Self-Disclosure or Burying the Evidence Dilemma: A Legal Review of the Data Breach Rules under the Turkish Personal Data Protection Law
dc.authorscopusid | 57189635058 | |
dc.contributor.author | Kaya, M.B. | |
dc.date.accessioned | 2024-07-18T20:17:24Z | |
dc.date.available | 2024-07-18T20:17:24Z | |
dc.date.issued | 2021 | |
dc.description.abstract | Technology has penetrated every aspect of life and brought security and privacy issues to the forefront of the regulatory landscape. In such a hyper-connected world, security breaches are inevitable. Hence, general legislation in the field of protection of personal data is becoming ubiquitous. The rules are likewise being drafted to ensure the highest degree of privacy and security. The violation of security requirements can have an unprecedented and catastrophic consequence on data controllers. A security incident can compel the data controller to notify a competent data protection authority of a breach and communicate all facts to affected data subjects. Data breach notification is self-disclosure of the data controller about a personal data-related incident regardless of the intentional or negligent character of the event. The underlying aim of this obligation is to prevent or mitigate all adverse effects or damage deriving from a data breach incident. This article maps out the legal framework governing data breach notification under the European Union’s law, in particular General Data Protection Regulation and the Turkish Data Protection Law. This article maintains that strict and burdensome data breach notification rules do not serve the interest of data protection of individuals as data controllers could refrain from notification and bury the pieces of evidence. Such a notification-phobia is a major threat to the overall cybersecurity realm. The article emphasizes that there is a need for balanced rules and adequate accountability tools which would encourage data controllers to report any data breach incidents without hesitation. © 2021 The authors. | en_US |
dc.identifier.doi | 10.26650/annales.2021.70.0007 | |
dc.identifier.endpage | 241 | en_US |
dc.identifier.issn | 0578-9745 | |
dc.identifier.issue | 70 | en_US |
dc.identifier.scopus | 2-s2.0-85174480758 | en_US |
dc.identifier.scopusquality | N/A | en_US |
dc.identifier.startpage | 195 | en_US |
dc.identifier.trdizinid | 510419 | en_US |
dc.identifier.uri | https://doi.org/10.26650/annales.2021.70.0007 | |
dc.identifier.uri | https://search.trdizin.gov.tr/yayin/detay/510419 | |
dc.identifier.uri | https://hdl.handle.net/11411/6518 | |
dc.indekslendigikaynak | Scopus | en_US |
dc.indekslendigikaynak | TR-Dizin | en_US |
dc.language.iso | en | en_US |
dc.publisher | Istanbul University Press | en_US |
dc.relation.ispartof | Annales de la Faculte de Droit d'Istanbul | en_US |
dc.relation.publicationcategory | Makale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı | en_US |
dc.rights | info:eu-repo/semantics/openAccess | en_US |
dc.subject | Breach | en_US |
dc.subject | Cybersecurity | en_US |
dc.subject | Data Protection | en_US |
dc.subject | Notification | en_US |
dc.subject | Privacy | en_US |
dc.title | Self-Disclosure or Burying the Evidence Dilemma: A Legal Review of the Data Breach Rules under the Turkish Personal Data Protection Law | en_US |
dc.title.alternative | Kendini Ihbar Etme veya Delilleri Yok Etme Ikilemi: Kişisel Verilerin Korunması Hukuku Bağlamında Veri Ihlal Bildirimi Kurallarının Hukuki Analizi | en_US |
dc.type | Article | en_US |