GDPR

Madde 60

Baş denetim makamı ve diğer ilgili denetim makamları arasında iş birliği

Son Güncelleme: 1 Ağustos 2026
GDPR İlgili Dibaceler 5 dibace
Official Journal text EUR-Lex
Recital 124

Where the processing of personal data takes place in the context of the activities of an establishment of a controller or a processor in the Union and the controller or processor is established in more than one Member State, or where processing taking place in the context of the activities of a single establishment of a controller or processor in the Union substantially affects or is likely to substantially affect data subjects in more than one Member State, the supervisory authority for the main establishment of the controller or processor or for the single establishment of the controller or processor should act as lead authority. It should cooperate with the other authorities concerned, because the controller or processor has an establishment on the territory of their Member State, because data subjects residing on their territory are substantially affected, or because a complaint has been lodged with them. Also where a data subject not residing in that Member State has lodged a complaint, the supervisory authority with which such complaint has been lodged should also be a supervisory authority concerned. Within its tasks to issue guidelines on any question covering the application of this Regulation, the Board should be able to issue guidelines in particular on the criteria to be taken into account in order to ascertain whether the processing in question substantially affects data subjects in more than one Member State and on what constitutes a relevant and reasoned objection.

Recital 125

The lead authority should be competent to adopt binding decisions regarding measures applying the powers conferred on it in accordance with this Regulation. In its capacity as lead authority, the supervisory authority should closely involve and coordinate the supervisory authorities concerned in the decision-making process. Where the decision is to reject the complaint by the data subject in whole or in part, that decision should be adopted by the supervisory authority with which the complaint has been lodged.

Recital 126

The decision should be agreed jointly by the lead supervisory authority and the supervisory authorities concerned and should be directed towards the main or single establishment of the controller or processor and be binding on the controller and processor. The controller or processor should take the necessary measures to ensure compliance with this Regulation and the implementation of the decision notified by the lead supervisory authority to the main establishment of the controller or processor as regards the processing activities in the Union.

Recital 130

Where the supervisory authority with which the complaint has been lodged is not the lead supervisory authority, the lead supervisory authority should closely cooperate with the supervisory authority with which the complaint has been lodged in accordance with the provisions on cooperation and consistency laid down in this Regulation. In such cases, the lead supervisory authority should, when taking measures intended to produce legal effects, including the imposition of administrative fines, take utmost account of the view of the supervisory authority with which the complaint has been lodged and which should remain competent to carry out any investigation on the territory of its own Member State in liaison with the competent supervisory authority.

Recital 131

Where another supervisory authority should act as a lead supervisory authority for the processing activities of the controller or processor but the concrete subject matter of a complaint or the possible infringement concerns only processing activities of the controller or processor in the Member State where the complaint has been lodged or the possible infringement detected and the matter does not substantially affect or is not likely to substantially affect data subjects in other Member States, the supervisory authority receiving a complaint or detecting or being informed otherwise of situations that entail possible infringements of this Regulation should seek an amicable settlement with the controller and, if this proves unsuccessful, exercise its full range of powers. This should include: specific processing carried out in the territory of the Member State of the supervisory authority or with regard to data subjects on the territory of that Member State; processing that is carried out in the context of an offer of goods or services specifically aimed at data subjects in the territory of the Member State of the supervisory authority; or processing that has to be assessed taking into account relevant legal obligations under Member State law.

01

Tek durak mekanizmasında ortak karar

GDPR m.60, sınır ötesi işleme hakkında karar verecek baş denetim makamının diğer ilgili denetim makamlarıyla nasıl çalışacağını düzenler. Baş denetim makamı süreci yürütür, fakat ilgili makamların üzerinde yer alan bir üst makam değildir. İlgili makamlar bilgi edinme, görüş bildirme ve maddede öngörülen şartlarla karara itiraz etme yetkilerini korur.1

Maddenin birinci fıkrası, makamların uzlaşmaya varmak amacıyla çaba göstermelerini ve birbirlerine gerekli bilgileri iletmelerini öngörür. Karar taslağına yöneltilen ilgili ve gerekçeli itiraz çözülemezse m.60/4 ile m.65'teki uyuşmazlık çözümü yolu işletilecektir.2 Bu düzenleme, baş denetim makamına tek başına karar verme serbestisi tanımaz. Bununla birlikte uzlaşma yükümlülüğü, her görüş ayrılığının mutlaka anlaşmayla sonuçlanacağı anlamına da gelmez.

Tek durak mekanizması, sınır ötesi işleme hakkında birbiriyle çelişen ulusal kararların önlenmesine hizmet eder. Aynı zamanda şikayetin yapıldığı yerde incelenebilmesini ve ilgili kişinin kendi denetim makamıyla temasını korur.3 Bu iki yön birlikte değerlendirildiğinde m.60, yalnız yetki paylaşan bir hüküm değil, ortak kararın hazırlanmasına ilişkin bir usul hükmüdür.

02

Bilgi paylaşımı ve karar taslağı

Baş denetim makamı, ilgili denetim makamlarından karşılıklı yardım veya ortak operasyon talep edebilir. Talebin niteliğine göre m.61 veya m.62'deki özel usul uygulanacaktır.1 Bu imkan, makamlar arasındaki olağan bilgi paylaşımının yerini almaz.

Baş denetim makamı, konuyu inceledikten sonra karar taslağını gecikmeksizin diğer ilgili makamlara sunmalıdır. Karar taslağı, makamların görüş bildirebileceği kadar açık olmalı ve dosyanın değerlendirilmesi için gerekli bilgileri taşımalıdır. Baş denetim makamı, ilgili makamların görüşlerini karar taslağı hazırlanırken ve gerektiğinde taslak yeniden düzenlenirken gereği gibi dikkate alacaktır.2 İlgili makamların sürece katılması, taslak tamamlandıktan sonra yapılan şekli bir bildirimden ibaret değildir.

Görüşleri dikkate alma yükümlülüğü, baş denetim makamını her görüşe katılmaya mecbur bırakmaz. Görüş ayrılığı m.60/4'teki nitelikleri taşıyan bir itiraza dönüşürse baş denetim makamı ya itirazı kabul ederek yeni bir taslak sunacak ya da konuyu Avrupa Veri Koruma Kuruluna götürecektir.3

03

İlgili ve gerekçeli itiraz

İlgili denetim makamı, karar taslağının kendisine sunulmasından itibaren dört hafta içinde itiraz edebilir. Her görüş ayrılığı bu sonucu doğurmaz. İtirazın karar taslağına yönelmesi ve GDPR m.4/24 anlamında ilgili ve gerekçeli olması gerekir. Buna göre itiraz, somut olayda Tüzüğün ihlal edilip edilmediği veya veri sorumlusu ya da veri işleyene yönelik öngörülen tedbirin Tüzüğe uygun olup olmadığı konularından birine dayanmalı ve taslağın ilgili kişilerin temel hak ve özgürlükleri ya da Birlik içinde kişisel verilerin serbest dolaşımı bakımından taşıdığı riskin önemini açıkça göstermelidir.1

Baş denetim makamı itirazı kabul ederse yeni karar taslağını ilgili makamlara sunar. Yeni taslağa itiraz süresi iki haftadır.2 Böylece ilk taslak için tanınan dört haftalık süre, yeniden düzenlenen taslak bakımından kısaltılmıştır.

Baş denetim makamı itirazı kabul etmezse veya itirazı ilgili ve gerekçeli bulmazsa konuyu m.65'teki uyuşmazlık çözümü için Avrupa Veri Koruma Kuruluna iletmelidir. Baş denetim makamı, bu halde itirazı yalnız kendi kararıyla etkisiz bırakarak nihai karar veremez.3

04

Nihai kararın kabulü ve bildirimi

İlgili denetim makamları karar taslağına süresinde itiraz etmezse taslağı kabul etmiş sayılır ve karar onları bağlar. Baş denetim makamı, veri sorumlusu veya veri işleyenin ana kuruluşuna ya da tek kuruluşuna yönelik kararı kabul eder ve bildirir. Diğer ilgili makamlar ile Avrupa Veri Koruma Kurulu da bilgilendirilir.1

Şikayetin reddedildiği veya kabul edilemez bulunduğu hallerde kararı, şikayetin yapıldığı denetim makamı kabul eder ve ilgili kişiye bildirir. Veri sorumlusu da karardan haberdar edilir. Şikayetin kısmen reddedildiği, kısmen de veri sorumlusu veya veri işleyene yönelik işlem yapılmasını gerektirdiği hallerde ise iki ayrı karar verilir.2 Bu ayrım, ilgili kişinin kendi makamı önünde hukuki korunmasını sürdürürken işletmeye yönelen kararın baş denetim makamı tarafından alınmasını sağlar.

Kararı hangi makamın kabul edeceği, kararın maddi sonucuna göre belirlenir. Şikayetin reddi ile veri sorumlusu veya veri işleyene yükümlülük getiren kısım aynı makam adına tek kararda birleştirilemez.3

05

Kararın sınır ötesi etkisi

Veri sorumlusu veya veri işleyen, kendisine GDPR m.60/7 veya m.60/9 uyarınca bildirilen karara m.60/10 gereğince uymalı ve gerekli tedbirleri Birlik içindeki bütün kuruluşlarında ilgili işleme faaliyeti bakımından uygulamalıdır.1 Bu yükümlülük, kararı yalnız ana kuruluşun bulunduğu üye devlette sonuç doğuran bir işlem olmaktan çıkarır.

Kararın kapsamı, hakkında inceleme yapılan işleme faaliyetiyle sınırlıdır. Aynı işletme grubunun başka bir işleme faaliyeti, yalnız aynı veri sorumlusunca yürütüldüğü için kendiliğinden kararın kapsamına girmez.2 Hangi kuruluşların ve işlemelerin karardan etkilendiği, kararın gerekçesi ve hüküm kısmı birlikte değerlendirilerek belirlenecektir.

Veri sorumlusu veya veri işleyen, karara uymak için aldığı önlemleri baş denetim makamına bildirmelidir. Baş denetim makamı da bu bilgiyi diğer ilgili denetim makamlarına iletir.3 Böylece kararın sınır ötesi uygulanması yalnız işletmenin beyanına bırakılmamış, makamlar arasındaki bilgi akışına bağlanmıştır.

06

Acil usul ve elektronik iletişim

Olağan iş birliği usulü, ilgili kişilerin menfaatlerini korumak için gecikmeksizin harekete geçilmesi gereken istisnai halleri ortadan kaldırmaz. GDPR m.60/11, bu durumda m.66'daki acil usulün uygulanmasına imkan tanır.1 Acil usule başvurulması için yalnız makamlar arasında görüş ayrılığı bulunması yeterli değildir. GDPR m.66'da aranan istisnai şartlar ayrıca gerçekleşmelidir.

Makamlar m.60 kapsamında birbirlerine elektronik yollarla ve standartlaştırılmış bir format kullanarak bilgi verir. Bu şekil, karar taslaklarının, itirazların ve diğer usul belgelerinin bütün ilgili makamlara aynı düzen içinde iletilmesine hizmet eder.2 Elektronik iletişim kuralı, uzlaşma çabasını veya ilgili makamın görüşünün gereği gibi değerlendirilmesini ikame eden bir şekil şartı değildir.

07

KVKK ile karşılaştırma

GDPR m.60'ın baş denetim makamı ile diğer ilgili denetim makamları arasında kurduğu ortak karar usulünün KVKK'da doğrudan karşılığı bulunmaz. KVKK, Kişisel Verileri Koruma Kurumunu tek ulusal denetim yapısı olarak kurmuş ve Kurumun karar organını Kişisel Verileri Koruma Kurulu olarak belirlemiştir.1 Bu nedenle KVKK kapsamındaki bir şikayette farklı ulusal denetim makamlarının aynı taslak karar üzerinde uzlaşması veya birbirine itiraz etmesi söz konusu değildir.

KVKK m.13-15'te ilgili kişinin önce veri sorumlusuna başvurması, ardından şartları varsa Kurula şikayette bulunması ve Kurulun şikayet üzerine ya da resen inceleme yapması düzenlenmiştir.2 Şikayet usulünde veri sorumlusu, ilgili kişi ve Kurul arasında farklı aşamalar bulunsa da bu yapı GDPR m.60'taki baş denetim makamı ile ilgili makamlar arasındaki yetki paylaşımıyla aynı değildir.

§ Tüzük Metni
Official Journal text EUR-Lex

1. The lead supervisory authority shall cooperate with the other supervisory authorities concerned in accordance with this Article in an endeavour to reach consensus. The lead supervisory authority and the supervisory authorities concerned shall exchange all relevant information with each other.

2. The lead supervisory authority may request at any time other supervisory authorities concerned to provide mutual assistance pursuant to Article 61 and may conduct joint operations pursuant to Article 62, in particular for carrying out investigations or for monitoring the implementation of a measure concerning a controller or processor established in another Member State.

3. The lead supervisory authority shall, without delay, communicate the relevant information on the matter to the other supervisory authorities concerned. It shall without delay submit a draft decision to the other supervisory authorities concerned for their opinion and take due account of their views.

4. Where any of the other supervisory authorities concerned within a period of four weeks after having been consulted in accordance with paragraph 3 of this Article, expresses a relevant and reasoned objection to the draft decision, the lead supervisory authority shall, if it does not follow the relevant and reasoned objection or is of the opinion that the objection is not relevant or reasoned, submit the matter to the consistency mechanism referred to in Article 63.

5. Where the lead supervisory authority intends to follow the relevant and reasoned objection made, it shall submit to the other supervisory authorities concerned a revised draft decision for their opinion. That revised draft decision shall be subject to the procedure referred to in paragraph 4 within a period of two weeks.

6. Where none of the other supervisory authorities concerned has objected to the draft decision submitted by the lead supervisory authority within the period referred to in paragraphs 4 and 5, the lead supervisory authority and the supervisory authorities concerned shall be deemed to be in agreement with that draft decision and shall be bound by it.

7. The lead supervisory authority shall adopt and notify the decision to the main establishment or single establishment of the controller or processor, as the case may be and inform the other supervisory authorities concerned and the Board of the decision in question, including a summary of the relevant facts and grounds. The supervisory authority with which a complaint has been lodged shall inform the complainant on the decision.

8. By derogation from paragraph 7, where a complaint is dismissed or rejected, the supervisory authority with which the complaint was lodged shall adopt the decision and notify it to the complainant and shall inform the controller thereof.

9. Where the lead supervisory authority and the supervisory authorities concerned agree to dismiss or reject parts of a complaint and to act on other parts of that complaint, a separate decision shall be adopted for each of those parts of the matter. The lead supervisory authority shall adopt the decision for the part concerning actions in relation to the controller, shall notify it to the main establishment or single establishment of the controller or processor on the territory of its Member State and shall inform the complainant thereof, while the supervisory authority of the complainant shall adopt the decision for the part concerning dismissal or rejection of that complaint, and shall notify it to that complainant and shall inform the controller or processor thereof.

10. After being notified of the decision of the lead supervisory authority pursuant to paragraphs 7 and 9, the controller or processor shall take the necessary measures to ensure compliance with the decision as regards processing activities in the context of all its establishments in the Union. The controller or processor shall notify the measures taken for complying with the decision to the lead supervisory authority, which shall inform the other supervisory authorities concerned.

11. Where, in exceptional circumstances, a supervisory authority concerned has reasons to consider that there is an urgent need to act in order to protect the interests of data subjects, the urgency procedure referred to in Article 66 shall apply.

12. The lead supervisory authority and the other supervisory authorities concerned shall supply the information required under this Article to each other by electronic means, using a standardised format.

§ İlgili Dibaceler GDPR · 5
Official Journal text EUR-Lex
Recital 124

Where the processing of personal data takes place in the context of the activities of an establishment of a controller or a processor in the Union and the controller or processor is established in more than one Member State, or where processing taking place in the context of the activities of a single establishment of a controller or processor in the Union substantially affects or is likely to substantially affect data subjects in more than one Member State, the supervisory authority for the main establishment of the controller or processor or for the single establishment of the controller or processor should act as lead authority. It should cooperate with the other authorities concerned, because the controller or processor has an establishment on the territory of their Member State, because data subjects residing on their territory are substantially affected, or because a complaint has been lodged with them. Also where a data subject not residing in that Member State has lodged a complaint, the supervisory authority with which such complaint has been lodged should also be a supervisory authority concerned. Within its tasks to issue guidelines on any question covering the application of this Regulation, the Board should be able to issue guidelines in particular on the criteria to be taken into account in order to ascertain whether the processing in question substantially affects data subjects in more than one Member State and on what constitutes a relevant and reasoned objection.

Recital 125

The lead authority should be competent to adopt binding decisions regarding measures applying the powers conferred on it in accordance with this Regulation. In its capacity as lead authority, the supervisory authority should closely involve and coordinate the supervisory authorities concerned in the decision-making process. Where the decision is to reject the complaint by the data subject in whole or in part, that decision should be adopted by the supervisory authority with which the complaint has been lodged.

Recital 126

The decision should be agreed jointly by the lead supervisory authority and the supervisory authorities concerned and should be directed towards the main or single establishment of the controller or processor and be binding on the controller and processor. The controller or processor should take the necessary measures to ensure compliance with this Regulation and the implementation of the decision notified by the lead supervisory authority to the main establishment of the controller or processor as regards the processing activities in the Union.

Recital 130

Where the supervisory authority with which the complaint has been lodged is not the lead supervisory authority, the lead supervisory authority should closely cooperate with the supervisory authority with which the complaint has been lodged in accordance with the provisions on cooperation and consistency laid down in this Regulation. In such cases, the lead supervisory authority should, when taking measures intended to produce legal effects, including the imposition of administrative fines, take utmost account of the view of the supervisory authority with which the complaint has been lodged and which should remain competent to carry out any investigation on the territory of its own Member State in liaison with the competent supervisory authority.

Recital 131

Where another supervisory authority should act as a lead supervisory authority for the processing activities of the controller or processor but the concrete subject matter of a complaint or the possible infringement concerns only processing activities of the controller or processor in the Member State where the complaint has been lodged or the possible infringement detected and the matter does not substantially affect or is not likely to substantially affect data subjects in other Member States, the supervisory authority receiving a complaint or detecting or being informed otherwise of situations that entail possible infringements of this Regulation should seek an amicable settlement with the controller and, if this proves unsuccessful, exercise its full range of powers. This should include: specific processing carried out in the territory of the Member State of the supervisory authority or with regard to data subjects on the territory of that Member State; processing that is carried out in the context of an offer of goods or services specifically aimed at data subjects in the territory of the Member State of the supervisory authority; or processing that has to be assessed taking into account relevant legal obligations under Member State law.

01

Tek durak mekanizmasında ortak karar

GDPR m.60, sınır ötesi işleme hakkında karar verecek baş denetim makamının diğer ilgili denetim makamlarıyla nasıl çalışacağını düzenler. Baş denetim makamı süreci yürütür, fakat ilgili makamların üzerinde yer alan bir üst makam değildir. İlgili makamlar bilgi edinme, görüş bildirme ve maddede öngörülen şartlarla karara itiraz etme yetkilerini korur.1

Maddenin birinci fıkrası, makamların uzlaşmaya varmak amacıyla çaba göstermelerini ve birbirlerine gerekli bilgileri iletmelerini öngörür. Karar taslağına yöneltilen ilgili ve gerekçeli itiraz çözülemezse m.60/4 ile m.65'teki uyuşmazlık çözümü yolu işletilecektir.2 Bu düzenleme, baş denetim makamına tek başına karar verme serbestisi tanımaz. Bununla birlikte uzlaşma yükümlülüğü, her görüş ayrılığının mutlaka anlaşmayla sonuçlanacağı anlamına da gelmez.

Tek durak mekanizması, sınır ötesi işleme hakkında birbiriyle çelişen ulusal kararların önlenmesine hizmet eder. Aynı zamanda şikayetin yapıldığı yerde incelenebilmesini ve ilgili kişinin kendi denetim makamıyla temasını korur.3 Bu iki yön birlikte değerlendirildiğinde m.60, yalnız yetki paylaşan bir hüküm değil, ortak kararın hazırlanmasına ilişkin bir usul hükmüdür.

02

Bilgi paylaşımı ve karar taslağı

Baş denetim makamı, ilgili denetim makamlarından karşılıklı yardım veya ortak operasyon talep edebilir. Talebin niteliğine göre m.61 veya m.62'deki özel usul uygulanacaktır.1 Bu imkan, makamlar arasındaki olağan bilgi paylaşımının yerini almaz.

Baş denetim makamı, konuyu inceledikten sonra karar taslağını gecikmeksizin diğer ilgili makamlara sunmalıdır. Karar taslağı, makamların görüş bildirebileceği kadar açık olmalı ve dosyanın değerlendirilmesi için gerekli bilgileri taşımalıdır. Baş denetim makamı, ilgili makamların görüşlerini karar taslağı hazırlanırken ve gerektiğinde taslak yeniden düzenlenirken gereği gibi dikkate alacaktır.2 İlgili makamların sürece katılması, taslak tamamlandıktan sonra yapılan şekli bir bildirimden ibaret değildir.

Görüşleri dikkate alma yükümlülüğü, baş denetim makamını her görüşe katılmaya mecbur bırakmaz. Görüş ayrılığı m.60/4'teki nitelikleri taşıyan bir itiraza dönüşürse baş denetim makamı ya itirazı kabul ederek yeni bir taslak sunacak ya da konuyu Avrupa Veri Koruma Kuruluna götürecektir.3

03

İlgili ve gerekçeli itiraz

İlgili denetim makamı, karar taslağının kendisine sunulmasından itibaren dört hafta içinde itiraz edebilir. Her görüş ayrılığı bu sonucu doğurmaz. İtirazın karar taslağına yönelmesi ve GDPR m.4/24 anlamında ilgili ve gerekçeli olması gerekir. Buna göre itiraz, somut olayda Tüzüğün ihlal edilip edilmediği veya veri sorumlusu ya da veri işleyene yönelik öngörülen tedbirin Tüzüğe uygun olup olmadığı konularından birine dayanmalı ve taslağın ilgili kişilerin temel hak ve özgürlükleri ya da Birlik içinde kişisel verilerin serbest dolaşımı bakımından taşıdığı riskin önemini açıkça göstermelidir.1

Baş denetim makamı itirazı kabul ederse yeni karar taslağını ilgili makamlara sunar. Yeni taslağa itiraz süresi iki haftadır.2 Böylece ilk taslak için tanınan dört haftalık süre, yeniden düzenlenen taslak bakımından kısaltılmıştır.

Baş denetim makamı itirazı kabul etmezse veya itirazı ilgili ve gerekçeli bulmazsa konuyu m.65'teki uyuşmazlık çözümü için Avrupa Veri Koruma Kuruluna iletmelidir. Baş denetim makamı, bu halde itirazı yalnız kendi kararıyla etkisiz bırakarak nihai karar veremez.3

04

Nihai kararın kabulü ve bildirimi

İlgili denetim makamları karar taslağına süresinde itiraz etmezse taslağı kabul etmiş sayılır ve karar onları bağlar. Baş denetim makamı, veri sorumlusu veya veri işleyenin ana kuruluşuna ya da tek kuruluşuna yönelik kararı kabul eder ve bildirir. Diğer ilgili makamlar ile Avrupa Veri Koruma Kurulu da bilgilendirilir.1

Şikayetin reddedildiği veya kabul edilemez bulunduğu hallerde kararı, şikayetin yapıldığı denetim makamı kabul eder ve ilgili kişiye bildirir. Veri sorumlusu da karardan haberdar edilir. Şikayetin kısmen reddedildiği, kısmen de veri sorumlusu veya veri işleyene yönelik işlem yapılmasını gerektirdiği hallerde ise iki ayrı karar verilir.2 Bu ayrım, ilgili kişinin kendi makamı önünde hukuki korunmasını sürdürürken işletmeye yönelen kararın baş denetim makamı tarafından alınmasını sağlar.

Kararı hangi makamın kabul edeceği, kararın maddi sonucuna göre belirlenir. Şikayetin reddi ile veri sorumlusu veya veri işleyene yükümlülük getiren kısım aynı makam adına tek kararda birleştirilemez.3

05

Kararın sınır ötesi etkisi

Veri sorumlusu veya veri işleyen, kendisine GDPR m.60/7 veya m.60/9 uyarınca bildirilen karara m.60/10 gereğince uymalı ve gerekli tedbirleri Birlik içindeki bütün kuruluşlarında ilgili işleme faaliyeti bakımından uygulamalıdır.1 Bu yükümlülük, kararı yalnız ana kuruluşun bulunduğu üye devlette sonuç doğuran bir işlem olmaktan çıkarır.

Kararın kapsamı, hakkında inceleme yapılan işleme faaliyetiyle sınırlıdır. Aynı işletme grubunun başka bir işleme faaliyeti, yalnız aynı veri sorumlusunca yürütüldüğü için kendiliğinden kararın kapsamına girmez.2 Hangi kuruluşların ve işlemelerin karardan etkilendiği, kararın gerekçesi ve hüküm kısmı birlikte değerlendirilerek belirlenecektir.

Veri sorumlusu veya veri işleyen, karara uymak için aldığı önlemleri baş denetim makamına bildirmelidir. Baş denetim makamı da bu bilgiyi diğer ilgili denetim makamlarına iletir.3 Böylece kararın sınır ötesi uygulanması yalnız işletmenin beyanına bırakılmamış, makamlar arasındaki bilgi akışına bağlanmıştır.

06

Acil usul ve elektronik iletişim

Olağan iş birliği usulü, ilgili kişilerin menfaatlerini korumak için gecikmeksizin harekete geçilmesi gereken istisnai halleri ortadan kaldırmaz. GDPR m.60/11, bu durumda m.66'daki acil usulün uygulanmasına imkan tanır.1 Acil usule başvurulması için yalnız makamlar arasında görüş ayrılığı bulunması yeterli değildir. GDPR m.66'da aranan istisnai şartlar ayrıca gerçekleşmelidir.

Makamlar m.60 kapsamında birbirlerine elektronik yollarla ve standartlaştırılmış bir format kullanarak bilgi verir. Bu şekil, karar taslaklarının, itirazların ve diğer usul belgelerinin bütün ilgili makamlara aynı düzen içinde iletilmesine hizmet eder.2 Elektronik iletişim kuralı, uzlaşma çabasını veya ilgili makamın görüşünün gereği gibi değerlendirilmesini ikame eden bir şekil şartı değildir.

07

KVKK ile karşılaştırma

GDPR m.60'ın baş denetim makamı ile diğer ilgili denetim makamları arasında kurduğu ortak karar usulünün KVKK'da doğrudan karşılığı bulunmaz. KVKK, Kişisel Verileri Koruma Kurumunu tek ulusal denetim yapısı olarak kurmuş ve Kurumun karar organını Kişisel Verileri Koruma Kurulu olarak belirlemiştir.1 Bu nedenle KVKK kapsamındaki bir şikayette farklı ulusal denetim makamlarının aynı taslak karar üzerinde uzlaşması veya birbirine itiraz etmesi söz konusu değildir.

KVKK m.13-15'te ilgili kişinin önce veri sorumlusuna başvurması, ardından şartları varsa Kurula şikayette bulunması ve Kurulun şikayet üzerine ya da resen inceleme yapması düzenlenmiştir.2 Şikayet usulünde veri sorumlusu, ilgili kişi ve Kurul arasında farklı aşamalar bulunsa da bu yapı GDPR m.60'taki baş denetim makamı ile ilgili makamlar arasındaki yetki paylaşımıyla aynı değildir.