Data Privacy and Protection
The origin of the legal protection of personal data lies in the idea of protecting the individual against the state. In particular, the discrimination carried out by the State against Jewish people in Nazi Germany fueled the notion that personal data belonging to individuals should not be known even by the state. Subsequently, with the development of information technology methods and the growth of companies, the idea that personal data should be protected against companies and other individuals as much as against the state began to take hold. The categorization and profiling of individuals based on criteria such as their political views, ideologies, religious attitudes, sexual orientation, and ethnic origins—without their knowledge or consent—as well as the circulation and sale of this information, are contrary to human dignity and constitute a great interference with individuals’ privacy (and even their freedom). At the same time, the risk of this data falling into the hands of unwanted individuals further increases the danger. For this reason, prohibiting the processing (recording, sharing, etc.) of all personal data belonging to individuals without explicit consent (except for specific exceptions) has been accepted as a general principle. It is for these reasons that many legal protections similar to the standards in European Union countries have been introduced regarding personal data in Turkey, as in many other countries.
This relatively new legal field grants certain rights to individuals while also imposing specific obligations on institutions. The violation of these obligations exposes institutions to significant penalties. Therefore, both individuals and institutions need the support of legal professionals specialized in this area.
How Can We Assist You?
TEK&partners provides the following services to its corporate clients to ensure they do not face any compensation claims or administrative fines related to data privacy:
Auditing: Conducting audits.
VERBIS Registration: Registration with the Data Controllers Registry Information System (VERBIS).
Inventory Preparation: Preparing the data inventory.
Legacy Data Compliance: Organizing previous data and adapting it to comply with the law.
Policy Determination: Defining the personal data collection policy.
Sensitive Data Policy: Defining the collection policy for special categories of personal data (sensitive personal data).
Notice Preparation: Drafting the mandatory data protection notice
Consent Preparation: Drafting the explicit consent form
Awareness Training: Conducting awareness training sessions.
Security Measures: Implementing administrative and technical measures, and establishing system and physical security precautions.
Destruction Policy: Defining the personal data destruction policy.
Sensitive Data Destruction Policy: Defining the destruction policy for special categories of personal data.