The Personal Data Protection Authority (KVKK) published a public announcement titled "About the Data Controllers Registry" on 01.08.2024. The announcement stated that a total of 503,935,000 TL (Five hundred three million nine hundred thirty-five thousand Turkish Lirasi, approximately 14,000,000 EUR) in administrative fines had been imposed on domestic and foreign data controllers who failed to fulfill their registration and notification obligations, and disciplinary measures had been applied to public institutions.
The key points of the announcement are as follows:
Mandatory Registration:
According to Article 16 of the Personal Data Protection Law No. 6698, real and legal persons processing personal data are required to register with the Data Controllers Registry before starting data processing.
All data controllers, except those exempted by the Personal Data Protection Board Decision No. 2021/238 dated 11 March 2021, were obligated to register and notify the Registry by 31 December 2021.
Penalties for Non-Compliance:
Article 18 of the Law prescribes administrative fines ranging from 20,000 TL to 1,000,000 TL for those who fail to register and notify the Registry.
Public institutions and organizations, along with professional organizations with public institution status, are subject to disciplinary actions for non-compliance, as per the notification by the Board.
According to these regulations, the Board conducted ex officio investigations on approximately 16,350 data controllers out of the 130,600 obligated to register, who failed to fulfill their registration and notification duties. As a result of these investigations, as of 1 August 2024, a total of 503,935,000 TL (Five hundred three million nine hundred thirty-five thousand Turkish Liras) in administrative fines were imposed on non-compliant domestic and foreign data controllers. Additionally, disciplinary measures were applied to the relevant public institutions and professional organizations.
This announcement contains significant decisions that underscore KVKK's commitment to ensuring compliance with data protection regulations and accountability of data controllers.
The comprehensive inspection by KVKK, resulting in a total of 503,935,000 TL in administrative fines and the identification of approximately 16,350 data controllers who failed to meet their registration and notification obligations, highlights the necessity for data controllers to comply both domestically and internationally. This indicates that data controllers operating outside of Turkey are also subject to Turkish KVKK regulations and can face penalties for non-compliance.
In conclusion, this announcement by KVKK on 1 August 2024 demonstrates that stricter inspections and serious sanctions are being implemented in the field of personal data protection. It is of utmost importance that data controllers fulfill their registration and notification obligations timely and completely.