What we do
Calculators Legal guide Legal glossary Frequently asked questions About us Contact

Personal Data Breach: How to Complain Under Turkish Data Protection Law

What can you do when your data is processed without consent? The order of applications, time limits and compensation.

Personal Data Breach: How to Complain Under Turkish Data Protection Law — Uzun Law Office legal guide

In short: When your data is processed without your consent there is a fixed order of steps, and skipping it means the complaint is rejected. This guide covers the application to the data controller, the complaint to the Board, the time limits and compensation.

A personal data breach is the unlawful obtaining, recording, use, transfer or disclosure of information belonging to a person. Your name, telephone number, address, identity number, location data, and audio and video recordings are all personal data. Information about health, biometric data, religion, sexual life and criminal convictions counts as special-category data and is subject to much stricter protection.

Which situations are breaches? #

  • Processing data without consent or without a legal basis
  • Using a telephone number given for a purchase to send advertising messages
  • A company’s database leaking and customer information being spread
  • A CV taken in a job application being transferred to other companies not applied to
  • Footage from a site camera being shared on social media
  • Data whose erasure has been requested not being erased
  • The duty to inform not being performed at all

The order to follow: first, an application to the data controller #

A complaint cannot be made directly to the Personal Data Protection Board. It is compulsory first to apply in writing to the data controller, that is the body processing the data. The application can be made by written petition, registered electronic mail, secure electronic signature, or an e-mail address previously notified to the body.

The application must clearly set out identity details, the request and the information on which it is based. What can be requested is: to learn whether the data has been processed, to learn the purpose, to learn the third parties to whom it has been transferred, to have it corrected if processed incompletely or wrongly, to have it erased or destroyed, and to have those steps notified to the parties to whom it was transferred.

The data controller must conclude the application within thirty days at the latest. Where the process involves a further cost, the fee in the tariff can be charged; as a rule the application is free.

Complaint to the Board #

If the application is refused, if the answer given is found insufficient, or if no answer is given at all within thirty days, a complaint can be made to the Board. There are two periods and both must be met: the complaint must be made within thirty days of learning of the answer and, in any event, within sixty days of the date of the application.

The complaint is made through the Board’s online system or in writing. If the Board finds a breach, it requires the data controller to remedy the non-compliance and may impose an administrative fine. Where losses difficult to make good would arise and there is a clear non-compliance, it can also order the processing of data to be stopped.

Notification of a data leak #

When a personal data breach occurs — where a system leak happens, for instance — the data controller must notify the Board as soon as possible and within seventy-two hours at the latest. Notification must also be given to the affected individuals within the shortest reasonable time. Failure to notify is a non-compliance in itself and a ground for an administrative sanction.

Claim for compensation #

The administrative process does not make good the loss suffered. Independently of the route of complaint to the Board, a claim for pecuniary and non-pecuniary damages can be brought under the general provisions. The nature of the data, how widely it spread, the reputational loss suffered by the victim and the duration of the breach are all taken into account in setting the award.

In files where special-category data — health information or criminal convictions, for instance — has been disclosed, awards of non-pecuniary damages rise markedly. Having complained to the Board is not a condition for bringing a compensation claim; but a Board decision constitutes strong evidence in the civil case.

Situations that constitute an offence #

A personal data breach can also be an offence. The Turkish Criminal Code separately makes it an offence to record personal data unlawfully, to give it to another or to obtain it, and to fail to destroy it once the statutory period has passed. These offences do not depend on a complaint; the prosecutor opens an investigation of their own motion.

A criminal complaint can be made independently of the compensation claim and of the complaint to the Board. All three routes can be run at the same time. For the steps to follow at the investigation stage, see our guide to statements and the right of defence.

Unsolicited advertising messages #

A commercial electronic message sent without consent breaches both the data protection and the commercial communication rules. For messages of that kind, consent can be withdrawn through the message management system and a complaint can be made to the Ministry of Trade. Asking where your number was obtained from, by contrast, is the subject of a personal data application; the data controller is obliged to disclose the source of the data.

How should evidence be kept? #

The problem encountered most often in these files is proof. A screenshot on its own is weak evidence; if there is a chance the content will disappear, the securing of evidence should be sought from the court. Recording the messages received together with the date and time, keeping e-mails with their header information, and having web content certified by a notary all prove decisive at the later stage.

For the subject as a whole see our information law and data protection page, and for checking time limits our time limit and limitation checker.

What can be done against a Board decision? #

The Personal Data Protection Board examines the complaint and, if it finds a breach, directs the data controller to the way of putting it right; it may also impose an administrative fine. If the Board does not answer the complaint within sixty days, the request is treated as refused. Both that implied refusal and an express refusal are administrative acts: an action for annulment can be brought in the administrative court within sixty days of service. On the data controller’s side, an administrative fine is challenged not before the criminal judgeship of peace but, again, in the administrative court.

If you are a company: the first 72 hours after a breach #

When a data leak occurs, the data controller’s obligation runs independently of the leak itself: the position must be notified to the Board within seventy-two hours, reasonably, and to the affected individuals as soon as possible. Failure to notify gives rise to a penalty as a non-compliance separate from the breach.

What must be done within that window is, in order: isolating the affected system, preserving the log records unaltered, establishing which category of data affected how many people, completing the Board’s breach notification form and preparing the text of the notification to be sent to the individuals concerned. That these steps rest on a written response plan prepared in advance, rather than being improvised at the moment of the incident, directly affects both meeting the notification deadline and the scope of any penalty.

A widespread misconception is that every processing of data requires express consent. In fact the law lists conditions for processing other than express consent: that it is expressly provided for by law, that it relates directly to the conclusion or performance of a contract, that the data controller is meeting a legal obligation, that the data has been made public by the person concerned, that it is necessary for the establishment or protection of a right, and legitimate interest.

That has two practical consequences. First, for data that is necessary for the performance of a contract, separate consent need not be sought — and if it is sought, the consent may not meet the condition of “free will”, since withdrawing it would interrupt the service. Second, consent cannot be made a condition of the service: a consent obtained by saying “if you do not accept, we cannot provide the service” is not valid.

The distinction between commercial electronic messages and data protection #

Two separate sets of rules operate where advertising messages are sent without consent. Under the commercial communication rules, the complaint is made to the message management system and the Ministry of Trade, and an administrative fine comes into play. Under data protection, by contrast, the question is where the data was obtained from; the person concerned can apply to the data controller and ask for their data to be erased. The two routes are not alternatives to one another and can be run together.

hasanhuseyinuzun
hasanhuseyinuzun
Avukat · Uzun Avukatlık Bürosu

Frequently asked on this subject

4 questions
Can I complain directly to the data protection authority?+
No. A written application to the data controller must be made first. If that stage is skipped the complaint is rejected on procedural grounds. In general breaches such as a data leak, however, the authority may open an examination of its own motion.
Can I ask for content about me on the internet to be removed?+
Yes. You can first request erasure from the data controller, that is, the platform hosting the content. For removal from search results the search engine is approached; if it refuses, a complaint to the authority or a request to the civil court for an interim injunction blocking access comes into play.
Can my employer read my e-mails?+
An employer may monitor corporate e-mail accounts within limits; but this requires that the employee was clearly informed in advance, that the monitoring pursues a legitimate aim and that it is proportionate. Comprehensive examinations carried out without prior notice are treated as unlawful.
Will I be paid compensation as a result of my complaint?+
No. The authority imposes an administrative fine and requires the breach to be remedied; that fine is paid to the state. To recover your own loss you must additionally bring an action for pecuniary and non-pecuniary damages in the civil courts.

This article is for general information; it is not legal advice on your own case. Time limits and their application can vary with the particulars of a file. Let us talk your situation through.

All our services in IT Lawyer in Istanbul and Information Technology Law Online and banking fraud, account takeover, content removal and blocking of access, privacy of…

You have read the article — now for your own file.

General information and your own situation never match exactly. Let us assess your case specifically in a short meeting.

WhatsApp Call