GDPR

Madde 59

Faaliyet raporları

Son Güncelleme: 1 Ağustos 2026
GDPR İlgili Dibaceler 1 dibace
Official Journal text EUR-Lex
Recital 129

In order to ensure consistent monitoring and enforcement of this Regulation throughout the Union, the supervisory authorities should have in each Member State the same tasks and effective powers, including powers of investigation, corrective powers and sanctions, and authorisation and advisory powers, in particular in cases of complaints from natural persons, and without prejudice to the powers of prosecutorial authorities under Member State law, to bring infringements of this Regulation to the attention of the judicial authorities and engage in legal proceedings. Such powers should also include the power to impose a temporary or definitive limitation, including a ban, on processing. Member States may specify other tasks related to the protection of personal data under this Regulation. The powers of supervisory authorities should be exercised in accordance with appropriate procedural safeguards set out in Union and Member State law, impartially, fairly and within a reasonable time. In particular each measure should be appropriate, necessary and proportionate in view of ensuring compliance with this Regulation, taking into account the circumstances of each individual case, respect the right of every person to be heard before any individual measure which would affect him or her adversely is taken and avoid superfluous costs and excessive inconveniences for the persons concerned. Investigatory powers as regards access to premises should be exercised in accordance with specific requirements in Member State procedural law, such as the requirement to obtain a prior judicial authorisation. Each legally binding measure of the supervisory authority should be in writing, be clear and unambiguous, indicate the supervisory authority which has issued the measure, the date of issue of the measure, bear the signature of the head, or a member of the supervisory authority authorised by him or her, give the reasons for the measure, and refer to the right of an effective remedy. This should not preclude additional requirements pursuant to Member State procedural law. The adoption of a legally binding decision implies that it may give rise to judicial review in the Member State of the supervisory authority that adopted the decision.

01

Yıllık rapor ve içeriği

Her denetim makamı faaliyetleri hakkında yıllık bir rapor hazırlamak zorundadır.1 Rapor, makama bildirilen ihlal türlerinin ve GDPR m.58/2 uyarınca alınan tedbir türlerinin bir listesini içerebilir. Maddede bu listenin rapora dahil edilebileceği belirtildiğinden, her raporda aynı ayrıntıyla yer alması zorunlu değildir.2

İhlal ve tedbir türleri, raporun bütün içeriğini sınırlamaz. Denetim makamı m.57'deki diğer görevlerini, m.58'deki yetkilerini ve veri koruma alanındaki gelişmeleri de raporlayabilir.3 Faaliyet raporu ile m.57/1-u uyarınca tutulan iç kayıt aynı belge değildir. İç kayıtlardaki bilgiler, gizlilik ve veri koruma şartları gözetilerek raporun hazırlanmasında kullanılabilir.

02

Raporun muhatapları ve erişim

Faaliyet raporu ulusal parlamentoya, hükümete ve üye devlet hukukunda belirlenen diğer makamlara gönderilmelidir. Rapor ayrıca kamuya, Avrupa Komisyonuna ve Avrupa Veri Koruma Kuruluna açık tutulmalıdır.1

Gönderme ve kamuya açma ayrı yükümlülüklerdir. Ulusal makamların raporu doğrudan alması, raporun kamuya erişilebilir hale getirilmesinin yerine geçmez. Maddenin lafzı belirli bir yayın biçimi öngörmemiştir. Kullanılan yöntem, rapora fiilen ve makul biçimde erişilmesini sağlamalıdır.

03

Bağımsızlık ve kamusal hesap verebilirlik

Faaliyet raporu, bağımsız denetim makamının çalışmalarını demokratik kurumlara ve kamuya açıklamasını sağlar. Makamın bağımsız olması, kamu kaynağını nasıl kullandığı ve görevlerini nasıl yerine getirdiği konusunda bilgi vermesine engel değildir.1

Rapor verme yükümlülüğü, parlamento veya hükümete denetim makamının bireysel kararlarını değiştirme ya da makama talimat verme yetkisi tanımaz. Kamusal hesap verebilirlik ile karar bağımsızlığı birlikte korunacaktır.2 GDPR m.59 için özel bir doğrudan gerekçe bulunmamaktadır.

04

KVKK ile karşılaştırma

6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) m.20/1-ç, Kişisel Verileri Koruma Kurumunun yıllık faaliyet raporunu Cumhurbaşkanlığına ve Türkiye Büyük Millet Meclisi İnsan Haklarını İnceleme Komisyonuna sunmasını öngörür.1 Rapor taslaklarını hazırlayıp Kurula sunma görevi KVKK m.25/4-f uyarınca Başkanlığa, taslakları onaylama ve yayımlama yetkisi ise m.22/1-j uyarınca Kişisel Verileri Koruma Kuruluna aittir.2 Böylece hazırlama, onaylama, yayımlama ve raporu kanunda belirtilen makamlara sunma işlemleri Kurumun farklı organları arasında paylaştırılmıştır.

GDPR m.59, faaliyet raporunun ulusal makamların yanı sıra kamuya, Avrupa Komisyonuna ve Avrupa Veri Koruma Kuruluna açık tutulmasını ister. KVKK m.20/1-ç ulusal muhatapları farklı belirlemiş, m.22/1-j ise raporun yayımlanmasını ayrıca Kurulun görev ve yetkileri arasında saymıştır.3 GDPR m.59 raporda ihlal türleri ile alınan tedbir türlerinin listelenebileceğini açıkça belirtir. KVKK m.22/1-j ise rapor taslaklarını Kurumun performansı, mali durumu, yıllık faaliyetleri ve ihtiyaç duyulan konular bakımından daha genel ifadelerle tanımlar.4

§ Tüzük Metni
Official Journal text EUR-Lex

Each supervisory authority shall draw up an annual report on its activities, which may include a list of types of infringement notified and types of measures taken in accordance with Article 58(2). Those reports shall be transmitted to the national parliament, the government and other authorities as designated by Member State law. They shall be made available to the public, to the Commission and to the Board.

§ İlgili Dibaceler GDPR · 1
Official Journal text EUR-Lex
Recital 129

In order to ensure consistent monitoring and enforcement of this Regulation throughout the Union, the supervisory authorities should have in each Member State the same tasks and effective powers, including powers of investigation, corrective powers and sanctions, and authorisation and advisory powers, in particular in cases of complaints from natural persons, and without prejudice to the powers of prosecutorial authorities under Member State law, to bring infringements of this Regulation to the attention of the judicial authorities and engage in legal proceedings. Such powers should also include the power to impose a temporary or definitive limitation, including a ban, on processing. Member States may specify other tasks related to the protection of personal data under this Regulation. The powers of supervisory authorities should be exercised in accordance with appropriate procedural safeguards set out in Union and Member State law, impartially, fairly and within a reasonable time. In particular each measure should be appropriate, necessary and proportionate in view of ensuring compliance with this Regulation, taking into account the circumstances of each individual case, respect the right of every person to be heard before any individual measure which would affect him or her adversely is taken and avoid superfluous costs and excessive inconveniences for the persons concerned. Investigatory powers as regards access to premises should be exercised in accordance with specific requirements in Member State procedural law, such as the requirement to obtain a prior judicial authorisation. Each legally binding measure of the supervisory authority should be in writing, be clear and unambiguous, indicate the supervisory authority which has issued the measure, the date of issue of the measure, bear the signature of the head, or a member of the supervisory authority authorised by him or her, give the reasons for the measure, and refer to the right of an effective remedy. This should not preclude additional requirements pursuant to Member State procedural law. The adoption of a legally binding decision implies that it may give rise to judicial review in the Member State of the supervisory authority that adopted the decision.

01

Yıllık rapor ve içeriği

Her denetim makamı faaliyetleri hakkında yıllık bir rapor hazırlamak zorundadır.1 Rapor, makama bildirilen ihlal türlerinin ve GDPR m.58/2 uyarınca alınan tedbir türlerinin bir listesini içerebilir. Maddede bu listenin rapora dahil edilebileceği belirtildiğinden, her raporda aynı ayrıntıyla yer alması zorunlu değildir.2

İhlal ve tedbir türleri, raporun bütün içeriğini sınırlamaz. Denetim makamı m.57'deki diğer görevlerini, m.58'deki yetkilerini ve veri koruma alanındaki gelişmeleri de raporlayabilir.3 Faaliyet raporu ile m.57/1-u uyarınca tutulan iç kayıt aynı belge değildir. İç kayıtlardaki bilgiler, gizlilik ve veri koruma şartları gözetilerek raporun hazırlanmasında kullanılabilir.

02

Raporun muhatapları ve erişim

Faaliyet raporu ulusal parlamentoya, hükümete ve üye devlet hukukunda belirlenen diğer makamlara gönderilmelidir. Rapor ayrıca kamuya, Avrupa Komisyonuna ve Avrupa Veri Koruma Kuruluna açık tutulmalıdır.1

Gönderme ve kamuya açma ayrı yükümlülüklerdir. Ulusal makamların raporu doğrudan alması, raporun kamuya erişilebilir hale getirilmesinin yerine geçmez. Maddenin lafzı belirli bir yayın biçimi öngörmemiştir. Kullanılan yöntem, rapora fiilen ve makul biçimde erişilmesini sağlamalıdır.

03

Bağımsızlık ve kamusal hesap verebilirlik

Faaliyet raporu, bağımsız denetim makamının çalışmalarını demokratik kurumlara ve kamuya açıklamasını sağlar. Makamın bağımsız olması, kamu kaynağını nasıl kullandığı ve görevlerini nasıl yerine getirdiği konusunda bilgi vermesine engel değildir.1

Rapor verme yükümlülüğü, parlamento veya hükümete denetim makamının bireysel kararlarını değiştirme ya da makama talimat verme yetkisi tanımaz. Kamusal hesap verebilirlik ile karar bağımsızlığı birlikte korunacaktır.2 GDPR m.59 için özel bir doğrudan gerekçe bulunmamaktadır.

04

KVKK ile karşılaştırma

6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) m.20/1-ç, Kişisel Verileri Koruma Kurumunun yıllık faaliyet raporunu Cumhurbaşkanlığına ve Türkiye Büyük Millet Meclisi İnsan Haklarını İnceleme Komisyonuna sunmasını öngörür.1 Rapor taslaklarını hazırlayıp Kurula sunma görevi KVKK m.25/4-f uyarınca Başkanlığa, taslakları onaylama ve yayımlama yetkisi ise m.22/1-j uyarınca Kişisel Verileri Koruma Kuruluna aittir.2 Böylece hazırlama, onaylama, yayımlama ve raporu kanunda belirtilen makamlara sunma işlemleri Kurumun farklı organları arasında paylaştırılmıştır.

GDPR m.59, faaliyet raporunun ulusal makamların yanı sıra kamuya, Avrupa Komisyonuna ve Avrupa Veri Koruma Kuruluna açık tutulmasını ister. KVKK m.20/1-ç ulusal muhatapları farklı belirlemiş, m.22/1-j ise raporun yayımlanmasını ayrıca Kurulun görev ve yetkileri arasında saymıştır.3 GDPR m.59 raporda ihlal türleri ile alınan tedbir türlerinin listelenebileceğini açıkça belirtir. KVKK m.22/1-j ise rapor taslaklarını Kurumun performansı, mali durumu, yıllık faaliyetleri ve ihtiyaç duyulan konular bakımından daha genel ifadelerle tanımlar.4