Introduction
Patient privacy and personal data protection in Turkish pharmacies are essential parts of modern pharmacy law. A pharmacy is not an ordinary retail shop. It is a healthcare institution where patients disclose highly sensitive information about their identity, illnesses, prescriptions, medicines, diagnoses, chronic conditions, psychiatric treatment, reproductive health, disability status, controlled medicine use and SGK reimbursement records.
In Turkey, pharmacies process both ordinary personal data and special category personal data. The most important legal framework is based on Law No. 6698 on the Protection of Personal Data, known as KVKK, the Personal Health Data Regulation, and the Regulation on Pharmacists and Pharmacies. Under the Turkish pharmacy regulation, a pharmacy is defined as a healthcare institution opened under the ownership and responsible management of a pharmacist, and pharmacy practice is defined as a healthcare service involving medicine preparation, medicine supply, quality assurance, patient information and reporting of medicine-related problems.
Patient privacy is therefore not only an ethical duty. It is a statutory compliance obligation. A pharmacy that fails to protect patient data may face administrative sanctions, professional disciplinary proceedings, compensation claims, reputational damage and, in serious cases, criminal law consequences.
Legal Framework
The legal foundation begins with the KVKK. According to the Personal Data Protection Authority, personal data means any information relating to an identified or identifiable natural person. Processing includes collection, recording, storage, preservation, alteration, disclosure, transfer, classification or prevention of use of personal data.
Health data is more sensitive. The KVKK authority explains that special category personal data includes, among other categories, data relating to health, sexual life, biometric and genetic data, criminal convictions and security measures. It also emphasizes that special category personal data requires stronger protection because disclosure may cause discrimination or victimization.
The Personal Health Data Regulation defines personal health data as any information relating to the physical or mental health of an identified or identifiable person, as well as information relating to health services provided to that person. The regulation also states that health service providers must take necessary physical, technical and administrative measures to prevent unauthorized persons from seeing, hearing, learning or obtaining another person’s personal data in areas such as counters, desks and service points.
Pharmacy-specific law also imposes a direct confidentiality duty. The Regulation on Pharmacists and Pharmacies states that the pharmacist must act in accordance with professional and ethical conduct and must protect the patient’s or service recipient’s private life and privacy.
What Personal Data Do Pharmacies Process?
A Turkish pharmacy may process many categories of personal data. These include name and surname, Turkish identity number, passport number, date of birth, phone number, address, SGK status, prescription information, medicine history, diagnosis, medical report details, physician information, controlled medicine records, payment information, camera recordings and complaint records.
Some of these data are ordinary personal data. Others are special category data. For example, a prescription for insulin may reveal diabetes. A psychiatric medicine may reveal mental health treatment. A fertility medicine may reveal reproductive treatment. A red or green prescription may reveal use of controlled medicines. A medical report may reveal disability or chronic disease. Therefore, pharmacies should treat prescription and medicine data as high-risk health data.
This is why pharmacy data protection must be stronger than ordinary store privacy policies. A pharmacy does not merely record a sales transaction. It records information that may affect the patient’s dignity, social life, employment, family relations, insurance status and personal autonomy.
Core KVKK Principles for Pharmacies
Pharmacies must comply with the general principles of personal data processing. The Personal Health Data Regulation expressly states that personal data processing must comply with the general principles in Article 4 of the KVKK and all other rules of the law.
In pharmacy practice, these principles mean that patient data must be processed lawfully, fairly, accurately, for specific and legitimate purposes, in a limited and proportionate manner, and retained only as long as necessary. A pharmacy should not collect unnecessary patient data merely because it may be useful later.
For example, if a medicine can be supplied without collecting a phone number, the pharmacy should not require one unless there is a lawful and necessary purpose. If a patient asks a general question, the pharmacy should not record sensitive details unnecessarily. If a report or prescription copy is no longer legally needed, retention and destruction rules should be reviewed.
Legal Basis for Processing Health Data
Health data is special category personal data. Under the KVKK framework, special category data can be processed only under limited legal grounds. The KVKK authority states that special category data may be processed with explicit consent or under specific statutory conditions, including where processing is necessary by persons under a confidentiality obligation or authorized institutions for public health protection, preventive medicine, medical diagnosis, treatment and care services, or planning, management and financing of health services.
For pharmacies, this means that not every data processing activity requires explicit consent. Many prescription, medicine supply, SGK reimbursement, record-keeping and legal reporting activities may be based on legal obligation, health service provision, public health, treatment and financing grounds. However, if the pharmacy wants to process data for marketing, loyalty programs, promotional messaging, profiling or non-essential commercial purposes, explicit consent may become necessary.
A common mistake is asking for blanket consent for everything. If a data processing activity has a lawful basis other than explicit consent, relying unnecessarily on consent may be legally problematic. The KVKK authority notes that where processing can be carried out based on a non-consent legal ground, making it dependent on explicit consent may be misleading or abusive.
Aydınlatma Obligation
Every pharmacy must inform patients about data processing. The KVKK authority explains that data subjects must be informed about who processes their data, for what purposes, on what legal grounds, by which methods, to whom data may be transferred and what rights they have.
In pharmacy practice, this requires a clear privacy notice. The notice should explain that the pharmacy processes identity, contact, prescription, health, SGK, payment and transaction data for medicine supply, prescription processing, legal obligations, SGK reimbursement, İTS and MEDULA processes, accounting, complaint management and patient safety.
The privacy notice should be accessible in the pharmacy. It may be displayed physically and, where lawful, made available digitally. However, the notice should not be a generic copy-paste text. It should reflect the pharmacy’s actual data processing activities.
Physical Privacy in the Pharmacy
Patient privacy begins at the counter. The Personal Health Data Regulation specifically requires health service providers to take measures at counters, desks and similar areas so that unauthorized persons cannot hear, see, learn or obtain personal data belonging to other service recipients.
This rule is highly relevant to pharmacies. Patients often stand close to each other. A pharmacy employee may call out a medicine name, diagnosis, report status or identity number. A patient may ask about a sensitive medicine while another customer is standing nearby. Prescription screens may be visible to third parties. Printed reports may remain on the counter.
A compliant pharmacy should therefore create privacy-friendly service practices. Patient identity numbers should not be spoken loudly. Sensitive medicine names should not be announced publicly. Computer screens should be angled away from customers. Prescription documents should not be left openly on counters. Waiting patients should not be able to read another patient’s prescription or SGK report.
Prescription Privacy
Prescriptions are among the most sensitive documents processed by pharmacies. A prescription may reveal the patient’s diagnosis, physician, treatment plan, medicine history and reimbursement status. Even the name of a medicine may reveal sensitive health information.
Pharmacy personnel should handle prescriptions carefully. Paper prescriptions, prescription printouts, medical reports and SGK documents should not be left in open areas. Documents should be stored securely, accessed only by authorized staff and destroyed when retention is no longer required.
Digital prescriptions also require protection. E-prescription systems, MEDULA screens, İTS records and pharmacy software should be accessed only by authorized users. Passwords should not be shared among employees. User accounts should be personal where possible, and access logs should be preserved where the system allows it.
Employee Confidentiality
Pharmacy staff are one of the biggest privacy risk points. The pharmacist may understand KVKK obligations, but employees may unintentionally disclose patient information during daily work. A pharmacy employee may discuss a patient’s medicines with a neighbor, send a prescription image through WhatsApp, leave reports on the counter or answer questions from a relative without authority.
The KVKK authority states that data controllers and data processors cannot disclose personal data contrary to the law or use it outside the purpose of processing, and this duty continues after leaving the job.
Therefore, every pharmacy should train staff on confidentiality. Employment contracts should include data protection clauses. Employees should be instructed not to disclose patient data to relatives, employers, neighbors, spouses, friends, clinic staff or delivery persons unless there is a lawful basis. Staff should understand that even confirming whether a person bought a particular medicine may violate privacy.
Sharing Data with Patient Relatives
Pharmacies frequently face requests from relatives. A spouse may ask what medicine the patient bought. A parent may ask for information about an adult child’s prescription. An employer may call to verify whether an employee obtained a medicine. A neighbor may ask whether the patient uses psychiatric medication.
The default rule should be caution. Personal health data should not be disclosed to third parties unless the patient has authorized it or a clear legal basis exists. The Personal Health Data Regulation provides that sharing personal health data with patient relatives must comply with the principles of the KVKK and the Patient Rights Regulation.
For minors, guardianship, custody and maturity issues may arise. The Personal Health Data Regulation contains specific rules on access to children’s health data, including parental access and the ability of children with sufficient discernment to make access subject to permission in e-Nabız.
WhatsApp, SMS and Digital Communication
Many pharmacies use WhatsApp or SMS to communicate with patients. This creates significant privacy risk. Patients may send prescription photos, identity numbers, medical reports or medicine requests through messaging applications. Pharmacy staff may respond using personal phones. Images may remain in chat histories, cloud backups or employee devices.
A pharmacy should avoid unnecessary health data communication through insecure channels. If digital communication is used, it should be limited, controlled and documented under a clear policy. Employees should not store patient prescriptions on personal phones. Sensitive prescription images should not be shared in informal staff groups. Patient data should not be forwarded to suppliers, couriers or third parties unless legally necessary and secure.
Digital convenience cannot override confidentiality. A patient’s willingness to send a prescription photo does not automatically authorize unlimited storage, forwarding or reuse of that image.
CCTV in Pharmacies
Security cameras are common in pharmacies. They may be needed to prevent theft, protect staff and ensure security. However, CCTV recordings are also personal data. If cameras capture patients buying sensitive medicines, they may indirectly reveal health information.
A pharmacy should use cameras proportionately. Cameras should not focus unnecessarily on prescription screens, counseling areas, payment PIN pads or private patient conversations. CCTV signs and privacy notices should inform visitors. Record retention should be limited. Access to recordings should be restricted.
If camera recordings are shared with police, courts, insurers or third parties, the pharmacy should document the legal basis and scope of disclosure.
SGK, MEDULA and İTS Data
Pharmacies process data through SGK, MEDULA and İTS systems. These systems involve identity, prescription, medicine, reimbursement and stock information. Processing in these systems is generally connected to legal obligations, health service financing and medicine traceability.
However, lawful access does not mean unlimited use. Employees should use SGK, MEDULA and İTS data only for pharmacy service, reimbursement, stock tracking and legal compliance. A staff member should not look up a patient’s records out of curiosity. A pharmacist should not use reimbursement data for marketing. Prescription history should not be disclosed to third parties.
System access should be controlled. Passwords should be protected. Former employees’ access should be removed. Devices should be secured. Printouts should be kept safely.
Data Transfers to Third Parties
Pharmacies may transfer personal data to SGK, TİTCK, Ministry systems, accountants, software providers, payment service providers, lawyers, courts, enforcement offices, insurers or authorized public bodies. Each transfer must have a lawful basis and must be limited to the necessary data.
The Personal Health Data Regulation states that domestic transfers of personal health data must comply with KVKK Article 8 and international transfers must comply with Article 9. It also requires certain public institution transfers to be based on protocols containing data protection principles, security provisions and the categories of data to be transferred.
For pharmacies, this means that third-party service providers should not receive unrestricted access to patient data. Pharmacy software providers, accountants and IT technicians may become data processors. Written agreements should define confidentiality, security, access limits, retention, deletion and breach notification duties.
Data Security Obligations
The KVKK authority explains that data controllers must prevent unlawful processing, prevent unlawful access and ensure preservation of personal data. Data controllers must take all necessary technical and administrative measures appropriate to the risk.
For pharmacies, technical measures may include password protection, access authorization, antivirus software, backups, secure pharmacy software, screen locking, encrypted devices, restricted user accounts and secure disposal of old computers.
Administrative measures may include staff training, confidentiality undertakings, privacy policies, data inventory, access rules, physical archive security, breach response procedures, data processor agreements and periodic internal audits.
Because health data is sensitive, the pharmacy should take stronger measures than an ordinary retail business.
Data Breach Management
A data breach may occur if prescription records are stolen, pharmacy software is hacked, a staff member sends data to the wrong person, a laptop containing patient records is lost, paper prescriptions are thrown into ordinary trash, or CCTV footage is disclosed unlawfully.
The KVKK authority states that where personal data is obtained by others through unlawful means, the data controller must notify the data subject and the Board as soon as possible.
A pharmacy should have a breach response plan. The plan should identify who investigates the incident, how affected data is determined, whether patients must be notified, whether the KVKK Board must be notified, how evidence is preserved and how recurrence is prevented.
Data Subject Rights
Patients have rights under KVKK. The KVKK authority states that data subjects may ask whether their personal data is processed, request information, learn the purpose of processing, learn third-party transfers, request correction, request deletion or destruction, object to certain automated processing outcomes and claim compensation if they suffer damage due to unlawful processing.
A pharmacy should have a written procedure for responding to these requests. Staff should know that patient requests cannot be ignored. However, requests must also be verified. A pharmacy should not disclose health data to someone merely because they claim to be the patient. Identity verification is essential.
Retention and Destruction
Pharmacies must retain certain records because of pharmacy law, tax law, SGK rules, inspection requirements and possible legal disputes. However, data should not be kept indefinitely without legal basis.
The Personal Health Data Regulation states that destruction of personal health data must comply with KVKK Article 7 and the regulation on deletion, destruction or anonymization of personal data.
A pharmacy should prepare a retention and destruction policy. Paper records should be shredded or destroyed securely. Digital records should be deleted in a way that prevents unauthorized recovery when retention is no longer necessary. Archive rooms should be locked. Old computers and storage devices should be wiped before disposal.
High-Risk Privacy Scenarios in Pharmacies
Some pharmacy transactions require extra privacy protection. Psychiatric medicines, HIV medicines, reproductive health products, emergency contraception, addiction treatment medicines, oncology medicines, infertility medicines, controlled prescriptions and disability reports may expose patients to stigma or discrimination.
The Personal Health Data Regulation recognizes that some health data may have a higher privacy level where disclosure may negatively affect a person’s social life or mental health. It allows proportionate access restrictions for such data.
Pharmacies should handle these cases discreetly. Sensitive medicines should not be discussed loudly. Counseling should be offered privately where possible. Documents should not be visible to others. Staff should be trained to avoid judgmental language.
Marketing and Loyalty Programs
Pharmacies should be cautious with marketing. A loyalty program that records what medicines or health products a patient buys may create sensitive health profiles. Sending promotional messages based on medicine history may violate KVKK if there is no valid explicit consent and lawful basis.
A patient who buys a diabetes product should not later receive marketing messages revealing that condition. A patient who buys psychiatric medicine should not be profiled for mental health campaigns. Even supplement and cosmetic purchases may reveal health concerns.
Marketing consent must be separate, informed and freely given. It should not be bundled with essential pharmacy services. Refusing marketing consent should not prevent the patient from receiving lawful pharmacy service.
Legal Liability
Privacy violations in pharmacies may lead to multiple consequences. Administrative sanctions may arise under KVKK. The Personal Health Data Regulation states that offences and misdemeanors concerning protected personal data are handled under KVKK Articles 17 and 18, and that real persons and private legal persons are subject to action under the relevant legislation.
Civil liability may arise if the patient suffers damage due to unlawful disclosure. For example, if an employee discloses a patient’s psychiatric medicine use to the patient’s employer, the patient may claim compensation.
Professional disciplinary liability may arise because the pharmacist has a direct duty to protect patient privacy under pharmacy regulation. Criminal liability may arise in serious unlawful disclosure or misuse cases, depending on the conduct and applicable penal provisions.
Practical Compliance Checklist for Pharmacies
A legally careful pharmacy should apply the following checklist:
Prepare a pharmacy-specific privacy notice.
Train all employees on patient confidentiality.
Use written confidentiality undertakings.
Limit access to prescription, SGK, MEDULA and İTS systems.
Do not share passwords.
Prevent patients from seeing other patients’ prescriptions or screens.
Avoid calling sensitive medicines loudly.
Keep paper prescriptions and reports in secure areas.
Use secure destruction for paper and digital records.
Limit WhatsApp and personal phone use.
Do not disclose patient data to relatives without lawful basis.
Use CCTV proportionately and inform visitors.
Sign data processing agreements with software providers and accountants.
Prepare a data breach response plan.
Keep a record of patient data requests.
Review marketing and loyalty programs carefully.
This checklist should be reviewed regularly by the responsible pharmacist.
Frequently Asked Questions
Are pharmacy prescription records personal data?
Yes. Prescription records identify or make a patient identifiable and usually contain health information. Therefore, they are personal data and often special category personal data under KVKK.
Is health data specially protected in Turkey?
Yes. Health data is special category personal data and requires stricter protection. It can be processed only under limited legal grounds and with adequate safeguards.
Can pharmacy staff tell a patient’s spouse what medicine the patient bought?
As a rule, no. Health data should not be disclosed to relatives unless the patient authorized it or there is another lawful basis.
Must pharmacies inform patients about data processing?
Yes. Data controllers must inform individuals about identity of the controller, purposes of processing, transfers, collection method, legal basis and rights.
Can patients request correction or deletion of pharmacy data?
Patients have KVKK rights, including rights to request information, correction, deletion or destruction where legal conditions are met. However, pharmacies may need to retain certain records because of legal, SGK, tax or inspection obligations.
What should a pharmacy do after a data breach?
The pharmacy should investigate, secure the data, document the incident, assess affected persons and notify the data subject and the KVKK Board where required.
Conclusion
Patient privacy and personal data protection in Turkish pharmacies are central to lawful and ethical pharmacy practice. Pharmacies process highly sensitive health information every day through prescriptions, SGK records, MEDULA, İTS, medical reports, payment systems, CCTV and patient communications.
The pharmacist has a direct professional duty to protect the patient’s private life and privacy. Turkish pharmacy regulation expressly states that the pharmacist must act ethically and protect the patient’s or service recipient’s private life and confidentiality.
The KVKK framework requires lawful, limited, proportionate and secure processing of personal data. Health data is special category personal data and requires stricter protection. The Personal Health Data Regulation also requires health service providers to take physical, technical and administrative measures so that unauthorized persons cannot see, hear, learn or obtain another person’s health data in service areas such as counters and desks.
For pharmacies, the safest approach is preventive compliance. Patient data should be processed only when necessary, accessed only by authorized persons, disclosed only on a lawful basis, protected through technical and administrative safeguards, and destroyed securely when retention is no longer required.
A pharmacy that protects patient privacy protects more than data. It protects patient dignity, professional trust, public health and the pharmacist’s legal security.
Yanıt yok