3 July 2019Murat Volkan DülgerCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

The subject of this study is the “Bill Amending the Law on the Prevention of Violence and Disorder in Sports”, debated in the Grand National Assembly of Türkiye (TBMM) on 27 June 2019. The Bill consists of twenty articles and is based, in general, on the aim of preventing incidents of violence at sports events. Here, however, I will deal not with the Bill as a whole but only with its relevant article, which contains serious provisions concerning data protection law. In doing so, to make the subject easier to understand, I will avoid theoretical information and debates as far as possible and will underline what the provision seeks to introduce and the threats that may arise if it is introduced.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

Assoc. Prof. Dr. Murat Volkan Dülger*

The subject of this study is the “Bill Amending the Law on the Prevention of Violence and Disorder in Sports”1, which was debated in the Grand National Assembly of Türkiye (TBMM) on 27 June 20192. The Bill consists of twenty articles and is, in general, founded on the aim of preventing the incidents of violence that occur at sports events. Here, however, I shall not deal with the Bill as a whole, but only with the one article that contains serious provisions concerning data protection law. In doing so, and in order to make the subject easier to understand, I shall avoid theoretical information and debates as far as possible and underline what the provision in question seeks to introduce and the threats that may arise if it is introduced.

1. The relevant provision of the Bill

The provision under examination, sub-paragraph (d) of Article 3 of the Bill, reads as follows:

“The establishment of a system of identity verification by biometric methods at the entry of spectators to competition and spectator areas shall be decided by the Ministry after obtaining the opinion of the relevant federation. The technical equipment required for this purpose shall be installed by the institutions and organisations holding the right to use the sports facility.”

As can be seen, the provision regulates the taking of biometric data from persons entering sports competition and spectator areas. The establishment of the system through which these data are to be collected has, for its part, been left to the duty and competence of the Ministry.

Although I shall set out below, one by one, the reasons given for the provision and my criticisms of it, I must state before all else that this is the entire content of a bill which provides for so serious a personal data processing activity as the taking of biometric data from individuals. Neither where, by whom or in what manner these data are to be stored, nor the storage period, has been specified. Moreover, no convincing, concrete reason whatsoever has been put forward to show that the collection of these data is really necessary. At the very time when we are trying to make headway in the protection of personal data, this is truly a dangerous state of affairs, one capable of thwarting those efforts.

2. The reasoning of the provision in question

The explanatory memorandum to the article states that the aim is to prevent entry to events by uploading a false photograph to the electronic card or, in other unlawful ways, with cards issued in the name of others. In this way, the problems encountered in practice with photograph-based identification are to be eliminated.

In the debates on the article, the incidents of violence that have occurred were cited as examples of these problems. The fights that take place from before an event until its end, pitch invasions, insults and even woundings with knives or cutting instruments are a fact of life. It was claimed that, although the persons who commit these acts are given penalties such as a ban from attending events, the photograph-based identification system does not allow these penalties to be enforced. It was stated that a person who has been penalised attends events by unlawful acts such as using a card issued in another person’s name or printing a false photograph on the card, and that acts of violence in sports cannot be prevented. As the solution to such problems, the method of taking biometric data from persons entering events has been envisaged.

3. Biometric data in general

Biometric data are a type of special category personal data which enable individuals to be identified and verified by means of computer-controlled automated systems. Data such as an individual’s fingerprints and palm prints, face, iris and retina recognition, vein pattern and DNA information are the types of biometric data most widely used with today’s technology; however, considering that the law will be applied for a long time into the future, it is a likely prospect that, in that period and in parallel with the development of technology, new biometric data of many kinds and in great number will emerge. If the draft becomes law, the new types of biometric data will also fall within its scope; consequently, the scope and framework of the application of the law are not defined, nor can they be expected to be. Both the greatest advantage and the greatest disadvantage of biometric data is that they deliver almost one hundred per cent success in identification and verification. While this provides a high level of security on the one hand, on the other it poses a serious danger and threat to the fundamental rights and freedoms of individuals, above all the right to respect for private life and the protection of personal data.

Finally, I would like to note that, as regards the purpose and scope of biometric data and the violations committed in respect of such data, our national legislation and case law have not yet developed, and that the judgments of the European Court of Human Rights (ECtHR) should be examined for detailed information on this subject. The Court has many judgments, ranging from the definition of biometric data and the question of which data fall within the scope of biometric data to the safeguards that must be provided in respect of such data. While I do not consider it necessary to explain those judgments in detail here, I recommend that the Court’s judgments be examined. For I shall criticise the provision of the Bill under examination, too, particularly in the light of the views adopted by the ECtHR.

4. The objectionable aspects of the provision of the Bill

I must point out that, although I have worded the heading as the objectionable aspects of the provision, under this heading I shall in fact explain directly why the provision is unlawful. For there is no respect in which this provision is lawful.

Every reason that demonstrates the unlawfulness of the provision must be considered within the framework of the following fundamental provisions:

• Article 8 of the European Convention on Human Rights (ECHR), entitled “respect for private and family life”: the Court deals with every kind of case concerning the protection of personal data under this article. Accordingly, cases concerning the protection and violation of biometric data are examined in the context of Article 8 and decided on that basis.

• Paragraph 3 of Article 20 of the Constitution, entitled “privacy of private life”: personal data are protected by the additional paragraph inserted into the Constitution in 2010.

• Article 6 of the Law on the Protection of Personal Data (KVKK), entitled “conditions for processing special categories of personal data”: biometric data, which are personal data of a special category, are protected by the relevant article of the KVKK legislation, which is the basic legislation on the subject.

The unlawful aspects of the provision may be grouped under the following headings:

• Is a system of identity verification by biometric methods

necessary for the aim pursued?

In my view, the provision envisaging the taking of biometric data at the entrances to sports events must first be examined in terms of whether it is really necessary for the aim it seeks to achieve.

First, the processing of personal data without the explicit consent of individuals is prohibited. Where any one of the conditions for processing set out in the Law is present, however, data may be processed without explicit consent. It must not be forgotten that, whatever the case, the general principles listed in Article 4 of the Law must be complied with in all personal data processing activities. These principles form the essence of data protection law and set out the procedures and principles to be observed at every stage, beginning with the initial collection of the data.

According to these principles, personal data must be processed for specified, explicit and legitimate purposes and must be relevant, limited and proportionate to the purposes for which they are processed. Moreover, even where a lawful purpose exists, they must be retained only for as long as that purpose requires. To what extent is the elimination of the problems caused in practice by the electronic card system used at sports events compatible with these principles?

Biometric data can in no way be regarded as relevant, limited and proportionate to the purpose given as the justification. Moreover, although it is accepted that the right to the protection of personal data, too, may be restricted where the conditions are met, it must not be forgotten that this has to be done in conformity with the principle of proportionality.

The unlawful situations arising from the electronic card scheme are of a kind that can be remedied by improving the scheme and carrying out security checks more effectively. What is more, even if various problems are experienced under the current scheme, the consequences of the dangers that may arise from the storage of biometric data are far more serious than the potential harm that may arise from those problems.

Consequently, restricting the right to the protection of personal data by taking biometric data is not a proportionate measure in relation to the aim pursued. For a restriction of this kind legalises the storage of individuals’ biometric data by private entities. Data stored in this way become open to arbitrary practices and malicious use. Exposing individuals’ biometric data to every kind of arbitrariness, without this being based on lawful grounds, cannot be accepted as a necessary and proportionate measure.

• Imposing a compulsory choice between watching a sports event

and handing over biometric data

By the provision in question, the individual has been obliged to hand over his or her biometric data in order to watch a sports event. Yet compelling individuals to hand over their personal data in order to exercise their fundamental rights and freedoms is wholly contrary to the essence and the fundamental principles of data protection law. Handing over biometric data and being forced to consent to their processing is being made a precondition for watching a sports event live. This is plainly contrary to the KVKK.

• The position of children’s data

Since the provision places no obstacle in the way of taking biometric data from a child who wishes to watch a sports event, there is a serious danger in this respect as well. Under the International Convention on the Rights of the Child, the definition of a child was fixed at the age of 18. Thus, if biometric data are also taken from the under-18 group coming to watch sports events, the issue of the processing of personal data belonging to children will arise.

Although there is no distinction in this respect under national legislation and the KVKK, the provisions of the General Data Protection Regulation (GDPR) must be borne in mind. For example, the taking of the biometric data of a child who is a citizen of the European Union for a sports event which he or she will watch in Türkiye together with his or her family is subject to the GDPR. Yet the Bill in question complies with the provisions of the GDPR neither in substance nor in form. For the GDPR has regulated personal data belonging to children separately; besides setting this age at 16, it has stated that the Member States may change this age, provided that it is not lower than 13. By regulating children’s personal data separately, the aim was to introduce higher safeguards, taking into account the sensitivity of the situation as far as children are concerned. For this reason, where the data of children in this age range are in any way subject to the GDPR, the protections provided for by the GDPR must additionally be ensured in respect of those data.

It is therefore clear that this situation involves very serious violations. This Bill is a provision directly contrary to the culture of personal data protection that has been built up in our country by KVKK No. 6698 and other legislation and by the guidelines and decisions of the Personal Data Protection Authority. It is, moreover, contrary to legislative drafting technique in terms of both its text and its reasoning. The article, which regulates a very important matter concerning fundamental rights and freedoms, lacks clarity and certainty. This, in turn, is contrary both to the law and to the Constitution.

Even if we were to assume for a moment that the practice of taking biometric data is necessary, the article of the Bill cannot be accepted as lawful, for the following reasons:

• Restrictions on fundamental rights and freedoms must be imposed by law.

Even if we were for a moment to regard the measure of taking biometric data at the entrances to sports events, in order to remedy the unlawful consequences to which the electronic card system gives rise in practice, as a lawful restriction, it must not be forgotten that this restriction has to be imposed by law. What is to be understood by being imposed by law is not merely that the interference in question appears in the text of a statutory provision; it is far broader than that. A restriction to be imposed on a fundamental right and freedom, where the other conditions are met, must be set out in the law in all its aspects. This encompasses why, how and in what manner the restriction is to be carried out, together with all its consequences and protection mechanisms. For an exceptional measure must be provided for in all its aspects.

Looking at the concrete case, the duty and power to establish a system of identity verification by biometric methods has been conferred on the Ministry without any method whatsoever being specified. Thus every rule concerning the system will be determined by the Ministry. This means nothing other than leaving individuals’ biometric data wholly open to arbitrary use by administrative bodies. On the basis of a statutory provision drafted by rote, with neither beginning nor end, the Ministry will collect biometric data and will be able to use these data as it pleases, as though they were its own property.

As we have seen from earlier examples in our country, the administration’s record in this matter is far from bright. It was openly stated from the rostrum of the TBMM that personal health data were used even in the course of the objection lodged with the Supreme Election Council in the most recent elections for the mayoralty of the Istanbul Metropolitan Municipality. No answer has yet been given to the question of how the personal health data that the people handed over “in trust” to the State, and hence to the administration, came into the hands of a political party. Before that, the sale of the data of the Social Security Institution (SGK) and the seizure of the electoral roll database by hackers were scandals known to everyone. There is no way of explaining, within the bounds of reason and logic, the granting of the power to hold and process biometric data to an administration with so bright a past, without any safeguard whatsoever being provided against it, and the placing of this on a statutory footing.

• The article does not specify where, by whom, in what manner and for how long the personal data are to be stored.

In a manner similar to the danger I have explained above, the medium in which the biometric data will be stored and the period of storage are in no way specified either. The data subject’s exercise of his or her rights has thus been rendered wholly inoperative. Moreover, the provision is also contrary to the principle that data are to be retained in connection with the purposes for which they are processed, and it paves the way for personal data to be retained for other purposes.

Conclusion

Above, I have dealt with sub-paragraph (d) of Article 3 of the Bill, which provides for the taking of biometric data from persons at the entrances to sports events with the aim of preventing the unlawful consequences to which the electronic card system gives rise in practice, and I have set out my criticisms of the provision one by one. For that reason, in order to avoid repetition, I shall not go into the reasons for the unlawfulness of the provision at this point and wish only to underline the gravity of the situation.

The use of biometric data for verification purposes at the entrances to sports events must not be permitted. This is not compatible with the philosophy of personal data protection law. If it is nonetheless to be done at all costs, it must be done not by the text cited above but, in conformity with the principle of proportionality, by a detailed, clear and precise article which shows in detail by whom, for what purpose, how and for how long these data will be processed and with whom they may be shared.

Footnotes

  1. Member of the Faculty of Law, Istanbul Aydın University / Attorney-at-law. ↑
  2. For the Bill and its explanatory memorandum see: https://www2.tbmm.gov.tr/d27/2/2-1974.pdf. ↑
  3. For the Committee Report of 27.06.2019, the date on which the Bill was debated, see: https://www.tbmm.gov.tr/develop/owa/komisyon_tutanaklari.goruntule?pTutanakId=2333. ↑

Download PDF (in Turkish)

Related publications