
In 2023, there was extensive discussion both nationally and internationally about data protection, cybersecurity, and artificial intelligence applications. Let’s take a closer look together at some of the notable developments in data protection and AI applications during that emerged in 2023.
A Public Announcement Regarding the Amendment to the Exemption Criteria for the Obligation to Register with the Data Controllers’ Registry has been Published. [3]
In the announcement, it was stated that businesses in our country have grown economically, their business volume has expanded, and the threshold of 25 million TRY, which was set in 2018, has become insufficient compared to the current annual financial statement totals. Therefore, the need to update the annual financial statement threshold specified in Board Decision No. 2018/87 has arisen. As a result of the assessment, the said exemption limit has been increased from 25 million Turkish Liras to 100 million Turkish Liras.
In this context, with its decision dated 06.07.2023 and numbered 2023/1154, the Board announced that real or legal person data controllers whose annual number of employees is less than 50 and whose annual financial statement total is less than 100 million Turkish Liras, and whose main activity does not involve the processing of sensitive personal data, are exempt from the obligation to register with the Registry. [4]
The “Recommendations on Privacy in Mobile Applications” Guide has been published. [5]
The key topics highlighted in the guide are summarized as follows:
Privacy protection measures for individuals using the mobile application
The Guide includes the following:
Public Announcement on the Processing of Personal Data by Sending Verification Codes via SMS to SMS to Data Subjects During In-Store Shopping!
The Personal Data Protection Board (“Board”) has made the following evaluations in summary:
The Personal Data Protection Authority (“KVKK”) has decided to impose an administrative fine of 1,750,000 TRY on TikTok.
Following its examination of the TikTok application on internet and social media platforms, the KVKK concluded the following:
The Network and Information Security (“NIS”) Directive is recognized as the first legislation on cybersecurity across the European Union (“EU”), with its primary objective being to ensure a high level of common cybersecurity among Member States.
In a statement published at the beginning of 2023 by the Parliament, it was noted that although the NIS Directive has strengthened the cybersecurity capacities of Member States, the increasing threats due to digitalization and the rise in cyberattacks necessitate revising the NIS Directive. Accordingly, the NIS2 Directive was introduced to strengthen security requirements, implement stricter monitoring measures, and establish more stringent enforcement requirements, ultimately aiming to enhance the level of cybersecurity in Europe in the long term.
The NIS2 Directive highlights several notable points:
As of January 16, 2023, the NIS2 Directive has entered into force, and Member States are required to transpose the measures into their national laws within a 21-month period, by October 17, 2024.
The social media platform Twitter announced the launch of a “zero tolerance against verbal violence” policy, completely banning violent content, threats, glorification of violence, or incitement to violence.
Twitter stated that it would review actions before temporarily or permanently suspending an account, clarifying that it would not intervene with accounts containing satire or artistic expression. However, it also emphasized that accounts violating the rules would be suspended, and in the event of repeated violations, the account would be permanently closed.
According to a news article published by Reuters, the Spanish data protection authority Agencia Española de Protección de Datos (“AEPD”) has officially called on the European Data Protection Board to examine the compliance of ChatGPT, owned by OpenAI, with the EU General Data Protection Regulation (“GDPR”). A spokesperson for AEPD stated that the matter was brought forward “to enable the implementation of harmonized actions within the framework of GDPR enforcement.”
Additionally, the report mentions that OpenAI offers payments of up to 20,000 USD for error reports concerning ChatGPT.
According to a BBC report, the Italian data protection authority (“Data Protection Authority”) issued a blocking decision against ChatGPT on the grounds that it violated rules related to the collection of Italian users’ data. The authority also ordered the suspension of data processing of users' information and warned that, due to the absence of a system to verify users’ ages, children might be exposed to responses inappropriate for their development and awareness.
This decision reportedly followed a data breach that occurred on March 20. The data protection authority gave OpenAI 20 days to implement the requested measures, warning that failure to comply could result in fines of up to 20 million Euros or 4% of the company’s annual global turnover. [11]
According to an investigation by Reuters, former Tesla employees allegedly circulated “highly intrusive videos and images recorded by customers’ vehicle cameras” within the company’s internal messaging system. The report includes interviews with nine former employees claiming that the recordings captured Tesla customers in embarrassing situations and were shared among employees between 2019 and 2022. Although Tesla’s privacy notice states that “camera recordings remain anonymous and are not linked to any individual or vehicle,” multiple employees assert that Tesla has a program capable of determining where the videos were recorded.
The French Data Protection Authority (“CNIL”) fined the scooter rental company Cityscoot €125,000 for collecting and recording vehicles’ geographic location data.
CNIL stated that Cityscoot failed to comply with data minimization and contractual framework obligations under the EU General Data Protection Regulation (“GDPR”) and also violated the French Data Protection Law by not informing users and failing to obtain consent for access to the data.
On June 27, 2023, the Danish Data Protection Authority (“Datatilsynet”) released a guideline regarding the use of CCTV cameras, covering important points companies must consider about CCTV usage. It details when a behavior constitutes CCTV surveillance, how companies can fulfill their obligation to inform individuals being monitored through CCTV, and the rules to be observed in the storage and disclosure of CCTV recordings.
The letter sent by the Information Commissioner’s Office detailed how companies can rectify their errors and stated that the relevant notice was shared publicly to encourage compliance among other websites.
The AP proposed presenting a full AI plan by 2030 to ensure more human control and to increase everyday awareness of how AI might impact lives.
IMY found that while Spotify responded to data access requests, it “did not provide sufficiently clear information on how the company uses this data,” adding that Spotify needs to be “more specific” in explaining its data practices and “make it easier for the individual requesting access to understand how the company uses their data.”
According to research commissioned by the ICO, which found that 70% of the public consider being monitored by an employer intrusive, the Authority emphasizes that all forms of monitoring must fully comply with data protection law. The guide also includes best practice recommendations to help employers build trust with their employees and respect their privacy rights.
The announcement states that following the official adoption by the Council, the new law will be published in the Official Journal of the EU in the coming weeks and will enter into force on the twentieth day after its publication.
The Data Act introduces new rules regarding who can access and use data produced in the EU across all economic sectors.
The purpose of the law has been outlined as follows, in summary:
With the relevant legislative regulation, it is anticipated that users of connected devices—ranging from smart home appliances to intelligent industrial machines—will be granted access to the data generated through the use of these devices, which is typically collected solely by manufacturers and service providers.
The Data Act, following its publication in the Official Journal on 22 December 2023, will enter into force on 11 January 2024. While certain provisions are known to take effect at a later stage, the majority of the rules will start to apply as of 12 September 2025.
In Brief:
[1] For detailed information, see https://www.kvkk.gov.tr/Icerik/7546/-Taahhutname-Basvurusu-Hakkinda-Duyuru
[2] For detailed information, see https://www.kvkk.gov.tr/Icerik/7700/Taahhutname-Basvurusu-Hakkinda-Duyuru
[3] For detailed information, see https://www.kvkk.gov.tr/Icerik/7646/Kamuoyu-Duyurusu-Veri-Sorumlulari-Siciline-Kayit-Yukumlulugune-Iliskin-Istisna-Kriterinde-Degisiklik-Yapilmasi-Hakkinda-
[4] For detailed information, see https://www.kvkk.gov.tr/Icerik/7646/Kamuoyu-Duyurusu-Veri-Sorumlulari-Siciline-Kayit-Yukumlulugune-Iliskin-Istisna-Kriterinde-Degisiklik-Yapilmasi-Hakkinda-.
[5] For detailed information, see https://kvkk.gov.tr/SharedFolderServer/CMSFiles/8ba209bb-fa93-4479-84f0-dd55aac97a0f.pdf
[6] For detailed information, see https://kvkk.gov.tr/SharedFolderServer/CMSFiles/703442e0-690c-4618-91c3-83e7583170ca.pdf.
[7] For detailed information, see https://www.kvkk.gov.tr/Icerik/7740/Magazalarda-Alisveris-Sirasinda-Ilgili-Kisilere-SMS-ile-Dogrulama-Kodu-Gonderilmesi-Suretiyle-Kisisel-Verilerin-Islenmesine-Iliskin-Kamuoyu-Duyurusu
[8] For the relevant decision text of the Personal Data Protection Authority (KVKK), see https://www.kvkk.gov.tr/Icerik/7538/2023-134.
[9] For access to the relevant Directive, see (ENG) https://www.europarl.europa.eu/RegData/etudes/BRIE/2021/689333/EPRS_BRI(2021)689333_EN.pdf.
[10] For detailed information, see https://iapp.org/news/a/aepd-urges-edpb-probe-into-chatgpt/.
[11] For the news content, see https://www.bbc.com/turkce/articles/cw0971dy8rzo.
[12] For the news content, see https://iapp.org/news/a/former-tesla-employees-allege-they-circulated-videos-of-customers-captured-by-their-vehicle/.
[13] For the relevant announcement see https://iapp.org/news/a/cnil-fines-rental-scooter-company-over-geolocation-data-collection/.
[14] For detailed information, see https://www.dataguidance.com/news/denmark-datatilsynet-issues-guidance-use-cctv
[15] For detailed information, see https://ico.org.uk/media/about-the-ico/documents/4027811/cookie-banner-concerns.pdf.
[16] For detailed information, see https://www.autoriteitpersoonsgegevens.nl/actueel/ai-algoritmerisicos-nemen-toe-nationaal-deltaplan-nodig.
[17] For detailed information, see https://iapp.org/news/a/swedens-dpa-issues-sek58m-gdpr-fine-to-spotify/.
[18] For detailed information, see https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2023/10/ico-publishes-guidance-to-ensure-lawful-monitoring-in-the-workplace
[19] For detailed information, see https://www.consilium.europa.eu/en/press/press-releases/2023/11/27/data-act-council-adopts-new-law-on-fair-access-to-and-use-of-data/?utm_source=dsms-auto&utm_medium=email&utm_campaign=Data+Act%3a+Council+adopts+new+law+on+fair+access+to+and+use+of+data.
[20] For detailed information, see https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202302854
[21] For detailed information, see https://fintechistanbul.org/2023/04/10/yapay-zeka-sohbet-robotu-chatgptnin-finans-hali-bloomberggpt-duyuruldu/.
[22] For detailed information, see https://iapp.org/news/a/2023-a-critical-inflection-point-for-ai/.
[23] For detailed information, see https://iapp.org/news/a/marketing-firm-contracted-by-dutch-national-railway-breached-through-a-software-supplier/.
[24] For detailed information, see https://iapp.org/news/a/norwegian-dpa-fines-medical-device-company-for-breach-notification-violation/.
[25] For detailed information, see https://ec.europa.eu/commission/presscorner/detail/en/IP_23_6709.
In 2023, there was extensive discussion both nationally and internationally about data protection, cybersecurity, and artificial intelligence applications. Let’s take a closer look together at some of the notable developments in data protection and AI applications during that emerged in 2023.
A Public Announcement Regarding the Amendment to the Exemption Criteria for the Obligation to Register with the Data Controllers’ Registry has been Published. [3]
In the announcement, it was stated that businesses in our country have grown economically, their business volume has expanded, and the threshold of 25 million TRY, which was set in 2018, has become insufficient compared to the current annual financial statement totals. Therefore, the need to update the annual financial statement threshold specified in Board Decision No. 2018/87 has arisen. As a result of the assessment, the said exemption limit has been increased from 25 million Turkish Liras to 100 million Turkish Liras.
In this context, with its decision dated 06.07.2023 and numbered 2023/1154, the Board announced that real or legal person data controllers whose annual number of employees is less than 50 and whose annual financial statement total is less than 100 million Turkish Liras, and whose main activity does not involve the processing of sensitive personal data, are exempt from the obligation to register with the Registry. [4]
The “Recommendations on Privacy in Mobile Applications” Guide has been published. [5]
The key topics highlighted in the guide are summarized as follows:
Privacy protection measures for individuals using the mobile application
The Guide includes the following:
Public Announcement on the Processing of Personal Data by Sending Verification Codes via SMS to SMS to Data Subjects During In-Store Shopping!
The Personal Data Protection Board (“Board”) has made the following evaluations in summary:
The Personal Data Protection Authority (“KVKK”) has decided to impose an administrative fine of 1,750,000 TRY on TikTok.
Following its examination of the TikTok application on internet and social media platforms, the KVKK concluded the following:
The Network and Information Security (“NIS”) Directive is recognized as the first legislation on cybersecurity across the European Union (“EU”), with its primary objective being to ensure a high level of common cybersecurity among Member States.
In a statement published at the beginning of 2023 by the Parliament, it was noted that although the NIS Directive has strengthened the cybersecurity capacities of Member States, the increasing threats due to digitalization and the rise in cyberattacks necessitate revising the NIS Directive. Accordingly, the NIS2 Directive was introduced to strengthen security requirements, implement stricter monitoring measures, and establish more stringent enforcement requirements, ultimately aiming to enhance the level of cybersecurity in Europe in the long term.
The NIS2 Directive highlights several notable points:
As of January 16, 2023, the NIS2 Directive has entered into force, and Member States are required to transpose the measures into their national laws within a 21-month period, by October 17, 2024.
The social media platform Twitter announced the launch of a “zero tolerance against verbal violence” policy, completely banning violent content, threats, glorification of violence, or incitement to violence.
Twitter stated that it would review actions before temporarily or permanently suspending an account, clarifying that it would not intervene with accounts containing satire or artistic expression. However, it also emphasized that accounts violating the rules would be suspended, and in the event of repeated violations, the account would be permanently closed.
According to a news article published by Reuters, the Spanish data protection authority Agencia Española de Protección de Datos (“AEPD”) has officially called on the European Data Protection Board to examine the compliance of ChatGPT, owned by OpenAI, with the EU General Data Protection Regulation (“GDPR”). A spokesperson for AEPD stated that the matter was brought forward “to enable the implementation of harmonized actions within the framework of GDPR enforcement.”
Additionally, the report mentions that OpenAI offers payments of up to 20,000 USD for error reports concerning ChatGPT.
According to a BBC report, the Italian data protection authority (“Data Protection Authority”) issued a blocking decision against ChatGPT on the grounds that it violated rules related to the collection of Italian users’ data. The authority also ordered the suspension of data processing of users' information and warned that, due to the absence of a system to verify users’ ages, children might be exposed to responses inappropriate for their development and awareness.
This decision reportedly followed a data breach that occurred on March 20. The data protection authority gave OpenAI 20 days to implement the requested measures, warning that failure to comply could result in fines of up to 20 million Euros or 4% of the company’s annual global turnover. [11]
According to an investigation by Reuters, former Tesla employees allegedly circulated “highly intrusive videos and images recorded by customers’ vehicle cameras” within the company’s internal messaging system. The report includes interviews with nine former employees claiming that the recordings captured Tesla customers in embarrassing situations and were shared among employees between 2019 and 2022. Although Tesla’s privacy notice states that “camera recordings remain anonymous and are not linked to any individual or vehicle,” multiple employees assert that Tesla has a program capable of determining where the videos were recorded.
The French Data Protection Authority (“CNIL”) fined the scooter rental company Cityscoot €125,000 for collecting and recording vehicles’ geographic location data.
CNIL stated that Cityscoot failed to comply with data minimization and contractual framework obligations under the EU General Data Protection Regulation (“GDPR”) and also violated the French Data Protection Law by not informing users and failing to obtain consent for access to the data.
On June 27, 2023, the Danish Data Protection Authority (“Datatilsynet”) released a guideline regarding the use of CCTV cameras, covering important points companies must consider about CCTV usage. It details when a behavior constitutes CCTV surveillance, how companies can fulfill their obligation to inform individuals being monitored through CCTV, and the rules to be observed in the storage and disclosure of CCTV recordings.
The letter sent by the Information Commissioner’s Office detailed how companies can rectify their errors and stated that the relevant notice was shared publicly to encourage compliance among other websites.
The AP proposed presenting a full AI plan by 2030 to ensure more human control and to increase everyday awareness of how AI might impact lives.
IMY found that while Spotify responded to data access requests, it “did not provide sufficiently clear information on how the company uses this data,” adding that Spotify needs to be “more specific” in explaining its data practices and “make it easier for the individual requesting access to understand how the company uses their data.”
According to research commissioned by the ICO, which found that 70% of the public consider being monitored by an employer intrusive, the Authority emphasizes that all forms of monitoring must fully comply with data protection law. The guide also includes best practice recommendations to help employers build trust with their employees and respect their privacy rights.
The announcement states that following the official adoption by the Council, the new law will be published in the Official Journal of the EU in the coming weeks and will enter into force on the twentieth day after its publication.
The Data Act introduces new rules regarding who can access and use data produced in the EU across all economic sectors.
The purpose of the law has been outlined as follows, in summary:
With the relevant legislative regulation, it is anticipated that users of connected devices—ranging from smart home appliances to intelligent industrial machines—will be granted access to the data generated through the use of these devices, which is typically collected solely by manufacturers and service providers.
The Data Act, following its publication in the Official Journal on 22 December 2023, will enter into force on 11 January 2024. While certain provisions are known to take effect at a later stage, the majority of the rules will start to apply as of 12 September 2025.
In Brief:
[1] For detailed information, see https://www.kvkk.gov.tr/Icerik/7546/-Taahhutname-Basvurusu-Hakkinda-Duyuru
[2] For detailed information, see https://www.kvkk.gov.tr/Icerik/7700/Taahhutname-Basvurusu-Hakkinda-Duyuru
[3] For detailed information, see https://www.kvkk.gov.tr/Icerik/7646/Kamuoyu-Duyurusu-Veri-Sorumlulari-Siciline-Kayit-Yukumlulugune-Iliskin-Istisna-Kriterinde-Degisiklik-Yapilmasi-Hakkinda-
[4] For detailed information, see https://www.kvkk.gov.tr/Icerik/7646/Kamuoyu-Duyurusu-Veri-Sorumlulari-Siciline-Kayit-Yukumlulugune-Iliskin-Istisna-Kriterinde-Degisiklik-Yapilmasi-Hakkinda-.
[5] For detailed information, see https://kvkk.gov.tr/SharedFolderServer/CMSFiles/8ba209bb-fa93-4479-84f0-dd55aac97a0f.pdf
[6] For detailed information, see https://kvkk.gov.tr/SharedFolderServer/CMSFiles/703442e0-690c-4618-91c3-83e7583170ca.pdf.
[7] For detailed information, see https://www.kvkk.gov.tr/Icerik/7740/Magazalarda-Alisveris-Sirasinda-Ilgili-Kisilere-SMS-ile-Dogrulama-Kodu-Gonderilmesi-Suretiyle-Kisisel-Verilerin-Islenmesine-Iliskin-Kamuoyu-Duyurusu
[8] For the relevant decision text of the Personal Data Protection Authority (KVKK), see https://www.kvkk.gov.tr/Icerik/7538/2023-134.
[9] For access to the relevant Directive, see (ENG) https://www.europarl.europa.eu/RegData/etudes/BRIE/2021/689333/EPRS_BRI(2021)689333_EN.pdf.
[10] For detailed information, see https://iapp.org/news/a/aepd-urges-edpb-probe-into-chatgpt/.
[11] For the news content, see https://www.bbc.com/turkce/articles/cw0971dy8rzo.
[12] For the news content, see https://iapp.org/news/a/former-tesla-employees-allege-they-circulated-videos-of-customers-captured-by-their-vehicle/.
[13] For the relevant announcement see https://iapp.org/news/a/cnil-fines-rental-scooter-company-over-geolocation-data-collection/.
[14] For detailed information, see https://www.dataguidance.com/news/denmark-datatilsynet-issues-guidance-use-cctv
[15] For detailed information, see https://ico.org.uk/media/about-the-ico/documents/4027811/cookie-banner-concerns.pdf.
[16] For detailed information, see https://www.autoriteitpersoonsgegevens.nl/actueel/ai-algoritmerisicos-nemen-toe-nationaal-deltaplan-nodig.
[17] For detailed information, see https://iapp.org/news/a/swedens-dpa-issues-sek58m-gdpr-fine-to-spotify/.
[18] For detailed information, see https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2023/10/ico-publishes-guidance-to-ensure-lawful-monitoring-in-the-workplace
[19] For detailed information, see https://www.consilium.europa.eu/en/press/press-releases/2023/11/27/data-act-council-adopts-new-law-on-fair-access-to-and-use-of-data/?utm_source=dsms-auto&utm_medium=email&utm_campaign=Data+Act%3a+Council+adopts+new+law+on+fair+access+to+and+use+of+data.
[20] For detailed information, see https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202302854
[21] For detailed information, see https://fintechistanbul.org/2023/04/10/yapay-zeka-sohbet-robotu-chatgptnin-finans-hali-bloomberggpt-duyuruldu/.
[22] For detailed information, see https://iapp.org/news/a/2023-a-critical-inflection-point-for-ai/.
[23] For detailed information, see https://iapp.org/news/a/marketing-firm-contracted-by-dutch-national-railway-breached-through-a-software-supplier/.
[24] For detailed information, see https://iapp.org/news/a/norwegian-dpa-fines-medical-device-company-for-breach-notification-violation/.
[25] For detailed information, see https://ec.europa.eu/commission/presscorner/detail/en/IP_23_6709.