KVKK Publications No: 30
ISBN: 978-605-80554-2-1
Date: July, 2019
Place: Ankara
Republic of Turkey Personal Data Protection Authority
Address: Nasuh Akar Neighborhood 1407 Street No: 4 Çankaya / ANKARA
Phone: 0.312.216 50 00
Web: www.kvkk.gov.tr
The copying, reproduction, use, publication, and distribution of the writings and other contents in this guide, partially or entirely, without permission other than for individual use, is prohibited. Legal action will be taken against those who do not comply with this prohibition pursuant to Law No. 5846. All rights reserved.
Contents
- Introduction
- Definition
- Those Obliged to Prepare the Inventory
- Differences Between the Inventory and VERBİS
- Inventory Content
- Formation of a Team or Assignment of Persons to Prepare the Inventory
- Inventory Preparation Stages
- Identification of Personal Data Based on Process or Activity
- Determination of the Characteristics of Identified Personal Data
- Determination of the Legal Basis for the Processed Personal Data
- Determination of Personal Data Processing Purposes
- Determination of the Data Subject Group
- Determination of the Retention Period of Processed Personal Data
- Determination of Recipients / Recipient Groups to Whom Processed Personal Data is Transferred
- Identification of Personal Data Transferred to Foreign Countries
- Determination of Technical and Administrative Measures Taken for Processed Personal Data
- Inventory Sample
Introduction
Today, many companies, public institutions and organizations, foreign institutions or real persons obtain and use a large amount of personal data within the scope of their activities and aim to access more personal data and share it with third parties to provide better service or increase trade volume and thus contribute to economic development. However, moving towards processing more personal data brings various risks and potential violations related to data security, despite the conveniences and advantages provided by the processed personal data contributing to the national economy.
Due to these risks, the protection of personal data and the establishment of a legal infrastructure for this purpose became necessary. Primarily, with the amendment made to the Constitution of the Republic of Turkey in 2010, the right to protect personal data was constitutionally guaranteed, and it was stipulated that regulation should be made by law.
Constitution of the Republic of Turkey ARTICLE 20
Everyone has the right to demand respect for their private and family life. The confidentiality of private and family life shall not be violated. (Additional paragraph: 12/9/2010-5982/2 article.) Everyone has the right to demand the protection of their personal data. This right includes being informed about personal data concerning oneself, accessing such data, requesting correction or deletion, and learning whether they are used in accordance with their purposes. Personal data can only be processed in cases prescribed by law or with the explicit consent of the person. The principles and procedures regarding the protection of personal data shall be regulated by law.
Pursuant to this provision, the Turkish Grand National Assembly adopted Law No. 6698 on the Protection of Personal Data (“Law”), which was published in the Official Gazette dated 07.04.2016 and entered into force. The Law aims to protect fundamental rights and freedoms, determine the procedures and principles to be followed by real and legal persons processing personal data in Turkey, and prevent violations of personality rights resulting from arbitrary or unlawful processing of personal data by data controllers, unauthorized access to such data, and unlawful sharing.
In this respect, the Law does not limit the processing of personal data but rather regulates the procedures and principles regarding personal data processing to prepare a more competitive environment in the data-driven economy. The Law established the Personal Data Protection Authority (“Authority”), a public legal entity with administrative and financial autonomy affiliated with the Ministry of Justice, responsible for ensuring the implementation of the Law, issuing regulatory and supervisory acts within the framework of the Law, making secondary regulations where necessary, and ensuring that data controllers process personal data in compliance with the Law based on transparency and accountability principles.
Within this scope, the Authority has prepared the “Regulation on the Data Controllers Registry” and the “Regulation on the Deletion, Destruction or Anonymization of Personal Data,” which regulate certain procedures and principles that data controllers must comply with for the implementation of the Law. These regulations entered into force as of 01.01.2018.
Under the Law, real and legal persons processing personal data are obliged to comply with the fundamental principles and conditions of personal data processing, comply with the Law provisions in domestic and international transfers, fulfill the obligation to inform, take technical and administrative measures regarding data security, register with the Data Controllers Registry (“Registry”), and fulfill obligations such as deletion, destruction, or anonymization (“Destruction”). In addition to the obligations introduced by the Law, these regulations also impose certain obligations, one of which is the preparation of a Personal Data Processing Inventory (“Inventory”).
Definition
The Inventory is defined in Article 4, paragraph 1(h) of the Regulation on the Data Controllers Registry published in the Official Gazette dated 30.12.2017. (The provision was amended by Article 1 of the Regulation Amending the Regulation on the Data Controllers Registry published in the Official Gazette dated 28.04.2019.)
Regulation on the Data Controllers Registry ARTICLE 4 – (1) h) Personal data processing inventory: Refers to the inventory created by data controllers associating their personal data processing activities carried out according to their business processes with personal data processing purposes and legal basis, data categories, recipient groups to whom data is transferred, and data subject groups, detailing the maximum retention period necessary for the purposes for which personal data is processed, personal data envisaged to be transferred to foreign countries, and the measures taken regarding data security.
Accordingly, the Inventory is a kind of report that emerges as a result of a detailed analysis by data controllers processing personal data within their activities, evaluating all processes, examining all activities within these processes, identifying each personal data processed in each activity one by one, specifying for each personal data the purposes and legal reasons for processing, whether it is transferred, to whom it is transferred, the data subject groups, the retention period determined by the data controller for each personal data, whether it is transferred abroad, and the technical or administrative measures taken for data security.
The reason for imposing the obligation to prepare the Inventory is to ensure compliance with the Law in all processes related to the activities of data controllers, in other words, to facilitate the easy detection of any unlawful personal data processing. In other words, it is a kind of self-audit by the data controller regarding the compliance of personal data processing activities with the Law.
Those Obliged to Prepare the Inventory
Article 5, paragraph 1(c) of the Regulation on the Data Controllers Registry states: “Data controllers obliged to register in the Registry are required to prepare a Personal Data Processing Inventory. The information to be declared in the Registry during Registry applications shall be prepared based on the Personal Data Processing Inventory.” Paragraph (d) states: “In the obligation to inform specified for data controllers in Article 10 of the Law, in responding to applications by data subjects specified in Article 13 of the Law, and in determining the scope of explicit consent to be declared by data subjects, the information submitted to and published in the Registry based on the personal data processing inventory shall be taken as basis.” (Paragraph (c) was amended by Article 2 of the Regulation Amending the Regulation on the Data Controllers Registry published in the Official Gazette dated 28.04.2019.)
Regulation on the Data Controllers Registry ARTICLE 5 – (1) The following principles, procedures, and rules shall be followed regarding the establishment, management, and supervision of the Registry:
- c) Data controllers obliged to register in the Registry are required to prepare a Personal Data Processing Inventory. The information to be declared in the Registry during Registry applications shall be prepared based on the Personal Data Processing Inventory.
- d) In the obligation to inform specified for data controllers in Article 10 of the Law, in responding to applications by data subjects specified in Article 13 of the Law, and in determining the scope of explicit consent to be declared by data subjects, the information submitted to and published in the Registry based on the personal data processing inventory shall be taken as basis.
Additionally, Article 5, paragraph 1 of the Regulation on the Deletion, Destruction or Anonymization of Personal Data states: “Data controllers obliged to register in the Data Controllers Registry pursuant to Article 16 of the Law are required to prepare a personal data retention and destruction policy in accordance with the personal data processing inventory.”
Regulation on the Deletion, Destruction or Anonymization of Personal Data ARTICLE 5 – (1) Data controllers obliged to register in the Data Controllers Registry pursuant to Article 16 of the Law are required to prepare a personal data retention and destruction policy in accordance with the personal data processing inventory.
Accordingly, all data controllers obliged to register in the Data Controllers Registry must prepare an Inventory. Furthermore, the Inventory must be taken as basis when fulfilling the Registry registration and information obligations, responding to data subject applications, and determining the scope of explicit consent.
Differences Between the Inventory and VERBİS
According to Article 16 of the Law, the Data Controllers Registry must be kept publicly accessible, and real and legal persons processing personal data must register with the Data Controllers Registry before starting data processing. The information to be entered in the Registry is also clearly enumerated.
Accordingly, the information to be entered in the Registry includes the identity and address information of the data controller and its representative if any, explanations about the purposes for which personal data will be processed, data subject groups and the data categories belonging to these persons, recipients or recipient groups to whom personal data may be transferred, personal data envisaged to be transferred to foreign countries, measures taken regarding personal data security, and the maximum retention period necessary for the purposes for which personal data is processed.
Our Authority has prepared a system that allows data controllers to enter information into the Registry within this scope, which has been put into service under the name Data Controllers Registry Information System (“VERBİS”). Since the Registry will be kept publicly accessible, only information in categories will be entered into VERBİS. In other words, data related to real persons whose personal data is processed will not be entered into VERBİS; instead, information will be entered categorically under the headings of these data.
Although the Inventory and VERBİS show many similarities in terms of data, they differ in three main aspects.
In VERBİS, information must be entered by the data controller regarding whether personal data is processed based on “data categories,” and if so, for which purposes these data categories are processed, whether there is any transfer, recipient groups to whom data is transferred, retention periods if any, data subjects, and security measures taken. In contrast, the Inventory must be a much more detailed report that includes, for each personal data processed in all activities within all business processes of the data controller, the purposes and legal grounds for processing, whether it is transferred, third parties to whom it is transferred, retention periods, data subject groups, and security measures taken. In short, while only categorical information is entered in VERBİS, the Inventory must include these data with detailed breakdowns.
While the information entered into VERBİS, which is publicly accessible as required by Article 16 of the Law, can be viewed by anyone, the Inventory will remain within the data controller’s own organization and will not be publicly accessible. However, the Inventory must be submitted to the Board upon request. Also, the Inventory must be used when responding to data subject applications.
While a system has been prepared for VERBİS and data entry through relevant screens is mandatory, no guidance has been provided regarding the form of the Inventory. The Inventory can be kept, for example, as an office file or in relevant files in a database.
Inventory Content
According to the Regulation on the Data Controllers Registry, the Inventory must at least include;
- Data category,
- Personal data processing purposes and legal basis,
- Recipients / recipient groups to whom data is transferred,
- Data subject groups,
- The maximum retention period necessary for the purposes for which personal data is processed,
- Personal data envisaged to be transferred to foreign countries,
- Technical and administrative measures taken regarding data security,
must be included.
The nature and number of processed personal data, the nature and number of data subjects, the diversity of personal data, the circulation of personal data within the data controller or third parties to whom data is transferred, the difficulty level of technical and administrative measures to be taken for data security, foreign transfers, processing of a large number of personal data requiring explicit consent, the quantity of data differing in retention periods, sufficient measures to be taken for special categories of personal data, and the legal basis for transfers, if any, are among many criteria to be evaluated to decide the nature, form, structure, and environment of the Inventory.
It should be noted that the mentioned regulations include the minimum requirements for the Inventory, and it should not be understood that the Inventory must only contain these items. On the contrary, data controllers can detail the Inventory by adding other items covering their activities in addition to these minimum requirements (such as department name, unit name, person entering information, process name, activity name, activity description, category of processed personal data, processed personal data, processing condition under Article 5 of the Law, category of special personal data processed, etc.).
