Turkish Law in EnglishTÜRKİYE
Law on the Protection of Personal Data

Article 12: Obligations relating to data security

Chapter Three: Rights and Obligations

(1) The data controller shall, in order to:

a) Prevent the unlawful processing of personal data,

b) Prevent unlawful access to personal data,

c) Ensure the retention of personal data,

be obliged to take all necessary technical and administrative measures to ensure an appropriate level of security.

(2) Where personal data are processed by another natural or legal person on behalf of the data controller, the data controller shall be jointly liable with such persons for taking the measures specified in paragraph 1.

(3) The data controller shall be obliged to carry out, or have carried out, the necessary audits within its own institution or organisation in order to ensure the implementation of the provisions of this Law.

(4) Data controllers and data processors shall not disclose personal data that they have learned to others in breach of the provisions of this Law, nor use such data for purposes other than processing. This obligation shall continue after they leave office.

(5) Where processed personal data are obtained by others by unlawful means, the data controller shall notify the data subject and the Board of this situation as soon as possible. The Board may, where necessary, announce this situation on its own website or by any other method it deems appropriate.

Original Turkish text

MADDE 12 · Veri güvenliğine ilişkin yükümlülükler

(1) Veri sorumlusu;

a) Kişisel verilerin hukuka aykırı olarak işlenmesini önlemek,

b) Kişisel verilere hukuka aykırı olarak erişilmesini önlemek,

c) Kişisel verilerin muhafazasını sağlamak,

amacıyla uygun güvenlik düzeyini temin etmeye yönelik gerekli her türlü teknik ve idari tedbirleri almak zorundadır.

(2) Veri sorumlusu, kişisel verilerin kendi adına başka bir gerçek veya tüzel kişi tarafından işlenmesi hâlinde, birinci fıkrada belirtilen tedbirlerin alınması hususunda bu kişilerle birlikte müştereken sorumludur.

(3) Veri sorumlusu, kendi kurum veya kuruluşunda, bu Kanun hükümlerinin uygulanmasını sağlamak amacıyla gerekli denetimleri yapmak veya yaptırmak zorundadır.

(4) Veri sorumluları ile veri işleyen kişiler, öğrendikleri kişisel verileri bu Kanun hükümlerine aykırı olarak başkasına açıklayamaz ve işleme amacı dışında kullanamazlar. Bu yükümlülük görevden ayrılmalarından sonra da devam eder.

(5) İşlenen kişisel verilerin kanuni olmayan yollarla başkaları tarafından elde edilmesi hâlinde, veri sorumlusu bu durumu en kısa sürede ilgilisine ve Kurula bildirir. Kurul, gerekmesi hâlinde bu durumu, kendi internet sitesinde ya da uygun göreceği başka bir yöntemle ilan edebilir.

Text as of 1 October 2026 · Official source (Turkish): mevzuat.gov.tr ↗

Unofficial translation for information only. The Turkish text published in the Official Gazette is the only authoritative version. This page is not legal advice.