KVKK ve Kripto Veri Güvenliği
Data Privacy & On-Chain Security

The Importance of Personal Data in the Crypto Ecosystem

Phishing Attacks

Recently, investors have frequently been exposed to crypto-focused cyber phishing attacks. Phishing is a dangerous method that occurs with the illegal seizure of personal data and is the most preferred by cyber scammers.

Scammers use complex techniques such as Clone Phishing, Pharming, Phishing, Ice Phishing and Evil Twin. Some of these attacks are based on social engineering manipulations, while others are carried out directly with malware.

A Typical Phishing Case:Investors are directed to fake (clone) sites with fake e-mails disguised as coming from the website of the exchanges they actively use. The username, password, 2FA codes or wallet secret keys entered here fall into the hands of cyber pirates. Pirates empty all funds in digital wallets with a single transaction without the consent of the investor. This situation, together with the data security breach, directly leads to financial destruction.

Risks of Unconscious Application Usage

Victimization rates can be reduced by creating high awareness of personal data breaches.

⚠️ Sectoral Warning // Data Breach News:Global news that the Pi Network project, which allows crypto asset mining over the phone, caused a massive 17 GB personal data leak and identity theft vulnerability, clearly proves how much of a threat users are under in the mobile ecosystem.
LAW NO. 6698

Personal Data Protection Law Art. 18

Legal sanctions applied to data controller companies in case of violation of data security and information obligations (Misdemeanors):

a)

Violation of the Obligation to Inform

Those who do not fulfill the obligation to inform stipulated in Article 10 are given an administrative fine from 5,000 Turkish liras to 100,000 Turkish liras.

b)

Violation of Data Security Obligation

Those who do not fulfill the technical and administrative obligations regarding data security stipulated in Article 12 are given an administrative fine from 15,000 Turkish liras to 1,000,000 Turkish liras.

c)

Contradiction to Board Decisions

Those who do not fulfill the decisions taken by the Board in accordance with Article 15 are given an administrative fine from 25,000 Turkish liras to 1,000,000 Turkish liras.

d)

Data Controllers Registry (VERBIS)

Those who act contrary to the obligation to register and notify the Data Controllers Registry stipulated in Article 16 are given an administrative fine from 20,000 Turkish liras to 1,000,000 Turkish liras.

TURKISH PENAL CODE LEGISLATION

Crimes Committed Against Personal Data

Imprisonment sanctions envisaged directly for real person data controllers and perpetrators in unlawful data processing activities:

Article 135

Recording of Personal Data

A person who unlawfully records personal data is sentenced to imprisonment from one year to three years. If the data belongs to sexual life, health, religious/political views or racial origin, the penalty is increased by half.

Article 136

Unlawfully Giving/Seizing Data

A person who unlawfully gives, disseminates or seizes personal data to another person is sentenced to imprisonment from two years to four years.

Article 137

Qualified Cases

If the crimes are committed by a public official by abusing the authority given by the duty or by taking advantage of the convenience provided by a certain profession and art, the penalty is increased by half.

Article 138

Not Destroying Data

Those who are obliged to destroy data within the system despite the passage of the periods determined by the laws are given a prison sentence from one year to two years if they do not fulfill their duties.

🏢

Legal Responsibility of Crypto Exchanges

Crypto asset service providers, just like banks, are under an aggravated objective duty of care. Platforms are obliged to bring system security into compliance with the latest known technological developments and establish mechanisms to prevent cyber attackers from entering. In this regard, exchanges are considered fully responsible even for their slight faults.

In cases of perpetrator violation, the obligation to compensate the material damage of the victim investor arises in accordance with TCO Art. 49 and Art. 112 due to the exchange's violation of the contract by acting contrary to the duty of care and protection. Exchanges are obliged to prove that they are not responsible.

🔥 NEW REFORM LAW NO. 7518 (TCO Art. 71):With the latest amendments to the law numbered 6362, crypto asset service providers (exchanges) directly are held legally responsible for crypto asset losses experienced due to cyber attacks or faulty behaviors of personnel on the basis of danger liability.
👤

Original Responsibility of the Investor

In order to maintain a safe transaction environment, individual investors are also obliged to take the maximum security measures that fall upon them in accordance with the rule of honesty. Vulnerabilities arising from user error can alleviate or completely eliminate the responsibility of the exchange.

Investor Security Protocol:
  • Exchange passwords should be chosen complexly and changed at regular intervals.
  • Suspicious e-mails and links from unknown sources should never be opened.
  • Crypto transfer transactions should never be made over public internet cafes or unencrypted common Wi-Fi networks that may create security vulnerabilities.
TCO ARTICLE 52 // CONTRIBUTORY NEGLIGENCEIf the investor has gross negligence in protecting their own account security, this situation is considered as "contributory negligence" (joint fault) by the judicial authorities and causes a reduction in the compensation amount to be paid by the platform at the rate of fault.
QUICK CONTACT

To Start Your Legal Process
Contact Us

Time is crucial in crypto asset cases and cybersecurity breaches. We are aware of the urgency of your situation. You can submit the form below completely for preliminary evaluation.

📞
24/7 Emergency Support+90 536 265 19 23