PROTECTION OF PERSONAL DATA DURING CORONAVIRUS (COVID-19) EPIDEMIC

PROTECTION OF PERSONAL DATA DURING CORONAVIRUS (COVID-19) EPIDEMIC

The Coronavirus (COVID-19) epidemic, which is effective in our country, has significantly affected the economic and social life, as well as brought some questions and problems in the world of law. In many areas from business law, commercial law, contracts law to corporate law, current law provisions and legal practices had to be reevaluated regarding this new situation and order. Personal data protection, which was one of the mostly discussed issues in the pre-epidemic period, is also came to the fore again in this direction.

Within the scope of measures taken by both administrative institutions and employers to prevent the epidemic, processing of many personal data, including sensitive personal data, has become inevitable. However, on what extend the duties and responsibilities of data controllers and data processors will continue under the Law No. 6698 on Protection of Personal Data (“Law”)?

HOW DOES THE CORONAVIRUS (COVID-19) EPIDEMIC AFFECT THE OBLIGATIONS RELATED TO PERSONAL DATA PROTECTION?

First of all, it should be noted that the performance of the obligations envisaged for data controllers and data processors within the scope of the Law has not been ceased or postponed. In fact, since the collection and processing of health data, which is currently considered as sensitive personal data, has become more widespread, it is even more important to carry out all activities in accordance with the provisions of the Law and to implement the measures taken for the security of personal data without delay.

WHAT ARE THE PRINCIPLES THAT MUST BE FOLLOWED DURING EPIDEMIC?

Although the protection of individuals and public health is essential in the process of fighting against the epidemic, it is clear that personal data processing activities should be necessary, linked, limited and measured in this process in order to protect the fundamental rights and freedoms of individuals. Therefore; data controllers and data processors are expected to comply with a number of basic principles. These principles are listed in the Public Announcement published by the Personal Data Protection Authority on 27.03.2020 as follows:

  • Being in compliance with the law and honesty rules,
  • Being accurate and up-to-date when necessary,
  • Being processed for specific, clear and legitimate purposes,
  • Being connected, limited and restrained for the purpose for which they are processed; and
  • Being kept for a period as defined under the related legislation or as necessary for the purpose of the collection of such data and deletion, destruction or anonymization in the event that the reasons requiring the process of the data are disappeared.

All personal data processing activities within the scope of fighting against the Coronavirus (COVID-19) epidemic should be carried out in accordance with these principles.

WHAT SHOULD BE CONSIDERED IN PROCESSING OF PERSONAL DATA COLLECTED TO MONITOR THE CORONAVIRUS (COVID-19) EPIDEMIC?

In accordance with the 1st Paragraph of Article 6 of the Law; the data related to people’s race, ethnicity, political thought, philosophical belief, religion, sect or other beliefs, disguise and outfit, association, foundation or union membership, health, sexual life, criminal conviction and security measures and biometric and genetic data is regarded as sensitive personal data.

As can be seen; health data is defined as sensitive personal data within the scope of the Law and subjected to more comprehensive protection. Although it is regulated under the second paragraph of Article 6 that it is forbidden to process sensitive personal data without the explicit consent of the concerned, it is envisaged under paragraph 3 of the same Article that it is allowed for the people who are under confidentiality obligation or authorized institutions and organizations to process personal data related to health and sexual life without explicit consent of the concerned party for the purposes of public health protection, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and financing.

Therefore; it would be appropriate for the data controllers who regularly take fever measurements to monitor the epidemic in their facility, request test results from their employees, and take similar measures leading to the collection of health data to obtain the explicit consent of their employees for the processing of this data. Additionally; it is essential that the disclosure obligation has been fulfilled before obtaining the explicit consent . In that respect; it is important that data controllers, who process the health data in question, provide information to employees on the measures they take, including the purpose of collecting personal data and how long it will be stored, by using a short, easily accessible, understandable, clear and plain language.

Nonetheless; if there is no health data in the data collected for the purpose of preventing the epidemic; for example, if it is merely required from the employees to provide information on whether they were in abroad within the last 14 days, or whether they have visited the risky areas, it may be evaluated that there is no need to obtain explicit consent in accordance with the exceptions specified under 5th Paragraph of Article 5 of the Law.

However, in this case, attention should be paid to data minimization, and the data processing activities carried out for the purpose of preventing the spread of Coronavirus (COVID-19) epidemic should be made in strict relation with the purpose of data collection and with a limited extend. In this respect; excessive processing of personal data should be avoided and the data obtained should be deleted, destroyed or anonymized in accordance with the destruction policies or in the event that the purpose of processing data disappears.

IS IT POSSIBLE TO TRANSFER THE PERSONAL DATA COLLECTED TO MONITOR THE SPREAD OF CORONAVIRUS (COVID-19) EPIDEMIC TO THIRD PARTIES?

As we mentioned above; the health data are regarded as sensitive personal data within the scope of the Law and therefore, subjected to more comprehensive protection. In that respect; the necessary administrative and technical measures should be taken to ensure the safety of the data in the processes related to the collection, storage and processing of health data collected in order to prevent the spread of the Coronavirus (COVID-19) epidemic. Additionally; such data should not be transferred to any third party without a mandatory legal obligation or a clear and compelling justification.

 

ERKUT LAW OFFICE

For Turkish version, click here.