{"id":1157,"date":"2024-12-17T16:55:42","date_gmt":"2024-12-17T13:55:42","guid":{"rendered":"https:\/\/demo.sandyapiinsaat.com.tr\/?page_id=1157"},"modified":"2024-12-17T17:02:17","modified_gmt":"2024-12-17T14:02:17","slug":"kisisel-verilerin-korunmasi-kanunu-kvkk-nedir","status":"publish","type":"page","link":"https:\/\/sandyapiinsaat.com.tr\/en\/kisisel-verilerin-korunmasi-kanunu-kvkk-nedir","title":{"rendered":"What is the Personal Data Protection Law \u2013 KVKK?"},"content":{"rendered":"<div data-elementor-type=\"wp-page\" data-elementor-id=\"1157\" class=\"elementor elementor-1157\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6a181b99 e-flex e-con-boxed e-con e-parent\" data-id=\"6a181b99\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-253e606e elementor-widget elementor-widget-text-editor\" data-id=\"253e606e\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\n<h2 class=\"wp-block-heading\">What is KVKK? What does KVKK mean?<\/h2>\n\n<p>KVKK is the abbreviation of the first letters of the Law on the Protection of Personal Data No. 6698; it entered into force with the aim of protecting the fundamental rights and freedoms of individuals, especially the right to privacy, in the processing of personal data and to regulate the procedures and principles to be followed by real and legal persons who process personal data fully or partially automatically or non-automatically, provided that it is part of any data recording system.<\/p>\n\n<p>It also refers to the abbreviations consisting of the first letters of the Personal Data Protection Authority, which is an institution established by this law, has administrative and financial autonomy and is a public legal entity, and the Personal Data Protection Board, whose powers and duties are listed in the relevant law.<\/p>\n\n<h2 class=\"wp-block-heading\">What is Personal Data? What is Special Personal Data?<\/h2>\n\n<p>Any information relating to an identified or identifiable natural person, revealing the identity of the person and specific to the person (name, surname, date of birth, home address, work address, e-mail address, IP address, telephone number, fax number, credit card information, citizenship number, tax number, passport number, social security number, driver&#039;s license number, vehicle license plate, CV, photograph, video, etc.) is considered personal data within the scope of the Personal Data Protection Law No. 6698; processing by natural or legal persons is only possible with the explicit consent of the person concerned.<\/p>\n\n<p>In addition, Article 6 of the Law on the Protection of Personal Data No. 6698 includes data on individuals&#039; race, ethnic origin, political opinion, philosophical belief, religion, sect or other belief, appearance and dress, membership in associations, foundations or unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data, which are considered special personal data and are prohibited from being processed without the explicit consent of the relevant parties.<\/p>\n\n<h2 class=\"wp-block-heading\">What is KVKK Explicit Consent? What is the Information Text?<\/h2>\n\n<p>Article 3 of the Personal Data Protection Law No. 6698, titled Definitions, defines explicit consent as consent related to a specific subject, based on information and expressed with free will; as can be understood from this definition, explicit consent must be based on information.<\/p>\n\n<p>The fact that there is no specific form requirement regarding how this information will be provided and how explicit consent will be obtained makes it possible to fulfill the obligations of Information and Explicit Consent in electronic environment with the Information Text and the acceptance button below it or through the call center, provided that the burden of proof is on the data controller.<\/p>\n\n<h2 class=\"wp-block-heading\">When Did KVKK Come into Force?<\/h2>\n\n<p>The European Union adopted the \u201cDirective of the European Parliament and of the Council of Europe on the Protection of Individuals with Regard to the Processing of Personal Data and on the Free Movement of Such Data\u201d in 1995 in order to harmonize the regulations between the member states regarding the protection of personal data. This Directive is the source of the legal regulations in the domestic laws of the member states, including Turkey, and the European Union General Data Protection Regulation (GDPR) No. 2016\/679, which was made by the European Parliament, the Council of Europe and the European Commission in 2016, entered into force in 2018 and is still the current legislation in the EU today.<\/p>\n\n<p>In our country, KVKK was prepared for the effective protection of human rights, membership negotiations with the EU and increasing international cooperation and trade, and was submitted to the Presidency of the Grand National Assembly of Turkey on 26 December 2014; it became law on 24 March 2016 and entered into force upon publication in the Official Gazette dated 7 April 2016 and numbered 29677.<\/p>\n\n<h2 class=\"wp-block-heading\">For Whom is KVKK Mandatory?<\/h2>\n\n<p>Article 2 of the Personal Data Protection Law No. 6698 outlines the scope of the law as &quot;applicable to real and legal persons who process personal data by fully or partially automatic means or non-automatic means provided that they are part of any data recording system&quot;.<\/p>\n\n<p>Processing of personal data refers to any operation performed on data, such as obtaining, recording, storing, preserving, changing, rearranging, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data; everyone, regardless of whether they are real or legal persons who perform these actions, is obliged to comply with the regulations introduced by the KVKK.<\/p>\n\n<h2 class=\"wp-block-heading\">Who is the Data Controller of KVKK? Who is the Data Processor?<\/h2>\n\n<p>According to Article 3 of the Personal Data Protection Law No. 6698, titled Definitions, the Data Controller is defined as the natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.<\/p>\n\n<p>The Data Processor is defined in the same article as a natural or legal person who processes personal data on behalf of the Data Controller based on the authority granted by the Data Controller. In order to distinguish between the two concepts, it is necessary to determine the person who will answer the questions of &quot;why&quot; and &quot;how&quot; the processing activity will be carried out.<\/p>\n\n<h2 class=\"wp-block-heading\">What needs to be done within the scope of KVKK?<\/h2>\n\n<p>Pursuant to the Law on the Protection of Personal Data No. 6698, the obligations of the Data Controller can be listed as informing the applications of the relevant persons (relevant person: the person whose personal data is processed), taking the necessary measures to ensure data security, registration in the Data Controllers Registry (VERBIS), responding to the applications of the relevant persons and deleting, destroying or anonymizing personal data ex officio or upon the request of the relevant person in case the reasons requiring processing are eliminated and fulfilling the decisions of the Personal Data Protection Board.<\/p>\n\n<h2 class=\"wp-block-heading\">What are the KVKK Penalties and Sanctions?<\/h2>\n\n<p>According to the Turkish Penal Code No. 5237, anyone who illegally records personal data shall be sentenced to imprisonment from one to three years; (depending on the nature of the data, this penalty may be increased by half) anyone who illegally obtains or distributes such data shall be sentenced to imprisonment from two to four years; anyone who acts contrary to the obligation to delete, destroy or anonymize such data shall be sentenced to imprisonment from one to two years.<\/p>\n\n<p>In addition, according to the Law on the Protection of Personal Data No. 6698, administrative fines of between 5,000 Turkish Lira and 10,000 Turkish Lira will be imposed on data controllers who fail to fulfill their obligation to inform, between 15,000 Turkish Lira and 1,000,000 Turkish Lira will be imposed on those who fail to fulfill their obligations regarding data security, and between 20,000 Turkish Lira and 1,000,000 Turkish Lira will be imposed on those who violate the obligation to register with the Data Controllers Registry.<\/p>\n\n<h2 class=\"wp-block-heading\">What are the differences between KVKK and GDPR?<\/h2>\n\n<p>Although EU legal regulations were taken as a model during the preparation of the Personal Data Protection Law No. 6698, there are some differences between the KVKK and GDPR;<\/p>\n\n<p>Under the GDPR, any company or individual who processes data, even if they are not the data controller (including third parties such as cloud service providers), is considered responsible for the lawful processing of data, whereas pursuant to Article 18\/2 of the Law on the Protection of Personal Data No. 6698, a different level of responsibility is determined for the data controller and the data processor, and the administrative fine sanction is applied only to data controllers, and the obligation to register in the data controllers&#039; registry covers only data controllers.<\/p>\n\n<p>Although the concept of the right to be forgotten, which is generally expressed as the right of individuals to control their personal data and, if possible, to delete it, was included in a legal regulation framework for the first time with the GDPR; there is no separate regulation regarding this in the Personal Data Protection Law No. 6698, and this concept is shaped by the decisions of the Supreme Court and the Constitutional Court in our country.<\/p>\n\n<p>While significant amounts of sanctions such as 200 million Euros or four percent of the service provider&#039;s global revenue are foreseen for violations of data protection rules introduced by the GDPR, it is seen that the relevant administrative fines in the Personal Data Protection Law No. 6698 are limited to relatively lower amounts (5 thousand Turkish Lira - 1 million Turkish Lira).<\/p>\n\n<p>Regulations regarding institutions such as the \u201cright to data portability\u201d regulated by the GDPR, the \u201cmandatory data protection officer\u201d for the processing of sensitive data and the \u201cmandatory data protection impact assessment\u201d for risky data processing activities are not included in the Personal Data Protection Law No. 6698.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>KVKK Nedir? KVKK Ne Demek? KVKK, 6698 say\u0131l\u0131 Ki\u015fisel Verilerin Korunmas\u0131 Kanununun ilk harflerinden olu\u015fan k\u0131saltmas\u0131 olup; ki\u015fisel verilerin i\u015flenmesinde, ba\u015fta \u00f6zel hayat\u0131n gizlili\u011fi olmak&#8230;<\/p>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-1157","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/sandyapiinsaat.com.tr\/en\/wp-json\/wp\/v2\/pages\/1157","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sandyapiinsaat.com.tr\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sandyapiinsaat.com.tr\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sandyapiinsaat.com.tr\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sandyapiinsaat.com.tr\/en\/wp-json\/wp\/v2\/comments?post=1157"}],"version-history":[{"count":4,"href":"https:\/\/sandyapiinsaat.com.tr\/en\/wp-json\/wp\/v2\/pages\/1157\/revisions"}],"predecessor-version":[{"id":1169,"href":"https:\/\/sandyapiinsaat.com.tr\/en\/wp-json\/wp\/v2\/pages\/1157\/revisions\/1169"}],"wp:attachment":[{"href":"https:\/\/sandyapiinsaat.com.tr\/en\/wp-json\/wp\/v2\/media?parent=1157"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}