2011-07-17
Added · Updated
The Minister of Justice issued these regulations to implement the Law on the Protection of Personal Data, defining key terms such as Data Controller, Data Processor, and Sensitive Personal Data. The rules impose specific obligations on Data Controllers to ensure lawful, fair, and transparent processing, including requirements for data minimization, accuracy, limited retention, and appropriate security measures. Controllers must maintain detailed records of processing activities, restrict access to authorized personnel, and cooperate with the supervisory Authority. These regulations entered into force upon their publication in the Official Gazette on July 17, 2011.
1 2011/17/7 No. 5102
Article 1: For the purpose of implementing the provisions of the Law on the Protection of Personal Data (hereinafter referred to as "the Law"), the following regulations are issued.
Article 2: The definitions of terms used in these regulations are as follows:
Article 3: The Minister of Justice shall have the authority to issue necessary instructions and circulars to implement these regulations.
Article 4: The Data Controller shall ensure that the processing of personal data is lawful, fair, and transparent in relation to the Data Subject.
Article 5: Personal data shall be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
Article 6: Personal data shall be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
Article 7: Personal data shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.
Article 8: Personal data shall be kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed.
Article 9: Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.
Article 10: The Data Controller shall implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
Article 11: The Data Controller shall ensure that any person acting under the authority of the Data Controller or the Data Processor who has access to personal data does not process them except on instructions from the Data Controller or Data Processor.
Article 12: The Data Controller shall cooperate with the Authority established under the Law and provide any information or documents requested by the Authority to ensure compliance with the Law and these regulations.
Article 13: The Data Controller shall maintain a record of processing activities under its responsibility and control, containing the name and contact details of the Data Controller, the purposes of the processing, the categories of data subjects and personal data, the categories of recipients, transfers to third countries, retention periods, and a general description of technical and organizational security measures.
Article 14: The provisions of these regulations shall come into force on the date of their publication in the Official Gazette.
Issued on 17/7/2011 corresponding to 5102 Minister of Justice