Several measures are taken in our country to prevent the spread of Coronavirus (Covid-19) epidemic, which is effective all over the world. Within the scope of these measures, many employers have implemented different measures to protect the health of their employees, customers, visitors, business partners and their families. One of such measures is the remote working model which raises the question of what will be the responsibilities of the data controllers during the application of remote working model?
IS THERE ANY REGULATION UNDER THE PERSONAL DATA PROTECTION LEGISLATION PREVENTING THE APPLICATION OF REMOTE WORKING MODEL?
First of all, it should be noted that the performance of the obligations envisaged for data controllers and data processors within the scope of the Personal Data Protection Law No. 6698 (“Law”) has not been ceased or postponed. As it always has been; all data processing activities should be carried out in accordance with the provisions of the Law and measures should be taken for the protection of personal data without disruption during the epidemic period.
However; although data controllers have taken all necessary administrative and technical measures in their workplaces for the protection and security of their personal data, and have created the appropriate technical infrastructure; with the transition to remote working model, the question is raised on how to maintain the protection of this data during working from home.
It should be stated that there are no regulations either under the Law or under the decisions and announcements of the Personal Data Protection Authority that will prevent the implementation of remote working model. Therefore; during the epidemic, employees can work from home and continue to perform their duties using their own devices or communication equipment. Nonetheless; in this process, the legal obligations of data controllers and data processors continue and therefore, all necessary security measures, administrative and technical precautions for the protection of personal data should be taken during the application of remote working model.
WHAT MEASURES SHOULD BE TAKEN TO ENSURE THE PROTECTION OF PERSONAL DATA DURING REMOTE WORKING?
As stated in the Public Announcement of Personal Data Protection Authority dated 27.03.2020; in order to minimize the risks that may be caused by remote working, it is required to take every precaution to maintain the protection of personal data during remote working period, such as ensuring that the data traffic between the systems is carried out with secure communication protocols and ensuring that it does not contain any weakness, and that anti-virus systems and firewalls are updated, and also it is important to inform the employees about the measures to be taken by the same during such period.
At this point, it becomes important whether the employees have remote access to the infrastructure systems of the workplace during the work from home and whether they perform their work through these systems. Under normal conditions, storage and processing of data in the workplace is done within a certain systematic and rules. For example; who can access to which information in the system is defined, employees’ access to the system, their log-in and log-out are tracked, documents containing personal data are kept accessible to certain people, etc. In this way; personal data is prevented from being exchanged, transferred and the access to the data is limited within the scope of the need-to-know principle. In addition, data storage systems are protected with superior technical measures and secured against possible access by unauthorized persons. However, it is difficult to achieve this systematic protection in the process of working from home, since many employees use personal communication tools instead of office computers, phones and e-mail addresses. At this point, ensuring data security maintains a problem.
Similarly; it will also be necessary to evaluate whether the explicit consents received from the employees regarding the storage and processing of their personal data currently include new personal data to be obtained during remote working process, since employees’ personal cell phones, e-mail addresses, and information about their location to be shared in this process also constitute personal data. For example; if an employee resides at an address other than his residence address included in his personal employment file, and shares this address for communication, an explicit consent of such employee should be obtained for collection, storage and processing of such data in accordance with Paragraph 1 of Article 5, of the Law. In this respect; the information flow processes during the implementation of the remote working model should also be evaluated within the scope of the Law.
WHY IS IT NECESSARY TO COMPLY WITH DATA PROTECTION PROVISIONS DURING REMOTE WORKING?
As we mentioned above; the obligations imposed on the data controllers continue during the process of remote working, which is one of the measures taken within the scope of fighting against the epidemic. Therefore; the measures to be taken by the employees during working from home will not eliminate the responsibility of the data controllers to ensure the security of personal data under the Law.
In accordance with Articles 5 and 10 of the Law, explicit consents must be obtained and disclosure obligations must be fulfilled, and also data security must be maintained pursuant to Article 12. In that respect; data controllers are required to take measures to ensure that their employees do not violate data confidentiality and their obligations envisaged under the Law during the remote working process. Otherwise, it may be possible to be subjected to the sanctions envisaged under the Law.
ERKUT LAW OFFICE
For Turkish version, click here.
Türkçe
