Overview of the Definitons of Data Controller and Data Processor within the Scope of The Turkish Code of Personal Data Protection (TCDP)
Öz
The definition of data controller based on TCDP Art. 3: (ı). The definition of controller within the TCDP requires four main elements; 1) the data processing, 2) determining the purposes and means of the processing of personal data, 3) the natural or legal person, 4) alone or jointly with others. For secondary elements, the provision TCDP Art. 3(ı) seemingly entails two elements within the determination of data controller. The first element is to determine the purpose and means of processing personal data, the second is to establish and manage the data registry system. The first and second elements should not exist cumulatively. In fact, the first element contains all the constitutents of the second element that were implied in TCDP Art. 3 (ı), since the establishment of a personal data registry system requires a determination of the means of collecting and recording personal data. The management of the data registry system requires the performance of one of the operation listed within the scope of the processing of personal data and can therefore be evaluated within the scope of processing personal data. Considering the definitions of data controller and processor in the TCDP, even though the data controller and the data processor are likely to be identified separately in the TCDP, a natural or legal person may have both the title of data controller and data processor. When a processor deviates from the instructions of a controller, the processor becomes the “de facto” controller. This embraces those cases where the processor doesn’t act on behalf of the controller, rather acts on his/her own behalf. In this context, there will be two separate data controllers. Although the TCDP does not explicitly refer to it, the “de facto” data controller should also be allocated the responsibilities and obligations of the “legal” data controller in the TCDP.
Anahtar Kelimeler
Destekleyen Kurum
Kaynakça
- Article 29 Data Protection Working Party, “Opinion 1/2010 on the concepts of “controller” and “processor”, 2010.
- (http://ec.europa.eu/justice_home/fsj/privacy/index_en.htm00264/10/EN WP 169 Opinion 1/2010 on the concepts of “controller” and “processor”) Ayözger, A. Çiğdem: Kişisel Verilerin Korunması, Beta, İstanbul, 2016.
- Korkmaz, İbrahim: “Kişisel Verilerin Korunması Kanunu Hakkında Bir Değerlendirme”, TBB 2016/214, pp. 82-152.
- Brick, Stefan / Wolff, Heinrich: Amadeus BeckOK Datenschutzrecht, 27. Ed. München, 2019.
- Develioğlu, Hüseyin Murat: 6698 sayılı Kişisel Verilerin Korunması Kanunu ile Karşılaştırmalı Olarak Avrupa Birliği Genel Veri Koruma Tüzüğü uyarınca Kişisel Verilerin Korunması Hukuku, On İki Levha, İstanbul, 2017.
- Jürgen, Hartung/ Büttgen, Lisa: “Die Auftragsverarbeitung nach der DS-GVO”, DuD 2017/9, pp. 550-551.
- Kühling Jürgen / Bunchner, Benedikt: Datenschutz-Grundverodnung/ BDSG, 2. Aufl, München, 2018.
- Küzeci, Elif: Kişisel Verilerin Korunması, 3. Baskı, Turhan, Ankara, 2019. KVKK: Data Protection in Turkey, Ankara.
Ayrıntılar
Birincil Dil
İngilizce
Konular
Hukuk
Bölüm
Araştırma Makalesi
Yazarlar
Cuneyt Pekmez
*
0000-0001-7703-440X
Türkiye
Yayımlanma Tarihi
26 Kasım 2019
Gönderilme Tarihi
10 Haziran 2019
Kabul Tarihi
17 Ağustos 2019
Yayımlandığı Sayı
Yıl 2018 Sayı: 67