Data Protection Law

Data Protection Law

What is KVKK?

Personal Data Protection Law No. 6698, which entered into force on 01.05.2016 (in short, KVKK), in order to protect the privacy of private life of natural persons and the fundamental rights and freedoms of natural persons; It was issued in order to determine the procedure and law to be followed by real and legal persons who process personal data of individuals.

Who is Data Protection Law Mandatory For?

Legal and real persons, including public institutions, are obliged to comply with this law if they process personal data.

What is VERBİS?

VERBIS, also called the data controllers registry, is a public registry where real and legal persons who process personal data categorically enter information into the system and where it is mandatory for real and legal persons who process personal data to register in the system.

For Whom is The Data Controllers Registry Mandatory?

Pursuant to Article 16 of the Personal Data Protection Law, natural and legal persons who are data controllers, that is, who process personal data, have to register with the Data Controllers Registry before processing personal data.

In accordance with the law; real or legal person data controllers with less than 50 employees and an annual financial balance of less than 25 million TL, whose main field of activity is not to process sensitive personal data, customs consultants and specially authorized customs consultants operating in accordance with the law no 4458, arbitragers and persons with the title of data controller, excluding lawyers, must be registered in the Data Controllers Registry.

What is Personal Data?

Belonging to real persons, making that person identifiable directly or indirectly; phone number information, photo, identity information, political opinion, professional experience, license plate information, sexual life information, health information… etc. Any kind of information is called personal data.

What is Clarification Text?

It is the text, which is considered within the scope of the right to information, that enables the persons whose personal data are processed to learn by whom, how, for what purpose, for which legal reasons and by which method these data can be processed and transferred. The person responsible for the disclosure obligation has been brought to the data controller with KVKK.

What is Explicit Consent? - What is Explicit Consent Text?

With the information given to the person himself, having sufficient information, of his own free will; It is the consent and approval of the relevant process by being limited to the event covering the information process made to it.

Explicit consent text; It is a written text in which the person freely consents to the processing of his personal data with the information given to him.

Who is Data Controller?

Data controller refers to the natural or legal person who answers the questions "why" and "how" the personal data processing will be done, determines the purposes and means of processing personal data, and is responsible for the establishment and management of the data recording system.

Who is Data Subject?

The person whose personal data is processed is called the data subject.

What is Data Processing?

All kinds of activities carried out with the relevant personal data in the process from the collection of personal data in accordance with the law to the processes of deletion, destruction or anonymization are called data processing..

What is Personal Data Inventory?

Personal data inventory is the chart that shows the personal data processing purposes of the data controllers and how long they will process the personal data by categorizing the personal data.

Is Personal Data Protection Law (KVKK) Training?

Pursuant to KVKK, data controllers and data processors are obliged to prevent unlawful processing of personal data, to prevent unlawful access and to ensure the preservation of personal data. For these purposes, data subjects have to take administrative and technical measures. In accordance with the Personal Data Security Guide of the Personal Data Protection Authority, data controllers are obliged to provide their personnel with KVKK training and raise awareness about the issues they should do and pay attention to in accordance with the law.

What is GDPR?

General Data Protection Regulation refers to the personal data regulation covering the European Union countries. GDPR regulates the rules and obligations to be complied with in the processing of personal data.

Even if the data processing process takes place in another geography, if it will operate within EU countries or if the data processing process starts within EU countries and will be effective in other geographies, it must be GDPR compliant.. 

**This study is prepared by Kula Law Office. Please contact by e-mail ([email protected]) or call at +902324350604 for publication of the article in other channels, detailed information and questions about the subject.

Related Publications
  • Data Protection Law