Dergiler / Yeditepe Üniversitesi Hukuk Fakültesi Dergisi / 2018 / Cilt: 15 - Sayı: 1
KİŞİSEL VERİLERİN İŞLENMESİNDE RIZA
- Sayfa
- 13–33
- DOI
- —
Özet
Kişisel Verilerin Korunması Kanunu’nda (KVVK) belirtildiği üzere, birgerçek kişinin kişisel verilerinin işlenebilmesi için o kimsenin bu işlemeye rızagöstermiş olması gerekir. Bireyin rızası olmadan kişisel verilerinin işlenmesi,ancak kanunda belirtilen hallerde ve kanunda belirtilen sınırlar çerçevesindemümkündür. KVKK, kişisel verilerin hukuka uygun bir şekilde işlenebilmesiiçin rızanın, “açık rıza” şeklinde verilmesini aramaktadır. KVKK, açıkrızanın tanımını 3. maddenin a bendinde yapmaktadır. Ancak bu tanımda yeralmayan bir unsur olan, rızanın “tereddüde yer bırakmayacak açıklıkta”olması gereği, kanun koyucunun bu unsuru tanımda yazmayı unutmuş olduğuizlenimi yaratırcasına madde gerekçesinde yer almaktadır. Kafa karışıklığınadaha çok sebep olan durum ise, 3. maddenin gerekçesinde açık rızanıntanımının mehaz düzenleme olan 95/46/EC sayılı Direktif dikkate alınarakyapıldığıdır. Ancak adı geçen direktif açık rızanın değil, sadece rızanıntanımını yapmakta ve rızanın tanımında, 3. maddenin gerekçesindebelirtilenin aksine, rızanın “tereddüde yer bırakmayacak açıklıkta”olması unsura yer vermemektedir. Bunun ötesinde KVKK, hem genelnitelikteki kişisel verilerin hem de korunmaya daha çok muhtaç olduğu içindaha nitelikli bir rızanın aranması gereken özel nitelikli kişisel verilerinişlenebilmesi için bünyesinde aynı unsurları barındıran ve tanımını da eksikolarak verdiği “açık rıza”nın varlığını aramaktadır. Mehaz düzenleme olan95/46/EC sayılı Direktif’in ise bu iki farklı kategorideki kişisel verilerinişlenebilmesi için aradığı rıza, farklı unsurları bünyesinde barındırmaktadır.Bütün bu nedenlerle KVKK’da bahsedilen açık rızadan neyin anlaşılmasıgerektiği sorusu, açıklığa kavuşturulması gereken güncel bir sorundur.Çalışmamızda da bu soruna yönelik çözüm önerileri getirilecektir.
Abstract
According to the (Turkish) Law on the Protection of Personal Data (LPPD), personal data may be processed if the data subject has declared its consent. Processing personal data without obtaining consent is only lawful within the scope and the limits of a legal basis. In order to process personal data lawfully, the LPPD requires the data subject’s consent to be given as “explicit consent”. The definition of “explicit consent” is laid down in Article 3 lit. a) LPPD. However, according to the grounds of this article, the consent has to be given “unambiguously” which might indicate that the aforementioned element has been forgotten to be included into the definition of Article 3 lit. a) itself. Another circumstance which creates even more confusion is that, according to the grounds of this article, the definition of “explicit consent” was made with reference to Directive 95/46/EC. Yet, the said Directive defines consent instead of explicit consent and the definition does not require the consent to be given “unambiguously” – contrary to the grounds of Article 3 LPPD. Moreover, under the LPPD, the concept of “explicit consent” applies to both – processing general personal data as well as processing sensitive personal data. The latter, however, requires a higher level of protection and, thus, also a more qualified type of consent – which is not expressed in the definition of “explicit consent” under the LPPD. On the contrary, Directive 95/46/EC – as referenced rule – requires different criteria including different elements for consent in order to process personal data in the abovementioned situations. Against this background, the question of how the concept of “explicit consent” in the sense of Article 3 lit. a) LPPD is to be understood, is a problem that needs to be solved urgently. Possible solutions to this problem will be presented in this article.