Offense of Unlawful Disclosure, Dissemination, or Acquisition of Personal Data

The protection of personal data is a fundamental element of individual liberties in contemporary legal systems. In Turkey, Article 136 of the Turkish Penal Code (TPC) regulates the offense of unlawful disclosure, dissemination, or acquisition of personal data. For the offense to be constituted, the data must qualify as personal data and be unlawfully disclosed. Different considerations may apply in cases involving public interest.

The protection of personal data is considered one of the fundamental elements of individual liberties in contemporary legal systems. Especially today, with technological advancements threatening individuals' private lives, ensuring data security is imperative not only at an individual level but also for the preservation of social peace. In Turkey, this protection mechanism is regulated under Article 136 of the Turkish Penal Code, which addresses the offense of unlawful disclosure, dissemination, or acquisition of personal data. This regulation constitutes a significant penal norm aimed at safeguarding an individual's right to privacy.

Article 136 of the Turkish Penal Code not only penalizes acts that violate the privacy of private life but also protects an individual's presence within information systems. For the offense to be constituted, personal data must be intentionally and unlawfully transferred, disclosed, or acquired by third parties. At this juncture, the concept of personal data is defined as any information pertaining to an identified or identifiable natural person, and from a social sciences perspective, it is regarded as the digital manifestation of an individual's social identity.

That is to say, the sharing of any information may not always constitute an offense. In this context, the question arises: Can all forms of data sharing be penalized under Article 136 of the TPC? Particularly in cases where there is a public interest, the disclosure of certain information may be deemed lawful. Consequently, for the offense to be constituted, it is imperative that the personal data has been unlawfully disclosed and that the data qualifies as personal data.

The offense of unlawful disclosure of personal data is not subject to a complaint. That is, the Public Prosecutor's Office may initiate an investigation *ex officio* without requiring a complaint from the victim. Notably, the victim's subsequent consent does not negate the commission of the offense, as the offense is completed the moment the data is unlawfully disclosed to third parties. This point is frequently emphasized in defenses presented by criminal defense attorneys. Furthermore, this offense is not among those subject to conciliation. This is because conciliation provisions are stipulated in the Turkish Penal Code and the Code of Criminal Procedure only for specific offenses, and the offense of personal data breach is not listed among offenses amenable to conciliation, due to both its public order implications and its impact on social trust. Consequently, even if conciliation is reached between the parties during the investigation and prosecution of this offense, the judicial proceedings continue *ex officio*, and the court renders a judgment based on the evidentiary record and legal assessment.

The statute of limitations for prosecution for this offense is 8 years, in accordance with Article 66/1-e of the TPC. This means that if an investigation or prosecution is not initiated within 8 years from the date the offense was committed, the criminal case will be dismissed due to the statute of limitations. Regarding the statute of limitations for enforcement of sentence, a 10-year period is stipulated under Article 68 of the TPC for final imprisonment sentences of 3 years or less. Consequently, these limitation periods directly affect both the initiation of public prosecutions and the enforcement of conviction judgments.

Based on actions that interrupt or suspend the limitation period, the statute of limitations for prosecution recommences for its full duration from the moment it was interrupted. However, in practice, the incorrect identification of actions that interrupt the limitation period can prejudice the right to a fair trial. Particularly in the case law of the Regional Courts of Appeal (Criminal Divisions) and the Court of Cassation, it is emphasized that limitation provisions must be meticulously evaluated in personal data breach cases.

While investigations into the offense of unlawful disclosure of personal data are conducted *ex officio* without the need for a complaint, it should be noted that the statute of limitations for prosecution is 8 years, and the statute of limitations for enforcement of sentence is 10 years. During this process, examinations and defenses conducted by a criminal defense attorney are of great importance for the proper management of limitation risks and the prevention of loss of rights. All these aspects demonstrate that data security holds vital significance not only as an individual right but also for social peace.

The perpetrator's having a specific motive is not an element of the offense. However, in practice, it is frequently examined whether the perpetrator acted with aims such as gaining benefit, causing harm, or creating public outrage. The misuse of information is directly linked to power relations and control mechanisms over individuals. Indeed, possessing information has historically been a significant instrument for the exercise of power.

At this point, another question arises: How does the unlawful disclosure of personal data affect the social structure? Indeed, the misuse of personal data not only leads to individual grievances but also gives rise to a general atmosphere of distrust within society. When evaluated in light of the concept of social capital, this situation causes an erosion of trust that individuals place in each other and in public institutions, thereby weakening social solidarity.

The aggravating circumstances regulated in Article 137 of the TPC allow for the more severe punishment of this offense. Situations such as a public official participating in the offense by abusing their office, or the offense being committed through opportunities provided by certain professions, elevate the nature of the act to a more dangerous level. Particularly in cases of data breaches by public officials, social trust is seen to be damaged in a way that is difficult to remedy.

However, the protection aimed at ensuring data security has not been confined solely within the boundaries of criminal law. The administrative and private law regulations introduced by the Law on the Protection of Personal Data No. 6698 (LPPD) ensure a multi-dimensional protection of the right to personal data. This multi-layered protection approach guarantees an individual's rights not only through the threat of criminal penalties but also through administrative sanctions and private law liabilities.

During the criminal proceedings, determining whether personal data has been unlawfully disclosed is predominantly possible through examinations requiring expertise in technical and information technology fields. In the evaluation of evidence, adhering to the principle of legality, it is mandatory to collect both exculpatory and inculpatory evidence. It is undeniable that the defense activities undertaken by a criminal defense attorney also play a significant role in ensuring the right to a fair trial during this process.

Regarding the offense of unlawful disclosure of personal data, mitigating circumstances are evaluated within the framework of general criminal law provisions. That is, institutions such as effective remorse, discretionary mitigating circumstances (TPC Article 62), and unjust provocation (TPC Article 29), which are found in the general provisions of the Turkish Penal Code, may also be applied to this type of offense if the appropriate conditions exist. If the perpetrator demonstrates effective remorse during the investigation phase by retrieving the data to prevent its dissemination, compensating the victim's damage, or attempting to minimize public harm, this may create an opportunity for it to be considered a discretionary mitigating circumstance. Furthermore, if the perpetrator was subjected to unjust provocation for personal reasons while committing the offense, it is also possible for the judge to reduce the sentence.

However, in personal data breach offenses, the perpetrator's post-offense conduct is of particular importance. Nevertheless, even when a sentence reduction is applied, the reduction rate is kept limited, considering the nature of the offense and its societal impact. According to the approach predominantly adopted by the Criminal Divisions of the Regional Courts of Appeal and the Court of Cassation, the application of discretionary mitigation should be more cautious and well-reasoned in cases involving severe consequences arising from data dissemination or the victimization of a large number of individuals. The examination of these matters is crucial, given the courts' obligation to ensure both individual justice and social peace.

The case law of the Criminal Divisions of the Regional Courts of Appeal and the Court of Cassation states that the elements of personal data breaches must be carefully examined within the context of the specific facts of each case. However, some decisions are overturned due to insufficient examination, which highlights the importance of accurately uncovering the material truth in criminal proceedings. In particular, the clear establishment of the elements of data qualification, unlawfulness, and intent is of great importance for the administration of justice.

As explicitly emphasized in the jurisprudence of the Constitutional Court, the right to the protection of personal data is regarded as one of the fundamental guarantees of an individual's honor and dignity. That is, the unauthorized disclosure of information pertaining to an individual's identity, private life, and privacy not only causes material damages but also inflicts deep wounds on an individual's moral integrity. In this context, personal data breaches are considered a direct violation of individual personality rights, harming an individual's reputation within society.

The right to the protection of personal data, which is constitutionally guaranteed, holds vital importance not only at an individual level but also for the continuation of a democratic social order. However, if this right is violated, the resulting harm is not limited solely to the victimized individual but also permeates the general structure of society by undermining public trust. Indeed, in a society where individuals' private lives are constantly under threat, freedom of expression, freedom of association, and other fundamental rights and freedoms effectively become dysfunctional.

The European Court of Human Rights also attaches great importance to the protection of personal data within the scope of the right to respect for private life. In its jurisprudence established under Article 8 of the Convention, the Court states that data security is an inseparable part of an individual's right to respect for private life and imposes not only negative but also positive obligations on states. These positive obligations mandate that the state enact necessary legislation to ensure the protection of personal data and establish effective administrative and judicial oversight mechanisms.

At this juncture, the following point is significant: The jurisprudence of the European Court of Human Rights and the Constitutional Court ensures the direct protection against personal data breaches through individual application mechanisms. However, if domestic remedies are not exhausted or are ineffective, individuals may file an individual application with the Constitutional Court, and if a violation is identified, the state's obligation to take effective measures arises. These developments also pave the way for criminal defense attorneys to undertake an important representation and defense function in individual application processes on behalf of victims of data breaches.

The protection of personal data is essential for both the free development of an individual's personality and the healthy continuation of a democratic society. The principles and standards articulated in the jurisprudence of the Constitutional Court and the European Court of Human Rights also guide national legal practitioners, clearly demonstrating the necessity of providing effective protection against personal data breaches. In this context, the protection of personal data is not merely an individual right but also an indispensable prerequisite for establishing an environment of social peace and trust.

The offense of unlawful disclosure of personal data serves a fundamental function in protecting individuals' personality rights and the democratic social order. The integration of criminal law regulations with administrative and private law measures contributes to the effective protection of an individual's data security. At this point, obtaining professional criminal defense attorney support during both the investigation and prosecution phases is critically important for both the accurate ascertainment of the material truth and the prevention of rights violations. Data security is no longer merely a technical issue; it has become an inseparable part of protecting human dignity and freedoms.