Two-Minute Recap Of Recent Developments In Turkish Personal Data Protection Law – June 2022

GT
Gen Temizer

Contributor

Gen Temizer is a leading independent Turkish law firm located in Istanbul's financial centre. The Firm has an excellent track record of handling cross-border matters for clients and covers the full bandwidth of most complex transactions and litigation with its cross-departmental, multi-disciplinary and diverse team of over 30 lawyers. The Firm is deeply rooted in the local market with over 80 years of combined experience of the name partners while providing the highest global standards of legal services.
In June 2022, the Turkish Personal Data Protection Authority (the "Authority") published guidelines on the use of online cookies, opened draft guidelines on loyalty programs for public opinion...
Turkey Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

In June 2022, the Turkish Personal Data Protection Authority (the "Authority") published guidelines on the use of online cookies, opened draft guidelines on loyalty programs for public opinion, and announced five data breach notifications.

The Authority cooks guidelines on cookies

On 20 June 2022, the Authority published guidelines (the "Guidelines") on the use of cookies to collect personal data and the use of personal data in online environments such as websites, mobile applications, smartphones, and tablets.

In summary, the Guidelines evaluate the use of cookies and provide information on:

  • the different types of cookies;
  • the rules for processing personal data through cookies;
  • cookies that may be implemented without obtaining the explicit consent of data subjects;
  • cookies that may be implemented based on the explicit consent of data subjects;
  • the elements of valid explicit consent;
  • cross-border data flows via cookies;
  • the obligation to inform before cookie implementation.

The Guidelines classify cookies under three fundamental groups: (i) cookies by their duration, (ii) cookies by their usage purposes; and (iii) cookies by parties. The Guidelines also define the types of cookies and the legal requirements to use them. In this respect, data controllers need to determine the types of cookies in use and ensure that the use of such cookies is in compliance with Turkish DP Law. For detailed information, please see our article here.

How are loyalty programs loyal to data privacy rules?

On 16 June 2022, the Authority published draft guidelines on the processing of personal data via loyalty programs (the "Draft Guidelines") and announced that the Draft Guidelines will be available for public opinion until 16 July 2022.

The Draft Guidelines state that loyalty program operators are considered as data controllers, and customers who are beneficiaries of such programs are considered as data subjects.

In addition, the Draft Guidelines classify personal data processed through loyalty programs as follows:

  1. data that is actively and voluntarily provided by customers;
  2. data that is passively provided by customers; and
  3. data that is obtained from other sources.

The Draft Guidelines also touch on fundamental matters of Turkish data protection law: explicit consent and data controllers' obligation to inform. Accordingly:

  • requesting explicit consent to carry out a loyalty program from a customer before providing a service shall not be deemed as implementing explicit consent as a pre-condition of services;
  • if a customer does not give explicit consent, such service may be offered without additional benefits. However, in such a case, advantages to be provided under the loyalty program must not (i) cause a significant disadvantage and (ii) affect the will of the data subject;
  • the obligation to inform must be fulfilled in compliance with Turkish DP Law and secondary legislation.

You can access the draft guideline here (available only in Turkish).

The Board announced the following data breach notifications in June

Data Controller

Affected Data Subjects

Affected Personal Data

Number of Data Subjects

MBtech Mühendislik ve Danismanlik Ltd. Sti.

Employees, Users, Customers and Potential Customers

Identity, Communication Information, Location, Information on Consumer Transaction, Personnel Information, Finance, Information on Professional Experience, Audio and Visual Records

500

Pegasus Hava Tasimaciligi Anonim Sirketi

Employees

Identity, Communication Information and Visual Records

N/A

Barçin Spor Malzemeleri Ticaret ve Sanayi Anonim Sirketi

Users, Customers and Potential Customers

Identity, Communication Information, Information on Customer Transaction and Other (Membership Date)

187,930

Tofisa Tekstil Sanayi ve Ticaret Limited Sirketi

Customers and Potential Customers

Identity and Communication Information

42,373

ARG Denizcilik Insaat Otomotiv Sanayi ve Ticaret Ltd. Sti,

Istek Gemi Insa Bakim Insaat Hirdavat Sanayi ve Ticaret Ltd. Sti, and

Safter Ulubay

Employees

Identity, Communication Information and Personnel Information

Approx. 2,000

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More