<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.4 20241031//EN"
        "https://jats.nlm.nih.gov/publishing/1.4/JATS-journalpublishing1-4.dtd">
<article  article-type="other"        dtd-version="1.4">
            <front>

                <journal-meta>
                                    <journal-id></journal-id>
            <journal-title-group>
                                                                                    <journal-title>Kişisel Verileri Koruma Dergisi</journal-title>
            </journal-title-group>
                            <issn pub-type="ppub">2667-6524</issn>
                                        <issn pub-type="epub">2667-8918</issn>
                                                                                            <publisher>
                    <publisher-name>Kişisel Verileri Koruma Kurumu</publisher-name>
                </publisher>
                    </journal-meta>
                <article-meta>
                                        <article-id/>
                                                                <article-categories>
                                            <subj-group  xml:lang="en">
                                                            <subject>Privacy and Data Rights</subject>
                                                    </subj-group>
                                            <subj-group  xml:lang="tr">
                                                            <subject>Kişisel Veriler ve Gizlilik</subject>
                                                    </subj-group>
                                    </article-categories>
                                                                                                                                                        <title-group>
                                                                                                                        <article-title>Comparative Analysis of the European Union and Turkish Personal Data Protection Laws: Basic Principles, Legal Grounds, and Rights of Data Subjects</article-title>
                                                                                                                                                                                                <trans-title-group xml:lang="tr">
                                    <trans-title>Avrupa Birliği ve Türkiye Kişisel Verilerin Korunması Kanunlarının Karşılaştırmalı Analizi: Temel İlkeler, Yasal Dayanaklar ve İlgili Kişi Hakları</trans-title>
                                </trans-title-group>
                                                                                                    </title-group>
            
                                                    <contrib-group content-type="authors">
                                                                        <contrib contrib-type="author">
                                                                    <contrib-id contrib-id-type="orcid">
                                        https://orcid.org/0009-0008-4205-7538</contrib-id>
                                                                <name>
                                    <surname>Evren</surname>
                                    <given-names>Adife Gül</given-names>
                                </name>
                                                            </contrib>
                                                                                </contrib-group>
                        
                                        <pub-date pub-type="pub" iso-8601-date="20231229">
                    <day>12</day>
                    <month>29</month>
                    <year>2023</year>
                </pub-date>
                                        <volume>5</volume>
                                        <issue>2</issue>
                                        <fpage>39</fpage>
                                        <lpage>64</lpage>
                        
                        <history>
                                    <date date-type="received" iso-8601-date="20231218">
                        <day>12</day>
                        <month>18</month>
                        <year>2023</year>
                    </date>
                                                    <date date-type="accepted" iso-8601-date="20231225">
                        <day>12</day>
                        <month>25</month>
                        <year>2023</year>
                    </date>
                            </history>
                                        <permissions>
                    <copyright-statement>Copyright © 2019, Kişisel Verileri Koruma Dergisi</copyright-statement>
                    <copyright-year>2019</copyright-year>
                    <copyright-holder>Kişisel Verileri Koruma Dergisi</copyright-holder>
                </permissions>
            
                                                                                                <abstract><p>This study provides a brief overview of the European General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law (KVKK), specifically examining their similarities and differences in terms of fundamental principles governing data processing, legal grounds for personal data processing, including for processing special categories of personal data, and the rights of data subjects. While a significant alignment is observed between the two regulations regarding fundamental principles, the study highlights differences, particularly in certain data processing conditions and regulations pertaining to the rights of relevant parties. It is noted that the coherence observed between the two legislations is also attributed to the proactive efforts of the Turkish Personal Data Protection Authority. In conclusion, despite disparities between the two legislations, the study underscores the commitment of Turkish authorities to ensure full compliance with the GDPR and asserts that comprehensive compliance can be attained through a holistic approach.</p></abstract>
                                                                                                                                    <trans-abstract xml:lang="tr">
                            <p>Bu çalışma, Avrupa Genel Veri Koruma Tüzüğü (GDPR) ve Türk Kişisel Verilerin Korunması Kanunu&#039;nun (KVKK) veri işlemeye halim olan temel ilkeler, özel nitelikli kişisel veriler için belirlenenler dahil olmak üzere temel veri işleme şartları ve veri sahiplerinin hakları yönünden benzerlik ve farklılıklarına odaklanarak kısa bir inceleme gerçekleştirmektedir. Temel ilkelerde iki düzenleme arasında önemli bir uyumun varlığı sergilenirken, özellikle bazı veri işleme şartları ve ilgili tarafların haklarına odaklanan düzenlemelerde farklılar üzerinde durulmaktadır. Bununla beraber, iki mevzuat arasında gözlemlenen uyumluluğun aynı zamanda Türkiye Kişisel Verileri Koruma Kurumu&#039;nun proaktif çabalarına dayandığı belirtilmektedir. Son olarak, her ne kadar iki mevzuat arasında farklılıklar bulunsa da, bu çalışma, Türk yetkililerin GDPR ile tam uyumluluğu sağlama konusundaki kararlılığını vurgulayarak bütünsel bir yaklaşımla tam uyumun sağlanabileceğini ifade eder.</p></trans-abstract>
                                                            
            
                                                            <kwd-group>
                                                    <kwd>GDPR</kwd>
                                                    <kwd>  KVKK</kwd>
                                                    <kwd>  personal data protection</kwd>
                                                    <kwd>  basic principles</kwd>
                                                    <kwd>  legal grounds</kwd>
                                                    <kwd>  data subject rights</kwd>
                                                    <kwd>  comparative analysis</kwd>
                                            </kwd-group>
                                                        
                                                                            <kwd-group xml:lang="tr">
                                                    <kwd>KVKK</kwd>
                                                    <kwd>  GDPR</kwd>
                                                    <kwd>  kişisel evrilerin korunması</kwd>
                                                    <kwd>  temel ilkeler</kwd>
                                                    <kwd>  veri işleme şartları</kwd>
                                                    <kwd>  ilgili kişi hakları</kwd>
                                                    <kwd>  karşılaştırmalı analiz</kwd>
                                            </kwd-group>
                                                                                                            </article-meta>
    </front>
    <back>
                            <ref-list>
                                    <ref id="ref1">
                        <label>1</label>
                        <mixed-citation publication-type="journal">Açık Rıza | Kişisel Verileri Koruma Kurumu. (n.d.). Retrieved from https://kvkk.gov.tr/yayinlar/A%C3%87IK%20RIZA.pdf</mixed-citation>
                    </ref>
                                    <ref id="ref2">
                        <label>2</label>
                        <mixed-citation publication-type="journal">Açık Rıza Alırken Dikkat Edilecek Hususlar | Kişisel Verileri Koruma Kurumu. (n.d.). Retrieved from https://www.kvkk.gov.tr/Icerik/2037/Acik-Riza-Alirken-Dikkat-Edilecek-Hususlar</mixed-citation>
                    </ref>
                                    <ref id="ref3">
                        <label>3</label>
                        <mixed-citation publication-type="journal">Alenileştirme” Hakkında Kamuoyu Duyurusu | Kişisel Verileri Koruma Kurumu. (2020). Retrieved from https://www.kvkk.gov.tr/Icerik/6843/-ALENILESTIRME-HAKKINDA-KAMUOYU-DUYURUSU</mixed-citation>
                    </ref>
                                    <ref id="ref4">
                        <label>4</label>
                        <mixed-citation publication-type="journal">Are there any exceptions? (n.d.). Retrieved from https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/the-right-to-be-informed/are-there-any-exceptions/#id4</mixed-citation>
                    </ref>
                                    <ref id="ref5">
                        <label>5</label>
                        <mixed-citation publication-type="journal">Ausloos, J. (2020, January 1). The Right to Erasure in EU Data Protection Law. http://books.google.ie/books?id=eYyjzQEACAAJ&amp;dq=The+Right+to+Erasure++in+EU+Data++Protection+Law&amp;hl=&amp;cd=1&amp;source=gbs_api</mixed-citation>
                    </ref>
                                    <ref id="ref6">
                        <label>6</label>
                        <mixed-citation publication-type="journal">Besemer, L. (2020). PRIVACY AND DATA PROTECTION. Retrieved from http://books.google.ie/books?id=ZMTXzQEACAAJ&amp;dq=Privacy+and+Data+Protection+based+on+the+GDPR&amp;hl=&amp;cd=2&amp;source=gbs_api</mixed-citation>
                    </ref>
                                    <ref id="ref7">
                        <label>7</label>
                        <mixed-citation publication-type="journal">Bilir F. (2020). The Review of 6698 Numbered Personal Data Protection Law and Protection of Personal Data in the Internet Age. Anayasa Yargısı, Cilt: 37, Sayı: 2, s.305–342. Retrieved from https://ayam.anayasa.gov.tr/media/6686/04_faruk_bilir.pdf</mixed-citation>
                    </ref>
                                    <ref id="ref8">
                        <label>8</label>
                        <mixed-citation publication-type="journal">Binding Decision 3/2022 on the dispute submitted by the Irish SA on Meta Platforms Ireland Limited and its Facebook service (Art. 65 GDPR) | European Data Protection Board. (n.d.). Retrieved from https://edpb.europa.eu/our-work-tools/our-documents/binding-decision-board-art-65/binding-decision-32022-dispute-submitted_en</mixed-citation>
                    </ref>
                                    <ref id="ref9">
                        <label>9</label>
                        <mixed-citation publication-type="journal">Case C 487/21 (2023) Österreichische Datenschutzbehörde, v. CRIF GmbH</mixed-citation>
                    </ref>
                                    <ref id="ref10">
                        <label>10</label>
                        <mixed-citation publication-type="journal">Case C 579/21 (2023) J.M. v. Apulaistietosuojavaltuutettu, Pankki S</mixed-citation>
                    </ref>
                                    <ref id="ref11">
                        <label>11</label>
                        <mixed-citation publication-type="journal">Communique on Principles and Procedures to Be Followed in Fulfillment of the Obligation to Inform | Kişisel Verileri Koruma Kurumu. (2018). Retrieved from https://www.kvkk.gov.tr/Icerik/6637/Communique-On-Principles-And-Procedures-To-Be-Followed-In-Fullfillment-Of-The-Obligation-To-Inform</mixed-citation>
                    </ref>
                                    <ref id="ref12">
                        <label>12</label>
                        <mixed-citation publication-type="journal">Develioğlu M.(2017). 6698 sayılı Kişisel Verilerin Korunması Kanunu ile Karşılaştırmalı Olarak Avrupa Birliği Genel Veri Koruma Tüzüğü Uyarınca Kişisel Verilerin Korunması Hukuku. İstanbul: On İki Levha Yayıncılık.</mixed-citation>
                    </ref>
                                    <ref id="ref13">
                        <label>13</label>
                        <mixed-citation publication-type="journal">Dienst S.(2017). Lawful processing of personal data in companies under the GDPR. D. Rücker &amp;T. Kugler (Eds.). New European General Data Protection Regulation: A Practitioner&#039;s Guide (pp.49-103)</mixed-citation>
                    </ref>
                                    <ref id="ref14">
                        <label>14</label>
                        <mixed-citation publication-type="journal">Doğru Bilinen Yanlışlar 2 | Kişisel Verileri Koruma Kurumu. (n.d.) Retrieved from https://www.kvkk.gov.tr/Icerik/7151/6698-Sayili-Kisisel-Verilerin-Korunmasi-Kanunu-Hakkinda-Dogru-Bilinen-Yanlislar-2</mixed-citation>
                    </ref>
                                    <ref id="ref15">
                        <label>15</label>
                        <mixed-citation publication-type="journal">Europe, C. O., &amp; Rights, E. U. A. F. F. (2018). Handbook on European data protection law. Council of Europe. Retrieved from http://books.google.ie/books?id=X_OFDwAAQBAJ&amp;pg=PP2&amp;dq=978-92-871-9849-5&amp;hl=&amp;cd=1&amp;source=gbs_api</mixed-citation>
                    </ref>
                                    <ref id="ref16">
                        <label>16</label>
                        <mixed-citation publication-type="journal">Guidelines on Data Protection Officers (&#039;DPOs&#039;) | Article29 Working Party. (2017). Retrieved from https://ec.europa.eu/newsroom/article29/items/612048</mixed-citation>
                    </ref>
                                    <ref id="ref17">
                        <label>17</label>
                        <mixed-citation publication-type="journal">Han, I. A., Kişisel Verilerin İşlenmesi Bağlamında Hukuka Uygunluk Sebebi Olarak Veri Sahibinin Rızası, Galatasaray Üniversitesi Hukuk Fakültesi Dergisi, 18(1), 417-459</mixed-citation>
                    </ref>
                                    <ref id="ref18">
                        <label>18</label>
                        <mixed-citation publication-type="journal">Kaya, M. B. (2021). The New Paradigm of Data Protection Law: The Principle of Accountability. İstanbul Hukuk Mecmuası. https://doi.org/10.26650/mecmua.2020.78.4.0005</mixed-citation>
                    </ref>
                                    <ref id="ref19">
                        <label>19</label>
                        <mixed-citation publication-type="journal">Kişisel Veri İşleme Şartları | Kişisel Verileri Koruma Kurumu. (n.d.).  Retrieved from https://www.kvkk.gov.tr/Icerik/4190/Kisisel-Verilerin-Islenme-Sartlari</mixed-citation>
                    </ref>
                                    <ref id="ref20">
                        <label>20</label>
                        <mixed-citation publication-type="journal">Madde ve Gerekçesi ile Kişisel Verilerin Korunması Kanunu | Kişisel Verileri Koruma Kurumu. (2019). Retrieved from https://www.kvkk.gov.tr/Icerik/5388/Madde-ve-Gerekcesi-ile-Kisisel-Verilerin-Korunmasi-Kanunu-Bilgi-Notu-ve-Kisisel-Verilerin-Korunmasina-Iliskin-Terimler-Sozlugu</mixed-citation>
                    </ref>
                                    <ref id="ref21">
                        <label>21</label>
                        <mixed-citation publication-type="journal">Opinion 06/2014 on the &quot;Notion of legitimate interests of the data controller under Article 7 of Directive 95/46/EC&quot; | Article 29 Data Protection Working Party (n.d.), https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2014/wp217_en.pdf</mixed-citation>
                    </ref>
                                    <ref id="ref22">
                        <label>22</label>
                        <mixed-citation publication-type="journal">Özel Nitelikli Kişisel Verilerin İşlenme Şartları | Kişisel Verileri Koruma Kurulu.(n.d.). Retrieved from https://www.kvkk.gov.tr/Icerik/5238/Ozel-Nitelikli-Kisisel-Verilerin-Islenme-Sartlari</mixed-citation>
                    </ref>
                                    <ref id="ref23">
                        <label>23</label>
                        <mixed-citation publication-type="journal">Press Release No 158/22 |Court of Justice of the European Union”, 2022, https://curia.europa.eu/jcms/upload/docs/application/pdf/2022-09/cp220158en.pdf</mixed-citation>
                    </ref>
                                    <ref id="ref24">
                        <label>24</label>
                        <mixed-citation publication-type="journal">Rücker, D., &amp; Kugler, T. (2017). New European General Data Protection Regulation. Nomos/Hart. Retrieved from http://books.google.ie/books?id=Ru7pswEACAAJ&amp;dq=Tobias+Kugler&amp;hl=&amp;cd=1&amp;source=gbs_api</mixed-citation>
                    </ref>
                                    <ref id="ref25">
                        <label>25</label>
                        <mixed-citation publication-type="journal">Sıkça Sorulan Sorular | Kişisel Verileri Koruma Kurumu. (2019). Retrieved from https://www.kvkk.gov.tr/Icerik/4196/Kisisel-Verilerin-Korunmasi-Kanunu-Hakkinda-Sikca-Sorulan-Sorular</mixed-citation>
                    </ref>
                                    <ref id="ref26">
                        <label>26</label>
                        <mixed-citation publication-type="journal">Special category data. (n.d.). Retrieved from https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/a-guide-to-lawful-basis/lawful-basis-for-processing/special-category-data/</mixed-citation>
                    </ref>
                                    <ref id="ref27">
                        <label>27</label>
                        <mixed-citation publication-type="journal">Temel İlkeler | Kişisel Verileri Koruma Kurumu. (n.d.). Retrieved from https://www.kvkk.gov.tr/Icerik/4189/Kisisel-Verilerin-Islenmesine-Iliskin-Temel-Ilkeler</mixed-citation>
                    </ref>
                                    <ref id="ref28">
                        <label>28</label>
                        <mixed-citation publication-type="journal">The Criteria for The Determination of Countries Having an Adequate Level of Protection | Kişisel Verileri Koruma Kurulu. (2019). Retrieved from https://www.kvkk.gov.tr/Icerik/6642/Transfer-of-Personal-Data-Abroad</mixed-citation>
                    </ref>
                                    <ref id="ref29">
                        <label>29</label>
                        <mixed-citation publication-type="journal">The Eleventh Development Plan | Presidency of Republic of Turkey Presidency of Strategy and Budget. (2019). Retrieved from https://www.sbb.gov.tr/wp-content/uploads/2022/07/Eleventh_Development_Plan_2019-2023.pdf</mixed-citation>
                    </ref>
                                    <ref id="ref30">
                        <label>30</label>
                        <mixed-citation publication-type="journal">Uçak, M. (2021). Kişisel Verilerin Hukuka Uygun İşlenmesinde Çocuğun Rızası. Kişisel Verileri Koruma Dergisi, 3(1), 41-60.</mixed-citation>
                    </ref>
                                    <ref id="ref31">
                        <label>31</label>
                        <mixed-citation publication-type="journal">Uršič, H. (2021). Data Subject Rights Under the GDPR. Retrieved from http://books.google.ie/books?id=SECizgEACAAJ&amp;dq=HELENA+U.+VRABEC&amp;hl=&amp;cd=1&amp;source=gbs_api</mixed-citation>
                    </ref>
                                    <ref id="ref32">
                        <label>32</label>
                        <mixed-citation publication-type="journal">Ustaran, E. (2022). European Data Protection, Third Edition. Retrieved from http://books.google.ie/books?id=6AFGzwEACAAJ&amp;dq=978-1-948771-72-6&amp;hl=&amp;cd=1&amp;source=gbs_api</mixed-citation>
                    </ref>
                                    <ref id="ref33">
                        <label>33</label>
                        <mixed-citation publication-type="journal">Van Alsenoy, B. (2019). Data Protection Law in the EU. Retrieved from http://books.google.ie/books?id=xfwiwwEACAAJ&amp;dq=9781780688459&amp;hl=&amp;cd=3&amp;source=gbs_api</mixed-citation>
                    </ref>
                                    <ref id="ref34">
                        <label>34</label>
                        <mixed-citation publication-type="journal">Yapay Zekâ Alanında Kişisel Verilerin Korunmasına Dair Tavsiyeler| Kişisel Verileri Koruma Kurulu. (n.d.). Retrieved from https://www.kvkk.gov.tr/Icerik/7048/Yapay-Zeka-Alaninda-Kisisel-Verilerin-Korunmasina-Dair-Tavsiyeler</mixed-citation>
                    </ref>
                                    <ref id="ref35">
                        <label>35</label>
                        <mixed-citation publication-type="journal">2018/10 sayılı Kurul Kararı | Kişisel Verileri Koruma Kurulu. (2018). Retrieved from https://www.kvkk.gov.tr/Icerik/4110/2018-10</mixed-citation>
                    </ref>
                                    <ref id="ref36">
                        <label>36</label>
                        <mixed-citation publication-type="journal">2019/125 sayılı Kurul Kararı | Kişisel Verileri Koruma Kurulu. (2019).  Retrieved from https://www.kvkk.gov.tr/Icerik/5469/-Yeterli-korumanin-bulundugu-ulkelerin-tayininde-kullanilmak-uzere-olusturulan-form-hakkindaki-02-05-2019-tarihli-ve-2019-125-sayili-Kurul-Karari</mixed-citation>
                    </ref>
                                    <ref id="ref37">
                        <label>37</label>
                        <mixed-citation publication-type="journal">2020/173 sayılı Kurul Kararı | Kişisel Verileri Koruma Kurumu. (2020). Retrieved from https://www.kvkk.gov.tr/Icerik/6739/2020-173</mixed-citation>
                    </ref>
                            </ref-list>
                    </back>
    </article>
