ARTICLE
6 December 2021

Personal Data Protection Authority: Data Breach Notification Concerning The Retail Apparel Company

DI
Deris IP Attorneys

Contributor

Deris is a one-stop shop for IP services with one of the largest and internationally regarded IP prosecution and advisory team. We have been the pioneer in shaping the IP landscape by obtaining the precedent decisions and participating the preparation of the IP legislation upon the invitation of the legislative bodies. We provide a wide spectrum of high-quality services that are essential for securing, maintaining and enforcing IP rights.
The decision relates to a late-detected violation due to insufficient tests during the design phase of the web page. 
Turkey Privacy

The Turkish Personal Data Protection Authority ( "Authority"  ) has published its decision dated 20/01/2020 and numbered 2020/50 regarding the personal data breach notification of a retail clothing company.The decision relates to a late-detected violation due to insufficient tests during the design phase of the web page.

In the data breach notification submitted to the Authority, the data controller stated that the personal data of some customers who opened new accounts were transferred to some third-party vendors/providers via a URL. The determination of this violation has emerged during the regular examination of the data controller.

The Board made the following conclusions in its decision.

· The fact that the data breaches that took place on 01.08.2018 and 21.10.2018 were detected on 02.07.2019, approximately one year later, is an indication that the company's tracking alarm systems were not effective and the company did not make the necessary controls.

· The fact that personal data can be seen by third-party vendors/providers via the URL is an indication that the tests performed during the web page design phase are insufficient or that the necessary tests are not performed.

Concerning the reasons explained above, about the data controller who does not take the necessary technical and administrative measures to ensure data security within the framework of paragraph (1) of Article 12 of the Personal Data Protection Law (Law) No. 6698, it is decided to impose a50.000 TLadministrative fine according to subparagraph (b) of paragraph (1) of Article 18 of the Law.

Deris Intellectual Property

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More