Public Announcement on Technical and Administrative Measures Recommended to be Taken by Data Controllers Regarding User Security
In the announcement made by the Board, by reminding the obligations of data controllers within the scope of preventing unlawful processing of personal data regulated in Article 12/1 of the Personal Data Protection Law No. 6698 (‘KVKK’); Considering that recently, user information (username and password) on the websites of data controllers have been seized by malicious persons and marketed for an economic value, the importance of technical and administrative measures such as ‘using the same username and password on different platforms, not changing the password at certain time intervals, not using login methods such as two-stage authentication, etc.’ has been emphasised. The importance of technical and administrative precaution deficiencies such as ‘using the same username and password on different platforms, not changing passwords at certain time intervals, not using login methods such as two-step authentication etc.’ were emphasised.
Accordingly, the Board shared its recommendations regarding the administrative and technical measures that can be taken to prevent possible data breaches and to minimise the negative consequences that data subjects may face in the event of a breach. These recommendations are as follows:
- Using a two-stage authentication system and offering this as an alternative to users when they apply for membership,
- In case users log in from a different device, the login information is sent to the relevant persons via e-mail, SMS, etc,
- Limiting the number of failed login attempts from the IP address,
- Ensuring that the relevant persons change their passwords at certain intervals,
- Preventing new passwords from being the same as at least the last three passwords and using verification processes (CAPTCHA, four operations…),
- In the event that third-party software or services are used to access the systems of data controllers, security updates of these software and services are regularly performed and necessary controls are carried out
- Ensuring that passwords with a minimum length of 10 characters, numbers, upper and lower case letters and special characters are determined together
Considering that the measures in the announcement made by the Board are presented as ‘recommendations’, we are of the opinion that in the face of a similar breach, compliance with the recommendations in the announcement will not be sought one-to-one, but the ‘obligations regarding data security’ regulation for data controllers in Art. 12 of the LPPD will be considered as a subtitle.
In this case, it is important for data controllers to consider the recommendations in the announcement.
