Legal limits on data collection in mobile apps

Technology 2 min 24 Oct 2016
Cover image for Legal limits on data collection in mobile apps
Turkey's Personal Data Protection Law demands purpose-limited, proportionate processing. Mobile apps that grab contacts, camera, or SMS without a real need risk fines up to 1 million TL.

Turkey’s Personal Data Protection Law (the Law) was published in the Official Gazette on 7 April 2016 and took full effect on 7 October 2016. Privacy of personal data has been a constitutional right since 2010, so the Law and its duties touch everyone and put real obligations on companies that process data. This piece looks at one core principle through the lens of mobile apps.

When processing personal data about real people, the Law requires processing to be connected to its purpose, limited, and proportionate. Personal data means any information that identifies or makes a person identifiable. Processing can be non-automatic as part of a filing system, or fully or partly automatic. It covers collecting, recording, storing, keeping, altering, reorganizing, disclosing, transferring, acquiring, making available, classifying, or blocking use.

Do collected data fit the purpose?

Proportionate processing needs care: who decides purposes and means, and who builds and runs the filing system, matters. If personal data is processed, it needs a legitimate, acceptable link to why it was collected.

Take a free recipe app that reaches a phone owner’s location, contacts, camera, or SMS and processes those data. Claiming a legitimate, proportionate link to “serving recipes” needs a strong explanation. By contrast, a location-based app that shows nearby restaurant menus or local recipes has a clearer, proportionate reason to use location.

Fines can reach 1 million TL

Quietly, the Law says: do not process data you do not need. That invites conservative readings. If the Data Protection Authority reviews a complaint and finds unlawful processing, administrative fines up to 1 million TL are not far-fetched. How these purpose-and-proportion rules play out in practice will become clearer over time.

The same test applies across insurance, health, e-commerce, banking, and every other sector where controllers process data. With the Authority standing up from October, companies will face hard questions and will need to rebuild personal data procedures. If they want to avoid serious fines, a legality review of processing flows should not wait.

Oğuzhan Koçaklı

I have worked professionally in marketing, gaming and blockchain since 2015. I have helped create and carry out marketing strategies for many major brands. These days I work on mobile games and blockchain integration for games. AI has been my hobby for many years.

All posts

Leave a Reply

Your email address will not be published. Required fields are marked *