
The Importance of Personal Data in the Crypto Ecosystem
Phishing Attacks
Recently, investors have frequently been exposed to crypto-focused cyber phishing attacks. Phishing is a dangerous method that occurs with the illegal seizure of personal data and is the most preferred by cyber scammers.
Scammers use complex techniques such as Clone Phishing, Pharming, Phishing, Ice Phishing and Evil Twin. Some of these attacks are based on social engineering manipulations, while others are carried out directly with malware.
Risks of Unconscious Application Usage
Victimization rates can be reduced by creating high awareness of personal data breaches.
Personal Data Protection Law Art. 18
Legal sanctions applied to data controller companies in case of violation of data security and information obligations (Misdemeanors):
Violation of the Obligation to Inform
Those who do not fulfill the obligation to inform stipulated in Article 10 are given an administrative fine from 5,000 Turkish liras to 100,000 Turkish liras.
Violation of Data Security Obligation
Those who do not fulfill the technical and administrative obligations regarding data security stipulated in Article 12 are given an administrative fine from 15,000 Turkish liras to 1,000,000 Turkish liras.
Contradiction to Board Decisions
Those who do not fulfill the decisions taken by the Board in accordance with Article 15 are given an administrative fine from 25,000 Turkish liras to 1,000,000 Turkish liras.
Data Controllers Registry (VERBIS)
Those who act contrary to the obligation to register and notify the Data Controllers Registry stipulated in Article 16 are given an administrative fine from 20,000 Turkish liras to 1,000,000 Turkish liras.
Crimes Committed Against Personal Data
Imprisonment sanctions envisaged directly for real person data controllers and perpetrators in unlawful data processing activities:
Recording of Personal Data
A person who unlawfully records personal data is sentenced to imprisonment from one year to three years. If the data belongs to sexual life, health, religious/political views or racial origin, the penalty is increased by half.
Unlawfully Giving/Seizing Data
A person who unlawfully gives, disseminates or seizes personal data to another person is sentenced to imprisonment from two years to four years.
Qualified Cases
If the crimes are committed by a public official by abusing the authority given by the duty or by taking advantage of the convenience provided by a certain profession and art, the penalty is increased by half.
Not Destroying Data
Those who are obliged to destroy data within the system despite the passage of the periods determined by the laws are given a prison sentence from one year to two years if they do not fulfill their duties.
Legal Responsibility of Crypto Exchanges
Crypto asset service providers, just like banks, are under an aggravated objective duty of care. Platforms are obliged to bring system security into compliance with the latest known technological developments and establish mechanisms to prevent cyber attackers from entering. In this regard, exchanges are considered fully responsible even for their slight faults.
In cases of perpetrator violation, the obligation to compensate the material damage of the victim investor arises in accordance with TCO Art. 49 and Art. 112 due to the exchange's violation of the contract by acting contrary to the duty of care and protection. Exchanges are obliged to prove that they are not responsible.
Original Responsibility of the Investor
In order to maintain a safe transaction environment, individual investors are also obliged to take the maximum security measures that fall upon them in accordance with the rule of honesty. Vulnerabilities arising from user error can alleviate or completely eliminate the responsibility of the exchange.
- Exchange passwords should be chosen complexly and changed at regular intervals.
- Suspicious e-mails and links from unknown sources should never be opened.
- Crypto transfer transactions should never be made over public internet cafes or unencrypted common Wi-Fi networks that may create security vulnerabilities.
