Turkish DPA’s Guidelines on Data Protection in the Banking Sector

Recent Developments

On 5 August 2022, the Turkish Personal Data Protection Authority (DPA) published the Guidelines on Protection of Personal Data in the Banking Sector (“ Guidelines “). The Guidelines provide detailed explanations on data processing activities and give examples of good practices in the banking sector. The Guidelines are available online here (in Turkish).

What do the Guidelines say?

The Guidelines mainly cover the following areas:

Conclusion

In the Guidelines, the DPA discusses data processing activities within the scope of banking operations in detail and provides important guidance for implementing the obligations. The Guidelines clarified the relationship between Article 73 of the Banking Law and LPPD. Accordingly, for the transfer of client information under Article 73, the provisions of Banking Law will take priority. Banks should review the Guidelines and take action in accordance with the guidance.