Kişisel Verilerin Korunması Kanunu’nda Düzenlenen Kabahatler ile Siber Güvenlik Kanunu’nda Düzenlenen Kabahatler Arasında İçtima İlişkisi
Öz
Bu makale, Kişisel Verilerin Korunması (KVK) Kanunu m. 18’de düzenlenen kabahatler ile Siber Güvenlik (SG) Kanunu m. 16’da düzenlenen kabahatler arasındaki içtima ilişkisini incelemektedir. Makalede SG Kanunu'nun kabulünden sonra tartışılan zımni yürürlükten kaldırılma iddialarının kabahatler hukuku bağlamındaki mevcut düzenlemeler ile bağdaşmadığı ortaya konmuştur. KVK Kanunu m. 18/1-b’de yer alan veri güvenliği yükümlülüklerinin ihlali kabahati ile SG Kanunu m. 16/10’daki siber güvenlik tedbirlerini uygulamama kabahati arasındaki içtima ilişkisi, Kabahatler Kanunu m. 15/1 çerçevesinde fikri içtima hükümleri uygulanarak çözümlenmelidir. Makalede, başta SG Kanunu m. 17/2’de yer alan nispî idari para cezası düzenlemesi olmak üzere çeşitli sebeplerle, Kabahatler Kanunu m. 15/1 hükmü bağlamındaki daha ağır idari para cezasının somut idari para cezaları kıyaslanarak bulunması gerekmekte olduğu savunulmuştur. SG Kanunu m. 7/1-b’de yer alan siber olayları bildirme yükümlülüğü ile KVK Kanunu m. 12/5’te yer alan kişisel veri ihlallerini bildirme yükümlülüğü farklı içerik ve muhataba sahip olduğundan, bu durumda gerçek içtima uygulanarak her iki otoritenin de ayrı yaptırım uygulayacağı sonucuna varılmıştır. Makalede, KVK Kurumu ile SG Başkanlığı arasında güçlü bir işbirliği ve koordinasyon mekanizması kurulmasının gerekliliği vurgulanmıştır.
Anahtar Kelimeler
Kabahatler, Fikri içtima, Kişisel veri, Veri güvenliği, Siber güvenlik
The Relationship of Concurrence between Misdemeanors under the Personal Data Protection Law and the Cybersecurity Law
Öz
This article examines the concurrence of misdemeanors regulated in Article 18 of the Personal Data Protection Law and misdemeanors regulated in Article 16 of the Cybersecurity Law. It has been demonstrated that claims of implied repeal following the adoption of the Cybersecurity Law are unfounded. The concurrence of the misdemeanor of violating data security obligations in Article 18/1-b of the Personal Data Protection Law and the misdemeanor of failing to implement cybersecurity measures in Article 16/10 of the Cybersecurity Law has been resolved by applying provisions on concurrence rules under Article 15/1 of the Misdemeanors Law. Primarily due to the proportional administrative fine established in Article 17/2 of the Cybersecurity Law, as well as for various other reasons, it has been established that the determination of the more severe administrative fine within the meaning of Article 15/1 of the Misdemeanors Law must be made by comparing the specific administrative fines in question. Moreover, since the obligation to report cyber incidents under Article 7/1-b of the Cybersecurity Law and the obligation to report personal data breaches under Article 12/5 of the Personal Data Protection Law have different content and addressees, it has been concluded that real concurrence shall apply in this case, with both authorities imposing separate sanctions. The article emphasizes the need to establish strong cooperation and coordination mechanisms between the Personal Data Protection Authority and the Cybersecurity Presidency.
Anahtar Kelimeler
Misdemeanors, Ideal concurrence, Personal data, Data security, Cybersecurity