Bultenler
Guideline on Good Practices on Protection of Personal Data in the Banking Sector
The Turkish Personal Data Protection Authority (“Authority”) has published its Best Practice Guideline (‘‘Guideline’’) on the Protection of Personal Data in the Banking Sector with the aim of implementing the Turkish Law on the Protection of Personal Data (“Law No. 6698”), providing guidance to banks, and establishing best practice examples.
The Guideline provides general explanations of the principles and procedures that banks must follow in the field of personal data protection, as well as the obligations they must uphold. Banks are also required to comply with Law No. 6698 and relevant secondary regulations. In addition, after receiving a complaint or learning of the alleged violation, the Turkish Personal Data Protection Board (“Board”) will make its decision following the launching of an ex officio investigation.
- Relationship Between Data Controller and Data Processor
Banks may have the title of the data controller or data processor within the scope of their data processing activities. According to Article 4 of Banking Law No. 5411 (“Law No:5411”) banks are data controllers for their banking activities. The Data Controllers Registry records data processing activities of banks with the title of "data controller." The distinction between a data controller and a data processor also helps to clarify who can perform data processing activities.
Accordingly, the data processing provisions may be included in the service contract between the data controller and the data processor. In addition to the service contract, a separate arrangement can be made.
Banks can procure marketing assistance from support service institutions. In practice, banks appear to be data processors for mentioned institutions in some cases.
Banks can also provide services to their subsidiaries with the Banking Regulation and Supervision Agency’s permission to expand their operations.
Each service provided by the banks should be evaluated separately, and the parties' data controller-data processor titles should be determined using the aforementioned criteria.
- Processed Personal Data
Sensitive personal data may also be processed in the banking sector. Criminal convictions and security measures, as well as personal data like identity, communication, location, finance, risk management, and special categories of personal data such as biometric data and health information, can be processed in this context.
Data controller banks are subject to Article 5 of Law No. 6698 and not be able to change the conditions in their favor.
- Bank Channel Practices
The bank is not required to provide a written and signed text because the explicit consent of the data subjects does not need to be written but the data controller is responsible for proving that the explicit consent has been obtained.
For the branch, explicit consent texts from data subjects can be approved using a wet ink signature or another, legally required method (such as an e-signature or digital signature).
After logging into the ATM, the data subject’s consent can be obtained with the explicit consent text provided by the ATM.
In order to obtain the data subject's explicit consent, internet and mobile banking both have boxes, buttons, and other elements to tick or select. The options shouldn't already be pre-ticked or selected in the selections made using these methods.
For call centers, the data subject can express their preference to the customer representative verbally or by pressing a button, which can be used to obtain explicit consent.
By sending an SMS to the registered phone numbers in the bank and an SMS with a verification code, it is possible to direct the data subjects to respond to the processing of their personal data.
- Processing Special Categories of Personal Data in the Banking Sector
In accordance with the fourth paragraph of Article 6 of Law No. 6698, it is obligatory to take adequate measures determined by the Board in the processing of special categories of personal data. Obtaining a copy of a person's identity card is a special category of personal data so banks;
- Without explicit consent, sensitive data contained in the identity document should not be processed.
- The sensitive personal data contained in the identity document should not be processed; instead, only the front side or pertinent page of the identity document should be processed.
- Technical and administrative measures should be taken to obscure or not to process the sensitive data in the ID for those whose explicit consent can not be obtained.
- Requesting identity documents from individuals in bank transactions is one of the activities carried out due to the requirement of identification under banking regulations.
Furthermore, since banks cannot meet the conditions in the Law in terms of processing health data, the process can only be carried out with the explicit consent of the data subject.
Banks also must obtain the data subject's explicit consent before processing biometric data. In addition, technical and administrative measures specified in the Guideline on Matters to be Considered in the Processing of Biometric Data should be taken by data controllers.
- Obligations of Data Controller
The obligation of the data controller to inform is regulated in Article 10 of Law No. 6698. According to Article, when personal data are obtained, the data controller or the person authorised by it is obliged to inform the data subjects about the following: the identity of the data controller and its representative, if any, the purpose of the processing of personal data, to whom and for which purposes the processed personal data may be transferred, the method and legal basis of the collection of personal data and other things referred to in Article 11.
Each bank will be able to establish its own enlightenment texts based on its own operations and systems, including personal data categories, data collection methods, processing purposes, legal justifications, and the parties to whom personal data is transferred. The information to be given to the data subject within the framework of the obligation to inform, on the other hand, must be compatible with the information disclosed in the Data Controllers Registry Information System.
It would be appropriate for banks to establish the enlightenment texts themselves given the bank's extensive data processing needs. The mandatory content that states to whom personal data can be transferred; institutions from which banks procure support services, business partners, affiliates, auditing companies, and authorized public institutions should be written.
Banks, on the other hand, are required to notify the natural person (staff, visitors, etc.) whose data they process. It is recommended that additional information be provided to the data subject during the stages of obtaining personal data in the context of banking activities. Principally, the data controller must fulfil the obligation to inform at the time of obtaining personal data.
- Erasure, Destruction, or Anonymization of Personal Data
Banks are required to keep documents related to their transactions for ten years according to Articles 64, 65, and 82 of the Turkish Commercial Code No. 6102 and Article 42 of the Banking Law No. 5411.
Personal data shall be erased, destructed, or anonymized by the controller ex officio (by its own initiative) or upon the request of the data subject, if all the conditions for processing data no longer exist. In banking sector, the purpose of processing can be summarized as carrying out the activities specified in Article 4 of the Banking Law and complying with the legal retention periods defined by the regulation. When a customer requests to terminate the continuous business relationship by closing their accounts, or when the continuous business relationship is terminated, and the retention periods arising from legal regulations regarding the preservation of customer documents have passed, the purpose of processing may be deemed to have disappeared.
Banks should delete data immediately if requested by the data subject. Each bank, on the other hand, will be able to choose its own method of erasing, anonymization, or destruction.
- Request to Data Controller
The procedures and principles of make a request to the data controller are regulated by the Law and Communiqué on Principles and Procedures to be Followed in Fulfilment of the Obligation to Inform (‘‘Communiqué’’) published in the Official Gazette dated March 10, 2018. Article 5 of the Communiqué regulates the procedures and principles that should be focused on the application. There are two provisions in the Law regarding the form of applications to be made to the data controller. The first of these is the written application containing a wet ink signature. In addition, applications can be made electronically.
The data controller will fulfil the requests in the application as soon as possible and no later than thirty days; however if the process requires an additional cost, the fee in the tariff determined by the Board may be charged. The 30-day period in written request starts with the date of notification of the document to the data controller or its representative, requests made by other methods; It will start from the date the request is received by the data controller.
As a result of the request of the data subject to the data controller;
- If the request is refused,
- The response is found insufficient
- The request is not responded to within the specified time period,
The data subject may lodge a complaint with the Board within thirty days as he or she learns about the response of the data controller, or within sixty days as of the requested date, in any case.
Within the scope of the Board decision dated 24.01.2019 and numbered 2019/9 data subjects can file a complaint with the Board within 60 days of making a request to the data controller.
You can reach further information here.
Kind regards,
Zumbul Attorneys at Law
Türkçe
English