Common Problems

Common Problems

  • What are the privacy laws and regulations in Türkiye?

    Personal Data Protection Law (PDPL), enacted on March 24, 2016, was amended on February 16, 2024 by Amendments to the Criminal Procedure Law and Certain Laws and the Decree Law No. 659. The purpose of this law is to ensure the privacy of individuals when their personal data is processed to protect entities and natural persons processing personal data, and to specify obligations, principles, and procedures defining how personal data or legal persons are to be processed.

    Regulation on the Erasure, Destruction, or Anonymization of Personal Data, enacted on October 28, 2017, stipulates the procedures and principles to be followed by data controllers regarding the erasure, destruction, and anonymization of personal data processed in whole or in part by the data controller's data recording system by automatic or non-automatic means, in accordance with Article 7 of the PDPL.

    Communique on Procedures and Principles for Compliance with the Obligation to Inform, enacted on March 10, 2018, stipulates the procedures and principles to be followed by data controllers within the scope of the obligation to inform the data subjects of data processing activities in accordance with Article 10 of the PDPL.

    The Decision of Data Protection Board, dated January 24, 2019, No. 2019/10 about Procedures and Principles of Personal Data Breach Notification: Issued on January 24, 2019, this resolution provides guidelines for reporting data breaches under Article 12 of the Personal Data Protection Law (PDPL). It outlines the procedures and principles that data controllers and processors should follow in the event of a data breach.

    ● Regulations on the Registration of Data Controllers, enacted on January 1, 2018, stipulates the procedures and principles for registration under Articles 16 and 22 of the PDPL.

    ● Regulations on the Procedures and Principles for Transferring Personal Data Abroad, enacted on July 10, 2024, stipulates the procedures and principles for transferring personal data abroad under Article 9 of the PDPL.

  • What role does Huawei Cloud play regarding the privacy laws and regulations in Türkiye?

    Personal data processed by Huawei Cloud includes account data and customer data.

    ● Huawei Cloud as a processor of customer data

    The customer fully owns and controls their data. Huawei Cloud services are only used for storage and processing. Customers deliver instructions via function configurations or APIs provided by the cloud services, and Huawei Cloud processes the data according to the instructions. When the customer acts as a data controller, Huawei Cloud functions as the data processor. If the customer is functioning as a data processor, Huawei Cloud acts as a sub-processor of customer data.

    ● Huawei Cloud as the controller of account data

    Huawei Cloud determines the data collection method and processing purpose for account data submitted by customers during interactions. This makes Huawei Cloud the data controller. Huawei Cloud will also be responsible for the security and privacy protection of personal data based on the privacy laws of Türkiye, ensure that the collection, processing, storage, and transmission of personal data comply with laws and regulations, and respond to personal data subjects' requests.



  • How does Huawei Cloud comply with privacy laws and regulations in Türkiye?

    ● Huawei Cloud as a data processor

    Huawei Cloud has released the Data Processing Appendix to clarify the data processing activities and obligations of Huawei Cloud as a data (sub-) processor for customer data.

    ● Huawei Cloud as a data controller

    Cyber security and privacy protection are Huawei Cloud's top priorities. Huawei Cloud integrates these principles into its services, ensuring stable, reliable, secure, trustworthy, and sustainable offerings while also safeguarding customer privacy.

    Huawei Cloud prioritizes privacy protection and takes responsibility for complying with global privacy protection laws and regulations. Huawei Cloud has established a professional privacy protection team, established and optimized processes, actively developed new technologies, and continuously built privacy protection capabilities to achieve its privacy protection objectives: comply with service boundaries, protect customers' personal data, and help customers implement privacy protection.

    For details, see Huawei Cloud Türkiye Privacy Compliance Guide.

  • As a customer of Huawei Cloud, what laws and regulations should I comply with?

    You have the right to choose how to use cloud products and services you purchase. This includes how you store and process content data that may contain personal data. Therefore, you are responsible for the security and compliance of the content data. You are responsible for content security. Your specific responsibilities are as follows:

    Content data protection: You must correctly and completely identify personal data in the cloud, and develop policies and measures to maintain personal data security and protect privacy. Specific measures include configuring security based on service and privacy protection requirements, such as operating system settings, network configurations, security protection, and database encryption policies, and proper access control policies and password policies.

    Responses to the rights of data subjects: You must protect the rights of data subjects and respond to their requests. If a personal data breach occurs, you must take appropriate actions in compliance with all relevant laws and regulations, such as notifying regulatory authorities, notifying data subjects, and taking mitigation measures.

  • How does Huawei Cloud help me comply with the requirements of Türkiye privacy laws and regulations?

    Huawei Cloud understands your privacy requirements. We integrate our privacy protection practices and technical capabilities into Huawei Cloud products and services to help you comply with the laws and regulations. Huawei Cloud provides you with a large range of products and services such as networking products, database products, security products, and solutions for management and deployment. Data protection, data deletion, network isolation, rights management, and other functions implemented in Huawei Cloud products can help you ensure the privacy and security of content data.

    For details, see Huawei Cloud Türkiye Privacy Compliance Guide.

Compliance Resources

Documents related to compliance with laws and regulations of Türkiye. More documents are available from Resource Center.

  • Huawei Cloud Türkiye Privacy Compliance Instruction

    This white paper shares Huawei's experience and best practices in privacy protection and describes how Huawei Cloud will help you comply with requirements of Türkiye's PDPL.

  • HUAWEI CLOUD User Guide to Financial & Government Service Regulations & Guidelines in Türkiye

    This document describes how Huawei Cloud will help you meet the supervision requirements of Digital Transformation Office of the Presidency in Türkiye and BRSA when using Huawei Cloud, and shows Huawei Cloud's compliance with regulations in Türkiye.

  • HUAWEI CLOUD Compliance with CSA CCM

    Introduce the cloud security measures taken by HUAWEI CLOUD based on CCM and CAIQ which are published by Cloud Security Alliance.

  • Practical Guide for PCI DSS

    Based on the main content of PCI DSS, the whitepaper introduces the data protection measures took by HUAWEI CLOUD and how HUAWEI CLOUD's products and services help customers respond the requirements of the certification.

  • HUAWEI CLOUD Compliance with ISO/IEC 27001

    Based on the main content of ISO/IEC 27001, the whitepaper introduces HUAWEI CLOUD’s overall information security policies and specific control measures and how HUAWEI CLOUD's products and services help customers respond the requirements of the certification.