1 January 2018Murat Volkan DülgerCommentary

Introduction

This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.

The “Regulation on the Data Controllers’ Registry” was published in Official Gazette No. 30286 on 30 December 2017. Those who follow the field of personal data protection had been awaiting it with interest, and it contains extensive provisions on the Data Controllers’ Registry first provided for in Law No. 6698 on the Protection of Personal Data (KVKK). The date of entry into force of the Regulation was set as 1 January 2018. It should be said at the outset that the concept of the Data Controllers’ Registry was already present in the KVKK before this Regulation. Under Article 16 of the Law: “A Data Controllers’ Registry open to the public shall be kept by the Presidency under the supervision of the Board.”

This article of the Law thus imposed an obligation both on the Personal Data Protection Board to keep a Data Controllers’ Registry and on natural and legal persons who process personal data to register with it. Paragraph 2 of the same article of the Law provides that the Board may introduce exceptions to this requirement, and paragraph 3 sets out what an application for registration with the Data Controllers’ Registry must contain. Lastly, by stating in paragraph 5 of the same article that the other procedures and principles relating to the Data Controllers’ Registry would be laid down by regulation, the Law gave an indication that the Regulation examined here would be issued. To understand the importance of the obligation to register with the Data Controllers’ Registry, the sanctions provided for in the Law must also be mentioned.

Related publications