Common Misconceptions About Law No. 6698 on the Protection of Personal Data
Personal Data Protection Authority
Address: Nasuh Akar Neighborhood 1407. Street No: 4 Balgat / Çankaya / ANKARA / TURKEY
Phone: +90 312 216 50 00
Web: www.kvkk.gov.tr
Prepared for Publication by: ADALET PUBLISHING HOUSE
Address: Strasbourg Street No: 10/B Sıhhiye-Ankara
Phone: (0312) 231 17 00
Fax: (0312) 231 17 10
Web: www.adalet.com.tr
Contents
- Are the data of legal entities also protected under Law No. 6698 on the Protection of Personal Data (Law No. 6698)? (Page 13)
- Can randomly written names, surnames, and phone numbers on a piece of paper be considered within the scope of the Law? (Page 14)
- Are personal data processed through a data recording system covered by the Law? (Page 15)
- Are those processing personal data by non-automatic means exempt from the Law? (Page 15)
- If some personal data are kept on a computer only for storage purposes in file form, is personal data considered processed in this case? (Page 16)
- Are citizens' personal data stored within the Personal Data Protection Authority (“Authority”)? (Page 17)
- Is the data controller a natural person appointed to fulfill the duties assigned by the Law? (Page 17)
- Whom should a company designate as the data controller? (Page 18)
- Whom should a Ministry designate as the data controller? (Page 19)
- Are affiliated, related, and connected units of a Ministry considered data controllers? (Page 19)
- Is each company within a corporate group separately considered a data controller? (Page 20)
- Are employees or units of a company data processors? (Page 21)
- Can a natural or legal person be both a data controller and a data processor? (Page 22)
- Should the data subject apply to the data controller or the data processor regarding their rights under the Law? (Page 22)
- Who is responsible for ensuring the accuracy and updating of personal data held by a data controller? (Page 23)
- Is anonymized data considered personal data? (Page 24)
- Can personal data only be processed with the explicit consent of the data subject? (Page 25)
- If personal data is processed based on one of the conditions other than explicit consent, is it also possible to obtain explicit consent from the data subject? (Page 25)
- Is the obtaining of explicit consent subject to any form? (Page 27)
- How long should explicit consent texts be retained? (Page 27)
- Is processing personal data by obtaining consent such as "I accept the processing and sharing of my personal data" during a purchase compliant with the Law? (Page 28)
- If personal data is made public by the data subject themselves, can the data controller process this personal data for any purpose? (Page 29)
- If personal data is processed by a data controller based on a condition explicitly stipulated in laws, is this activity exempt from Law No. 6698? (Page 30)
- Can personal health data be processed according to the processing conditions listed in Article 5 of the Law? (Page 31)
- Can personal health data be processed by data controllers within the scope of legitimate interest? (Page 31)
- Is a person's 'gender' considered special category personal data? (Page 32)
- If the data subject requests deletion or destruction of their personal data, must data controllers comply with this request under all circumstances? (Page 33)
- Is a commitment letter required for cross-border data transfer even if explicit consent of the data subject exists? (Page 34)
- Is there a time frame foreseen for the Authority's evaluation when a commitment letter signed for cross-border data transfer is sent to the Personal Data Protection Board (“Board”) for approval? (Page 35)
- Does the Board have the authority to stop data processing or data transfer abroad? (Page 35)
- Can the customer information text and explicit consent text be presented under the same heading? (Page 36)
- If personal data is processed based on the condition of "explicitly stipulated in laws," should the notification obligation still be fulfilled? (Page 38)
- Should data controllers also send the prepared notification texts to the Authority? (Page 38)
- Is it necessary to specify retention periods in notification texts? (Page 39)
- What is layered notification, and how should “layered notification” be performed under the notification obligation? (Page 40)
- A call center directs callers to a webpage link to perform layered notification. Is this considered fulfilling the notification obligation? (Page 42)
- When the data controller and data processor are different persons, how is responsibility determined under the Law? (Page 43)
- A company receives services from a data processor under a signed contract. In case of a violation by the data processor, who is responsible under the Law? (Page 44)
- If personal data is obtained unlawfully by others, can the data controller notify the Authority within a suitable time frame? (Page 45)
- Can only the data subject apply to the data controller? (Page 46)
- Must applications to the data controller be in Turkish? (Page 46)
- If the data controller responds on the 15th day from the application date, within how many days can the data subject file a complaint to the Authority from that date? (Page 46)
- If 30 days have passed since the application date without a response from the data controller, within how many days can the data subject file a complaint to the Authority from that date? (Page 49)
- Can a complaint be made directly to the Authority without applying to the data controller first? (Page 51)
- Can the data subject submit a complaint to the Authority via e-mail, phone, or call center? (Page 52)
- Can the data subject claim compensation when applying to the Authority for a complaint? (Page 52)
- How long does the Board have to respond when a complaint application is made to the Authority? (Page 53)
- Can the Board conduct an ex officio investigation against data controllers who do not fulfill their legal obligations? (Page 53)
- Will the Data Controllers Registry Information System (“VERBİS”) contain personal data? (Page 54)
- Are lawyers exempt from the Law because they are exempt from the Registry registration obligation? (Page 54)
- Will the Authority determine and announce personal data retention periods? (Page 55)
- Are all data controllers required to prepare a personal data processing inventory? (Page 56)
- Should the prepared personal data processing inventory also be sent to the Authority? (Page 57)
- Is it necessary to upload the personal data processing inventory to VERBİS? (Page 58)
- Is it necessary to specify retention periods in the personal data processing inventory? (Page 58)
- Does the Board have the authority to request the personal data processing inventory and personal data retention and destruction policy prepared by data controllers? (Page 59)
- How should the coordination officer be appointed in public institutions? (Page 59)
- How should the contact person be appointed in public institutions? (Page 60)
- Can the VERBİS registration application form be sent from a different Registered Electronic Mail (KEP) address than the one specified in the form? (Page 60)
- Are the number of employees and annual financial balance considered as exemption criteria from the Registry registration obligation for data controllers established abroad? (Page 61)
- Can a contact person be appointed as the contact person for more than one data controller at the same time? (Page 61)
- Does making VERBİS publicly accessible mean that personal data also becomes publicly accessible? (Page 61)
- Should foundation universities register in VERBİS under the “domestically established legal/natural person” section? (Page 62)
- Should chambers of commerce register in VERBİS under the “domestically established legal/natural person” section? (Page 63)
- Will actions be taken against those who do not fulfill the Registry registration obligation despite not being exempt? (Page 63)
- What procedure will be followed if a criminal element is detected as a result of inspections conducted under the Law? (Page 64)
- Are administrative fines specified in the Law increased every year? (Page 64)
- Can administrative fines imposed by the Board be appealed? (Page 65)
- Is a data controller within the scope of exemption under Article 28, paragraph 1 of the Law also exempt from the Law? (Page 65)
- Is a data controller within the scope of exemption under Article 28, paragraph 2 of the Law also exempt from the Law? (Page 66)
1) Are the data of legal entities also protected under Law No. 6698 on the Protection of Personal Data (Law No. 6698)?
Law No. 6698 protects the data of legal entities. Article 2 of Law No. 6698 states that the provisions of the Law shall apply to natural persons whose personal data are processed. Accordingly, the Law generally covers only the data of natural persons, and the data of legal entities are excluded from the scope of this Law.
2) Can randomly written names, surnames, and phone numbers on a piece of paper be considered within the scope of the Law?
Randomly written names, surnames, and phone numbers on a piece of paper are not within the scope of the Law. For personal data processing to be considered within the scope of the Law, the processed personal data must be part of a data recording system, meaning they must be structured and processed according to certain criteria. If data such as name, surname, and phone number are written within an index, directory, or similar data recording system, the data processing activity will be subject to the Law. Personal data written manually and randomly on a piece of paper will not be within the scope of the Law. However, the fact that personal data processed without being part of a data recording system is not subject to Law No. 6698 does not mean that such data can be used arbitrarily. Situations constituting a crime are addressed under the Turkish Penal Code No. 5237.
3) Are personal data processed through a data recording system covered by the Law?
Personal data processed as part of a data recording system are covered by Law No. 6698. The Law defines a “data recording system” as a recording system in which personal data are processed structured according to certain criteria. Therefore, if personal data are processed according to certain criteria such as index, number, name-surname, alphabet, category, or order, it will be within the scope of the Law.
4) Are those processing personal data by non-automatic means exempt from the Law?
The Law does not completely exclude personal data processing by non-automatic means from its scope. If data processing by non-automatic means is carried out as part of a data recording system, this data processing activity is also considered within the scope of the Law. Therefore, personal data processed by non-automatic means will be within the scope of the Law if they are part of a data recording system.
5) If some personal data are kept on a computer only for storage purposes in file form, is personal data considered processed in this case?
Keeping personal data on a computer in file form solely for storage purposes is also considered personal data processing. Article 3 of Law No. 6698 defines the processing of personal data as “any operation performed on personal data such as obtaining, recording, storing, preserving, altering, reorganizing, disclosing, transferring, taking over, making accessible, classifying, or preventing the use of data, either fully or partially by automatic means or by non-automatic means as part of any data recording system.” Accordingly, even if personal data are kept in file form only for storage purposes and no other operation is performed on them, it will be considered personal data processing, and this activity will be within the scope of the Law.
6) Are citizens' personal data stored within the Personal Data Protection Authority (“Authority”)?
The Authority does not store citizens' personal data. Moreover, it is not possible for the Authority to record all personal data processed in Turkey.
