Turkey is Taking Small but Firm Steps towards GDPR

22.02.2019

As you know, the delegation from “DIGITALEUROPE has recently visited Turkey. They discussed the advancement of technology with “Digital Turkey Platform”, and evaluate the current position of Turkey in regards to the steps to be taken in the future to accelerate flows of data. The delegation specifically stated that “Turkey will need to complete its journey in developing a compatible regime to the General Data Protection Regulation (GDPR) [1] where the data of the EU citizens will receive adequate privacy protections.

Even though Turkey has started this compliance journey not so long ago, the process is not going so bad considering that the newly introduced law is the first of its kind[2]. For now, the Turkish Data Protection Law (“KVKK”) is more similar to the former EU Directive[3]. But the work is in progress for full compliance in the future.

Most recent update with regards to the compliance process was about the breach notifications. KVKK already stipulates that in case of any breach, data controller shall immediately notify the Data Protection Board  (the “Board”) and the data subject[4]. However, it is not clear “how immediate it shall be” in the law. Through the decision (numbered 2019/10-dated 24.01.2019), the Board declared, -in corresponding to the General Data Protection Regulation-, that “the notion of ‘immediate’ shall mean 72 hours at most”. From now on, the data controller shall immediately notify the Board no later than 72 hours, when s/he is aware of such breach. Also, the notification of the data subject shall take place in short notice, just right after the controller obtains the data subjects' contact information. If otherwise, the controllers shall announce that relevant breach on their own website.

Should you have any queries and/or remarks, please do not hesitate to contact us. 

Kind regards,

Zumbul Attorneys-at-Law

info@zumbul.av.tr

 

 


[1] General Data Protection Regulation (EU) 2016/679

[2] Although the concept of "data protection" existed under constitution and several regulations, it was the first to introduce as a completely dedicated to data protection of personal data.

[3] Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data

[4] Article 12(5) of KVKK “In case the processed data are collected by other parties through unlawful methods, the controller shall notify the data subject and the Board within the shortest time. Where necessary, the Board may announce such breach at its official website or through other methods it deems appropriate.”

__

* gerekli alanlar

__ (0)