As Özkök Law Firm, the security of our clients’ personal data is of great importance to us. The Personal Data Protection Law (KVKK) was enacted to prevent the unlawful processing of personal data and to ensure the security of this data. In this blog post, you can find the basic security measures and practical tips that law firms should take to comply with KVKK.

Part 1: Identification of Personal Data and Limited Use

• What data do you process? Determine in detail what personal data you have about your clients. If you process special personal data (such as health status, belief) in addition to basic data such as name, surname, Turkish Republic ID number, contact information, you must also have legal grounds for processing this data.

• Data processing purposes: Use the collected personal data only for the specified purposes. These purposes must be clearly stated to the clients when collecting the data.

• Data minimization principle: Keep the data you process to the minimum level necessary to achieve your purpose. Do not store unnecessary data.
Section 2: Security Measures
• Physical security: Limit access to personal data in the office environment. Take physical security measures for computers, files and other data carriers (locked cabinets, security cameras).

• Technical security:
o Strong passwords: Ensure that all users use strong and unique passwords.
o Access control: Restrict access to personal data to authorized persons. Review access permissions regularly.
o Up-to-date security software: Use and regularly update security software such as antivirus and firewall on your computers and network.
o Backup: Back up your personal data regularly and ensure the security of backups.
o Data encryption: Protect sensitive personal data by encrypting it.

• Organizational security:
o Personnel training: Regularly train your personnel on KVKK. Increase their awareness of data security.
o Contracts: Sign contracts with data processors (such as cloud service providers) that include the necessary obligations regarding data security.
o Incident notification mechanism: Create an incident notification mechanism to be able to intervene quickly in the event of personal data breaches.
Section 3: Transparency and Information
• Information text: Inform your clients about their personal data. Prepare and have them sign an information text that includes the purpose of data collection, data processing methods, rights and contact information.
• Data recording system: Create a data recording system where you are obliged to keep the personal data you process. In this system, regularly update information such as which data you process, for what purpose you process it and the retention periods of the data.
Section 4: Rights of Individuals
Respect the rights of your clients granted by the KVKK (access, correction, deletion, etc.). Respond to requests in a timely and complete manner.