{"id":1166,"date":"2023-09-22T17:45:31","date_gmt":"2023-09-22T14:45:31","guid":{"rendered":"https:\/\/ensari.av.tr\/en\/?p=1166"},"modified":"2023-09-22T17:45:32","modified_gmt":"2023-09-22T14:45:32","slug":"compliance-process-for-companies-regarding-kvkk","status":"publish","type":"post","link":"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/","title":{"rendered":"Compliance Process For Companies Regarding KVKK"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">KVKK Compliance Process for Companies<\/h2>\n\n\n\n<p>The main source of the Law on the Protection of Personal Data, which was published in the<br>Official Gazette on April 7, 2016, and entered into force, is Law No. 6698 on the Protection of<br>Personal Data.<br><br>According to the law, the concept of personal data is defined. Accordingly, personal data<br>refers to any kind of information related to a specific or identifiable real person. Companies<br>have access to the personal data of many individuals as a result of their commercial activities.<br>According to the law, the company&#8217;s legal personality carries the title of data controller<br>regarding this data. <\/p>\n\n\n\n<p>The data controller is defined as the person who determines the purposes<br>and means of processing the data and is responsible for the establishment and management of<br>the data recording system. In this context, it is necessary to fulfill the responsibilities arising<br>from the Law. It is useful to share some basic information about how companies will conduct<br>the KVKK compliance process and what needs to be done in accordance with the KVKK and<br>related legislation:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Data controller companies process the data of individuals in three different categories as data<br>controllers. These are; <\/li>\n\n\n\n<li>Company employees and job applicants, <\/li>\n\n\n\n<li>Customers, <\/li>\n\n\n\n<li>Business partners, suppliers, and consultants.<\/li>\n<\/ul>\n\n\n\n<p><br>Companies are obliged to protect the data of individuals in these three groups. The content of<br>this protection is mainly the processing, storage, sharing, deletion, and anonymization of<br>personal data in accordance with the Law. However, establishing the necessary technical<br>infrastructure regarding the platforms where personal data is processed and stored and taking<br>measures against possible cyber attacks is another important point.<\/p>\n\n\n\n<p><br>Processing of personal data is only possible with the explicit prior consent of the data subject.<br>Although there are exceptions to this rule, explicit consent is generally required. In this<br>regard, some documents need to be prepared and work needs to be done. These documents;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A- Preparation of the Information Text<\/h2>\n\n\n\n<p>The information text refers to the text that includes the purpose of acquiring the information,<br>where the data is stored, who has access permission to this data, and to whom the data can be<br>transferred. The data policy and data destruction policies should also be included in this text.<br>The company needs to prepare an information text for the following individuals;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Employees or job applicants<\/li>\n\n\n\n<li>Customers<\/li>\n\n\n\n<li>Third parties with the public<\/li>\n<\/ul>\n\n\n\n<p>After sharing the information text, the explicit consent of individuals must be obtained.<br>Explicit consent must be obtained before the data is processed. It is possible to obtain explicit<br>consent both in writing and online. Companies that collect data using websites should make<br>the necessary arrangements to allow individuals to give online consent for the processing of<br>their personal data after ensuring that the information text is read on the website where data is<br>collected.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">B- Preparation of Privacy and Cookie Policies<\/h2>\n\n\n\n<p>Companies with active websites must have privacy and cookie policies on their sites.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">C- Preparation of Confidentiality Agreements<\/h2>\n\n\n\n<p>Confidentiality agreements must be made with business partners, suppliers, accountants, call<br>centers, and other companies with whom business is conducted.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u00c7- Establishment of Company Internal Cyber Protection Policies<\/h2>\n\n\n\n<p>Data controllers have an obligation to implement necessary protection measures regarding the<br>data they process. The necessary technological infrastructure against cyber attacks should be<br>established, and auditing activities should be carried out. Otherwise, there may be penalties<br>and legal sanctions. Companies have obligations to ensure the confidentiality of their<br>employees&#8217; and customers&#8217; data, prevent unauthorized access to this data, and establish the<br>necessary technical infrastructure for this purpose. Even if the employer receives services<br>from another workplace or company to ensure data security, this does not eliminate the<br>company&#8217;s own responsibility.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">D- Obligations Regarding Commercial Electronic Communications<\/h2>\n\n\n\n<p>Companies must obtain the explicit consent of individuals in accordance with the KVKK in<br>order to use the contact information they have obtained about their customers to send<br>commercial electronic communications to these individuals. The provisions in the Regulation<br>on Commercial Communication and Commercial Electronic Communications have made it<br>mandatory for companies wishing to send commercial electronic communications to register<br>with the Message Management System. The Message Management System (IYS) is a national<br>database where companies can store and manage permissions for commercial<br>communications such as calls, messages, and emails, and where recipients can view, remove,<br>and store the permissions they have given.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Obligations of Companies Regarding the Message Management System<\/h2>\n\n\n\n<p>The explicit consent of customers regarding data processing must be obtained online through<br>the IYS. If the company has obtained the explicit consent of the customer through its own<br>means rather than through the system, it must record the consent declaration within three<br>business days, with the burden of proof on itself.<\/p>\n\n\n\n<p>Unrecorded approvals in the Message Management System are considered invalid. Sending<br>commercial electronic communications to customers without obtaining consent is against the<br>law. The deadline for recording existing approvals in the IYS is May 31, 2021. Approvals that<br>are not recorded in the system before this date will be considered invalid, and sending<br>commercial electronic communications to these recipients will be against the law.<br>According to the regulation, companies are obliged to keep records of approvals related to<br>commercial electronic communications sent to recipients&#8217; electronic communication addresses<br>for three years from the date of recording, as well as other records related to commercial<br>electronic communications. These records are for the purpose of promoting products and<br>services, marketing, or increasing visibility with content such as greetings and wishes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">E- Obligations Regarding Data Transfer Abroad<\/h2>\n\n\n\n<p>The first requirement for the transfer of personal data abroad is to obtain the explicit consent<br>of the data subject. In addition, it is necessary to investigate whether the country to which<br>personal data will be shared can provide sufficient protection for these data, and if it is<br>determined that it cannot provide such protection, data sharing should not be carried out.<br>The Personal Data Protection Board announces countries that provide sufficient protection for<br>data sharing. If data will be shared with a country that is not included in this list, a decision<br>should be made by evaluating international agreements, the principle of reciprocity, and the<br>protection measures committed by the data controller who will share the data. Sharing<br>personal data of multinational companies with centers or affiliated partnerships abroad in<br>violation of these obligations may result in liability under the KVKK.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">F- Preparation of Data Inventory by Classifying Processed Personal Data and Notification to<br>VERB\u0130S<\/h2>\n\n\n\n<p><br>Companies are obliged to register with the VERB\u0130S system under the title of data controller.<br>Companies are not required to upload all the data they process to VERB\u0130S. Their obligations<br>in this regard are to provide general information about the data they process. In order to make<br>this notification, the categorized inventory of all data recorded by the company should be<br>prepared, the types of data should be determined, information should be provided regarding<br>the purpose and duration of data processing and data storage, and notification should be made<br>regarding other issues such as to whom the data can be transferred. The information that<br>needs to be registered in VERB\u0130S is as follows:<br><br>Identity and address information of the data controller and, if any, its representative,<br>The purpose of processing personal data determined within the scope of the use of personal<br>data,<br><br>The time that may be required according to the reason for processing personal data,<br>Information about data categories related to data subject groups and these individuals,<br>Recipient groups to which personal data can be transferred,<br>Personal data to be shared with foreign countries,<\/p>\n\n\n\n<p>Measures implemented to ensure the protection of personal data.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">G- Reporting Data Breaches<\/h2>\n\n\n\n<p>In the event that personal data processed is unlawfully obtained by others, the data controller<br>must notify the Personal Data Protection Board within 72 hours. This notification can be<br>made through the Board&#8217;s website. If the data controller identifies the data subjects whose<br>data has been breached, they must also notify these individuals as soon as possible.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>KVKK Compliance Process for Companies The main source of the Law on the Protection of Personal Data, which was published in theOfficial Gazette on April 7, 2016, and entered into force, is Law No. 6698 on the Protection ofPersonal Data. According to the law, the concept of personal data is defined. Accordingly, personal datarefers to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1167,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28],"tags":[49,48,50,51],"class_list":["post-1166","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-turkey-law","tag-kvkk-compliance","tag-kvkk-compliance-process-for-companies","tag-turkey-kvkk-compliance","tag-turkish-compliance-process-for-companies"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v21.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Compliance Process For Companies Regarding KVKK - Lawyer Orhan Oguzhan Ensari Law Office<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Compliance Process For Companies Regarding KVKK - Lawyer Orhan Oguzhan Ensari Law Office\" \/>\n<meta property=\"og:description\" content=\"KVKK Compliance Process for Companies The main source of the Law on the Protection of Personal Data, which was published in theOfficial Gazette on April 7, 2016, and entered into force, is Law No. 6698 on the Protection ofPersonal Data. According to the law, the concept of personal data is defined. Accordingly, personal datarefers to [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/\" \/>\n<meta property=\"og:site_name\" content=\"Lawyer Orhan Oguzhan Ensari Law Office\" \/>\n<meta property=\"article:published_time\" content=\"2023-09-22T14:45:31+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-09-22T14:45:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/ensari.av.tr\/en\/wp-content\/uploads\/2023\/09\/compliance-process-for-companies.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"ensari\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ensari\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/\",\"url\":\"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/\",\"name\":\"Compliance Process For Companies Regarding KVKK - Lawyer Orhan Oguzhan Ensari Law Office\",\"isPartOf\":{\"@id\":\"https:\/\/ensari.av.tr\/en\/#website\"},\"datePublished\":\"2023-09-22T14:45:31+00:00\",\"dateModified\":\"2023-09-22T14:45:32+00:00\",\"author\":{\"@id\":\"https:\/\/ensari.av.tr\/en\/#\/schema\/person\/553a9f585d044a513ab579b2ef463ebf\"},\"breadcrumb\":{\"@id\":\"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Anasayfa\",\"item\":\"https:\/\/ensari.av.tr\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Compliance Process For Companies Regarding KVKK\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/ensari.av.tr\/en\/#website\",\"url\":\"https:\/\/ensari.av.tr\/en\/\",\"name\":\"Lawyer Orhan Oguzhan Ensari Law Office\",\"description\":\"Advocacy and Legal Consultancy\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/ensari.av.tr\/en\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/ensari.av.tr\/en\/#\/schema\/person\/553a9f585d044a513ab579b2ef463ebf\",\"name\":\"ensari\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ensari.av.tr\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f9f1f61527836f4db7429099c069a61d67768910a61eecdac52c5e34f9cb51d2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f9f1f61527836f4db7429099c069a61d67768910a61eecdac52c5e34f9cb51d2?s=96&d=mm&r=g\",\"caption\":\"ensari\"},\"url\":\"https:\/\/ensari.av.tr\/en\/author\/ensari\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Compliance Process For Companies Regarding KVKK - Lawyer Orhan Oguzhan Ensari Law Office","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/","og_locale":"en_US","og_type":"article","og_title":"Compliance Process For Companies Regarding KVKK - Lawyer Orhan Oguzhan Ensari Law Office","og_description":"KVKK Compliance Process for Companies The main source of the Law on the Protection of Personal Data, which was published in theOfficial Gazette on April 7, 2016, and entered into force, is Law No. 6698 on the Protection ofPersonal Data. According to the law, the concept of personal data is defined. Accordingly, personal datarefers to [&hellip;]","og_url":"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/","og_site_name":"Lawyer Orhan Oguzhan Ensari Law Office","article_published_time":"2023-09-22T14:45:31+00:00","article_modified_time":"2023-09-22T14:45:32+00:00","og_image":[{"width":1080,"height":720,"url":"https:\/\/ensari.av.tr\/en\/wp-content\/uploads\/2023\/09\/compliance-process-for-companies.jpg","type":"image\/jpeg"}],"author":"ensari","twitter_card":"summary_large_image","twitter_misc":{"Written by":"ensari","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/","url":"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/","name":"Compliance Process For Companies Regarding KVKK - Lawyer Orhan Oguzhan Ensari Law Office","isPartOf":{"@id":"https:\/\/ensari.av.tr\/en\/#website"},"datePublished":"2023-09-22T14:45:31+00:00","dateModified":"2023-09-22T14:45:32+00:00","author":{"@id":"https:\/\/ensari.av.tr\/en\/#\/schema\/person\/553a9f585d044a513ab579b2ef463ebf"},"breadcrumb":{"@id":"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/ensari.av.tr\/en\/compliance-process-for-companies-regarding-kvkk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Anasayfa","item":"https:\/\/ensari.av.tr\/en\/"},{"@type":"ListItem","position":2,"name":"Compliance Process For Companies Regarding KVKK"}]},{"@type":"WebSite","@id":"https:\/\/ensari.av.tr\/en\/#website","url":"https:\/\/ensari.av.tr\/en\/","name":"Lawyer Orhan Oguzhan Ensari Law Office","description":"Advocacy and Legal Consultancy","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ensari.av.tr\/en\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/ensari.av.tr\/en\/#\/schema\/person\/553a9f585d044a513ab579b2ef463ebf","name":"ensari","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ensari.av.tr\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f9f1f61527836f4db7429099c069a61d67768910a61eecdac52c5e34f9cb51d2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f9f1f61527836f4db7429099c069a61d67768910a61eecdac52c5e34f9cb51d2?s=96&d=mm&r=g","caption":"ensari"},"url":"https:\/\/ensari.av.tr\/en\/author\/ensari\/"}]}},"_links":{"self":[{"href":"https:\/\/ensari.av.tr\/en\/wp-json\/wp\/v2\/posts\/1166","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ensari.av.tr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ensari.av.tr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ensari.av.tr\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ensari.av.tr\/en\/wp-json\/wp\/v2\/comments?post=1166"}],"version-history":[{"count":1,"href":"https:\/\/ensari.av.tr\/en\/wp-json\/wp\/v2\/posts\/1166\/revisions"}],"predecessor-version":[{"id":1168,"href":"https:\/\/ensari.av.tr\/en\/wp-json\/wp\/v2\/posts\/1166\/revisions\/1168"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ensari.av.tr\/en\/wp-json\/wp\/v2\/media\/1167"}],"wp:attachment":[{"href":"https:\/\/ensari.av.tr\/en\/wp-json\/wp\/v2\/media?parent=1166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ensari.av.tr\/en\/wp-json\/wp\/v2\/categories?post=1166"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ensari.av.tr\/en\/wp-json\/wp\/v2\/tags?post=1166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}