The amendment to Article 9 of the KVKK introduces limited grounds for incidental transfers where the safeguards required for continuous transfers cannot be established. This overview considers those grounds in light of the GDPR and EDPB guidance.
The adoption of the 8th Judicial Reform Package by the Grand National Assembly of Türkiye introduced significant amendments to the Turkish Personal Data Protection Law No. 6698 (KVKK) concerning cross-border transfers of personal data. In addition to the rules governing continuous transfers, one of these amendments concerns transfers that are not continuous and are made only incidentally.
Under the new regime, a cross-border transfer may be made by this method where none of the safeguards for continuous transfers listed in Article 9(4) can be provided and one of the processing conditions set out below is met.
The circumstances listed in the provision on incidental transfers can be better understood in light of Guidelines 2/2018 on derogations under Article 49 of Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), referred to below as the Guidelines.
First, an incidental transfer may be considered only where there is no adequacy decision for the destination country and none of the safeguards listed in Article 9(4) of the KVKK can be provided. Because this is an exceptional form of processing, it must be interpreted narrowly. The amended provision lists the following incidental transfer grounds:
- The data subject gives explicit consent to the transfer after being informed of the possible risks.
- The transfer is necessary for the performance of a contract between the data subject and the data controller, or for the implementation of pre-contractual measures taken at the data subject's request.
- The transfer is necessary for the conclusion or performance of a contract, in the interest of the data subject, between the data controller and another natural or legal person.
- The transfer is necessary for an overriding public interest.
- The transfer of personal data is necessary for the establishment, exercise or protection of a right.
- The transfer is necessary to protect the life or physical integrity of the data subject, or of another person, where the data subject is physically incapable of giving consent or the consent would not be legally valid.
- The transfer is made from a register open to the public or to persons with a legitimate interest, provided that the conditions for access under the relevant legislation are met and the person with a legitimate interest requests the transfer.
Because the incidental transfer grounds introduced into Turkish law by the Judicial Reform Package were based on the GDPR, they correspond directly to the GDPR grounds, apart from subparagraph (g), which was adapted for Türkiye. The principal difference is that Turkish law has not yet adopted guidance equivalent to the Guidelines cited above.
The Guidelines explain how the GDPR provisions should be applied and clarify their definitions, scope and examples. Reviewing them is therefore important for understanding the incidental transfer rules that are entering Turkish practice.
Details of Incidental Transfers Under the Guidelines
According to the Guidelines, which were issued to explain and support the application of the GDPR, incidental transfers should generally have the following characteristics:[1]
- The transfer must be occasional. It must not form part of a stable, repeated course of transfers. For example, a transfer between an exporter and an importer that have an ongoing relationship cannot be regarded as incidental.
- There must be a necessity to rely on the derogation.
- Decisions issued by the authorities of the destination country do not, by themselves, provide a legal ground for the transfer.
- There must be no adequacy decision and none of the safeguards required for continuous data transfers must be available.
The data subject gives explicit consent to the transfer after being informed of the possible risks.[2]
A data controller may carry out the proposed transfer where, after being informed of the risks arising from the absence of an adequacy decision and appropriate safeguards, the data subject expressly consents to it. According to the Guidelines:
- Consent must be explicit.
- Consent must relate to the specific transfer that qualifies as incidental.
- For example, consent obtained by a company from data subjects for delivery purposes cannot be used several years later when the company is sold and a transfer abroad becomes necessary. Consent must be obtained for the specific circumstances existing at the time of the transfer.
- The data subject must be informed of the possible risks.
- The data subject must receive appropriate advance information about the specific circumstances of the transfer, including the identity of the controller, purpose of the transfer, categories of data, right to withdraw consent, and identity or categories of recipients. The data subject must also be informed that the destination country is not covered by an adequacy decision, that appropriate safeguards are absent and that consent is required as the legal basis.
This is one of the notable elements of the KVKK reform. The concept of explicit consent in Article 9 has been restructured. In addition to the general information duties for cross-border transfers, data controllers now have a separate duty to inform the data subject of the risks. This constitutes a specific and independent transparency obligation.[3]
When informing the data subject about a processing activity, the controller must provide the information required by the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform, issued by the Turkish Personal Data Protection Authority, and must also explain the risks of the incidental transfer.[4] This duty is expressly included in the law, and failure to comply may result in an administrative fine.
Under the amended Article 9 governing cross-border transfers, explicit consent is limited to incidental transfers. As a result, practitioners and data controllers will need to prepare revised privacy notices for transfers abroad that fall within the definition of an incidental transfer.
The transitional provisions of the reform ended the previous system of consent-based cross-border transfers on 1 September 2024. Before that date, data controllers needed to distinguish incidental transfers from continuous transfers and align the information provided for consent-based incidental transfers with the new rules.
The transfer is necessary for the performance of a contract between the data subject and the data controller, or for the implementation of pre-contractual measures taken at the data subject's request.[5]
A travel agency making a provisional hotel reservation in a third country for a customer is one example. The relationship with the hotel in that country is incidental. Where pre-contractual measures are concerned, they must be taken at the data subject's request.[6]
The transfer is necessary for the conclusion or performance of a contract, in the interest of the data subject, between the data controller and another natural or legal person.[7]
In this case the contract is not concluded with the data subject, but between the controller and a third natural or legal person. Data transmitted for travel and accommodation arranged for the benefit of the data subject may fall within this ground.
The transfer is necessary for an overriding public interest.[8]
An overriding public interest must justify the transfer. The provision deliberately uses a standard beyond ordinary public interest. Transfers concerning competition, taxation, social security, epidemics, anti-money laundering or match-fixing may, depending on the circumstances, fall within this ground.
The Guidelines state that it makes no difference whether the exporter or recipient is a public body or a private person.
The Guidelines nevertheless recommend, especially for public bodies, establishing safeguards and using a sustainable transfer mechanism instead of repeatedly relying on incidental circumstances.
The transfer of personal data is necessary for the establishment, exercise or protection of a right.[9]
According to the Guidelines, this ground may apply to judicial, administrative and out-of-court procedures. It may also apply to activities carried out by public authorities in the exercise of official powers. Procedures taking place in a third country are also within its scope.
The transfer must, however, be necessary in relation to an actual procedure; an abstract possibility does not provide a legal basis. Controllers should also consider whether the third country has blocking legislation or similar restrictions. The Guidelines further state that exporters must observe the GDPR principle of data minimisation in such transfers.
For example, this ground may be relied upon where a parent company established in a third country is sued by an employee temporarily assigned to one of the group's subsidiaries and data must be transferred for evidential purposes.[10]
The transfer is necessary to protect the life or physical integrity of the data subject, or of another person, where the data subject is physically incapable of giving consent or the consent would not be legally valid.[11]
The Guidelines explain that if a person loses consciousness outside the EU and needs urgent medical care, an exporter established in an EU Member State, such as the person's regular physician, must be legally able to provide the necessary data, including certain personal data.
This derogation cannot justify transferring medical data outside the EU unless the purpose is to treat the data subject's specific condition or that of another person. It cannot, for example, be used for general medical research expected to produce future results. Legal incapacity may also fall within this ground.
Search and rescue operations following a natural disaster are among the clearest examples given in the Guidelines.
This ground may also be used for an urgent transfer of a patient's medical data to a third country for treatment. There must be a serious threat to the life or physical integrity of the data subject. General transfers of health data cannot be based on this derogation.[12]
Transfer from an open register.[13]
This is the first ground that differs in its detailed wording from the corresponding GDPR provision. Under Turkish law, a transfer from an open register requires a legitimate interest and compliance with the statutory conditions governing access to that register.
The register must be open for consultation either by the public generally or by any person who can demonstrate a legitimate interest. Private registers cannot fall within this derogation. Examples may include company registers, association registers, criminal conviction registers, land registers and public vehicle registers.
The transfer may not cover all categories of data in the register and may be made only to the person making the request, with due regard to the interests of the data subjects.
The reform restricts reliance on incidental transfer grounds by public institutions and organisations when carrying out activities governed by public law. In that context, they may not rely on: (a) the data subject's explicit consent after being informed of possible risks; (b) necessity for the performance of a contract between the data subject and controller or for pre-contractual measures taken at the data subject's request; or (c) necessity for a contract concluded or performed in the data subject's interest between the controller and another natural or legal person.
The Turkish Personal Data Protection Authority should issue guidance to clarify the incidental transfer grounds.
The new Turkish rules clearly require certain situations to be assessed as exceptional circumstances. They also recognise that some scenarios may make the cross-border transfer of personal data unavoidable.
For this reason, guidance comparable to the GDPR Guidelines discussed above is also essential for the KVKK framework.
Such guidance should provide detailed rules and direction for protecting personal data and regulating international transfers in a way that reflects the specific needs and conditions of the KVKK.
In particular, it should guide controllers and data subjects and provide clarity on the circumstances in which an incidental transfer may be made and the steps required to carry it out.
References
- [1] European Data Protection Board (EDPB) (2018), Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679, https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_2_2018_derogations_en.pdf
- [2] EDPB (2018), ibid., p. 6.
- [3] Kaya, Mehmet Bedii (2024), KVKK Reformu: 2024 Değişiklikleri, p. 46 (Digital Edition 1.0), https://mbkaya.com/hukuk/kvkk-reformu.pdf
- [4] https://kvkk.gov.tr/Icerik/5443/AYDINLATMA-YUKUMLULUGUNUN-YERINE-GETIRILMESINDE-UYULACAK-USUL-VE-ESASLAR-HAKKINDA-TEBLIG
- [5] EDPB (2018), Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679, p. 8.
- [6] Kaya, Mehmet Bedii (2024), ibid., p. 48.
- [7] EDPB (2018), Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679, p. 9.
- [8] EDPB (2018), ibid., p. 10.
- [9] EDPB (2018), ibid., p. 11.
- [10] Kaya, Mehmet Bedii (2024), ibid., p. 49.
- [11] EDPB (2018), ibid., p. 12.
- [12] Kaya, Mehmet Bedii (2024), ibid., p. 50.
- [13] EDPB (2018), ibid., p. 13.
This content is provided for general information only and does not constitute legal advice.
