ARTICLE
23 August 2022

The Guideline Regarding Good Practices On Protection Of Personal Data In The Banking Sector Has Been Published By The Personal Data Protection Authority

SL
SRP Legal

Contributor

SRP-Legal is providing legal service to clients in a wide range of legal areas and providing legal consultancy services in sectors transformed by new business models, information and communication technologies. SRP-Legal focuses on Technology and Privacy Law. SRP-Legal’s primary expertise areas are Commercial/E-Commerce Law, Competition Law, Corporate Law, Data Protection & Data Privacy Law, Financial Technology Law, Public Policy, Technology Law, Media Law, Communication Law. SRP-Legal’s blockchain practice has experience of advising on specific, complex regulatory matters in relation to the application of blockchain technology. SRP-Legal offers advice to clients on legal and regulatory matters in highly regulated markets and industries, as well as public policy support before the Governmantal Institutions. SRP-Legal is committed to its clients’ expectations and needs and seeking their views and feedback. SRP-Legal’s target is to provide a bespoke legal, regulatory, policy and strategic advice that is fit
The Guideline Regarding Good Practices on Protection of Personal Data in the Banking Sector has been published on 05.08.2022 by the Personal Data Protection Authority
Turkey Privacy
The Guideline Regarding Good Practices on Protection of Personal Data in the Banking Sector ("Guideline") has been published on 05.08.2022 by the Personal Data Protection Authority ("Authority").
The purpose of the Guideline is to guide the data controller banks to carry out their personal data processing activities in accordance with the Personal Data Protection Law numbered 6698 ("Law") and the secondary legislation issued by the Personal Data Protection Board, and to set good practice examples within this framework. The Guideline includes general explanations regarding the procedures and principles which banks must comply with for the personal data protection, and obligation of banks to comply with the Law and the relevant secondary legislation continues.

In the Guideline:

  • The following issues have been evaluated within the scope of data controller-data processor relations: (i) data processing agreement to be made between data controller and data processor, (ii) support services, (iii) affiliates and subsidiaries, (iv) open banking, (v) situations in which the banks act as agents.
  • The conditions for the processing of personal data as: explicit consent, being stipulated in the laws and fulfilment of a legal obligation, processing the personal data of parties of a contract, legitimate interests, being compulsory for the establishment, usage, or protection of a right evaluated within the scope of banking activities and examples of good practices specific to banking activities are included.
  • The processing of special categories of personal data in the banking sector has also been evaluated and measures to be taken have been included in this regard.
  • The transfer of personal data domestically and abroad within the scope of banking activities are evaluated.
  • The obligations of the data controller as: the obligation of the data controller to inform, to register with the data controllers' registry and to prepare a data inventory has been reviewed. In addition, deletion, destruction, anonymization of personal data, data security, the rights of the data subject and the management of complaints has been evaluated.
In the Guideline, the Authority evaluated the protection of personal data within the scope of banking activities and included good practice examples for data controller banks. The Guideline constitutes an important resource for personal data processing activities of banks.

You may reach the full Turkish text of the Guideline via the link below.

https://kvkk.gov.tr/SharedFolderServer/CMSFiles/12236bad-8de1-4c94-aad6-bb93f53271fb.pdf

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More