Turkish Law in EnglishTÜRKİYE
Law on the Protection of Personal Data

Article 22: Duties and powers of the Board

Chapter Six: Personal Data Protection Authority and Organisation

(1) The duties and powers of the Board are as follows:

a) To ensure that personal data are processed in accordance with fundamental rights and freedoms.

b) To decide on the complaints of those who claim that their rights relating to personal data have been violated.

c) Upon complaint, or ex officio where it learns of an alleged violation, to examine, on matters falling within its field of duty, whether personal data are processed in accordance with the law, and to take interim measures in this respect where necessary.

ç) To determine the adequate measures required for the processing of special categories of personal data.

d) To ensure that the Data Controllers Registry is kept.

e) To carry out the necessary regulatory acts on matters relating to the Board's field of duty and the functioning of the Authority.

f) To carry out regulatory acts for the purpose of determining the obligations relating to data security.

g) To carry out regulatory acts concerning the duties, powers and responsibilities of the data controller and its representative.

ğ) To decide on the administrative sanctions provided for in this Law.

h) To give opinions on draft legislation prepared by other institutions and organisations that contain provisions relating to personal data.

ı) To decide on the strategic plan of the Authority and to determine its aims and objectives, service quality standards and performance criteria.

i) To discuss and decide on the budget proposal prepared in accordance with the strategic plan and the aims and objectives of the Authority.

j) To approve and publish the draft reports prepared on the performance, financial situation and annual activities of the Authority and on matters as needed.

k) To discuss and decide on proposals concerning the purchase, sale and lease of immovable property.

l) To perform the other duties assigned by law.

Original Turkish text

MADDE 22 · Kurulun görev ve yetkileri

(1) Kurulun görev ve yetkileri şunlardır:

a) Kişisel verilerin, temel hak ve özgürlüklere uygun şekilde işlenmesini sağlamak.

b) Kişisel verilerle ilgili haklarının ihlal edildiğini ileri sürenlerin şikâyetlerini karara bağlamak.

c) Şikâyet üzerine veya ihlal iddiasını öğrenmesi durumunda resen görev alanına giren konularda kişisel verilerin kanunlara uygun olarak işlenip işlenmediğini incelemek ve gerektiğinde bu konuda geçici önlemler almak.

ç) Özel nitelikli kişisel verilerin işlenmesi için aranan yeterli önlemleri belirlemek.

d) Veri Sorumluları Sicilinin tutulmasını sağlamak.

e) Kurulun görev alanı ile Kurumun işleyişine ilişkin konularda gerekli düzenleyici işlemleri yapmak.

f) Veri güvenliğine ilişkin yükümlülükleri belirlemek amacıyla düzenleyici işlem yapmak.

g) Veri sorumlusunun ve temsilcisinin görev, yetki ve sorumluluklarına ilişkin düzenleyici işlem yapmak.

ğ) Bu Kanunda öngörülen idari yaptırımlara karar vermek.

h) Diğer kurum ve kuruluşlarca hazırlanan ve kişisel verilere ilişkin hüküm içeren mevzuat taslakları hakkında görüş bildirmek.

ı) Kurumun; stratejik planını karara bağlamak, amaç ve hedeflerini, hizmet kalite standartlarını ve performans kriterlerini belirlemek.

i) Kurumun stratejik planı ile amaç ve hedeflerine uygun olarak hazırlanan bütçe teklifini görüşmek ve karara bağlamak.

j) Kurumun performansı, mali durumu, yıllık faaliyetleri ve ihtiyaç duyulan konular hakkında hazırlanan rapor taslaklarını onaylamak ve yayımlamak.

k) Taşınmaz alımı, satımı ve kiralanması konularındaki önerileri görüşüp karara bağlamak.

l) Kanunlarla verilen diğer görevleri yerine getirmek.

Text as of 1 October 2026 · Official source (Turkish): mevzuat.gov.tr ↗

Unofficial translation for information only. The Turkish text published in the Official Gazette is the only authoritative version. This page is not legal advice.