The electronic certificate service provider:
a) May not request from the person requesting an electronic certificate any information other than the information necessary for issuing the electronic certificate, and may not obtain such information without the person's consent,
b) May not keep the certificate in environments accessible to third parties without the permission of the electronic certificate holder,
c) Shall prevent third parties from obtaining personal data without the written consent of the person requesting the electronic certificate. It may not transmit such information to third parties or use it for other purposes without the approval of the certificate holder.
Original Turkish text
MADDE 12 · Bilgilerin korunması
Elektronik sertifika hizmet sağlayıcısı;
a) Elektronik sertifika talep eden kişiden, elektronik sertifika vermek için gerekli bilgiler hariç bilgi talep edemez ve bu bilgileri kişinin rızası dışında elde edemez,
b) Elektronik sertifika sahibinin izni olmaksızın sertifikayı üçüncü kişilerin ulaşabileceği ortamlarda bulunduramaz,
c) Elektronik sertifika talep eden kişinin yazılı rızası olmaksızın üçüncü kişilerin kişisel verileri elde etmesini engeller. Bu bilgileri sertifika sahibinin onayı olmaksızın üçüncü kişilere iletemez ve başka amaçlarla kullanamaz.