A COMPARATIVE ANALYSIS OF JOINT DATA CONTROLLERSHIP UNDER EU AND TURKISH LAW
Öz
Technological development and the expansion of digital ecosystems have significantly increased the scale, speed and complexity of personal data processing. This evolution has reshaped the legal meaning of “data controller” and brought forward the modern notion of joint data controllership, particularly under the EU’s General Data Protection Regulation (GDPR). Although Turkish Personal Data Protection Law No. 6698 (PDPL) does not explicitly regulate joint data controllers, the processing practices of both public and private actors demonstrate that multiple entities frequently determine purposes and means together. Therefore, a comprehensive comparative analysis is necessary to clarify the legal nature, conditions, obligations and liability of joint data controllers under both legal systems. This article consists of three parts. Part I examines the historical evolution of personal data protection, basic concepts such as personal data, sensitive data and data processing, and core principles guiding lawful processing. Part II analyses the emergence, definition and legal basis of joint data controllership, including seminal Court of Justice of the European Union (CJEU) rulings—Wirtschaftsakademie, Jehovah’s Witnesses and Fashion ID—which shaped the concept. Part III investigates the consequences of joint data controllership, focusing on liability, compensation, internal allocation of responsibility, and the applicability of joint liability principles in Turkish law. Through this comparative approach, the article demonstrates that Turkey must incorporate explicit joint data controllership rules into the PDPL to close interpretive gaps, strengthen legal certainty, and align its framework with international standards. The analysis also highlights that joint data controllership serves both to enhance data protection and to impose more burdens on organisations operating in complex digital environments.
Anahtar Kelimeler
Etik Beyan
Kaynakça
- Alsenoy, B. (2016). Liability under EU data protection law: From Directive 95/46 to the General Data Protection Regulation. Journal of Intellectual Property, Information Technology and E-Commerce Law, 7, 271–288.
- Ardıç, Ş. (2018). Kişisel verilerin silinmesi, yok edilmesi veya anonim hale getirilmesi. Marmara Üniversitesi Hukuk Fakültesi Hukuk Araştırmaları Dergisi, 24(2), 748–752.
- Atasoy, A. S. (2019). 6698 sayılı Kişisel Verilerin Korunması Kanunu ve GDPR kapsamında veri sorumlusu ve veri işleyen kavramları. İstanbul Hukuk Mecmuası, 77(2), 755.
- Ayözger, Ç. (2019). Kişisel verilerin korunması hukuku: Elektronik haberleşme sektörüne ilişkin özel düzenlemeler dahil (2nd ed.). Beta Basım Yayın.
- Ayrancı, H., Çolak, A., & Özcan, O. (2022). Kişisel Verilerin Korunması Kanunu şerhi. Yetkin Yayınları.
- Başalp, N. (2019). Kişisel verilerin korunması hukukunda veri sorumlusu, veri işleyen ve ortak veri sorumlusu. Kişisel Verileri Koruma Dergisi, 1(1), 22–25.
- Blume, P. (2013). Controller and processor: Is there a risk of confusion? International Data Privacy Law, 3(2), 140–145.
- Bygrave, L. A. (2014). Data privacy law: An international perspective. Oxford University Press.
Ayrıntılar
Birincil Dil
İngilizce
Konular
Avrupa Birliği Hukuku
Bölüm
Araştırma Makalesi
Yazarlar
Ümit Çalışkan
*
Türkiye
Yayımlanma Tarihi
30 Haziran 2026
Gönderilme Tarihi
30 Kasım 2025
Kabul Tarihi
30 Haziran 2026
Yayımlandığı Sayı
Yıl 2026 Cilt: 34 Sayı: 1