Data Protection and Privacy 2025

TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Kübra İslamoğlu Bayer, Simge Yüce and Yiğit Aktimur, YAZICIOGLU Legal

Moreover, specific requirements for obtaining consent from users are further regulated in sec - ondary legislation. For instance, in cases where traffic and location data will be transferred, users must be informed about the scope of the data to be transferred, the name and address of the recipient party, the purpose and duration of the transfer, and if the third party is located abroad, the name of the country to which the data will be transferred, at the time of obtaining their con - sent. In a 2019 decision, ICTA mandated that all infra - structure, systems, and storage units related to eSIM technologies, including eSIM subscription management, must be set up in Türkiye either by operators authorised in Türkiye or by third parties designated by the operators, with the operator bearing full responsibility. Additionally, any data generated through eSIM technologies must be stored in Türkiye. Social Network Providers (SNPs) SNPs with daily access exceeding one mil - lion must implement the necessary measures to ensure that the data of their Turkish users is retained within Türkiye. ICTA further emphasised that priority should be given to storing essential user data and any other data specified by ICTA within Türkiye. Recently, on 18 September 2024, the Commu - nique on Commercial Electronic Message Man - agement System Integrators was published in the Official Gazette. It mandates that authori - sation from the Ministry of Trade is required to act as an integrator for service providers in registering approvals and rejections of market - ing communications in the MMS or to carry out these transactions through the MMS. The com - Commercial Electronic Message Management System Integrators

munique further stipulates that the information processing system used in integrator services, including software, hardware, and server infra - structure, must be located within a database inside Türkiye. Critical Infrastructure Service Providers The Decree on Information and Communication Security Measures issued by the Presidency of Türkiye (the “Presidency Decree”) sets specific measures to mitigate security risks, particularly for critical data that could jeopardise national security or public order if compromised. It man - dates that critical infrastructure (eg, energy, elec - tronic communications, banking, transportation) service providers ensure their primary and back - up data systems remain within Türkiye. The Presidency Decree applies not only to busi - nesses providing critical infrastructure services but also to public institutions and organisations, which must ensure the storage of critical data (eg, population, health and communication records, and genetic and biometric data) within Türkiye. Moreover, it stipulates that data from public institutions must not be stored in cloud services unless hosted in the institutions’ private systems or with local service providers under their con - trol. 5.4 Blocking Statutes Türkiye does not have specific “blocking” stat - utes, but general statutory provisions prevent the disclosure of matters relating to national interests to foreign entities. 5.5 Recent Developments Introduced in March 2024 through DP Law Amendments and came into effect on 1 June 2024, the new regime governing data transfers

492 CHAMBERS.COM

Powered by