KVKK Publications
ISBN: 978-975-19-6834-0
January 2018, Ankara
Personal Data Protection Authority
Address: Nasuh Akar Neighborhood Ziyabey Street 1407. Street No: 6 Balgat/Çankaya/ANKARA/TURKEY
Phone: +90 312 216 50 50
Web: www.kvkk.gov.tr

“The copying, reproduction, use, publication, and distribution of the writings, photographs, and other contents in this book, partially or entirely, without permission other than for individual use, is strictly prohibited. Legal action will be taken against those who do not comply with this prohibition pursuant to the Law No. 5846 on Intellectual and Artistic Works. All rights reserved.”

Summary

This Guide explains the main methods regarding the technical and administrative measures that data controllers must take to prevent unlawful processing of personal data and unlawful access to personal data, and to ensure the preservation of personal data, separately in sections, pursuant to the Law No. 6698 on the Protection of Personal Data (“Law”).

Keywords

Personal data, personal data security, technical and administrative measures.

Contents

  • 1. Introduction
    • 1.1. Purpose and Basis
    • 1.2. Scope
    • 1.3. Definitions
  • 2. Administrative Measures Regarding Personal Data Security
    • 2.1. Identification of Existing Risks and Threats
    • 2.2. Training of Employees and Awareness Activities
    • 2.3. Determination of Personal Data Security Policies and Procedures
    • 2.4. Minimization of Personal Data as Much as Possible
    • 2.5. Management of Relations with Data Processors
  • 3. Technical Measures Regarding Personal Data Security
    • 3.1. Ensuring Cybersecurity
    • 3.2. Monitoring Personal Data Security
    • 3.3. Ensuring Security of Environments Containing Personal Data
    • 3.4. Storing Personal Data in the Cloud
    • 3.5. Procurement, Development, and Maintenance of Information Technology Systems
    • 3.6. Backup of Personal Data
  • 4. Summary Tables within the Scope of Technical and Administrative Measures Regarding Personal Data Security
    • 4.1. Summary Table of Technical Measures
    • 4.2. Summary Table of Administrative Measures
  • 5. Sources Used in the Preparation of the Guide and Documents Considered Appropriate for Review

1. Introduction

1.1. Purpose and Basis

Article 12, paragraph one of the Law states; “The data controller;
a) Shall prevent unlawful processing of personal data,
b) Shall prevent unlawful access to personal data,
c) Shall take all kinds of necessary technical and administrative measures to ensure an appropriate level of security to protect personal data.”

Within this scope, the Personal Data Protection Board (“Board”) has prepared the Personal Data Security Guide (“Guide”) to clarify the technical and administrative measures that data controllers must take during the processing of personal data and to provide good practice examples.

1.2. Scope

Various risks may arise regarding personal data security in data recording systems. To prevent these risks, it is necessary to provide the required time, resources, and expertise and to take appropriate technical and administrative measures. These measures do not always require high costs; it is also possible to take these measures free of charge or at low cost or that they already exist in the systems.

The Guide is prepared to guide data controllers to prevent unlawful processing and unlawful access to personal data, ensure the preservation of personal data, and protect individuals' fundamental rights and freedoms. The Guide includes technical and administrative measures that can be taken.

The Guide’s;
The first section is the introduction, covering the purpose, basis, scope, and definitions of the Guide,
The second section covers administrative measures regarding personal data security,
The third section covers technical measures regarding personal data security,
The fourth section includes summary tables created within the scope of the measures mentioned in the second and third sections,
The fifth section includes sources used in the preparation of the Guide and documents considered appropriate for review.

1.3. Definitions

  • Secure Socket Layer (SSL): The certificate that enables the security and integrity of data flowing between the server and the client,
  • Data subject: The natural person whose personal data is processed,
  • Destruction: The deletion, destruction, or anonymization of personal data,
  • Law: The Law No. 6698 on the Protection of Personal Data dated 24/3/2016,
  • Recording medium: Any environment where personal data is stored, processed either fully or partially automatically or by non-automatic means as part of any data recording system,
  • Personal data retention and destruction policy: The policy data controllers base on determining the maximum period necessary for personal data to be processed for the purpose and for deletion, destruction, and anonymization processes,
  • Data Loss Prevention (DLP): Security software that prevents or reports the unauthorized or malicious transfer of personal data outside the institution,
  • Data recording system: The recording system where personal data is processed structured according to certain criteria.

For definitions not included in this Guide, the definitions in the Law may be referred to.

2. Administrative Measures Regarding Personal Data Security

2.1. Identification of Existing Risks and Threats

To ensure the security of personal data, the data controller must first correctly identify all personal data processed, the likelihood of risks that may arise regarding the protection of these data, and the losses that may occur if these risks materialize, and take appropriate measures accordingly.

When identifying these risks;

  • Whether the personal data is special category personal data,
  • The degree of confidentiality required by its nature,
  • The nature and extent of harm that may arise for the data subject in case of a security breach should be considered.

After defining and prioritizing these risks; control and solution alternatives to reduce or eliminate these risks should be evaluated according to cost, feasibility, and benefit principles, and necessary technical and administrative measures should be planned and implemented.

2.2. Training of Employees and Awareness Activities

Even if employees have limited knowledge about attacks that may damage personal data security and cybersecurity, their ability to make the first intervention is very important for ensuring personal data security.

Besides attacks aimed at violating personal data security, unlawful disclosure or sharing of personal data are among the main personal data security breaches. These breaches may also occur by exploiting users’ weaknesses such as carelessness, distraction, or inexperience, for example by opening an email attachment containing malware or sending an email to the wrong recipient, thus exposing personal data to third parties.

Therefore, it is very important for employees to receive training on not unlawfully disclosing or sharing personal data, to conduct awareness activities for employees, and to create an environment where security risks can be identified to ensure personal data security.

Everyone working under the data controller, regardless of their position, should have their roles and responsibilities regarding personal data security defined in their job descriptions, and employees should be made aware of their roles and responsibilities in this regard.

Moreover, when granting access rights to environments containing personal data or creating an institutional culture on this matter, the principle of “Everything is permitted unless prohibited” should not be applied; instead, the principle of “Everything is prohibited unless permitted” should be followed.

Additionally, confidentiality agreements may be requested as part of the hiring process. There must also be a disciplinary process that will be activated if employees do not comply with security policies and procedures.

When significant changes occur in policies and procedures related to personal data security, new trainings should be conducted to inform employees about these changes and keep their knowledge about threats to personal data security up to date.

2.3. Determination of Personal Data Security Policies and Procedures

Preparing a good policy regarding personal data security will enable the identification of risks in advance and consistent preventive measures.

Correct and consistent policies and procedures regarding personal data security should be integrated appropriately into the data controller’s operations and functioning.

If policies and procedures are not prepared properly and timely by data controllers, problematic areas cannot be identified, or existing security measures cannot be utilized, the level of personal data security cannot be adequately ensured.

Good incident management, where measures to be taken are predetermined, will reduce the pressure on employees.

Therefore, data controllers must be sure of which personal data are in their data recording systems and review existing security measures to ensure compliance with other legal obligations.

Within the scope of policies and procedures; regular checks should be performed, these checks should be documented, areas needing improvement should be identified, and after necessary updates, regular checks should continue.

Also, the risks that may arise for each personal data category and how security breaches will be managed should be clearly defined.

2.4. Minimization of Personal Data as Much as Possible

According to subparagraphs (b) and (d) of the second paragraph of Article 4 of the Law, personal data must be accurate and up-to-date when necessary and retained for the period prescribed by relevant legislation or necessary for the purpose for which they are processed.

However, especially data controllers operating for a long time collect a large amount of personal data, some of which may become inaccurate, outdated, and serve no purpose over time.

To prevent this, data controllers should evaluate whether the mentioned personal data are still needed for processing purposes and ensure that personal data are stored in the correct place.

Additionally, to prevent unauthorized access, although personal data may be appropriate for processing purposes, personal data that data controllers do not frequently access and are kept for archival purposes are recommended to be stored in more secure environments, and personal data that are no longer needed should be securely destroyed in accordance with the personal data retention and destruction policy and the regulation on deletion, destruction, or anonymization of personal data.

2.5. Management of Relations with Data Processors

Some data controllers receive services from data processors to meet their information technology needs.

Data controllers must ensure that data processors provide at least the same level of security for personal data as they do when receiving services.

Because according to the second paragraph of Article 12 of the Law, data processors are jointly responsible with the data controller for ensuring the security of personal data.

It is recommended that the contract signed with the data processor be in writing, include a provision that the data processor will act only according to the data controller’s instructions, in accordance with the data processing purpose and scope specified in the contract, and comply with personal data protection legislation and the Personal Data Retention and Destruction Policy.

It is also important that the contract includes the data processor’s obligation to maintain confidentiality indefinitely regarding the personal data processed.

Furthermore, the contract should foresee that in case of any data breach, the data processor is obliged to immediately notify the data controller, which will help the data controller fulfill its obligation to promptly notify the Personal Data Protection Board and the relevant data subject about the breach.

Also, to the extent the nature of the contract allows, specifying the categories and types of personal data transferred by the data controller to the data processor in a separate clause will be beneficial for the data processor to fulfill its obligation to ensure data security.

Moreover, the data controller conducts or has conducted necessary audits on the system containing personal data, can review the audit reports, and inspect the service provider on-site.

3. Technical Measures Regarding Personal Data Security

3.1. Ensuring Cybersecurity

The view that full security can be achieved by using a single cybersecurity product is not always correct for ensuring personal data security. Because threats continuously change in size and nature, expanding their impact areas.

Within this scope, the recommended approach is to apply a set of complementary measures under many principles and regularly checked.

Primary measures to protect information technology systems containing personal data against unauthorized access threats from the internet are firewalls and gateways. These will be the first line of defense against attacks from environments like the internet.

A well-configured firewall can stop breaches before deeply penetrating the network in use. An internet gateway can prevent employees from accessing websites or online services that pose threats to personal data security.

Additionally, almost every software and hardware requires some installation and configuration processes. However, some widely used software, especially older versions, have documented security vulnerabilities, and removing unused software and services from devices helps reduce potential security vulnerabilities.

Therefore, deleting unused software and services instead of keeping them updated is a method that can be preferred primarily due to its ease.

Another important element is patch management and software updates. Proper functioning of software and hardware and regular checks on whether security measures taken for systems are sufficient contribute to closing possible security gaps.