'Most Innovative Startup 2020' by RSA - Watch the video
Learn MoreTurkey’s Law on the Protection of Personal Data (LPPD) is considered the trendsetter for data protection’s comprehensive worldwide legislation. Turkey published LPPD covering personal data protection on April 07, 2016. The LPPD is based on the European Union Data Protection Directive 95/46/EC and aims to ensure individuals’ data protection and rights. Similarly, on 14 April 2016, EU lawmakers prepared the draft of the General Data Protection Regulation (GDPR). On 25 May 2018, the European Union's General Assembly put the GDPR into effect to ensure that individuals get greater control of their personal data and organizations secure their personal data.
Both GDPR and LPPD apply to entities that collect and process personal data belonging to EU and Turkey residents, respectively, irrespective of the physical presence of the controller or processor. LPPD and GDPR apply to the processing of "Personal data," which means any kind of information relating to an identified or identifiable person. Following is a more in-depth comparison between the two regulations.
Articles 1(1), 2(1), 17
LPPD applies to natural persons whose personal data are processed and natural or legal persons who process such data fully or partially through automatic means or provided that the process is a part of any data registry system, through non-automatic means.
LPPD does not differentiate between private corporations and public authorities and applies to all institutions and organizations.
LPPD is silent on its extraterritorial scope in terms of data origin; however, it is generally accepted that it applies to data processing activities related to personal data originating in Turkey.
Articles 3, 4(1) Recitals 2, 14, 22-25
GDPR “applies to natural persons, whatever their nationality or place of residence, concerning the processing of their personal data.”
Regarding extraterritorial scope, GDPR applies to organizations that are not established in the EU, but instead monitor individuals’ behavior, as long as their behavior occurs in the EU.
GDPR also applies to organizations located outside the EU (those that do not have an establishment in the EU) if they offer goods or services to, or monitor the behavior of, data subjects located in the EU, irrespective of their nationality or the company’s location.
Both regulations give individuals rights relating to their personal data, which they can exercise. Under LPPD, the data controller must process data subject’ requests and take all necessary administrative and technical measures within 30 days. LPPD does not provide a period extension. There is no fee for the data subject’ request to data controllers. However, the data controller may impose a fee, as set by the Data Protection Regulation Authority, if the request necessitates a response. Under LPPD, the data subject also has the right to complain to the Turkish Personal Data Protection Authority (KVKK). The KVKK must inform the data subject of the progress and outcome of his or her complaint.
GDPR also ensures data subject’ rights where the data subjects can request the controller or processors to implement their rights. GDPR allows controllers and businesses to either charge a reasonable fee or refuse to respond to manifestly unfounded or excessive data subject’ requests. Furthermore, under GDPR, the controller must inform the data subject of the reasons for not taking any action on their request without delay and within one month of receipt, at the latest. The following section explains each right and how they differ across the two laws.
Articles 7, 10, 11, 13
Article 12 of the Regulation on Erasure, Destruction or
Anonymization of Personal Data
LPPD requires data controllers to delete the personal data upon demand by the data subject if the reasons for processing no longer exist. However, in any scenario, data subjects can have the right to request the deletion of their personal data.
The LPPD does not provide any exceptions to the right of deletion.
Articles: 12, 17 Recitals: 59, 65, 66
The right to erasure only applies in instances where consent is withdrawn. There is no other legal ground for processing or when personal data is no longer necessary for the purpose for which it was collected.
The data subject’ requests under the right to deletion must be responded to without delay and in any event within one month of the receipt.
The deadline can be extended to two additional months where there is great complexity or depending on the number of requests. In any of these cases, the data subject must be notified of any such extension within one month of receiving the request, along with the reasons for the delay and the possibility of complaining to the supervisory authority.
Articles 10. 11
Data subjects have the right to be informed about the processing of their personal data. They also have the right to know the purpose of data processing and whether their data is used for the intended purposes.
When collecting personal data, the controller or the person authorized by him is obliged to inform the data subjects about the following:
the identity of the controller and his representative, if any,
The controller is obliged to inform the data subject when the data processing adheres to the data subject’s explicit consent or processing under another condition of the LPPD. The controller should inform the data subject in every situation where his or her personal data is processed.
The LPPD provides a general requirement to provide information on the collection methods but does not explicitly refer to automated decision-making or profiling.
Articles: 5-14, Recitals: 58 - 63
This right requires the controller to provide the following information to the data subject when requested. This should be given in a concise, transparent, intelligible, and easily accessible form, using plain language:
The controller must provide information necessary to ensure fair and transparent processing whether or not the personal data is collected from the data subject. This information includes the duration of data storage, the controller’s legitimate interests, and the existence of the rights to access erasure, rectification, restriction of processing, data portability, and filing complaints to the supervisory authority.
Data subjects must be informed of the existence of automated decision-making, including profiling, at the time when personal data was obtained.
Articles 11, 23, 27, 30
Data subjects have the right to object if the processing results in a negative outcome for them due to the analysis of their data by automatic means.
There is no explicit right to withdraw the consent available under the LPPD; however, the interpretations of various provisions suggest that data subjects have the right to withdraw their consent to the processing of their personal data whenever they desire.
Under LPPD, data subjects have the right to be informed regarding their right to object to the processing.
Articles 7, 18, 21
GDPR provides data subjects with the right to object and withdraw consent to personal data processing. Data subjects have the right to object to the processing of their personal data. This can be done based on legitimate interest or public interest.
Once this right is exercised, the controller must stop processing the individual's data unless it demonstrates grounds that override the data subject's request.
Article 11
LPPD states that data subjects have the right to learn and know whether the personal data relating to themselves is being processed.
In general, data controllers must provide the following information while responding to data subject requests;
A data controller may refuse a data subject's request with justified grounds. However, the LPPD is silent on the definition of justified grounds.
Articles 15 Recitals 59 - 64
GDPR states that, when responding to an access request, a data controller must indicate the following:
The information must be provided without undue delay and in any event within one month of the request’s receipt.
No Article
LPPD does not provide the right to data portability.
Articles 12, 20, 28 Recitals 68, 73
GDPR defines the right to data portability as the right to send data in a “structured, commonly used, and machine-readable format.” This right may be exercised only when it is technically feasible to do so.
Article 11
Under LPPD,data subjects have the right to apply to the data controller to request the rectification of incomplete or inaccurate data.
Article 16
This is the data subject’s right to obtain from the controller the rectification of inaccurate personal data and to have incomplete personal data completed.
This right has close links to the accuracy principle of GDPR (Article 5(1)(d)).
No Article
Not Applicable
Article 18
This right applies when the data subject contests data accuracy, the processing is unlawful, and the data subject opposes erasure and requests restriction. The controller must inform data subjects before any such restriction is lifted.
No Article
Not Applicable
Articles 22
GDPR provides data subjects the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them.
GDPR prescribes that data controllers and data processors, including their representatives, must appoint a DPO, whereas there is no such requirement under LPPD.
Articles 16
Under LPPD, natural persons or legal persons who process personal data must enroll in the Data Registry of Controllers before taking any steps to process personal data. Application for registering must be made with a notification containing the following essentials:
VERBIS registration should be made via the VERBIS online portal.
Articles 30 Recitals 82
Data controllers and data processors must maintain a record of processing activities.
GDPR prescribes a list of information that a data controller must record:
The processing information recorded by a data controller or processor shall be in writing or electronic form.
Articles 5(2), 6(3), 8, 9
According to Article 8 of LPPD, personal data can only be transferred with the data subject's explicit consent to transfer personal data inside Turkey. To transfer the personal data without the data subject's explicit consent, LPPD stipulates the same conditions as mentioned in Article 5(2) and 6(3) of the LPPD for processing personal data.
Under Article 9 of LPPD, cross-border transfer of personal data may take place once one of the following conditions is met:
Articles 44-50 Recitals 101, 112
GDPR states that personal data shall be transferred to a third country or international organization with an adequate protection level as determined by the EU Commission.
Suppose there is no decision on an adequate protection level. In that case, a transfer is only permitted when the data controller or data processor provides appropriate safeguards that ensure data subject' rights.
Appropriate safeguards include:
Regarding enforcement,LPPD imposes both criminal and non-criminal penalties, whereas the GDPR only provides administrative penalties for non-compliance.
Articles 17, 18
LPPD states that Article 135-140 of Turkish Penal Code No. 5237 of 26/9/2004 shall apply in terms of crimes concerning the personal data which can be subject to imprisonment.
Under Article 18 of LPPD, the Personal Data Protection Board can impose administrative penalties up to TRY 1.000.000 for each incidence of non-compliance. Following non-compliance with the data protection laws can result in:
Articles 83, 84 Recitals 158, 149
GDPR has an upper cap on their monetary penalties, either: 2% of global annual turnover or €10 million, whichever is higher, or 4% of global annual turnover or €20 million, whichever is higher. This depends on the level of violation, which is decided by the member states and public authorities.
Both GDPR and LPPD obligate controllers and processors to adopt security measures to protect the personal data they are processing.
Articles 12
The Board Decision No. 2019/10 ('the Decision') Guidance on Data Protection (technical and organizational measures)
The controller must take all necessary organizational and technical measures to fulfill the obligation stated under LPPD. Turkey has issued a Personal Data Security Guide to clarify the technical and organizational measures for the secure processing of personal data.
Under Article 12 of LPPD, the Data controller’s responsibility is to ensure personal data retention, prevent unlawful processing of personal data, and prevent illegal access to personal data.
In cases where other persons unlawfully collect the processed personal data, the data controller shall notify the same to the data subject and the Board of the KVKK within the shortest time.
As per the Decision, the data controller must notify the Board of the KVKK without delay and not later than 72 hours after becoming aware of any data breach.
Under the LPPD, there are no exemptions to the obligation to notify the unlawful collection of personal data to the Board of the KVKK and the data subject.
Articles 5, 24, 32-34 Recitals 74-77, 83-88
The GDPR requires organizations to take appropriate technical and organizational measures to ensure personal information processing security. These measures may include the following:
Under GDPR, organizations must notify supervisory authorities of any personal data breach that is likely to result in a risk to natural persons’ rights and freedoms without undue delay and not later than 72 hours after becoming aware of the breach. The information may also be provided in phases, and a justification must accompany any delay. The communication of the breach to data subjects, however, must take place without undue delay.
Global privacy regulations are encouraging organizations to automate their data privacy operations to comply seamlessly. Robotic automation is no longer a want but rather a need in this current digital landscape. Several organizations offer software that helps companies comply with global privacy regulations, but these solutions have been restricted to mainly process-driven tasks or rudimentary data-driven functions.
SECURITI’s AI-powered bot,Auti is the only solution that combines reliability, intelligence, and simplicity of use, with ended-to-end automation. Auti is the only solution that can help ensure complete compliance with modern privacy laws at scale.
See how easy it is to manage privacy compliance with robotic automation.
[email protected]
PO Box 13039,
Coyote CA 95013
Find data assets, and discover personal and sensitive data in structured and unstructured data systems, across on-premises and multi-cloud.
Classify & label data to ensure appropriate security controls are enabled on most sensitive data in your organization
Collect, organize, enrich and build a data catalog to address privacy, security and governance solutions
Connect to structured and unstructured data sources and automatically discover and build a relationship map between personal data and its owner.
Assess risk scores for every data asset, asset location, or personal data category
Auto discover personal data in Snowflake and enforce access governance
Auto discover personal data in Snowflake and enforce access governance
Discover, classify, manage and protect sensitive data in Box. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Slack. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more
Discover, classify, manage and protect sensitive data in Workday. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Github. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Jira. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Dropbox. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in SAP Successfactors. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Servicenow. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Zendesk. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Apache Hive. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Apache Spark SQL. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Cassandra. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Couchbase. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Maintain your Data Catalog with continuous automated updates
Automate data subject rights request fulfillment and maintain proof of compliance
Connect to structured and unstructured data sources and automatically discover and build a relationship map between personal data and its owner.
Audit once and comply with many regulations. Collaborate and track all internal assessments in one place.
Automation of privacy assessment collection from third parties, collaboration among stakeholders, follow-ups and compliance analytics.
Automate global cookie consent compliance.
Simplify and automate universal consent management.
Automate the incident response process by gathering incident details, identifying the scope and optimizing notifications to comply with global privacy regulations.
Keeping privacy notices up-to-date made easy
Operationalize GDPR compliance with the most comprehensive PrivacyOps platform
Operationalize CCPA compliance with the most comprehensive PrivacyOps platform
Revolutionize LGPD compliance through PrivacyOps
Enable privacy by design through the AI driven PrivacyOps platform
Discover data assets, detect & catalog sensitive data in it
Classify and label data to ensure appropriate security controls
Monitor data security posture and identify external and internals risks to data security
Policy based alerts and remediations to protect data from external and internal threats
Investigate data security issues and take remediation actions
Snowflake is a cloud based data warehouse that allows organizations to run large scale data analytics projects to uncover business insights, run or train machine learning models, and modernize their data infrastructure.
The Amazon S3 (Simple Storage Service) is a web-service which allows for scalable storage solutions for data archival, backup, and recovery purposes.
Microsoft O365 is the ubiquitous productivity suite for every business worker. Users rely on Office products such as OneDrive and SharePoint to collaborate with their co-workers.
Organizations want to migrate their on-premises data to cloud data stores to take advantage of scale and flexibility while reducing operational cost of managing on-premises infrastructure. However, due to privacy regulations such as GDPR, CCPA administrators have to ensure that data is migrated in compliance with these laws.
Protecting sensitive content is a priority for all organizations, however, due to volume of sensitive content and
While data aids in business decision making, global privacy regulations such as GDPR, CPRA require organization to identify personal & sensitive data & use only for its intended purpose and implement adequate protection.
The California Consumer Privacy Act (CCPA) was signed into law on June 28, 2018 and is scheduled to come into effect on January 01, 2020. Often compared to GDPR, CCPA protects consumers from mismanagement of their personal data and gives the consumer control over what data is collected, processed, shared or sold.
The EU General Data Protection Regulation (GDPR) came into effect on May 25, 2018 and changed the global privacy landscape. It has broadened the definition of processing activities and personal data, impacting companies worldwide, and has tightened the rules to obtain consent before processing information.
The Lei Geral de Proteção de Dados (LGPD) is modeled with similarities to the General European Data Protection Regulation (GDPR) and contains sixty-five articles. It was approved on August 14, 2018 and its validity has undergone several changes, the last relevant fact being MPV 959. LGPD is in effect since September 18, 2020. The sanctions by the ANPD (Brazilian Data Protection Authority) were postponed to August 2021. The LGPD allows people have more rights over their data and expects organizations to comply with their regulations or face heavy penalties or fines.
The government of New Zealand has recently replaced its long-existing Privacy Act of 1993 with a modernized version, the Privacy Act 2020. The New Zealand Privacy Act 2020 (NZPA) will take effect from December 1, 2020.
The Personal Data Protection Act, B.E. 2562 (2019) ('PDPA') is Thailand's first consolidated data protection law, which was published in the Thai Government Gazette on 27 May 2019. This law was said to go into effect on 27 May 2020. However, in May 2020, the Thai Cabinet through a Royal Decree has deferred the enforcement of certain data protection provisions of the PDPA until 31 May 2021.
In order to protect the data of individuals in South Africa, Parliament assented to the Protection of Personal Information Act (POPIA) on 19th November 2013. The commencement date of section 1, Part A of Chapter 5, section 112 and section 113 was 11 April 2014. The commencement date of the remaining sections (excluding section 110 and 114(4)) was 1st July 2020. As per the Regulator’s Operational Readiness Plan the Regulator will be able to take enforcement actions for the violation of POPIA by July 1st 2021.
The DIFC Data Protection Law, 2020 lays down regulations regarding the collection, disclosure and processing of personal data in the DIFC, a special economic zone in Dubai. It also gives rights to individuals whom the personal data relates to and provides power to the Commissioner of Data Protection to enforce the law, enact regulations and approve industry-wide Codes of Conduct.
The Australia Privacy Act 1988 (Privacy Act) was enacted to protect the privacy of data subjects and regulate how Australian agencies and organizations with an annual turnover of more than $3 million handle their customers’ personal information.
Singapore’s Personal Data Protection Act (PDPA) comprises various provisions governing the collection, disclosure, use, and care of personal data. It recognizes the rights of individuals to have more control over their personal data and the needs of organizations to collect, use, or disclose personal data for legitimate and reasonable purposes.
On April 13, 2000, the Personal Information Protection and Electronic Documents Act (PIPEDA) received Royal Assent. It came into force in stages, beginning on January 1, 2001. PIPEDA came fully into effect on January 1, 2004. The legislation applies to organizations that collect, use or disclose personal information in the course of commercial activities.
After the invalidation of Privacy Shield, many companies are relying on the SCCs in order to continue transferring data of EU citizens to companies based in countries who are not deemed adequate for data transfer.
After the CJEU judgement, it is clear that these companies have to conduct Risk Assessments with the data recipients in these countries in order to ensure they have enough controls to mitigate any potential data or regulatory risk.
On 2nd March, 2019, the Department of Health—Abu Dhabi (DoH), launched the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard. This is the first standard that aims to provide healthcare professionals and entities a comprehensive guide to the regulation of healthcare data in Abu Dhabi. This law ensures the highest levels of privacy and security of patients’ data, in line with international standards, is maintained.
On January 31, 2020, the government of Saudi Arabia issued the Executive Regulations to the Saudi E-Commerce Law 2019 (“ECL”) that was in effect since October 2019. The Executive Regulations together with the ECL (“Law”) aim to protect consumers’ personal data by requiring organizations to take appropriate technical and administrative measures.
Turkey was one of the first countries to start the trend of legislating data protection. Turkey published “Law on the Protection of Personal Data No. 6698 (LPPD) covering personal data protection on April 07, 2016.” The LPPD is based on the European Union Data Protection Directive 95/46/EC and has several similarities with the GDPR. It aims to give data subjects’ control over their personal data and outlines obligations that organizations and individuals dealing with personal data must comply with. The LPPD has also provided comprehensive guidelines for the transfer of personal data to the third parties.
In December 2019, India, following several other countries' footsteps on the privacy laws' developments, introduced the Personal Data Protection Bill (PDPB) to regulate the processing, collection, and storage of personal data.
On 13 October 2020, the National People's Congress of the Republic of China submitted the long awaited draft of the Personal Information Protection Law (Draft PIPL) to the Standing Committee meeting for preliminary review. This draft was officially released for the public consultation on 21 October, 2020. The consultation period will last until 19 November 2020.
The Irish Data Protection Act, 2018 (Irish DPA) implements the General Data Protection Regulation (GDPR) and transposes the European Union Law Enforcement Directive in Ireland. Since it incorporates most of the provisions from the GDPR and the Law Enforcement Directive with limited additions and deletions as per the national law, it is considered to be the principal data protection legislation in Ireland.
The Personal Data (Privacy) Ordinance (Cap. 486) as amended in 2012 (the “PDPO) is the primary legislation in Hong Kong which was enacted to protect the privacy of individuals’ personal data, and regulate the collection, holding, processing, disclosure, or use of personal data by the organizations.. The Data Protection Principles ( the “DPPs or DPP ''), which are contained in Schedule 1 to the PDPO, outline how entities should collect, handle, disclose, and use personal data.
In 2012, the Philippines passed the comprehensive privacy law, Data Privacy Act 2012 Republic Act. No, 10173 (the "DPA"). The DPA recognizes the rights of individuals to have more control over their personal data while ensuring a free flow of information to promote innovation and growth.
The United Arab Emirates (UAE) has a Federal Telecommunication Law ( Federal Law) which requires that a company must hold a license in order to provide public communications services and operate public telecommunication networks. Under this Federal Law, a Telecommunication Regulatory Authority (TRA) was established which regulates the telecommunication sector in the UAE.