TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal
• insurance and private pension companies (except for services such as email, teleconference or vide - oconference); • certain public companies, as well as certain capital markets institutions; and • financial lease, factoring and finance companies. Banking Law and its Secondary Legislation Under the Banking Law, customer secrets cannot be disclosed or transferred abroad without customer instruction, with the following two exceptions: • transfers to authorities authorised by Turkish laws; and • sharing information and documents related to the preparation of consolidated financial statements, risk management and internal audit practices with a foreign parent company, provided that its capital share is at least 10% and a non-disclosure agree - ment is signed The By-Law on the Sharing of Secret Information applies to bank and customer secrets collectively, and also provides exceptions to secrecy prohibitions. Per - mitted transfers include: • per a Board resolution, sharing with third parties bank secrets that only contain banks-classified information; and • disclosures to the foreign judicial and alternative dispute resolution authorities or to the parties rep - resenting the bank in such disputes, when neces - sary for the proof of the claim or defence. The Communiqué on Payment Services Institutions may share data with foreign third parties for cross-border payment transactions, subject to domestic storage, necessity and proportionality. For outsourced products or services, the Communiqué on Payment Services requires the use of local products, or the manufacturers thereof to have R&D centres and response centres in Türkiye. General DP Law Regime on International Personal Data Transfers International personal data transfers are governed by the DP Law, amended on 12 March 2024 (effective
from 1 September 2024) to align with the General Data Protection Regulation. International personal data transfers are permitted under the following conditions. • The existence of a valid legal basis under the DP Law and an adequacy decision for the recipient country, international organisation or the sectors therein (note that the DPA has not yet issued any adequacy decision). • In the absence of an adequacy decision – the existence of a valid legal basis under the DP Law, enforceable rights and effective legal remedies for data subjects and provision of one of the following appropriate safeguards: (a) a legally binding and enforceable instrument between public authorities or bodies; (b) binding corporate rules; (c) standard contractual clauses; or (d) a written letter of commitment, together with the approval of the transfer by the Board. • In the absence of an adequacy decision or appro - priate safeguards – the existence of derogations for specific situations outlined in the DP Law, where the transfer is “occasional”. Although the DPA published the By-Law on Proce - dures for the Transfer of Personal Data Abroad and a guideline, debates on interpreting these provisions persist. The DP Law provides a reservation for provisions under other laws. Consequently, where such a spe - cific provision is applicable, it will override the transfer regime under the DP Law. The provisions explicitly mentioned in the Banking Sector Best Practices Guide on the Protection of Per - sonal Data are those on “consumer secrets” under the Banking Law and related secondary regulations. Although not explicitly mentioned, Article 24 under the By-Law on Measures for Preventing Money Launder - ing and Financing of Terrorism, which provides for the minimum information to be included in an international e-transfer, will also apply in a preceding manner.
428 CHAMBERS.COM
Powered by FlippingBook