One emphasis stands out in the compliance guidance published by Turkey's data protection authority: in a breach, responsibility falls not only on whoever acted but on whoever failed to take the necessary measures.
01. Where Responsibility Sits
The data controller is the organisation itself, not a department or an employee. An employee's mistake doesn't relieve the organisation; instead the question becomes whether the necessary technical and administrative measures were in place.
02. A Protocol Alone Isn't Enough
Data sharing protocols between institutions do not on their own constitute a legal basis. The statutory ground for sharing has to be shown separately. This is a frequent gap in supplier and partner agreements.
03. The Measures List
Access authorisation, logging, encryption, backup, security awareness training and an incident response plan. Their existence matters, and so does a record showing they are operated regularly.
04. A Culture of Evidence
An inspection asks not for the practice but for its record. If the annual permission review happened, there should be minutes; if training was delivered, an attendance list. Good practice without records is treated as absent.
05. The Supplier Chain
Suppliers acting as data processors must be shown to apply the same measures. Writing an audit right into the contract and exercising it at least annually is the expected behaviour.
06. Where to Start
A data inventory, a permission matrix and a retention period table. Without those three documents, every other measure hangs in the air.