Eryürekli | Communiqués Recently Published by Capital Markets Board on Information Systems Management and Independent Audit of Information Systems

Capital Markets General Legal Alert

Communiqués Recently Published by Capital Markets Board on Information Systems Management and Independent Audit of Information Systems

Eryürekli | Communiqués Recently Published by Capital Markets Board on Information Systems Management and Independent Audit of Information Systems

Download PDF

Share

  • Yazdır

This legal alert seeks to outline the rules and principles regarding information systems management and independent audit of information systems according to the Communiqués recently published by Capital Markets Board of Turkey.

On January 5, 2018, Capital Markets Board (“Board”) published 2 (two) new communiqués; (i) Communiqué on Information Systems Management numbered VII-128.9 (“Communiqué numbered VII-128.9”) and (ii) Communiqué on Independent Audit of Information Systems numbered III-62.2 (“Communiqué numbered III-62.2”), which have entered into force on the day they have been published in the Official Gazette.

Communiqué numbered VII-128.9 sets forth the rules, policies and procedures regarding the management, security, sustainability and efficient operation of information systems of the entities which are respectively, Istanbul Stock Exchange (Borsa Istanbul A.Ş.), organized markets, pension funds, Istanbul Clearing, Settlement and Custody Bank (Istanbul Takas ve Saklama Bankası A.Ş.), Central Securities Depository of Turkey (Merkezi Kayıt Kuruluşu A.Ş.), custodians, Capital Markets Licensing Agency (Sermaye Piyasası Lisanslama Sicil ve Eğitim Kuruluşu A.Ş.), capital markets institutions, publicly held joint stock companies, Turkish Capital Markets Association (Türkiye Sermaye Piyasaları Birliği) and Turkish Appraisers Association (Türkiye Değerleme Uzmanları Birliği). Besides, Communiqué numbered III-62.2 sets forth the rules, policies and principles regarding the independent audit of the information systems of such entities.

It is worth to note that as per Article 2 of the Communiqué numbered III-62.2, banks, insurance companies, financial lease, factoring and finance companies are already required to comply with the rules and principles regarding information systems arising from their own legislation and such entities are deemed to be compliant with the above-mentioned Communiqués as long as they comply with their own applicable legislation regarding information systems. Notwithstanding the afore-mentioned, the same Communiqué as per Article 29, requires these entities to provide a copy of their independent audit reports to the Board within 30 days’ period following the expiry of the respective audit term.

As regards to the Communiqué numbered VII-128.9, we would like to highlight the following provisions applicable to the entities enlisted under the respective Communiqué.

  • The management of the information systems of the entities has become a part of corporate governance practice,
  • “Information Security Policy” shall be executed by the executive management and approved by the Board of Directors (BoD) of the respective entity for the establishment, management and use of information systems,
  • Executive management of the entity is responsible and liable for the exercise of Information Security Policy,
  • BoD is liable to conduct efficient and sufficient controls over the entity regarding the operation of information systems in the framework of Information Security Policy,
  • For data protection, specific measures shall be taken as precaution to protect the secrecy of the data received, processed or undisclosed in the course of the information systems operations such as network security, identity verification, monitoring of the outsource companies, physical access only through authorized persons,
  • Specific other precautions shall be taken for protection of client data acquired through information systems,
  • The primary and secondary systems of the entity are required to exist within the territory of Turkey,
  • The penetration test shall be made at least once a year,
  • Entities explicitly listed under the Communiqué numbered VII-128.9 such as asset management companies whose paid-in capital is equal to or less than 5 million TRY, brokerage companies with limited authority, asset lease companies, publicly held companies are held exempt from certain requirements regarding authorization, identity verification or information secrecy violation,
  • Further rules and procedures with respect to sustainability of primary and secondary information systems, maintenance, recording mechanism and violation of such systems are set forth under this Communiqué.

As regards to the Communiqué numbered III-62.2, we would like to highlight the following provisions applicable to the entities enlisted under the respective Communiqué.

  • Independent auditor company reports whether the audited entity is in line with the information system management principles in terms of its operations, equipment and software pursuant to Communiqué numbered VII-128.9,
  • Independent auditor company intending to independently audit the information systems of an entity and carrying the criteria envisaged under the Communiqué numbered III – 62.2 applies to the Board to be authorized for such independent audit service,
  • Independent auditor company is selected among the companies enlisted under Board’s authorized independent auditors and shall employ adequate number of personnel to duly complete the information systems auditing.
  • The entity to be audited shall make available all the information systems documentation and also any records, information and system for independent audit process,
  • The entity to be audited shall execute an “information systems independent audit agreement” within the first 4 (four) months of the term subject to audit, and a copy of the agreement shall be submitted to Board within 6 (six) days following its execution1;
  • Independent auditor company shall present a written report to the BoD of the entity upon the preparation of the opinion, and following a declaration of the BoD regarding its acceptance of such report, the entity shall provide a copy of the independent audit report and acceptance declaration to the Board,
  • Further rules and principles with respect to auditing methodology, reporting requirements and exemptions applicable for certain entities are set forth under this Communiqué.

In the table hereunder, we would like to present the frequency of the information systems audits that are rendered compulsory by the Communiqué numbered III – 62.2 to be conducted by the respective entities:

Borsa İstanbul A.Ş. (İstanbul Stock Exchange)

Istanbul Clearing, Settlement and Custody Bank (İstanbul Takas ve Saklama Bankası A.Ş.)

Central Securities Depository of Turkey (Merkezi Kayıt Kuruluşu A.Ş.)

Other organized markets

Central clearance houses

Central custodians

Data storage institutions

  • Once a year
  • The first audit shall be conducted regarding the year the Communiqué has entered into force (year 2018)
Brokers holding partial and broad authorization

Asset management companies with a paid-in capital of more than 5 million TRY

  • Once every 2 (two) years
  • The first audit shall be conducted regarding the second year following the entry into force of this Communiqué (year 2020).
Asset management companies with a paid-in capital of less than 5 million TRY

Capital Markets Licensing Agency (Sermaye Piyasası Lisanslama Sicil ve Eğitim Kuruluşu A.Ş.)

  • Once every 3 (three) years
  • The first audit shall be conducted regarding the third year following the entry into force of this Communiqué (year 2021).
Brokers with limited authorization

Publicly held joint stock companies

Collective Investment Schemes (Mutual funds and investment partnerships)

Asset lease companies (varlık kiralama şirketleri)

Pension funds

Housing finance and wealth finance funds (Konut finansman ve varlık finansman fonları)

Turkish Capital Markets Association (Türkiye Sermaye Piyasaları Birliği)

Independent Audit, Valuation and Rating Institutions (Bağımsız Denetim, Değerleme ve Derecelendirme kuruluşları)

Turkish Capital Markets Association (Türkiye Sermaye Piyasaları Birliği)

Turkish Appraisers Association (Türkiye Değerleme Uzmanları Birliği),

  • Not subject to periodic independent audit.

***

1 The 4 months-restriction for contract signing is not enforceable for the first audit term of the entity according to the first provisional article of the Communiqué.

 

Relevant Expert Insights

Publication Subscription Privacy Notice

Thank you for your interest in our Firm.

As Eryürekli Law Firm (“Eryürekli”), we attach great importance to the protection of your personal data and to the processing of such data in compliance with the Law No. 6698 on the Protection of Personal Data (“Law”) and other applicable legislation.

If you subscribe to our newsletter and other publications through the “Newsletter” section by visiting our office website, we collect and process your personal data in our capacity as the data controller.

By providing your explicit consent in the “Newsletter” section and filling out the form on our website and/or the relevant directed page, we automatically collect and process your name, surname, e-mail address, and language preference in an electronic environment for the purposes of managing your subscription and delivering our publications to you.

Within the framework of the data processing activities mentioned above, our publications are sent to the e-mail address you have shared. Since the servers of the service infrastructure we use for these transmissions are located abroad, your personal data shared through the form will be transferred to servers located abroad based on your explicit consent.

Your personal data will be destroyed in the event that you unsubscribe from our publications.

We would like to inform you that, pursuant to Article 11 of the Law, you hold the following rights regarding your personal data processed by Eryürekli:

  • To learn whether your personal data is being processed,
  • To request information if your personal data has been processed,
  • To learn the purpose of the processing of your personal data and whether such data are used in accordance with that purpose,
  • To learn the identity of third parties to whom your personal data are transferred, whether domestically or abroad,
  • To request the correction of personal data if it is incomplete or inaccurately processed,
  • To request the deletion or destruction of your personal data if the reasons requiring their processing cease to exist,
  • To request that the correction, deletion, or destruction of your personal data be notified to third parties to whom such data have been transferred,
  • To object to any outcome detrimental to you resulting from the analysis of your data exclusively through automated systems,
  • To claim compensation for damages incurred due to the unlawful processing of your personal data.

You may contact us regarding your requests via [email protected].

Yayın Aboneliği Aydınlatma Metni

Büromuza göstermiş olduğunuz ilgi için teşekkür ederiz.

Eryürekli Hukuk Bürosu (“Eryürekli”) olarak kişisel verilerinizin korunmasını ve 6698 sayılı Kişisel Verilerin Korunması Kanunu (“Kanun”) ve sair mevzuata uygun olarak işlenmesini önemsiyoruz.

Ofis web sitemizi ziyaret ederek “Newsletter” bölümünden bültenimize ve diğer yayınlarımıza abone olmanız durumunda kişisel verilerinizi veri sorumlusu sıfatıyla topluyor ve işliyoruz.

“Newsletter” bölümününde açık rızanızı vermek suretiyle web sitemiz ve/veya yönlendirildiğiniz ilgili sayfada yer alan formu doldurmanız ve yayınlarımıza abone olmanız halinde, adınız ve soyadınızı, elektronik posta adresinizi ve dil tercihinizi, aboneliğinizin gerçekleştirilmesi ve yayınlarımızın size iletilmesi amacıyla elektronik ortamda otomatik olarak toplamakta ve işlemekteyiz.

Yayınlarımız, yukarıdaki veri işleme faaliyetleri çerçevesinde, paylaşmış olduğunuz elektronik posta adresine gönderilmekte olup; gönderilerde kullandığımız servis altyapısı sunucularının yurt dışında olması sebebiyle, form aracılığıyla paylaştığınız kişisel verileriniz, açık rızanıza istinaden yurt dışında bulunan sunuculara aktarılacaktır.

Kişisel verileriniz, yayınlarımıza abonelikten çıkmanız halinde imha edilir.

Eryürekli bünyesinde işlenmekte olan kişisel verilerinize ilişkin olarak Kanun’un 11.maddesi uyarınca aşağıda sayılan haklarınızın bulunduğunu belirtmek isteriz:

  • Kişisel verilerinizin işlenip işlenmediğini öğrenme,
  • Kişisel verileriniz işleniyorsa bunlara ilişkin bilgi edinme,
  • Kişisel verilerinizin işlenme amacının ne olduğu ve kişisel verilerinizin amacına uygun olarak kullanılıp kullanılmadığını öğrenme,
  • Varsa yurt içinde veya yurt dışında kişisel verilerinizin aktarıldığı üçüncü kişilerin kimler olduğunu öğrenme,
  • İşlenen kişisel verilerinizin eksik veya yanlış olması halinde bunların düzeltilmesini isteme,
  • Kişisel verilerinizin işlenmesini gerektiren sebeplerin ortadan kalkması halinde, işlenmiş olunan kişisel verilerinizin silinmesini veya yok edilmesini isteme,
  • Kişisel verilerinizin düzeltilmesi, silinmesi ya da yok edilmesi halinde bu işlemlerin kişisel verilerinizin aktarıldığı üçüncü kişilere bildirilmesini isteme,
  • İşlenen kişisel verilerinizin münhasıran otomatik sistemler vasıtasıyla analiz edilmesi suretiyle aleyhinize bir sonucun ortaya çıkmasına itiraz etme,
  • Kişisel verilerinizin kanuna aykırı olarak işlenmesi sebebiyle zarara uğramanız halinde zararın giderilmesini talep etme.

Talepleriniz için bizimle [email protected] adresimiz aracılığıyla iletişime geçebilirsiniz.

Career Privacy Notice

Thank you for your interest in our Firm.

As Eryürekli Law Firm (“Eryürekli”), we attach great importance to the protection of your personal data and to the processing of such data in compliance with the Law No. 6698 on the Protection of Personal Data (“Law”) and other applicable legislation.

If you apply for a position through our career page, we collect and process your personal data in our capacity as the data controller.

By filling out the form on our career page and providing your explicit consent to apply for a position, we automatically collect and process your name and surname, e-mail address, telephone number, and any other personal data included in your CV through electronic means. This data is processed solely for the purposes of evaluating your job application and contacting you if necessary.

The personal data you share during your job application is not transferred to third parties.

Once your application has been evaluated, your personal data stored in the electronic environment will be destroyed as soon as possible.

We would like to inform you that, pursuant to Article 11 of the Law, you hold the following rights regarding your personal data processed by Eryürekli:

  • To learn whether your personal data is being processed,
  • To request information if your personal data has been processed,
  • To learn the purpose of the processing of your personal data and whether such data are used in accordance with that purpose,
  • To learn the identity of third parties to whom your personal data are transferred, whether domestically or abroad,
  • To request the correction of personal data if it is incomplete or inaccurately processed,
  • To request the deletion or destruction of your personal data if the reasons requiring their processing cease to exist,
  • To request that the correction, deletion, or destruction of your personal data be notified to third parties to whom such data have been transferred,
  • To object to any outcome detrimental to you resulting from the analysis of your data exclusively through automated systems,
  • To claim compensation for damages incurred due to the unlawful processing of your personal data.

You may contact us regarding your requests via [email protected].

 

Kariyer Aydınlatma Metni

Büromuza göstermiş olduğunuz ilgi için teşekkür ederiz.

Eryürekli Hukuk Bürosu (“Eryürekli”) olarak kişisel verilerinizin korunmasını ve 6698 sayılı Kişisel Verilerin Korunması Kanunu (“Kanun”) ve sair mevzuata uygun olarak işlenmesini önemsiyoruz.

Kariyer sayfamızdan iş başvurusunda bulunmanız durumunda kişisel verilerinizi veri sorumlusu sıfatıyla topluyor ve işliyoruz.

Kariyer sayfamızda yer alan formu doldurmak ve açık rızanızı vermek suretiyle iş başvurusunda bulunmanız halinde, adınız ve soyadınızı, elektronik posta adresinizi, telefon numaranızı ve özgeçmişinizde yer alan diğer kişisel verilerinizi, iş başvurunuzu değerlendirmek ve gerekmesi halinde size ulaşabilmek amacıyla elektronik ortamda otomatik olarak toplamakta ve işlemekteyiz.

İş başvurusu esnasında paylaşmış olduğunuz kişisel verileriniz üçüncü taraflara aktarılmamaktadır.

İş başvurunuzun en kısa sürede değerlendirilmesi üzerine kişisel verileriniz kayıtlı bulunduğu elektronik ortamda imha edilmektedir.

Eryürekli bünyesinde işlenmekte olan kişisel verilerinize ilişkin olarak Kanun’un 11.maddesi uyarınca aşağıda sayılan haklarınızın bulunduğunu belirtmek isteriz:

  • Kişisel verilerinizin işlenip işlenmediğini öğrenme,
  • Kişisel verileriniz işleniyorsa bunlara ilişkin bilgi edinme,
  • Kişisel verilerinizin işlenme amacının ne olduğu ve kişisel verilerinizin amacına uygun olarak kullanılıp kullanılmadığını öğrenme,
  • Varsa yurt içinde veya yurt dışında kişisel verilerinizin aktarıldığı üçüncü kişilerin kimler olduğunu öğrenme,
  • İşlenen kişisel verilerinizin eksik veya yanlış olması halinde bunların düzeltilmesini isteme,
  • Kişisel verilerinizin işlenmesini gerektiren sebeplerin ortadan kalkması halinde, işlenmiş olunan kişisel verilerinizin silinmesini veya yok edilmesini isteme,
  • Kişisel verilerinizin düzeltilmesi, silinmesi ya da yok edilmesi halinde bu işlemlerin kişisel verilerinizin aktarıldığı üçüncü kişilere bildirilmesini isteme,
  • İşlenen kişisel verilerinizin münhasıran otomatik sistemler vasıtasıyla analiz edilmesi suretiyle aleyhinize bir sonucun ortaya çıkmasına itiraz etme,
  • Kişisel verilerinizin kanuna aykırı olarak işlenmesi sebebiyle zarara uğramanız halinde zararın giderilmesini talep etme.

Talepleriniz için bizimle [email protected] adresimiz aracılığıyla iletişime geçebilirsiniz.

Kayıt Formu / Subscription Form

* indicates required
Your e-mail address
Your First name
Your Last Name
Gönderi Dili / Publication Language
Herhangi birisi veya her ikisi / Either any or both