Single Blog Title

This is a single blog caption

Transfer of Personal Data Abroad and Legal Requirements

Entrance

The transfer of personal data abroad is one of the most important legal issues in the digitalized business world. Today, many companies use email infrastructure, CRM systems, cloud storage services, human resources software, accounting programs, live support tools, advertising and analytics technologies, payment systems, or customer management panels through service providers based abroad. Therefore, a company located in Türkiye may be transferring personal data abroad, even unknowingly.

For example, a company's use of Google Workspace, Microsoft 365, AWS, Meta Pixel, Google Analytics, HubSpot, Salesforce, Mailchimp, Zoom, Slack, foreign hosting providers, international payment institutions, or foreign-based human resources software may raise the issue of personal data transfer abroad. Similarly, a company in Türkiye sending employee data to its parent company abroad, storing customer data on a foreign server, processing e-commerce customer order information in a foreign CRM system, or using third-party advertising cookies on its website can also be considered as data transfer abroad.

In Türkiye, the transfer of personal data abroad is regulated in Article 9 of the Law No. 6698 on the Protection of Personal Data. Law No. 7499, published in the Official Gazette on March 12, 2024, made significant changes to Article 9 of the Law, and these changes entered into force on June 1, 2024. With these changes, new appropriate safeguard methods, such as standard contracts and binding company rules, have been introduced for data transfers abroad.

Therefore, when evaluating data transfers abroad, simply stating "we obtained explicit consent" is no longer sufficient, as is often the case with old habits. Under the new system, the transfer activity must be examined in stages; first, the general data processing requirement should be assessed, followed by a decision on adequacy, appropriate assurances, or exceptions for incidental transfers.

What is the Transfer of Personal Data Abroad?

The transfer of personal data abroad refers to the transmission, accessibility, or technical processing of personal data located in Türkiye to a natural or legal person, data controller, data processor, server, cloud service provider, group company, software platform, or international organization located abroad.

Data transfer doesn't always occur through active email sending. Storing personal data on servers abroad, a foreign service provider remotely accessing data in Türkiye, transmitting user information to foreign advertising platforms via website cookies, entering customer information into foreign CRM software, or a group company abroad accessing employee data can also be considered data transfer abroad.

At this point, the approach of data controllers such as "we enter the data in Türkiye" or "we don't know where the server is located" is insufficient. The data flow of the software, cloud infrastructure, advertising technology, email service, customer management system, and payment infrastructure used must be technically examined. Because what is important from the perspective of the Personal Data Protection Law is whether the personal data is actually transferred to a recipient abroad or whether it becomes accessible from abroad.

The New Data Transfer Regime in Article 9 of the KVKK (Personal Data Protection Law)

Following the amendment to Article 9 of the Personal Data Protection Law (KVKK), a tiered regime has been adopted for the transfer of personal data abroad. According to the Personal Data Protection Authority, this system generally consists of three stages: obtaining a decision of competence regarding the country, sector, or international organization to which the data will be transferred; if a decision of competence is not available, providing one of the appropriate safeguards stipulated in the Law; and if neither of these exists, exceptional transfers can only be made in limited and incidental cases.

However, before proceeding to these three stages, there is a fundamental condition that must not be forgotten: the transfer of personal data abroad is also a personal data processing activity. Therefore, there must first be a data processing condition under Article 5 of the Personal Data Protection Law (KVKK) or, in the case of special categories of personal data, Article 6 of the KVKK. In other words, the transfer activity must be lawful not only according to Article 9, but also according to general data processing conditions.

For example, transferring an e-commerce customer's order information to a foreign cargo integration system may be necessary for the performance of the contract. Transferring an employee's salary information to the parent company abroad for reporting purposes should be evaluated separately in terms of legitimate interest or contractual obligation. If special categories of personal data such as health data, biometric data, or criminal conviction data are involved, the stricter conditions in Article 6 of the KVKK (Personal Data Protection Law) must be taken into account.

First Method: Obtaining a Decision of Eligibility

The first stage of the new regime is the adequacy decision. According to Article 9 of the Personal Data Protection Law, personal data may be transferred abroad if one of the processing conditions specified in Articles 5 and 6 of the Law is met and there is an adequacy decision regarding the country, sectors within the country, or international organization to which the data will be transferred.

The adequacy decision is a Board decision indicating that the country or sector to which the data will be transferred has an adequate level of protection for personal data. This decision provides a practical advantage for data controllers. Because if the transfer is to a country with an adequacy decision, mechanisms such as standard contracts, binding company rules, or Board approvals may not be required.

However, the Personal Data Protection Authority's page on data transfers abroad states that the Authority has not yet made a determination regarding countries where adequate protection exists. Therefore, in practice, it is currently not possible for many companies to transfer data based on a decision on adequacy; transfers mostly have to be evaluated based on appropriate safeguards or narrow exceptions.

Second Option: Appropriate Guarantees

If an adequacy decision is not available, appropriate safeguards must be provided for the transfer of personal data abroad. An appropriate safeguard is a legal mechanism that ensures the data subject can exercise their rights and access effective legal remedies in the receiving country, even if an adequacy decision is not available.

Under Article 9 of the Personal Data Protection Law (KVKK), appropriate safeguards include agreements between public institutions or international organizations that do not have the nature of international contracts, Board approval, binding company rules, standard contracts, and written undertakings containing provisions to ensure adequate protection, along with Board approval. The Authority's statements indicate that these methods are mechanisms that can be resorted to when a decision on adequacy is not available.

Appropriate assurance methods are of great importance in practice, especially for companies. This is because companies using foreign cloud services, CRM software, human resources platforms, global group companies, international payment institutions, or overseas technical support services often cannot rely on "incidental transfer" exceptions for their regular and continuous transfers. These companies need to evaluate appropriate assurance tools such as standard contracts, binding company rules, or undertakings.

Standard Contracts

One of the most practical methods of the new transfer regime is standard contracts. Standard contracts are texts published by the Personal Data Protection Board that can be used for the transfer of personal data abroad. With the Board's decision dated 04.06.2024 and numbered 2024/959, standard contract texts, binding company rules, application forms, and supporting guides were adopted and published on the Board's website.

The institution has prepared four different standard contract models: data controller-to-data controller, data controller-to-data processor, data processor-to-data processor, and data processor-to-data controller transfers. This distinction is extremely important because if the legal status of the parties to the transfer is incorrectly determined, the wrong standard contract will be used. These four contract types are also listed on the institution's standard contracts page.

For example, if an e-commerce company in Türkiye transfers customer data to a CRM provider abroad, in most cases this could be considered a transfer from a data controller to a data processor. Conversely, if a company in Türkiye transfers customer data to an independent business partner abroad for processing for its own purposes, this could be considered a transfer from one data controller to another. And if a service provider acting as a data processor transfers data to a sub-processor, this could be considered a transfer from one data processor to another.

One of the most important aspects of standard contracts is that they allow data transfer without requiring separate permission from the Board. However, signing a standard contract alone is not sufficient. According to Article 9 of the Personal Data Protection Law, the standard contract must be notified to the Authority within five business days of its signing. To facilitate this notification more quickly, the Authority has made the Standard Contract Notification Module available.

Points to Consider in Standard Contracts

One of the most common mistakes when preparing a standard contract is assuming that the obligation ends completely upon signing the contract. However, for a standard contract to be valid, it must be established, signed by the correct parties, the authority of the signatories must be documented, and it must be reported to the Institution within the specified time.

The Personal Data Protection Authority's recent announcement regarding points to be considered in standard contracts states that standard contracts must be signed by the transfer parties or by persons authorized to represent and sign on their behalf; that the contract is invalid if a valid signature is missing; that signatures must be present on the Turkish text even if concluded in a foreign language; and that documents demonstrating signing authority must be submitted to the Authority.

Therefore, companies should not view the standard contract process as merely "signing forms." It is crucial to correctly identify the transfer parties, accurately define data categories, concretize the transfer purposes, ensure technical and administrative measures reflect the actual situation, specify additional measures for special categories of data, and not miss the five-business-day notification period.

Furthermore, even if a standard contract is used, the data controller is not relieved of general GDPR obligations. The information text should be updated, the data inventory revised, foreign recipients and transfer purposes clearly stated, the data processing relationship with third-party service providers should be regulated separately, and security measures should be taken.

Binding Corporate Rules

Binding corporate rules are an important method of data transfer abroad, especially for multinational corporate groups. If there is a regular and systematic transfer of personal data between group companies operating in multiple countries, it may not be practical to create separate standard agreements for each transfer. In this case, the creation of group-wide binding corporate rules may be considered.

According to the Authority's statement, binding corporate rules are data protection rules used for the transfer of personal data abroad by multinational group companies operating in countries where adequate protection is not available, and which ensure that adequate protection is provided in writing. Companies falling within this scope must apply to the Authority by filling out the relevant form.

Binding corporate rules are a powerful compliance tool for holding companies that transfer data within groups, international companies, multinational technology companies, companies using global human resources management, and businesses managing international customer databases. However, this method is a more comprehensive process than a standard contract, as it requires preparation, internal policy, auditing, exercise of rights, accountability, a complaints mechanism, and Board approval.

Undertaking and Board Approval

One suitable safeguard method is a written undertaking containing provisions to ensure adequate protection and the approval of the Board. This method may be relevant in situations where a standard contract is unavailable or where the parties need to prepare a separate undertaking due to the specific nature of the transfer.

The Authority's statement regarding data transfer abroad indicates that, due to sectoral or regional necessities that prevent transfers via standard undertakings, transfers can only be made if the parties submit an undertaking containing their commitments regarding the protection of personal data to the Board for approval.

Because the undertaking method is subject to Board approval, it is a longer and more meticulous process compared to standard contracts. The application must clearly demonstrate the parties' powers, data categories, purpose of transfer, recipient country, technical and administrative measures, rights of the data subject, application mechanisms, and security measures. While undertakings were one of the most important tools in the old system, the introduction of standard contracts in the new regime has significantly reduced this burden in practice.

Cases of Accidental Transfer

Unless a decision of adequacy is made and one of the appropriate safeguards can be provided, the transfer of personal data abroad is only possible in exceptional and incidental circumstances. The word "incidental" is very important here. These exceptions cannot apply to regular, continuous, systematic, and repetitive data transfers.

According to the Authority's statement, incidental transfers are only possible if one of the limited circumstances listed in the Law and Regulation exists. These circumstances include: the data subject giving explicit consent after being informed of the potential risks; the transfer being necessary for the performance of the contract; the transfer being necessary for the establishment or performance of a contract to be made in the interest of the data subject; superior public interest; necessity for the establishment or protection of a right; protection of life or bodily integrity in case of factual impossibility; and transfer from a public register under certain conditions. The Authority also states that these exceptions should be interpreted narrowly.

Therefore, relying on the exception of "obtaining explicit consent from the relevant party" for foreign cloud services, CRM software, email infrastructure, advertising pixels, or human resources platforms that companies constantly use is often risky. Under the new regime, explicit consent has ceased to be a general solution, especially for regular transfers; it has become a narrow mechanism that can be used in incidental and exceptional cases, provided that the individual is informed about the potential risks.

Transfer Abroad with Explicit Consent

Explicit consent for data transfers abroad has not been completely eliminated. However, the status of explicit consent has changed under the new regime. In the previous period, companies often tried to resolve data transfers abroad with explicit consent. In the new system, explicit consent should be considered one of the limited circumstances where adequate safeguards are not available and the transfer is incidental.

For explicit consent to be valid, the data subject must be informed about the potential risks of the transfer. Furthermore, the consent must be specific, informed, and given freely. General and abstract statements such as "I consent to the transfer of my personal data abroad" are not sufficient. It should be as concrete as possible which data is being transferred, to which country, to which recipient, and for what purpose.

Making explicit consent a condition of service, especially for international transfers that are not essential for the provision of the service, may raise questions about free will. For example, if a person is denied access to a website without explicitly consenting to advertising cookies, it becomes debatable whether that consent was given freely. Therefore, the explicit consent mechanism must be carefully designed.

Analysis Companies Need to Conduct When Exporting Goods Abroad

Companies wishing to determine whether they are transferring data abroad should first create a data map and data inventory. They need to answer questions such as: What personal data is being collected, where is it stored, which service providers are being used, where are the servers located, who has access to the data, which group companies are receiving the data, which cookies are being used, and which foreign platforms are receiving the data?.

In the second stage, the status of the parties must be determined. Is the company in Türkiye a data controller or a data processor? Is the recipient abroad a data controller or a data processor? Is the transfer from a data controller to a data processor, from one data controller to another, or from a data processor to a sub-processor? This determination directly affects which standard contract will be used.

In the third stage, the continuity of the transfer should be evaluated. Is the transfer regular and systematic, or is it truly incidental? A CRM system that runs every day, a constantly running advertising cookie, or regular cloud backups cannot be considered incidental. On the other hand, sending certain documents to a court abroad in an exceptional case file, or a one-time transaction at the request of the relevant person, can be considered an incidental transfer.

In the fourth stage, an appropriate transfer mechanism should be selected. If there is no eligibility decision and the transfer is regular, the standard contract is the most practical option for most companies. In intra-group transfers within multinational groups, binding company rules may be considered. In special cases, a letter of commitment and Board approval may be required. Incidental cases should be interpreted narrowly and should not be used as a general solution for continuous transfers.

Websites, Cookies, and Data Transfer Abroad

When it comes to transferring data abroad, most companies only think of contracts or customer databases. However, cookies and third-party tools used on websites can also lead to data transfer abroad.

For example, Google Analytics, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, foreign live support software, map services, video embedding tools, or advertising networks may transmit users' IP addresses, device information, behavioral data, or cookie IDs to recipients abroad. In this case, both the obligation to obtain explicit consent and information regarding cookies and the conditions for transferring data abroad must be considered together.

Simply stating "we have a cookie policy" on a website is not enough. It is essential to technically identify which cookies are actually being used; non-essential cookies should not be activated without user consent; and if cookies are being transferred abroad, this should be stated in the cookie policy and general privacy policy. Whether a standard agreement or other appropriate safeguards are required should also be examined.

Transfer of Special Categories of Personal Data

The transfer of sensitive personal data abroad is a particularly delicate matter. Data such as health data, biometric data, genetic data, sexual information, criminal convictions and security measures, political opinions, religious beliefs, sect, and trade union membership are among the high-risk data categories.

The transfer of such data must first meet the processing requirements stipulated in Article 6 of the Personal Data Protection Law (KVKK). Following this, a decision on adequacy, appropriate assurance, or an incidental exception should be evaluated under Article 9. Standard contracts must also specify additional technical and administrative measures to be taken for special categories of personal data. The Authority's statements regarding transfers abroad indicate that standard contracts should include elements such as data categories, transfer purposes, recipients, technical and administrative measures, and additional precautions for special categories of data.

Medical tourism companies, hospitals, clinics, businesses using biometric authentication, human resources platforms, and insurance companies should be particularly careful in this regard. For example, sharing health data with doctors, intermediaries, or insurance companies abroad for the coordination of foreign patients requires a separate legal analysis.

How should the privacy policy for international data transfers be prepared?

If data is transferred abroad, this must be clearly stated in the notification to the data subject. The notification should include the identity of the data controller, the categories of data processed, the purposes of processing, the legal grounds, the recipient groups to whom the data will be transferred, the purpose of the transfer, and the rights of the data subject. If the data is transferred abroad, the recipient groups and the reason for the transfer must be specified.

For example, a general statement like "your personal data may be transferred abroad" is insufficient in most cases. Instead, more concrete statements should be used, such as "it may be transferred to a foreign-based CRM service provider for the purpose of managing customer relationship processes" or "a foreign-based cloud service provider is used to provide email communication infrastructure.".

If the data transfer is based on explicit consent, the consent text should be separate from the information text, and the data subject should be informed about the potential risks. If appropriate safeguards are used, such as standard contracts or binding company rules, the existence of this mechanism should be demonstrated in the data inventory and compliance documents.

Common Mistakes When Transferring Data Abroad

One of the most common mistakes in practice is failing to recognize that data is being transferred abroad. A company might say, "we are not sending data to anyone," but the software it uses may be running on a server located abroad. Therefore, a sound legal assessment cannot be made without examining the technical infrastructure and suppliers.

The second mistake is trying to resolve every data transfer with explicit consent. Under the new GDPR Article 9 regime, explicit consent is not a general solution for regular data transfers. For regular and systematic data transfers, standard contracts, binding company rules, or other appropriate safeguard methods should be considered.

The third mistake is choosing the wrong type of party in the standard contract. If a standard contract is signed without distinguishing between data controller and data processor, the transfer mechanism may become legally problematic. This party relationship is the reason why there are four different standard contract models.

The fourth error is the failure to notify the Institution of the standard contract within the specified timeframe. The law stipulates that the standard contract must be notified to the Institution within five business days of its signing. The Institution's Standard Contract Notification Module has been created to enable these notifications to be made electronically.

The fifth mistake is failing to update privacy policies. Companies that start using new foreign software, add advertising pixels, or begin transferring data to a foreign group company must update their privacy policies and data inventory.

Consequences of Unlawful Transfer

The unlawful transfer of personal data abroad may result in administrative sanctions under the Personal Data Protection Law (KVKK). If the data controller fails to fulfill its data security obligations and transfer conditions, it may face consequences such as investigation by the Board, administrative fines, suspension of data processing activities, disciplinary action, and damage to its reputation.

In addition, compensation claims may arise if the individuals involved have suffered harm. For example, if a customer's financial data has been transferred to an insecure system abroad and subsequently leaked, the individual may demand compensation for their material and moral damages. This risk is further increased in cases of unlawful transfer of sensitive personal data.

Furthermore, unlawful data transfer may also have criminal implications in some cases. Unlawful disclosure, dissemination, or acquisition of personal data may result in criminal liability under Article 136 of the Turkish Penal Code. Therefore, if company managers, employees, or third parties unlawfully transfer personal data to individuals or institutions abroad, the criminal risks should also be considered.

Compliance Checklist for Companies

Companies that transfer data abroad, or may transfer data abroad, should first list all their digital tools. Email provider, cloud storage, CRM, ERP, human resources system, accounting software, payment infrastructure, advertising technologies, cookies, live support tool, call center system, and group companies should be examined separately.

Then, for each transfer, the following questions should be asked: What personal data is being transferred? Who is the recipient? In which country is the recipient? Is the recipient a data controller or a data processor? Is the transfer regular or incidental? Is there a processing requirement under Article 5 or Article 6 of the KVKK (Personal Data Protection Law)? Is there an adequacy decision? Has adequate safeguard been provided? If a standard contract is required, has the correct contract type been selected? Has notification been given within five business days? Is the information text up-to-date? Is there any special category data? Are the technical and administrative measures sufficient?

It is not healthy to say "we are GDPR compliant" without conducting this analysis. Data transfer abroad should now be addressed as a separate topic in companies' GDPR compliance processes; contracts, technical infrastructure, privacy notices, cookie panel, supplier management, and data inventory should be updated together.

The Role of the Lawyer and Legal Counsel

The transfer of personal data abroad is a complex process with technical, contractual, and legal dimensions. Therefore, it is often insufficient for either the IT team or the legal team to evaluate it alone. The technical team must identify data flows, server locations, cookies, and software integrations; while the legal team must determine the legal transfer mechanism in accordance with Articles 5, 6, and 9 of the Personal Data Protection Law.

The role of a lawyer working in the field of GDPR and information technology law includes: legally reviewing the data transfer map, determining the appropriate safeguard method, selecting the standard contract type, updating the information texts, drafting data processor contracts, analyzing international transfer risks, evaluating the consent mechanism in terms of cookie and advertising technologies, and preparing for possible Board investigations.

Companies that work with foreign software providers, are multinational group companies, engage in e-commerce, process health data, use advertising technologies, or transfer sensitive data abroad must seek professional legal support regarding data transfers.

Conclusion

The transfer of personal data abroad is one of the most critical and technical aspects of GDPR compliance. The amendments to Article 9 of the GDPR by Law No. 7499 entered into force on June 1, 2024, and a new tiered system for data transfer abroad has been adopted. In this system, firstly, a valid processing condition under Article 5 or 6 of the GDPR must be met; then, a decision on adequacy, appropriate assurances, or limited incidental exceptions must be evaluated.

Due to the lack of adequacy decisions in practice, standard contracts, binding company rules, or appropriate assurance methods such as undertakings have become important for many companies. While standard contracts are a practical tool, it is essential to select the correct type of contract, have it signed by authorized persons, ensure the signatures are on the Turkish version, and notify the Authority within five business days of signing.

Explicit consent should no longer be seen as an easy, general solution for regular and continuous transfers. Explicit consent is a narrow avenue that can only be used in cases of incidental and exceptional transfers, where a decision of competence and appropriate assurance are not available, and provided that the data subject is informed of the potential risks. According to the Authority's explanations, the exceptions for incidental transfers should be interpreted narrowly and applied to irregular and infrequent transfer activities.

In conclusion, companies, websites, e-commerce platforms, healthcare organizations, technology companies, and international group companies must re-evaluate their data transfer processes abroad. Foreign software, cloud services, advertising and analytics cookies, CRM systems, human resources tools, payment infrastructures, and intra-group data flows must be examined individually. For each transfer, the recipient, country, data category, processing purpose, legal basis, transfer mechanism, and technical-administrative measures must be clearly defined.

The transfer of personal data abroad is not simply a matter of contract or consent. This process is a comprehensive legal compliance effort requiring a data inventory, technical data flow analysis, evaluation of Articles 5 and 6 of the Personal Data Protection Law (KVKK), Article 9 transfer regime, standard contractual notification, updating of the information text, cookie management, data processor relationship, and security measures. Therefore, it is of great importance for all data controllers transferring data abroad to manage the process professionally in order to prevent potential administrative sanctions, compensation claims, and reputational damage.

Leave a Reply

Call Now Button