JUS. Legal Tech Hub

Terminology

A comprehensive glossary of privacy and data protection terms used across global regulations.

Category:
More...

Showing 52 of 52 terms

Personal Data

Core Concepts

Any information relating to an identified or identifiable natural person. This includes name, identification number, email address, IP address, location data, and similar information.

Example: Name, surname, national ID number, email address, IP address

Also known as: Şahsi Veri, Bireysel Veri

KVKKGDPR

Special Categories of Personal Data

Core Concepts

Data revealing racial or ethnic origin, political opinions, religious beliefs, health data, sexual orientation, genetic data, biometric data, and criminal conviction data.

Also known as: Hassas Veri, Sensitive Data

KVKKGDPR

Special Category Data

data_protection

Data revealing racial or ethnic origin, political opinions, religious beliefs, health data, and data concerning sex life.

Example: Health report, biometric data, criminal conviction records

Also known as: hassas veri, sensitive data

kvkk-hubgdpr-hub

Data Controller

Actors

The natural or legal person which determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.

Example: Company, institution, association, foundation

Also known as: Kontrolör

KVKKGDPR

Data Processor

Actors

A natural or legal person who processes personal data on behalf of the data controller based on the authority given by the controller.

Example: Cloud service provider, payroll company, marketing agency

Also known as: İşleyici

KVKKGDPR

Data Subject

Actors

An identified or identifiable natural person whose personal data is being processed. Only natural persons can be data subjects under data protection law.

Also known as: Veri Sahibi

KVKKGDPR

Explicit Consent

Legal Basis

A freely given, specific, informed and unambiguous indication of the data subject's wishes. Consent cannot be obtained through silence or pre-ticked boxes.

Example: Ticking a consent box, written declaration, electronic signature

Also known as: Onay, Muvafakat

KVKKGDPR

Processing of Personal Data

Core Concepts

Any operation performed on personal data, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure or destruction.

Also known as: Veri İşleme

KVKKGDPR

Data Controllers Registry

Regulatory

Data Controllers Registry Information System. The official registry in Turkey where data controllers are required to register with the Personal Data Protection Authority.

Example: Companies registering with VERBİS

Also known as: Veri Sorumluları Sicili

KVKK

Legitimate Interest

Legal Basis

Processing necessary for the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights of the data subject.

Also known as: Yasal Çıkar

KVKKGDPR

Performance of Contract

Legal Basis

Processing necessary for the performance of a contract to which the data subject is party or to take steps at the request of the data subject prior to entering into a contract.

Also known as: Sözleşme Gereği

KVKKGDPR

Legal Obligation

Legal Basis

Processing necessary for compliance with a legal obligation to which the controller is subject.

Also known as: Hukuki Yükümlülük

KVKKGDPR

Public Interest

Legal Basis

Processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Also known as: Kamusal Görev

KVKKGDPR

Right to Information

Data Subject Rights

The right of the data subject to obtain information about whether their personal data is being processed and to request information about such processing.

Also known as: Erişim Hakkı

KVKKGDPR

Right to Rectification

Data Subject Rights

The right of the data subject to obtain the rectification of inaccurate personal data and to have incomplete data completed.

Also known as: Güncelleme Hakkı

KVKKGDPR

Right to Erasure

Data Subject Rights

The right of the data subject to obtain the erasure of personal data. Also known as the 'Right to be Forgotten' under GDPR.

Also known as: Unutulma Hakkı, Right to be Forgotten

KVKKGDPR

Right to Object

Data Subject Rights

The right of the data subject to object to the processing of their personal data, particularly for direct marketing purposes.

Also known as: Karşı Çıkma Hakkı

KVKKGDPR

Right to Data Portability

Data Subject Rights

The right to receive personal data in a structured, commonly used and machine-readable format and to transmit that data to another controller.

Also known as: Taşınabilirlik

GDPR

Automated Decision-Making

Data Subject Rights

The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects the data subject.

Also known as: Profilleme

KVKKGDPR

Transparency Obligation

Obligations

The obligation of the data controller to inform data subjects about: controller identity, processing purposes, recipients, collection method, legal basis, and their rights.

Also known as: Bilgilendirme Yükümlülüğü

KVKKGDPR

Data Security

Obligations

Implementation of appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including protection against unauthorized or unlawful processing and accidental loss, destruction or damage.

Also known as: Bilgi Güvenliği

KVKKGDPR

Data Breach Notification

Obligations

The obligation to notify the supervisory authority within 72 hours of becoming aware of a personal data breach, and to communicate to data subjects if the breach is likely to result in a high risk to their rights and freedoms.

Also known as: İhlal Bildirimi

KVKKGDPR

Records of Processing Activities

Obligations

The obligation for controllers and processors to maintain records of processing activities under their responsibility.

Also known as: İşleme Faaliyetleri Kaydı

KVKKGDPR

Anonymization

Technical Measures

The process of removing or modifying personal data so that the data subject is no longer identifiable, even when combined with other data.

Also known as: Kimliksizleştirme

KVKKGDPR

Pseudonymization

Technical Measures

Processing personal data in such a manner that it can no longer be attributed to a specific data subject without the use of additional information kept separately.

Also known as: Pseudonymization, Rumuz Kullanma

KVKKGDPR

Encryption

Technical Measures

The process of encoding data using cryptographic algorithms so that only authorized parties can access it.

Also known as: Kriptolama

KVKKGDPR

Privacy by Design

Technical Measures

An approach to systems engineering which takes privacy into account throughout the whole engineering process from the outset.

Also known as: Mahremiyet Odaklı Tasarım

GDPR

Privacy by Default

Technical Measures

The principle that products and services should be configured with the highest privacy settings by default.

Also known as: Default Privacy

GDPR

Adequacy Decision

International Transfer

A decision by the competent authority that a third country ensures an adequate level of protection for personal data transfers.

Also known as: Yeterli Koruma Kararı

KVKKGDPR

Standard Contractual Clauses

International Transfer

Pre-approved contractual clauses for transferring personal data to countries without an adequacy decision.

Also known as: Model Sözleşme

KVKKGDPR

Binding Corporate Rules

International Transfer

Internal rules adopted by multinational companies for international transfers of personal data within the corporate group, approved by the supervisory authority.

Also known as: BCR

KVKKGDPR

Cross-Border Transfer

International Transfer

The transfer of personal data to recipients outside the country. Requires explicit consent or adequate safeguards under data protection law.

Also known as: Uluslararası Aktarım

KVKKGDPR

Personal Data Protection Authority

Regulatory

The independent administrative authority responsible for regulating and supervising personal data protection in Turkey.

Also known as: KVKK Kurumu, Kurum

KVKK

Personal Data Protection Board

Regulatory

The decision-making body of the Personal Data Protection Authority, authorized to make decisions, regulations and impose administrative sanctions.

Also known as: Kurul

KVKK

Supervisory Authority

Regulatory

An independent public authority responsible for monitoring and enforcing the application of GDPR in the member state.

Also known as: Veri Koruma Otoritesi, DPA

GDPR

European Data Protection Board

Regulatory

An independent European body composed of representatives of national data protection authorities, ensuring consistent application of GDPR.

Also known as: EDPB

GDPR

Administrative Fine

Sanctions

Financial penalty imposed by the supervisory authority for violations of data protection law. Under GDPR, fines can reach up to €20 million or 4% of global annual turnover.

Also known as: Para Cezası

KVKKGDPR

Data Protection Officer

Actors

A designated expert who advises on data protection matters and monitors compliance with data protection regulations within an organization.

Also known as: DPO, Kişisel Verileri Koruma Sorumlusu

KVKKGDPR

Data Protection Impact Assessment

Risk Management

A systematic assessment conducted before high-risk processing activities to identify and mitigate risks to individuals' rights and freedoms.

Also known as: DPIA, Etki Değerlendirmesi

KVKKGDPR

Data Minimization

Principles

The principle that personal data collected should be adequate, relevant and limited to what is necessary for the purposes for which they are processed.

Also known as: En Az Veri İlkesi

KVKKGDPR

Purpose Limitation

Principles

The principle that personal data must be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.

Also known as: Amaçla Sınırlılık

KVKKGDPR

Data Accuracy

Principles

The principle that personal data must be accurate and, where necessary, kept up to date. Inaccurate data must be erased or rectified without delay.

Also known as: Doğruluk İlkesi

KVKKGDPR

Storage Limitation

Principles

The principle that personal data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data are processed.

Also known as: Saklama Sınırlaması

KVKKGDPR

Accountability

Principles

The principle that the controller is responsible for, and must be able to demonstrate compliance with, data protection principles.

Also known as: Sorumluluk İlkesi

KVKKGDPR

Children's Personal Data

Special Cases

Processing of children's personal data requires special protection. GDPR sets a consent age of 16 for information society services, though member states may lower this to 13.

Also known as: Çocuk Verileri

KVKKGDPR

Cookie

Technical Concepts

Small text files placed on users' devices by websites. May contain personal data and require a cookie policy and explicit consent.

Also known as: Cookie, Web Çerezi

KVKKGDPRePrivacy

Personal Data Breach

Security

A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Also known as: Veri İhlali, Data Breach

KVKKGDPR

Third Party

Actors

A natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who are authorized to process personal data under the direct authority of the controller or processor.

Also known as: Dış Taraf

KVKKGDPR

Data Processing Agreement

Contracts

A contract between a data controller and data processor that specifies the terms and conditions of data processing and security measures.

Also known as: DPA, Veri İşleyici Sözleşmesi

KVKKGDPR

Privacy Notice

Documents

A document that explains to data subjects how their personal data is processed. Used to fulfill the transparency obligation.

Also known as: Privacy Policy, Gizlilik Politikası

KVKKGDPR

Withdrawal of Consent

Data Subject Rights

The right of the data subject to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.

Also known as: Onay İptali

KVKKGDPR

Restriction of Processing

Data Subject Rights

The marking of stored personal data with the aim of limiting their processing in the future, at the request of the data subject.

Also known as: İşleme Kısıtlaması

KVKKGDPR
52
Total Terms
17
Categories
5
Regulations
Monthly
Updates
Request Demo