Protection of Personal Data with Examples

KVKK Publications No: 29

ISBN: 978-605-80554-1-4

Date: June, 2019

Place: Ankara

Publisher: Republic of Turkey Personal Data Protection Authority

Address: Nasuh Akar Neighborhood 1407 Street No: 4 Çankaya / ANKARA

Phone: 0.312.216 50 00

Web: www.kvkk.gov.tr

The copying, reproduction, use, publication, and distribution of the writings and other contents in this booklet, partially or entirely, without permission other than for individual use is prohibited. Legal action will be taken against those who do not comply with this prohibition pursuant to Law No. 5846. All rights reserved.

Contents

  1. Personal Data
  2. General (Basic) Principles
    • Compliance with Law and Honesty Rules
    • Being Accurate and Updated When Necessary
    • Processing for Specific, Clear, and Legitimate Purposes
    • Being Relevant, Limited, and Proportionate to the Purpose Processed
    • Retention for the Period Prescribed by Relevant Legislation or Necessary for the Purpose Processed
  3. Conditions for Processing Personal Data
    • Explicit Consent of the Data Subject
    • Explicit Provision in Laws
    • Mandatory for Protecting the Life or Physical Integrity of the Data Subject Who Cannot Express Consent Due to Actual Impossibility or Whose Consent Has No Legal Validity
    • Necessary for Processing Personal Data of the Parties to a Contract Directly Related to the Establishment or Performance of the Contract
    • Necessary for the Data Controller to Fulfill a Legal Obligation
    • Data Made Public by the Data Subject Themselves
    • Necessary for Establishing, Exercising, or Protecting a Right
    • Necessary for the Legitimate Interests of the Data Controller Without Harm to the Fundamental Rights and Freedoms of the Data Subject
  4. Special Categories of Personal Data (Sensitive Data)
  5. Deletion, Destruction, or Anonymization of Personal Data
    • Deletion of Personal Data
    • Destruction of Personal Data
    • Anonymization of Personal Data
  6. Obligation to Inform
  7. Rights of the Data Subject
  8. Application to the Data Controller
  9. Complaint to the Board and Examination Process
    • Complaint to the Board
    • Procedures and Principles of Examination Upon Complaint or Ex Officio
  10. Registration to the Data Controllers Registry
  11. Exceptions
    • Cases Where the Law Does Not Apply Completely
    • Cases Where Some Articles of the Law Do Not Apply
  12. Data Controller and Data Processor

What You Need to Know About the Personal Data Protection Law

1. Personal Data

In the Personal Data Protection Law No. 6698 (“Law”), personal data is defined as any information relating to an identified or identifiable natural person. The term "any information" includes not only information that directly identifies the individual such as name, surname, date of birth, place of birth but also information related to physical, familial, economic, social, and similar characteristics that make the individual identifiable.

Since personal data is not exhaustively listed in the Law, the scope of personal data can be extended depending on the specifics of each case. In this context, information such as a real person's vehicle license plate, interview results, IP addresses of electronic devices used, audio and video recordings, location data, criminal record, credit card statements, social media likes, fingerprints, etc., can also be defined as personal data.

Examples:

  • Images of individuals captured by a video surveillance system can be considered personal data if the individuals are identifiable.
  • In telephone banking systems, the voice recording of a customer giving instructions to the bank can be accepted as personal data.
  • In a custody case, a drawing made by a child about their family is personal data because it shows the child's feelings towards their family. Additionally, if the drawing reveals the behavior of the mother and father within the family, it is also considered their personal data.

According to the Law, for information to be considered personal data, it must relate to a natural person; data related to legal entities are excluded from the definition of personal data.

Example:

Information related to a legal entity such as a company's trade name or address (except when linked to a real person) is not considered personal data.

For information to be personal data, it must relate to an identified or identifiable natural person. "Identified" means the data directly shows the identity of a real person; "identifiable" means the person can be identified by linking the data with any record.

Examples:

  • Name and surname alone are personal data and can identify a real person. However, name and surname may not always be sufficient to identify a real person; sometimes additional information is needed.
  • Common combinations of name and surname may not uniquely identify a person but are still personal data because they can make a real person identifiable. Name and surname sometimes directly identify the person if unique, or indirectly if multiple exist. This does not exclude them from being personal data.
  • Similarly, in some cases, a person can be identified even without mentioning name and surname.
  • The phrase “A middle-aged, short-statured male employee of Institution A in Unit B who owns a red X brand vehicle” is personal data if it identifies a single person.
  • Nicknames or aliases, alone or combined with other sources, are considered personal data if they can identify the person. However, the identifiability of the real person must be evaluated case by case based on the data's ability to identify.

2. General (Basic) Principles

The general principles to be followed in processing personal data are stated in Article 4 of the Law. These principles are;

  • Compliance with law and honesty rules
  • Being accurate and updated when necessary
  • Processing for specific, clear, and legitimate purposes
  • Being relevant, limited, and proportionate to the purposes processed
  • Retention for the period prescribed by relevant legislation or necessary for the purposes processed

Regardless of the legal basis or processing condition, all data processing activities must comply with these principles.

a) Compliance with Law and Honesty Rules

This principle means acting in accordance with the principles set by laws and other legal regulations in processing personal data, and also considering the interests and reasonable expectations of the data subjects during processing.

Note: Compliance with law means that data processing is not contrary to the Personal Data Protection Law or other legislation.

Note: Honesty means not using the data subject's personal data in a way that causes injustice to them, meeting their reasonable expectations, and not exceeding the purpose of data collection.

b) Being Accurate and Updated When Necessary

This principle means that the data should accurately represent the subject it relates to. This principle aligns with the data subjects' right to request correction of their data.

Example:

When calculating the Minimum Living Allowance (AGI), having the current number of children and spouse's employment status is important for accurate calculation and the person's economic interests.

c) Processing for Specific, Clear, and Legitimate Purposes

This principle requires the data controller to clearly and understandably specify the purpose of data processing and that the purpose is legitimate. If data controllers process data for purposes other than those stated to the data subject, they will be held responsible for such acts.

Legitimacy of the purpose means that the processed personal data is related to and necessary for the data controller's business or service.

Example:

An e-commerce site processing the buyer's name, surname, and address for shipping is within legitimate purpose, whereas processing mother's maiden name or blood type is not.

d) Being Relevant, Limited, and Proportionate to the Purposes Processed

This principle means that the processed data should be suitable for achieving the specified purposes, and unnecessary or unrelated personal data should be avoided.

Examples:

  • Requesting information about social life preferences from a credit card applicant violates the proportionality principle.
  • Sending promotional emails by a foundation university to a symposium participant who provided their email for participation violates the purpose limitation principle.

e) Retention for the Period Prescribed by Relevant Legislation or Necessary for the Purposes Processed

According to this principle, data controllers must comply with any legally prescribed retention period; if none exists, data can only be kept as long as necessary for the purpose processed.

Example:

In a campaign where a gas station rewards customers who buy a certain amount of fuel within a period, the collected names and vehicle plate numbers must be deleted after the campaign ends if no other processing condition applies.

Personal data cannot be kept after the retention period expires, the purpose is achieved, or the processing condition ceases, based on potential future use.

3. Conditions for Processing Personal Data

For lawful processing of personal data, at least one of the processing conditions listed in Article 5 of the Law must exist. These conditions are:

a) Explicit Consent of the Data Subject

The explicit consent must be specific, based on information, and freely given.

Note: Obtaining explicit consent does not mean data can be processed contrary to the general principles in Article 4 of the Law.

b) Explicit Provision in Laws

If there is an explicit provision in any law regarding personal data processing, processing is possible based on that provision.

Examples:

  • Keeping employee personal records as required by the Labor Law.
  • Processing customer information held by banks under Article 42 of the Banking Law.
  • Data controllers entering information into VERBİS within the scope of the obligation to register in the Data Controllers Registry regulated in Article 16 of Law No. 6698.
  • Processing personal data of individuals renting real estate by the relevant units of the Ministry of Finance within the scope of the annual declaration obligation under Article 70 of the Income Tax Law.

c) Mandatory for Protecting the Life or Physical Integrity of the Data Subject Who Cannot Express Consent Due to Actual Impossibility or Whose Consent Has No Legal Validity

Processing personal data is possible if the data subject cannot express consent due to actual impossibility or if the person whose consent has no legal validity, and processing is necessary to protect their or another person's life or physical integrity.

Examples:

  • Processing name, surname, ID number, phone number, etc., of an unconscious person for medical intervention, notifying relatives, or accessing patient history by authorized health institutions.
  • Processing personal data such as cell phone signals, credit card usage, vehicle tracking, MOBESE records by relevant units to locate a detained person for rescue.
  • Processing cell phone signals, GPS, and mobile traffic data to locate a person stranded in the mountains for rescue.

d) Necessary for Processing Personal Data of the Parties to a Contract Directly Related to the Establishment or Performance of the Contract

Processing must genuinely serve this purpose and be limited to it. Only personal data of the parties to the contract should be processed within the contract's scope.

Examples:

  • A real estate agent processing and keeping personal data such as ID number, bank account number, address, signature, and phone of parties in a lease contract.
  • A seller providing the customer's address to a shipping company to deliver a sold product.
  • A bank processing and keeping personal data such as ID number, email, address, signature, and phone number of a salary customer under a contract.

e) Necessary for the Data Controller to Fulfill a Legal Obligation

Processing must be necessary and limited to fulfilling the data controller's legal obligation.

Examples:

  • A cargo company recording recipient's address and contact information to deliver shipments.
  • A company processing bank account information to pay employee salaries.
  • Processing personal data such as ID number, signature, and phone number of seminar participants to ensure participant and building security.

f) Data Made Public by the Data Subject Themselves

Personal data publicly disclosed by the data subject can be processed if related to the purpose of public disclosure. The will to disclose is essential; processing for other purposes is not allowed.

Examples:

  • Sharing name, surname, and work phone of a public institution employee on the institution's website for easy public access, which can be used within the institution's authorized operations.
  • Using contact information of a person selling a used car on a website for marketing purposes other than vehicle sales is not covered by this processing condition.