TR
EN
Self-Disclosure or Burying the Evidence Dilemma: A Legal Review of the Data Breach Rules under the Turkish Personal Data Protection Law
Öz
Technology has penetrated every aspect of life and brought security and privacy issues to the forefront of the regulatory landscape. In such a hyper-connected world, security breaches are inevitable. Hence, general legislation in the field of protection of personal data is becoming ubiquitous. The rules are likewise being drafted to ensure the highest degree of privacy and security.
The violation of security requirements can have an unprecedented and catastrophic consequence on data controllers. A security incident can compel the data controller to notify a competent data protection authority of a breach and communicate all facts to affected data subjects. Data breach notification is self-disclosure of the data controller about a personal data-related incident regardless of the intentional or negligent character of the event. The underlying aim of this obligation is to prevent or mitigate all adverse effects or damage deriving from a data breach incident.
This article maps out the legal framework governing data breach notification under the European Union’s law, in particular General Data Protection Regulation and the Turkish Data Protection Law. This article maintains that strict and burdensome data breach notification rules do not serve the interest of data protection of individuals as data controllers could refrain from notification and bury the pieces of evidence. Such a notification-phobia is a major threat to the overall cybersecurity realm. The article emphasizes that there is a need for balanced rules and adequate accountability tools which would encourage data controllers to report any data breach incidents without hesitation.
Anahtar Kelimeler
Destekleyen Kurum
The author received no grant support for this work.
Kaynakça
- Article 29 Data Protection Working Party, ‘Guidelines on Personal data breach notification under Regulation 2016/679 (Adopted on 3 October 2017 As last Revised and Adopted on 6 February2018)’ https://ec.europa.eu/newsroom/article29/document.cfm?action=display&doc_id=49827
- Article 29 Data Protection Working Party, ‘Guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679 Adopted on 3 October 2017’ http://ec.europa.eu/newsroom/just/document.cfm?doc_id=47889
- Burdon M, Lane B and Von Nessen P, ‘Data breach notification law in the EU and Australia e Where to now?’ (2012) 28 Computer Law & Security Review.
- Council of Europe, ‘Explanatory Report to the Protocol amending the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data’ https://rm.coe.int/cets-223-explanatory-report-to-the-protocol-amending-the-convention-fo/16808ac91a
- Çekin, M S, Avrupa Birliği Hukukuyla Mukayeseli Olarak 6698 sayılı Kişisel Verilerin Korunması Kanunu (On İki Levha 2018).
- Determann L, Determann's Field Guide to Data Privacy Law (Fourth Edition) (Edward Elgar 2020).
- DiGrazia K, ‘Cyber Insurance, Data Security, and Blockchain in the Wake of the Equifax Breach’ (2018) 13 Journal of Business & Technology Law 225.
- Dülger, M V, Kişisel Verilerin Korunması Hukuku 2. Baskı (Hukuk Akademisi 2019).
Ayrıntılar
Birincil Dil
İngilizce
Konular
Hukuk
Bölüm
Araştırma Makalesi
Yazarlar
Yayımlanma Tarihi
31 Aralık 2021
Gönderilme Tarihi
7 Nisan 2021
Kabul Tarihi
27 Ağustos 2021
Yayımlandığı Sayı
Yıl 2021 Sayı: 70
APA
Kaya, M. B. (2021). Self-Disclosure or Burying the Evidence Dilemma: A Legal Review of the Data Breach Rules under the Turkish Personal Data Protection Law. Annales de la Faculté de Droit d’Istanbul, 70, 195-241. https://doi.org/10.26650/annales.2021.70.0007
AMA
1.Kaya MB. Self-Disclosure or Burying the Evidence Dilemma: A Legal Review of the Data Breach Rules under the Turkish Personal Data Protection Law. Annales de la Faculté de Droit d’Istanbul. 2021;(70):195-241. doi:10.26650/annales.2021.70.0007
Chicago
Kaya, Mehmet Bedii. 2021. “Self-Disclosure or Burying the Evidence Dilemma: A Legal Review of the Data Breach Rules under the Turkish Personal Data Protection Law”. Annales de la Faculté de Droit d’Istanbul, sy 70: 195-241. https://doi.org/10.26650/annales.2021.70.0007.
EndNote
Kaya MB (01 Aralık 2021) Self-Disclosure or Burying the Evidence Dilemma: A Legal Review of the Data Breach Rules under the Turkish Personal Data Protection Law. Annales de la Faculté de Droit d’Istanbul 70 195–241.
IEEE
[1]M. B. Kaya, “Self-Disclosure or Burying the Evidence Dilemma: A Legal Review of the Data Breach Rules under the Turkish Personal Data Protection Law”, Annales de la Faculté de Droit d’Istanbul, sy 70, ss. 195–241, Ara. 2021, doi: 10.26650/annales.2021.70.0007.
ISNAD
Kaya, Mehmet Bedii. “Self-Disclosure or Burying the Evidence Dilemma: A Legal Review of the Data Breach Rules under the Turkish Personal Data Protection Law”. Annales de la Faculté de Droit d’Istanbul. 70 (01 Aralık 2021): 195-241. https://doi.org/10.26650/annales.2021.70.0007.
JAMA
1.Kaya MB. Self-Disclosure or Burying the Evidence Dilemma: A Legal Review of the Data Breach Rules under the Turkish Personal Data Protection Law. Annales de la Faculté de Droit d’Istanbul. 2021;:195–241.
MLA
Kaya, Mehmet Bedii. “Self-Disclosure or Burying the Evidence Dilemma: A Legal Review of the Data Breach Rules under the Turkish Personal Data Protection Law”. Annales de la Faculté de Droit d’Istanbul, sy 70, Aralık 2021, ss. 195-41, doi:10.26650/annales.2021.70.0007.
Vancouver
1.Mehmet Bedii Kaya. Self-Disclosure or Burying the Evidence Dilemma: A Legal Review of the Data Breach Rules under the Turkish Personal Data Protection Law. Annales de la Faculté de Droit d’Istanbul. 01 Aralık 2021;(70):195-241. doi:10.26650/annales.2021.70.0007