concept that requires narrow interpretation in view of the drawbacks to which it may give rise. This concept must be considered in particular together with the principle of being relevant and limited to the purpose6. In cases of doubt as to whether a data processing activity may be carried out under the processing condition in question, the following is asked: are the personal data that we intend to process under this processing condition relevant, limited and proportionate to the purpose we envisage?

Although, alongside the essential elements of a contract, its ancillary elements may also give rise to this case of processing, it is not sufficient in itself that a processing activity is in some way associated with the contract, or even that the contract contains an express provision to that effect. What matters is whether the processing of the data is necessary for the performance of the principal and ancillary obligations forming the subject matter of the contract.

Accordingly, for the application of this processing condition, debates such as “must the personal data be limited to those contained in the contract”, “can personal data that are not contained in the contract not be processed under this processing condition”, “must there be an express provision to that effect in the contract in order to rely on this condition” are in fact wholly meaningless. Moreover, had the legislature pursued the aim that only personal data contained in the contract could be processed under this condition, it would have used the expression “provided that they are contained in the contract” instead of saying “provided that it is directly related” to the contract. Here the legislature has in fact left the controller a very small margin beyond what is contained in the contract, and has in any case prevented that margin from being interpreted broadly by means of the fundamental principles. Controllers, for their part, should therefore not fall under the impression that every item of personal data that is remotely or closely related to the contract may be processed within this scope. What is essential is that a balance be struck between the two parties, and that this balance be achieved by acting within that small margin which the legislature has left to the controller.

At this point, the cases in which the contract contains a provision on the processing of personal data must also be specifically addressed. For in practice data that must be processed on the basis of explicit consent may be confused with data to be processed for the performance of the contract, and, in a situation where explicit consent must be obtained, it is supposed that, where the contract instead contains an express provision on the processing of personal data, the data are being processed for the performance of the contract. Yet where data are processed within the scope of the performance of a contract, there is no need to insert a specific provision to that effect, because there is no such criterion. Consequently, just as an express provision in the contract does not make it lawful to process the data under the processing condition in question without obtaining explicit consent, so the absence of an express provision in the contract does not mean that explicit consent must be obtained in every case.

If the text of a contract contains a provision on the processing of personal data, or more precisely, if it cannot be inferred from the other provisions of the contract that the data will be processed and the need arises to insert a special provision for this, it becomes apparent that what is involved here is in fact data that must be processed on the basis of the explicit consent condition. In such a case the provision inserted in the contract will not amount to the obtaining of explicit consent either (more precisely, this explicit consent will not be valid because it is a consent obtained as tied to the contract), and the processing of the data will be unlawful. It should not be forgotten that data protection law rests on a philosophy of human rights that goes beyond the declaration and consent even of the data subject, and that, whatever the intentions of the parties may be, compliance with the fundamental principles laid down for the processing of personal data must be ensured.

In conclusion, what matters is to determine whether the processing of the personal data is directly related to the performance of the provisions of the contract proper. The criterion here is that the processing of the data concerned is objectively necessary for the performance of the contract. In other words, it must not be possible to perform a contractual obligation without the data processing activity in question taking place. According to the European Data Protection Board, when the assessment relating to this determination is made the following questions should be asked and the answers to them taken into account7:

• What is the nature of the service or goods to be provided to the data subject? What are the distinguishing features of this service or these goods?

• What exactly is the purpose of the contract? (Its substance and fundamental object)

• What are the essential elements of the contract and those ancillary elements that are important enough to affect its substance?

• What are the mutual positions and expectations of the parties to the contract?

• How have the service or goods to be provided been presented or marketed?

• Having regard to the nature of the service or goods, would an ordinary recipient of this service or these goods know or foresee that the data processing in question must take place under the contract concluded?

Example: Under the contract for the use of internet banking that it has concluded with its customer, a bank is required to process the customer's identity details, account details, mobile telephone number, e-mail address, security password and online transaction records within the framework of the service provided. Having regard to the nature of the internet banking service, the processing of these data is objectively necessary for the provision of the service that is the subject of the contract, and there is no need for the contract to contain a special provision stating that these data will be processed.

Example: A bank that wishes to analyse its customer's internet banking transactions and, on that basis, to market the services or products of its business partners to the customer cannot process data on the ground of performance of the contract by inserting provisions to that effect in the contract it concludes with its customer. It cannot be said that the data in question are an objective requirement of the internet banking service. For this reason, inserting a provision to that effect in the contract does not legitimise the data processing activity. What the bank must do in this situation is obtain its customer's explicit consent in respect of the data processing activity in question.

In this context I would also like to underline emphatically that contractual provisions in the nature of standard terms and conditions, in particular, will not make it possible to process data lawfully under this exception. Controllers who, fearing that data subjects will not give explicit consent, hope to achieve a result by including provisions on the processing of personal data among the provisions of pre-printed contracts will in that case be able to rely neither on the contract condition nor on the explicit consent condition, and may face heavy liability and sanctions.

In conclusion, controllers should not regard the condition of being necessary for the conclusion and performance of the contract as a catch-all processing condition as regards the justification for data processing; for cases that cannot be considered to fall within its scope they should either obtain explicit consent or, if any exist, rely on the other processing conditions. In order to record and process personal data on the basis of this condition in a process it is carrying out, the controller should test “whether the data are objectively necessary for the conclusion and performance of the contract” and should consider this processing condition together with the fundamental principles, first and foremost that of being “relevant, limited and proportionate to the purpose”.

Footnotes

  1. Academic / Attorney-at-law. ↑
  2. According to the Legal Dictionary of the Ministry of Justice, a contract is defined as follows: “A legal transaction which two or more persons carry out by declaring their mutual and concordant intentions with the aim of creating a legal bond between them, or of altering or extinguishing that bond; agreement.”. http://www.sozluk.adalet.gov.tr/Sözleşme. ↑
  3. Explanatory memorandum to Art. 5 KVKK. ↑
  4. Örneklerle KVKK Rehberi, s. 13. ↑
  5. Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects Adopted on 9 April 2019, European Data Protection Board, s. 7. ↑
  6. Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects Adopted on 9 April 2019, s. 12. ↑
  7. Article 29 Working Party Opinion 06/2014 on the notion of legitimate interests of the data controller under Article 7 of Directive 95/46/EC (WP217), s. 16–17 ↑
  8. Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects Adopted on 9 April 2019, s. 9. ↑

Download PDF (in Turkish)

Related publications