Turkish abstract: Kisisel Verileri Koruma Kurulu bir cok farkli alanda ilke kararlar yayimlamis olup son olarak 18 Subat 2019 tarihli Resmi Gazete’de “Saglik verilerini Kanununun 6’nci maddesinde yer alan isleme sartlarindan birine dayanmadan ucuncu bir kisiye aktaran veri sorumlusu hakkinda Kisisel Verileri Koruma Kurulunun 05/12/2018 tarihli, 2018/143 sayili” kararini, “Kisisel verilere hukuka aykiri erisilmesini onleme yukumlulugunu yerine getirmeyen veri sorumlusu hakkinda Kisisel Verileri Koruma Kurulu’nun 26/07/2018 tarihli, 2018/91 sayili” kararini ve “Sicil dosyalarindaki kisisel verilerin, islenmelerini gerektiren sebeplerin ortadan kalkmamasi halinde, imha edilmemesi gerektigi hakkinda Kisisel Verileri Koruma Kurulu’nun 28/06/2018 tarihli, 2018/69 sayili” kararini ilke karar olarak yayimlamistir. Bu kararlarin ozelligi, dikkatli okundugunda, aslinda hukuk sistemimizde olmayan ancak GDPR ile AB’nin gundemine gelen “tasarlanmis ve onceden tanimlanmis veri koruma” ile karsilastirmali hukukta var olan ulkemizde bugune kadar kabul edilmeyen “risk sorumlulugu” kavramlarini hukuk sistemimize girmesinde oncu nitelikte olmasidir. Bu makalemde Kurul tarafindan yayimlanan soz konusu kararlari basta 6698 sayili Kanun olmak uzere konuyla iliskili diger mevzuatlari da goz onunde bulundurarak yukarida belirtmis oldugum kavramlar baglaminda ele alacagim. English abstract:The Personal Data Protection Board has published policy decisions in many different areas, and lastly, in the Official Gazette dated February 18, 2019, it was stated that the Personal Data Protection Board, on 05 December 2018 dated and numbered 2018/143, the decision of the Personal Data Protection Board dated July 26, 2018, numbered 2018/91 about the data controller who does not fulfill the obligation to prevent unlawful access to personal data, and the "personal data in the registry files, the reasons that require processing has published the decision of the Personal Data Protection Board dated June 28, 2018 and numbered 2018/69, stating that it should not be destroyed, in case it is not removed. The feature of these decisions, when carefully read, is that they are pioneers in the introduction of the concepts of "designed and predefined data protection", which are not actually in our legal system, but brought to the agenda of the EU with the GDPR, and "risk liability" concepts, which have not been accepted until today in our country, in comparative law. In this article, I will discuss the aforementioned decisions published by the Board in the context of the concepts I have mentioned above, taking into account the Law No. 6698 and other relevant legislation.