About us.
agento presents legal and technical measures integratedly in a single awareness training.
Phone :+90 (232) 461 62 71
Penalties.
You can find all the details of the penalties related to KVKK on this page.
in Europe
For the first time since the General Data Protection Regulation (GDPR), adopted by the European Union last year, came into force, companies began to be fined. Companies in the EU were fined a total of 315 million Euros for not complying with the regulations.
The biggest penalty for data breaches was given to British Airways. The airline, whose customers' data was stolen by hackers in 2018, was fined 204 million euros.
It is also thought that the EU, which fined the hotel and luxury goods group Marriott, which announced that hackers had accessed the guest reservation database and had access to customer data for years, fined approximately 111 million euros at the end of last year, and will continue to impose high criminal sanctions.
In Turkey
Sanctions in terms of KVKK are divided into two. Sanctions have been issued in two different ways, in the sense of TCK (Turkish Penal Code) and in the sense of KVKK (Personal Data Protection Law).
Within the scope of the TPC, crimes between Articles 135 and 140 are regulated and there is a danger of imprisonment from 1 to 4 years.
In terms of KVKK, the Personal Data Protection Authority has an administrative fine. This administrative fine is between 5.000 TL - 1.000.000 TL.
Personal Data Protection Authority President Prof. Dr. Faruk BİLİR stated that the total number of files pending (meaning a lawsuit has been filed and is still being pending) so far due to the violation of personal data is around 850 and that the institutions have been fined approximately 5 million TL.
The institution may impose an administrative fine by examining your business ex officio (without any complaint) or upon complaint.
The Institution established the Alo 198 KVKK Information Consultancy Line in order to speed up the complaint process and the President of the Institution Prof. Dr. Faruk Bilir stated that more than 300 complaints were received per day.
Sanctions envisaged in the Law are arranged under two separate headings: Offenses and Misdemeanors.
Offenses Under the TCK
TCK Article 135,
Unlawful Recording of Personal Data: Imprisonment from 1 year to 3 years,
Article 136 of the TCK,
Unlawful Giving, Dissemination, Seizure of Personal Given: 2 to 4 years imprisonment to be given,
TCK Article 137,
Qualified forms of crimes in Article 136,
Article 138 of the TCK,
Those who are responsible for destroying the data within the system do not fulfill their duties;1 to 2 years imprisonment sentence,
Article 139 of the TCK,
Complaint path,
Article 140 of the TCK,
The implementation of security measures against legal entities has been regulated.
Pursuant to the TCK (Turkish Penal Code) No. 5235, the proceedings regarding the above crimes will be held in the Criminal Courts of First Instance. In terms of these crimes, as there is a possibility that the postponement of the sentence and the postponement of the announcement of the verdict may not be implemented pursuant to the provisions of the Turkish Penal Code and the CMK, in this case, a prison sentence may be faced when the sentence becomes final.
Misdemeanors in the Meaning of KVKK
Article 18 of the Law is regulated under the heading of Misdemeanors, and the amount is determined by the Board to real and legal persons who do not fulfill the obligations listed below, with the amount at intervals regulated in the relevant article of the Law.administrative finescan be given.
Administrative fines may be imposed on companies that process personal data, private law legal entities such as foundations, associations, and real persons, excluding public legal entities.
Those who do not fulfill the obligation of lighting regulated in article 10 of the Law about;
From 5,000 Turkish lira to 100,000 Turkish lira,
Those who do not fulfill their obligations regarding data security about;
From 15,000 Turkish lira to 1,000,000 Turkish lira,
Those who do not fulfill the decisions made by the Board about;
From 25,000 Turkish lira to 1,000,000 Turkish lira,
About those who violate the obligation to register and notify the Data Controllers Registry ;
Fines from 20,000 Turkish liras to 1,000,000 Turkish liras can be imposed.
