Single Blog Title

This is a single blog caption

The Relationship Between Personal Data Protection Law and Information Technology Law

Entrance

Digitalization has placed personal data protection law at the heart of information technology law. Today, individuals share a large amount of personal data when registering on websites, downloading mobile applications, making e-commerce purchases, using social media accounts, conducting banking transactions, making hospital appointments, applying for jobs, or contacting companies. Examples of personal data that can be processed digitally include name, surname, phone number, email address, IP address, location information, camera footage, photographs, health data, financial information, shopping history, cookie records, and device information.

Therefore, personal data protection law and information technology law cannot be considered separately. Information technology law covers areas such as the internet, software, digital platforms, cybersecurity, e-commerce, social media, artificial intelligence, digital evidence, and cybercrimes, while personal data protection law regulates the conditions under which data processed in these areas can be collected, stored, transferred, and protected.

In Türkiye, the fundamental legal basis for the protection of personal data is Law No. 6698 on the Protection of Personal Data. The purpose of the law is to protect fundamental rights and freedoms, primarily the right to privacy, in the processing of personal data, and to regulate the obligations of natural and legal persons who process personal data. The law applies to natural persons whose personal data is processed, and to natural and legal persons who process this data automatically or non-automatically as part of a data recording system.

The importance of the Personal Data Protection Law (KVKK) in terms of information technology law stems from the fact that personal data is largely processed in digital systems. When a website tracks user behavior with cookies, a mobile application collects location information, an e-commerce site stores payment and address information, a company keeps track of employees' emails and log records, or a social media platform processes photo and message data, personal data protection law comes into play directly.

What is Personal Data?

Personal data is any information relating to an identified or identifiable natural person. This definition is extremely broad. Information does not necessarily have to include a person's name and surname to be considered personal data. Any information that directly or indirectly identifies a person can be considered personal data.

For example, Turkish national identity number, passport number, phone number, email address, IP address, customer number, vehicle license plate, bank account information, card information, photograph, voice recording, camera footage, location data, professional information, resume, signature, username, social media account, and device ID can be considered personal data. Website visitor logs, application device information, e-commerce site order history, or a company's employee entry and exit records can also contain personal data.

The broad scope of the concept of personal data is of great importance from the perspective of information systems. This is because even if a significant portion of the data collected in the digital environment doesn't directly reveal a person's identity, when combined with other data, it can make the person identifiable. Therefore, approaches such as "we only collect IP addresses," "we only use cookies," or "we only collect device information" are insufficient on their own. The entire data processing activity must be evaluated according to its purpose and scope.

What is Personal Data Protection Law?

Data protection law is the branch of law that regulates the lawful processing, storage, transfer, deletion, destruction, or anonymization of personal data. This legal field aims to protect an individual's right to privacy, data confidentiality, information security, digital identity, and personal autonomy.

According to the Turkish Personal Data Protection Law (KVKK), personal data must be processed in accordance with certain principles. These principles are: compliance with the law and rules of fairness, accuracy and timeliness when necessary, processing for specific, explicit and legitimate purposes, being relevant, limited and proportionate to the purpose for which they are processed, and retention for the period stipulated in the relevant legislation or necessary for the purpose for which they are processed.

From the perspective of information technology law, the practical application of these principles is as follows: A company should not collect unnecessary data on its website, should not store user data for unspecified purposes, should clearly disclose any tracking it uses cookies, should keep e-commerce customers' addresses and payment information in secure systems, should only allow access to employee data to authorized individuals, and should implement data destruction processes when the data retention period expires.

The Key Link Between Information Technology Law and the Personal Data Protection Law

Information technology law examines legal issues arising from the use of digital systems. The Personal Data Protection Law (KVKK) ensures the protection of personal data processed within these digital systems. Therefore, many disputes in information technology law are also personal data disputes.

For example, in the case of a social media account being hacked, not only the crime of unauthorized access to an information system but also the unlawful acquisition of personal data may come into play. If an e-commerce site's database is leaked, not only a cyberattack but also a breach of data security obligations is discussed. If a mobile application collects location data without permission, not only consumer or internet law but also the principles of explicit consent, the duty to inform, and proportionality are considered.

One of the best examples illustrating this relationship is data breaches. Hacking a company's customer database, sending employee files to the wrong people, unauthorized access to hospital records, sharing email lists with third parties, or publishing user passwords online all have consequences under both information technology law and personal data protection law.

Concepts of Data Controller and Data Processor

One of the most important concepts in the application of the KVKK (Turkish the data controller. The data controller is the natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system. The person or company that decides why and how personal data will be processed is considered the data controller.

For example, an e-commerce company is a data controller if it decides for what purpose it will process its customers' names, surnames, addresses, phone numbers, order and payment information. An employer is a data controller if it processes employees' personnel files, salary information, camera footage and entry/exit records. A hospital is a data controller if it processes patient records and health data.

A data processor is a person who processes personal data on behalf of the data controller, based on the authorization given by the data controller. For example, a cloud service provider, an email marketing company, a call center company, a software infrastructure provider, or an accounting software service provider may be considered a data processor. However, in the specific case, what is important is not the contractual roles of the parties, but who actually determines the purposes and means of data processing.

In information technology law, the distinction between data controller and data processor is of great importance, especially in software, SaaS, cloud computing, hosting, digital marketing, payment infrastructure, CRM, and call center services. This is because, in the event of a cyberattack or data breach, which party has violated which obligation is determined according to this distinction.

The Relationship Between Data Security and Cybersecurity

Data security is one of the strongest points of intersection between personal data protection law and information technology law. According to Article 12 of the Personal Data Protection Law (KVKK), the data controller is obliged to take the necessary technical and administrative measures to prevent the unlawful processing of personal data, to prevent unlawful access to data, and to ensure the preservation of data. Furthermore, the data controller may be jointly liable with the persons processing the data on their behalf for taking the necessary measures.

This provision does not only impose an obligation on companies to prepare legal texts. A disclosure statement, explicit consent form, or privacy policy alone does not guarantee compliance with the Personal Data Protection Law (KVKK). Data security requires access authorization, password policy, multi-factor authentication, log records, encryption, data masking, backup, network security, malware protection, employee training, data processor agreements, retention and destruction policy, and an incident response plan.

The Personal Data Protection Authority's Personal Data Security Guide has also been prepared to guide data controllers on technical and administrative measures. The guide includes measures that can be taken to prevent the unlawful processing of personal data and unlawful access to data, as well as to ensure the preservation of data.

At this point, IT law and cybersecurity are intertwined. For example, if a company does not implement a strong password policy, allows employees unlimited access to all customer data, does not revoke system privileges for former employees, does not encrypt data, or does not maintain log records, a data breach may result not only in technical vulnerabilities but also legal liability under the Personal Data Protection Law (KVKK).

What is a data breach?

A data breach refers to situations where personal data is obtained, lost, altered, disclosed, rendered inaccessible, or processed unlawfully by unauthorized individuals. A data breach doesn't always occur through an external hacker attack. Examples include an employee querying customer data for personal gain, sending an email to the wrong recipient, a lost USB drive, an open-access cloud folder, incorrect authorization, a ransomware attack, or leaving a database exposed to the internet.

According to the Personal Data Protection Law (KVKK), if personal data processed is obtained by others through unlawful means, the data controller is obliged to notify the data subject and the Board as soon as possible. In the Board's practice, it is accepted that notification to the Board must be made without delay and within a maximum of 72 hours from the time the data breach is learned of.

This obligation is critically important from the perspective of information technology law. This is because companies that are subjected to cyberattacks often focus on technical intervention first, delaying their legal notification obligations. However, in a data breach incident, technical analysis, legal assessment, GDPR notification, notification to relevant parties, evidence preservation, application to the prosecutor's office, and crisis communication should be carried out together.

Personal Data Crimes within the Scope of the Turkish Penal Code

The protection of personal data is not merely a matter of administrative sanctions. The Turkish Penal Code also regulates crimes against personal data. Article 135 of the TCK criminalizes the unlawful recording of personal data. Article 136 penalizes the unlawful act of giving, disseminating, or obtaining personal data to another person. Article 138 regulates the crime of failing to destroy data. Articles 135 to 140 of the TCK are particularly important in terms of personal data crimes.

In the context of cyber law, these crimes are frequently encountered in practice. For example, the unauthorized use of a person's photograph on a fake social media account, the copying of a customer list by a former employee, the disclosure of patient information to third parties, the unauthorized sharing of phone numbers for advertising purposes, the dissemination of identity information in Telegram groups, the theft of bank card information, or the sale of email addresses can be evaluated under Articles 135 and 136 of the Turkish Penal Code.

Especially in social media files, Article 134 of the Turkish Penal Code (TCK), which concerns the violation of the privacy of private life, and Article 136, which concerns the unlawful disclosure or acquisition of personal data, can be discussed together. Not every photograph or video falls within the scope of private life; however, a photograph that identifies a person may constitute personal data. Therefore, whether the incident will be evaluated under Article 134, Article 136, or both, should be determined according to the specific content.

Social Media and Personal Data

Social media is one of the areas where personal data breaches occur most frequently. Users' photos, names, locations, friend lists, messages, likes, accounts they follow, posts, and behavioral data are processed on social media platforms. Furthermore, posts users make about others may also contain the personal data of third parties.

Sharing someone's photo without permission, publishing their private correspondence, disclosing their phone number or address, creating a fake account, impersonating someone else, sharing images from a past relationship, or publishing someone's workplace information in a way that targets them can all create problems in terms of personal rights, criminal law, and the Turkish Personal Data Protection Law (KVKK).

A social media user cannot escape responsibility by simply saying, "I only shared it on my own account." The content of the post, the individual's consent, the nature of the data, the purpose of the post, the reach of the post, and its impact on the victim are all considered together. The legal risk is particularly higher for data related to sensitive areas such as private life, health information, children's data, sexual life, religious or political views.

E-commerce, Mobile Applications and GDPR

E-commerce websites and mobile applications are areas where personal data is processed extensively. Membership forms, order processing, payment processes, shipping information, customer service records, product preferences, cookies, marketing permissions, and advertising technologies can all constitute personal data processing activities.

For an e-commerce site to comply with the Turkish Personal Data Protection Law (KVKK), simply publishing a privacy policy is not enough. An information notice must be prepared, clearly stating which data is processed and for what purposes; separate consents for commercial electronic communications must be obtained; cookie preferences must be managed correctly; payment information must be processed using a secure infrastructure; membership data must be kept within reasonable limits; data processing agreements must be established with suppliers; and storage and destruction processes must be implemented.

In mobile applications, permissions such as location, camera, microphone, contacts, gallery, and device ID require particular attention. If an application accesses data that is not essential for the service it provides, the principle of proportionality may be violated. Simply displaying a permission screen to the user is not sufficient; in terms of the Personal Data Protection Law (KVKK), the information must be clear, understandable, and relevant to the purpose of data processing.

Cookies and Information Technology Law

Cookies are small data files that websites place on users' devices. Through cookies, session management, language preference, shopping cart information, performance measurement, analytical tracking, advertising targeting, and user behavior monitoring are possible. Therefore, cookies are an important topic in terms of information technology law and the Turkish Personal Data Protection Law (KVKK).

The Personal Data Protection Authority's Guide on Cookie Practices has been prepared to offer practical advice to data controllers operating websites. The guide covers the processing of personal data through cookies; it excludes cookies not used for the processing of personal data. It is stated that the guide is also valid for desktop and mobile websites or web applications.

The main distinction in cookies is between essential cookies and advertising, marketing, and behavioral tracking cookies. Essential cookies may be necessary for a site to function. However, for cookies used for advertising and marketing purposes, profiling the user, or transferring data to third parties, explicit consent and proper information are of paramount importance. The approach of "By continuing to use the site, you agree to the use of cookies" is not a valid and secure method in all cases.

Cloud Computing and Data Transfer Abroad

Cloud computing is one of the current and important areas of information law. Companies often use cloud systems based abroad for services such as email, file storage, CRM, accounting, human resources, cybersecurity, project management, and data analytics. In this case, the transfer of personal data abroad may become an issue.

The KVKK's (Turkish Personal Data Protection Law) regime for transferring personal data abroad changed significantly in 2024. The amendments to Article 9 of the KVKK, introduced by Law No. 7499, came into effect on June 1, 2024. Within the scope of these amendments, standard contracts and binding company rules are stipulated as appropriate safeguard methods that can be used for the transfer of personal data abroad.

This change is of great importance in terms of information technology law practice. Because companies using cloud services, foreign software providers, global CRM systems, overseas email infrastructures, advertising technologies, and international data centers need to review their data transfer processes. The legal basis for data transfer, the recipient, data categories, purpose of transfer, technical and administrative measures, standard contracts, or binding company rules must be clearly defined.

The Balance Between Digital Evidence and Personal Data

Digital evidence is of great importance in cyber law cases. WhatsApp conversations, email records, IP addresses, log records, camera footage, social media posts, audio recordings, screenshots, and device examinations can change the course of lawsuits. However, personal data protection rules must not be ignored when collecting digital evidence.

An employer examining an employee's computer, a company storing log records, a person presenting their WhatsApp conversations to court, a website maintaining IP addresses, or an institution sharing camera footage can all be considered personal data processing activities. Therefore, a balance must be struck between the right to obtain evidence and the right to privacy and the protection of personal data.

Digital evidence obtained illegally can create problems in both criminal and civil proceedings. For example, unauthorized access to someone else's account to obtain correspondence, secretly examining someone's phone, or copying a database without permission may not be considered lawful, even if done with the intention of obtaining evidence. Therefore, the principles of lawfulness, proportionality, and necessity must be observed in the collection of digital evidence.

GDPR and Information Technology Law Compliance Process for Companies

For companies, GDPR compliance is not a static paperwork process, but a continuous risk management process. GDPR and information technology law should be considered together, especially for technology companies, e-commerce businesses, healthcare organizations, educational institutions, financial technology companies, gaming companies, digital agencies, human resources companies, and all businesses that process data.

A healthy transition process should begin with creating a data inventory. Questions such as: What personal data is collected, for what purposes is it processed, with whom is it shared, is it transferred abroad, in which systems is it stored, for how long is it kept, who has access to it, and what legal basis is used? must be answered.

Subsequently, information texts, explicit consent processes, employee confidentiality commitments, data processor agreements, cookie policy, retention and destruction policy, information security policies, access authorization matrix, data breach response plan, and application management procedures should be prepared. For data controllers with VERBİS obligations, the registration process with the Data Controllers Registry should be evaluated separately. The Regulation on the Data Controllers Registry regulates the principles regarding the creation of the registry, which will be kept publicly accessible under the supervision of the Board, and the registration procedures.

What should a company do in case of a data breach?

When a company experiences a data breach, the first step is to technically determine the scope of the breach. Questions such as which systems were affected, which data was leaked, how many people were affected, whether the data is sensitive, whether the attack is ongoing, whether log records are protected, whether backups are secure, and whether a third-party provider was affected must be answered.

The second step is a legal assessment. It must be evaluated whether the violation requires notification under the Personal Data Protection Law (KVKK), whether the relevant individuals should be notified, what information should be submitted to the Board, whether a criminal complaint should be filed with the prosecutor's office, whether there is an obligation to notify the contracting parties, whether a press release is required, and whether an insurance notification should be made.

The third step is preserving the evidence. Logs, server records, attack traces, email headers, malware samples, user access logs, and incident response reports must be preserved. The technical team must not destroy evidence while cleaning the system. Therefore, the legal, IT, and management teams need to work together.

The Role of the Lawyer in Personal Data Protection Law

Data protection law is a specialized field with technical, administrative, and legal dimensions. Therefore, the lawyer's role is not limited to preparing information notices. The lawyer must conduct a legal analysis of data processing activities, evaluate the company's IT infrastructure in terms of data protection obligations, review data processing contracts, regulate international data transfer processes, manage the notification process in case of a data breach, and monitor Board decisions and current legislation.

An IT law attorney must also evaluate both the technical and legal aspects of cases involving cyberattacks, data leaks, employee-caused data breaches, fake accounts, social media disclosures, e-commerce data disputes, cookie complaints, explicit consent arguments, data deletion requests, the right to be forgotten, personal data crimes, and compensation claims.

Conclusion

The relationship between personal data protection law and information technology law is one of the most important legal connections of the digital age. Personal data is now largely processed, stored, transferred, and analyzed in digital systems. Therefore, websites, mobile applications, e-commerce platforms, social media accounts, cloud systems, artificial intelligence tools, CRM software, payment infrastructures, and in-house digital systems are directly related to the Personal Data Protection Law (KVKK).

The Personal Data Protection Law (KVKK) regulates the lawful processing of personal data, the protection of data subjects' rights, the obligations of data controllers, data security, and data breach notifications. Information technology law, on the other hand, establishes the legal framework for the digital environments, software, platforms, cyberattacks, electronic contracts, digital evidence, and cybercrimes in which this data is processed. Therefore, these two fields complement each other.

For companies, GDPR compliance is not just about preparing text; it's a multifaceted process encompassing data inventory, technical and administrative measures, cookie management, data processor agreements, international data transfer analysis, employee training, log management, access control, and a data breach response plan. For individuals, personal data protection law provides strong legal protection against social media disclosures, fake accounts, dissemination of personal information, data leaks, and unauthorized advertising and marketing activities.

In conclusion, personal data protection law is not merely a complementary element, but a constitutive element of information technology law. Secure commerce, secure communication, data privacy, cybersecurity, and the protection of fundamental rights in the digital world are only possible through the combined consideration of these two areas. Therefore, it is of great importance that both individuals and companies act consciously, regularly, and professionally regarding personal data protection and information technology law.

Leave a Reply

Call Now Button