ABOUT THE PROTECTION OF PERSONAL DATA
Personal data can be defined as any information that makes it possible to identify individuals. In this context, a person’s identity, contact, health and financial information, as well as information relating to their private life, religious belief and political opinion, are considered personal data. For example: first name, surname, date of birth, mobile phone number, e-mail, gender, address, occupation, education, point and time of purchase, how much they paid, which campaign they benefited from, the amount of discount they received, the product information in their purchase, browsing and click data on the application, location data of where they opened the application, etc.
Today, this data is frequently used through automated means via information systems by both the private sector and the public sector. Although the use of this information provides certain conveniences or advantages for individuals and those who offer goods and services, this situation also brings with it the risk of the information in question being abused. The acquisition, use and disclosure of this data by unauthorized persons arises as a violation of both the contracts to which we are party and the fundamental rights protected under our Constitution. A reasonable balance must be established between these two interests. The absence of a specific law and an effective supervisory mechanism regarding the processing of personal data causes a negative perception to form in our society. In order to eliminate this perception, principles regarding the processing, retention and control of personal data under certain conditions must be determined.
In our age, in parallel with the development of awareness of the protection of human rights, the importance of protecting personal data is also increasing day by day. For this reason, it is observed today that detailed legal regulations are being implemented in the field of the protection of personal data in developed countries.
By contrast, in our country there is no law that comprehensively regulates the field relating to the protection of personal data; provisions on this subject are found in different laws. Furthermore, there is no institution in our country to control and supervise the process of processing personal data. As a result of this, personal data can still be used by many persons or institutions without being subject to adequate regulation and supervision, and this situation can cause certain rights violations to occur.
There are various reasons requiring the entry into force of a law that will ensure the protection of personal data in our country. First of all, in Articles 135 et seq. of the Turkish Penal Code No. 5237, the acts of unlawfully obtaining, recording or disclosing personal data have been regulated as crimes and made subject to sanctions. However, due to the absence of a specific law on the processing of personal data, it is observed that hesitations are experienced in determining when these acts are unlawful and when they are lawful.
On the other hand, with the regulation made in Article 20 of the Constitution by Law No. 5982, adopted as a result of the referendum held on 12 September 2010, the protection of personal data was guaranteed as a fundamental human right and it was envisaged that the details would be regulated by law.
Again, in the ongoing European Union full membership process concerning our country, four of the negotiation chapters are directly related to personal data. In order for the process regarding these chapters to advance, a fundamental law on the protection of personal data must enter into force in our country.
The subject of the protection of personal data began to appear in international documents from the 1980s onwards. Firstly, the “Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data” were adopted on 23/9/1980 by the Organisation for Economic Co-operation and Development (OECD), of which our country is also a member. The Convention No. 108 “for the Protection of Individuals with regard to Automatic Processing of Personal Data”, prepared by the Council of Europe with the aim of protecting personal data to the same standards in all member states and determining the principles of transborder data flow, was opened for signature on 28 January 1981 and was also signed by our country.
The Council of Europe has also adopted recommendations determining the principles to be applied in various sectors regarding the protection of personal data, such as medical data banks, scientific research and statistics, direct marketing, social security, insurance, police records, employment, electronic payment, telecommunications and the internet. During the preparation of the Draft, while the recommendations in question were taken into account, the “framework draft” nature of the Draft was preserved. Considering that the volume of the Draft would expand greatly if regulations relating to all sectors were included, the recommendations in question were not incorporated into the Draft. It was assessed that the principles contained in these recommendations could be included, in the coming process, in regulations to be made concerning various sectors.
On the other hand, the European Union put into force the “Directive on the Protection of Individuals with regard to the Processing of Personal Data and on the Free Movement of Such Data” (95/46/EC) on 24/10/1995, in order to ensure harmony among the legislation of the member states regarding the protection of personal data. With this Directive, it was aimed to protect the personal data of individuals in the member states at a high level and to make a clear and permanent regulation that would ensure the free movement of personal data within the European Union. When international documents concerning the protection of personal data are taken into account, it is observed that in a law to be prepared on this subject, the conditions for the processing of personal data, the informing of individuals, the establishment of an authority to supervise and regulate this field, and the taking of the necessary measures regarding data security are accepted as fundamental principles.
In the face of the aforementioned Data Protection Directive and earlier treaties and directives becoming inadequate against current developments, and the differences among the treaties and directives signed from country to country, agreement was reached on 15 December 2011 on a reform that would cover the whole of the EU. Within this scope, the GDPR, prepared in 2012, was adopted by the EU Parliament on 14 April 2016. While Article 94 of the GDPR repealed the 95/46 Data Protection Directive, it expanded the scope of application of the 2002/58/EC Electronic Data Protection Directive.
With the constitutional amendment made by Law No. 5982 in 2010, an additional paragraph was added to Article 20 of the Constitution. That paragraph states: “Everyone has the right to request the protection of the personal data concerning them. This right includes being informed about one’s personal data, accessing this data, requesting its correction or deletion, and learning whether it is used in accordance with its purposes. Personal data may only be processed in cases prescribed by law or with the explicit consent of the person. The principles and procedures regarding the protection of personal data shall be regulated by law.”
The Constitution also states that detailed regulations regarding the protection of personal data will be made by law. Within this scope, the “Draft Law on the Protection of Personal Data” was submitted to the Presidency of the Grand National Assembly of Türkiye on 26 December 2014. The Draft became law on 24 March 2016, and Law No. 6698 on the Protection of Personal Data was published in the Official Gazette dated 7 April 2016 and numbered 29677, thereby entering into force.
With the Draft prepared by taking into account international documents, comparative law practices and the needs of our country, it is aimed to process and protect personal data at contemporary standards.
