|
Banking Law No. 5411BRSA
|
Banks and other institutions within the Law’s scope |
Internal control, risk management, internal audit systems, consolidated oversight and governance responsibilities. |
|
Source
|
|
Regulation on Information Systems and Electronic Banking ServicesBRSA
|
Banks operating in Turkey |
Information-systems governance, risk controls, continuity, third-party services, security events, monitoring and electronic-banking resilience. |
|
Source
|
|
Communique on Corporate Governance II-17.1CMB
|
Publicly held companies within the Communique’s applicable scope |
Board and committee governance, internal control and audit oversight, risk management, disclosure and accountable follow-up. |
|
Source
|
|
Personal Data Protection Law No. 6698KVKK
|
Data controllers and processors within scope |
Data-security measures, controller accountability, internal audits and notification when data is obtained unlawfully. |
|
Source
|
|
Board Decision No. 2019/10 on Breach NotificationKVKK
|
Data controllers, including relevant overseas controllers |
72-hour Board notification, affected-person communication, breach documentation, response plans and accountable ownership. |
|
Source
|