15 November 2020Murat Volkan DülgerCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

The internet, defined as an international network of interconnected computers, has brought people in different parts of the world closer to one another and has made access and interaction between them easier. The number of internet users, which continues to grow, reached 4.57 billion as of July 2020. This figure corresponds to approximately 59% of the world’s population. As internet use has become so widespread, the trade, marketing and advertising strategies of businesses and the shopping preferences of consumers have turned towards digital platforms.

Full text

This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.

Murat Volkan Dülger*

Introduction

The internet, defined as the international network made up of interconnected computers, has brought people in different parts of the world closer to one another and has facilitated access and interaction between them. The number of users of the internet, the use of which is becoming ever more widespread, reached 4.57 billion as of July 2020.1 This figure corresponds to approximately 59% of the world’s population. As internet use has become so widespread, the trade, marketing and advertising strategies of businesses and the shopping preferences of consumers have turned towards digital platforms. Electronic commerce, which gathered momentum in the 1990s with the founding of Amazon, eBay and PayPal, is expected to generate revenue of 6.54 trillion US dollars by 2022.2 In these days, when we are all trying to get through the novel coronavirus pandemic together, the shift towards electronic commerce, in which we are not in one-to-one contact with the seller, has increased by 159% in our country.3 In addition to electronic commerce, businesses have also integrated their marketing activities into the digital world, on account of advantages such as the possibility of reaching the target audience directly, the scope for personalisation, lower cost and a flexible structure.

One of the fundamental functions of law is to respond to social needs. Since the provisions of the Turkish Commercial Code No. 6102 and the Turkish Code of Obligations No. 6098 were not considered sufficient for our digitalising world, the “Law on the Regulation of Electronic Commerce” No. 6563, published in the Official Gazette of 05.11.2014, No. 29166, was brought into force on 01.05.2015. With the adoption of Law No. 6563 on the Regulation of Electronic Commerce, new terms entered our legislation, one of which is the Commercial Electronic Message. In order to regulate the details of this innovation in our legislation and to set out how Law No. 6563 is to be implemented, the “Regulation on Commercial Communications and Commercial Electronic Messages” was published in the Official Gazette of 15.07.2015, No. 29417.

Law No. 6563 defines the commercial electronic message as “a message containing data, sound and image content that is transmitted in the electronic environment and sent for commercial purposes using means such as telephone, call centres, fax, automatic calling machines, smart voice recorder systems, electronic mail and short message service”.

Having regard to the statutory definition, there are certain points that must be considered in order for any data flow to be regarded as a commercial message. For a data flow to be accepted as a commercial electronic message, the environment in which the data flow takes place must first be determined. Irrespective of the means used, such as e-mail, telephone or short message, the data flow must take place in the electronic environment. The ultimate purpose that the data flow taking place in the electronic environment seeks to achieve is another important point. The ultimate purpose sought to be achieved by this data flow in the electronic environment must be of a commercial nature, such as businesses promoting or marketing their goods and services, promoting their business, or increasing their recognition through content such as greetings and good wishes.

As mentioned above, the market share of electronic commerce is steadily increasing and the conditions of competition are becoming more stringent. In order to make their presence felt in electronic commerce and to increase the recognition of their products and/or services, businesses wish to send commercial messages containing advertising, campaigns and promotions, in some cases directly to end consumers and in other cases to their other customers, to whom they supply products or services but who are not end consumers.

Under Article 6 of Law No. 6563, commercial electronic messages may be sent to recipients only on condition that their prior approval has been obtained. With the entry into force of the Law, companies intending to send commercial messages began to obtain approvals from individuals in physical or digital form; as the number of persons to whom commercial messages were to be sent increased, retaining, safekeeping and storing the approvals obtained and ensuring the confidentiality and security of the documents became a complicated matter. Likewise, as the companies wishing to obtain approval for commercial electronic messages became more numerous, it also became complicated for individuals to keep track of which companies they had given approval to and to withdraw with ease the approvals they had given.

It was for this purpose, namely to remedy the difficulties arising for both sides of commercial electronic messages, that, by an amendment made on 04.01.2020 to the “Regulation on Commercial Communications and Commercial Electronic Messages” published in the Official Gazette of 15.07.2015, No. 29417, companies wishing to send commercial messages were placed under an obligation to register, by 01.06.2020, the approvals they had obtained under the relevant legislation in the national database called the “Message Management System”, which enables message permissions to be managed, permissions to be viewed by recipients and complaints concerning messages to be examined.

Under the Regulation on Commercial Communications and Commercial Electronic Messages, the Ministry of Trade is responsible for establishing the Message Management System (İYS) and for carrying out the other tasks and operations required. The Ministry of Trade, for its part, authorised the Union of Chambers and Commodity Exchanges of Türkiye (TOBB) to establish the İYS. TOBB, in turn, set up a private company under the name İleti Yönetim Sistemi A.Ş. in order to establish, manage and maintain the İYS process, and transferred the task in question to that company.

Following requests for a postponement of the transition to the system made to the Ministry of Trade by businesses that had switched to various arrangements such as short-time working, remote working or suspension of production on account of the coronavirus pandemic, and by civil society organisations, the Ministry, by its announcement of 23.05.2020, postponed the date for uploading approvals to 31.08.2020 so that no hardship would be suffered. As the coronavirus situation had not come to an end, the date for uploading the approvals to the system was postponed until 01.12.2020 in accordance with the provisions of the “Regulation Amending the Regulation on Commercial Communications and Commercial Electronic Messages” published in the Official Gazette of 28.08.2020, No. 31227.

I. Cases in Which Approval Is Required, Cases in Which It Is Not Required and Cases Outside the Scope

A. Cases in Which Approval Is Required

Article 4, entitled “Definitions”, of the Regulation on Commercial Communications and Commercial Electronic Messages (the Regulation), published in the Official Gazette of 15.07.2015, No. 29417, defines “natural or legal persons engaged in electronic commerce activities” as the “Service Provider” and “natural or legal persons who are consumers or who act for professional or other purposes” as the “Recipient”. By Article 5 of the Regulation, the legislature laid down the general framework of the messages for which approval must be obtained; under that article, approval must be obtained for the commercial electronic messages that the service provider sends to the electronic communication addresses of recipients for the purpose of promoting or marketing its goods and services, promoting its business, or increasing its recognition through content such as greetings and good wishes.

B. Cases in Which Approval Is Not Required

As with every legal regulation, of course, exceptions and cases outside the scope have also been laid down in respect of commercial electronic messages requiring approval. Accordingly, in Article 6 of the Regulation,

1. Commercial electronic messages concerning changes to, and the use and maintenance of, the goods or services supplied, where the recipient has provided his or her contact details for the purpose of being contacted, 2. Messages containing notifications concerning an ongoing subscription, membership or partnership status and concerning collection, debt reminders, information updates, purchase and delivery or similar matters, provided that no goods or services are encouraged or promoted, as well as commercial electronic messages intended to fulfil an obligation to provide information imposed on the service provider by the relevant legislation, 3. Commercial electronic messages sent to the electronic communication addresses of recipients who are merchants or tradesmen, provided that they have not exercised their right of refusal, 4. Commercial electronic messages sent for information purposes to their customers by companies engaged in intermediary activities under the capital markets legislation,

are expressly listed as exceptional cases in which approval is not required, and accordingly no approval need be obtained for the commercial electronic messages in question.

C. Cases Outside the Scope

Cases outside the scope have also been laid down by Article 2 of the Regulation. In that article,

1. Commercial electronic messages sent by operators within the scope of the Electronic Communications Law No. 5809 of 05.11.2008 to their subscribers and users exclusively for the purpose of promoting or marketing their own goods and services or promoting their business, 2. Messages sent by foundation universities to their students and to the parents or guardians of those students, 3. Messages sent to their members by professional organisations having the status of public institutions, by associations working for the public benefit and by foundations granted tax exemption, in connection with the activities of the commercial enterprises belonging to them, 4. Informational messages concerning media services provided for the purpose of informing and educating the public by organisations engaged in radio and television broadcasting in accordance with the provisions of Law No. 6112 of 15.2.2011 on the Establishment of Radio and Television Enterprises and Their Media Services, 5. Messages sent by the State, local administrations and other public legal persons for the purpose of informing the public,

are expressly listed as cases outside the scope, and accordingly no approval need be obtained for the commercial electronic messages in question.

II. Conditions of Validity and Form of the Approval

In order for the approvals obtained to produce the effects of a legally valid approval, the Regulation lays down various conditions of validity and form. Under Article 7 et seq. of the Regulation, approvals may be obtained in writing or by any means of electronic communication; however, the conditions of validity and form differ according to whether the approval is obtained in writing or in the electronic environment.

For the approval to be valid, irrespective of whether it is obtained in writing or in the electronic environment,

the following is required:

1. The approval must contain the recipient’s affirmative declaration of intent to the effect that he or she accepts the sending of commercial electronic messages, his or her name and surname and his or her electronic communication address, 2. Where the approval is obtained by being included in the content of a contract such as a subscription, sale or membership contract, it must be set out at the end of the contract, before the affirmative declaration of intent or the signature, under the marginal heading “commercial electronic message”, in at least twelve-point type and with the possibility of refusal also being afforded, 3. The approval must not have been put forward by the service provider as a precondition for the supply of the goods and services it offers.

Where the approval is obtained in the electronic environment:

1. The affirmative declaration of intent must not appear pre-selected in the approval text, 2. Where the approval is obtained in the electronic environment, the information that the approval has been obtained must be transmitted to the recipient’s electronic communication address on the same day, with the possibility of refusal also being afforded.

Where the approval is obtained in writing:

1. It must bear the signature of the person giving the approval, 2. Where it is obtained by being included in the content of a contract such as a subscription, sale or membership contract, it must be obtained by being set out at the end of the contract, before the affirmative declaration of intent or the signature, under the marginal heading “commercial electronic message”, in at least twelve-point type and with the possibility of refusal also being afforded.

It should be noted that the service provider may also use the approval it has obtained for goods and services offered as a promotion, provided that they are offered together with its own goods or services. However, this promotional relationship is required to be based on a contract. Furthermore, irrespective of whether it is given in writing or in the electronic environment, an approval given to one of the parties to an agency, specially authorised business or dealership contract is deemed to have been given also for the other party to the contract, limited to the goods, services or brand that are the subject of the contract.

Another important point to be noted is that the burden of proving that the approval has been obtained and that the approval was handled in compliance with all the conditions listed above lies with the service provider.

Article 7(4) of the Regulation contains the provision that “Approval may not be requested by sending a commercial electronic message to the recipient’s electronic communication address.” The wording of the article is clear and expressly lays down that approval may not be requested by sending a commercial electronic message to the recipient’s electronic communication address; nevertheless, since the Law contains no such restriction and since, within the possibilities afforded by technology today, the provision makes it virtually impossible in practice for service providers to obtain approval in the electronic environment, we interpret the article as meaning that approval may be requested via recipients’ electronic communication addresses, but that requests for approval may not in addition be accompanied by commercial electronic messages aimed at increasing the service provider’s recognition, such as the promotion or marketing of goods and services or good wishes.

One of the matters giving rise to hesitation in practice is whether obtaining a single approval makes it possible to send the recipient every kind of commercial electronic message, whether electronic, physical or by voice. In our opinion, since the concept of the commercial electronic message encompasses every kind of communication with the recipient, whether electronic, physical or by voice, it will be sufficient to obtain a single approval from the recipient, provided that the channels in question are specified separately.

III. Procedure for Sending Commercial Electronic Messages

Although obtaining approval is a condition for being able to send commercial electronic messages, obtaining approval is not the only rule governing the sending of commercial electronic messages. That being so, there are points that must be observed when commercial electronic messages are sent to recipients after approval has been obtained.

First of all, the content of the commercial electronic message must be consistent with the approval obtained from the recipient. The heading or content of the commercial electronic message must include, for merchants, the MERSİS number and trade name and, for tradesmen, the name and surname and the Republic of Türkiye identity number. In addition to these, it is at the service provider’s discretion to include other information identifying it, such as its brand or business name.

Where the commercial electronic message is sent using limited spaces such as short messages, it is necessary and sufficient for the content of the message to include, for merchants, the MERSİS number and, for tradesmen, the name and surname and the Republic of Türkiye identity number. Here again, it is at the service provider’s discretion to include, in addition to these, other information identifying it, such as its brand or business name.

The commercial electronic message must include at least one of the service provider’s accessible contact details, such as its telephone, fax or short message number and electronic mail address, depending on the type of the means of electronic communication.

If the nature of the commercial electronic message cannot be clearly understood from its content, a wording identifying its nature, such as promotion, campaign or information, must be included. This wording must be indicated at the beginning of the message in messages sent by short message, in the subject line in messages sent by electronic mail, and at the beginning of the conversation in voice calls.

Where the commercial electronic message contains promotions such as discounts and gifts, or promotional competitions or games, this must be clearly stated in the message. The period of validity of the promotions and the conditions relating to the obligations that the recipient must fulfil in order to benefit from them must be made available to the recipient clearly and unambiguously, by easily accessible methods such as a URL address dedicated to these matters or a customer service number.

IV. The Recipient’s Right of Refusal

The final point to be observed with regard to the sending of commercial messages is the recipient’s right of refusal. Under Article 9 of the Regulation, entitled “Right of Refusal and Method of Notification”, the recipient has the right to refuse to receive commercial electronic messages without giving any reason. In order to enable the recipient to give notice of refusal, the service provider is obliged to provide in the commercial electronic message an accessible contact address, such as a customer service number, a short message number or a URL address dedicated solely to notices of refusal.

The possibility of giving notice of refusal must be afforded to the recipient, easily and free of charge, through the same communication channel as that by which the commercial electronic message was sent. It is important to note that it is mandatory for the possibility of giving notice of refusal to be included in every commercial electronic message sent. However, the fact that the recipient has exercised the right of refusal does not prevent the notifications that must be sent to the recipient under the provisions of the relevant legislation to which the service provider is subject. Accordingly, even if the recipient has exercised the right of refusal, the service provider may send notifications to the recipient in order to fulfil its obligations arising from the provisions of the legislation by which it is bound.

However, the service provider is obliged, within three working days after the recipient’s request refusing to receive commercial electronic messages reaches it, to stop sending commercial electronic messages to the recipient and to record the recipient’s declaration of refusal in the message management system; as stated above, this obligation does not prevent the service provider from sending notifications to the recipient as required by the legislation by which it is bound.

V. Intermediary Service Providers

Article 4 of the Regulation defines “natural and legal persons who provide the electronic commerce environment for the carrying out of economic and commercial activities belonging to others” as the “Intermediary Service Provider”. Under Article 11 of the Regulation, which governs the rights and obligations of intermediary service providers, intermediary service providers are obliged:

1. To send the content prepared by the service provider, 2. To provide the software, hardware, database and management system necessary for the commercial electronic message to be created, sent, received and stored and for the recipients’ information to be retained and processed, 3. To afford the facilities for the performance of the other obligations laid down for the service provider by the Regulation, 4. To include, in the content of the commercial electronic messages sent, at least one of the following details belonging to the intermediary service provider itself: brand name, trade name or business name.

The intermediary service provider may not obtain approval for the purpose of sending commercial electronic messages on behalf of others in order to promote or market their goods and services or to promote their business; it may, however, at the request of the service provider, send commercial electronic messages to recipients whose approval has been obtained by the service provider.

Finally, it must be noted that the intermediary service provider is not obliged to monitor the content provided by the natural and legal persons using the electronic environment for which it provides services, or to investigate whether there is any unlawful activity or situation relating to that content or to the goods or services that are the subject of the content.

VI. Retention Periods and Burden of Proof

In the event of a dispute, the burden of proof lies with the service provider and the intermediary service provider. The service provider and the intermediary service provider shall retain the approval records for three years from the date on which the validity of the approval ends, and the other records relating to commercial electronic messages for three years from the date of the record. These records shall be submitted to the Ministry upon request.

VII. The Recipient’s Right of Complaint

Recipients have the right to lodge a complaint electronically via the e-Government Gateway or the Ministry’s website, or in writing with the provincial directorate of the place where the complainant is resident. The complaint must contain, if the complainant is a natural person, his or her name and surname, signature and residential address and, if a legal person, its name and address together with the name, surname and signature of the person authorised to represent it or of its attorney. Recipients have a right of complaint only in respect of commercial electronic messages sent to their own contact addresses, and a recipient wishing to exercise the right of complaint must do so within 3 months from the date on which the commercial electronic message complained of was transmitted to him or her.

Although they differ according to whether the commercial electronic message was sent in the form of a short message, electronic mail or voice call, the recipient’s complaint will not be processed unless all of the mandatory elements listed in Article 14 of the Regulation have been indicated.

VIII. İYS Business Partners (Integrators)

On account of the size of the databases that service providers must upload to the Message Management System (İYS) by 01.12.2020, İleti Yönetim Sistemi A.Ş. has entered into agreements with various companies to act as intermediaries in making the İYS registrations of service providers. According to the criteria published by the İYS on its website, firms providing CRM software, ERP software, bulk short message and e-mail sending, call centre services and similar services may become business partners. These companies, which are official business partners of İleti Yönetim Sistemi A.Ş. and will be referred to in short as “integrators”, carry out the İYS integration of service providers. Although service providers are not formally obliged to work with integrators, since the free package of the message management system does not allow large volumes of data to be uploaded in one go and this privilege rests with the integrators, service providers are in practice virtually compelled to contract with integrators.

It must not be overlooked that integrators provide only technical support, whereas the approvals that service providers must obtain from recipients and the commercial electronic messages that they must send to recipients call for extremely comprehensive legal advice requiring expertise.

IX. Administrative Fines

In order to underline the importance of the legal procedure for sending commercial electronic messages, the principal administrative fines that will be faced in the event of non-compliance with the conditions set out above are as follows:

•

•

•

•

•

•

•

•

•

•

•

X.

Where unapproved messages are sent to more than one person at a time, 3,803 - 104,677 TL; where a commercial electronic message is sent without the recipient’s approval, 1,899 - 9,515 TL; where the approval obtained for the sending of commercial electronic messages does not contain the recipient’s affirmative declaration of intent accepting the sending of commercial electronic messages, his or her name and surname and his or her electronic communication address, 1,899 - 9,515 TL; where an approval obtained in physical form does not bear the signature of the person giving the approval, 1,899

- 9,515 TL; where, the approval having been obtained in the electronic environment, the information that the approval has been obtained is not transmitted to the recipient’s electronic communication address on the same day with the possibility of refusal being afforded, 1,899 - 9,515 TL; where the affirmative declaration of intent appears pre-selected in the approval text, 1,899 - 9,515 TL; where the possibility of giving notice of refusal is not included in every commercial message sent, 3,803 - 28,546 TL; where, although merchants and tradesmen have exercised their right of refusal, the sending of commercial electronic messages to them is not stopped within three working days, 3,803

- 28,546 TL; where, although the recipient has given notice of refusal, the sending of commercial electronic messages through the communication channel by which the notice was given is not brought to an end within three working days, 3,803 - 28,546 TL; where the heading or content of the commercial electronic message does not include, for merchants, the MERSİS number and trade name and, for tradesmen, the name, surname and Republic of Türkiye identity number, 1,899 - 19,031 TL; where the content of a commercial electronic message sent using limited spaces such as short messages does not include, for merchants, the MERSİS number and, for tradesmen, the name, surname and Republic of Türkiye identity number, 1,899 - 19,031 TL; in each of these cases an administrative fine in the amount indicated may be imposed.

The Relationship between the Message Management System and the Protection of Personal Data

When the data to be uploaded to the Message Management System are considered, it is apparent that the system is closely connected with the legislation on the protection of personal data. The close and inseparable link between commercial electronic messages and the legislation on the protection of personal data has made it essential for the two processes to be designed in businesses in such a way as to complement each other. Indeed, in the resolution of principle of the Personal Data Protection Board of 16.10.2018, No. 2018/119, on messages with advertising content, and in its decisions of 31.05.2019, No. 2019/162; of 08.07.2019, No. 2019/204; of 18.09.2019, No. 2019/276; of 07.11.109, No. 2019/332; of 14.01.2020, No. 2020/20; of 16.01.2020, No. 2020/34; of 27.01.2020, No. 2020/67; and of 10.09.2020, No. 2020/691, it has been repeatedly emphasised that the matter is connected with the legislation on the protection of personal data and that, in all matters relating to personal data, it is necessary to act in compliance with Law No. 6698 on the Protection of Personal Data. To deal only with the technical dimension of the commercial electronic message and to disregard the legal obligations may expose businesses to various sanctions. Equal attention must be paid to the fact that, if a correct relationship cannot be established between the legislation governing commercial electronic messages and the legislation on the protection of personal data, sanctions may be imposed both by the Ministry of Trade and by the Personal Data Protection Authority.

Under Law No. 6698 on the Protection of Personal Data, any information relating to an identified or identifiable natural person is deemed to be personal data. Under the personal data legislation the information must relate to a natural person, and information relating to legal persons is not considered to fall within the scope of that legislation. Law No. 6563 on the Regulation of Electronic Commerce, for its part, lays down separate rules for tradesmen and merchants. Accordingly, for the special rules concerning tradesmen and merchants to be applicable, no information containing personal data must be processed. Since e-mail addresses opened on a departmental basis under corporate e-mail domains (for example [email protected], [email protected] ) and calls reaching the switchboard via the company’s landline do not render any natural person identifiable, these may be used, provided that the other conditions laid down in the legislation on tradesmen and merchants are also fulfilled. E-mail addresses created from persons’ names together with corporate e-mail domains must, although there are views to the contrary, be regarded as personal data. (for example yı[email protected]) As can be seen from the example, since a natural person is identifiable by means of e-mail addresses used in this way, they must be regarded as the employee’s personal data, and the commercial electronic message system must be set up accordingly.

Businesses which are deemed to be service providers under Law No. 6563 on the Regulation of Electronic Commerce, which obtain the personal data of natural-person customers and of the officers and employees of legal-person customers, and which themselves determine the purposes and means of processing, at the same time have the status of controller under Law No. 6698 on the Protection of Personal Data. Those acting as controller are obliged, under Article 10 of the same Law, to provide information to the data subjects at the latest at the time when the personal data are obtained. One of the points to be observed in fulfilling the obligation to inform is the purpose of processing. If the data of the data subjects are obtained in order to send commercial electronic messages, this purpose of processing must be communicated to the data subjects.

In parallel with this, if, although there was no purpose of sending commercial electronic messages when the personal data of natural-person customers and of the officers and employees of legal-person customers were obtained, the business has subsequently decided to carry out commercial electronic message processes, the changed purpose of processing must also be communicated to the data subjects.

To whom and for what purpose the personal data will be transferred is another point to be observed in fulfilling the obligation to inform. Bearing in mind that the personal data to be registered in the İYS will not be transferred solely to the Ministry of Trade, the competent public legal person, and having regard also to the establishment and management of the İYS and the stages of registration with the İYS explained above, it must be determined to whom and for what purposes the data are transferred, and the data subjects whose personal data are processed must be correctly informed.

Under Law No. 6698, persons having the status of controller must, in addition to the obligation to inform, carry out processing in compliance with the conditions in Articles 5 and 6 of the same Law. Since the processing of data in the identity and contact data categories of individuals in order to carry out marketing processes, to promote the business or to increase its recognition through content such as greetings and good wishes does not correspond to the other conditions for processing in Article 5(2) of the Law, the data in question may be processed only where the data subjects have given their explicit consent. The Personal Data Protection Authority, too, from its resolution of principle of 16.10.2018, No. 2018/119, to its most recently published decision of 10.09.2020, No. 2020/691, has consistently decided that messages with advertising content may be processed only where the data subjects have given their explicit consent pursuant to Article 5(1) of Law No. 6698.

Law No. 6563, by contrast, refers to the mechanism of “approval”. There are many different approaches to the use of the concepts of approval and explicit consent in practice. First of all, explicit consent is the declaration given by the data subject concerning the processing of his or her personal data, on the basis of sufficient information, with a clarity leaving no room for doubt and limited solely to that operation. Explicit consent must be given before the personal data processing activity. Approval in relation to commercial electronic messages is likewise defined as a declaration obtained in advance in order to send messages.

As can be seen, both are based on the method of obtaining an affirmative declaration of intent from individuals before data are processed. Although differences are seen in practice, there is no legal benefit in obtaining the declarations of explicit consent and of approval separately in order to send commercial electronic messages. Not only may this be confusing for a person making two separate declarations of intent to the same effect, but in cases where one is given and the other is not, it also becomes unclear how service providers are to determine their course of action.

Where explicit consent is withdrawn, in accordance with Article 7 of Law No. 6698, which provides that “Despite having been processed in compliance with the provisions of this Law and of other relevant laws, personal data shall be erased, destroyed or anonymised by the controller, ex officio or upon the request of the data subject, where the reasons requiring their processing cease to exist”, the data subject’s electronic communication address processed for the purpose of sending commercial messages, or his or her data falling within the identity data category, must be erased, destroyed or anonymised. In addition, as mentioned above, under the Regulation on Commercial Communications and Commercial Electronic Messages, service providers and/or intermediary service providers are under an obligation to retain the approval records for three years from the date on which the validity of the approval ends, and the other records relating to commercial electronic messages for three years from the date of the record. Where explicit consent is withdrawn, businesses are likely to find themselves in a dilemma. Businesses that, from the date on which explicit consent is withdrawn, erase all the relevant data in such a way that they can in no way be accessed or used may be regarded as having acted contrary to the retention-period provisions of the Regulation. On the other hand, businesses that deactivate the data of persons who have withdrawn their explicit consent, send them no commercial messages and keep the data for the retention period as required by the Regulation may be regarded as having acted contrary to Law No. 6698 throughout that period.

In our view, if it is provided that as from 01.12.2020 the records are to be retained by the İYS, the businesses concerned will be able to escape from this impasse, and the obligation to ensure legal stability and legal certainty, which are indispensable elements of the principle of the rule of law set out in Article 3 of the Constitution of the Republic of Türkiye, will also be capable of being fulfilled. Even if it may be inferred, by argument a contrario from the requirement, expressed by the Personal Data Protection Authority in its decision of 10.09.2020, No. 2020/691, that data which are unlawful from the outset be erased immediately, that data which become unlawful subsequently through the withdrawal of explicit consent need not be erased immediately, there is no clear approach to the situation in question, and it would be more appropriate for rules to be made having regard to the hierarchy of norms.

It appears likely that problems with declarations of approval will be experienced even after the İYS has come into active use. At present, without any declaration of approval at all, identity and contact details — sometimes obtained through the unlawful transfer of another legal entity’s record system, sometimes obtained earlier for the purpose of performing a contract, in particular those dating from before May 2015 — may be entered, as though the individuals’ approval existed, into the İYS, which has been left to operate solely on the basis of declarations; and, unless the individuals become aware of this and refuse it, service providers will be able to act as though this were lawful. It would be more appropriate for these instances of unlawfulness that may arise in the future to be prevented by means of a control mechanism operated by those responsible for the establishment and management of the İYS, both so that unlawfulness does not arise at all and with a view to giving prominence to the will of individuals, which is one of the aims of the İYS. The Personal Data Protection Authority addressed this matter in its decision of 10.09.2020, No. 2020/691. It decided that, where unlawful processing of personal data is at issue (for example data obtained by means of illegal software, data shared unlawfully between companies, etc.) these personal data must be erased immediately, since this situation, which ought never to have occurred from the outset and which is currently unlawful, must be eliminated immediately and lawfulness restored as soon as possible. Finding that engaging in unlawful data processing in this way was contrary to Article 12(1)(a) of Law No. 6698, it imposed an administrative fine. In addition, the provisions on the administrative fines to be imposed by the Ministry of Trade for messages sent without approval are reserved.

Having regard also to international legislation, one of the reasons for seeking to bring the sending of commercial electronic messages under discipline is to prevent the unlawful transfer of the data of persons whose personal data are processed for this purpose. When personal data are transferred, the transfer must be made in compliance with Article 8 of Law No. 6698 on the Protection of Personal Data. If there is no appropriate purpose for the transfer when individuals’ data are transferred, the transfer is deemed to be an unlawful transfer. Since the business partners published on the İYS website are legal persons under private law, the data of natural persons are being transferred to other private-law legal persons. In publishing its business partners, the İYS has not indicated whether there is a confidentiality agreement between them or whether all the administrative and technical measures required by Article 12 of Law No. 6698 have been taken. In addition, it has been announced that a single service provider may work with more than one business partner. Taking all of this into account, it is established that the data of persons whose personal data are processed for this purpose will be transferred to the business partners, to İYS A.Ş., to TOBB and to the Ministry of Trade. If the principle of proportionality is also taken into account in the transfer of personal data, the extent to which this transfer under the system is lawful is open to debate.

XI. Concerns Regarding the İYS

Although the concerns will be addressed separately for each of the parties affected by the regulation of the sending of commercial electronic messages, the general concern shared by all parties is that, instead of the problem of unsolicited commercial messages being sent to individuals — which has reached a level that may be described as “SMS terror” — being resolved by the State itself (through the relevant ministry) by means of public regulation, a commercial company with private-law legal personality has been authorised in this matter.

Since 2015, when the Regulation granted recipients a right of complaint, the complaints lodged have far exceeded the assessment capacity of the relevant ministry, with the result that the right of complaint has become incapable of protecting the rights of recipients. That being so, although, besides genuinely “protecting individuals from SMS terror”, there is a need for rules on the burden of proof and on determining the conditions of validity and form of commercial electronic messages, the authorisation of a commercial company with private-law legal personality to establish and manage the Message Management System introduced for this purpose gives rise to the concern that the aim is not to safeguard the public interest by taking account of all the parties whose interests are affected and finding common ground, but to derive profit from the obligation that has arisen.4

If we examine the concerns separately from the standpoint of the parties whose interests are affected by the regulation:

As regards individuals, although I have explained all the details under the heading “The Relationship between the Message Management System and the Protection of Personal Data”, I must state under this heading too that, since the individuals to whom commercial electronic messages are intended to be sent comprise virtually all the individuals in our country, the recording of the contact details — in other words the personal data — of all individuals, such as telephone numbers and e-mail addresses, in the system of a commercial company that is a private-law legal person gives rise to great concern as to the security of those data. It should also be noted that the system is intended to be used by individuals as well. In that case, İleti Yönetim Sistemi A.Ş. too has the status of controller under Law No. 6698 on the Protection of Personal Data and is obliged to process the personal data of individuals in compliance with the legislation and to take the necessary administrative and technical measures for the protection of personal data. However, whether a private-law legal person which, by virtue of the legislation, will act with public power and occupy a monopoly position will (be able to) fulfil these conditions gives rise to concern.

If we consider the concerns from the standpoint of service providers: at a time when databases constitute a company’s greatest economic asset, requiring service providers to upload their data covering all their customers to a system under the management of another commercial company gives rise to the concern that the data may be used for purposes other than the intended one. Moreover, service providers that are required by the legislation to register with the Message Management System (İYS) are also made to sign, for the purposes of registration, a standard-form “Message Management System Basic Services Usage Undertaking”; in other words, service providers are not even afforded the opportunity to put forward their own conditions and requests concerning the protection, retention or processing of their data.

As a further concern, bearing in mind that all service providers will wish to send commercial electronic messages to all their customers on a daily basis, there is concern as to the technical capacity of the İYS, namely whether it will be able to transmit millions of commercial electronic messages every day. Given that the messages of greeting and good wishes requested on special days such as religious and national holidays can be delivered, even by operators that have spent millions on their infrastructure and are firmly established with years of know-how, only by shutting down certain other services, there is no doubt that this concern has a basis in reality.

This concern brings with it yet another concern. Since the İYS will be inadequate when it comes to sending the commercial electronic messages of all service providers at the moment they request, there is concern that “prioritisation” may be carried out among service providers and that, by privileges being granted in this way to certain service providers, many service providers may be exposed to unfair competition and suffer harm.

Finally, if we consider the concerns from the standpoint of the companies that provided infrastructure services for the sending of commercial electronic messages before the regulation: given that a message management system has been set up and its management has been assumed by a commercial company with private-law legal personality, there is concern that, because the infrastructure service in question will be carried out via the İYS and registration with the system is compulsory, İleti Yönetim A.Ş. will acquire a monopoly in this field and that these companies are doomed to disappear from the market.

XII. Commercial Electronic Messages in European Union Law

In European Union law there is no single regulation or other instrument dedicated to commercial electronic messages. In line with the needs that have arisen over the course of time, commercial electronic messages have been addressed and regulated, as occasion arose, within the framework of the legislation on the protection of personal data and on the regulation of electronic commerce. In this context, although it contains no specific provision on the sending of unsolicited commercial electronic messages, commercial electronic messages were first addressed, within the framework of the protection of personal data in the course of marketing activities, in Directive 95/46/EC of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data.5

The first specific rule on the sending of unsolicited commercial electronic messages, for its part, was introduced into the legislation by Directive 97/7/EC of the European Parliament and of the Council of 20 May 1997 on the protection of consumers in respect of distance contracts.6 Given its date, that rule makes the sending of messages to the consumer by methods requiring no human intervention, such as fax or automatic calling machines, subject to the condition that the consumer’s prior consent has been obtained.

The basic conditions of validity and form relating to the sending of unsolicited commercial electronic messages were laid down in Directive 2000/31/EC of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market, also known in legal scholarship as the “EU E-Commerce Directive”.7 Under Article 6 of the Directive, the following are listed as minimum conditions: that the information on the commercial communication be clearly provided; that the name and surname of the sender of the commercial message (today’s service provider), if a natural person, or the company name, if a legal person, be clearly stated; and that offers such as promotions, gifts and the like, provided that they are permitted by the Member State to which the sender of the message is subject, be clearly and unambiguously described in writing and be easily accessible.

Although the directives listed above determined the conditions of validity of commercial electronic messages and provided that they are subject to approval, these rules proved insufficient in combating the sending of unsolicited commercial electronic messages. In this context, Directive 97/66/EC concerning the processing of personal data and the protection of privacy in the telecommunications sector was adopted with a view to protecting recipients. However, owing to the rapid development in the technology sector, that directive became incapable of meeting demands within a very short time and was repealed by Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector. With the onset of the use of cookies in line with the possibilities offered by developing technology, that directive took its final form through Directive 2009/136/EC, also known in legal scholarship as the “EU Cookie Directive”8. With the repeal in 2011 of Directive 97/7/EC of 20 May 1997 as well and the adoption of Directive 2011/83/EU of the European Parliament and of the Council of 25 October on consumer rights, the sector-based rules took their present form.

Finally, the European General Data Protection Regulation, adopted by repealing Directive 95/46/EC, brought about ground-breaking changes in the field of the protection of personal data and put in place a new system consisting of new principles and basic conditions for processing. By Article 21 of the Regulation, in parallel with Directive 95/46/EC, the sending of commercial electronic messages is treated as falling within marketing activities, and recipients are granted a right to object with a view to the protection of their personal data in the course of such activities.

Although commercial electronic messages do not fall entirely within data protection law, there is no doubt that, as also explained in detail under the heading “The Relationship between the Message Management System and the Protection of Personal Data”, they are virtually intertwined with data protection law and must be regarded as parts of an inseparable whole. In European Union law, this matter came to the fore following the adoption of the European General Data Protection Regulation, because the Regulation and the EU Cookie Directive were not fully consistent with each other. At present, work is continuing in European Union law on bringing the EU Cookie Directive into line with the Regulation, and in this way it will be possible to have uniform legislation.

Assessment and Conclusion

It is accepted that the system also has positive aspects, considering that it will enable recipients, who today have in practice completely lost their rights of control and refusal over the commercial electronic messages that companies send them, to regain those rights and, on the other hand, will enable service providers to send commercial electronic messages without fear of being faced with administrative fines; nevertheless, uploading commercial electronic messages to a single system under a State monopoly and handling all messages through a single system is consistent neither with a world that is becoming more globalised with each passing day nor with the outlook of the 21st century.

The fact that the Ministry has left the establishment of the İYS to a private company through TOBB, and that registrations in the system have been left solely to technical integrators to the exclusion of lawyers with a command of the legislation, is not an adequate solution and will have serious adverse consequences, both in terms of the harm that will be caused by the failure to protect the personal data of hundreds of thousands of persons and in terms of the administrative fines that service providers will face.

While these are our views on the law as it ought to be, from the standpoint of the law as it stands it is essential, when electronic messages are sent, to observe the points we have set out above and to carry out the sending in the manner indicated by the relevant legislation. Otherwise, violations may arise in respect of both the İYS and Law No. 6698 on the Protection of Personal Data (KVKK).

Footnotes

  1. Assoc. Prof. Dr., faculty member in Criminal Law, Criminal Procedure Law and IT Law, Istanbul Aydın University Faculty of Law, [email protected], ORCID: 0000-0003-4034-5436. ↑
  2. https://www.statista.com/statistics/617136/digital-population-worldwide/#:~:text=How%20many%20people%20use%20the,in%20terms%20of%20internet%20users. (Erişim Tarihi : 03.09.2020) ↑
  3. https://www.statista.com/statistics/379046/worldwide-retail-e-commerce-sales/ (Erişim Tarihi: 03.09.2020) ↑
  4. https://www.dunya.com/ekonomi/pandemide-e-ticaret-159-artis-gosterdi-haberi-474318 (Erişim tarihi: 03.09.2020) ↑
  5. See: https://turk-internet.com/ileti-yonetim-sistemi-endise-yaratiyor/ (s.e.t. 08.09.2020) ↑
  6. Mehmet Bedii Kaya, Elektronik Ticaret Hukuku Ticari Elektronik İletiler, 2. Baskı, İstanbul, On İki Levha Yayıncılık, s. 31. ↑
  7. Kaya, Ticari Elektronik İletiler, (2), s. 32. ↑
  8. Kaya, Ticari Elektronik İletiler, (2), s. 33. ↑
  9. Kaya, Ticari Elektronik İletiler, (2), s. 35. ↑

Download PDF (in Turkish)

Related publications