Introduction
This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.
Since Law No. 6698 on the Protection of Personal Data (KVKK) entered into force on 7 April 2016, the legislation that followed has removed the uncertainty on almost every issue in the field of personal data protection law. The transfer of personal data abroad, however, has never been clarified and has become a major problem. Although the Personal Data Protection Board (the Board) is taking steps on the matter, it is clear that these are not sufficient to resolve the present situation. This is because, owing to the uncertainties surrounding the issue, it is in fact technically impossible for most of the processing activities currently carried out by way of transfers abroad to be lawful.
Indeed, for this reason there have also been rumours that the Board could not find an infringement or impose an administrative fine in this respect on a data controller that transfers data abroad. Contrary to these rumours, however, on 7 May 2020 the Board published on its website its Decision No. 2020/173 of 27 February 2020 (the Decision), which imposes administrative fines totalling TRY 1,200,000 on Amazon Turkey Perakende Hizmetleri Limited Şirketi (Amazon). In doing so it moved to a new stage on this issue and put an end to the view that no administrative fine would be imposed for transfers of data abroad.
Full text
This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.
Murat Volkan Dülger*
Although the legislation enacted in the wake of the entry into force, on 7 April 2016, of Law No. 6698 on the Protection of Personal Data (KVKK; hereinafter “the Law”) has removed the uncertainty surrounding almost every issue in the field of data protection law, the position regarding transfers of data abroad has never been clarified and has become a major problem. Although the Personal Data Protection Board (the Board) is taking steps on the matter, it is clear that these are not sufficient to resolve the present situation. For, as things stand, it is in fact technically impossible for most of the processing activities carried out by way of transfers of data abroad to be lawful, on account of the uncertainties surrounding the matter. Indeed, for this reason there are even rumours to the effect that the Board cannot, in this context, find a violation against a controller that transfers data abroad or impose an administrative fine on it.
Contrary to these rumours, however, on 7 May 2020 the Board published on its website its Decision No. 2020/173 of 27/02/2020 (the Decision) imposing administrative fines totalling TRY 1,200,000 on Amazon Turkey Perakende Hizmetleri Limited Şirketi (Amazon); it thereby moved to a new stage in this matter and also put an end to the belief that no administrative fine would be imposed in respect of transfers of data abroad.
Let us briefly recall the provisions on transfers of data abroad and the steps
taken on the matter:
Under Article 9 of the Law, entitled “Transfer of personal data abroad”, a transfer of data abroad is a processing activity that may not be carried out without the explicit consent of the data subject; the transfer may nevertheless be made where one or more of the legal grounds set out in Articles 5 and 6 of the Law exist. Article 9(2) of the Law, however, lays down certain conditions with regard to the countries to which the personal data are to be transferred. Accordingly, for a transfer of personal data without the explicit consent of the data subjects to be lawful, one of the following conditions must be met in the foreign country to which the personal data are to be transferred: “a) adequate protection exists” or “b) where adequate protection does not exist, the controllers in Turkey and in the foreign country concerned undertake in writing to provide adequate protection and the Board has given its permission” .
First of all, the fact that, in the four (4) years that have passed, the Board has still not published the countries in which adequate protection exists is the subject of serious criticism. Although on 11 June 2019 the Board published, by its decision No. 2019/125 of 02/05/2019, the form drawn up for use in determining the countries with adequate protection together with the criteria to be taken as the basis for identifying those countries, the fact that the countries themselves have still not been announced is a major shortcoming. Indeed, we see the consequences of this shortcoming in the decision under review. If the shortcoming is not remedied, we shall continue to see similar decisions.
Since the safe countries have still not been announced and this option is therefore ruled out from the outset, a controller wishing to transfer data abroad lawfully must itself, together with the controller located in the foreign country, undertake to provide adequate protection, and the Board must then grant permission following that undertaking. It will be recalled that the minimum elements to be included in the undertaking were published by the Board on 16 May 2018. The way was thereby opened for controllers to obtain the Board’s permission in order to transfer data abroad. However, we do not know with any certainty whether any of the applications made to the Board on the matter has produced a result.
Consequently, the only possibility afforded to a controller for transferring data abroad is to obtain explicit consent. But is this possible in practice? While it may seem feasible to some degree for small companies or for companies that only rarely transfer data abroad, how is explicit consent to be obtained by companies that are large, or have a great number of employees, or have direct links abroad and transfer almost all their data abroad? The same question applies to the multi-user institutions, organisations, companies and private persons acting as controllers whose cloud services are hosted on servers located abroad.
On the other hand, it is worth recalling the step which the Board took with regard to the problem of transfers of data abroad when, by the announcement it published on 10 April 2020, it adopted Binding Corporate Rules. Yet it is extremely difficult to say that this, too, is in many respects an appropriate solution that eliminates the problems as far as our country is concerned.
Most recently, on 7 May 2020, the Board took two new steps on the matter which I think will cause a considerable stir and become the subject of debate: an announcement was made on the points to be observed in the undertakings to be drawn up by controllers, and the summary of a decision imposing a fine running into the millions on Amazon was published. The subject of this article is that Amazon decision. I shall try to assess the conclusions reached in the decision by reading the explanations I have given above on the problem of transfers abroad together with the published summary of the decision.
The Board’s Decision on Amazon Turkey Perakende Hizmetleri Limited Şirketi (dated 27/02/2020
and No. 2020/173)
The subject matter of the Decision is a written report and its annex.
1. Allegations and Defences
The points set out in summary in that report and the defences submitted by Amazon at the Board’s request are as follows:
• As regards the legislation to which Amazon is subject
The report stated that the activities carried on via www.amazon.com.tr, which has the status of a service provider and intermediary service provider, infringed the provisions of Law No. 6563 on the Regulation of Electronic Commerce.
Amazon, for its part, contends that the reports concerning commercial electronic messages are unfounded and, moreover, that requests on the matter ought to be addressed to the Ministry of Trade; that, with due respect to the Board, the procedures and principles governing the matter are regulated specifically within the framework of the legislation on electronic commerce; and that, for this reason, the informant, instead of using the complaint mechanism under that legislation, based his complaint on hypothetical assumptions and addressed it to the wrong Authority.
• As regards the texts of the “Conditions of Use and Sale” and the “Privacy Notice”
According to the informant’s allegation, on the “Conditions of Use and Sale” page of the website the services offered by Amazon Europe Core SARL, Amazon Turkey Perakende Hizmetleri Limited Şirketi and/or their affiliates and by Amazon.com.tr are referred to collectively as Amazon Services, and the page contains the statement “Please review our Privacy Notice and our Cookies Notice in order to understand how your personal information is collected and processed through Amazon Services.”
In addition, the first section, entitled Electronic Communications, provides that where individuals use any Amazon Service they have communicated with Amazon electronically; that, for this reason, they have consented to receive communications electronically for contractual purposes; and that they are deemed to have agreed that all means of communication provided electronically satisfy the legal requirements.
In response to these allegations, Amazon stated that Amazon Turkey had prepared the texts of the “Conditions of Use” and the “Privacy Notice” in order to ensure transparency as regards the processing of its customers’ personal data in compliance with the legislation in force. It then went on to explain – in a manner which in essence confirms the informant’s allegations – that, once an account has been created, electronic communication concerning Amazon products and services is established with registered customers; that the Privacy Notice is accepted upon creation of the account; and that, when a customer places an order, he or she is also given a reminder in the following terms: “By placing your order, you agree to Amazon.com.tr’s Privacy Notice, Conditions of Use and Sale and Cookies Notice.”
• As regards the unlawful obtaining of approval for commercial electronic messages
According to the allegation, Amazon does not at any stage obtain explicit consent in order to be able to send commercial electronic messages, nor does it give any explanation as to the existence of any legal ground. Individuals are obliged to create a member account in order to shop and, in doing so, have to accept the Conditions of Use and Sale containing the statements in question. Thus, by creating a member account, the statements referred to are accepted and permission for commercial electronic communication is given as well.
In reply, it appears that – apart from what it explained above with regard to the texts concerned – Amazon was able to argue only that it provides its registered customers with the means to select easily the areas in which they wish to receive commercial electronic messages, to restrict them, or to refuse to receive commercial electronic messages whenever they wish.
• As regards the unlawful transfer of personal data abroad
The informant alleges that, although the section “Does Amazon Share Your Personal Information?” of the “Privacy Notice” page on the website states that personal data may be transferred to the European Union and from the European Union to the United States of America, explicit consent to the transfer of personal data abroad is not obtained at any stage.
In reply to this too, Amazon maintained similar defences, stating that customers had accepted this transfer by approving the Privacy Notice and that discussions were under way with the Authority concerning undertakings for the transfer of data abroad.
The report and the defences set out above were examined by the Board. It is worth noting in this connection that the application which the informant had also made to the Ministry of Trade was likewise forwarded to the Authority with the request that the matter be assessed within the framework of the KVKK.
2. Examination of the Decision on the Merits
The examination on the merits of the above allegations and defences is as follows:
• Is the Board competent to examine unlawful conduct relating to commercial electronic messages?
The Amazon decision brings back onto the agenda the debate over the relationship between the electronic commerce legislation and Law No. 6698. In the case at hand, it is alleged that Amazon sent electronic commercial messages unlawfully, whereas Amazon argues that this can be examined under the e-commerce legislation. The principles and procedures governing electronic commercial messages are laid down essentially by Law No. 6563 on the Regulation of Electronic Commerce (Law No. 6563) and the Regulation on Commercial Communication and Commercial Electronic Messages (the Regulation). It is therefore perfectly clear that the electronic commerce legislation and the data protection legislation are two separate bodies of legislation. Indeed, the purposes of the two and the legal interests they protect are entirely different: whereas Law No. 6563 and the related Regulation safeguard the orderly regulation of electronic commerce, Law No. 6698 protects the fundamental rights and freedoms of the individual, specifically the individual’s right to the protection of personal data.
That said, the relationship between the two bodies of legislation cannot be denied. At this point, however, it should be borne in mind that personal data need to be protected in almost every field and that, since data protection law is a multidisciplinary field, the examination of concrete cases in particular requires Law No. 6698 to be considered from time to time together with many other pieces of legislation. If one recalls the decisions published by the Board, the legislation on health, banking and telecommunications may be cited as examples. Yet the consideration of those regulations together with the Law is not a matter of debate. Why, then?
The fundamental reason for this is undoubtedly the conflict between the electronic commerce legislation and the Law. The Law requires the explicit consent of the data subject where no legal ground exists for the processing of personal data. The Regulation referred to, in a similar vein, makes the electronic commercial messages to be sent to persons for the purposes of promoting and marketing goods and services, promoting the business or, through content such as greetings and good wishes, increasing recognition, subject to the condition of approval1.
The problem here is that, since under Article 5 of the Law personal data cannot be processed without the explicit consent of the data subjects, activities such as advertising, marketing and promotion cannot be carried out under the Law without explicit consent, and consequently electronic messages cannot be sent either. For in this way the approval made mandatory by the Regulation comes face to face with the explicit consent prescribed by the Law. In practice this issue is resolved by obtaining permission for commercial electronic messages in accordance with the Regulation.
What needs to be discussed here, however, is the effect of this point of contention on the Board’s competence to examine the Amazon case and the other cases in which commercial electronic messages are at issue. The Board’s power of examination falls within the scope of the Law; and, given that the Law is a very general piece of legislation as regards personal data and that personal data need regulation in almost every field, the Law – and hence the Board – must necessarily come into contact with a great many fields. That field will differ in each concrete case according to the legislation with which the case is concerned.
Returning to the case at hand: under Article 5 of the Law controllers may not process personal data without explicit consent and, since sending electronic commercial messages is an activity involving the processing of many different personal data, electronic commercial messages may not be sent either. In the present case this concerns electronic commercial messages, whereas in another case it will differ according to each personal data processing operation whose conformity with Article 5 is being examined. For Article 5 applies to personal data processed in every field, and most examinations carried out under Article 5 will necessarily involve another piece of legislation as well; this should not be interpreted as meaning that the Board, by carrying out an examination with regard to the legislation thus involved, exceeds its competence. Consequently, although the subject matter of the present case is the unlawful sending of electronic commercial messages, I consider that the Board is competent to examine it in so far as the matter involves a breach of Article 5 of the Law. Indeed, by its Resolution of Principle No. 2018/119 of 16.10.2018 the Board also stated that it would take action in respect of acts of this kind under Article 18 of the Law. On this point, therefore, I agree with the Board’s statements that the decision “concerns not the sending of commercial electronic messages but the processes of processing personal data”, and I do not find Amazon’s defences well founded.
On the other hand, it is evident that the point of contention described above needs to be clarified. For it is uncertain what kind of decision the Board would give if, in a concrete case, a lawful approval had been obtained under the Regulation but no separate explicit consent had been obtained under the Law. Faced with such a report and complaint, must the controller produce two separate consents, or will it be released from this obligation if it has obtained a single approval?
• The problem of explicit consent in the sending of electronic commercial messages
We see that the Board examined whether the electronic commercial messages at issue in the present case were unlawful from the standpoint of explicit consent under Article 5 of the Law. At this point it did not touch upon the approval required under the Regulation, and reviewed whether the controller had complied with the requirement of explicit consent. The examination established that, when one goes to the “my account” tab after completing the Amazon membership process, although the statement “select all the communication categories you wish to be informed about” appears there, ten headings are treated as already selected by default. Apart from this, it was observed that at the very bottom of the relevant section there is a box for refusing to receive marketing e-mails.
The Board stated that, by the very definition of explicit consent, a method under which approval of the processing of personal data is presumed to have been given automatically without the individual’s prior approval being obtained (opt-out) cannot be used, and that a system must be set up in which the individual approves the processing of his or her personal data by a conscious act (opt-in). Indeed, the fact that the person has been given the possibility of withdrawing consent should carry no weight here. A person should not have to make a separate effort in order for his or her personal data not to be processed. The rule is that personal data are not processed, and a separate act is required only in order to consent to their processing. The controller, too, must design its explicit consent processes in this way (the principles of privacy by design and privacy by default / data protection [privacy] by design and by default).
Furthermore, a system arranged in such a way that the Privacy Notice is accepted automatically upon becoming a member of Amazon and that, in the Privacy Notice, the person is taken to have agreed to be sent electronic messages is, according to the Board, contrary to the rules of fairness. Although Amazon gave data subjects detailed information on the matter in the Privacy Notice, it must not be forgotten that, where the processing of personal data is based on the condition of explicit consent, the processes of fulfilling the obligation to inform and of obtaining explicit consent must be carried out separately from each other, and that the obligation to inform does not dispense with the obligation to obtain explicit consent.
In the light of these findings, the Board concluded that, because it had carried out the personal data processing activity involved in sending electronic commercial messages without explicit consent, Amazon had failed to fulfil the obligation under Article 12 of the Law to take all necessary technical and organisational measures to ensure an appropriate level of security for the purpose of preventing the unlawful processing of personal data.
It is clear that the system designed by Amazon with regard to electronic commercial messages infringes the individual’s right to the protection of personal data. Accordingly, while I agree with the Board’s finding of a violation in this respect, I also repeat my criticism, as stated above, that the question whether two different approvals/consents have to be obtained under the Regulation and the Law needs to be clarified.
• Review of the conformity of the present case with the general principles
Article 4 of the Law, which sets out the general principles governing the processing of personal data, forms the foundation of data protection law, and every violation committed by a controller at the same time amounts to a breach of these principles. However, because these principles denote an abstract domain rather than a concrete rule, and in essence constitute the philosophy of this field, they come into play principally in practices of the controller that are contrary to the rules of fairness and the fundamental principles, and then call for a separate examination as well. In the present case, too, the system designed by Amazon and the texts it put into effect led the Board to carry out an examination from this angle as well.
The examination of Amazon’s Privacy Notice established that this text uses the statements “You may choose not to provide certain information, but in that case you will not be able to use most of the Amazon Services” and “If you block or reject our cookies, you will not be able to add items to your shopping basket, proceed to checkout, or use any Amazon service that requires you to sign in”. First, where the processing of a person’s personal data is in any event necessary in order for that person to use Amazon’s services, the processing rests on the legal ground of the processing of data belonging to the parties to a contract; obtaining explicit consent in such a case is, according to the Board’s settled view, an abuse of right, since it would mislead the data subject and cause him or her to be wrongly guided. Secondly, an arrangement under which the data subject cannot use the service at all if cookies are blocked means that explicit consent is made a condition of the service. This, too, is a point which the Board has made clear ever since the very first decisions it published. The Board concluded that in this respect Amazon had acted contrary to the general principles of lawfulness and fairness and of being relevant, limited and proportionate to the purposes for which the data are processed.
In its examination of the categories of personal data collected by Amazon, the Board found that data relating to data subjects whose processing is not necessary in the personal data processes, such as “credit history information, status-related information, corporate and financial information”, were being collected. In addition, the e-mail addresses of the data subject’s contacts are processed without being based on the explicit consent of those persons. In this respect too Amazon acted contrary to the principles of lawfulness and fairness and of being relevant, limited and proportionate to the purposes for which the data are processed.
• As regards the transfer of personal data within the country
The object of examination for determining the lawfulness of the controller’s transfer processes is, once again, the Privacy Notice in question. The processes relating to transfers are explained under the heading “Does Amazon Share Your Personal Information?”. The examination carried out here identified the statement “Other than as set out above, you will receive notice when personal information about you is shared with third parties, and you will have an opportunity to choose not to share the information.”
This statement involves more than one instance of unlawfulness. First, to notify the data subject after the transfer has been made, and to give the data subject as a result of that notification the chance to choose that the transfer should not be made, means that after the transfer has been carried out the data subject will be sent a notification of the kind that offers a chance to refuse a presumed consent, which does not in fact amount to obtaining proper explicit consent. On the basis of a presumption, the data subject’s explicit consent has been taken to exist; moreover, even if the notification sent were a lawful text for obtaining explicit consent, consent obtained after the transfer has been made has no validity and is, besides, unlawful from the standpoint of data protection law. For, as regards the time at which it must be obtained, explicit consent is a process that must be completed at the latest at the initial stage of the processing of personal data. Consequently, for the controller, after carrying out the transfer, to send a notification to the effect that the consent it has presumed may be withdrawn has no practical or legal meaning whatsoever and is an unlawful practice.
As a result of its examination in this context the Board reached the following conclusion: “the vague statements in the privacy notice concerning the transfer of personal data give rise to the impression that the provisions of the Law on transfers have been contravened”.
It is clear that Amazon acted unlawfully on account of the practice in question. Moreover, I believe that, in arriving at its conclusions, the Board carries out a far broader examination than appears from the decision summaries it publishes and, what is more, that it establishes the necessary communication with the controller on the matter and obtains information in detail. Nevertheless, expressions such as “it is understood” or “give rise to the impression” in the decision summaries create the impression among practitioners in the field that the Board has not carried out an adequate examination and, in particular, has not established the necessary and sufficient contact with the controller. While I think that there is no decision-making mechanism of that kind and that these are merely the result of poor wording, I should take this opportunity to underline that care needs to be taken on these points.
• As regards the transfer of personal data abroad
As stated above, one of the most important points of the Amazon decision is the part concerning the transfer of personal data abroad. Indeed, it is apparent that the administrative fine imposed relates to this aspect in particular. Since the uncertainties and criticisms surrounding the matter have been set out above, I shall here assess the Board’s conclusions only in the context of the present case.
The Decision explains that Amazon had submitted its letters of undertaking to the Board but that the Board had not yet given a decision in that regard; and, as I stated above, it notes that in such a situation, since the countries with adequate protection have not yet been published either, the controller’s only possibility for transferring data abroad is to obtain explicit consent.
In addition, the defences put forward by Amazon in response to the allegation that it had transferred data abroad unlawfully (namely that the Privacy Notice is accepted upon creation of the account and the transfer is accepted along with that text, while a reminder that the Privacy Notice has been accepted is given at the time of ordering) were found by the Board to be contrary to the legislation on the ground that approval was being obtained by way of an implied declaration of intent. Moreover, having all the acts that fall within Amazon’s processing of data, such as the use of cookies and the transfer of personal data, approved by a single declaration of consent amounts to what is termed “blanket consent”, that is, consent of a general nature that is not limited to a specific matter; and it is impossible for consent of this kind to comply with the Law.
According to the Board, in the present situation, the fact that Amazon, although under an obligation to obtain explicit consent in order to carry out transfers abroad, did not seek to obtain lawful explicit consent, and the assumption that the matters set out in the privacy notice have been accepted merely by using Amazon’s services, are contrary to Article 12 of the Law on data security.
While I agree with the conclusion the Board reached “having regard to the present situation”, I think that the difficulty which the present situation creates for controllers should not be overlooked either. For, as stated above, the fact that the uncertainties on the matter persist even though more than four years have passed since the publication of the Law makes it difficult for controllers to design their processes for transfers abroad. The reasoning that explicit consent is the only method that can be followed under the existing rules should not suffice for the conclusion that the controller has failed to fulfil its obligations. For it cannot be a sound approach to demand what is, especially for certain controllers, close to impossible and then to find a violation because it has not been done. While it is an undeniable fact that Amazon’s conduct in this respect involves manifest unlawfulness, it should also not be forgotten that the situation in question needs to be clarified in a way that eases practice, provided that the essence of the right to the protection of personal data is not impaired.
• As regards the obligation to inform
Lastly, Amazon’s personal data processing operations were examined within the framework of the controller’s obligation to inform. The part in which the obligation to inform was examined is the processing activity relating to cookies. As stated above, the services offered are referred to collectively as Amazon Services, and the text of Amazon’s Conditions of Use and Sale states that personal data begin to be processed as soon as the website is visited. The cookies processed in this connection are stated to be “cookies, pixels and other technologies (collectively referred to as ‘cookies’) used to recognise the browser or device of persons visiting the site, to learn more about their interests, to provide the necessary features and services, and for additional purposes including those listed below”.
Consequently, these data are processed as soon as a person merely visits Amazon’s website, without using any service. Although this information is contained in the texts, it was established that, in order to see it, a person has to go into the texts specifically, and that otherwise the information in question is not presented to the person by methods such as a pop-up message. Nor did the Board consider it possible for a person to know that these data are being processed merely because he or she has entered a website. It was therefore concluded that, as regards the processing carried out by Amazon in this respect, no lawful information had been provided and that the provisions of the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform (the Communiqué) had been infringed.
The use of cookies constitutes another data processing operation that controllers need to design with care. The data subject cannot be expected to guess that his or her personal data are being processed and to make a special effort to obtain information about it. Accordingly, the information to be given to the data subject as regards the use of cookies must be provided simultaneously with the data subject’s visit to the website. In this way, at the latest at the time when the personal data are processed, the obligation to inform will have been fulfilled. A further point to be noted in this respect is that the relevant system should be designed not so that the data subject accepts all cookies, but so that he or she accepts the different types of cookies in layers, on an opt-in basis. While the cookies that are strictly necessary for the website to function are selected by default, the processing of cookies collected for analytics and performance, statistics, or advertising and marketing purposes should be left unselected, to be decided by the data subject’s approval. Compliance with the Law and, in particular, with the European principles on the processing of cookies will thereby be ensured.
3. The Penalties Imposed on Amazon
In the light of the explanations given above, the penalties imposed on Amazon by the Board are as follows:
| • In view of Amazon’s failure to obtain explicit consent in order to send commercial electronic messages, | |
|---|---|
| its conduct contrary to the general principles set out in Article 4 of the Law, and its unlawful | |
| conduct with regard to the transfer of personal data within the country and | |
| abroad, Amazon was found to have infringed the provision governing the obligations relating to data security, | |
| Article 12 of the Law, and was fined, pursuant to | |
| Article 18(1)(b) of the Law, TRY 1,100,000; | |
| • because the information concerning the processing of cookies was not duly | |
| provided, the controller was found to have acted contrary to the provisions of the Communiqué and, within the scope of Article 10 of the Law, | |
| to the obligation to inform, and was fined, | |
| pursuant to Article 18(1)(a) of the Law, TRY 100,000; | |
| it was thus decided to impose administrative fines totalling TRY 1,200,000 | |
| in all. |
• It was further decided to instruct Amazon, in respect of the violations found, to update the texts giving rise to the violations so as to bring its website and applications into compliance with the Law, and to inform the Board of the outcome.
Conclusion
First of all, the decision in question is important in that it is so detailed and deals with several contentious issues at once. It is also important both because it states that explicit consent under the KVKK is additionally required in order to send electronic messages and because it states that the way cookie policies are determined and the information provided in that regard are inadequate.
In my view, however, the first of the two most important points is that it has clearly articulated the principle of privacy by design and by default. From now on, companies engaged in electronic commerce must, with proper information, leave all choices to their customers, who are the data subjects.
The other most important point is that this decision has also put an end to the rumours that “no fines are being imposed for transfers of data abroad for the time being”. Even though the safe countries have not been announced, the use of cookies was accepted as constituting a transfer of data abroad (which is indeed the case) and, because the options available within the existing framework were not used, a fine that is serious by Turkish standards was imposed on a company such as Amazon, which everyone uses in daily life.
Nevertheless, the answers to some questions remain uncertain. On which law and which regulation will controllers base their conduct in the case of electronic messages? How far is obtaining a separate approval and consent for each piece of legislation compatible with the realities of commercial life and the ordinary course of daily life? How equitable is it to give a decision carrying such a serious sanction immediately after making an announcement on undertakings for transfers of data abroad? When no undertaking has yet been accepted, when the Binding Corporate Rules have only just been announced, and when the whole world conducts its commercial and daily life through systems that give rise to transfers of data abroad, such as the processing of cookies, how realistic is it to prevent this by means of an administrative fine (especially when one considers the amount of the fine against the profit earned from this trade)? Even if large companies may somehow manage to comply with these policies, how will small and medium-sized enterprises comply with them on limited budgets?
As can be seen, although this is perhaps one of the finest and most detailed decisions the Board has given to date, many questions in the field of data protection still await an answer. I hope that realistic solutions in which the interests of the players in the sector and of data subjects meet on common ground will be devised as soon as possible.
Footnotes
- Assoc. Prof. Dr., Istanbul Aydın University Faculty of Law, Department of Criminal Law and Criminal Procedure Law, Attorney-at-Law, [email protected]. ↑
- Commercial electronic messages and approval ARTICLE 5 – (1) For commercial electronic messages which the service provider sends to the electronic communication addresses of recipients in order to promote or market its goods and services, to promote its business, or to increase its recognition through content such as greetings and good wishes, approval shall be obtained in advance by the service provider. The approval shall remain valid until the right of refusal is exercised. Obtaining approval ARTICLE 7 – (1) Approval may be obtained in writing or by any means of electronic communication. The approval shall contain the recipient’s affirmative declaration of intent to the effect that he or she agrees to be sent commercial electronic messages, his or her first name and surname, and his or her electronic communication address. Protection of personal data ARTICLE 12 – (2) In order for personal data to be shared with third parties, processed or used for other purposes, the prior approval of the person concerned must be obtained. ↑
Related publications
Dülger, Murat Volkan / Gümüş, Gülçin, Personal Data Protection Law (Kişisel Verilerin Korunması Hukuku), 4th ed., Seçkin Publishing, Ankara, 2026.
Dülger, Murat Volkan, Legislation on Information Technology, Personal Data Protection and Internet Communication (Bilişim, Kişisel Verilerin Korunması ve İnternet İletişimi Mevzuatı), 7th ed., Seçkin Publishing, Ankara, 2021.
Dülger, Murat Volkan, “The Use of Bulk Data and Metadata in Preventive Policing and Intelligence Work from the Standpoint of Human Rights, Personal Data Protection and Criminal Procedure Law” (İnsan Hakları, Kişisel Verilerin Korunması ve Ceza Muhakemesi Hukuku Açısından Önleyici Kolluk Hizmetleri ve İstihbari Çalışmalarda Toplu Veri ve Metadata Kullanımı), conference presentation, 2026.
Dülger, Murat Volkan, “Lawyers' Obligations under the KVKK in the Light of the Board's Decisions” (Kurul Kararları Işığında Avukatların KVKK Yükümlülükleri), conference presentation, 2025.
Dülger, Murat Volkan / Gümüş, Gülçin, “The Right to Be Forgotten”, Essays in Honour of Prof. Dr. Yadigar İzmirli (Prof. Dr. Yadigar İzmirli'ye Armağan), 2024.
