GDPR

Madde 35

Veri koruma etki değerlendirmesi

Son Güncelleme: 30 Temmuz 2026
GDPR İlgili Dibaceler 9 dibace
Official Journal text EUR-Lex
Recital 75

The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from personal data processing which could lead to physical, material or non-material damage, in particular: where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage; where data subjects might be deprived of their rights and freedoms or prevented from exercising control over their personal data; where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, and the processing of genetic data, data concerning health or data concerning sex life or criminal convictions and offences or related security measures; where personal aspects are evaluated, in particular analysing or predicting aspects concerning performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, in order to create or use personal profiles; where personal data of vulnerable natural persons, in particular of children, are processed; or where processing involves a large amount of personal data and affects a large number of data subjects.

Recital 76

The likelihood and severity of the risk to the rights and freedoms of the data subject should be determined by reference to the nature, scope, context and purposes of the processing. Risk should be evaluated on the basis of an objective assessment, by which it is established whether data processing operations involve a risk or a high risk.

Recital 84

In order to enhance compliance with this Regulation where processing operations are likely to result in a high risk to the rights and freedoms of natural persons, the controller should be responsible for the carrying-out of a data protection impact assessment to evaluate, in particular, the origin, nature, particularity and severity of that risk. The outcome of the assessment should be taken into account when determining the appropriate measures to be taken in order to demonstrate that the processing of personal data complies with this Regulation. Where a data-protection impact assessment indicates that processing operations involve a high risk which the controller cannot mitigate by appropriate measures in terms of available technology and costs of implementation, a consultation of the supervisory authority should take place prior to the processing.

Recital 89

Directive 95/46/EC provided for a general obligation to notify the processing of personal data to the supervisory authorities. While that obligation produces administrative and financial burdens, it did not in all cases contribute to improving the protection of personal data. Such indiscriminate general notification obligations should therefore be abolished, and replaced by effective procedures and mechanisms which focus instead on those types of processing operations which are likely to result in a high risk to the rights and freedoms of natural persons by virtue of their nature, scope, context and purposes. Such types of processing operations may be those which in, particular, involve using new technologies, or are of a new kind and where no data protection impact assessment has been carried out before by the controller, or where they become necessary in the light of the time that has elapsed since the initial processing.

Recital 90

In such cases, a data protection impact assessment should be carried out by the controller prior to the processing in order to assess the particular likelihood and severity of the high risk, taking into account the nature, scope, context and purposes of the processing and the sources of the risk. That impact assessment should include, in particular, the measures, safeguards and mechanisms envisaged for mitigating that risk, ensuring the protection of personal data and demonstrating compliance with this Regulation.

Recital 91

This should in particular apply to large-scale processing operations which aim to process a considerable amount of personal data at regional, national or supranational level and which could affect a large number of data subjects and which are likely to result in a high risk, for example, on account of their sensitivity, where in accordance with the achieved state of technological knowledge a new technology is used on a large scale as well as to other processing operations which result in a high risk to the rights and freedoms of data subjects, in particular where those operations render it more difficult for data subjects to exercise their rights. A data protection impact assessment should also be made where personal data are processed for taking decisions regarding specific natural persons following any systematic and extensive evaluation of personal aspects relating to natural persons based on profiling those data or following the processing of special categories of personal data, biometric data, or data on criminal convictions and offences or related security measures. A data protection impact assessment is equally required for monitoring publicly accessible areas on a large scale, especially when using optic-electronic devices or for any other operations where the competent supervisory authority considers that the processing is likely to result in a high risk to the rights and freedoms of data subjects, in particular because they prevent data subjects from exercising a right or using a service or a contract, or because they are carried out systematically on a large scale. The processing of personal data should not be considered to be on a large scale if the processing concerns personal data from patients or clients by an individual physician, other health care professional or lawyer. In such cases, a data protection impact assessment should not be mandatory.

Recital 92

There are circumstances under which it may be reasonable and economical for the subject of a data protection impact assessment to be broader than a single project, for example where public authorities or bodies intend to establish a common application or processing platform or where several controllers plan to introduce a common application or processing environment across an industry sector or segment or for a widely used horizontal activity.

Recital 93

In the context of the adoption of the Member State law on which the performance of the tasks of the public authority or public body is based and which regulates the specific processing operation or set of operations in question, Member States may deem it necessary to carry out such assessment prior to the processing activities.

Recital 95

The processor should assist the controller, where necessary and upon request, in ensuring compliance with the obligations deriving from the carrying out of data protection impact assessments and from prior consultation of the supervisory authority.

01

Yüksek risk eşiği ve değerlendirmenin işlevi

Planlanan bir işleme türünün gerçek kişilerin hak ve özgürlükleri bakımından yüksek risk doğurması muhtemelse veri sorumlusu, işlemeye başlamadan önce veri koruma etki değerlendirmesi yapmalıdır.1 Riskin belirlenmesinde işlemenin niteliği, kapsamı, bağlamı ve amaçları birlikte ele alınır. Yeni teknolojinin kullanılması bu değerlendirmede önem taşıyabilir, ancak tek başına değerlendirme yükümlülüğü doğurmaz.2

Etki değerlendirmesi, planlanan işlemenin hukuka uygunluğunu ve kişiler üzerindeki etkilerini işlemeye başlanmadan önce sınamaya yarar. Amaç, yüksek riskin kaynağını ve ağırlığını ortaya koymak, riski azaltacak tedbirleri belirlemek ve alınan kararların hesap verebilirlik çerçevesinde gösterilebilmesini sağlamaktır.3 Bu nedenle değerlendirme, karar verildikten sonra hazırlanacak biçimsel bir rapora indirgenemez.4

02

Değerlendirme gerektiren işleme türleri

GDPR m.35/3, değerlendirme yapılması gereken üç işleme grubunu özellikle gösterir. Bunlar, kişiler hakkında hukuki veya benzer ölçüde önemli sonuç doğuran kararlara temel oluşturan sistematik ve kapsamlı kişisel yön değerlendirmeleri, özel nitelikli veriler veya mahkumiyet ve suç verilerinin geniş ölçekte işlenmesi ile kamuya açık alanların geniş ölçekte sistematik olarak izlenmesidir.1

Bu sayım sınırlı değildir. Başka bir işleme de m.35/1'deki yüksek risk eşiğini karşılıyorsa değerlendirmeye tabi olacaktır.2 Denetim makamının m.35/4 uyarınca yayımladığı liste, değerlendirme yapılacak işleme türlerini somutlaştırır. Maddenin beşinci fıkrası ise denetim makamına değerlendirme gerektirmeyen işleme türlerini gösteren bir liste yayımlama imkanı verir.3

Bir işleme listelerde açıkça yer almıyorsa yalnız bu nedenle yüksek risk incelemesi sona ermez. Veri sorumlusu, planlanan işlemenin özelliklerini m.35/1'deki ölçütlere göre değerlendirmeli ve vardığı sonucu gösterebilmelidir.4

03

Değerlendirmenin asgari içeriği

Etki değerlendirmesi, planlanan işleme faaliyetlerini ve amaçlarını sistematik biçimde açıklamalıdır. Veri sorumlusu meşru menfaate dayanıyorsa izlenen menfaat de gösterilmelidir.1 Ardından işleme faaliyetinin amaç bakımından gerekli ve orantılı olup olmadığı incelenmelidir.2

İncelenecek riskler, yalnızca güvenlik açığı ihtimaliyle sınırlı değildir. Kişilerin hak ve özgürlükleri üzerindeki muhtemel sonuçların niteliği, gerçekleşme ihtimali ve ağırlığı değerlendirilmelidir.3 Belirlenen riskleri karşılayacak güvenceler, güvenlik tedbirleri ve hukuka uygunluğu gösterecek mekanizmalar da açıklanmalıdır.4

Bu unsurlar birbiriyle bağlantılıdır. İşleme faaliyeti ve amacı yeterince açıklanmadan gereklilik ile orantılılık denetlenemez. Riskler belirlenmeden de hangi tedbirin yeterli olduğu ve işlemden sonra hangi riskin kaldığı gösterilemez.5

04

Sorumluluk ve katılım

Etki değerlendirmesini yapma sorumluluğu veri sorumlusuna aittir. Veri sorumlusu çalışmayı uzmanlara veya başka kişilere yaptırabilir, ancak değerlendirme yükümlülüğünü ve sonuçlarına ilişkin sorumluluğu devredemez.1

Veri koruma görevlisi belirlenmişse değerlendirme sırasında görüşü alınmalıdır.2 Veri işleyen de gerekli olduğu ölçüde ve veri sorumlusunun talebi üzerine değerlendirme yükümlülüğünün yerine getirilmesine yardımcı olmalıdır.3 Bu aktörlerin katkısı, işleme amaçları ve araçları hakkında karar veren veri sorumlusunun sorumluluğunu değiştirmez.

Uygun olduğu hallerde ilgili kişilerin veya temsilcilerinin planlanan işlemeye ilişkin görüşleri de alınmalıdır. Ancak görüş alma süreci ticari veya kamusal menfaatleri ya da işleme güvenliğini zedelememelidir.4 Görüş alınması, ilgili kişinin işlemenin hukuka uygunluğu hakkında karar vermesi veya veri sorumlusunun risk değerlendirmesini devralması anlamına gelmez.5

05

Zaman, kapsam ve yenileme

Etki değerlendirmesi işlemeye başlanmadan önce tamamlanmalıdır. Değerlendirme, işleme faaliyetinin tasarımını ve uygulanacak tedbirleri etkileyebilecek kadar erken bir aşamada yapılmalıdır.1 Birbiriyle benzer ve aynı nitelikte yüksek risk doğuran işleme faaliyetleri tek bir değerlendirme içinde ele alınabilir.2

Değerlendirme bir kez hazırlanıp değişmeden saklanan bir belge değildir. İşleme faaliyetinin doğurduğu risk değiştiğinde veri sorumlusu, işlemenin etki değerlendirmesine uygun biçimde yürütülüp yürütülmediğini yeniden incelemelidir.3 Yeni bir teknolojiye geçilmesi, veri kapsamının genişlemesi, işleme amacının değişmesi veya güvenlik tedbirlerinin etkisini değiştiren gelişmeler bu incelemeyi gerekli kılabilir.4

Yenileme yükümlülüğü, her küçük değişiklikte bütün değerlendirmenin baştan yapılmasını gerektirmez. Değişikliğin riskin niteliği, ihtimali veya ağırlığı üzerindeki etkisi belirlenmeli ve değerlendirme bu etkiye göre güncellenmelidir.5

06

Kanuni dayanağa bağlı işleme ve ön danışma

Belirli bir işleme faaliyeti Birlik veya üye devlet hukukuna dayanabilir. Bu hukuki dayanak hazırlanırken genel bir etki değerlendirmesi yapılmışsa GDPR m.35/10'daki koşullar altında maddenin birinci ila yedinci fıkraları ayrıca uygulanmayabilir.1 Bu sonuç, kanuni dayanağa bağlı her işleme faaliyetinin etki değerlendirmesinden muaf olduğu anlamına gelmez. Hukuki düzenlemenin belirli işlemeyi kapsaması ve değerlendirme şartlarının somut olayda karşılanması gerekir.2

Etki değerlendirmesi sonucunda yüksek riskin alınacak tedbirlerle giderilemediği anlaşılırsa işlemeye başlanmadan önce GDPR m.36 uyarınca denetim makamına danışılmalıdır.3 Böylece etki değerlendirmesi ile ön danışma birbirini izleyen iki aşama oluşturur. Yüksek riskin uygun tedbirlerle kabul edilebilir düzeye indirilmesi halinde sırf başlangıçta yüksek risk görülmüş olması ön danışmayı zorunlu kılmaz.4

07

KVKK ile karşılaştırma

KVKK m.12, veri sorumlusuna uygun güvenlik düzeyini sağlamak için gerekli teknik ve idari tedbirleri alma ve Kanun hükümlerinin uygulanmasını sağlamak amacıyla gerekli denetimleri yapma veya yaptırma yükümlülüğü getirir.1 Bu hükümler risklerin önceden değerlendirilmesini gerektirebilir. Ancak KVKK, GDPR m.35'te olduğu gibi adı, uygulanma eşiği, asgari içeriği ve katılım usulü belirlenmiş genel bir veri koruma etki değerlendirmesi öngörmez.2

KVKK m.16'daki Sicile kayıt ve bildirim yükümlülüğü de etki değerlendirmesiyle aynı işlevi görmez. Sicil bildirimi işleme amaçları, veri kategorileri, alıcı grupları, yurt dışı aktarım ve güvenlik tedbirleri gibi bilgileri içerir. GDPR m.35 ise planlanan belirli bir işlemenin gerekliliğini, orantılılığını ve kişiler üzerindeki yüksek riskini değerlendirmeyi amaçlar.3

Bu nedenle GDPR m.35'teki yöntem, Türk hukukunda veri güvenliği ve hesap verebilirlik çalışmalarına karşılaştırmalı bir çerçeve sunabilir. Bununla birlikte GDPR'deki eşik, liste ve ön danışma sonuçları KVKK'ye doğrudan taşınamaz.4

§ Tüzük Metni
Official Journal text EUR-Lex

1. Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.

2. The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.

3. A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:

(a) a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;

(b) processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or

(c) a systematic monitoring of a publicly accessible area on a large scale.

4. The supervisory authority shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. The supervisory authority shall communicate those lists to the Board referred to in Article 68.

5. The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board.

6. Prior to the adoption of the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union.

7. The assessment shall contain at least:

(a) a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;

(b) an assessment of the necessity and proportionality of the processing operations in relation to the purposes;

(c) an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and

(d) the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.

8. Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.

9. Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.

10. Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities.

11. Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.

§ İlgili Dibaceler GDPR · 9
Official Journal text EUR-Lex
Recital 75

The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from personal data processing which could lead to physical, material or non-material damage, in particular: where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage; where data subjects might be deprived of their rights and freedoms or prevented from exercising control over their personal data; where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, and the processing of genetic data, data concerning health or data concerning sex life or criminal convictions and offences or related security measures; where personal aspects are evaluated, in particular analysing or predicting aspects concerning performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, in order to create or use personal profiles; where personal data of vulnerable natural persons, in particular of children, are processed; or where processing involves a large amount of personal data and affects a large number of data subjects.

Recital 76

The likelihood and severity of the risk to the rights and freedoms of the data subject should be determined by reference to the nature, scope, context and purposes of the processing. Risk should be evaluated on the basis of an objective assessment, by which it is established whether data processing operations involve a risk or a high risk.

Recital 84

In order to enhance compliance with this Regulation where processing operations are likely to result in a high risk to the rights and freedoms of natural persons, the controller should be responsible for the carrying-out of a data protection impact assessment to evaluate, in particular, the origin, nature, particularity and severity of that risk. The outcome of the assessment should be taken into account when determining the appropriate measures to be taken in order to demonstrate that the processing of personal data complies with this Regulation. Where a data-protection impact assessment indicates that processing operations involve a high risk which the controller cannot mitigate by appropriate measures in terms of available technology and costs of implementation, a consultation of the supervisory authority should take place prior to the processing.

Recital 89

Directive 95/46/EC provided for a general obligation to notify the processing of personal data to the supervisory authorities. While that obligation produces administrative and financial burdens, it did not in all cases contribute to improving the protection of personal data. Such indiscriminate general notification obligations should therefore be abolished, and replaced by effective procedures and mechanisms which focus instead on those types of processing operations which are likely to result in a high risk to the rights and freedoms of natural persons by virtue of their nature, scope, context and purposes. Such types of processing operations may be those which in, particular, involve using new technologies, or are of a new kind and where no data protection impact assessment has been carried out before by the controller, or where they become necessary in the light of the time that has elapsed since the initial processing.

Recital 90

In such cases, a data protection impact assessment should be carried out by the controller prior to the processing in order to assess the particular likelihood and severity of the high risk, taking into account the nature, scope, context and purposes of the processing and the sources of the risk. That impact assessment should include, in particular, the measures, safeguards and mechanisms envisaged for mitigating that risk, ensuring the protection of personal data and demonstrating compliance with this Regulation.

Recital 91

This should in particular apply to large-scale processing operations which aim to process a considerable amount of personal data at regional, national or supranational level and which could affect a large number of data subjects and which are likely to result in a high risk, for example, on account of their sensitivity, where in accordance with the achieved state of technological knowledge a new technology is used on a large scale as well as to other processing operations which result in a high risk to the rights and freedoms of data subjects, in particular where those operations render it more difficult for data subjects to exercise their rights. A data protection impact assessment should also be made where personal data are processed for taking decisions regarding specific natural persons following any systematic and extensive evaluation of personal aspects relating to natural persons based on profiling those data or following the processing of special categories of personal data, biometric data, or data on criminal convictions and offences or related security measures. A data protection impact assessment is equally required for monitoring publicly accessible areas on a large scale, especially when using optic-electronic devices or for any other operations where the competent supervisory authority considers that the processing is likely to result in a high risk to the rights and freedoms of data subjects, in particular because they prevent data subjects from exercising a right or using a service or a contract, or because they are carried out systematically on a large scale. The processing of personal data should not be considered to be on a large scale if the processing concerns personal data from patients or clients by an individual physician, other health care professional or lawyer. In such cases, a data protection impact assessment should not be mandatory.

Recital 92

There are circumstances under which it may be reasonable and economical for the subject of a data protection impact assessment to be broader than a single project, for example where public authorities or bodies intend to establish a common application or processing platform or where several controllers plan to introduce a common application or processing environment across an industry sector or segment or for a widely used horizontal activity.

Recital 93

In the context of the adoption of the Member State law on which the performance of the tasks of the public authority or public body is based and which regulates the specific processing operation or set of operations in question, Member States may deem it necessary to carry out such assessment prior to the processing activities.

Recital 95

The processor should assist the controller, where necessary and upon request, in ensuring compliance with the obligations deriving from the carrying out of data protection impact assessments and from prior consultation of the supervisory authority.

01

Yüksek risk eşiği ve değerlendirmenin işlevi

Planlanan bir işleme türünün gerçek kişilerin hak ve özgürlükleri bakımından yüksek risk doğurması muhtemelse veri sorumlusu, işlemeye başlamadan önce veri koruma etki değerlendirmesi yapmalıdır.1 Riskin belirlenmesinde işlemenin niteliği, kapsamı, bağlamı ve amaçları birlikte ele alınır. Yeni teknolojinin kullanılması bu değerlendirmede önem taşıyabilir, ancak tek başına değerlendirme yükümlülüğü doğurmaz.2

Etki değerlendirmesi, planlanan işlemenin hukuka uygunluğunu ve kişiler üzerindeki etkilerini işlemeye başlanmadan önce sınamaya yarar. Amaç, yüksek riskin kaynağını ve ağırlığını ortaya koymak, riski azaltacak tedbirleri belirlemek ve alınan kararların hesap verebilirlik çerçevesinde gösterilebilmesini sağlamaktır.3 Bu nedenle değerlendirme, karar verildikten sonra hazırlanacak biçimsel bir rapora indirgenemez.4

02

Değerlendirme gerektiren işleme türleri

GDPR m.35/3, değerlendirme yapılması gereken üç işleme grubunu özellikle gösterir. Bunlar, kişiler hakkında hukuki veya benzer ölçüde önemli sonuç doğuran kararlara temel oluşturan sistematik ve kapsamlı kişisel yön değerlendirmeleri, özel nitelikli veriler veya mahkumiyet ve suç verilerinin geniş ölçekte işlenmesi ile kamuya açık alanların geniş ölçekte sistematik olarak izlenmesidir.1

Bu sayım sınırlı değildir. Başka bir işleme de m.35/1'deki yüksek risk eşiğini karşılıyorsa değerlendirmeye tabi olacaktır.2 Denetim makamının m.35/4 uyarınca yayımladığı liste, değerlendirme yapılacak işleme türlerini somutlaştırır. Maddenin beşinci fıkrası ise denetim makamına değerlendirme gerektirmeyen işleme türlerini gösteren bir liste yayımlama imkanı verir.3

Bir işleme listelerde açıkça yer almıyorsa yalnız bu nedenle yüksek risk incelemesi sona ermez. Veri sorumlusu, planlanan işlemenin özelliklerini m.35/1'deki ölçütlere göre değerlendirmeli ve vardığı sonucu gösterebilmelidir.4

03

Değerlendirmenin asgari içeriği

Etki değerlendirmesi, planlanan işleme faaliyetlerini ve amaçlarını sistematik biçimde açıklamalıdır. Veri sorumlusu meşru menfaate dayanıyorsa izlenen menfaat de gösterilmelidir.1 Ardından işleme faaliyetinin amaç bakımından gerekli ve orantılı olup olmadığı incelenmelidir.2

İncelenecek riskler, yalnızca güvenlik açığı ihtimaliyle sınırlı değildir. Kişilerin hak ve özgürlükleri üzerindeki muhtemel sonuçların niteliği, gerçekleşme ihtimali ve ağırlığı değerlendirilmelidir.3 Belirlenen riskleri karşılayacak güvenceler, güvenlik tedbirleri ve hukuka uygunluğu gösterecek mekanizmalar da açıklanmalıdır.4

Bu unsurlar birbiriyle bağlantılıdır. İşleme faaliyeti ve amacı yeterince açıklanmadan gereklilik ile orantılılık denetlenemez. Riskler belirlenmeden de hangi tedbirin yeterli olduğu ve işlemden sonra hangi riskin kaldığı gösterilemez.5

04

Sorumluluk ve katılım

Etki değerlendirmesini yapma sorumluluğu veri sorumlusuna aittir. Veri sorumlusu çalışmayı uzmanlara veya başka kişilere yaptırabilir, ancak değerlendirme yükümlülüğünü ve sonuçlarına ilişkin sorumluluğu devredemez.1

Veri koruma görevlisi belirlenmişse değerlendirme sırasında görüşü alınmalıdır.2 Veri işleyen de gerekli olduğu ölçüde ve veri sorumlusunun talebi üzerine değerlendirme yükümlülüğünün yerine getirilmesine yardımcı olmalıdır.3 Bu aktörlerin katkısı, işleme amaçları ve araçları hakkında karar veren veri sorumlusunun sorumluluğunu değiştirmez.

Uygun olduğu hallerde ilgili kişilerin veya temsilcilerinin planlanan işlemeye ilişkin görüşleri de alınmalıdır. Ancak görüş alma süreci ticari veya kamusal menfaatleri ya da işleme güvenliğini zedelememelidir.4 Görüş alınması, ilgili kişinin işlemenin hukuka uygunluğu hakkında karar vermesi veya veri sorumlusunun risk değerlendirmesini devralması anlamına gelmez.5

05

Zaman, kapsam ve yenileme

Etki değerlendirmesi işlemeye başlanmadan önce tamamlanmalıdır. Değerlendirme, işleme faaliyetinin tasarımını ve uygulanacak tedbirleri etkileyebilecek kadar erken bir aşamada yapılmalıdır.1 Birbiriyle benzer ve aynı nitelikte yüksek risk doğuran işleme faaliyetleri tek bir değerlendirme içinde ele alınabilir.2

Değerlendirme bir kez hazırlanıp değişmeden saklanan bir belge değildir. İşleme faaliyetinin doğurduğu risk değiştiğinde veri sorumlusu, işlemenin etki değerlendirmesine uygun biçimde yürütülüp yürütülmediğini yeniden incelemelidir.3 Yeni bir teknolojiye geçilmesi, veri kapsamının genişlemesi, işleme amacının değişmesi veya güvenlik tedbirlerinin etkisini değiştiren gelişmeler bu incelemeyi gerekli kılabilir.4

Yenileme yükümlülüğü, her küçük değişiklikte bütün değerlendirmenin baştan yapılmasını gerektirmez. Değişikliğin riskin niteliği, ihtimali veya ağırlığı üzerindeki etkisi belirlenmeli ve değerlendirme bu etkiye göre güncellenmelidir.5

06

Kanuni dayanağa bağlı işleme ve ön danışma

Belirli bir işleme faaliyeti Birlik veya üye devlet hukukuna dayanabilir. Bu hukuki dayanak hazırlanırken genel bir etki değerlendirmesi yapılmışsa GDPR m.35/10'daki koşullar altında maddenin birinci ila yedinci fıkraları ayrıca uygulanmayabilir.1 Bu sonuç, kanuni dayanağa bağlı her işleme faaliyetinin etki değerlendirmesinden muaf olduğu anlamına gelmez. Hukuki düzenlemenin belirli işlemeyi kapsaması ve değerlendirme şartlarının somut olayda karşılanması gerekir.2

Etki değerlendirmesi sonucunda yüksek riskin alınacak tedbirlerle giderilemediği anlaşılırsa işlemeye başlanmadan önce GDPR m.36 uyarınca denetim makamına danışılmalıdır.3 Böylece etki değerlendirmesi ile ön danışma birbirini izleyen iki aşama oluşturur. Yüksek riskin uygun tedbirlerle kabul edilebilir düzeye indirilmesi halinde sırf başlangıçta yüksek risk görülmüş olması ön danışmayı zorunlu kılmaz.4

07

KVKK ile karşılaştırma

KVKK m.12, veri sorumlusuna uygun güvenlik düzeyini sağlamak için gerekli teknik ve idari tedbirleri alma ve Kanun hükümlerinin uygulanmasını sağlamak amacıyla gerekli denetimleri yapma veya yaptırma yükümlülüğü getirir.1 Bu hükümler risklerin önceden değerlendirilmesini gerektirebilir. Ancak KVKK, GDPR m.35'te olduğu gibi adı, uygulanma eşiği, asgari içeriği ve katılım usulü belirlenmiş genel bir veri koruma etki değerlendirmesi öngörmez.2

KVKK m.16'daki Sicile kayıt ve bildirim yükümlülüğü de etki değerlendirmesiyle aynı işlevi görmez. Sicil bildirimi işleme amaçları, veri kategorileri, alıcı grupları, yurt dışı aktarım ve güvenlik tedbirleri gibi bilgileri içerir. GDPR m.35 ise planlanan belirli bir işlemenin gerekliliğini, orantılılığını ve kişiler üzerindeki yüksek riskini değerlendirmeyi amaçlar.3

Bu nedenle GDPR m.35'teki yöntem, Türk hukukunda veri güvenliği ve hesap verebilirlik çalışmalarına karşılaştırmalı bir çerçeve sunabilir. Bununla birlikte GDPR'deki eşik, liste ve ön danışma sonuçları KVKK'ye doğrudan taşınamaz.4