Although information security usually comes to mind when it comes to "protection of personal data", in fact the scope of this term is quite wide. The Law on Protection of Personal Data, which affects not only information security but also the functioning of different areas such as marketing and advertising, was published in the Official Gazette, albeit a little late, and entered into force since 2016. So, what is KVKK that we constantly encounter on the internet?
The law that ensures that the data is processed with clear boundaries and thus the fundamental rights and freedoms of the person are protected, is called the Personal Data Protection Law. The law, which was adopted in March 2016 and entered into force in April of the same year, aims to prevent individuals or institutions from recording, sharing or using other people's personal information without permission. Accordingly, those who violate the articles of KVKK can be given various penalties, from fines to imprisonment.
Although the first thing that comes to mind when talking about KVKK is to prevent the theft of personal data, in fact the relevant law has a much wider scope. For example, a website that you are a member of by giving you a lot of information from your address to your phone number cannot receive your information without permission thanks to KVKK, nor can it be used to send you promotional SMS, spam mails or promotional brochures to your address.
Why is the Law on Protection of Personal Data Important?
KVKK is a law that protects fundamental rights and freedoms, especially the privacy of private life. Although the acceleration of digitalization accelerates and normalizes personal data sharing, the haphazard use of this data is also extremely important in terms of data security. Because unwanted situations such as sharing the collected data with third parties and its malicious use can be experienced frequently all over the world. Here, KVKK steps in to protect both fundamental rights and freedoms and data security.
Until recently, it was quite normal to transfer all the data we shared with websites to different companies and as a result, to receive promotional messages and e-mails constantly. However, with the KVKK, you no longer have to share your data with websites, even if you do, it is illegal to use your information for sales, marketing, advertising or other purposes. With the KVKK, a telecommunications company, e-commerce site or other organization will now be able to receive only the information they need from you with your consent and use this information only for the purpose of providing services to you. Otherwise, many sanctions from imprisonment to fine may be imposed on the relevant organization on the grounds that it violates the Personal Data Protection Law.
What are the Penalties of the Personal Data Protection Law?
Administrative fines to be imposed on those who do not fulfill their obligations under the KVKK are as follows:
- Fines between 5.000 and 100.000 TL for those who do not fulfill their lighting obligation.
- Fines between 15.000 and 1.000.000 TL for those who do not fulfill their obligations regarding data security.
- Fines between 25.000 TL and 1.000.000 TL for those who do not fulfill the decisions made by the Board.
- Fines between 20.000 and 1.000.000 TL for those who violate the registration and notification obligations of the Data Controllers Registry
The Turkish Penal Code penalties to be given to those who do not fulfill their obligations under the KVKK are as follows:
- 1 to 3 years of imprisonment for those who unlawfully record personal data
- 2 to 4 years of imprisonment for those who unlawfully obtain and disseminate personal data
- Those who continue to keep personal data outside of the period specified by the laws and those who do not delete them, are sentenced to 1 to 2 years in prison.