Turkish Law in EnglishTÜRKİYE
Law No. 6698

Law on the Protection of Personal Data

Kişisel Verilerin Korunması Kanunu

Law No. 6698 regulates the processing of personal data in order to protect fundamental rights and freedoms, in particular privacy, and sets out the obligations of data controllers, the rights of data subjects, rules on transfers abroad and the Personal Data Protection Authority.

Chapter One: Purpose, Scope and Definitions

Article 1Purpose

Link to this article ↗

(1) The purpose of this Law is to protect the fundamental rights and freedoms of persons, in particular the right to privacy, in the processing of personal data, and to regulate the obligations of natural and legal persons who process personal data and the procedures and principles they shall comply with.

Original Turkish text

MADDE 1 · Amaç

(1) Bu Kanunun amacı, kişisel verilerin işlenmesinde başta özel hayatın gizliliği olmak üzere kişilerin temel hak ve özgürlüklerini korumak ve kişisel verileri işleyen gerçek ve tüzel kişilerin yükümlülükleri ile uyacakları usul ve esasları düzenlemektir.

(1) The provisions of this Law shall apply to natural persons whose personal data are processed and to natural and legal persons who process such data by fully or partially automated means or, provided that they form part of a data filing system, by non-automated means.

Original Turkish text

MADDE 2 · Kapsam

(1) Bu Kanun hükümleri, kişisel verileri işlenen gerçek kişiler ile bu verileri tamamen veya kısmen otomatik olan ya da herhangi bir veri kayıt sisteminin parçası olmak kaydıyla otomatik olmayan yollarla işleyen gerçek ve tüzel kişiler hakkında uygulanır.

Article 3Definitions

Link to this article ↗

(1) In the implementation of this Law:

a) Explicit consent: consent relating to a specific matter, based on information and freely given;

b) Anonymisation: rendering personal data such that they can in no way be associated with an identified or identifiable natural person, even by matching them with other data;

c) President: the President of the Personal Data Protection Authority;

ç) Data subject: the natural person whose personal data are processed;

d) Personal data: any information relating to an identified or identifiable natural person;

e) Processing of personal data: any operation performed on data, such as the obtaining, recording, storage, retention, alteration, reorganisation, disclosure, transfer, takeover, making obtainable, classification or prevention of the use of personal data, by fully or partially automated means or, provided that they form part of a data filing system, by non-automated means;

f) Board: the Personal Data Protection Board;

g) Authority: the Personal Data Protection Authority;

ğ) Data processor: the natural or legal person who processes personal data on behalf of the data controller on the basis of the authority granted by the data controller;

h) Data filing system: the filing system in which personal data are processed by being structured according to specific criteria;

ı) Data controller: the natural or legal person who determines the purposes and means of processing personal data and who is responsible for the establishment and management of the data filing system.

shall have the meanings assigned to them above.

Original Turkish text

MADDE 3 · Tanımlar

(1) Bu Kanunun uygulanmasında;

a) Açık rıza: Belirli bir konuya ilişkin, bilgilendirilmeye dayanan ve özgür iradeyle açıklanan rızayı,

b) Anonim hâle getirme: Kişisel verilerin, başka verilerle eşleştirilerek dahi hiçbir surette kimliği belirli veya belirlenebilir bir gerçek kişiyle ilişkilendirilemeyecek hâle getirilmesini,

c) Başkan: Kişisel Verileri Koruma Kurumu Başkanını,

ç) İlgili kişi: Kişisel verisi işlenen gerçek kişiyi,

d) Kişisel veri: Kimliği belirli veya belirlenebilir gerçek kişiye ilişkin her türlü bilgiyi,

e) Kişisel verilerin işlenmesi: Kişisel verilerin tamamen veya kısmen otomatik olan ya da herhangi bir veri kayıt sisteminin parçası olmak kaydıyla otomatik olmayan yollarla elde edilmesi, kaydedilmesi, depolanması, muhafaza edilmesi, değiştirilmesi, yeniden düzenlenmesi, açıklanması, aktarılması, devralınması, elde edilebilir hâle getirilmesi, sınıflandırılması ya da kullanılmasının engellenmesi gibi veriler üzerinde gerçekleştirilen her türlü işlemi,

f) Kurul: Kişisel Verileri Koruma Kurulunu,

g) Kurum: Kişisel Verileri Koruma Kurumunu,

ğ) Veri işleyen: Veri sorumlusunun verdiği yetkiye dayanarak onun adına kişisel verileri işleyen gerçek veya tüzel kişiyi,

h) Veri kayıt sistemi: Kişisel verilerin belirli kriterlere göre yapılandırılarak işlendiği kayıt sistemini,

ı) Veri sorumlusu: Kişisel verilerin işleme amaçlarını ve vasıtalarını belirleyen, veri kayıt sisteminin kurulmasından ve yönetilmesinden sorumlu olan gerçek veya tüzel kişiyi,

ifade eder.

Chapter Two: Processing of Personal Data

Article 4General principles

Link to this article ↗

(1) Personal data may be processed only in accordance with the procedures and principles laid down in this Law and in other laws.

(2) Compliance with the following principles shall be mandatory in the processing of personal data:

a) Being in conformity with the law and the rules of good faith.

b) Being accurate and, where necessary, kept up to date.

c) Being processed for specified, explicit and legitimate purposes.

ç) Being relevant, limited and proportionate to the purposes for which they are processed.

d) Being retained for the period laid down in the relevant legislation or for the period necessary for the purpose for which they are processed.

Original Turkish text

MADDE 4 · Genel ilkeler

(1) Kişisel veriler, ancak bu Kanunda ve diğer kanunlarda öngörülen usul ve esaslara uygun olarak işlenebilir.

(2) Kişisel verilerin işlenmesinde aşağıdaki ilkelere uyulması zorunludur:

a) Hukuka ve dürüstlük kurallarına uygun olma.

b) Doğru ve gerektiğinde güncel olma.

c) Belirli, açık ve meşru amaçlar için işlenme.

ç) İşlendikleri amaçla bağlantılı, sınırlı ve ölçülü olma.

d) İlgili mevzuatta öngörülen veya işlendikleri amaç için gerekli olan süre kadar muhafaza edilme.

Article 5Conditions for processing personal data

Link to this article ↗

(1) Personal data shall not be processed without the explicit consent of the data subject.

(2) Personal data of the data subject may be processed without seeking his or her explicit consent where one of the following conditions exists:

a) It is expressly provided for by law.

b) It is necessary for the protection of the life or bodily integrity of the person himself or herself or of another person, where the person is unable to express consent due to actual impossibility or where his or her consent is not deemed legally valid.

c) Processing of personal data belonging to the parties to a contract is necessary, provided that it is directly related to the conclusion or performance of that contract.

ç) It is necessary for the data controller to fulfil its legal obligation.

d) The data have been made public by the data subject himself or herself.

e) Data processing is necessary for the establishment, exercise or protection of a right.

f) Data processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.

Original Turkish text

MADDE 5 · Kişisel verilerin işlenme şartları

(1) Kişisel veriler ilgili kişinin açık rızası olmaksızın işlenemez.

(2) Aşağıdaki şartlardan birinin varlığı hâlinde, ilgili kişinin açık rızası aranmaksızın kişisel verilerinin işlenmesi mümkündür:

a) Kanunlarda açıkça öngörülmesi.

b) Fiili imkânsızlık nedeniyle rızasını açıklayamayacak durumda bulunan veya rızasına hukuki geçerlilik tanınmayan kişinin kendisinin ya da bir başkasının hayatı veya beden bütünlüğünün korunması için zorunlu olması.

c) Bir sözleşmenin kurulması veya ifasıyla doğrudan doğruya ilgili olması kaydıyla, sözleşmenin taraflarına ait kişisel verilerin işlenmesinin gerekli olması.

ç) Veri sorumlusunun hukuki yükümlülüğünü yerine getirebilmesi için zorunlu olması.

d) İlgili kişinin kendisi tarafından alenileştirilmiş olması.

e) Bir hakkın tesisi, kullanılması veya korunması için veri işlemenin zorunlu olması.

f) İlgili kişinin temel hak ve özgürlüklerine zarar vermemek kaydıyla, veri sorumlusunun meşru menfaatleri için veri işlenmesinin zorunlu olması.

Article 6Conditions for processing special categories of personal data

Link to this article ↗

(1) Data relating to the race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures of persons, as well as biometric and genetic data, are special categories of personal data.

(2) Repealed: 2/3/2024, Law No. 7499, Art. 33

(3) Amended: 2/3/2024, Law No. 7499, Art. 33 The processing of special categories of personal data is prohibited. However, the processing of such data shall be permitted in the following cases:

a) The data subject has given explicit consent,

b) It is expressly provided for by law,

c) It is necessary for the protection of the life or bodily integrity of the person himself or herself or of another person, where the person is unable to express consent due to actual impossibility or where his or her consent is not deemed legally valid,

ç) It relates to personal data made public by the data subject and is in accordance with the data subject's intention to make them public,

d) It is necessary for the establishment, exercise or protection of a right,

e) It is necessary, by persons under an obligation of confidentiality or by authorised institutions and organisations, for the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning, management and financing of health services,

f) It is necessary for the fulfilment of legal obligations in the fields of employment, occupational health and safety, social security, social services and social assistance,

g) It concerns current or former members and affiliates of foundations, associations and other non-profit organisations or bodies established for political, philosophical, religious or trade union purposes, or persons who are in regular contact with such organisations and bodies, provided that it is in accordance with the legislation to which they are subject and their purposes, is limited to their fields of activity and is not disclosed to third parties.

where any of the above applies.

(4) In the processing of special categories of personal data, it is further required that adequate measures determined by the Board be taken.

Original Turkish text

MADDE 6 · Özel nitelikli kişisel verilerin işlenme şartları

(1) Kişilerin ırkı, etnik kökeni, siyasi düşüncesi, felsefi inancı, dini, mezhebi veya diğer inançları, kılık ve kıyafeti, dernek, vakıf ya da sendika üyeliği, sağlığı, cinsel hayatı, ceza mahkûmiyeti ve güvenlik tedbirleriyle ilgili verileri ile biyometrik ve genetik verileri özel nitelikli kişisel veridir.

(2) (Mülga:2/3/2024-7499/33 md.)

(3) (Değişik:2/3/2024-7499/33 md.) Özel nitelikli kişisel verilerin işlenmesi yasaktır. Ancak bu verilerin işlenmesi;

a) İlgili kişinin açık rızasının olması,

b) Kanunlarda açıkça öngörülmesi,

c) Fiili imkânsızlık nedeniyle rızasını açıklayamayacak durumda bulunan veya rızasına hukuki geçerlilik tanınmayan kişinin, kendisinin ya da bir başkasının hayatı veya beden bütünlüğünün korunması için zorunlu olması,

ç) İlgili kişinin alenileştirdiği kişisel verilere ilişkin ve alenileştirme iradesine uygun olması,

d) Bir hakkın tesisi, kullanılması veya korunması için zorunlu olması,

e) Sır saklama yükümlülüğü altında bulunan kişiler veya yetkili kurum ve kuruluşlarca, kamu sağlığının korunması, koruyucu hekimlik, tıbbi teşhis, tedavi ve bakım hizmetlerinin yürütülmesi ile sağlık hizmetlerinin planlanması, yönetimi ve finansmanı amacıyla gerekli olması,

f) İstihdam, iş sağlığı ve güvenliği, sosyal güvenlik, sosyal hizmetler ve sosyal yardım alanlarındaki hukuki yükümlülüklerin yerine getirilmesi için zorunlu olması,

g) Siyasi, felsefi, dini veya sendikal amaçlarla kurulan vakıf, dernek ve diğer kâr amacı gütmeyen kuruluş ya da oluşumların, tâbi oldukları mevzuata ve amaçlarına uygun olmak, faaliyet alanlarıyla sınırlı olmak ve üçüncü kişilere açıklanmamak kaydıyla; mevcut veya eski üyelerine ve mensuplarına veyahut bu kuruluş ve oluşumlarla düzenli olarak temasta olan kişilere yönelik olması,

halinde mümkündür.

(4) Özel nitelikli kişisel verilerin işlenmesinde, ayrıca Kurul tarafından belirlenen yeterli önlemlerin alınması şarttır.

Article 7Erasure, destruction or anonymisation of personal data

Link to this article ↗

(1) Notwithstanding that they have been processed in accordance with the provisions of this Law and other relevant laws, personal data shall be erased, destroyed or anonymised by the data controller, ex officio or upon the request of the data subject, where the reasons requiring their processing cease to exist.

(2) The provisions of other laws relating to the erasure, destruction or anonymisation of personal data are reserved.

(3) The procedures and principles relating to the erasure, destruction or anonymisation of personal data shall be regulated by regulation.

Original Turkish text

MADDE 7 · Kişisel verilerin silinmesi, yok edilmesi veya anonim hâle getirilmesi

(1) Bu Kanun ve ilgili diğer kanun hükümlerine uygun olarak işlenmiş olmasına rağmen, işlenmesini gerektiren sebeplerin ortadan kalkması hâlinde kişisel veriler resen veya ilgili kişinin talebi üzerine veri sorumlusu tarafından silinir, yok edilir veya anonim hâle getirilir.

(2) Kişisel verilerin silinmesi, yok edilmesi veya anonim hâle getirilmesine ilişkin diğer kanunlarda yer alan hükümler saklıdır.

(3) Kişisel verilerin silinmesine, yok edilmesine veya anonim hâle getirilmesine ilişkin usul ve esaslar yönetmelikle düzenlenir.

Article 8Transfer of personal data

Link to this article ↗

(1) Personal data shall not be transferred without the explicit consent of the data subject.

(2) Personal data may be transferred without seeking the explicit consent of the data subject where one of the conditions set out

a) in paragraph 2 of Article 5, or

b) provided that adequate measures are taken, in paragraph 3 of Article 6,

exists.

(3) The provisions of other laws relating to the transfer of personal data are reserved.

Original Turkish text

MADDE 8 · Kişisel verilerin aktarılması

(1) Kişisel veriler, ilgili kişinin açık rızası olmaksızın aktarılamaz.

(2) Kişisel veriler;

a) 5 inci maddenin ikinci fıkrasında,

b) Yeterli önlemler alınmak kaydıyla, 6 ncı maddenin üçüncü fıkrasında,

belirtilen şartlardan birinin bulunması hâlinde, ilgili kişinin açık rızası aranmaksızın aktarılabilir.

(3) Kişisel verilerin aktarılmasına ilişkin diğer kanunlarda yer alan hükümler saklıdır.

Article 9Transfer of personal data abroad

Link to this article ↗

Amended: 2/3/2024, Law No. 7499, Art. 34

(1) Personal data may be transferred abroad by data controllers and data processors where one of the conditions set out in Articles 5 and 6 exists and there is an adequacy decision concerning the country, sectors within the country or international organisations to which the transfer is to be made.

(2) The adequacy decision shall be issued by the Board and published in the Official Gazette. The Board shall obtain the opinion of the relevant institutions and organisations where it deems necessary. The adequacy decision shall be reviewed at least once every four years. As a result of the review or in other cases it deems necessary, the Board may amend, suspend or revoke the adequacy decision with prospective effect.

(3) In issuing an adequacy decision, the following matters shall primarily be taken into account:

a) Reciprocity regarding the transfer of personal data between Türkiye and the country, sectors within the country or international organisations to which the personal data are to be transferred.

b) The relevant legislation and practice of the country to which the personal data are to be transferred, and the rules to which the international organisation to which the personal data are to be transferred is subject.

c) The existence of an independent and effective data protection authority in the country to which the personal data are to be transferred or to which the international organisation is subject, and the availability of administrative and judicial remedies.

ç) Whether the country or international organisation to which the personal data are to be transferred is a party to international conventions or a member of international organisations relating to the protection of personal data.

d) Whether the country or international organisation to which the personal data are to be transferred is a member of global or regional organisations of which Türkiye is a member.

e) International conventions to which Türkiye is a party.

(4) In the absence of an adequacy decision, personal data may be transferred abroad by data controllers and data processors where one of the conditions set out in Articles 5 and 6 exists, provided that the data subject also has the opportunity to exercise his or her rights and to seek effective legal remedies in the country to which the transfer is to be made, if one of the following appropriate safeguards is provided by the parties:

a) The existence of an agreement, not having the nature of an international convention, between public institutions and organisations or international organisations abroad and public institutions and organisations or professional organisations having the nature of public institutions in Türkiye, and authorisation of the transfer by the Board.

b) The existence of binding corporate rules, approved by the Board, containing provisions on the protection of personal data, with which companies within a group of undertakings engaged in a joint economic activity are obliged to comply.

c) The existence of a standard contract announced by the Board, containing matters such as data categories, purposes of the data transfer, recipients and groups of recipients, technical and administrative measures to be taken by the data recipient, and additional measures taken for special categories of personal data.

ç) The existence of a written undertaking containing provisions that will ensure adequate protection, and authorisation of the transfer by the Board.

(5) The standard contract shall be notified to the Authority by the data controller or the data processor within five business days of its signature.

(6) In the absence of an adequacy decision and where none of the appropriate safeguards provided for in paragraph 4 can be provided, data controllers and data processors may transfer personal data abroad, on an incidental basis only, solely where one of the following cases exists:

a) The data subject gives explicit consent to the transfer, provided that he or she has been informed of the possible risks.

b) The transfer is necessary for the performance of a contract between the data subject and the data controller or for the implementation of pre-contractual measures taken at the request of the data subject.

c) The transfer is necessary for the conclusion or performance of a contract to be concluded between the data controller and another natural or legal person for the benefit of the data subject.

ç) The transfer is necessary for an overriding public interest.

d) The transfer of personal data is necessary for the establishment, exercise or protection of a right.

e) The transfer of personal data is necessary for the protection of the life or bodily integrity of the person himself or herself or of another person, where the person is unable to express consent due to actual impossibility or where his or her consent is not deemed legally valid.

f) The transfer is made from a register open to the public or to persons having a legitimate interest, provided that the conditions required by the relevant legislation for access to the register are met and the person having a legitimate interest so requests.

(7) Subparagraphs (a), (b) and (c) of paragraph 6 shall not apply to the activities of public institutions and organisations that are subject to public law.

(8) With regard to onward transfers of personal data transferred abroad and to transfers to international organisations, data controllers and data processors shall also ensure the safeguards set out in this Law, and the provisions of this Article shall apply.

(9) Without prejudice to the provisions of international conventions, in cases where the interests of Türkiye or of the data subject would be seriously harmed, personal data may be transferred abroad only with the permission of the Board, after obtaining the opinion of the relevant public institution or organisation.

(10) The provisions of other laws relating to the transfer of personal data abroad are reserved.

(11) The procedures and principles relating to the implementation of this Article shall be regulated by regulation.

Original Turkish text

MADDE 9 · Kişisel verilerin yurt dışına aktarılması

(Değişik:2/3/2024-7499/34 md.)

(1) Kişisel veriler, 5 inci ve 6 ncı maddelerde belirtilen şartlardan birinin varlığı ve aktarımın yapılacağı ülke, ülke içerisindeki sektörler veya uluslararası kuruluşlar hakkında yeterlilik kararı bulunması halinde, veri sorumluları ve veri işleyenler tarafından yurt dışına aktarılabilir.

(2) Yeterlilik kararı, Kurul tarafından verilir ve Resmî Gazete’de yayımlanır. Kurul, ihtiyaç duyması halinde ilgili kurum ve kuruluşların görüşünü alır. Yeterlilik kararı, en geç dört yılda bir değerlendirilir. Kurul, değerlendirme sonucunda veya gerekli gördüğü diğer hallerde, yeterlilik kararını ileriye etkili olmak üzere değiştirebilir, askıya alabilir veya kaldırabilir.

(3) Yeterlilik kararı verilirken öncelikle aşağıdaki hususlar dikkate alınır:

a) Kişisel verilerin aktarılacağı ülke, ülke içerisindeki sektörler veya uluslararası kuruluşlar ile Türkiye arasında kişisel veri aktarımına ilişkin karşılıklılık durumu.

b) Kişisel verilerin aktarılacağı ülkenin ilgili mevzuatı ve uygulaması ile kişisel verilerin aktarılacağı uluslararası kuruluşun tâbi olduğu kurallar.

c) Kişisel verilerin aktarılacağı ülkede veya uluslararası kuruluşun tâbi olduğu bağımsız ve etkin bir veri koruma kurumunun varlığı ile idari ve adli başvuru yollarının bulunması.

ç) Kişisel verilerin aktarılacağı ülkenin veya uluslararası kuruluşun, kişisel verilerin korunmasıyla ilgili uluslararası sözleşmelere taraf veya uluslararası kuruluşlara üye olma durumu.

d) Kişisel verilerin aktarılacağı ülkenin veya uluslararası kuruluşun, Türkiye’nin üye olduğu küresel veya bölgesel kuruluşlara üye olma durumu.

e) Türkiye’nin taraf olduğu uluslararası sözleşmeler.

(4) Kişisel veriler, yeterlilik kararının bulunmaması durumunda, 5 inci ve 6 ncı maddelerde belirtilen şartlardan birinin varlığı, ilgili kişinin aktarımın yapılacağı ülkede de haklarını kullanma ve etkili kanun yollarına başvurma imkânının bulunması kaydıyla, aşağıda belirtilen uygun güvencelerden birinin taraflarca sağlanması halinde veri sorumluları ve veri işleyenler tarafından yurt dışına aktarılabilir:

a) Yurt dışındaki kamu kurum ve kuruluşları veya uluslararası kuruluşlar ile Türkiye’deki kamu kurum ve kuruluşları veya kamu kurumu niteliğindeki meslek kuruluşları arasında yapılan uluslararası sözleşme niteliğinde olmayan anlaşmanın varlığı ve Kurul tarafından aktarıma izin verilmesi.

b) Ortak ekonomik faaliyette bulunan teşebbüs grubu bünyesindeki şirketlerin uymakla yükümlü oldukları, kişisel verilerin korunmasına ilişkin hükümler ihtiva eden ve Kurul tarafından onaylanan bağlayıcı şirket kurallarının varlığı.

c) Kurul tarafından ilan edilen, veri kategorileri, veri aktarımının amaçları, alıcı ve alıcı grupları, veri alıcısı tarafından alınacak teknik ve idari tedbirler, özel nitelikli kişisel veriler için alınan ek önlemler gibi hususları ihtiva eden standart sözleşmenin varlığı.

ç) Yeterli korumayı sağlayacak hükümlerin yer aldığı yazılı bir taahhütnamenin varlığı ve Kurul tarafından aktarıma izin verilmesi.

(5) Standart sözleşme, imzalanmasından itibaren beş iş günü içinde veri sorumlusu veya veri işleyen tarafından Kuruma bildirilir.

(6) Veri sorumluları ve veri işleyenler, yeterlilik kararının bulunmaması ve dördüncü fıkrada öngörülen uygun güvencelerden herhangi birinin sağlanamaması durumunda, arızi olmak kaydıyla sadece aşağıdaki hallerden birinin varlığı halinde yurt dışına kişisel veri aktarabilir:

a) İlgili kişinin, muhtemel riskler hakkında bilgilendirilmesi kaydıyla, aktarıma açık rıza vermesi.

b) Aktarımın, ilgili kişi ile veri sorumlusu arasındaki bir sözleşmenin ifası veya ilgili kişinin talebi üzerine alınan sözleşme öncesi tedbirlerin uygulanması için zorunlu olması.

c) Aktarımın, ilgili kişi yararına veri sorumlusu ve diğer bir gerçek veya tüzel kişi arasında yapılacak bir sözleşmenin kurulması veya ifası için zorunlu olması.

ç) Aktarımın üstün bir kamu yararı için zorunlu olması.

d) Bir hakkın tesisi, kullanılması veya korunması için kişisel verilerin aktarılmasının zorunlu olması.

e) Fiili imkânsızlık nedeniyle rızasını açıklayamayacak durumda bulunan veya rızasına hukuki geçerlilik tanınmayan kişinin kendisinin ya da bir başkasının hayatı veya beden bütünlüğünün korunması için kişisel verilerin aktarılmasının zorunlu olması.

f) Kamuya veya meşru menfaati bulunan kişilere açık olan bir sicilden, ilgili mevzuatta sicile erişmek için gereken şartların sağlanması ve meşru menfaati olan kişinin talep etmesi kaydıyla aktarım yapılması.

(7) Altıncı fıkranın (a), (b) ve (c) bentleri, kamu kurum ve kuruluşlarının kamu hukukuna tâbi faaliyetlerine uygulanmaz.

(8) Veri sorumlusu ve veri işleyenler tarafından, yurt dışına aktarılan kişisel verilerin sonraki aktarımları ve uluslararası kuruluşlara aktarımlar bakımından da bu Kanunda yer alan güvenceler sağlanır ve bu madde hükümleri uygulanır.

(9) Kişisel veriler, uluslararası sözleşme hükümleri saklı kalmak üzere, Türkiye’nin veya ilgili kişinin menfaatinin ciddi bir şekilde zarar göreceği durumlarda, ancak ilgili kamu kurum veya kuruluşunun görüşü alınarak Kurulun izniyle yurt dışına aktarılabilir.

(10) Kişisel verilerin yurt dışına aktarılmasına ilişkin diğer kanunlarda yer alan hükümler saklıdır.

(11) Bu maddenin uygulanmasına ilişkin usul ve esaslar yönetmelikle düzenlenir.

Chapter Three: Rights and Obligations

Article 10Data controller's obligation to inform

Link to this article ↗

(1) While obtaining personal data, the data controller or the person authorised by it shall, with respect to data subjects, provide information on:

a) The identity of the data controller and of its representative, if any,

b) The purpose for which the personal data will be processed,

c) To whom and for what purpose the processed personal data may be transferred,

ç) The method and legal basis of the collection of personal data,

d) The other rights listed in Article 11.

and shall be obliged to do so.

Original Turkish text

MADDE 10 · Veri sorumlusunun aydınlatma yükümlülüğü

(1) Kişisel verilerin elde edilmesi sırasında veri sorumlusu veya yetkilendirdiği kişi, ilgili kişilere;

a) Veri sorumlusunun ve varsa temsilcisinin kimliği,

b) Kişisel verilerin hangi amaçla işleneceği,

c) İşlenen kişisel verilerin kimlere ve hangi amaçla aktarılabileceği,

ç) Kişisel veri toplamanın yöntemi ve hukuki sebebi,

d) 11 inci maddede sayılan diğer hakları,

konusunda bilgi vermekle yükümlüdür.

Article 11Rights of the data subject

Link to this article ↗

(1) Everyone, by applying to the data controller, with respect to himself or herself, has the rights to:

a) Learn whether personal data are being processed,

b) Request information in this regard if personal data have been processed,

c) Learn the purpose of the processing of personal data and whether they are used in accordance with their purpose,

ç) Know the third parties, in the country or abroad, to whom personal data have been transferred,

d) Request rectification of personal data if they have been processed incompletely or inaccurately,

e) Request erasure or destruction of personal data within the framework of the conditions set out in Article 7,

f) Request that the operations carried out pursuant to subparagraphs (d) and (e) be notified to the third parties to whom the personal data have been transferred,

g) Object to the emergence of a result to the detriment of the person himself or herself by means of the analysis of the processed data exclusively through automated systems,

ğ) Claim compensation for damage if he or she suffers damage due to the unlawful processing of personal data.

as set out above.

Original Turkish text

MADDE 11 · İlgili kişinin hakları

(1) Herkes, veri sorumlusuna başvurarak kendisiyle ilgili;

a) Kişisel veri işlenip işlenmediğini öğrenme,

b) Kişisel verileri işlenmişse buna ilişkin bilgi talep etme,

c) Kişisel verilerin işlenme amacını ve bunların amacına uygun kullanılıp kullanılmadığını öğrenme,

ç) Yurt içinde veya yurt dışında kişisel verilerin aktarıldığı üçüncü kişileri bilme,

d) Kişisel verilerin eksik veya yanlış işlenmiş olması hâlinde bunların düzeltilmesini isteme,

e) 7 nci maddede öngörülen şartlar çerçevesinde kişisel verilerin silinmesini veya yok edilmesini isteme,

f) (d) ve (e) bentleri uyarınca yapılan işlemlerin, kişisel verilerin aktarıldığı üçüncü kişilere bildirilmesini isteme,

g) İşlenen verilerin münhasıran otomatik sistemler vasıtasıyla analiz edilmesi suretiyle kişinin kendisi aleyhine bir sonucun ortaya çıkmasına itiraz etme,

ğ) Kişisel verilerin kanuna aykırı olarak işlenmesi sebebiyle zarara uğraması hâlinde zararın giderilmesini talep etme,

haklarına sahiptir.

Article 12Obligations relating to data security

Link to this article ↗

(1) The data controller shall, in order to:

a) Prevent the unlawful processing of personal data,

b) Prevent unlawful access to personal data,

c) Ensure the retention of personal data,

be obliged to take all necessary technical and administrative measures to ensure an appropriate level of security.

(2) Where personal data are processed by another natural or legal person on behalf of the data controller, the data controller shall be jointly liable with such persons for taking the measures specified in paragraph 1.

(3) The data controller shall be obliged to carry out, or have carried out, the necessary audits within its own institution or organisation in order to ensure the implementation of the provisions of this Law.

(4) Data controllers and data processors shall not disclose personal data that they have learned to others in breach of the provisions of this Law, nor use such data for purposes other than processing. This obligation shall continue after they leave office.

(5) Where processed personal data are obtained by others by unlawful means, the data controller shall notify the data subject and the Board of this situation as soon as possible. The Board may, where necessary, announce this situation on its own website or by any other method it deems appropriate.

Original Turkish text

MADDE 12 · Veri güvenliğine ilişkin yükümlülükler

(1) Veri sorumlusu;

a) Kişisel verilerin hukuka aykırı olarak işlenmesini önlemek,

b) Kişisel verilere hukuka aykırı olarak erişilmesini önlemek,

c) Kişisel verilerin muhafazasını sağlamak,

amacıyla uygun güvenlik düzeyini temin etmeye yönelik gerekli her türlü teknik ve idari tedbirleri almak zorundadır.

(2) Veri sorumlusu, kişisel verilerin kendi adına başka bir gerçek veya tüzel kişi tarafından işlenmesi hâlinde, birinci fıkrada belirtilen tedbirlerin alınması hususunda bu kişilerle birlikte müştereken sorumludur.

(3) Veri sorumlusu, kendi kurum veya kuruluşunda, bu Kanun hükümlerinin uygulanmasını sağlamak amacıyla gerekli denetimleri yapmak veya yaptırmak zorundadır.

(4) Veri sorumluları ile veri işleyen kişiler, öğrendikleri kişisel verileri bu Kanun hükümlerine aykırı olarak başkasına açıklayamaz ve işleme amacı dışında kullanamazlar. Bu yükümlülük görevden ayrılmalarından sonra da devam eder.

(5) İşlenen kişisel verilerin kanuni olmayan yollarla başkaları tarafından elde edilmesi hâlinde, veri sorumlusu bu durumu en kısa sürede ilgilisine ve Kurula bildirir. Kurul, gerekmesi hâlinde bu durumu, kendi internet sitesinde ya da uygun göreceği başka bir yöntemle ilan edebilir.

Chapter Four: Application, Complaint and Data Controllers Registry

Article 13Application to the data controller

Link to this article ↗

(1) The data subject shall submit his or her requests concerning the implementation of this Law to the data controller in writing or by other methods to be determined by the Board.

(2) The data controller shall conclude the requests contained in the application free of charge as soon as possible, depending on the nature of the request, and within thirty days at the latest. However, where the operation additionally entails a cost, the fee set out in the tariff determined by the Board may be charged.

(3) The data controller shall accept the request or reject it by stating its reasons, and shall notify its response to the data subject in writing or electronically. Where the request contained in the application is accepted, the data controller shall take the necessary action. Where the application arises from an error of the data controller, the fee charged shall be refunded to the data subject.

Original Turkish text

MADDE 13 · Veri sorumlusuna başvuru

(1) İlgili kişi, bu Kanunun uygulanmasıyla ilgili taleplerini yazılı olarak veya Kurulun belirleyeceği diğer yöntemlerle veri sorumlusuna iletir.

(2) Veri sorumlusu başvuruda yer alan talepleri, talebin niteliğine göre en kısa sürede ve en geç otuz gün içinde ücretsiz olarak sonuçlandırır. Ancak, işlemin ayrıca bir maliyeti gerektirmesi hâlinde, Kurulca belirlenen tarifedeki ücret alınabilir.

(3) Veri sorumlusu talebi kabul eder veya gerekçesini açıklayarak reddeder ve cevabını ilgili kişiye yazılı olarak veya elektronik ortamda bildirir. Başvuruda yer alan talebin kabul edilmesi hâlinde veri sorumlusunca gereği yerine getirilir. Başvurunun veri sorumlusunun hatasından kaynaklanması hâlinde alınan ücret ilgiliye iade edilir.

Article 14Complaint to the Board

Link to this article ↗

(1) In cases where the application is rejected, the response given is found insufficient or the application is not responded to within the time limit, the data subject may lodge a complaint with the Board within thirty days from the date on which he or she learns of the data controller's response and, in any event, within sixty days from the date of application.

(2) A complaint may not be lodged unless the application procedure under Article 13 has been exhausted.

(3) The right to compensation under general provisions of persons whose personality rights have been violated is reserved.

Original Turkish text

MADDE 14 · Kurula şikâyet

(1) Başvurunun reddedilmesi, verilen cevabın yetersiz bulunması veya süresinde başvuruya cevap verilmemesi hâllerinde; ilgili kişi, veri sorumlusunun cevabını öğrendiği tarihten itibaren otuz ve her hâlde başvuru tarihinden itibaren altmış gün içinde Kurula şikâyette bulunabilir.

(2) 13 üncü madde uyarınca başvuru yolu tüketilmeden şikâyet yoluna başvurulamaz.

(3) Kişilik hakları ihlal edilenlerin, genel hükümlere göre tazminat hakkı saklıdır.

Article 15Procedures and principles of examination upon complaint or ex officio

Link to this article ↗

(1) The Board shall carry out the necessary examination on matters falling within its remit upon complaint or, where it learns of an alleged violation, ex officio.

(2) Notices or complaints that do not meet the conditions set out in Article 6 of the Law No. 3071 on the Exercise of the Right of Petition dated 1/11/1984 shall not be examined.

(3) Except for information and documents having the nature of state secrets, the data controller shall be obliged to send the information and documents requested by the Board in relation to the subject of the examination within fifteen days and, where necessary, to enable an on-site examination to be carried out.

(4) Upon a complaint, the Board shall examine the request and give a response to the persons concerned. If no response is given within sixty days from the date of the complaint, the request shall be deemed rejected.

(5) Where, as a result of an examination carried out upon complaint or ex officio, it is established that a violation exists, the Board shall decide that the unlawful acts it has identified be remedied by the data controller and shall serve this decision on the persons concerned. This decision shall be implemented without delay and within thirty days at the latest from service.

(6) Where, as a result of an examination carried out upon complaint or ex officio, it is determined that the violation is widespread, the Board shall adopt a decision of principle on this matter and publish this decision. Before adopting a decision of principle, the Board may also, where it deems necessary, obtain the opinions of the relevant institutions and organisations.

(7) Where damages that are difficult or impossible to remedy may arise and there is a manifest unlawfulness, the Board may decide to suspend the processing of data or the transfer of data abroad.

Original Turkish text

MADDE 15 · Şikâyet üzerine veya resen incelemenin usul ve esasları

(1) Kurul, şikâyet üzerine veya ihlal iddiasını öğrenmesi durumunda resen, görev alanına giren konularda gerekli incelemeyi yapar.

(2) 1/11/1984 tarihli ve 3071 sayılı Dilekçe Hakkının Kullanılmasına Dair Kanunun 6 ncı maddesinde belirtilen şartları taşımayan ihbar veya şikâyetler incelemeye alınmaz.

(3) Devlet sırrı niteliğindeki bilgi ve belgeler hariç; veri sorumlusu, Kurulun, inceleme konusuyla ilgili istemiş olduğu bilgi ve belgeleri on beş gün içinde göndermek ve gerektiğinde yerinde inceleme yapılmasına imkân sağlamak zorundadır.

(4) Şikâyet üzerine Kurul, talebi inceleyerek ilgililere bir cevap verir. Şikâyet tarihinden itibaren altmış gün içinde cevap verilmezse talep reddedilmiş sayılır.

(5) Şikâyet üzerine veya resen yapılan inceleme sonucunda, ihlalin varlığının anlaşılması hâlinde Kurul, tespit ettiği hukuka aykırılıkların veri sorumlusu tarafından giderilmesine karar vererek ilgililere tebliğ eder. Bu karar, tebliğden itibaren gecikmeksizin ve en geç otuz gün içinde yerine getirilir.

(6) Şikâyet üzerine veya resen yapılan inceleme sonucunda, ihlalin yaygın olduğunun tespit edilmesi hâlinde Kurul, bu konuda ilke kararı alır ve bu kararı yayımlar. Kurul, ilke kararı almadan önce ihtiyaç duyması hâlinde, ilgili kurum ve kuruluşların görüşlerini de alabilir.

(7) Kurul, telafisi güç veya imkânsız zararların doğması ve açıkça hukuka aykırılık olması hâlinde, veri işlenmesinin veya verinin yurt dışına aktarılmasının durdurulmasına karar verebilir.

Article 16Data Controllers Registry

Link to this article ↗

(1) A Data Controllers Registry open to the public shall be kept by the Presidency under the supervision of the Board.

(2) Natural and legal persons who process personal data shall be obliged to register with the Data Controllers Registry before starting to process data. However, the Board may provide for exceptions to the obligation to register with the Data Controllers Registry, taking into account objective criteria to be determined by the Board, such as the nature and quantity of the personal data processed, whether the data processing arises from law, or whether the data are transferred to third parties.

(3) The application for registration with the Data Controllers Registry shall be made by a notification containing the following matters:

a) The identity and address details of the data controller and of its representative, if any.

b) The purpose for which the personal data will be processed.

c) Explanations regarding the group or groups of data subjects and the categories of data belonging to such persons.

ç) The recipients or groups of recipients to whom the personal data may be transferred.

d) Personal data envisaged to be transferred to foreign countries.

e) Measures taken regarding the security of personal data.

f) The maximum period necessary for the purpose for which the personal data are processed.

(4) Any changes to the information provided pursuant to paragraph 3 shall be notified to the Presidency forthwith.

(5) Other procedures and principles relating to the Data Controllers Registry shall be regulated by regulation.

Original Turkish text

MADDE 16 · Veri Sorumluları Sicili

(1) Kurulun gözetiminde, Başkanlık tarafından kamuya açık olarak Veri Sorumluları Sicili tutulur.

(2) Kişisel verileri işleyen gerçek ve tüzel kişiler, veri işlemeye başlamadan önce Veri Sorumluları Siciline kaydolmak zorundadır. Ancak, işlenen kişisel verinin niteliği, sayısı, veri işlemenin kanundan kaynaklanması veya üçüncü kişilere aktarılma durumu gibi Kurulca belirlenecek objektif kriterler göz önüne alınmak suretiyle, Kurul tarafından, Veri Sorumluları Siciline kayıt zorunluluğuna istisna getirilebilir.

(3) Veri Sorumluları Siciline kayıt başvurusu aşağıdaki hususları içeren bir bildirimle yapılır:

a) Veri sorumlusu ve varsa temsilcisinin kimlik ve adres bilgileri.

b) Kişisel verilerin hangi amaçla işleneceği.

c) Veri konusu kişi grubu ve grupları ile bu kişilere ait veri kategorileri hakkındaki açıklamalar.

ç) Kişisel verilerin aktarılabileceği alıcı veya alıcı grupları.

d) Yabancı ülkelere aktarımı öngörülen kişisel veriler.

e) Kişisel veri güvenliğine ilişkin alınan tedbirler.

f) Kişisel verilerin işlendikleri amaç için gerekli olan azami süre.

(4) Üçüncü fıkra uyarınca verilen bilgilerde meydana gelen değişiklikler derhâl Başkanlığa bildirilir.

(5) Veri Sorumluları Siciline ilişkin diğer usul ve esaslar yönetmelikle düzenlenir.

Chapter Five: Offences and Misdemeanours

Article 17Offences

Link to this article ↗

(1) With respect to offences relating to personal data, the provisions of Articles 135 to 140 of the Turkish Penal Code No. 5237 dated 26/9/2004 shall apply.

(2) Persons who, in breach of the provision of Article 7 of this Law, fail to erase or anonymise personal data shall be punished in accordance with Article 138 of Law No. 5237.

Original Turkish text

MADDE 17 · Suçlar

(1) Kişisel verilere ilişkin suçlar bakımından 26/9/2004 tarihli ve 5237 sayılı Türk Ceza Kanununun 135 ila 140 ıncı madde hükümleri uygulanır.

(2) Bu Kanunun 7 nci maddesi hükmüne aykırı olarak; kişisel verileri silmeyen veya anonim hâle getirmeyenler 5237 sayılı Kanunun 138 inci maddesine göre cezalandırılır.

Article 18Misdemeanours

Link to this article ↗

(1) Under this Law:

a) on those who fail to fulfil the obligation to inform provided for in Article 10, from 5,000 Turkish liras to 100,000 Turkish liras,

b) on those who fail to fulfil the obligations relating to data security provided for in Article 12, from 15,000 Turkish liras to 1,000,000 Turkish liras,

c) on those who fail to comply with the decisions issued by the Board pursuant to Article 15, from 25,000 Turkish liras to 1,000,000 Turkish liras,

ç) on those who act in breach of the obligation of registration with and notification to the Data Controllers Registry provided for in Article 16, from 20,000 Turkish liras to 1,000,000 Turkish liras,

d) Added: 2/3/2024, Law No. 7499, Art. 35 on those who fail to fulfil the notification obligation provided for in paragraph 5 of Article 9, from 50,000 Turkish liras to 1,000,000 Turkish liras,

an administrative fine shall be imposed within the limits specified above.

(2) Amended: 2/3/2024, Law No. 7499, Art. 35 The administrative fines provided for in subparagraphs (a), (b), (c) and (ç) of paragraph 1 shall be imposed on data controllers, and the administrative fine provided for in subparagraph (d) shall be imposed on data controllers or data processors, who are natural persons or legal persons governed by private law.

(3) Added: 2/3/2024, Law No. 7499, Art. 35 An action may be brought before the administrative courts against administrative fines imposed by the Board.

(4) Where the acts listed in paragraph 1 are committed within public institutions and organisations or professional organisations having the status of public institutions, upon notification by the Board, disciplinary proceedings shall be conducted in accordance with the disciplinary provisions against the civil servants and other public officials serving in the relevant public institution or organisation and against those serving in the professional organisations having the status of public institutions, and the outcome shall be notified to the Board.

Original Turkish text

MADDE 18 · Kabahatler

(1) Bu Kanunun;

a) 10 uncu maddesinde öngörülen aydınlatma yükümlülüğünü yerine getirmeyenler hakkında 5.000 Türk lirasından 100.000 Türk lirasına kadar,

b) 12 nci maddesinde öngörülen veri güvenliğine ilişkin yükümlülükleri yerine getirmeyenler hakkında 15.000 Türk lirasından 1.000.000 Türk lirasına kadar,

c) 15 inci maddesi uyarınca Kurul tarafından verilen kararları yerine getirmeyenler hakkında 25.000 Türk lirasından 1.000.000 Türk lirasına kadar,

ç) 16 ncı maddesinde öngörülen Veri Sorumluları Siciline kayıt ve bildirim yükümlülüğüne aykırı hareket edenler hakkında 20.000 Türk lirasından 1.000.000 Türk lirasına kadar,

d) (Ek:2/3/2024-7499/35 md.) 9 uncu maddenin beşinci fıkrasında öngörülen bildirim yükümlülüğünü yerine getirmeyenler hakkında 50.000 Türk lirasından 1.000.000 Türk lirasına kadar,

idari para cezası verilir.

(2) (Değişik:2/3/2024-7499/35 md.) Birinci fıkranın (a), (b), (c) ve (ç) bentlerinde öngörülen idari para cezaları veri sorumlusu, (d) bendinde öngörülen idari para cezası veri sorumlusu veya veri işleyen gerçek kişiler ile özel hukuk tüzel kişileri hakkında uygulanır.

(3) (Ek:2/3/2024-7499/35 md.) Kurulca verilen idari para cezalarına karşı, idare mahkemelerinde dava açılabilir.

(4) Birinci fıkrada sayılan eylemlerin kamu kurum ve kuruluşları ile kamu kurumu niteliğindeki meslek kuruluşları bünyesinde işlenmesi hâlinde, Kurulun yapacağı bildirim üzerine, ilgili kamu kurum ve kuruluşunda görev yapan memurlar ve diğer kamu görevlileri ile kamu kurumu niteliğindeki meslek kuruluşlarında görev yapanlar hakkında disiplin hükümlerine göre işlem yapılır ve sonucu Kurula bildirilir.

Chapter Six: Personal Data Protection Authority and Organisation

Article 19Personal Data Protection Authority

Link to this article ↗

(1) The Personal Data Protection Authority, having administrative and financial autonomy and public legal personality, has been established to perform the duties assigned by this Law.

(2) The Authority shall be related to the minister to be designated by the President of the Republic.

(3) The headquarters of the Authority is in Ankara.

(4) The Authority consists of the Board and the Presidency. The decision-making body of the Authority is the Board.

Original Turkish text

MADDE 19 · Kişisel Verileri Koruma Kurumu

(1) Bu Kanunla verilen görevleri yerine getirmek üzere, idari ve mali özerkliğe sahip ve kamu tüzel kişiliğini haiz Kişisel Verileri Koruma Kurumu kurulmuştur.

(2) Kurum Cumhurbaşkanının görevlendireceği bakan ile ilişkilidir.

(3) Kurumun merkezi Ankara’dadır.

(4) Kurum, Kurul ve Başkanlıktan oluşur. Kurumun karar organı Kuruldur.

Article 20Duties of the Authority

Link to this article ↗

(1) The duties of the Authority are as follows:

a) To monitor practices and developments in the legislation within its field of duty, to make evaluations and recommendations, and to conduct or have conducted research and examinations.

b) Where needed, to cooperate with public institutions and organisations, non-governmental organisations, professional organisations or universities on matters falling within its field of duty.

c) To monitor and evaluate international developments relating to personal data, to cooperate with international organisations on matters falling within its field of duty, and to participate in meetings.

ç) To submit the annual activity report to the Presidency of the Republic and to the Human Rights Inquiry Committee of the Grand National Assembly of Türkiye (…).

d) To perform the other duties assigned by law.

Original Turkish text

MADDE 20 · Kurumun görevleri

(1) Kurumun görevleri şunlardır:

a) Görev alanı itibarıyla, uygulamaları ve mevzuattaki gelişmeleri takip etmek, değerlendirme ve önerilerde bulunmak, araştırma ve incelemeler yapmak veya yaptırmak.

b) İhtiyaç duyulması hâlinde, görev alanına giren konularda kamu kurum ve kuruluşları, sivil toplum kuruluşları, meslek örgütleri veya üniversitelerle iş birliği yapmak.

c) Kişisel verilerle ilgili uluslararası gelişmeleri izlemek ve değerlendirmek, görev alanına giren konularda uluslararası kuruluşlarla iş birliği yapmak, toplantılara katılmak.

ç) Yıllık faaliyet raporunu Cumhurbaşkanlığına, Türkiye Büyük Millet Meclisi İnsan Haklarını İnceleme Komisyonuna (…) sunmak.

d) Kanunlarla verilen diğer görevleri yerine getirmek.

Article 21Personal Data Protection Board

Link to this article ↗

(1) The Board shall perform and exercise the duties and powers conferred on it by this Law and other legislation independently and under its own responsibility. No organ, authority, office or person may give orders or instructions to the Board, or make recommendations or suggestions to it, on matters falling within its field of duty.

(2) The Board consists of nine members. Five members of the Board shall be elected by the Grand National Assembly of Türkiye and four members by the President of the Republic.

(3) The following conditions shall be required in order to become a member of the Board:

a) Having knowledge and experience in matters within the Authority's field of duty.

b) Possessing the qualifications specified in sub-subparagraphs (1), (4), (5), (6) and (7) of subparagraph (A) of paragraph 1 of Article 48 of the Civil Servants Law No. 657 dated 14/7/1965.

c) Not being a member of any political party.

ç) Having completed higher education at the undergraduate level of at least four years.

d) Repealed: 2/7/2018, Decree-Law No. 703, Art. 163

(4) Repealed: 2/7/2018, Decree-Law No. 703, Art. 163

(5) The Grand National Assembly of Türkiye shall elect the members of the Board in accordance with the following procedure:

a) For the election, twice the number of members to be determined in proportion to the number of members of the political party groups shall be nominated as candidates, and the Board members shall be elected by the Plenary of the Grand National Assembly of Türkiye from among these candidates on the basis of the number of members falling to each political party group. However, no deliberation may be held and no decision may be taken within political party groups as to whom votes will be cast for in elections to be held in the Grand National Assembly of Türkiye.

b) The election of the Board members shall be held within ten days after the candidates have been determined and announced. A combined ballot paper shall be prepared in the form of separate lists for the candidates nominated by the political party groups. Votes shall be cast by marking the special space opposite the names of the candidates. Votes cast in excess of the number of members to be elected to the Board from the quotas of the political party groups determined in accordance with the second paragraph shall be deemed invalid.

c) Provided that the decision quorum is met, the candidates receiving the most votes in the election, in a number equal to the number of vacant memberships, shall be deemed elected.

ç) An election shall be held under the same procedure two months before the expiry of the members' terms of office; where a membership becomes vacant for any reason, within one month from the date of vacancy or, if the Grand National Assembly of Türkiye is in recess on the date of vacancy, from the end of the recess. In these elections, the distribution of the vacant memberships among the political party groups shall be made by taking into account the number of members elected from the quotas of the political party groups in the first election and the current proportion of the political party groups.

(6) Where forty-five days remain before the expiry of the term of office of one of the members elected by the President of the Republic (…), or where the office terminates for any reason, the situation shall be notified by the Authority to the Presidency of the Republic (…) within fifteen days. The election of a new member shall be held one month before the expiry of the members' term of office. Where any of these memberships becomes vacant for any reason before the expiry of the term of office, the election shall be held within fifteen days from the notification.

(7) The Board shall elect the President and the Deputy President from among its members. The President of the Board shall also be the President of the Authority.

(8) The term of office of the Board members is four years. A member whose term has expired may be re-elected. A person elected to replace a member whose office terminates for any reason before the expiry of the term of office shall complete the remaining term of the member whom he or she replaces.

(9) The elected members shall take an oath before the First Presidency Board of the Court of Cassation in the following form: “I swear upon my honour and dignity that I shall perform my duty in accordance with the Constitution and the laws, with complete impartiality, integrity, equity and a sense of justice.” An application made to the Court of Cassation for the taking of the oath shall be deemed an urgent matter.

(10) Unless based on a special law, Board members may not undertake any official or private duty other than the performance of their official duties at the Board, may not serve as executives in associations, foundations, cooperatives and similar entities, may not engage in commerce, may not carry on any liberal professional activity, and may not act as arbitrators or expert witnesses. However, Board members may, in a manner that does not hinder their principal duties, publish for scientific purposes, give lectures and conferences, and receive the royalties arising therefrom as well as fees for lectures and conferences.

(11) Investigations concerning offences allegedly committed by the members by reason of their duties shall be conducted in accordance with the Law on the Prosecution of Civil Servants and Other Public Officials No. 4483 dated 2/12/1999, and permission to investigate them shall be granted by the President of the Republic.

(12) The provisions of Law No. 657 shall apply to disciplinary investigations and prosecutions to be conducted against the Board members.

(13) Board members may not be dismissed from office for any reason before the expiry of their terms. With respect to Board members:

a) Where it is subsequently established that they do not possess the conditions required for election,

b) Where a conviction rendered against them for offences committed in connection with their duties becomes final,

c) Where it is definitively established by a medical board report that they are unable to perform their duties,

ç) Where it is established that they have failed to attend to their duties without leave, without excuse and without interruption for fifteen days, or for a total of thirty days within one year,

d) Where it is established that they have failed to attend, without leave and without excuse, a total of three Board meetings within one month or a total of ten Board meetings within one year,

in such cases, their membership shall terminate by decision of the Board.

(14) The connection of those elected to the membership of the Board with their previous posts shall be severed for as long as they serve on the Board. Those who were public officials when elected to membership shall, provided that they have not lost the conditions for entry into the civil service, be appointed within one month by the authority competent to make appointments to a position appropriate to their acquired rights, in the event that their term of office expires or they request to leave office and apply to their former institutions within thirty days. Until the appointment is made, all payments they had been receiving shall continue to be paid by the Authority. Those who were not working in a public institution when elected to membership and whose office terminates in the manner specified above shall continue to be paid by the Authority all payments they had been receiving until they commence any duty or employment, and the payment to be made by the Authority to those whose membership terminates in this manner may not exceed three months. The periods they spend at the Authority shall be deemed to have been spent at their previous institutions or organisations with respect to their personnel and other rights.

Original Turkish text

MADDE 21 · Kişisel Verileri Koruma Kurulu

(1) Kurul, bu Kanunla ve diğer mevzuatla verilen görev ve yetkilerini kendi sorumluluğu altında, bağımsız olarak yerine getirir ve kullanır. Görev alanına giren konularla ilgili olarak hiçbir organ, makam, merci veya kişi, Kurula emir ve talimat veremez, tavsiye veya telkinde bulunamaz.

(2) Kurul, dokuz üyeden oluşur. Kurulun beş üyesi Türkiye Büyük Millet Meclisi, dört üyesi Cumhurbaşkanı tarafından seçilir.

(3) Kurula üye olabilmek için aşağıdaki şartlar aranır:

a) Kurumun görev alanındaki konularda bilgi ve deneyim sahibi olmak.

b) 14/7/1965 tarihli ve 657 sayılı Devlet Memurları Kanununun 48 inci maddesinin birinci fıkrasının (A) bendinin (1), (4), (5), (6) ve (7) numaralı alt bentlerinde belirtilen nitelikleri taşımak.

c) Herhangi bir siyasi parti üyesi olmamak.

ç) En az dört yıllık lisans düzeyinde yükseköğrenim görmüş olmak.

d) (Mülga: 2/7/2018-KHK-703/163 md.)

(4) (Mülga: 2/7/2018-KHK-703/163 md.)

(5) Türkiye Büyük Millet Meclisi, Kurula üye seçimini aşağıdaki usulle yapar:

a) Seçim için, siyasi parti gruplarının üye sayısı oranında belirlenecek üye sayısının ikişer katı aday gösterilir ve Kurul üyeleri bu adaylar arasından her siyasi parti grubuna düşen üye sayısı esas alınmak suretiyle Türkiye Büyük Millet Meclisi Genel Kurulunca seçilir. Ancak, siyasi parti gruplarında, Türkiye Büyük Millet Meclisinde yapılacak seçimlerde kime oy kullanılacağına dair görüşme yapılamaz ve karar alınamaz.

b) Kurul üyelerinin seçimi, adayların belirlenerek ilanından sonra on gün içinde yapılır. Siyasi parti grupları tarafından gösterilen adaylar için ayrı ayrı listeler hâlinde birleşik oy pusulası düzenlenir. Adayların adlarının karşısındaki özel yer işaretlenmek suretiyle oy kullanılır. Siyasi parti gruplarının ikinci fıkraya göre belirlenen kontenjanlarından Kurula seçilecek üyelerin sayısından fazla verilen oylar geçersiz sayılır.

c) Karar yeter sayısı olmak şartıyla seçimde en çok oyu alan boş üyelik sayısı kadar aday seçilmiş olur.

ç) Üyelerin görev sürelerinin bitiminden iki ay önce; üyeliklerde herhangi bir sebeple boşalma olması hâlinde, boşalma tarihinden veya boşalma tarihinde Türkiye Büyük Millet Meclisi tatilde ise tatilin bitiminden itibaren bir ay içinde aynı usulle seçim yapılır. Bu seçimlerde, boşalan üyeliklerin siyasi parti gruplarına dağılımı, ilk seçimde siyasi parti grupları kontenjanından seçilen üye sayısı ve siyasi parti gruplarının hâlihazırdaki oranı dikkate alınmak suretiyle yapılır.

(6) Cumhurbaşkanı (…) tarafından seçilen üyelerden birinin görev süresinin bitiminden kırk beş gün önce veya herhangi bir sebeple görevin sona ermesi hâlinde durum, on beş gün içinde Kurum tarafından, Cumhurbaşkanlığına (…)5 bildirilir. Üyelerin görev süresinin dolmasına bir ay kala yeni üye seçimi yapılır. Bu üyeliklerde, görev süresi dolmadan herhangi bir sebeple boşalma olması hâlinde ise bildirimden itibaren on beş gün içinde seçim yapılır.

(7) Kurul, üyeleri arasından Başkan ve İkinci Başkanı seçer. Kurulun Başkanı, Kurumun da başkanıdır.

(8) Kurul üyelerinin görev süresi dört yıldır. Süresi biten üye yeniden seçilebilir. Görev süresi dolmadan herhangi bir sebeple görevi sona eren üyenin yerine seçilen kişi, yerine seçildiği üyenin kalan süresini tamamlar.

(9) Seçilen üyeler Yargıtay Birinci Başkanlık Kurulu huzurunda “Görevimi Anayasaya ve kanunlara uygun olarak, tam bir tarafsızlık, dürüstlük, hakkaniyet ve adalet anlayışı içinde yerine getireceğime, namusum ve şerefim üzerine yemin ederim.” şeklinde yemin ederler. Yargıtaya yemin için yapılan başvuru acele işlerden sayılır.

(10) Kurul üyeleri özel bir kanuna dayanmadıkça, Kuruldaki resmî görevlerinin yürütülmesi dışında resmî veya özel hiçbir görev alamaz, dernek, vakıf, kooperatif ve benzeri yerlerde yöneticilik yapamaz, ticaretle uğraşamaz, serbest meslek faaliyetinde bulunamaz, hakemlik ve bilirkişilik yapamazlar. Ancak, Kurul üyeleri, asli görevlerini aksatmayacak şekilde bilimsel amaçlı yayın yapabilir, ders ve konferans verebilir ve bunlardan doğacak telif hakları ile ders ve konferans ücretlerini alabilirler.

(11) Üyelerin görevleri sebebiyle işledikleri iddia edilen suçlara ilişkin soruşturmalar 2/12/1999 tarihli ve 4483 sayılı Memurlar ve Diğer Kamu Görevlilerinin Yargılanması Hakkında Kanuna göre yapılır ve bunlar hakkında soruşturma izni Cumhurbaşkanı tarafından verilir.

(12) Kurul üyeleri hakkında yapılacak disiplin soruşturması ve kovuşturmasında 657 sayılı Kanun hükümleri uygulanır.

(13) Kurul üyelerinin süreleri dolmadan herhangi bir nedenle görevlerine son verilemez. Kurul üyelerinin;

a) Seçilmek için gereken şartları taşımadıklarının sonradan anlaşılması,

b) Görevleriyle ilgili olarak işledikleri suçlardan dolayı haklarında verilen mahkûmiyet kararının kesinleşmesi,

c) Görevlerini yerine getiremeyeceklerinin sağlık kurulu raporuyla kesin olarak tespit edilmesi,

ç) Görevlerine izinsiz, mazeretsiz ve kesintisiz olarak on beş gün ya da bir yılda toplam otuz gün süreyle devam etmediklerinin tespit edilmesi,

d) Bir ay içinde izinsiz ve mazeretsiz olarak toplam üç, bir yıl içinde toplam on Kurul toplantısına katılmadıklarının tespit edilmesi,

hâllerinde Kurul kararıyla üyelikleri sona erer.

(14) Kurul üyeliğine seçilenlerin Kurulda görev yaptıkları sürece önceki görevleri ile olan ilişikleri kesilir. Kamu görevlisi iken üyeliğe seçilenler, memuriyete giriş şartlarını kaybetmemeleri kaydıyla, görev sürelerinin sona ermesi veya görevden ayrılma isteğinde bulunmaları ve otuz gün içinde eski kurumlarına başvurmaları durumunda atamaya yetkili makam tarafından bir ay içinde mükteseplerine uygun bir kadroya atanır. Atama gerçekleşinceye kadar, bunların almakta oldukları her türlü ödemelerin Kurum tarafından ödenmesine devam olunur. Bir kamu kurumunda çalışmayanlardan üyeliğe seçilip yukarıda belirtilen şekilde görevi sona erenlere herhangi bir görev veya işe başlayıncaya kadar, almakta oldukları her türlü ödemeler Kurum tarafından ödenmeye devam edilir ve bu şekilde üyeliği sona erenlere Kurum tarafından yapılacak ödeme üç ayı geçemez. Bunların Kurumda geçirdiği süreler, özlük ve diğer hakları açısından önceki kurum veya kuruluşlarında geçirilmiş sayılır.

Article 22Duties and powers of the Board

Link to this article ↗

(1) The duties and powers of the Board are as follows:

a) To ensure that personal data are processed in accordance with fundamental rights and freedoms.

b) To decide on the complaints of those who claim that their rights relating to personal data have been violated.

c) Upon complaint, or ex officio where it learns of an alleged violation, to examine, on matters falling within its field of duty, whether personal data are processed in accordance with the law, and to take interim measures in this respect where necessary.

ç) To determine the adequate measures required for the processing of special categories of personal data.

d) To ensure that the Data Controllers Registry is kept.

e) To carry out the necessary regulatory acts on matters relating to the Board's field of duty and the functioning of the Authority.

f) To carry out regulatory acts for the purpose of determining the obligations relating to data security.

g) To carry out regulatory acts concerning the duties, powers and responsibilities of the data controller and its representative.

ğ) To decide on the administrative sanctions provided for in this Law.

h) To give opinions on draft legislation prepared by other institutions and organisations that contain provisions relating to personal data.

ı) To decide on the strategic plan of the Authority and to determine its aims and objectives, service quality standards and performance criteria.

i) To discuss and decide on the budget proposal prepared in accordance with the strategic plan and the aims and objectives of the Authority.

j) To approve and publish the draft reports prepared on the performance, financial situation and annual activities of the Authority and on matters as needed.

k) To discuss and decide on proposals concerning the purchase, sale and lease of immovable property.

l) To perform the other duties assigned by law.

Original Turkish text

MADDE 22 · Kurulun görev ve yetkileri

(1) Kurulun görev ve yetkileri şunlardır:

a) Kişisel verilerin, temel hak ve özgürlüklere uygun şekilde işlenmesini sağlamak.

b) Kişisel verilerle ilgili haklarının ihlal edildiğini ileri sürenlerin şikâyetlerini karara bağlamak.

c) Şikâyet üzerine veya ihlal iddiasını öğrenmesi durumunda resen görev alanına giren konularda kişisel verilerin kanunlara uygun olarak işlenip işlenmediğini incelemek ve gerektiğinde bu konuda geçici önlemler almak.

ç) Özel nitelikli kişisel verilerin işlenmesi için aranan yeterli önlemleri belirlemek.

d) Veri Sorumluları Sicilinin tutulmasını sağlamak.

e) Kurulun görev alanı ile Kurumun işleyişine ilişkin konularda gerekli düzenleyici işlemleri yapmak.

f) Veri güvenliğine ilişkin yükümlülükleri belirlemek amacıyla düzenleyici işlem yapmak.

g) Veri sorumlusunun ve temsilcisinin görev, yetki ve sorumluluklarına ilişkin düzenleyici işlem yapmak.

ğ) Bu Kanunda öngörülen idari yaptırımlara karar vermek.

h) Diğer kurum ve kuruluşlarca hazırlanan ve kişisel verilere ilişkin hüküm içeren mevzuat taslakları hakkında görüş bildirmek.

ı) Kurumun; stratejik planını karara bağlamak, amaç ve hedeflerini, hizmet kalite standartlarını ve performans kriterlerini belirlemek.

i) Kurumun stratejik planı ile amaç ve hedeflerine uygun olarak hazırlanan bütçe teklifini görüşmek ve karara bağlamak.

j) Kurumun performansı, mali durumu, yıllık faaliyetleri ve ihtiyaç duyulan konular hakkında hazırlanan rapor taslaklarını onaylamak ve yayımlamak.

k) Taşınmaz alımı, satımı ve kiralanması konularındaki önerileri görüşüp karara bağlamak.

l) Kanunlarla verilen diğer görevleri yerine getirmek.

Article 23Working principles of the Board

Link to this article ↗

(1) The meeting days and agenda of the Board shall be determined by the President. The President may, where necessary, call the Board to an extraordinary meeting.

(2) The Board shall convene with at least six members, including the President, and shall take decisions by an absolute majority of its full membership. Board members may not cast abstaining votes.

(3) Board members may not participate in meetings and votes on matters concerning themselves, their relatives by blood up to the third degree and by marriage up to the second degree, their adopted children, and their spouses even if the marriage bond between them has ended.

(4) Board members may not disclose to anyone other than the authorities legally empowered in this respect, nor use for their own benefit, any secrets of the persons concerned and third parties that they learn in the course of their work. This obligation shall continue after they leave office.

(5) The matters discussed at the Board shall be recorded in minutes. Decisions and, if any, the reasoning of dissenting votes shall be written within fifteen days at the latest from the date of the decision. The Board shall announce to the public the decisions it deems necessary.

(6) Unless decided otherwise, the deliberations at Board meetings shall be confidential.

(7) The working procedures and principles of the Board, the drafting of decisions and other matters shall be governed by regulation.

Original Turkish text

MADDE 23 · Kurulun çalışma esasları

(1) Kurulun toplantı günlerini ve gündemini Başkan belirler. Başkan gereken hâllerde Kurulu olağanüstü toplantıya çağırabilir.

(2) Kurul, başkan dâhil en az altı üye ile toplanır ve üye tam sayısının salt çoğunluğuyla karar alır. Kurul üyeleri çekimser oy kullanamaz.

(3) Kurul üyeleri; kendilerini, üçüncü dereceye kadar kan ve ikinci dereceye kadar kayın hısımlarını, evlatlıklarını ve aralarındaki evlilik bağı kalkmış olsa bile eşlerini ilgilendiren konularla ilgili toplantı ve oylamaya katılamaz.

(4) Kurul üyeleri çalışmaları sırasında ilgililere ve üçüncü kişilere ait öğrendikleri sırları bu konuda kanunen yetkili kılınan mercilerden başkasına açıklayamazlar ve kendi yararlarına kullanamazlar. Bu yükümlülük görevden ayrılmalarından sonra da devam eder.

(5) Kurulda görüşülen işler tutanağa bağlanır. Kararlar ve varsa karşı oy gerekçeleri karar tarihinden itibaren en geç on beş gün içinde yazılır. Kurul, gerekli gördüğü kararları kamuoyuna duyurur.

(6) Aksi kararlaştırılmadıkça, Kurul toplantılarındaki görüşmeler gizlidir.

(7) Kurulun çalışma usul ve esasları ile kararların yazımı ve diğer hususlar yönetmelikle düzenlenir.

Article 24President

Link to this article ↗

(1) The President, in his or her capacity as the president of the Board and of the Authority, is the highest superior of the Authority and shall organise and conduct the services of the Authority in accordance with the legislation, the aims and policies of the Authority, its strategic plan, performance criteria and service quality standards, and shall ensure coordination among the service units.

(2) The President is responsible for the general management and representation of the Authority. This responsibility covers the duties and powers of organising, conducting, supervising and evaluating the work of the Authority and, where necessary, announcing it to the public.

(3) The duties of the President are as follows:

a) To chair the Board meetings.

b) To ensure the service of Board decisions and the announcement to the public of those deemed necessary by the Board, and to monitor their implementation.

c) To appoint the Vice President, the heads of department and the personnel of the Authority.

ç) To finalise the proposals received from the service units and submit them to the Board.

d) To ensure the implementation of the strategic plan, and to establish human resources and working policies in line with the service quality standards.

e) To prepare the annual budget and financial statements of the Authority in accordance with the determined strategies and annual aims and objectives.

f) To ensure coordination so that the Board and the service units work in a harmonious, efficient, disciplined and orderly manner.

g) To conduct the relations of the Authority with other organisations.

ğ) To determine the scope of duties and powers of the personnel authorised to sign on behalf of the President of the Authority.

h) To perform the other duties relating to the management and functioning of the Authority.

(4) In the absence of the President of the Authority, the Deputy President shall act on behalf of the President.

Original Turkish text

MADDE 24 · Başkan

(1) Başkan, Kurul ve Kurumun başkanı sıfatıyla Kurumun en üst amiri olup Kurum hizmetlerini mevzuata, Kurumun amaç ve politikalarına, stratejik planına, performans ölçütlerine ve hizmet kalite standartlarına uygun olarak düzenler, yürütür ve hizmet birimleri arasında koordinasyonu sağlar.

(2) Başkan, Kurumun genel yönetim ve temsilinden sorumludur. Bu sorumluluk, Kurum çalışmalarının düzenlenmesi, yürütülmesi, denetlenmesi, değerlendirilmesi ve gerektiğinde kamuoyuna duyurulması görev ve yetkilerini kapsar.

(3) Başkanın görevleri şunlardır:

a) Kurul toplantılarını idare etmek.

b) Kurul kararlarının tebliğini ve Kurulca gerekli görülenlerin kamuoyuna duyurulmasını sağlamak ve uygulanmalarını izlemek.

c) Başkan Yardımcısını, daire başkanlarını ve Kurum personelini atamak.

ç) Hizmet birimlerinden gelen önerilere son şeklini vererek Kurula sunmak.

d) Stratejik planın uygulanmasını sağlamak, hizmet kalite standartları doğrultusunda insan kaynakları ve çalışma politikalarını oluşturmak.

e) Belirlenen stratejilere, yıllık amaç ve hedeflere uygun olarak Kurumun yıllık bütçesi ile mali tablolarını hazırlamak.

f) Kurul ve hizmet birimlerinin uyumlu, verimli, disiplinli ve düzenli bir biçimde çalışması amacıyla koordinasyonu sağlamak.

g) Kurumun diğer kuruluşlarla ilişkilerini yürütmek.

ğ) Kurum Başkanı adına imzaya yetkili personelin görev ve yetki alanını belirlemek.

h) Kurumun yönetim ve işleyişine ilişkin diğer görevleri yerine getirmek.

(4) Kurum Başkanının yokluğunda İkinci Başkan, Başkana vekalet eder.

Article 25Composition and duties of the Presidency

Link to this article ↗

(1) The Presidency consists of the Vice President and the service units. The Presidency shall perform the duties listed in paragraph 4 through service units organised as departments. The number of departments may not exceed seven.

(2) One Vice President shall be appointed by the President to assist in the duties relating to the Authority.

(3) The Vice President and the heads of department shall be appointed by the President from among persons who are graduates of higher education institutions providing at least four years of education and who have served in the public service for ten years.

(4) The duties of the Presidency are as follows:

a) To keep the Data Controllers Registry.

b) To carry out the office and secretariat work of the Authority and the Board.

c) To represent the Authority through attorneys in actions and enforcement proceedings to which the Authority is a party, to pursue or have pursued such actions, and to carry out legal services.

ç) To carry out the personnel affairs of the Board members and of those serving at the Authority.

d) To perform the duties assigned by law to financial services and strategy development units.

e) To ensure the establishment and use of an information system for the conduct of the business and transactions of the Authority.

f) To prepare draft reports on the annual activities of the Board or on matters as needed and submit them to the Board.

g) To prepare the draft strategic plan of the Authority.

ğ) To determine the personnel policy of the Authority, and to prepare and implement the career and training plans of the personnel.

h) To carry out the appointment, transfer, disciplinary, performance, promotion, retirement and similar procedures of the personnel.

ı) To determine the ethical rules to be observed by the personnel and to provide the necessary training.

i) To carry out, within the framework of the Public Financial Management and Control Law No. 5018 dated 10/12/2003, all kinds of purchasing, leasing, maintenance, repair, construction, archive, health, social and similar services needed by the Authority.

j) To keep the records of the movable and immovable property belonging to the Authority.

k) To perform the other duties assigned by the Board or the President.

(5) The service units and the working procedures and principles of these units shall be determined, in accordance with the field of activity, duties and powers specified in this Law, by a regulation put into force by the President of the Republic upon the proposal of the Authority.

Original Turkish text

MADDE 25 · Başkanlığın oluşumu ve görevleri

(1) Başkanlık; Başkan Yardımcısı ve hizmet birimlerinden oluşur. Başkanlık, dördüncü fıkrada sayılan görevleri daire başkanlıkları şeklinde teşkilatlanan hizmet birimleri aracılığıyla yerine getirir. Daire başkanlıklarının sayısı yediyi geçemez.

(2) Başkan tarafından, Kuruma ilişkin görevlerinde yardımcı olmak üzere bir Başkan Yardımcısı atanır.

(3) Başkan Yardımcısı ve daire başkanları; en az dört yıllık yükseköğretim kurumu mezunu, on yıl süreyle kamu hizmetinde bulunan kişiler arasından Başkan tarafından atanır.

(4) Başkanlığın görevleri şunlardır:

a) Veri Sorumluları Sicilini tutmak.

b) Kurumun ve Kurulun büro ve sekretarya işlemlerini yürütmek.

c) Kurumun taraf olduğu davalar ile icra takiplerinde avukatlar vasıtasıyla Kurumu temsil etmek, davaları takip etmek veya ettirmek, hukuk hizmetlerini yürütmek.

ç) Kurul üyeleri ile Kurumda görev yapanların özlük işlemlerini yürütmek.

d) Kanunlarla mali hizmet ve strateji geliştirme birimlerine verilen görevleri yapmak.

e) Kurumun iş ve işlemlerinin yürütülmesi amacıyla bilişim sisteminin kurulmasını ve kullanılmasını sağlamak.

f) Kurulun yıllık faaliyetleri hakkında veya ihtiyaç duyulan konularda rapor taslaklarını hazırlamak ve Kurula sunmak.

g) Kurumun stratejik plan taslağını hazırlamak.

ğ) Kurumun personel politikasını belirlemek, personelin kariyer ve eğitim planlarını hazırlamak ve uygulamak.

h) Personelin atama, nakil, disiplin, performans, terfi, emeklilik ve benzeri işlemlerini yürütmek.

ı) Personelin uyacağı etik kuralları belirlemek ve gerekli eğitimi vermek.

i) 10/12/2003 tarihli ve 5018 sayılı Kamu Malî Yönetimi ve Kontrol Kanunu çerçevesinde Kurumun ihtiyacı olan her türlü satın alma, kiralama, bakım, onarım, yapım, arşiv, sağlık, sosyal ve benzeri hizmetleri yürütmek.

j) Kuruma ait taşınır ve taşınmazların kayıtlarını tutmak.

k) Kurul veya Başkan tarafından verilen diğer görevleri yapmak.

(5) Hizmet birimleri ile bu birimlerin çalışma usul ve esasları, bu Kanunda belirtilen faaliyet alanı, görev ve yetkilere uygun olarak Kurumun teklifi üzerine Cumhurbaşkanınca yürürlüğe konulan yönetmelikle belirlenir.

Article 26Personal Data Protection Experts and assistant experts

Link to this article ↗

(1) Personal Data Protection Experts and Assistant Personal Data Protection Experts may be employed at the Authority. Those among them who are appointed to the position of Personal Data Protection Expert within the framework of additional Article 41 of Law No. 657 shall be granted a one-grade promotion on a one-time basis.

Original Turkish text

MADDE 26 · Kişisel Verileri Koruma Uzmanı ve uzman yardımcıları

(1) Kurumda, Kişisel Verileri Koruma Uzmanı ve Kişisel Verileri Koruma Uzman Yardımcısı istihdam edilebilir. Bunlardan 657 sayılı Kanunun ek 41 inci maddesi çerçevesinde Kişisel Verileri Koruma Uzmanı kadrosuna atananlara bir defaya mahsus olmak üzere bir derece yükseltilmesi uygulanır.

Article 27Provisions concerning personnel and their personnel rights

Link to this article ↗

(1) The personnel of the Authority shall be subject to Law No. 657 except for the matters regulated by this Law.

(2) The payments made within the scope of financial and social rights to the equivalent personnel determined pursuant to additional Article 11 of Decree-Law No. 375 dated 27/6/1989 shall be paid to the President and members of the Board and to the personnel of the Authority under the same procedures and principles. Payments that are not subject to tax and other statutory deductions among those made to the equivalent personnel shall not be subject to tax and other deductions under this Law either.

(3) The President and members of the Board and the personnel of the Authority shall be subject to the provisions of subparagraph (c) of paragraph 1 of Article 4 of the Social Insurance and General Health Insurance Law No. 5510 dated 31/5/2006. The President and members of the Board and the personnel of the Authority shall also be deemed equivalent, in respect of pension rights, to the personnel determined as their equivalents. For those who were insured within the scope of subparagraph (c) of paragraph 1 of Article 4 of Law No. 5510 when appointed as President or members of the Board, and whose such duties end or who request to leave such duties, the periods of service spent in these duties shall be taken into account in determining their acquired-right salary, grade and step. For those among them who fall within the scope of provisional Article 4 of Law No. 5510 during these duties, the periods spent in these duties shall be counted as periods for which office allowance and representation allowance are to be paid. For those who were insured within the scope of subparagraph (a) of paragraph 1 of Article 4 of Law No. 5510 in public institutions and organisations when appointed as President or members of the Board, the severance of their connection with their previous institutions and organisations shall not require the payment of severance pay or end-of-service compensation to them. The periods of service of persons in this situation for which severance pay or end-of-service compensation is to be paid shall be combined with the periods of service spent as President of the Board and as Board members, and shall be counted as a period for which a retirement bonus is to be paid.

(4) Civil servants and other public officials serving in public administrations within the scope of central government, social security institutions, local administrations, administrations affiliated with local administrations, unions of local administrations, organisations with revolving funds, funds established by law, organisations having public legal personality, organisations more than fifty percent of whose capital belongs to the public sector, state economic enterprises and public economic organisations and their affiliated partnerships and establishments may, with the consent of their institutions, and judges and prosecutors may, with their own consent, be temporarily assigned to the Authority, provided that their salaries, allowances, all kinds of increments and compensation, and other financial and social rights and benefits are paid by their own institutions. The requests of the Authority in this respect shall be finalised by the relevant institutions and organisations with priority. Personnel assigned in this manner shall be deemed to be on paid leave from their institutions. While they are on leave, their connection with their civil service positions and their personnel rights shall continue, these periods shall also be taken into account in their promotion and retirement, and their promotions shall be effected in due time without the need for any further procedure. The periods spent at the Authority by those assigned under this Article shall be deemed to have been spent at their own institutions. The number of persons assigned in this manner may not exceed ten percent of the total number of positions of Personal Data Protection Expert and Assistant Personal Data Protection Expert, and the period of assignment may not exceed two years. However, where needed, this period may be extended in periods of one year.

(5) The titles and numbers of the positions for the personnel to be employed at the Authority are shown in the annexed Schedule (I). Changes of title and grade, the addition of new titles and the cancellation of vacant positions, without exceeding the total number of positions and limited to the position titles contained in the schedules annexed to Decree-Law No. 190 dated 13/12/1983 on General Staff and Procedure, shall be made by decision of the Board.

Original Turkish text

MADDE 27 · Personele ve özlük haklarına ilişkin hükümler

(1) Kurum personeli, bu Kanunla düzenlenen hususlar dışında 657 sayılı Kanuna tabidir.

(2) Kurul Başkan ve üyeleri ile Kurum personeline 27/6/1989 tarihli ve 375 sayılı Kanun Hükmünde Kararnamenin ek 11 inci maddesi uyarınca belirlenmiş emsali personele mali ve sosyal haklar kapsamında yapılan ödemeler aynı usul ve esaslar çerçevesinde ödenir. Emsali personele yapılan ödemelerden vergi ve diğer yasal kesintilere tabi olmayanlar bu Kanuna göre de vergi ve diğer kesintilere tabi olmaz.

(3) Kurul Başkan ve üyeleri ile Kurum personeli 31/5/2006 tarihli ve 5510 sayılı Sosyal Sigortalar ve Genel Sağlık Sigortası Kanununun 4 üncü maddesinin birinci fıkrasının (c) bendi hükümlerine tabidir. Kurul Başkan ve üyeleri ile Kurum personeli emeklilik hakları bakımından da emsali olarak belirlenen personel ile denk kabul edilir. 5510 sayılı Kanunun 4 üncü maddesinin birinci fıkrasının (c) bendi kapsamında sigortalı iken Kurul Başkanı ve üyeliklerine atananlardan bu görevleri sona erenler veya bu görevlerinden ayrılma isteğinde bulunanların bu görevlerde geçen hizmet süreleri kazanılmış hak aylık, derece ve kademelerinin tespitinde dikkate alınır. Bunlardan bu görevleri sırasında 5510 sayılı Kanunun geçici 4 üncü maddesi kapsamına girenlerin bu görevlerde geçen süreleri makam tazminatı ile temsil tazminatı ödenmesi gereken süre olarak değerlendirilir. Kamu kurum ve kuruluşlarında 5510 sayılı Kanunun 4 üncü maddesinin birinci fıkrasının (a) bendi kapsamında sigortalı iken Kurul Başkanı ve üyeliklerine atananların, önceki kurum ve kuruluşları ile ilişiklerinin kesilmesi kendilerine kıdem tazminatı veya iş sonu tazminatı ödenmesini gerektirmez. Bu durumda olanların kıdem tazminatı veya iş sonu tazminatı ödenmesi gereken hizmet süreleri, Kurul Başkanı ile Kurul üyeliği olarak geçen hizmet süreleri ile birleştirilir ve emeklilik ikramiyesi ödenecek süre olarak değerlendirilir.

(4) Merkezi yönetim kapsamındaki kamu idarelerinde, sosyal güvenlik kurumlarında, mahallî idarelerde, mahallî idarelere bağlı idarelerde, mahallî idare birliklerinde, döner sermayeli kuruluşlarda, kanunlarla kurulan fonlarda, kamu tüzel kişiliğini haiz kuruluşlarda, sermayesinin yüzde ellisinden fazlası kamuya ait kuruluşlarda, iktisadi devlet teşekkülleri ve kamu iktisadi kuruluşları ile bunlara bağlı ortaklıklar ve müesseselerde görevli memurlar ile diğer kamu görevlileri kurumlarının muvafakati, hâkimler ve savcılar ise kendilerinin muvafakati ile aylık, ödenek, her türlü zam ve tazminatlar ile diğer mali ve sosyal hak ve yardımları kurumlarınca ödenmek kaydıyla geçici olarak Kurumda görevlendirilebilir. Kurumun bu konudaki talepleri, ilgili kurum ve kuruluşlarca öncelikle sonuçlandırılır. Bu şekilde görevlendirilen personel, kurumlarından aylıklı izinli sayılır. Bu personelin izinli oldukları sürece memuriyetleri ile ilgileri ve özlük hakları devam ettiği gibi, bu süreler yükselme ve emekliliklerinde de hesaba katılır ve yükselmeleri başkaca bir işleme gerek duyulmadan süresinde yapılır. Bu madde kapsamında görevlendirilenlerin, Kurumda geçirdikleri süreler, kendi kurumlarında geçirilmiş sayılır. Bu şekilde görevlendirilenlerin sayısı Kişisel Verileri Koruma Uzmanı ve Kişisel Verileri Koruma Uzman Yardımcısı toplam kadro sayısının yüzde onunu aşamaz ve görevlendirme süresi iki yılı geçemez. Ancak ihtiyaç hâlinde bu süre bir yıllık dönemler hâlinde uzatılabilir.

(5) Kurumda istihdam edilecek personele ilişkin kadro unvan ve sayıları ekli (I) sayılı cetvelde gösterilmiştir. Toplam kadro sayısını geçmemek üzere 13/12/1983 tarihli ve 190 sayılı Genel Kadro ve Usulü Hakkında Kanun Hükmünde Kararnamenin eki cetvellerde yer alan kadro unvanlarıyla sınırlı olmak kaydıyla unvan ve derece değişikliği yapma, yeni unvan ekleme ve boş kadroların iptali Kurul kararıyla yapılır.

Chapter Seven: Miscellaneous Provisions

Article 28Exceptions

Link to this article ↗

(1) The provisions of this Law shall not apply in the following cases:

a) The processing of personal data by natural persons within the scope of activities relating exclusively to themselves or to family members living in the same household, provided that the data are not disclosed to third parties and the obligations relating to data security are complied with.

b) The processing of personal data for purposes such as research, planning and statistics by means of anonymisation through official statistics.

c) The processing of personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that it does not violate national defence, national security, public security, public order, economic security, the privacy of private life or personality rights, or constitute an offence.

ç) The processing of personal data within the scope of preventive, protective and intelligence activities carried out by public institutions and organisations assigned and authorised by law to ensure national defence, national security, public security, public order or economic security.

d) The processing of personal data by judicial authorities or enforcement authorities in relation to investigation, prosecution, trial or execution proceedings.

(2) Provided that it is in conformity with and proportionate to the purpose and basic principles of this Law, Article 10, which regulates the data controller's obligation to inform, Article 11, which regulates the rights of the data subject, except for the right to claim compensation for damage, and Article 16, which regulates the obligation to register with the Data Controllers Registry, shall not apply in the following cases:

a) Where the processing of personal data is necessary for the prevention of crime or for a criminal investigation.

b) The processing of personal data that have been made public by the data subject himself or herself.

c) Where the processing of personal data is necessary for the performance of supervisory or regulatory duties, or for disciplinary investigation or prosecution, by public institutions and organisations assigned and authorised on the basis of the authority conferred by law, and by professional organisations having the status of public institutions.

ç) Where the processing of personal data is necessary for the protection of the economic and financial interests of the State in relation to budgetary, tax and financial matters.

Original Turkish text

MADDE 28 · İstisnalar

(1) Bu Kanun hükümleri aşağıdaki hâllerde uygulanmaz:

a) Kişisel verilerin, üçüncü kişilere verilmemek ve veri güvenliğine ilişkin yükümlülüklere uyulmak kaydıyla gerçek kişiler tarafından tamamen kendisiyle veya aynı konutta yaşayan aile fertleriyle ilgili faaliyetler kapsamında işlenmesi.

b) Kişisel verilerin resmi istatistik ile anonim hâle getirilmek suretiyle araştırma, planlama ve istatistik gibi amaçlarla işlenmesi.

c) Kişisel verilerin millî savunmayı, millî güvenliği, kamu güvenliğini, kamu düzenini, ekonomik güvenliği, özel hayatın gizliliğini veya kişilik haklarını ihlal etmemek ya da suç teşkil etmemek kaydıyla, sanat, tarih, edebiyat veya bilimsel amaçlarla ya da ifade özgürlüğü kapsamında işlenmesi.

ç) Kişisel verilerin millî savunmayı, millî güvenliği, kamu güvenliğini, kamu düzenini veya ekonomik güvenliği sağlamaya yönelik olarak kanunla görev ve yetki verilmiş kamu kurum ve kuruluşları tarafından yürütülen önleyici, koruyucu ve istihbari faaliyetler kapsamında işlenmesi.

d) Kişisel verilerin soruşturma, kovuşturma, yargılama veya infaz işlemlerine ilişkin olarak yargı makamları veya infaz mercileri tarafından işlenmesi.

(2) Bu Kanunun amacına ve temel ilkelerine uygun ve orantılı olmak kaydıyla veri sorumlusunun aydınlatma yükümlülüğünü düzenleyen 10 uncu, zararın giderilmesini talep etme hakkı hariç, ilgili kişinin haklarını düzenleyen 11 inci ve Veri Sorumluları Siciline kayıt yükümlülüğünü düzenleyen 16 ncı maddeleri aşağıdaki hâllerde uygulanmaz:

a) Kişisel veri işlemenin suç işlenmesinin önlenmesi veya suç soruşturması için gerekli olması.

b) İlgili kişinin kendisi tarafından alenileştirilmiş kişisel verilerin işlenmesi.

c) Kişisel veri işlemenin kanunun verdiği yetkiye dayanılarak görevli ve yetkili kamu kurum ve kuruluşları ile kamu kurumu niteliğindeki meslek kuruluşlarınca, denetleme veya düzenleme görevlerinin yürütülmesi ile disiplin soruşturma veya kovuşturması için gerekli olması.

ç) Kişisel veri işlemenin bütçe, vergi ve mali konulara ilişkin olarak Devletin ekonomik ve mali çıkarlarının korunması için gerekli olması.

Article 29Budget and revenues of the Authority

Link to this article ↗

(1) The budget of the Authority shall be prepared and adopted in accordance with the procedures and principles set out in Law No. 5018.

(2) The revenues of the Authority are as follows:

a) Treasury aid to be provided from the general budget.

b) Revenues obtained from movable and immovable property belonging to the Authority.

c) Donations and aid received.

ç) Revenues obtained from the investment of its revenues.

d) Other revenues.

Original Turkish text

MADDE 29 · Kurumun bütçesi ve gelirleri

(1) Kurumun bütçesi, 5018 sayılı Kanunda belirlenen usul ve esaslara göre hazırlanır ve kabul edilir.

(2) Kurumun gelirleri şunlardır:

a) Genel bütçeden yapılacak hazine yardımları.

b) Kuruma ait taşınır ve taşınmazlardan elde edilen gelirler.

c) Alınan bağış ve yardımlar.

ç) Gelirlerinin değerlendirilmesinden elde edilen gelirler.

d) Diğer gelirler.

Article 30Amended and added provisions

Link to this article ↗

(1) Relates to Law No. 5018 of 10/12/2003 and has been incorporated into its place.

(2) to (5): Relate to Law No. 5237 of 26/9/2004 and have been incorporated into their places.

(6) Relates to the Basic Law on Health Services No. 3359 of 7/5/1987 and has been incorporated into its place.

(7) Relates to the Decree Having the Force of Law No. 663 of 11/10/2011 on the Organisation and Duties of the Ministry of Health and Its Affiliated Institutions and has been incorporated into its place.

Original Turkish text

MADDE 30 · Değiştirilen ve eklenen hükümler

(1) (10/12/2003 tarihli ve 5018 sayılı Kanun ile ilgili olup yerine işlenmiştir.)

(2) ila (5) - (26/9/2004 tarihli ve 5237 sayılı Kanun ile ilgili olup yerine işlenmiştir.)

(6) (7/5/1987 tarihli ve 3359 sayılı Sağlık Hizmetleri Temel Kanunu ile ilgili olup yerine işlenmiştir.)

(7) (11/10/2011 tarihli ve 663 sayılı Sağlık Bakanlığı ve Bağlı Kuruluşlarının Teşkilat ve Görevleri Hakkında Kanun Hükmünde Kararname ile ilgili olup yerine işlenmiştir.)

Article 31Regulations

Link to this article ↗

(1) Regulations concerning the implementation of this Law shall be put into force by the Authority.

Original Turkish text

MADDE 31 · Yönetmelik

(1) Bu Kanunun uygulanmasına ilişkin yönetmelikler Kurum tarafından yürürlüğe konulur.

Provisional Article 1Transitional provisions

Link to this article ↗

(1) Within six months from the date of publication of this Law, the members of the Board shall be elected in accordance with the procedure provided for in Article 21 and the organisation of the Presidency shall be established.

(2) Data controllers shall be obliged to register with the Data Controllers Registry within the period determined and announced by the Board.

(3) Personal data processed before the date of publication of this Law shall be brought into conformity with the provisions of this Law within two years from the date of publication. Personal data found to be contrary to the provisions of this Law shall be erased, destroyed or anonymised forthwith. However, consents lawfully obtained before the date of publication of this Law shall be deemed to be in conformity with this Law unless a declaration of intent to the contrary is made within one year.

(4) The regulations provided for in this Law shall be put into force within one year from the date of publication of this Law.

(5) Within one year from the date of publication of this Law, a senior executive shall be designated in public institutions and organisations to ensure coordination relating to the implementation of this Law and shall be notified to the Presidency.

(6) The President, the Second President and two members determined by drawing lots among those first elected shall serve for six years; the other five members shall serve for four years.

(7) Until a budget is allocated to the Authority;

a) The expenses of the Authority shall be covered from the budget of the Prime Ministry.

b) All necessary support services, such as buildings, vehicles, equipment, furnishings and hardware, for the Authority to carry out its services shall be provided by the Prime Ministry.

(8) Until the service units of the Authority become operational, secretariat services shall be carried out by the Prime Ministry.

Original Turkish text

GEÇİCİ MADDE 1 · Geçiş hükümleri

(1) Bu Kanunun yayımı tarihinden itibaren altı ay içinde 21 inci maddede öngörülen usule göre Kurul üyeleri seçilir ve Başkanlık teşkilatı oluşturulur.

(2) Veri sorumluları, Kurul tarafından belirlenen ve ilan edilen süre içinde Veri Sorumluları Siciline kayıt yaptırmak zorundadır.

(3) Bu Kanunun yayımı tarihinden önce işlenmiş olan kişisel veriler, yayımı tarihinden itibaren iki yıl içinde bu Kanun hükümlerine uygun hâle getirilir. Bu Kanun hükümlerine aykırı olduğu tespit edilen kişisel veriler derhâl silinir, yok edilir veya anonim hâle getirilir. Ancak bu Kanunun yayımı tarihinden önce hukuka uygun olarak alınmış rızalar, bir yıl içinde aksine bir irade beyanında bulunulmaması hâlinde, bu Kanuna uygun kabul edilir.

(4) Bu Kanunda öngörülen yönetmelikler bu Kanunun yayımı tarihinden itibaren bir yıl içinde yürürlüğe konulur.

(5) Bu Kanunun yayımı tarihinden itibaren bir yıl içinde, kamu kurum ve kuruluşlarında bu Kanunun uygulanmasıyla ilgili koordinasyonu sağlamak üzere üst düzey bir yönetici belirlenerek Başkanlığa bildirilir.

(6) İlk seçilen Başkan, İkinci Başkan ve kura ile belirlenen iki üye altı yıl; diğer beş üye ise dört yıl görev yapar.

(7) Kuruma bütçe tahsis edilene kadar;

a) Kurumun giderleri Başbakanlık bütçesinden karşılanır.

b) Kurumun hizmetlerini yerine getirmesi amacıyla bina, araç, gereç, mefruşat ve donanım gibi gerekli tüm destek hizmetleri Başbakanlıkça sağlanır.

(8) Kurumun hizmet birimleri faaliyete geçinceye kadar sekretarya hizmetleri Başbakanlık tarafından yerine getirilir.

Provisional Article 2

Link to this article ↗

Added: 28/11/2017, Law No. 7061, Art. 120

(1) Persons who have graduated from faculties of political science, economic and administrative sciences, economics, law and business administration providing at least four years of undergraduate education, from the electronics, electrical and electronics, electronics and communications, computer, or information systems engineering departments of engineering faculties, or from domestic or foreign higher education institutions whose equivalence to these has been accepted by the Council of Higher Education; who have been appointed to positions in the central organisations of institutions relating to the titles specified in subparagraph (11) of paragraph (A) of the section entitled "Common Provisions" of Article 36 of Law No. 657, entry into which is made through a special competitive examination for the profession and following in-service training of a specified duration and a special proficiency examination, and who have served in these positions for at least two years excluding periods of unpaid leave, as well as persons holding faculty member positions, may be appointed as Personal Data Protection Experts within one year from the date of entry into force of this Article, provided that they have obtained a score of at least seventy in the Foreign Language Proficiency Examination and have not reached the age of forty as of the date of appointment. The number of persons to be appointed in this manner may not exceed fifteen.

Original Turkish text

GEÇİCİ MADDE 2

(Ek:28/11/2017-7061/120 md.)

(1) En az dört yıllık lisans öğrenimi veren siyasal bilgiler, iktisadi ve idari bilimler, iktisat, hukuk ve işletme fakültelerinden, mühendislik fakültelerinin elektronik, elektrik-elektronik, elektronik ve haberleşme, bilgisayar, bilişim sistemleri mühendisliği bölümlerinden ya da bunlara denkliği Yükseköğretim Kurulu tarafından kabul edilen yurt içi ve yurt dışındaki yükseköğrenim kurumlarından mezun olanlardan; mesleğe özel yarışma sınavı ile girilen ve belirli süreli meslek içi eğitimden ve özel bir yeterlik sınavından sonra 657 sayılı Kanunun 36 ncı maddesinin “Ortak Hükümler” başlıklı bölümünün (A) fıkrasının (11) numaralı bendinde belirtilen unvanlara ilişkin kurumların merkez teşkilatlarına ait kadrolara atanmış ve bu kadrolarda aylıksız izin süreleri hariç en az iki yıl bulunmuş olanlar ile öğretim üyesi kadrolarında bulunanlar, Yabancı Dil Bilgisi Seviye Tespit Sınavından en az yetmiş puan almış olmak ve atama tarihi itibarıyla kırk yaşından gün almamış olmak kaydıyla, bu maddenin yürürlüğe girdiği tarihten itibaren bir yıl içinde Kişisel Verileri Koruma Uzmanı olarak atanabilirler. Bu şekilde atanacakların sayısı on beşi geçemez.

Provisional Article 3

Link to this article ↗

Added: 2/3/2024, Law No. 7499, Art. 36

(1) Paragraph 1 of Article 9, as it stood before being amended by the Law establishing this Article, shall continue to apply, together with the amended version of the Article that has entered into force, until 1/9/2024.

(2) Applications pending before criminal judgeships of peace as of 1/6/2024 shall continue to be heard by those judgeships.

Original Turkish text

GEÇİCİ MADDE 3

(Ek:2/3/2024-7499/36 md.)

(1) 9 uncu maddenin bu maddeyi ihdas eden Kanunla değiştirilmeden önceki birinci fıkrası, maddenin yürürlüğe giren değişik haliyle birlikte 1/9/2024 tarihine kadar uygulanmaya devam olunur.

(2) 1/6/2024 tarihi itibarıyla sulh ceza hâkimliklerinde görülmekte olan başvurular, bu hâkimliklerce görülmeye devam olunur.

Article 32Entry into force

Link to this article ↗

(1) Of this Law:

a) Articles 8, 9, 11, 13, 14, 15, 16, 17 and 18 shall enter into force six months after the date of its publication,

b) The other articles shall enter into force on the date of its publication,

as set out above.

Original Turkish text

MADDE 32 · Yürürlük

(1) Bu Kanunun;

a) 8 inci, 9 uncu, 11 inci, 13 üncü, 14 üncü, 15 inci, 16 ncı, 17 nci ve 18 inci maddeleri yayımı tarihinden altı ay sonra,

b) Diğer maddeleri ise yayımı tarihinde,

yürürlüğe girer.

Article 33Execution

Link to this article ↗

(1) The provisions of this Law shall be executed by the Council of Ministers.

SCHEDULE (I)

STAFF POSITIONS LIST OF THE PERSONAL DATA PROTECTION AUTHORITY

CLASS

TITLE

GRADE

TOTAL

General Administrative Services

Vice President

1

1

General Administrative Services

Head of Department

1

7

General Administrative Services

Legal Counsel

1

1

General Administrative Services

Legal Counsel

3

3

Legal Services

Attorney

6

4

General Administrative Services

Personal Data Protection Expert

5

10

General Administrative Services

Personal Data Protection Expert

7

20

General Administrative Services

Assistant Personal Data Protection Expert

9

60

General Administrative Services

Financial Services Expert

6

2

General Administrative Services

Assistant Financial Services Expert

9

2

General Administrative Services

Civil Servant (Clerk)

5

5

General Administrative Services

Civil Servant (Clerk)

7

5

General Administrative Services

Civil Servant (Clerk)

9

5

General Administrative Services

Civil Servant (Clerk)

11

5

General Administrative Services

Civil Servant (Clerk)

13

5

General Administrative Services

Computer Operator

7

5

General Administrative Services

Data Preparation and Control Operator

6

5

General Administrative Services

Data Preparation and Control Operator

7

5

General Administrative Services

Data Preparation and Control Operator

8

5

General Administrative Services

Data Preparation and Control Operator

9

5

General Administrative Services

Data Preparation and Control Operator

10

5

General Administrative Services

Secretary

5

3

General Administrative Services

Secretary

8

7

General Administrative Services

Switchboard Operator

9

1

General Administrative Services

Driver

11

4

Technical Services

Technician

6

3

Auxiliary Services

Assistant Technician

9

2

Auxiliary Services

Attendant

11

10

TOTAL

195

Original Turkish text

MADDE 33 · Yürütme

(1) Bu Kanun hükümlerini Bakanlar Kurulu yürütür.

(I) SAYILI CETVEL

KİŞİSEL VERİLERİ KORUMA KURUMU KADRO LİSTESİ

SINIF

UNVAN

DERECE

TOPLAM

GİH

Başkan Yardımcısı

1

1

GİH

Daire Başkanı

1

7

GİH

Hukuk Müşaviri

1

1

GİH

Hukuk Müşaviri

3

3

AH

Avukat

6

4

GİH

Kişisel Verileri Koruma Uzmanı

5

10

GİH

Kişisel Verileri Koruma Uzmanı

7

20

GİH

Kişisel Verileri Koruma Uzman Yardımcısı

9

60

GİH

Mali Hizmetler Uzmanı

6

2

GİH

Mali Hizmetler Uzman Yardımcısı

9

2

GİH

Memur

5

5

GİH

Memur

7

5

GİH

Memur

9

5

GİH

Memur

11

5

GİH

Memur

13

5

GİH

Bilgisayar İşletmeni

7

5

GİH

Veri Hazırlama ve Kontrol İşletmeni

6

5

GİH

Veri Hazırlama ve Kontrol İşletmeni

7

5

GİH

Veri Hazırlama ve Kontrol İşletmeni

8

5

GİH

Veri Hazırlama ve Kontrol İşletmeni

9

5

GİH

Veri Hazırlama ve Kontrol İşletmeni

10

5

GİH

Sekreter

5

3

GİH

Sekreter

8

7

GİH

Santral Memuru

9

1

GİH

Şoför

11

4

TH

Teknisyen

6

3

YH

Teknisyen Yardımcısı

9

2

YH

Hizmetli

11

10

TOPLAM

195

No article matches your search.

Unofficial translation for information only. The Turkish text published in the Official Gazette is the only authoritative version. This page is not legal advice.