Electronic Ticketing System and Protection of Personal Data within the Scope of Law No. 6222
Electronic Ticketing System and Protection of Personal Data within the Scope of Law No. 6222
Entrance
In sports law, electronic ticketing systems are no longer merely a technical application that facilitates passage through turnstiles. Especially in professional football matches, this system simultaneously generates numerous legal consequences, including ensuring security, identifying spectators, detecting banned individuals, block-based control, camera integration, and processing personal data. Therefore, electronic ticketing is not only a part of sports organization but also a special regime situated at the intersection of sports security law and personal data protection law.
Law No. 6222 on the Prevention of Violence and Disorder in Sports directly regulates the electronic card and electronic ticketing system at the legal level; it assigns authority and responsibility to clubs, federations, and some public institutions through this system. In contrast, Law No. 6698 on the Protection of Personal Data determines the limits within which identity, photograph, entry-exit, and similar data processed within the system can be used.
Therefore, the electronic ticketing system should be examined along two main axes. The first axis is ensuring security and maintaining public order in sports venues. The second axis is the lawful processing, protection, and, if necessary, correction or deletion of fans' personal data. A sound legal assessment is only possible when these two dimensions are considered together.
Legal Basis of the Electronic Ticketing System
Article 5 of Law No. 6222 stipulates that tickets for entry to spectator areas in the top football league and the league below it will be generated through an electronic system. According to the law, an electronic card containing the name, surname, Turkish Republic identity number, and photograph of the person wishing to purchase a ticket is created. For foreign nationals, instead of the Turkish Republic identity number, the name of their country of origin and the serial number of the passport used for entry into Türkiye are used.
This regulation indicates that entry to a sports venue is no longer anonymous. The legislator now wants to establish a clear identity link between the ticket holder and the spectator. This makes it easier to identify who entered the stadium, which block they were in, and, if necessary, what disciplinary or security measures they were subject to.
The electronic card system also establishes a personalized entry model. As a rule, a person can enter the match as a spectator with an electronic card issued in their name. Therefore, the system is important not only for ticket sales but also for verifying spectator identity and restricting access rights to the stadium.
The Role of Clubs and Federations in the Electronic Ticketing System
The electronic ticketing system is not merely a centralized technological infrastructure managed by the federation. Law No. 6222 places the responsibility for controlling the entry of spectators to sporting events on the host club. In non-host events, this responsibility is shared by both participating clubs. In national competitions, the responsibility lies with the relevant federation.
This provision shows that clubs are not merely passive actors organizing events. Clubs are responsible for verifying whether the electronic card actually belongs to the cardholder, whether entry to the spectator area complies with regulations, and whether prohibited individuals have infiltrated the system. Therefore, the electronic ticketing system is a direct part of the clubs' security and organizational responsibilities.
Federations are responsible for the central control and data management aspect of the system. According to the law, the authority to organize tickets and control and supervise spectator entry and exit belongs to the federations. For this purpose, a central control system is established within the federation. Thus, the electronic ticketing system operates as a hybrid model combining local club applications with central federation control.
Central Database and Electronic Card System
The electronic card system is not limited to card production alone. Law No. 6222 stipulates that personal information collected for the purpose of creating electronic cards will be stored in a central database within the federation. This database is also accessible to certain public institutions for security and auditing purposes.
This system has significant legal importance because fan information is no longer gathered in scattered club records, but in a centralized and traceable data infrastructure. This allows for much faster and more systematic processes such as identifying individuals banned from attending matches, block-based monitoring, electronic card cancellation, entry bans, or security checks.
However, this centralization also increases data protection risks. The scope, access limits, currency, and retention period of information in the central database must be managed very carefully. Otherwise, a system established for security purposes may lead to problems of unlawful data processing and interference with personal rights.
Integration of Electronic Ticketing System with Camera and Control Room
Law No. 6222 does not regulate the electronic ticketing regime separately from camera and technical surveillance systems. The law mandates the installation of necessary technical equipment to ensure security in competition and spectator areas and to identify those who violate the law. In this context, security cameras, control rooms, and technical monitoring infrastructure play a significant role in sports venues.
In professional football leagues in particular, the establishment of control rooms and the storage of camera recordings, when considered alongside electronic ticketing systems, takes on much greater significance. This is because the cardholder's identity, movement within the stadium, block information, and camera footage can be evaluated together when necessary. While this creates a robust security system, it also necessitates greater caution regarding personal data law.
What is important at this point is that the security system is operated in a measured and purposeful manner. The combination of camera system and electronic ticket data leads to the indirect monitoring of not only the moment of entry but also the movements of the fans during the match. Therefore, the obligation to provide information, data security, and the purpose of data processing become even more important.
What Personal Data is Processed in the Electronic Ticketing System?
The personal data processed within the electronic ticketing system is not limited to simple name and surname information. The system may process a wide range of data including name, surname, Turkish Republic identity number, passport information for foreigners, photograph, entry and exit data, block information, ticket purchase records, and travel ban decisions.
Some of this data is directly identifying. Others are indirect data that can reveal a person's movements in the stadium, which matches they attended, which tribune they occupied, and whether they pose a security risk. Therefore, the electronic ticketing system is not simply sales data, but a comprehensive personal data processing regime.
The key point here is that the scope of the processed data should be limited to the system's purpose. Collecting more data than is necessary to ensure security, accumulating data with the belief that it will be useful in the future, or using data for purposes other than those intended may constitute a violation of personal data protection law.
Legal Basis under the Personal Data Protection Law (KVKK)
Law No. 6222 explicitly states that information provided for the purpose of obtaining electronic cards can only be processed within the scope of activities covered by this law, and that the shared information cannot be used in a manner contrary to Law No. 6698 on the Protection of Personal Data. This provision clearly demonstrates that the electronic ticketing system is not outside the scope of personal data law.
In most cases, the legal basis for data processing here is not solely explicit consent. This is because Law No. 6222 explicitly regulates electronic card and database systems, thus providing a legal basis for data processing activities. However, the existence of a legal basis does not mean that the data controller is exempt from complying with the fundamental principles of the Personal Data Protection Law (KVKK).
Therefore, even if federations and clubs have a legal basis for data processing, they are obliged to process data for specific, clear, and legitimate purposes, to act in a manner that is relevant and proportionate to the purpose, to maintain accurate and up-to-date data, and not to store it for longer than necessary. The most critical legal balance of the electronic ticketing system is established precisely here.
Lighting Obligation and Informing the Fans
One of the most neglected obligations regarding electronic ticketing systems is providing information. Even if the processing of personal data is based on a lawful reason, the data subject, i.e., the fan, must be clearly informed about the purpose for which their data is being processed.
As part of the obligation to inform, the data controller must be identified, the types of data processed and for what purpose, with whom the data may be shared, the method and legal basis for data collection, and the data subject's rights must be clearly stated. This obligation is particularly important in electronic ticketing systems; because fans often provide data to the system for security reasons, but they are not fully aware of how this data is actually transmitted in practice.
Therefore, clubs and federations are required to provide clear, simple, and accessible information texts for electronic card applications, ticket purchases, mobile application usage, and stadium entry processes. Data processing activities carried out without this information may create legal disputes, despite the system's security purpose.
Fans' Rights Under the Personal Data Protection Law
Within the electronic ticketing system, the fan, as the data subject, is considered a data subject under the KVKK (Turkish Personal Data Protection Law) and has various rights. The fan has the right to learn whether their personal data is being processed, to request information regarding this processing if it is, to learn the purpose of the processing and whether it is being used appropriately, to know the third parties to whom their data has been transferred, to request the correction of inaccurate or incomplete data, and, if the conditions are met, to request the deletion or destruction of their data.
These rights are very concrete in the context of the electronic ticketing system. For example, a person may have been registered in the system with incorrect identity information, their photo may be outdated, an expired ban record may remain in the system, or incorrect block information may have been entered. In such cases, the relevant person can apply to the data controller to request correction or deletion.
Therefore, the fan is not a passive user in the face of the electronic ticketing system; they are an active legal subject with data rights. Making these rights available is essential for the legitimacy of the system.
Data Security Obligation
In big data processing regimes such as electronic ticketing systems, data security is a critical element of the legal framework. The data controller is obliged to take the necessary technical and administrative measures to prevent unlawful access to personal data, to prevent data from being seized by unauthorized persons, and to ensure its preservation.
In this context, the division of responsibilities between the federation, clubs, and third parties providing technical services to the system must be clearly defined. Who will have access to which data, which personnel will be authorized at what level, whether log records will be kept, and who will do what in case of a data breach must be determined in advance. Especially since the central database and e-ticket system contain a large amount of personal data, the risk arising from a security breach is also very high.
Therefore, the electronic ticketing system must not only be a sports security system, but also a robust cybersecurity and data security system. Otherwise, a structure established for physical security purposes could turn into a legal violation due to digital security vulnerabilities.
Identification of Prohibited Persons and E-Ticket System
One of the most important functions of the electronic ticketing system is to identify individuals banned from attending matches and prevent their entry to the stadium. Law No. 6222 stipulates that information regarding banned individuals will be recorded in an electronic database, and that clubs and federations will have access to this system.
This means that if a person has been banned from attending matches as a security or protective measure, the e-ticket system can technically prevent that person from entering the stadium. Thus, the security measure ceases to be merely a decision on paper and becomes practically enforceable.
However, the biggest legal risk in this area is the retention of incorrect or outdated records in the system. If a person who has been acquitted, had a decision of no prosecution issued, or whose ban has expired still appears banned in the system, it can lead to serious violations of rights. Therefore, data accuracy is one of the most critical legal requirements of the electronic ticketing system.
Commercial Use Risk and the Problem of Misuse of Data
The electronic ticketing system also carries the risk of commercial use because it creates a large dataset of fans. However, Law No. 6222, while allowing data sharing on behalf of clubs, explicitly states that this is limited only to the scope of activities covered by the law. Therefore, the unlimited use of data collected for security and match organization for unrelated commercial purposes is legally questionable.
It is certainly possible for clubs and federations to communicate with fans, provide information, or carry out certain legitimate activities. However, transforming data collected for security purposes into an excessive marketing tool, without clear legal basis and necessary data protection safeguards, cannot be considered legitimate.
Therefore, it is necessary to clarify for what purpose, on what legal grounds, and within what limits the data collected within the electronic ticketing system will be used. Otherwise, the system could transform from a legitimate infrastructure established for security purposes into a large-scale commercial data processing mechanism.
Conclusion
Under Law No. 6222, electronic ticketing systems and the protection of personal data are not two separate areas; they are two fundamental elements of the same legal framework. The electronic ticketing system is a powerful tool for ensuring security in sports venues, identifying prohibited individuals, controlling entry and exit, and maintaining public order. However, the power of this system does not mean that personal data can be processed without limit.
The legislator has explicitly stipulated that compliance with the Personal Data Protection Law (KVKK) is required simultaneously with the establishment of the electronic card and central database system. Therefore, federations and clubs are obliged to conduct their data processing activities within the principles of legal basis, proportionality, informing the public, data security, and the rights of the data subjects.
In conclusion, the electronic ticketing system can only maintain its legal legitimacy if the following balance is preserved: data necessary for security can be processed, but this data must be processed only to the extent necessary, for a specific purpose, transparently, and securely. The true legal limit and safeguard of the electronic ticketing system lies precisely here.