Single Blog Title

This is a single blog caption

E-Ticket, Digital Check-in and Data Security

Entrance

The aviation sector is one of the areas most affected by digitalization processes. Today, a large portion of airline ticket purchases, check-in procedures, seat selection, and other flight-related services are carried out online or through mobile applications. In this process, e-ticket and digital check-in systems provide great convenience to passengers and also offer cost advantages and operational speed for airlines.

However, this technological transformation brings with it serious legal obligations regarding the security of personal data and the protection of passenger information . In particular, in Turkey , the Law No. 6698 on the Protection of Personal Data (KVKK) contains binding provisions for airlines regarding the processing, storage, sharing with third parties, and security of passenger information.

In this article:

  • The legal nature of e-ticket and digital check-in systems,

  • Passenger data processing processes,

  • Obligations imposed within the framework of the Turkish Personal Data Protection Law (KVKK) and the European Union's General Data Protection Regulation (GDPR),

  • Supreme Court rulings and examples from practice,

  • Passengers can seek redress in cases of data security breaches

This will be discussed in detail.


I. Legal Nature of E-Tickets

1. Definition of Electronic Ticketing

An e-ticket is an electronically issued transportation contract proving a passenger's right to fly. It is a digital document that has replaced the traditional paper ticket and produces the same legal effects.

the Montreal Convention (1999) and the regulations of the General Directorate of Civil Aviation (GDCA) , an e-ticket is a reservation record linked to the passenger's identity and is used as the basis for the passenger's acceptance on the flight.

2. Legal Validity of Electronic Tickets

According to Article 20 and subsequent articles of the Turkish Code of Obligations, transportation contracts are not subject to any specific form. Therefore, a ticket issued electronically is also considered a valid contract. In Supreme Court rulings, e-tickets are also "electronic contracts" and their probative value is accepted.


II. Digital Check-in Process and Legal Consequences

1. What is Digital Check-in?

Digital check-in is when a passenger registers for their flight by verifying their identity online or via a mobile application before the flight.

In this process, the passenger's personal data is processed as follows:

  • Identity information (name, surname, Turkish National Identity Number/passport),

  • Contact information (phone, email),

  • Reservation and flight information,

  • Seating preferences, special meal requests, health information.

2. Contractual and Legal Effects

By checking in, the passenger fulfills their obligations necessary for the performance of the transportation contract. Therefore, check-in is considered both a complementary element of the contract and the process that initiates the carrier's obligations


III. Protection of Personal Data: Passenger Data within the Framework of the Personal Data Protection Law (KVKK)

1. Nature of Passenger Data

According to Article 3 of the KVKK (Law on Protection of Personal Data), any information relating to an identified or identifiable natural person is considered personal data.

Within the scope of passenger data:

  • Identity data,

  • Contact information,

  • Location data,

  • Payment information,

  • Health information (special categories of personal data),

is being processed.

2. Data Responsibility of Airline Companies

According to Article 10 and subsequent articles of the KVKK (Turkish Personal Data Protection Law), airlines "data controllers ." In this context:

  • Obligation to inform passengers,

  • Obtaining explicit consent (especially for health data),

  • The principle of data minimization,

  • Storage time limitation,

  • Permission from the Personal Data Protection Board is required for data transfer abroad

They have obligations.


IV. Data Security Measures

1. Technical Measures

  • SSL certificate encryption,

  • Two-factor authentication,

  • Server firewalls,

  • Database encryption.

2. Administrative Measures

  • Employee confidentiality agreements,

  • Access authorization,

  • Periodic inspections,

  • Compliance with GDPR provisions in contracts with data processors.


V. GDPR and International Regulations

When processing data of European Union citizens, the GDPR provisions also apply. In this case:

  • Transparency of data processing activities,

  • The data subject's right to be forgotten,

  • The right to data portability,

  • The right to object to profiling and automated decision-making

These are obligations that airlines must comply with.


VI. Supreme Court Decisions and Practice

The Supreme Court accepts the legal validity of e-tickets and passenger information. In particular:

  • Supreme Court 11th Civil Chamber, Case No. 2017/4358 E., Decision No. 2019/2211: Regarding the probative value of electronic tickets.

  • Supreme Court 13th Civil Chamber, Case No. 2016/27855 E., Decision No. 2019/11243: Regarding the breach of personal data security in services received electronically.

These precedents establish that a data controller will be liable for damages if they share passenger information with third parties


VII. Passenger Rights in Data Breach Cases

Passengers have the following rights under Article 11 of the Personal Data Protection Law:

  • To find out whether your personal data is being processed,

  • Questioning whether it is being used for its intended purpose,

  • Requesting correction or deletion,

  • To find out whether it has been transferred abroad,

  • Claim compensation in case of damage.

VIII. Conclusion and Evaluation

E-ticketing and digital check-in systems are cornerstones of the aviation industry's digital transformation. However, protecting passenger data in these processes is not just a technical issue but also a serious ​​legal obligation .

In Turkey, Law (KVKK), and internationally, the GDPR, are fundamental pillars for the security of passenger information. Airlines must fulfill both their contractual obligations and their responsibilities under data protection law.

Passengers can both appeal to the Personal Data Protection Board through administrative channels and file a compensation lawsuit in case of a breach of their personal data.

Thus, the conveniences offered by e-ticketing and digital check-in systems can be sustained in a lawful, secure, and transparent manner, without infringing on passenger rights.

Leave a Reply

Call Now Button