25 February 2019Murat Volkan DülgerCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

The Personal Data Protection Board has published decisions of principle in many different fields. Most recently, in the Official Gazette of 18 February 2019, it published as decisions of principle the “Decision of the Personal Data Protection Board of 5 December 2018, No. 2018/143, concerning a data controller that transferred health data to a third party without relying on one of the processing conditions set out in Article 6 of the Law”, the “Decision of the Personal Data Protection Board of 26 July 2018, No. 2018/91, concerning a data controller that failed to fulfil its obligation to prevent unlawful access to personal data” and the “Decision of the Personal Data Protection Board of 28 June 2018, No. 2018/69, to the effect that personal data in personnel record files must not be destroyed where the reasons requiring their processing have not ceased to exist”. What distinguishes these decisions, when they are read carefully, is that they pioneer the entry into our legal system of two concepts: “data protection by design and by default”, which does not in fact exist in our legal system but came onto the EU’s agenda with the GDPR, and “risk-based liability”, which exists in comparative law but has not been accepted in our country to date. In this article I will discuss these decisions published by the Board in the context of the concepts mentioned above, taking into account Law No. 6698 on the Protection of Personal Data (KVKK) first and foremost, as well as the other legislation related to the subject.

Related publications