GDPR

Madde 56

Baş denetim makamının yetkinliği

Son Güncelleme: 1 Ağustos 2026
GDPR İlgili Dibaceler 7 dibace
Official Journal text EUR-Lex
Recital 36

The main establishment of a controller in the Union should be the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union, in which case that other establishment should be considered to be the main establishment. The main establishment of a controller in the Union should be determined according to objective criteria and should imply the effective and real exercise of management activities determining the main decisions as to the purposes and means of processing through stable arrangements. That criterion should not depend on whether the processing of personal data is carried out at that location. The presence and use of technical means and technologies for processing personal data or processing activities do not, in themselves, constitute a main establishment and are therefore not determining criteria for a main establishment. The main establishment of the processor should be the place of its central administration in the Union or, if it has no central administration in the Union, the place where the main processing activities take place in the Union. In cases involving both the controller and the processor, the competent lead supervisory authority should remain the supervisory authority of the Member State where the controller has its main establishment, but the supervisory authority of the processor should be considered to be a supervisory authority concerned and that supervisory authority should participate in the cooperation procedure provided for by this Regulation. In any case, the supervisory authorities of the Member State or Member States where the processor has one or more establishments should not be considered to be supervisory authorities concerned where the draft decision concerns only the controller. Where the processing is carried out by a group of undertakings, the main establishment of the controlling undertaking should be considered to be the main establishment of the group of undertakings, except where the purposes and means of processing are determined by another undertaking.

Recital 37

A group of undertakings should cover a controlling undertaking and its controlled undertakings, whereby the controlling undertaking should be the undertaking which can exert a dominant influence over the other undertakings by virtue, for example, of ownership, financial participation or the rules which govern it or the power to have personal data protection rules implemented. An undertaking which controls the processing of personal data in undertakings affiliated to it should be regarded, together with those undertakings, as a group of undertakings.

Recital 124

Where the processing of personal data takes place in the context of the activities of an establishment of a controller or a processor in the Union and the controller or processor is established in more than one Member State, or where processing taking place in the context of the activities of a single establishment of a controller or processor in the Union substantially affects or is likely to substantially affect data subjects in more than one Member State, the supervisory authority for the main establishment of the controller or processor or for the single establishment of the controller or processor should act as lead authority. It should cooperate with the other authorities concerned, because the controller or processor has an establishment on the territory of their Member State, because data subjects residing on their territory are substantially affected, or because a complaint has been lodged with them. Also where a data subject not residing in that Member State has lodged a complaint, the supervisory authority with which such complaint has been lodged should also be a supervisory authority concerned. Within its tasks to issue guidelines on any question covering the application of this Regulation, the Board should be able to issue guidelines in particular on the criteria to be taken into account in order to ascertain whether the processing in question substantially affects data subjects in more than one Member State and on what constitutes a relevant and reasoned objection.

Recital 125

The lead authority should be competent to adopt binding decisions regarding measures applying the powers conferred on it in accordance with this Regulation. In its capacity as lead authority, the supervisory authority should closely involve and coordinate the supervisory authorities concerned in the decision-making process. Where the decision is to reject the complaint by the data subject in whole or in part, that decision should be adopted by the supervisory authority with which the complaint has been lodged.

Recital 126

The decision should be agreed jointly by the lead supervisory authority and the supervisory authorities concerned and should be directed towards the main or single establishment of the controller or processor and be binding on the controller and processor. The controller or processor should take the necessary measures to ensure compliance with this Regulation and the implementation of the decision notified by the lead supervisory authority to the main establishment of the controller or processor as regards the processing activities in the Union.

Recital 127

Each supervisory authority not acting as the lead supervisory authority should be competent to handle local cases where the controller or processor is established in more than one Member State, but the subject matter of the specific processing concerns only processing carried out in a single Member State and involves only data subjects in that single Member State, for example, where the subject matter concerns the processing of employees' personal data in the specific employment context of a Member State. In such cases, the supervisory authority should inform the lead supervisory authority without delay about the matter. After being informed, the lead supervisory authority should decide, whether it will handle the case pursuant to the provision on cooperation between the lead supervisory authority and other supervisory authorities concerned (‘one-stop-shop mechanism’), or whether the supervisory authority which informed it should handle the case at local level. When deciding whether it will handle the case, the lead supervisory authority should take into account whether there is an establishment of the controller or processor in the Member State of the supervisory authority which informed it in order to ensure effective enforcement of a decision vis-à-vis the controller or processor. Where the lead supervisory authority decides to handle the case, the supervisory authority which informed it should have the possibility to submit a draft for a decision, of which the lead supervisory authority should take utmost account when preparing its draft decision in that one-stop-shop mechanism.

Recital 128

The rules on the lead supervisory authority and the one-stop-shop mechanism should not apply where the processing is carried out by public authorities or private bodies in the public interest. In such cases the only supervisory authority competent to exercise the powers conferred to it in accordance with this Regulation should be the supervisory authority of the Member State where the public authority or private body is established.

01

Sınır ötesi işlemede baş denetim makamı

Bir veri sorumlusu veya veri işleyenin sınır ötesi işlemesi bakımından ana kuruluşun ya da tek kuruluşun bulunduğu üye devletin denetim makamı baş denetim makamı olarak hareket eder. Bu yetki, GDPR m.60'taki iş birliği usulü içinde kullanılacaktır.1

Baş denetim makamı düzeni yalnız GDPR m.4/23 anlamındaki sınır ötesi işlemelere uygulanır. Ayrıca veri sorumlusu veya veri işleyenin Birlik içinde bir ana ya da tek kuruluşu bulunmalıdır. Birlik içinde kuruluşu bulunmayan ve yalnız m.3/2 nedeniyle GDPR'a tabi olan bir kişi, temsilci atadığı için baş denetim makamı düzeninden yararlanamaz.2

Baş denetim makamı, ilgili diğer makamların bütün yetkilerini devralmaz. Karar sürecini yürütür, taslak kararı hazırlar ve m.60 uyarınca ilgili makamları sürece katar. Görüş ayrılığı çözülemezse m.65'teki uyuşmazlık çözüm yolu işletilecektir.3

ABAD, Facebook Ireland and Others kararında baş denetim makamının karar verme yetkisinin kural, diğer ilgili makamların karar verme yetkisinin ise istisna olduğunu kabul etmiştir. Bununla birlikte baş denetim makamı, diğer makamlarla yakın iş birliği ve gerçek bir diyalog içinde hareket etmelidir.4

02

Ana kuruluşun belirlenmesi

Baş denetim makamı, veri sorumlusu veya veri işleyenin kendi tercih bildirimiyle kurulmaz. Yetki, GDPR m.4/16'daki ana kuruluş tanımı ile somut işleme faaliyetinin nerede kararlaştırıldığı ve uygulandığına göre kanundan doğar.1

Veri sorumlusu bakımından Birlik içindeki merkezi idarenin bulunduğu yer kural olarak ana kuruluştur. Ancak işlemenin amaç ve araçlarına ilişkin kararlar başka bir Birlik kuruluşunda alınıyor ve bu kuruluş kararları uygulatma yetkisini kullanıyorsa ana kuruluş o yer olacaktır. Veri işleyen bakımından ise Birlik içindeki merkezi idarenin bulunduğu yer esas alınır. Birlik içinde merkezi idare bulunmuyorsa, veri işleyenin Tüzük kapsamındaki belirli yükümlülüklere tabi olduğu başlıca işleme faaliyetlerinin yürütüldüğü kuruluş ana kuruluş sayılacaktır.2 Kağıt üzerinde yapılan bir yer seçimi yeterli değildir. Kurumsal düzen gerçek ve işlevsel olmalıdır.

03

Yerel olay istisnası

Bir şikayet veya olası ihlal yalnız tek bir üye devletteki kuruluşa ilişkinse ya da yalnız o devletteki ilgili kişileri önemli ölçüde etkiliyorsa yerel denetim makamı olayı ele almaya yetkilidir.1 Gerekçe 127, belirli bir üye devletteki istihdam ilişkisi kapsamında çalışan verilerinin işlenmesini yerel olaya örnek gösterir.2

Bu istisna, olay sınır ötesi işleme tanımına girdiği halde uyuşmazlığın ağırlık merkezinin tek bir üye devlette bulunmasına dayanır. Başka üye devletlerdeki kişilerin önemli ölçüde etkilenip etkilenmediği somut olayda incelenecektir.3 Etkinin bulunup bulunmadığı belirsizse yerel istisna genişletilerek baş denetim makamı usulü dışlanmamalıdır.

04

Üç haftalık karar ve yerel taslak

Yerel denetim makamı m.56/2 kapsamındaki olayı baş denetim makamına gecikmeksizin bildirir. Baş denetim makamı, bildirimi aldıktan sonra üç hafta içinde olayı kendisinin ele alıp almayacağına karar vermelidir. Kararda, veri sorumlusu veya veri işleyenin bildirim yapan makamın üye devletinde bir kuruluşunun bulunup bulunmadığı dikkate alınacaktır.1

Baş denetim makamı olayı ele alırsa m.60 usulü uygulanır. Yerel makam bir karar taslağı sunabilir ve baş denetim makamı bu taslağı hazırladığı kararda azami ölçüde dikkate almalıdır.2 Baş denetim makamı olayı ele almazsa yerel makam m.61 ve m.62'deki karşılıklı yardım ve ortak operasyon hükümlerine göre işlemi sürdürür.3

05

Tek muhatap ve diğer makamlar

Baş denetim makamı, veri sorumlusu veya veri işleyenin sınır ötesi işlemesi bakımından tek muhatabıdır.1 Bu kural, aynı sınır ötesi işlem hakkında farklı denetim makamlarıyla paralel ve birbirinden kopuk idari görüşmeler yürütülmesini önlemeye yöneliktir.

Tek muhatap kuralı, ilgili diğer denetim makamlarının karar sürecindeki görevlerini sona erdirmez. Şikayetin yapıldığı makamın, ilgili kişilerin bulunduğu ülkedeki makamın ve m.4/22'de sayılan diğer ilgili makamların m.60 uyarınca sürece katılması devam eder.2 Yerel makamın m.56/4 uyarınca karar taslağı hazırladığı olayda, gerekli bilgiyi veri sorumlusu veya veri işleyenden edinme biçimi de iş birliği usulü içinde belirlenecektir.3

06

KVKK ile karşılaştırma

KVKK m.19/4 uyarınca Kişisel Verileri Koruma Kurumu, Kurul ve Başkanlıktan oluşur. Kurumun karar organı Kuruldur. KVKK m.21 ve m.22 de Kurulun oluşumu ile görev ve yetkilerini tek ulusal yapı içinde düzenler. Bu sistemde, farklı ülkelerdeki denetim makamları arasında baş denetim makamı belirlenmesini gerektiren bir yetki paylaşımı yoktur.1

GDPR m.56'daki baş denetim makamı, sınır ötesi işleme ve Birlik içindeki ana ya da tek kuruluş kavramlarına dayanır. Yerel olayın baş makama bildirilmesi, üç haftalık karar, yerel makamın taslak sunması ve tek muhatap kuralının KVKK m.19-27'de doğrudan bir karşılığı bulunmaz.2 Bu fark, KVKK sisteminde Kurulun her sınır ötesi olayda tek başına yetkili olduğu sonucunu kendiliğinden doğurmaz. Kurulun kanundan doğan görevleri, işlemenin KVKK kapsamına girip girmediği ve uygulanacak diğer hükümler uyarınca belirlenecektir.

§ Tüzük Metni
Official Journal text EUR-Lex

1. Without prejudice to Article 55, the supervisory authority of the main establishment or of the single establishment of the controller or processor shall be competent to act as lead supervisory authority for the cross-border processing carried out by that controller or processor in accordance with the procedure provided in Article 60.

2. By derogation from paragraph 1, each supervisory authority shall be competent to handle a complaint lodged with it or a possible infringement of this Regulation, if the subject matter relates only to an establishment in its Member State or substantially affects data subjects only in its Member State.

3. In the cases referred to in paragraph 2 of this Article, the supervisory authority shall inform the lead supervisory authority without delay on that matter. Within a period of three weeks after being informed the lead supervisory authority shall decide whether or not it will handle the case in accordance with the procedure provided in Article 60, taking into account whether or not there is an establishment of the controller or processor in the Member State of which the supervisory authority informed it.

4. Where the lead supervisory authority decides to handle the case, the procedure provided in Article 60 shall apply. The supervisory authority which informed the lead supervisory authority may submit to the lead supervisory authority a draft for a decision. The lead supervisory authority shall take utmost account of that draft when preparing the draft decision referred to in Article 60(3).

5. Where the lead supervisory authority decides not to handle the case, the supervisory authority which informed the lead supervisory authority shall handle it according to Articles 61 and 62.

6. The lead supervisory authority shall be the sole interlocutor of the controller or processor for the cross-border processing carried out by that controller or processor.

§ İlgili Dibaceler GDPR · 7
Official Journal text EUR-Lex
Recital 36

The main establishment of a controller in the Union should be the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union, in which case that other establishment should be considered to be the main establishment. The main establishment of a controller in the Union should be determined according to objective criteria and should imply the effective and real exercise of management activities determining the main decisions as to the purposes and means of processing through stable arrangements. That criterion should not depend on whether the processing of personal data is carried out at that location. The presence and use of technical means and technologies for processing personal data or processing activities do not, in themselves, constitute a main establishment and are therefore not determining criteria for a main establishment. The main establishment of the processor should be the place of its central administration in the Union or, if it has no central administration in the Union, the place where the main processing activities take place in the Union. In cases involving both the controller and the processor, the competent lead supervisory authority should remain the supervisory authority of the Member State where the controller has its main establishment, but the supervisory authority of the processor should be considered to be a supervisory authority concerned and that supervisory authority should participate in the cooperation procedure provided for by this Regulation. In any case, the supervisory authorities of the Member State or Member States where the processor has one or more establishments should not be considered to be supervisory authorities concerned where the draft decision concerns only the controller. Where the processing is carried out by a group of undertakings, the main establishment of the controlling undertaking should be considered to be the main establishment of the group of undertakings, except where the purposes and means of processing are determined by another undertaking.

Recital 37

A group of undertakings should cover a controlling undertaking and its controlled undertakings, whereby the controlling undertaking should be the undertaking which can exert a dominant influence over the other undertakings by virtue, for example, of ownership, financial participation or the rules which govern it or the power to have personal data protection rules implemented. An undertaking which controls the processing of personal data in undertakings affiliated to it should be regarded, together with those undertakings, as a group of undertakings.

Recital 124

Where the processing of personal data takes place in the context of the activities of an establishment of a controller or a processor in the Union and the controller or processor is established in more than one Member State, or where processing taking place in the context of the activities of a single establishment of a controller or processor in the Union substantially affects or is likely to substantially affect data subjects in more than one Member State, the supervisory authority for the main establishment of the controller or processor or for the single establishment of the controller or processor should act as lead authority. It should cooperate with the other authorities concerned, because the controller or processor has an establishment on the territory of their Member State, because data subjects residing on their territory are substantially affected, or because a complaint has been lodged with them. Also where a data subject not residing in that Member State has lodged a complaint, the supervisory authority with which such complaint has been lodged should also be a supervisory authority concerned. Within its tasks to issue guidelines on any question covering the application of this Regulation, the Board should be able to issue guidelines in particular on the criteria to be taken into account in order to ascertain whether the processing in question substantially affects data subjects in more than one Member State and on what constitutes a relevant and reasoned objection.

Recital 125

The lead authority should be competent to adopt binding decisions regarding measures applying the powers conferred on it in accordance with this Regulation. In its capacity as lead authority, the supervisory authority should closely involve and coordinate the supervisory authorities concerned in the decision-making process. Where the decision is to reject the complaint by the data subject in whole or in part, that decision should be adopted by the supervisory authority with which the complaint has been lodged.

Recital 126

The decision should be agreed jointly by the lead supervisory authority and the supervisory authorities concerned and should be directed towards the main or single establishment of the controller or processor and be binding on the controller and processor. The controller or processor should take the necessary measures to ensure compliance with this Regulation and the implementation of the decision notified by the lead supervisory authority to the main establishment of the controller or processor as regards the processing activities in the Union.

Recital 127

Each supervisory authority not acting as the lead supervisory authority should be competent to handle local cases where the controller or processor is established in more than one Member State, but the subject matter of the specific processing concerns only processing carried out in a single Member State and involves only data subjects in that single Member State, for example, where the subject matter concerns the processing of employees' personal data in the specific employment context of a Member State. In such cases, the supervisory authority should inform the lead supervisory authority without delay about the matter. After being informed, the lead supervisory authority should decide, whether it will handle the case pursuant to the provision on cooperation between the lead supervisory authority and other supervisory authorities concerned (‘one-stop-shop mechanism’), or whether the supervisory authority which informed it should handle the case at local level. When deciding whether it will handle the case, the lead supervisory authority should take into account whether there is an establishment of the controller or processor in the Member State of the supervisory authority which informed it in order to ensure effective enforcement of a decision vis-à-vis the controller or processor. Where the lead supervisory authority decides to handle the case, the supervisory authority which informed it should have the possibility to submit a draft for a decision, of which the lead supervisory authority should take utmost account when preparing its draft decision in that one-stop-shop mechanism.

Recital 128

The rules on the lead supervisory authority and the one-stop-shop mechanism should not apply where the processing is carried out by public authorities or private bodies in the public interest. In such cases the only supervisory authority competent to exercise the powers conferred to it in accordance with this Regulation should be the supervisory authority of the Member State where the public authority or private body is established.

01

Sınır ötesi işlemede baş denetim makamı

Bir veri sorumlusu veya veri işleyenin sınır ötesi işlemesi bakımından ana kuruluşun ya da tek kuruluşun bulunduğu üye devletin denetim makamı baş denetim makamı olarak hareket eder. Bu yetki, GDPR m.60'taki iş birliği usulü içinde kullanılacaktır.1

Baş denetim makamı düzeni yalnız GDPR m.4/23 anlamındaki sınır ötesi işlemelere uygulanır. Ayrıca veri sorumlusu veya veri işleyenin Birlik içinde bir ana ya da tek kuruluşu bulunmalıdır. Birlik içinde kuruluşu bulunmayan ve yalnız m.3/2 nedeniyle GDPR'a tabi olan bir kişi, temsilci atadığı için baş denetim makamı düzeninden yararlanamaz.2

Baş denetim makamı, ilgili diğer makamların bütün yetkilerini devralmaz. Karar sürecini yürütür, taslak kararı hazırlar ve m.60 uyarınca ilgili makamları sürece katar. Görüş ayrılığı çözülemezse m.65'teki uyuşmazlık çözüm yolu işletilecektir.3

ABAD, Facebook Ireland and Others kararında baş denetim makamının karar verme yetkisinin kural, diğer ilgili makamların karar verme yetkisinin ise istisna olduğunu kabul etmiştir. Bununla birlikte baş denetim makamı, diğer makamlarla yakın iş birliği ve gerçek bir diyalog içinde hareket etmelidir.4

02

Ana kuruluşun belirlenmesi

Baş denetim makamı, veri sorumlusu veya veri işleyenin kendi tercih bildirimiyle kurulmaz. Yetki, GDPR m.4/16'daki ana kuruluş tanımı ile somut işleme faaliyetinin nerede kararlaştırıldığı ve uygulandığına göre kanundan doğar.1

Veri sorumlusu bakımından Birlik içindeki merkezi idarenin bulunduğu yer kural olarak ana kuruluştur. Ancak işlemenin amaç ve araçlarına ilişkin kararlar başka bir Birlik kuruluşunda alınıyor ve bu kuruluş kararları uygulatma yetkisini kullanıyorsa ana kuruluş o yer olacaktır. Veri işleyen bakımından ise Birlik içindeki merkezi idarenin bulunduğu yer esas alınır. Birlik içinde merkezi idare bulunmuyorsa, veri işleyenin Tüzük kapsamındaki belirli yükümlülüklere tabi olduğu başlıca işleme faaliyetlerinin yürütüldüğü kuruluş ana kuruluş sayılacaktır.2 Kağıt üzerinde yapılan bir yer seçimi yeterli değildir. Kurumsal düzen gerçek ve işlevsel olmalıdır.

03

Yerel olay istisnası

Bir şikayet veya olası ihlal yalnız tek bir üye devletteki kuruluşa ilişkinse ya da yalnız o devletteki ilgili kişileri önemli ölçüde etkiliyorsa yerel denetim makamı olayı ele almaya yetkilidir.1 Gerekçe 127, belirli bir üye devletteki istihdam ilişkisi kapsamında çalışan verilerinin işlenmesini yerel olaya örnek gösterir.2

Bu istisna, olay sınır ötesi işleme tanımına girdiği halde uyuşmazlığın ağırlık merkezinin tek bir üye devlette bulunmasına dayanır. Başka üye devletlerdeki kişilerin önemli ölçüde etkilenip etkilenmediği somut olayda incelenecektir.3 Etkinin bulunup bulunmadığı belirsizse yerel istisna genişletilerek baş denetim makamı usulü dışlanmamalıdır.

04

Üç haftalık karar ve yerel taslak

Yerel denetim makamı m.56/2 kapsamındaki olayı baş denetim makamına gecikmeksizin bildirir. Baş denetim makamı, bildirimi aldıktan sonra üç hafta içinde olayı kendisinin ele alıp almayacağına karar vermelidir. Kararda, veri sorumlusu veya veri işleyenin bildirim yapan makamın üye devletinde bir kuruluşunun bulunup bulunmadığı dikkate alınacaktır.1

Baş denetim makamı olayı ele alırsa m.60 usulü uygulanır. Yerel makam bir karar taslağı sunabilir ve baş denetim makamı bu taslağı hazırladığı kararda azami ölçüde dikkate almalıdır.2 Baş denetim makamı olayı ele almazsa yerel makam m.61 ve m.62'deki karşılıklı yardım ve ortak operasyon hükümlerine göre işlemi sürdürür.3

05

Tek muhatap ve diğer makamlar

Baş denetim makamı, veri sorumlusu veya veri işleyenin sınır ötesi işlemesi bakımından tek muhatabıdır.1 Bu kural, aynı sınır ötesi işlem hakkında farklı denetim makamlarıyla paralel ve birbirinden kopuk idari görüşmeler yürütülmesini önlemeye yöneliktir.

Tek muhatap kuralı, ilgili diğer denetim makamlarının karar sürecindeki görevlerini sona erdirmez. Şikayetin yapıldığı makamın, ilgili kişilerin bulunduğu ülkedeki makamın ve m.4/22'de sayılan diğer ilgili makamların m.60 uyarınca sürece katılması devam eder.2 Yerel makamın m.56/4 uyarınca karar taslağı hazırladığı olayda, gerekli bilgiyi veri sorumlusu veya veri işleyenden edinme biçimi de iş birliği usulü içinde belirlenecektir.3

06

KVKK ile karşılaştırma

KVKK m.19/4 uyarınca Kişisel Verileri Koruma Kurumu, Kurul ve Başkanlıktan oluşur. Kurumun karar organı Kuruldur. KVKK m.21 ve m.22 de Kurulun oluşumu ile görev ve yetkilerini tek ulusal yapı içinde düzenler. Bu sistemde, farklı ülkelerdeki denetim makamları arasında baş denetim makamı belirlenmesini gerektiren bir yetki paylaşımı yoktur.1

GDPR m.56'daki baş denetim makamı, sınır ötesi işleme ve Birlik içindeki ana ya da tek kuruluş kavramlarına dayanır. Yerel olayın baş makama bildirilmesi, üç haftalık karar, yerel makamın taslak sunması ve tek muhatap kuralının KVKK m.19-27'de doğrudan bir karşılığı bulunmaz.2 Bu fark, KVKK sisteminde Kurulun her sınır ötesi olayda tek başına yetkili olduğu sonucunu kendiliğinden doğurmaz. Kurulun kanundan doğan görevleri, işlemenin KVKK kapsamına girip girmediği ve uygulanacak diğer hükümler uyarınca belirlenecektir.

📚 Kaynaklar