Single Blog Title

This is a single blog caption

Compensation and Remedies for Unlawful Sharing of Personal Data

Entrance

The unlawful sharing of personal data is one of the most common data breaches individuals face today. Examples include sharing a person's phone number with third parties, disclosing debt information to relatives or colleagues, sending medical reports without authorization, publishing camera footage on social media, identity photocopies falling into the wrong hands, a package containing another person's address information, or disclosing bank or customer information to unauthorized individuals.

The Law No. 6698 on the Protection of Personal Data permits the processing and transfer of personal data only for lawful reasons. Disclosure, transfer, dissemination, or making accessible personal data to third parties is also considered a personal data processing activity. Therefore, for data sharing to be lawful, it must comply with the processing and transfer conditions set forth in the Law. Otherwise, administrative sanctions, compensation, and criminal liability may arise.

The Personal Data Protection Authority's decisions clearly state that information such as name, surname, and address constitutes personal data because it identifies or makes an individual identifiable; and that obtaining, recording, disclosing, transferring, and making this information accessible is considered a personal data processing activity.

Therefore, the answer to the question "My personal data has been shared without my permission, what can I do?" is not limited to a single method. Depending on the specifics of the case, various legal avenues can be considered together, such as applying to the data controller, filing a complaint with the Personal Data Protection Board, making a criminal complaint with the prosecutor's office, pursuing a lawsuit for material and moral damages, requesting the removal of the content, blocking access, and gathering evidence.

What does it mean to unlawfully share personal data?

Unlawful sharing of personal data is the transfer, disclosure, dissemination, or making accessible to a person's data to third parties without the legal conditions stipulated by law. This sharing does not necessarily have to take the form of a large-scale data leak. Even the unauthorized sharing of a single person's phone number, debt information, address, health information, or identity information can constitute unlawful data sharing.

For example, a company giving a customer's phone number to other firms without permission, an employer sending an employee's medical report to other employees, an apartment manager sharing camera footage in a WhatsApp group, a bank informing a customer's debt information to their workplace, or a law firm sending debtor information to the debtor's relatives could all be grounds for an allegation of unlawful sharing of personal data.

For the sharing of personal data to be lawful, there must first be a specific, clear, and legitimate purpose. Furthermore, the sharing must be based on one of the legal grounds stipulated in the law. If grounds such as the explicit consent of the individual, explicit provision in the law, performance of a contract, fulfillment of a legal obligation, establishment or protection of a right are not present in the specific case, the data transfer may become unlawful.

From the perspective of the Personal Data Protection Law (KVKK), it is not only important that the data “belongs to the correct person.” The purpose for which the data is shared, to whom it is shared, the legal basis for sharing it, and the limits within which it is shared are also crucial. For example, it may be legally permissible for a shipping company to process a recipient's address as part of its transportation services; however, sending a person's address information to an unrelated third party due to a barcode error constitutes a separate and unlawful data sharing. In the Board's decision regarding the shipping company, the sharing of personal data with a third party as a result of a cross-barcode error was also evaluated separately under the Law.

What kind of information, when shared, could constitute a personal data breach?

Personal data is any information relating to an identified or identifiable natural person. Therefore, it is not only national identity numbers or passport information that can be considered personal data; name and surname, telephone number, email address, home address, work address, IP address, vehicle license plate number, camera footage, audio recording, bank account information, debt information, health report, criminal record, employee personal information, customer transaction history, and location information can also be considered personal data.

Some data is more sensitive than others. Health data, biometric data, criminal record information, union membership, religious beliefs, political opinions, sexual life, genetic data, and similar information are considered special categories of personal data. Unlawful sharing of this data can cause much more serious harm to the individual. For example, disseminating a person's medical information in the workplace is not only a violation of the Personal Data Protection Law but also constitutes a serious attack on their personal rights.

The unlawful sharing of personal data does not necessarily have to be for commercial purposes. Sharing personal data out of curiosity, coercion, threat, debt collection, revenge, disclosure, gossip, or negligence can also give rise to legal liability. Examples include disclosing a person's debt information to their family, sharing screenshots of their private messages, publishing their address on social media, or using their identity photograph for fraudulent purposes.

Applying to the Data Controller is the first step

Individuals whose personal data has been shared unlawfully must first apply to the data controller under the Personal Data Protection Law (KVKK). The data controller is the natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system. A company, bank, hospital, school, employer, courier company, e-commerce platform, insurance company, or association may be the data controller in this specific case.

The data subject may contact the data controller to inquire whether their personal data is being processed, request information on which data is being processed, ask about the purpose of data processing, find out to whom the data is transferred domestically or internationally, request the correction of inaccurate or incomplete data, and, if the conditions are met, request the deletion or destruction of the data. The law also regulates the right of a person who has suffered damage due to the unlawful processing of personal data to demand compensation for that damage.

Applications to the data controller may be made in writing, via registered electronic mail, secure electronic signature, mobile signature, email address registered in the data controller's system, or other methods determined by the Board. The application must clearly describe the situation, specify which personal data was shared with whom and in what manner, include evidence if possible, and clearly state the requests being made.

The data controller is obliged to process the application as soon as possible, and no later than thirty days, depending on its nature. If the data controller accepts the request, they must take the necessary action; if they reject it, they must state the reasons.

Complaint to the Personal Data Protection Board

If an application is rejected by the data controller, if the response is deemed insufficient, or if no response is given within thirty days, a complaint may be filed with the Personal Data Protection Board. The time limits are extremely important here. The data subject must file a complaint with the Board within thirty days of learning of the data controller's response, and in any case within sixty days of the application date.

If a complaint is filed directly with the Board without exhausting the application process, the complaint may be dismissed on procedural grounds. The Authority's public announcement also states that, in accordance with Article 14 of Law No. 6698, a complaint cannot be filed with the Board without first exhausting the application process with the data controller.

The Board may conduct an investigation upon receiving a complaint or upon learning of an alleged violation. If a violation is found as a result of the investigation, it may decide to remedy the illegality and impose administrative sanctions on the data controller. The data controller must comply with the decisions of the Board without delay and within a maximum of thirty days from the date of notification.

In complaints to the Board, both the legal and evidentiary aspects of the case are crucial. Screenshots, SMS records, email correspondence, shipping labels, social media posts, call logs, witness statements, the application made to the data controller, and the response received must be included in the file. Specifically, identifying who shared the data, when, by what method, and to whom it was shared is vital for an effective investigation of the complaint.

Can a Board Complaint Substitute for Compensation?

A complaint filed with the Board does not replace a compensation lawsuit. The Board may impose administrative sanctions on the data controller, order the rectification of the illegality, and request the implementation of data security measures; however, it does not act like a court that directly orders the payment of material or moral damages to an individual.

The Personal Data Protection Law (KVKK) rulings clearly state that those whose personal rights have been violated retain the right to compensation under general provisions, and that compensation claims must be brought before general courts. In a decision concerning a bank, the Board stated that a person claiming to have suffered damages must pursue their compensation claim before general courts.

Therefore, individuals whose personal data has been unlawfully shared must consider two separate avenues. Firstly, under the Personal Data Protection Law (KVKK), they can file an application with the data controller and a complaint with the Board. Secondly, they can pursue legal action for both material and moral damages. The Board's decision can be used as strong evidence in a compensation lawsuit. Especially in cases where the Board identifies a data breach and imposes an administrative fine on the data controller, this decision can support the plaintiff's claim before a civil court.

Can a lawsuit for material and moral damages be filed?

Yes. If a person has suffered material or moral damage due to the unlawful sharing of their personal data, they can file a compensation lawsuit. Material damage may include concrete monetary losses such as job loss, loss of income, loss of money due to fraud, expenses incurred due to wrongful transactions, and financial losses resulting from the misuse of identity information.

Non-pecuniary damage may arise in situations such as the violation of a person's privacy, humiliation in society, loss of reputation within family and work circles, psychological pressure, dissemination of private information, or the disclosure of debt or health information to third parties. The sharing of private data, particularly health data, debt information, criminal investigation information, images of private life, address information, or family information, can strengthen a claim for non-pecuniary damages.

In a compensation lawsuit, the plaintiff must prove that their personal data was unlawfully shared, that they suffered damages as a result of this sharing, and that there is a causal link between the damages and the unlawful sharing. However, the standard of proof differs for each specific case. For example, in a case where information about a debt was sent to colleagues, SMS records, witness statements, and the Board's decision could be important evidence. In a case where a medical report was disseminated at the workplace, email chains, WhatsApp messages, witnesses, and workplace records could be considered.

A compensation lawsuit can be filed in different courts depending on the parties involved and the nature of the legal relationship. If it's an employer-employee relationship, the labor court may have jurisdiction; if it's a consumer transaction, the consumer court; and if it's a general violation of personal rights, the civil court of first instance may have jurisdiction. Therefore, the legal nature of the relationship must be correctly determined before filing a lawsuit.

Can a criminal complaint be filed with the prosecutor's office?

In some cases, the unlawful sharing of personal data may constitute not only a violation of the Personal Data Protection Law (KVKK) but also a crime. Article 17 of Law No. 6698 refers to Articles 135 to 140 of the Turkish Penal Code regarding crimes related to personal data. The Personal Data Protection Authority also states that individuals who unlawfully record, give to another person, disseminate, or obtain personal data may be subject to imprisonment under the Turkish Penal Code.

Therefore, if a person's identity information is used for fraudulent purposes, their address is shared for threatening purposes, their private images are disseminated, their health information is disclosed, their bank details are given to third parties, or their personal data is obtained to carry out fraudulent transactions, a criminal complaint can be filed with the Public Prosecutor's Office.

However, criminal investigations and complaints under the Personal Data Protection Law (KVKK) are different procedures. The Board does not conduct criminal proceedings in matters falling under the jurisdiction of judicial authorities. The Board's announcements also state that legal action should be taken through the judicial system to initiate the necessary legal procedures regarding allegations containing elements of crime.

Therefore, if a data breach has administrative, legal, and criminal consequences, all avenues can be pursued simultaneously. For example, an individual can file a complaint with the data controller, then lodge a complaint with the Board, simultaneously file a criminal complaint with the prosecutor's office, and also initiate a compensation lawsuit. These avenues are not entirely alternatives to each other, but in most cases, they complement each other as legal remedies.

Data Controller's Notification Obligation in Case of Data Breach

If personal data is obtained by others through unlawful means, the data controller must notify the data subject and the Board of this situation as soon as possible. The data controller is also obliged to take the necessary technical and administrative measures to prevent the unlawful processing and access of personal data and to ensure the preservation of the data.

This obligation is particularly important for companies. A data breach can occur in a company's database due to a leak, unauthorized access to customer information by an employee, recipients accidentally viewing each other's emails, shipping information being sent to the wrong person, or users seeing each other's information due to a system vulnerability. In such cases, it is not enough for the company to simply say "it was a mistake." The scope of the breach must be determined, the affected individuals identified, the Board notified, the relevant individuals informed, and measures taken to prevent its recurrence.

The Board's decision regarding the airline company stated that the airline had failed to take the necessary technical and administrative measures to prevent unlawful access to personal data and ensure its protection, as this allowed information belonging to different individuals to be viewed through passenger name records.

Similarly, in the decision regarding the cargo company, the sharing of personal data with a third party due to a cross-barcode error was deemed a data breach; the data controller's obligation to take technical and administrative measures was emphasized.

Examples of Board Decisions

The Board's decisions regarding the unlawful sharing of personal data serve as guidelines for implementation. For example, one decision evaluated the sending of debt information via SMS by a lawyer handling enforcement proceedings to a person's colleagues and brother. The Board found that sharing the individual's debt information with these individuals and conducting certain inquiries using their Turkish Republic identity number were contrary to the law, and decided to impose an administrative fine on the data controller.

This decision is particularly important because it demonstrates the limits of the use of personal data in debt collection processes. Just because someone is in debt doesn't mean their debt information can be disclosed to their family, neighbors, colleagues, or employer. Even when collecting debts, personal data must be used appropriately, in a limited, and proportionate manner.

In another decision, the allegation that the airline's mobile application allowed access to third-party information such as passport details, date of birth, nationality, document numbers, and similar details during check-in was examined. The severity of the breach is further amplified by the fact that this type of data contains travel and identity information. The Board assessed the adequacy of technical and administrative measures and emphasized the importance of data security obligations.

The shipping company's decision examined the issue of name, surname, and address information being sent to an unrelated third party due to incorrect barcoding. The Board stated that this sharing constitutes a new and independent personal data processing activity, and that it must be based on one of the processing conditions stipulated in the Law.

These decisions demonstrate that personal data breaches are not limited to large-scale data leaks. Even seemingly simple everyday actions like SMS messages, shipping labels, system screens, emails, or WhatsApp posts can have serious consequences under the Turkish Personal Data Protection Law (KVKK).

Why is evidence gathering important?

One of the most important issues in allegations of unlawful data breaches is evidence. Since data breaches often occur digitally, evidence can quickly be deleted, altered, or rendered inaccessible. Therefore, the victim must secure the evidence as quickly as possible.

Screenshots should be taken, sharing links saved, emails saved, SMS and WhatsApp messages not deleted, shipping labels preserved, call logs noted, and potential witnesses identified. For social media posts, notarization, evidence gathering, or electronic evidence recording methods can be considered. Proper collection of evidence is extremely important, especially for compensation claims and criminal investigations.

It is also helpful to include evidence in the application to the data controller. For example, instead of simply saying "my personal data was shared," a more concrete application would be more effective, such as "my debt information was sent to these people via SMS from this number on this date" or "I received another person's address and phone number on this shipping label.".

Legal Risks for Companies

For companies, the unlawful sharing of personal data has serious consequences. Firstly, the Personal Data Protection Board may impose administrative fines. In addition, the company may face decisions requiring it to remedy the breach, increase data security measures, inform the relevant individuals, and improve internal processes.

Secondly, the victim can file a compensation claim. Claims for both material and moral damages may arise, particularly if the data breach results in job loss, fraud, social humiliation, or psychological harm.

Thirdly, if the data breach constitutes a crime, criminal investigations may be initiated against company employees, managers, or relevant individuals. For legal entities, security measures or industry-specific sanctions may also be considered.

Fourth, a data breach can have severe consequences for a company's reputation. Loss of customer trust, negative social media visibility, damaged business relationships, and harm to brand value often have a greater impact than a fine.

Therefore, companies should not view the GDPR compliance process as merely a text preparation activity. A personal data inventory, information texts, explicit consent processes, data processor agreements, access authorizations, employee training, log records, cybersecurity measures, and a data breach response plan should all be developed together.

In what order should the victim proceed?

The individual whose personal data has been unlawfully shared must first document the incident. It is necessary to determine which data was shared, by whom, to whom, when, and by what method. Then, a complaint should be filed with the data controller. The complaint should inquire about the legal basis for the data sharing, to whom it was transferred, what measures are being taken to remedy the breach, whether the data will be deleted, and how the damage will be compensated.

If the data controller fails to respond, provides an inadequate response, or rejects the request, a complaint should be filed with the Board. Deadlines must not be missed. The complaint should be prepared to be clear, supported by evidence, and contain legally sound requests.

If the incident constitutes a crime, a criminal complaint should be filed with the prosecutor's office. The criminal aspects should be specifically considered in cases such as the use of personal information for fraud, the dissemination of private images, the sharing of data for the purpose of threats or blackmail, unlawful access to systems, or the disclosure of health data.

If damage has occurred, a compensation lawsuit must be filed. Since filing a complaint with the Board does not replace a compensation lawsuit, the victim must separately present their material and moral damages in court.

Conclusion

The unlawful sharing of personal data is a violation with serious legal consequences for both individuals and companies. Unauthorized sharing of a person's phone number, address, debt information, health data, identity information, camera footage, or private correspondence can trigger legal proceedings such as a Personal Data Protection Law (KVKK) application, a complaint to the Board, a compensation lawsuit, and a criminal complaint to the prosecutor's office.

In such cases, the victim's most important advantage is being able to quickly document the incident and choose the correct legal course of action. Filing a complaint with the Board without first contacting the data controller may create procedural problems. However, filing a complaint with the Board does not replace a compensation lawsuit. A criminal investigation is also an independent avenue that should be considered separately.

For companies, personal data security is not a choice, but a legal obligation. The data controller must take the necessary technical and administrative measures to prevent the unlawful processing, unlawful access, and sharing of personal data with unauthorized persons. In the event of a data breach, there is an obligation to notify the Board and the relevant individuals.

In conclusion, a general approach such as simply "I will complain" or "I will seek compensation" is insufficient when personal data is shared unlawfully. Depending on the specifics of the case, a comprehensive plan should be developed, including a GDPR application, a complaint to the Board, a complaint to the prosecutor's office, a lawsuit for material and moral damages, and evidence gathering. A well-prepared application and lawsuit process can ensure the cessation of the violation, the redress of damages, and the imposition of sanctions on those responsible.

Leave a Reply

Call Now Button