Single Blog Title

This is a single blog caption

How to Apply for Personal Data Protection Law (KVKK)? Rights of Individuals Whose Personal Data Has Been Violated

Entrance

The protection of personal data is no longer just a technical compliance area concerning companies. Every individual has the right to protection regarding their personal data, including name, surname, telephone number, email address, national identity number, home address, IP address, bank information, health data, camera footage, workplace records, shopping history, debt information, social media data, and many others. If this data is processed unlawfully, shared with third parties, incorrectly recorded, stored for excessively long periods, used for unauthorized advertising purposes, or falls into the wrong hands as a result of a data breach, the data subject has legal recourse.

The Law No. 6698 on the Protection of Personal Data grants certain rights to the person whose personal data is processed, in their capacity as "data subject". The data subject can, by applying to the data controller, inquire whether their personal data is being processed, request information regarding this processing if applicable, ask about the purpose of the processing, learn to whom their data has been transferred, request the correction of inaccurate or incomplete data, request the deletion or destruction of their data if the conditions are met, and demand compensation for damages incurred due to the unlawful processing of personal data. The Personal Data Protection Authority's announcement regarding the procedural requirements for complaints explicitly lists these rights granted to the data subject in Article 11 of the Law.

Therefore, the question "How to file a GDPR violation?" is important for everyone whose personal data has been breached. However, the key point to note here is that directly filing a complaint with the Personal Data Protection Board is not always the right first step. As a rule, an application should first be made to the data controller, and the data controller's response should be awaited; if the application is rejected, the response is deemed insufficient, or no response is given within the specified time, then a complaint should be filed with the Board. The data controller is obliged to finalize the data subject's applications within a maximum of thirty days; if the response is insufficient or no response is given at all, the data subject may file a complaint with the Board within certain timeframes.

Who is the Data Subject under the KVKK (Turkish Personal Data Protection Law)?

Under the KVKK (Turkish Personal Data Protection Law), the data subject is the natural person whose personal data is being processed. A company, association, or foundation is not directly considered a data subject; however, if data belonging to a legal entity identifies or makes identifiable a natural person, then KVKK protection may apply to that natural person. For example, the name, mobile phone number, email address, or identification information in the signature circular of a company official may be considered personal data.

The term "data subject" is not limited solely to customers. An employee, former employee, job applicant, patient, student, tenant, resident, website user, e-commerce customer, debtor, creditor, witness, victim, suspect, or the opposing party in a case can also be considered a data subject. The important thing is that the person's data has been processed by a data controller.

For example, if a hospital sends a test result to the wrong person, the patient is the relevant party. If an employer shares an employee's medical report with other employees, the employee is the relevant party. If an e-commerce site sends an unsolicited promotional SMS to a customer, the customer is the relevant party. If an apartment management shares camera footage in a WhatsApp group, the person whose image was shared is the relevant party. A bank, insurance company, school, hotel, clinic, shipping company, e-commerce site, employer, or public institution may be the data controller in the specific case.

In what situations can a GDPR application be made?

A KVKK (Personal Data Protection Law) application can be made in cases where personal data has been processed unlawfully, is incomplete or inaccurate, stored unnecessarily, shared without permission, used contrary to its intended purpose, or where there has been a data processing activity that affects the rights of the individual.

For example, sending unauthorized advertising messages to a person's phone number, sharing customer information with third parties, disclosing debt information to family members or colleagues, disseminating health reports at the workplace, sharing camera footage on social media, failing to delete data even after membership closure, maintaining incorrect credit or debt records, storing job application resumes for unnecessary periods, tracking users on websites using cookies without explicit consent, or personal information falling into the wrong hands as a result of a data breach can all be grounds for a GDPR application.

The unlawful processing of personal data doesn't always manifest as a large-scale data breach. Sometimes, a single email, a single SMS message, a single camera image, a single shipping label, or even a single WhatsApp post can constitute a personal data breach. What matters is that the data identifies or makes the individual identifiable, and that this data is processed without a legal basis or in a manner contrary to its intended purpose.

Applications under the Personal Data Protection Law (KVKK) are not limited solely to requests to "delete my data." Data subjects may apply to learn which of their data is being processed, to inquire about the purpose of processing, to know who their data has been transferred to, to request the correction of inaccurate data, to request the deletion of unlawfully processed data, or to seek compensation for damages incurred.

To whom should a GDPR application be submitted?

Applications under the Personal Data Protection Law (KVKK) are primarily to the data controller . The data controller is the natural or legal person who determines the purposes and means of processing personal data. A hospital, clinic, bank, school, employer, e-commerce site, shipping company, hotel, insurance company, apartment management, association, foundation, municipality, or public institution can be a data controller.

For example, a company that sends unsolicited advertising SMS messages is the data controller. A hospital that sends a health report to the wrong person is the data controller. An employer that processes an employee's camera footage is the data controller. A company that processes user data on an e-commerce site is the data controller. Therefore, the correct data controller should be identified before submitting an application.

Submitting a complaint to the wrong person can prolong the process and lead to missing the complaint deadline. For example, if a shipping package contains address information belonging to someone else, the data controller may be the shipping company, but the sender, an e-commerce company, may also be held responsible. If the breach occurred through the employer's personnel tracking software, both the employer and the software provider should be examined in terms of their roles. Therefore, in the specific case, it is crucial to carefully consider who processed the data, for what purpose, and through which system.

How to Apply to the Data Controller?

The data subject may submit their requests under the Personal Data Protection Law (KVKK) to the data controller in writing or through other methods determined by the Board. According to the Communiqué on the Procedures and Principles for Applications to the Data Controller, applications can be made in writing, via a registered electronic mail address, secure electronic signature, mobile signature, the e-mail address previously provided by the data subject to the data controller and registered in the data controller's system, or through software or applications developed for the purpose of the application. The Board's announcement regarding the procedural requirements for complaints also explains these methods and the mandatory elements that must be included in the application.

The application must include the following information: full name, signature (if the application is in writing), Turkish Republic identity number or, for foreigners, identity/passport information, residential or business address for notification purposes, email address (if any), telephone or fax number, and the subject of the request. The subject of the request must be clear, concrete, and understandable. Instead of simply stating "I am complaining under the KVKK (Personal Data Protection Law)," it should be explained which data was violated and for what reason.

For example, a more effective explanation would be: “Your company is sending me advertising SMS messages to my registered phone number without my explicit consent. I request to be informed of the legal basis for processing my phone number, the date and method by which it was obtained, and whether I have given my consent for commercial communications; I also request that the data processing activity for advertising purposes be stopped and my phone number be removed from marketing lists.”

The application must also include supporting evidence. SMS screenshots, email printouts, call logs, shipping labels, social media posts, messages containing camera footage, incorrectly sent documents, correspondence with the data controller, or witness statements can enhance the validity of the application. Methods such as notarization, registered mail with return receipt, KEP (Registered Electronic Mail), secure electronic signature, or registered email can be used to prove the application's legitimacy.

How many days does the data controller have to respond?

The data controller is obliged to process the data subject's application as soon as possible, and no later than thirty days, depending on its nature. The application is processed free of charge; however, if the process requires additional costs, the fee specified in the tariff determined by the Board may be requested from the data subject. If the data controller accepts the request, they must take the necessary action; if they reject it, they must inform the data subject in writing or electronically, explaining the reason.

The thirty-day period is extremely important in the GDPR application process. If the data controller does not respond within this period, the data subject may file a complaint with the Board. Even if the data controller responds, if the response is insufficient, incomplete, unclear, or the request was unfairly rejected, a complaint may still be filed with the Board.

The data controller's response must be concrete. For example, general answers such as "We are acting in accordance with the KVKK (Personal Data Protection Law)" or "Your data is processed in accordance with the legislation" are often insufficient. The data controller should explain which data is being processed, for what purpose, on what legal grounds, to whom the data is transferred, and why the request was accepted or rejected.

When can a complaint be made to the Board?

In the KVKK (Personal Data Protection Law) system, complaints to the Board are generally made after exhausting the avenue of applying to the data controller. Going directly to the Board without first applying to the data controller carries the risk of the complaint being rejected on procedural grounds. The KVKK's announcement regarding the procedural requirements for complaints states that the methods for seeking redress are regulated in Articles 13 and 14 of the Law; and that the data subject must first submit their requests to the data controller.

If the data controller rejects the application, if the response is deemed inadequate, or if no response is given within the specified time, the data subject may file a complaint with the Board. The deadlines must be carefully observed. The data subject must file a complaint with the Board within thirty days of learning of the data controller's response, and in any case within sixty days of the application date.

For example, if a person submits an application to the data controller on March 1st, and the data controller responds on March 20th, and the response is inadequate, the person must file a complaint with the Board within thirty days of learning of the response. If the data controller does not respond at all, the complaint must be filed after the thirty-day response period has expired, and in any case, within a maximum period of sixty days from the date of application. Missing these deadlines can complicate the process of seeking redress.

How to File a Complaint with the Board?

Complaints to the Board can be made in writing or through the electronic complaint module provided by the Authority. The Personal Data Protection Authority's announcement clarifies that complaints can be submitted to the Board via mail, courier, or electronically through the Authority's complaint module.

The complaint should first describe the application made to the data controller and the outcome of that application. Was an application made to the data controller, on what date, what requests were made, when and how did the data controller respond, or did they not respond at all? These points are important for the Board's procedural review.

The alleged violation must then be substantiated. What personal data has been processed? How was this data obtained? For what purpose was it used? Where did the illegality occur? Has the data been transferred to third parties? What is the individual's harm or risk? Why is the data controller's response inadequate? Clear answers must be provided to all these questions.

The complaint must include the application letter submitted to the data controller, proof of receipt of the application, the data controller's response, evidence, screenshots, emails, SMS records, social media posts, shipping label, photographs, and witness information, if any. Complaints with incomplete or abstract evidence may not yield the desired result in the Board's review.

What requests can be made in a GDPR application?

The requests that can be made in a GDPR application vary depending on the specific case. The data subject may primarily want to know whether their data is being processed. This request is particularly important when the individual is unaware of what data is held by a company, hospital, employer, bank, or website.

Secondly, individuals can request information regarding the processing of their data. This may include questions about data categories, processing purpose, legal basis, retention period, data collection method, and the individuals or organizations to whom the data is transferred. Thirdly, individuals can ascertain the purpose for which their data is processed and whether it is being used in accordance with that purpose. For example, if a phone number provided for delivery is used for advertising purposes, an allegation of misuse may arise.

Fourthly, individuals may wish to know to whom their data is transferred, domestically or internationally. This request is particularly important in relation to cookies, advertising technologies, cloud service providers, outsourced companies of employers, or laboratory/insurance data sharing by healthcare organizations.

Fifthly, individuals may request the correction of incomplete or inaccurate data. For example, incorrect debt records, erroneous addresses, incorrect health information, incorrect membership information, or incorrect evaluation records must be corrected. Sixthly, individuals may request the deletion or destruction of their personal data if the conditions are met. The Regulation on the Deletion, Destruction, or Anonymization of Personal Data, within the scope of Article 7 of the Personal Data Protection Law (KVKK), regulates the procedures and principles regarding the deletion, destruction, or anonymization of data.

Seventh, the individual may request that the correction or deletion of data be notified to third parties to whom the data has been transferred. Eighth, the individual may object to the analysis of processed data exclusively through automated systems resulting in adverse consequences for them. Ninth, the individual may demand compensation for damages suffered due to the unlawful processing of their personal data. These rights are explicitly listed in Article 11 of the Law in the announcement by the Personal Data Protection Authority regarding the procedural requirements for complaints.

Is a request to delete personal data always accepted?

The right to request the deletion of personal data is an important right; however, it is not automatically granted in all cases. The data controller may partially or completely refuse a deletion request if they are still legally obligated to retain the personal data or if retention of the data is necessary for the establishment, exercise, or protection of a right. However, the refusal must be justified.

For example, an e-commerce company may be required to retain invoice records for a specific period due to tax regulations. An employer may retain certain personnel and payroll records of a former employee due to employment law and social security obligations. A hospital may keep medical records for a certain period due to health regulations and potential legal disputes. Conversely, requests to delete information such as phone numbers retained on marketing lists, profile data unnecessarily stored after membership termination, or camera footage used for unintended purposes may be more compelling.

Therefore, instead of simply stating "delete all my data" in a GDPR application, it should be explained which data needs to be deleted and for what reason. For example, a more accurate request might be: "I request that my marketing consent records and phone number, which appear to be used as the basis for sending me advertising SMS messages, be deleted from the marketing database; however, I request that my billing records, which must be kept due to legal requirements, not be used for marketing purposes.".

Is it possible to receive compensation through a GDPR application?

In a KVKK (Personal Data Protection Law) application, compensation for damages can be requested; however, the Personal Data Protection Board is not an authority that directly awards material or moral damages like a court. The Board can impose administrative sanctions on the data controller, decide on the remedy of the illegality, and request the implementation of data security measures; however, the decision to directly award compensation to an individual generally falls within the jurisdiction of the judicial system.

Individuals whose personal data has been processed unlawfully and who have suffered material or moral damages may file a compensation claim under general provisions. For example, the disclosure of health data, the reporting of debt information to the workplace, the sharing of address information for threatening purposes, the dissemination of private images, or harm to a person's credit, professional, or social life due to inaccurate data may be subject to a compensation claim.

Strategically, the Board's application and the compensation lawsuit can be planned together. A decision by the Board finding a violation can constitute strong evidence in a compensation lawsuit. However, for compensation, the damage, the unlawful act, and the causal link must also be demonstrated. Regarding moral damages, the severity of the interference with the person's private life, loss of reputation, psychological impact, humiliation in the social environment, and violation of privacy are evaluated.

Can a criminal complaint be filed with the prosecutor's office?

Some personal data breaches are not only subject to administrative appeals under the Personal Data Protection Law (KVKK), but may also constitute criminal offenses. The unlawful recording, disclosure, dissemination, or acquisition of personal data may result in criminal liability under the Turkish Penal Code. The KVKK's announcement regarding personal data breaches related to job promises also states that individuals who unlawfully record, disclose, disseminate, or acquire personal data may face imprisonment.

For example, a criminal complaint may be filed with the Public Prosecutor's Office if an identity photograph is used in a fraudulent transaction, personal data is collected for fraudulent purposes, private images are shared, health information is disclosed, address information is disseminated for threatening purposes, or data is obtained through unauthorized access to the system.

However, the Board and the prosecutor's office have different areas of authority. The Board conducts administrative investigations; accusations of crime and criminal proceedings fall within the purview of judicial authorities. The Personal Data Protection Authority (KVKK) also states in its decisions and announcements that applications concerning matters falling under the jurisdiction of judicial authorities cannot be examined by the Authority. Therefore, if the incident constitutes both a KVKK violation and a crime, the application to the data controller, the complaint to the Board, the criminal complaint, and the compensation lawsuit should be considered together.

Why is evidence gathering important?

The success of a GDPR application largely depends on the evidence. Since personal data breaches often occur in the digital environment, evidence can be quickly deleted or altered. Therefore, the person who notices the breach should secure as much evidence as possible before filing an application.

If an unauthorized SMS message is sent, a screenshot should be taken showing the sender's number and date. If an email is sent, the full email subject, sender's address, date, and content should be saved. If a social media post is shared, the link, screenshot, and date should be saved. If a WhatsApp post is shared, the message stream, sender, and shared data should be clearly visible and saved. If there is an error with the shipping label, the label and package should be photographed. If a health report or document is sent to the wrong person, the document should be kept.

In some cases, notarization, evidence gathering, or expert examination may be required. Securing evidence is particularly important for personal data published on websites, social media disclosures, or content that may be quickly deleted. Applications without evidence may remain abstract, and the data controller may deny the breach.

How should a GDPR application form be written?

The application form for a Personal Data Protection Law (KVKK) registration should be simple, concrete, and clearly state the legal requests. The application should begin with the applicant's identity and contact information. This should then specify the data controller and briefly describe the situation in chronological order.

Avoid unnecessary emotional expressions in the account, and clearly state which personal data was breached. For example, instead of saying "my personal data was breached," say "I learned that my name, surname, phone number, and debt information were sent via SMS to a third party, a colleague.".

Next, requests under Article 11 of the KVKK (Personal Data Protection Law) should be listed. These may include notification of which data is being processed, an explanation of the purpose for which the data is being processed, notification of which third parties the data is transferred to, cessation of unlawful processing, correction of inaccurate data, deletion or destruction of specific data, removal from marketing lists, notification to third parties, and compensation for any damages incurred.

The application should conclude by requesting that responses be submitted in writing or electronically, including supporting evidence, and should be dated and signed. The application method should be chosen in a verifiable manner.

Most Common Mistakes Made in Board Complaints

The most common mistake in filing a complaint with the Board is applying directly to the Board without first contacting the data controller. As a rule, the process of contacting the data controller should be exhausted first. If this step is skipped, the complaint may face procedural problems.

The second mistake is missing deadlines. After learning of the data controller's response, a complaint must be filed with the Board within thirty days, and in any case within sixty days from the date of application. Missing these deadlines weakens the right to seek redress before the Board.

The third mistake is writing the complaint in an abstract way. General statements such as "The company is violating the GDPR" are insufficient. It must specify which data, which transaction, which date, which evidence, and which request are being made.

The fourth mistake is applying solely to the Board with the expectation of compensation. The Board can impose administrative sanctions; however, lawsuits for material or moral damages may need to be filed in general courts.

The fifth mistake is that only applications related to the Personal Data Protection Law (KVKK) are made in cases involving criminal activity. In situations such as the theft, dissemination, or fraudulent use of personal data, the prosecution process should be considered separately.

Conclusion

A KVKK (Personal Data Protection Law) application is one of the most important legal avenues available to individuals whose personal data has been breached. By applying to the data controller, the data subject can inquire whether their data is being processed, request information regarding this processing if applicable, ask for the purpose of processing and to whom their data has been transferred, request the correction of inaccurate data, the deletion or destruction of unlawful data, and compensation for any damages incurred. These rights are recognized under Article 11 of the KVKK and are explicitly stated in the Authority's announcements.

The first step in the application process is, as a rule, submitting an application to the data controller. The data controller must respond to the application within a maximum of thirty days. If the application is rejected, the response is deemed insufficient, or no response is given within the specified time, the data subject may file a complaint with the Personal Data Protection Board within thirty days of learning of the data controller's response, and in any case within sixty days of the application date.

However, a KVKK (Personal Data Protection Law) application alone may not solve every problem. Depending on the nature of the specific case, a combination of methods such as a complaint to the Board, a criminal complaint to the prosecutor's office, a lawsuit for material and moral damages, removal of the content, blocking access, or evidence gathering should be considered. Especially in sensitive areas such as health data, debt information, identity data, address information, private images, bank information, or data belonging to children, acting quickly and based on evidence is of paramount importance.

In conclusion, individuals whose personal data has been breached should first document the incident, identify the correct data controller, submit a GDPR application clearly stating their requests, carefully evaluate the response, and file a complaint with the Board without missing deadlines. A well-prepared GDPR application ensures the cessation of unlawful data processing activities, the correction or deletion of data, the establishment of the data controller's responsibility, and, where necessary, a stronger enforcement of compensation or penalty procedures.

Leave a Reply

Call Now Button