6698 sayılı Kanun, Türkçe ve İngilizce aynı sayfada, Mart 2024 değişiklikleriyle. Kanun’u okuyun

TÜM NOTLAR KURUL KARARLARI

Personal Data Protection Board – Principle Decisions

Under Article 15(6) of Law No. 6698 the Board issues principle decisions that bind every data controller, not only the respondent in the file that produced them. This note covers all sixteen issued from 2017 to 2026, from 2017/61 on directory sites to 2026/1301 of 1 July 2026 on public bodies posting personal data online. Each is translated in full and arranged as a compliance checklist.

Çözümlemeler İngilizce yayımlanmaktadır. Aşağıdaki metin kaynak dilindedir ve makine çevirisine tabi tutulmamıştır.

Introduction

The Personal Data Protection Board’s principle decisions form a cornerstone of Turkish data-protection practice. Adopted under Article 15(6) of the Personal Data Protection Law No. 6698 (the “Law”), these decisions provide authoritative interpretations on recurring compliance issues such as unauthorized disclosure, marketing communications, insider misuse, and data-sharing mechanisms. They serve as practical guidance both for organizations established in Türkiye and for those abroad that process personal data of Turkish individuals. By presenting the key principle decisions, this article aims to serve your organization as a practical checklist to update policies, vendor/processor contracts, and technical controls.

Contents

  1. 2017/61 — Directory-style sites/apps: immediate cessation of sharing contact data without a legal basis; potential access-blocking and criminal referrals.

  2. 2017/62 — Counters/tellers/desks: physical and organizational measures to prevent customers from hearing/seeing one another’s personal data.

  3. 2018/63 — Insider misuse: personnel with access must not process beyond authority/purpose; controllers must implement robust access controls and monitoring.

  4. 2018/119 — Unsolicited marketing by SMS/e-mail/calls: stop processing absent explicit consent or another lawful basis; joint responsibility where processors act for controllers.

  5. 2019/308 — Unlawful lookup software: coordination with judicial authorities; referrals to prosecutors; administrative action against controllers using such tools.

  6. 2020/966 — Misdelivery of third-party data to wrong numbers/e-mails: duty to verify contact details and keep data accurate and up to date.

  7. 2021/1304 — Car-rental “blacklists”: cross-controller sharing via SaaS risks breaching general principles and transfer rules; potential joint controllership with software vendors.

  8. 2022/388 — Municipal property-tax payment and debt-inquiry pages: no access by T.R. identity number alone; membership and password, or two-factor verification with a second factor only the data subject can reach.

  9. 2025/1072 — SMS verification codes at checkout and sign-up: explain what the code is for before it is sent; no bundling of membership, processing permission and marketing approval in one code; marketing consent never a condition of the sale.

  10. 2025/2120 — Hotels and other places of accommodation: record name, surname and T.R. identity number against the ID; stop photocopying identity documents and destroy copies already held under Article 7.

  11. 2026/266 — Loyalty cards: no purchases on someone else’s phone or card number without verification (one-time SMS code, app barcode/QR, physical card or card password, opt-in choices); six months from publication to comply.

  12. 2026/347 — Privacy notices and explicit consent texts: always separate, under separate headings and with separate declarations; “I have read and understood”, never “I accept”; no consent text where another legal basis applies; good- and bad-practice templates annexed.

  13. 2026/348 — Debt lists in apartment/housing-complex common areas: posting residents’ dues and debt lists in elevators, entrances and corridors has no Article 5 processing condition and breaches Article 12; end the practice, take the lists down and notify owners only through channels third parties cannot reach.

  14. 2026/921 — Biometric working-time tracking: no law expressly provides for it, employee consent is doubtful and not enough on its own, and the processing fails proportionality even with valid consent; track attendance by card/PIN, paper sheets, RFID/NFC or supervised manual entry instead.

  15. 2026/1095 — Accident victims’ data: damage-consultancy firms and loss adjusters/attorneys acting beyond their authority face Board complaints and possible criminal referral; controllers holding victims’ data must apply training, least-privilege access, role-based controls and monitoring.

  16. 2026/1301 — Public bodies publishing personal data online: needs an Article 5/6 processing condition and Article 4 compliance; share the minimum, mask and time-limit posts, review and take down existing ones, and limit exam/draw results to participants or the data subject (e-Government or two-factor).

1 — Principle Decision dated 21/12/2017 and numbered 2017/61 on the protection of personal data on websites/applications providing directory services.

Subject: Protection of personal data on websites/applications providing directory services.

As a result of the assessments conducted within the scope of notices and complaints submitted to the Personal Data Protection Authority regarding websites and applications providing directory services in the form of querying a name to find a phone number, or querying a phone number to find a name, without obtaining the data subjects’ explicit consent in violation of the provisions of the Law, it has been determined that there are many applications and websites which, by collecting personal data through various applications, websites, or social media accounts and enabling the sharing of such data, provide services such as accessing phone number information when a name is queried, accessing name information when a phone number is queried, and learning how one is saved in other persons’ phone directories.

In subparagraph (e) of paragraph (1) of Article 3 of the Law, “any operation which is performed on personal data, wholly or partially by automated means or by non-automated means which provided that form part of a data filing system, such as collection, recording, storage, protection, alteration, adaptation, disclosure, transfer, retrieval, making available for collection, categorization, or preventing the use thereof” is regulated as the processing of personal data; in order for any of the enumerated actions to be carried out, one of the processing conditions set forth in Articles 5 and 6 of the Law must first exist, and the other obligations envisaged by the Law must also be fulfilled.

Within this scope, it was unanimously decided that:

  • It is required, pursuant to paragraph (7) of Article 15 of the Law, that the data processing activity carried out by websites and mobile applications that share the contact information of data subjects without any basis in the Law and the relevant legislation be immediately ceased;

  • In the event it is learned that the aforementioned websites/applications have not terminated such activities, applications shall be made to the competent authorities to ensure that access to these websites/applications is blocked; moreover, considering that personal data may have been obtained unlawfully, the matter shall be reported ex officio to the Office of the Chief Public Prosecutor pursuant to Article 158 of the Code of Criminal Procedure, for the initiation of the necessary legal proceedings against the relevant websites/applications within the framework of Article 136 of the Turkish Penal Code No. 5237 titled “Unlawful Delivery or Acquisition of Data”, and the public shall be informed in this regard;

  • Pursuant to paragraph (6) of Article 15 of the Law, this principle decision shall be published in the Official Gazette and on the website of the Authority, and action shall be taken against those who do not comply with this decision within the scope of Article 18 of the Law.

2 — Principle Decision dated 21/12/2017 and numbered 2017/62 regarding the protection of personal data in service areas such as counters, teller windows, and desks.

Subject: Protection of personal data in service areas such as counters, teller windows, and desks.

As a result of the assessment carried out within the scope of notices submitted to the Personal Data Protection Authority regarding personal data security breaches occurring in areas where services are provided to citizens such as counters, teller windows, and desks, to ensure prevention of practical problems, it was unanimously decided that:

  • Public and private sector institutions and organisations providing services—particularly in the banking and health sectors, and including postal and cargo services operating with multiple adjacent staff, travel agencies, customer service departments of chain stores, organisations where various subscription transactions are conducted, and services such as municipal, tax, and population registry procedures—shall, pursuant to Article 12 of the Law, take the necessary technical and administrative measures concerning the protection of personal data that will prevent unauthorised persons from being present in sections such as counters/teller windows/desks, and that will prevent persons receiving service simultaneously and in close proximity from hearing, seeing, learning, or obtaining one another’s personal data;

  • Pursuant to paragraph (6) of Article 15 of the Law, this principle decision shall be published in the Official Gazette and on the website of the Authority, and action shall be taken against those who do not comply with this decision within the scope of Article 18 of the Law.

3 — The Personal Data Protection Board’s Principle Decision dated 31/05/2018 and numbered 2018/63 regarding the assessment of the processing of the personal data in question by personnel who have access to personal data under the data controller but process such data beyond their authority and purpose

Subject: Assessment of the issue of processing the personal data in question, beyond authority and purpose, by personnel who have access to personal data under the data controller.

As a result of the assessments carried out regarding the notices and complaints submitted to the Personal Data Protection Authority concerning the processing of the personal data in question beyond the purpose of processing and by exceeding their authority, by those who, due to their position or duty under the data controller, have access to personal data; in order to prevent practical problems, it was unanimously decided that:

  • Since the processing of the personal data in question beyond the purpose of processing and/or the sharing of such data with third parties, by those who, due to their position or duty under a data controller, have access to personal data, by exceeding and/or abusing their authority, and based on personal purposes or reasons, would constitute a breach of paragraph (1) of Article 12 of the Law, the data controllers shall be informed that all necessary technical and administrative measures must be taken to ensure an appropriate level of security in order to prevent acts within this scope;

  • Pursuant to paragraph (6) of Article 15 of the Law, this principle decision shall be published in the Official Gazette and on the website of the Authority.

4 — The Personal Data Protection Board’s Principle Decision dated 16/10/2018 and numbered 2018/119 regarding the prevention of directing advertising notifications/calls to data subjects’ e-mail addresses or to their mobile phones by SMS or calls by data controllers and data processors

Subject: Taking a principle decision to prevent advertising notifications/calls from being directed to data subjects’ e-mail addresses or to their mobile phones by SMS or calls by data controllers and data processors.

Taking into account the large number of applications submitted to the Personal Data Protection Authority (Authority) and the findings reached within the scope of the ongoing examinations concerning the matter that advertising notifications/calls are sent to data subjects’ e-mail addresses or to their mobile phones by SMS or calls without obtaining their explicit consent, in violation of the provisions of the Law, it was decided unanimously to inform the public on the following matters and to publish this principle decision on the Authority’s website and in the Official Gazette:

  • That data controllers who direct advertising-content communications by sending SMS to telephone numbers, making calls, or sending mail to e-mail addresses without obtaining the consent of data subjects or without satisfying the processing conditions set forth in paragraph (2) of Article 5 of the Law, and data processors who, on behalf of data controllers, send advertising-content messages/e-mails or make calls by using such data without the explicit consent of data subjects, must immediately cease such data processing activities pursuant to paragraph (7) of Article 15 of the Law,

  • That within the scope of Article 12 of the Law, the data controller is obliged to take all necessary technical and administrative measures to ensure an appropriate level of security in order to prevent the unlawful processing of personal data, prevent unlawful access to personal data, and ensure the preservation of personal data; and that, where personal data are processed by another natural or legal person on behalf of the data controller, the data controller is jointly responsible with such persons for taking the aforementioned measures,

  • That action shall be taken against the data controllers engaged in the activities in question as specified above within the framework of the provisions of Article 18 of the Law,

  • That, considering that the personal data processed in the manner in question may have been obtained unlawfully, the matter shall be reported ex officio to the Office of the Chief Public Prosecutor pursuant to Article 158 of the Code of Criminal Procedure No. 5271, for the initiation of the necessary legal proceedings against the relevant data controllers within the framework of Article 136 of the Turkish Penal Code No. 5237 titled “Unlawful Delivery or Acquisition of Data”.

5 — The Personal Data Protection Board’s Principle Decision dated 18/10/2019 and numbered 2019/308 regarding software/programs/applications that enable querying citizens’ personal data such as identity and contact information based on data obtained unlawfully

Subject: Regarding software/programs/applications that allow the querying of citizens’ personal data such as identity and contact information obtained unlawfully.

With the application transmitted by the Ministry of Justice to the Personal Data Protection Authority and the Office of the Chief Public Prosecutor via CİMER, it was summarized that: a data controller is using a program that serves to find Turkish Republic (T.R.) identity numbers and addresses; when the name of any person is entered into this program, it provides that person’s T.R. identity number, residence address, relatives, and all identity information of those living in the same household; a video recording was made to demonstrate how the program works as evidence of the allegation, and in this video some names were queried and the program returned identity and address information at the press of a single key; it was the opinion that this program is unlawful; and it was stated that the program is installed and operational on the data controller’s desktop computers and laptops at the workplace and on the individual’s personal laptop, and that the necessary action be taken.

Upon our Authority also receiving the application in question, and upon the person who made the notification being informed that, in the event he submitted to our Authority concrete information or documents of a nature to substantiate his allegation, the notification would be treated as a tip-off and could be taken under examination within the scope of the Law, the video recording submitted with the application to the Authority was examined, and it was identified that:

  • When the program icon located on the home page of the laptop seen on the screen is clicked, a query page appears in the menu that opens after a user name and password are entered;

  • When a search is conducted by entering a person’s first name and surname, it is possible to access address information in a manner that includes the T.R. identity number, name, surname, gender, mother’s name, father’s name, place of birth, date of birth, the province and district of civil registry, as well as records relating to previous years concerning the province and district of civil registry, of the data subject and, if any, of other persons who have the same first name and surname as the person searched;

  • Although an example query was not carried out in the video recording, it was seen that there was also a field on the query page that could be marked as “Same Household”, and that the program also contained a tab titled “Bulk Query”; and it was understood that the recording in question had a nature substantiating the allegations made by the relevant person in his CİMER application.

In the data subject’s tip-off application, although there was no information as to whether the program was written/created by the data controller against whom the allegation was directed or obtained/purchased from a third person/persons/legal person, and if obtained in such a manner, who this third person/persons/legal person was/were; based on the statement and explanations on the login screen images in the video recording of the program in question reading “Member Login: ………”, “SMS Activation Code” and “Please Note! Our application will switch to a Fixed IP system in one month. We kindly ask all our users to take the necessary action in this regard.”, it was concluded that the program was obtained/purchased by the data controller against whom the allegation was directed from a third person/persons/legal person.

At this point, in the research conducted on the internet regarding the program and the company owning the program, it was observed that there are several programs created under the same name in different service branches and for different purposes; however, no internet page could be reached that could, without leaving room for doubt, be assessed as related to the program that is the subject of the tip-off application.

Nevertheless, it was seen that certain explanations on the subject were included in some news items reflected to the public. As can be seen in these news items as well, programs similar to the one subject to the data subject’s tip-off application—i.e., other programs/applications that allow the querying of citizens’ personal data such as identity and address through data considered to have been obtained unlawfully—are sold by criminal organizations for money to persons including lawyers; and it is understood that these unlawful activities have been the subject of various judicial investigations at different times.

As is known, the purpose of the Law is to protect, in the processing of personal data, the fundamental rights and freedoms of persons—primarily the right to privacy—and to regulate the obligations of natural and legal persons who process personal data and the procedures and principles to be complied with. The Law aims to prevent the collection of personal data in an unlimited and random manner, their acquisition by unauthorized persons, their disclosure, or the violation of personality rights as a result of their use for purposes other than those intended or their misuse. The Law, which seeks to bring under control the question of which rules personal data are subject to and under what conditions they may be processed, also aims, by introducing oversight mechanisms with respect to the processing of personal data, to prevent the unlawful processing of such data.

Articles 135, 136 and 137 of the Turkish Penal Code No. 5237 set out sanctions regarding the offences of unlawfully recording personal data and unlawfully giving, disseminating or obtaining personal data, and Article 17(1) of the Law stipulates that Articles 135 to 140 of the Turkish Penal Code shall apply in respect of offences relating to personal data. In addition, pursuant to Article 6 of the Law No. 3071 on the Exercise of the Right to Petition, no action can be taken by our Authority regarding matters falling within the jurisdiction of judicial bodies.

According to the reply given by the Office of the Chief Public Prosecutor to the application of the data subject—which had been forwarded both to our Authority and to the Office of the Chief Public Prosecutor via CİMER by the Ministry of Justice—it is seen that the CİMER application in question was processed by the correspondence offices of the Office of the Chief Public Prosecutor, the Ministry of Justice and the Council of Judges and Prosecutors.

Pursuant to Article 15(1) titled “Procedures and principles of examination upon complaint or ex officio” of the Law, the Personal Data Protection Board shall ex officio carry out the necessary examination in matters within its remit in the event it learns of an alleged violation upon a complaint or ex officio. In addition, pursuant to paragraph five of the same article, in the event that, as a result of an examination conducted upon a complaint or ex officio, the presence of a violation is established, the Board shall decide that the unlawfulness it has identified be remedied by the data controller and notify the relevant parties; and pursuant to paragraph six of the same article, in the event that the presence of a widespread violation is established as a result of an examination conducted upon a complaint or ex officio, the Board shall take a principle decision in this regard and publish that decision.

In consideration of the allegations in the tip-off application made to our Authority by the relevant person to the effect that a program belonging to the data controller was used to unlawfully obtain and sell personal data together with the employees working on site, the Board has unanimously decided:

  • With regard to the program that is the subject of the tip-off, to initiate an examination in respect of the data controllers who will be identified by the relevant judicial authorities as having used the program, in matters falling within the remit of the Board;

  • In order not to prejudice the proper conduct of the investigation processes initiated/to be initiated by the judicial authorities with respect to the allegation subject to the tip-off, to carry out the examination to be conducted by the Board in coordination with the judicial authorities and the administrative authorities deemed appropriate;

  • Furthermore, within the scope of the tip-offs transmitted to our Authority, it has been determined that software/programs/applications that allow the querying of citizens’ personal data such as identity and contact information through data obtained by various means are being used by certain persons and organisations operating in sectors such as legal services/law firms, finance, real estate consultancy, insurance, etc. In consequence of the assessment made, considering that this situation constitutes a breach of the obligations of data controllers regarding data security under Article 12 of the Law, and in order to prevent potential personal data security violations that may occur;

  • Those determined to be using software/programs/applications of this nature shall be reported, by way of tip-off, to the relevant Chief Public Prosecutors’ Offices pursuant to Article 158 of the Code of Criminal Procedure No. 5271 for the conduct of judicial proceedings under the Turkish Penal Code;

  • And, in terms of matters falling within the remit of the Board, the public shall be informed that administrative action will be taken against the data controllers within the framework of Article 18 of the Law;

  • That, pursuant to Article 15(6) of the Law, this principle decision has been adopted to be published in the Official Gazette and on the Authority’s website.

6 — Principle Decision of the Personal Data Protection Board dated 22/12/2020 and numbered 2020/966 on personal data of third parties unlawfully sent by data controllers to individuals’ communication channels such as phone numbers and e-mail addresses

Subject Summary: Principle Decision on personal data of third parties unlawfully sent by data controllers to individuals’ communication channels such as phone numbers and e-mail addresses.

Within the scope of complaints and tip-offs conveyed to the Personal Data Protection Authority, it is observed that in various sectors such as e-commerce, telecommunications, transportation and tourism, data controllers request data subjects to declare their phone numbers and/or e-mail addresses in order to send documents containing personal data—such as invoices, account statements and reservation documents—via SMS and/or e-mail; however, errors may occur when data subjects declare such information, or third parties’ information relating to data subjects may be declared, as a result of which the aforementioned documents containing personal data of the data subjects are transmitted to third parties.

As is known, Article 4(1) of the Law stipulates that personal data may be processed only in accordance with the procedures and principles set forth in this Law and other laws; and Article 4(2) provides that, in the processing of personal data, it is mandatory to comply with the following principles: “(a) Being processed lawfully and fairly. (b) Being accurate and, where necessary, up to date. (c) Being processed for specific, explicit and legitimate purposes. (ç) Being relevant, limited and proportionate to the purposes for which they are processed. (d) Being retained for the period stipulated in the relevant legislation or required for the purpose for which they are processed.”

Among these principles, keeping personal data accurate and, where necessary, up to date is required not only in line with the data controller’s interests but also for the protection of the data subject’s fundamental rights and freedoms; if the data controller produces a result regarding the data subject based on personal data and verifies it, the controller has an active duty of care to ensure that the personal data are accurate and, where necessary, up to date. Beyond this, it is important that the data controller always keeps channels open to ensure that the data subject’s information is accurate and, where necessary, up to date. Otherwise, individuals may suffer material and non-material damage due to personal data that are outdated or kept inaccurately. In this sense, in order to ensure that personal data are accurate and, where necessary, up to date; it is deemed necessary that the sources from which personal data are obtained be identifiable and that the accuracy of the source from which personal data are collected be verified, and—so as to prevent adverse consequences for data subjects arising from inaccurate personal data—that reasonable measures be taken to verify the contact information declared by data subjects (such as sending a verification code/link to the phone number and/or e-mail address).

On the other hand, Article 12 of the Law sets forth that data controllers are obliged to take all kinds of technical and administrative measures necessary to ensure an appropriate level of security for the purpose of preventing the unlawful processing of personal data, preventing unlawful access to personal data, and ensuring the safeguarding of personal data.

Within this scope; in order to prevent data controllers from sending documents such as account statements, invoices, etc., containing third parties’ personal data to individuals’ communication channels such as phone numbers and e-mail addresses in a manner that would constitute a violation of the Law; and, pursuant to Article 12(1) of the Law, to ensure that data controllers take the necessary administrative and technical measures to establish mechanisms to verify the accuracy of the contact information they hold, it has been decided unanimously to adopt this Principle Decision under Article 15(6) of the Law and to publish the said Principle Decision on the Authority’s website and in the Official Gazette.

7 — Principle Decision of the Personal Data Protection Board dated 23/12/2021 and numbered 2021/1304 regarding blacklist practices in the car-rental sector

Subject Summary: Principle Decision regarding blacklist practices in the car-rental sector.

Within the scope of tip-offs conveyed to the Personal Data Protection Authority (Authority), it has been understood, as a result of examinations carried out by the Personal Data Protection Board pursuant to Article 15 of the Law, that “blacklist” software/programs/applications are resorted to in the car-rental sector.

With respect to the said “blacklist” practices used in the car-rental sector, it has been ascertained that:

  • Software providers and vendors offer car-rental software to car-rental companies (or to natural persons engaging in car rental) that includes a “blacklist” feature;

  • Car-rental companies process, in the said software, the personal data of natural persons who rent vehicles as their customers; that among these data are information concerning any damage caused to the vehicle by these persons, adverse records, and “blacklist” information included in the rental companies’ comments;

  • These data are processed by car-rental companies to be used for decision-making in respect of subsequent rentals;

  • On the other hand, the said software are designed as systems that allow the data entered by one car-rental company to be made available to other car-rental companies;

  • Accordingly, a system is formed whereby the software provides a data flow/sharing concerning the blacklist to other car-rental companies that use the same software, and thus the personal data of the relevant persons who rent vehicles are mutually shared;

  • In general, the service offered by software companies is in the form of SaaS (Software as a Service); as required by the SaaS service, the database and software management rest with the software companies, and users with administrative authorization are assigned so that the software company can provide the necessary technical support and development to car-rental companies; the service offered is not hosted on the rental companies’ own servers; car-rental companies are not permitted to interfere with the software code, and therefore the authority of car-rental companies to control the content is limited;

  • Persons who rent vehicles are not aware that their personal data—such as identity and contact information, information regarding damage caused to the vehicle, and problems encountered during the payment process—are shared, via software including a blacklist feature, with an unknown number of users other than the car-rental company of which they are customers.

As is known, in Article 3 titled “Definitions” of the Law, paragraph (1)(ç) defines data subject as “the natural person whose personal data are processed,” paragraph (d) defines personal data as “any information relating to an identified or identifiable natural person,” paragraph (e) defines processing of personal data as “any operation which is performed on personal data, wholly or partially by automated means or non-automated means which provided that form part of a data filing system, such as collection, recording, storage, retention, alteration, re-arrangement, disclosure, transfer, taking over, making available for retrieval, classification, or preventing the use thereof,” and paragraph (ı) defines data controller as “the natural or legal person who determines the purposes and means of processing personal data and is responsible for establishment and management of the data filing system.”

In Article 5 titled “Conditions for processing of personal data,” paragraph (1) provides that personal data may not be processed without the explicit consent of the data subject; and paragraph (2) provides that, in cases where the conditions set forth in the laws are met, it shall be possible to process personal data without seeking the explicit consent of the data subject, if one of the following conditions exists: it is mandatory for the protection of the life or physical integrity of the person who is unable to express his consent due to actual impossibility or whose consent is not deemed legally valid, or of another person; it is necessary to process personal data of the parties to a contract, provided that it is directly related to the conclusion or performance of the contract; it is mandatory for the data controller to be able to fulfil its legal obligation; the data have been made public by the data subject; it is mandatory for the establishment, exercise or protection of a right; it is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.

Article 8 of the Law provides that “(1) Personal data cannot be transferred without the explicit consent of the data subject. (2) Personal data may be transferred without seeking explicit consent of the data subject if one of the conditions set forth in Article 5(2) and Article 6(3) is present, provided that adequate measures are taken. (3) Provisions contained in other laws regarding the transfer of personal data are reserved.”

On the other hand, Article 11 of the Law includes among the rights of the data subject the right “to object to a result against the person arising as a consequence of analysis of the processed data exclusively through automated systems,” as set forth in subparagraph (g) of paragraph (1).

Article 12 of the Law provides that data controllers are obliged to take all kinds of technical and administrative measures necessary to ensure an appropriate level of security for the purpose of preventing the unlawful processing of personal data, preventing unlawful access to personal data, and ensuring the safeguarding of personal data.

Pursuant to the relevant provisions of the Identity Notification Law No. 1774, there is an obligation to notify law-enforcement authorities of car-rental activities. Accordingly, the processing of personal data by car-rental companies in connection with entering data into the Rental Car Notification System (KABİS) may be assessed within the scope of the processing condition set forth in Article 5(2)(a) of the Law, “explicitly stipulated by laws,” as well as the processing condition set forth in subparagraph (ç), “it is mandatory for the data controller to be able to fulfil its legal obligation.”

Furthermore, since car-rental activity is carried out under a contract concluded between the parties, the processing of the personal data of data subjects by car-rental companies may be carried out within the scope of the processing condition set forth in Article 5(2)(c) of the Law, namely “it is necessary to process personal data of the parties to a contract, provided that it is directly related to the conclusion or performance of the contract.”

With respect to records such as blacklists, it is considered that there is a difference between processing personal data limited to business operations and making them available to other data controllers through software providers. Article 5(2)(f) of the Law regulates the processing condition “it is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.” Where, as a result of the balancing test to be conducted between the data subject’s fundamental rights and freedoms and the data controller’s legitimate interests, the legitimate interest prevails, keeping a blacklist record limited to business operations—i.e., within the body of the data controller—may, subject to separate assessment according to the concrete case, be applicable; however, it is considered that, where the personal data processed are made available to other data controllers (other car-rental companies) using the same software, the condition that the data subject’s fundamental rights and freedoms not be infringed cannot be met.

It is also considered that the sharing, by a car-rental company, of the personal data it processes with an unknown number of car-rental companies via software would contravene the General Principles set forth in Article 4 of the Law—namely “being processed lawfully and fairly,” “being processed for specific, explicit and legitimate purposes,” and “being relevant, limited and proportionate to the purposes for which they are processed.”

On the other hand, in the blacklist applications that are the subject of the tip-offs, the data controllers that collect the personal data of natural person customers firsthand are the car-rental companies. However, considering that access to the blacklist record is not limited to a single company and that other car-rental companies using the software can access the personal data transferred to the software and exercise control over the data, it is assessed that joint controllership between the car-rental companies that use the blacklist for their own interests and the software companies will arise.

For the purpose of determining the responsibilities of joint controllers and the degrees of fault, in any case, the data processing processes must be examined on a case-by-case basis; it will be necessary to identify by whom control over the data rests and who has control of the data. In determining fault among joint controllers, attention will be paid to factors such as who is the first and last user in the processing, who made the data entry, which party provided the data in question, who allowed the data to be changed or deleted or transferred, who granted access, and which data controllers other than the collecting party carried out which activities with these data.

Blacklist applications in the car-rental sector must also be evaluated in terms of the rights of the data subject. Since processing of personal data within the scope of a blacklist may lead to the use of the data subject’s personal data in a way that results in an adverse outcome for the person due to the very nature of blacklist practices, where a decision is made on the basis of this outcome, an adverse result will arise for the person as a consequence of profiling; however, since it may not be known which other car-rental companies the personal data of the relevant person renting the vehicle have been shared with, the exercise of the rights arising from Article 11 of the Law against these data controllers will become more difficult.

In light of all these assessments:

  • In cases where personal data are processed within the scope of blacklist applications in the car-rental sector in a manner contrary to the General Principles set forth in Article 4 of the Law, the processing conditions set forth in Article 5 of the Law, and the provisions regarding transfer set forth in Article 8 of the Law, the car-rental companies that have control over the data in question together with the software companies will be considered joint data controllers;

  • In order to put an end to such unlawful practices and ensure that personal data processing activities in the car-rental sector are in compliance with the Law, data controllers must take the necessary administrative and technical measures regulated under Article 12 of the Law;

  • The public shall be informed, within the framework of Article 18 of the Law, that administrative action will be taken against data controllers in the car-rental sector who, without taking the said measures and in violation of the provisions of the Law, carry out blacklist applications that are contrary to the Law;

  • Pursuant to Article 15(6) of the Law, it has been decided unanimously to publish this Principle Decision in the Official Gazette and on the Authority’s website.

8 — Principle Decision dated 21/04/2022 and numbered 2022/388 on the payment and debt-inquiry services of municipalities

Subject Summary: Principle Decision on the payment and debt-inquiry services of municipalities.

In various tip-offs conveyed to the Personal Data Protection Authority, it was stated that the fact that a citizen’s property information can be accessed by entering only the T.R. identity number on the property-tax payment/quick-payment or debt-inquiry pages offered online by municipalities poses a problem in terms of the protection of personal data, and it was requested that the matter be examined within the scope of the Personal Data Protection Law No. 6698 (the Law).

As is known, Article 12(1) of the Law provides: “The data controller is obliged to take all necessary technical and organizational measures to provide an appropriate level of security for the purposes of: a) preventing unlawful processing of personal data, b) preventing unlawful access to personal data, c) ensuring protection of personal data.” Paragraph (4) of the said article provides that data controllers and data processors may not disclose the personal data they have learned to others in breach of the provisions of the Law and may not use them outside the purpose of processing; and paragraph (5) provides that, where the processed personal data are obtained by others through unlawful means, the data controller shall notify this to the data subject and to the Board as soon as possible, and that the Board may, where necessary, announce this on its own website or by any other method it deems appropriate.

In this context, the Personal Data Security Guide (Technical and Administrative Measures), prepared by the Personal Data Protection Board and published on the Authority’s website in order to provide clarity in practice on the technical and administrative measures that data controllers must take in the course of processing personal data and to establish examples of good practice, lists the application of two-step authentication control, where personal data are accessed remotely in cases of necessity, among the measures to be taken to ensure security. Accordingly, where personal data are accessed remotely, it is necessary to use a two-stage inquiry system such that third parties cannot easily gain access; for example, while systems that grant access by querying a person’s T.R. identity number and birthday information are classified as single-step verification, systems in which access is granted by means of a password created specifically for the person, or an SMS code sent to the phone number the person has previously provided, in addition to the person’s T.R. identity number, are accepted as two-step verification.

Section 2.1 of the Personal Data Security Guide, titled “Technical and Administrative Measures Identification of Existing Risks and Threats”, also states: “In order to ensure the security of personal data, the data controller must first accurately determine what all the personal data it processes are, the probability of the risks that may arise in relation to the protection of these data materializing, and the losses they would cause if they materialized, and take measures accordingly. When determining these risks, whether the personal data are special categories of personal data, the degree of confidentiality they require by their nature, and the nature and extent of the damage that may arise for the data subject in the event of a security breach should be taken into account. After these risks have been identified and prioritized, control and solution alternatives for reducing or eliminating such risks should be evaluated in line with the principles of cost, feasibility and usefulness, and the necessary technical and administrative measures should be planned and put into practice.” Accordingly, it is important that, instead of single-step verification systems which carry the risk of persons’ information being easily accessed, inquiries be implemented with two-factor verification methods that will significantly reduce or eliminate this risk.

Within this framework, in order for the obligations under Article 12 of the Law to be fulfilled and any data breach to be prevented in respect of the services that municipalities offer online through pages such as property-tax payment/quick-payment or debt-inquiry pages, it is considered appropriate that, for two-factor verification, while the first verification is carried out with data such as the T.R. identity no., name and surname, tax no. or registration no., the second-level verification be carried out with a system such as a password created specifically for the person and sent by SMS or e-mail; and that, at the second level, instead of information relating to the person that others may also access, such as phone no., date of birth, mother’s and father’s names or registration no., the said services be offered through systems requesting data that will be determined specifically for the person and that only the data subject can access, or through a membership system.

In light of these assessments, it was unanimously decided:

  • that municipalities must take the necessary technical and administrative measures under Article 12 of the Law by using membership and password or two-factor verification in their property-tax payment/quick-payment and debt-inquiry services;

  • to inform the public that, in line with the complaints/tip-offs to be submitted concerning municipalities that do not take the said measures, action will be taken against the municipality concerned within the framework of the provisions of Article 18 of the Law;

  • to adopt a Principle Decision, under Article 15(6) of the Law, on the requirement that “membership and password” or “two-factor verification” be used under Article 12 of the Law in the property-tax payment/quick-payment and debt-inquiry services of municipalities, and to publish it in the Official Gazette and on the Authority’s website.

9 — Principle Decision dated 10/06/2025 and numbered 2025/1072 on the processing of personal data by sending verification codes to data subjects by SMS during the provision of products and services

Subject Summary: Personal Data Protection Board Principle Decision on the processing of personal data by sending verification codes to data subjects by SMS during the provision of products and services.

It is observed that a number of complaints and tip-offs conveyed to the Personal Data Protection Authority (Authority) contain allegations that, in processes relating to the provision of products and services (during payment, registration, membership creation, quotation creation and similar transactions), data subjects’ contact information is requested and a verification code is then sent to the data subjects by SMS; that the data subjects are asked to tell the said code to the staff member/enter it into the system on the ground that this is necessary to complete their payment, to generate an invoice, to send the invoice to their contact address or to update their information; but that, following the said transaction, commercial electronic messages relating to the activities of the data controller concerned are sent to the data subjects.

In the examinations carried out by the Personal Data Protection Board (Board) into the said complaints and tip-offs, it was established that, in processes relating to the provision of products and services (during payment, registration, membership creation, quotation creation and similar transactions), the data subjects were not informed in any way by the data controller or by the persons it authorized, either in the content of the SMS messages by which the verification codes were sent to them or before the SMS was sent, and/or that, although the said code was requested on the ground that it was necessary to complete payment transactions or to update their information, the data subjects were misled by the data controller obtaining, in this way, explicit consent to the sending of commercial electronic messages.

As is known:

  • Article 5 of the Personal Data Protection Law No. 6698 (the Law) sets out the conditions for processing personal data. Accordingly, after Article 5(1) of the Law provides that personal data may not be processed without the explicit consent of the data subject, Article 5(2) lists the processing conditions under which personal data may be processed without seeking the explicit consent of the data subject.

  • Article 3 of the Law defines explicit consent as “freely given, specific and informed consent”, and it is seen from this definition that there are three elements that explicit consent must bear. First, the explicit consent obtained must relate to a specific subject and be limited to that subject; in other words, the data controller must clearly set out the subject in respect of which the declaration of explicit consent is requested. If a declaration of explicit consent is to be made for the processing of data in more than one category, the explicit consent must also cover the different aspects of the processing, such as which data will be processed and for what purposes. Explicit consent is a declaration of will, and in order for a person to be able to consent freely, he or she must also know what he or she is consenting to; in this sense, the person must be fully informed not only about the subject but also about the consequences of his or her consent. Finally, explicit consent, being a declaration of will, will become valid if the person is aware of the conduct he or she performs and it is his or her own decision. Any circumstance that vitiates the person’s will, such as force, threat, mistake and fraud, will also vitiate the explicit consent given for the processing of personal data, and in such cases one cannot speak of a declaration of free will. Furthermore, where obtaining the data subject’s explicit consent is put forward as a precondition for providing a product or service or for allowing the use of a product or service, one cannot speak of valid explicit consent either, since the element of free will is impaired.

  • Pursuant to Article 10 of the Law, at the time personal data are obtained, the data controller or the person it has authorized must fulfil the obligation to inform by informing data subjects of the identity of the data controller and of its representative, if any; the purpose for which the personal data will be processed; to whom and for what purpose the processed personal data may be transferred; the method and legal basis of collection of personal data; and their other rights listed in Article 11 of the Law. In this context, the obligation to inform is an obligation that must be fulfilled independently both of obtaining explicit consent and of satisfying the other personal data processing conditions in the Law. However, where the personal data processing activity is carried out on the basis of the data subject’s explicit consent, the data controller must carry out the fulfilment of the obligation to inform and the obtaining of explicit consent separately. The information to be provided by data controllers must also comply with the provisions of the Communiqué on Principles and Procedures to be Followed in Fulfilment of the Obligation to Inform.

  • On the other hand, Article 12 of the Law sets out the obligations of data controllers concerning data security, and where these obligations are not fulfilled, the sanctions provided for in Article 18 of the Law must be applied to data controllers pursuant to the provisions of the Law.

In this context, as a result of the assessments made by the Board concerning the concrete situation, which is understood to be widely practised, it was decided that:

  • in processes relating to the provision of products and services (during payment, registration, membership creation, quotation creation and similar transactions), what the purpose of the SMS to be sent to data subjects’ phones is, and what consequences giving the code sent by that SMS will have, must, as a requirement of layered informing, be conveyed to data subjects clearly and comprehensibly by the data controller’s staff at the first stage, and, in order that the obligation to inform can be fulfilled, the necessary information channels must also be provided in the content of the said SMS messages;

  • practices aimed at carrying out, with a single action, processing activities distinct from one another—such as approving the membership agreement, obtaining permission to process personal data and obtaining approval for commercial electronic messages—by sending a verification code to data subjects by SMS must be ended, and explicit consent must be obtained from data subjects separately by offering options for the processing activities that must be carried out with explicit consent;

  • in addition, data controllers must carry out the obtaining of explicit consent and the fulfilment of the obligation to inform separately;

  • where a practice of sending an SMS verification code is adopted in order to obtain explicit consent for the sending of commercial electronic messages, the explicit consent to be obtained in that transaction must cover all the elements specified in the Law;

  • giving explicit consent to the processing of personal data for the purpose of sending commercial electronic messages must not be presented to data subjects as a mandatory element for completing the provision of the product or service, as otherwise the said practice may cause the elements of explicit consent of “being informed and being freely given” to be impaired; all processes must therefore be carried out in compliance with the Law;

  • in this context, explicit consent to the processing of personal data for the purpose of sending commercial electronic messages must be prevented from being perceived as a mandatory element of the provision of the product or service, by preferring the methods of requesting that explicit consent after the provision of the product or service has been completed, or of clearly stating—both in the SMS content and in the information provided by the data controller in the physical or digital environment—that consent given by sharing the said code with the staff member is not mandatory for completing the provision of the product or service, that the product or service can always be provided even if the code is not given, and that the permissions and preferences given by means of the code can be changed at any time;

  • in order to ensure the lawfulness of the said transactions, data controllers must periodically conduct the necessary training and awareness activities for the personnel involved in these processes.

Furthermore, Article 12(1) of the Law provides: “The data controller is obliged to take all necessary technical and organizational measures to provide an appropriate level of security for the purposes of: a) preventing unlawful processing of personal data, b) preventing unlawful access to personal data, c) ensuring protection of personal data.”

Within this framework, on the point that the matters set out above are among the administrative and technical measures that data controllers must take under Article 12(1) of the Law to ensure the lawful processing of personal data, and that, where it is established that the said matters have not been complied with, action will be taken against the data controllers concerned within the framework of the provisions of Article 18 of the Law, it was unanimously decided to inform the public and, in this context, to adopt a Principle Decision under Article 15(6) of the Law and publish it in the Official Gazette and on the Authority’s website.

10 — Principle Decision dated 06/11/2025 and numbered 2025/2120 on recording photocopies of the T.R. identity documents of persons receiving accommodation services in the tourism and hotel sector

Subject: Principle Decision on recording photocopies of the T.R. identity documents of persons receiving accommodation services in the tourism and hotel sector.

Because of its nature as a sector that serves people, the tourism and hotel sector is one of the sectors in which personal data are processed most intensively. In this vein, a number of complaints and tip-offs have been conveyed to the Personal Data Protection Authority (Authority) to the effect that photocopies of T.R. identity documents are taken from persons hosted at places of accommodation, and the need has arisen to inform the sector on this matter and for the Personal Data Protection Board (Board) to adopt a Principle Decision on the subject.

Within this framework, when the provisions of the legislation are examined:

  • Article 5 of the Personal Data Protection Law No. 6698 (the Law) sets out the conditions for processing personal data; paragraph one of that article provides that personal data may not be processed without the explicit consent of the data subject, and paragraph two provides that personal data may be processed without seeking the data subject’s explicit consent where one of the conditions set out therein (-It is expressly provided for by the laws, -It is necessary for the protection of life or physical integrity of the person himself/herself or of any other person, who is unable to explain his/her consent due to the physical disability or whose consent is not deemed legally valid, -Processing of personal data of the parties of a contract is necessary, provided that it is directly related to the establishment or performance of the contract, -It is necessary for compliance with a legal obligation to which the data controller is subject, -Personal data have been made public by the data subject himself/herself, -Data processing is necessary for the establishment, exercise or protection of any right, -Processing of data is necessary for the legitimate interests pursued by the data controller, provided that this processing shall not violate the fundamental rights and freedoms of the data subject) exists.

  • Pursuant to Article 6 of the Law: (1) Personal data relating to the race, ethnic origin, political opinion, philosophical belief, religion, religious sect or other belief, appearance, membership to associations, foundations or trade-unions, data concerning health, sexual life, criminal convictions and security measures, and the biometric and genetic data are deemed to be special categories of personal data. (2) (Repealed: 2/3/2024- Art. 7499/33) (3) (Amended: 2/3/2024- Art. 7499/33) It is prohibited to process special categories of personal data. However, such processing is permitted under the following conditions: a) Data subject has given his/her explicit consent, b) It is explicitly provided by laws, c) It is necessary for the protection of life or physical integrity of the person himself/herself or of any other person who is unable to explain his/her consent due to the physical disability or whose consent is not deemed legally valid, ç) It relates to personal data that have been made public by the data subject, and processing is in consistent with data subject’s intention to make such data public, d) It is necessary for the establishment, exercise or protection of any right, e) It is necessary for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, and for the planning, management and financing of health-care services by persons subject to legal obligation of confidentiality or by competent public institutions and organizations, f) It is necessary for the fulfilment of legal obligations in the fields of employment, occupational health and safety, social security, social services, and social assistance, g) It relates to the current or former members and affiliates of foundations, associations, and other non-profit organizations established for political, philosophical, religious, or trade union purposes, or to individuals who are in regular contact with these organizations, provided that such processing complies with the applicable legislation governing these organizations and their objectives, is limited to the organizations’ fields of activity, and does not involve disclosure of data to third parties. (4) Adequate measures, as determined by the Board, shall also be implemented in the processing of special categories of personal data.

  • Article 2 of the Identity Notification Law No. 1774 provides: “The responsible operators of hotels, motels, inns, guesthouses, bachelor rooms, houses rented by the day, camps, campsites, holiday villages and all similar private or official places of accommodation, and of private health establishments, rest homes and retirement homes, and the social facilities of religious and charitable institutions, are obliged to keep, day by day and in conformity with the model and procedure, the identity and arrival-departure records of every person, domestic or foreign, to whom they provide a place to sleep in these places, whether for a fee or free of charge, by day or by night, to keep them ready at all times for inspection by the general law-enforcement organizations, and to provide them to the State Institute of Statistics upon request.”

  • Article 5, titled “Registration”, of the Regulation on the Implementation of the Identity Notification Law provides: “Those who are obliged under the provisions of this Regulation to submit identity notification documents to the nearest competent general law-enforcement organization may not accommodate in their facilities, or employ in their homes and workplaces, persons who cannot prove their identity with a population identity card or other officially valid documents.”; and Article 23, titled “Obliged Party”, of the same Regulation provides: “By the responsible operators of the places listed in Article 6 of the Regulation, the identity and the dates of arrival and departure of every person, domestic or foreign, to whom a place to sleep is provided there, whether for a fee or free of charge, by day or by night, are entered day by day in the Accommodation Place Register (Form:7).
    Persons who will stay in these places must fill in and sign one copy of the Accommodation Document (form:8), with carbon copies, to be given to them, and hand it to the responsible operator.
    The information in the accommodation document is transferred to the accommodation place register after being compared with the valid official document establishing the person’s identity.”

When an overall assessment is made within the framework of the provisions of the legislation set out above, it is clear that the personal data processing activity consisting of recording, from data subjects receiving accommodation services at the said places, identity information composed of name, surname and T.R. identity number is carried out, in line with the express provisions of the Identity Notification Law No. 1774 and the Regulation on the Implementation of the Identity Notification Law, within the framework of the conditions in subparagraph (a), “It is expressly provided for by the laws”, and subparagraph (ç), “It is necessary for compliance with a legal obligation to which the data controller is subject”, of Article 5 of Law No. 6698, and is therefore a lawful processing activity.

That said, it must be emphasized that verifying the accuracy of the personal data processed from persons staying at the relevant places by comparing them with an official document, and requesting the T.R. identity document for this purpose, is lawful and, at the same time, required by the nature of things. However, the personal data processing activity consisting of also taking and recording a photocopy of the T.R. identity document after it has been requested, even if for verification purposes, results in processing more data than necessary, and, moreover, this processing activity has no legal basis whatsoever. It is therefore concluded that recording photocopies of the T.R. Identity Documents of data subjects is an unlawful processing activity under Law No. 6698.

In addition, as is known, in our country, from 2 January 2017 onwards, the old population identity cards have been replaced and a transition has been made to the chip-bearing identity card. However, population identity cards can still continue to be used at present. Therefore, considering that the population identity card also carries special categories of personal data of persons, such as religion and blood group, it is essential to state that, where data controllers record photocopies of data subjects’ population identity cards on account of accommodation, they engage in a processing activity that additionally constitutes a breach of Article 6 of the Law.

On the other hand, since the tourism and hotel sector generally involves the sale of a service relating to accommodation, it is also possible to process data subjects’ personal data for invoicing purposes. In this context, the relevant provisions of the legislation are as follows:

  • Article 230 of the Tax Procedure Law No. 213: “The invoice shall contain at least the following information:
    1. The date of issue and the series and sequence number of the invoice;
    2. The name, trade name if any, business address, tax office and account number of the person issuing the invoice;
    3. The name, trade name and address of the customer, and the tax office and account number, if any;
    4. The type, quantity, price and amount of the goods or work;
    5. (Amended: 4/12/1985- Art. 3239/19) The delivery date of the goods sold and the waybill number, (Where the goods are carried, or caused to be carried, by the seller for delivery to the buyer, the seller, and where the delivered goods are carried, or caused to be carried, by the buyer, the buyer, must issue a dispatch note for the goods carried or caused to be carried and keep it in the vehicle.”

  • Article 240, titled “Documents pertaining to transport and hotel businesses”, of the same Law: “…
    C) Daily customer lists: Places of accommodation such as hotels, motels and guesthouses shall draw up daily customer lists bearing consecutive series and sequence numbers in accordance with the plans of rooms, sections and beds, and shall keep them at the business.
    These lists shall contain the following information:
    1. The name, surname, title if any, and address of the taxpayer,
    2. The name and surname of the customer and the room rate, with the room numbers being written,
    3. Date of issue.”

In this context, within the framework of the above-cited articles of the Tax Procedure Law No. 213, the activity of processing the personal data of data subjects set out in the said article is a lawful processing activity within the framework of the condition “It is expressly provided for by the laws” in subparagraph (a) of Article 5 of Law No. 6698.

In conclusion, as a result of the assessment made by the Board, it was concluded that:

  • data controllers providing services in the field of tourism and hotels must end the practice of taking photocopies of T.R. identity documents from persons hosted at places of accommodation;

  • data controllers that recorded photocopies of the T.R. Identity Documents of data subjects who received services for accommodation purposes before the publication of the Principle Decision must destroy such documents in accordance with Article 7 of the Law.

As is known, Article 12(1) of the Law provides: “The data controller is obliged to take all necessary technical and organizational measures to provide an appropriate level of security for the purposes of: a) preventing unlawful processing of personal data, b) preventing unlawful access to personal data, c) ensuring protection of personal data.”; and Article 15(6) of the Law provides: “As a result of the examination made upon complaint or ex officio, in cases where it is determined that the infringement is widespread, the Board shall take a resolution on this matter and publishes this resolution”.

Within this framework, it was unanimously decided to inform the public and sector representatives that the matters set out above are among the administrative and technical measures that data controllers must take under Article 12(1) of the Law to ensure the lawful processing of personal data, and that where it is established that the said matters have not been complied with, action will be taken against the data controllers concerned within the framework of the provisions of Article 18 of the Law, and, in this context, to adopt a Principle Decision under Article 15(6) of the Law and publish it in the Official Gazette and on the Authority’s website.

11 — Principle Decision dated 11/02/2026 and numbered 2026/266 on the use, by a third party during shopping, of the mobile phone number or loyalty card number of a person holding a loyalty card membership

Subject: Principle Decision on the use, by a third party during shopping, of the mobile phone number or loyalty card number of a person holding a loyalty card membership.

Tip-offs and complaints have been conveyed to the Personal Data Protection Authority (Authority) through various channels alleging that, within the scope of the Loyalty Card Programs run by data controllers in various sectors, purchases are made by a third party sharing, during shopping, the mobile phone number of the data subject who holds the loyalty card with the cashier; that this purchase transaction via the loyalty card is carried out by the cashier without any transaction approval code being entered into the system; that, although the data subject is not at the checkout during the purchase transaction and has neither knowledge of it nor consent to it, the data controller enables purchases to be made via the loyalty card using the data subject’s personal data, by way of the third party sharing the data subject’s mobile phone number; and, furthermore, that an unlawful data processing activity is carried out and personal data security is breached by an invoice or similar document relating to the purchase being issued in the name of the data subject; and the need has arisen for the Personal Data Protection Board (Board) to adopt a Principle Decision on the matter.

As a result of the research conducted on the matter, it was established that:

  • the practice in question is widespread within the scope of loyalty card membership programs run by data controllers operating in various sectors such as food, cosmetics, technology, DIY stores and clothing;

  • in general, the loyalty card is issued by data controllers, within the framework of a membership agreement, for the personal use of data subjects;

  • loyalty card membership is carried out by using methods such as sending a one-time verification code by SMS to the data subject’s mobile phone number, or scanning a barcode/QR code provided through a mobile application/website;

  • purchases can be made via the loyalty card, and discounts and promotions can be benefited from, by stating the data subject’s mobile phone number or loyalty card number to the staff member at the checkout;

  • for the use of the loyalty card during shopping for purposes such as discounts, promotions and earning points, the practice whereby a purchase transaction can be carried out via the loyalty card merely by stating the data subject’s mobile phone number or loyalty card number to the staff member at the checkout, without data controllers establishing any verification mechanism as to whether the purchase is made by the data subject in person or with the data subject’s knowledge and approval, is widespread;

  • on the other hand, in transactions relating to the spending of points earned through use of the loyalty card, verification mechanisms established by using methods such as stating to the cashier the one-time verification code sent by SMS to the data subject’s mobile phone number, or scanning at the checkout the barcode/QR code provided through a mobile application/website, are widely used;

  • the invoice or similar document issued as a result of a purchase transaction carried out via the loyalty card is frequently issued in the name of the data subject holding the loyalty card, and customer transaction information relating to the purchase (the product/service purchased, the date of purchase, etc.) is entered among the records relating to the data subject; therefore, where the mobile phone number or loyalty card number of the data subject holding the loyalty card is used in shopping by a third party without the data subject’s knowledge and consent, personal data breaches may occur through incorrect customer transaction information being entered in the records/membership account of the data subject, or through an invoice being issued in the name of the data subject for a purchase that he or she did not make and of which he or she has no knowledge and to which he or she has not consented.

When the relevant provisions of the legislation are examined:

  • Article 4, titled “General Principles”, of the Personal Data Protection Law No. 6698 (the Law) provides that personal data may be processed only in accordance with the procedures and principles laid down in the Law and in other laws, and that compliance with the principles of “lawfulness and fairness”, “being accurate and kept up to date where necessary”, “being processed for specified, explicit and legitimate purposes”, “being relevant, limited and proportionate to the purposes for which they are processed” and “being stored for the period laid down by relevant legislation or the period required for the purpose for which the personal data are processed” is mandatory in the processing of personal data.

  • Paragraph (1) of Article 5, titled “Conditions for processing personal data”, of the Law provides that personal data may not be processed without the explicit consent of the data subject; and paragraph (2) provides that personal data may be processed without seeking the data subject’s explicit consent where one of the conditions “it is expressly provided for by the laws”, “it is necessary for the protection of life or physical integrity of the person himself/herself or of any other person, who is unable to explain his/her consent due to the physical disability or whose consent is not deemed legally valid”, “processing of personal data of the parties of a contract is necessary, provided that it is directly related to the establishment or performance of the contract”, “it is necessary for compliance with a legal obligation to which the data controller is subject”, “personal data have been made public by the data subject himself/herself”, “data processing is necessary for the establishment, exercise or protection of any right”, “processing of data is necessary for the legitimate interests pursued by the data controller, provided that this processing shall not violate the fundamental rights and freedoms of the data subject” exists.

  • Paragraph (1) of Article 12, titled “Obligations concerning data security”, of the Law provides that the data controller is obliged to take all kinds of technical and administrative measures necessary to ensure an appropriate level of security for the purpose of preventing the unlawful processing of personal data, preventing unlawful access to personal data and ensuring the safeguarding of personal data.

Within this framework, as a result of the assessments made by the Board, in line with the research conducted and also by obtaining the opinions of representatives of various sectors, regarding the practice in question, which is understood to be widespread within the scope of Loyalty Card Programs, it was assessed that:

  • carrying out a purchase transaction in the name of the data subject by a third party stating the data subject’s mobile phone number or loyalty card number, without his or her knowledge and consent, to the person on duty at the checkout during shopping cannot be based on any of the data processing conditions in Article 5 of the Law and will give rise to an unlawful personal data processing activity;

  • the personal data processing activity consisting of issuing an invoice or similar document in the name of the data subject, and/or entering customer transaction information (from which store, on which date, which product was purchased, etc.) in the records/membership account relating to the data subject, in respect of a purchase transaction carried out using the data subject’s mobile phone number or loyalty card number that was not made by the data subject in person and of which he or she has no knowledge and to which he or she has not consented, will constitute a breach of the principle of “being accurate and kept up to date where necessary” laid down in Article 4 of the Law;

  • although data controllers, under the Loyalty Card Membership Agreement, place on data subjects the responsibility of not allowing third parties to use the loyalty card issued for their personal use, this does not remove the obligation, laid down in Article 12 of the Law, to ensure personal data security in the personal data processing activities carried out by data controllers;

and it was unanimously decided:

  • that the practice, assessed as unlawful under the Law, which enables a purchase transaction to be made via the loyalty card by a third party stating the data subject’s mobile phone number or loyalty card number to the staff member at the checkout during shopping, outside the data subject’s knowledge and consent, be ended;

  • that, in order to ensure that personal data processing processes relating to purchase transactions carried out via the loyalty card comply with the Law, data controllers must take the necessary technical and administrative measures laid down in Article 12 of the Law;

  • that, in order to verify that a purchase transaction carried out by stating the mobile phone number or loyalty card number of the data subject holding the loyalty card to the cashier takes place with the data subject’s knowledge and consent, data controllers must establish verification mechanisms by using methods such as: stating to the cashier the one-time verification code sent by SMS to data subjects’ mobile phone numbers for the use of loyalty cards for any purpose (creating a membership, earning points on purchases, using points, benefiting from discounts/promotions, etc.); scanning at the checkout the barcode/QR code provided through a mobile application/website; presenting/scanning the physical loyalty card at the checkout; entering the loyalty card password into the transaction device at the checkout; and offering data subjects, as an “opt-in”, a choice, via the online membership account created under the loyalty card programs, as to which transactions (earning points on purchases/benefiting from discounts or promotions/spending points) they approve being carried out during shopping when the loyalty card is used merely by stating the mobile phone number;

  • that, considering that the fundamental aim is the use of the most appropriate verification methods aimed at preventing personal data breaches that may occur in personal data processing activities carried out through the use during shopping, by a third party and without the data subject’s knowledge and consent, of the mobile phone number or loyalty card number of a data subject holding a loyalty card membership, data controllers must prefer verification mechanisms that will serve this aim; that, in this context, alternative verification mechanisms may be offered for different groups of data subjects; and that different verification mechanisms may be used in the loyalty card scheme according to different types of transaction, such as membership verification, earning points/discounts/promotions and spending points, and according to the risk level of those transactions;

  • that data controllers be granted a compliance period of 6 months from the date of publication of this Principle Decision to establish the said verification mechanisms;

  • that the public and sector representatives be informed that action will be taken, within the framework of the provisions of Article 18 of the Law, against data controllers that, by not taking the said measures, continue this practice in breach of the provisions of the Law and are found not to have acted in accordance with the matters set out in this Principle Decision;

  • that this Principle Decision, adopted pursuant to Article 15(6) of the Law, be published in the Official Gazette and on the Authority’s website.

Subject: Principle Decision on the requirement that explicit consent texts and privacy notices be drawn up separately by data controllers.

Presenting the explicit consent text and the privacy notice to data subjects intertwined with one another is seen as one of the most frequently encountered instances of unlawfulness in the tip-offs and complaints conveyed to the Personal Data Protection Authority (Authority).

The obligation to inform laid down in Article 10 of the Personal Data Protection Law No. 6698 (the Law) essentially means informing the data subjects whose personal data are processed. Explicit consent, on the other hand, is one of the processing conditions provided for in the Law for personal data to be processed lawfully. Accordingly, the need has arisen to inform the public that explicit consent texts and privacy notices, which by their nature correspond to different concepts, must be drawn up as separate texts, and for the Personal Data Protection Board (Board) to adopt a Principle Decision on the matter.

Within this framework, looking at the provisions of the legislation relevant to the subject:

  • Paragraph three of Article 20 of the Constitution provides that personal data may be processed only in cases provided for by law or with the person’s explicit consent.

  • Article 5 of Law No. 6698 lists obtaining explicit consent among the personal data processing conditions for the processing of personal data, and Article 6 does so for the processing of special categories of personal data.

Explicit consent is defined in Article 3 of the Law as “freely given, specific and informed consent”. Within the scope of this definition, explicit consent means the freely given, subject-specific, informed and unambiguous consent of the data subject showing that he or she permits/approves the processing of personal data relating to him or her.

In explicit consent texts, data subjects must declare that they give explicit consent to the processing of their personal data on the basis of the purposes and legal bases set out in the text. Moreover, the burden of proving that explicit consent has been obtained in compliance with the Law rests with the data controller.

The obligation to inform, for its part, is set out in Article 10 of the Law as follows: “(1) At the time when personal data are obtained, the data controller or the person authorised by it is obliged to inform the data subjects about the following: a) the identity of the data controller and of its representative, if any, b) the purpose of processing of personal data; c) to whom and for which purposes the processed personal data may be transferred, ç) the method and legal basis of collection of personal data, d) other rights referred to in Article 11.” The purpose of the obligation to inform consists solely of informing data subjects about the personal data processed and the processing activities, and privacy notices are not contractual in nature. Therefore, instead of the statements placed at the end of the text in the form “I have read and accept”, “I have read and give explicit consent” or “I have read and approve”, which are among the errors frequently made in privacy notices, making a declaration in the form “I have read and understood”, to the effect that the privacy notice has been read and understood by the data subject, will constitute lawful usage at this stage. Furthermore, the burden of proving that the obligation to inform has been fulfilled also rests with the data controller.

Art. 5(1)(f) of the Communiqué on Principles and Procedures to be Followed in Fulfilment of the Obligation to Inform (“Communiqué”) provides: “During the fulfilment of the obligation to inform by the data controller or the person it has authorized through the use of a physical or electronic medium such as oral, written, voice recording or call centre, the procedures and principles listed below must be complied with: Where the personal data processing activity is carried out on the basis of the explicit consent condition, the obligation to inform and the obtaining of explicit consent must be carried out separately.”

In this context, the obligation to inform, which does not depend on a request by the data subject or on any approval, must be fulfilled by data controllers in every case (before personal data processing begins), irrespective of which of the processing conditions listed in the Law, including explicit consent, the personal data processing activity is based on. Where the personal data processing activity is carried out on the basis of the explicit consent condition, the privacy notice and the explicit consent text must be drawn up separately and presented to data subjects. Even if the said texts are to appear on a single page, since the declarations to be made by data subjects differ in nature, the two texts must appear separately, one below the other, and separate declarations must be made for each of the two texts.

On the other hand, in practice, instances of unlawfulness such as:

  • presenting explicit consent texts and privacy notices intertwined as a single text,

  • requesting approval/consent from data subjects to the effect that they have been informed,

  • data controllers using texts drawn up by another data controller verbatim, without adapting them to their own activities,

  • failing to use clear, comprehensible and plain language in privacy notices, and including information that is general in nature, open to different interpretations, incomplete, misleading to data subjects or false (for example, using expressions that create the impression that a transfer abroad is made when no transfer abroad is made, or including vague statements such as “your personal data are processed within the scope of the processing conditions set out in Articles 5 and 6 of the Law”)

  • using very detailed, complex and long texts,

are frequently identified.

Accordingly, it is brought to the attention of the public that:

  • the obligation to inform, which does not depend on a request by the data subject or on any approval, must be fulfilled by data controllers in every case (before personal data processing begins), irrespective of which of the processing conditions listed in the Law, including explicit consent, the personal data processing activity is based on;

  • where the personal data processing activity is carried out on the basis of the explicit consent condition, the privacy notice and the explicit consent texts must be drawn up as separate texts under different headings;

  • where the privacy notice and the explicit consent texts are on the same page, they must be drawn up under different headings (one below the other) and in such a way that separate declarations are made for the two texts;

  • where the personal data processing activity is carried out on the basis of any of the other processing conditions listed in the Law apart from the explicit consent condition, only the obligation to inform must be fulfilled, and an explicit consent text must not additionally be presented to data subjects;

  • only feedback that the privacy notice has been read and that information has been obtained must be taken from data subjects, and approval/consent must not be requested for the statements in the privacy notice;

  • texts drawn up by another data controller must not be used verbatim, and texts must be drawn up by each data controller in a manner appropriate to its own organization and activities;

  • clear, comprehensible and plain language must be used in the texts, and information that is general in nature, open to different interpretations, incomplete, misleading to data subjects or false must not be included;

  • very detailed, complex and long texts must not be used (for example, since including the whole of Article 11 of the Law would make the text longer, the rights must be referred to as “your rights under Article 11 of the Law”);

  • the personal data processed and their categories, together with the purpose and legal basis of the personal data processing activity, must be stated clearly and unambiguously in privacy notices.

Article 12(1) of the Law provides: “The data controller is obliged to take all necessary technical and organizational measures to provide an appropriate level of security for the purposes of: a) preventing unlawful processing of personal data, b) preventing unlawful access to personal data, c) ensuring protection of personal data.”; and Article 15(6) of the Law provides: “As a result of the examination made upon complaint or ex officio, in cases where it is determined that the infringement is widespread, the Board shall take a resolution on this matter and publishes this resolution”.

Within this framework, it was unanimously decided to inform the public that the matters set out above are among the administrative and technical measures that data controllers must take under Article 12(1) of the Law to ensure the lawful processing of personal data, and that, where it is established that the said matters have not been complied with, action will be taken against the data controllers concerned pursuant to the provisions of Article 18 of the Law; and, in this context, to adopt a Principle Decision under Article 15(6) of the Law on the requirement that explicit consent texts and privacy notices be drawn up separately by data controllers, and to publish the said Principle Decision, in the form set out in the annex to the Decision, in the Official Gazette and on the Authority’s website.

Annexes:

  1. Good Practice Templates

  2. Bad Practice Template

Annex 1: Good Practice Template

(..Title/name of the data controller..)
PRIVACY NOTICE ON THE PROCESSING AND PROTECTION OF PERSONAL DATA

This text has been prepared by (..title/name of the data controller..) in order to fulfil the obligation to inform concerning the processing of the personal data of customers shopping at our clothing stores, within the scope of Article 10 of the Personal Data Protection Law No. 6698 (KVKK).

1. IDENTITY OF THE DATA CONTROLLER: Title, MERSİS Number, Address, Telephone, E-mail, Registered Electronic Mail (KEP)

2. PERSONAL DATA PROCESSED, PURPOSE AND LEGAL BASIS OF PROCESSING

3. PURPOSE OF TRANSFER OF PERSONAL DATA AND RECIPIENT GROUPS

4. METHOD OF COLLECTING PERSONAL DATA

5. YOUR RIGHTS UNDER THE KVKK: You may at any time submit your requests under Article 11 of the KVKK concerning your personal data processed by us to the addresses below, in accordance with the Communiqué on the Principles and Procedures for the Request to Data Controller, in writing or by using a registered electronic mail (KEP) address, a secure electronic signature, a mobile signature or the e-mail address that you have previously notified to us and that is registered in our system: e-mail: KEP: Address:

Date of update: …

I have read and understood the privacy notice concerning the processing of my personal data.
Name-Surname/Signature/Date

EXPLICIT CONSENT TEXT

As (..title/name of the data controller..), if you give your explicit consent, we would like to inform you regarding … processes.

If you give your explicit consent to the processing of your personal data, your personal data are collected and processed for the purposes of … . We inform you that, if you give explicit consent, you may withdraw the explicit consent you have given at any time.

To the processing and sharing of my personal data for the purpose of …
I give explicit consent
I do not give explicit consent

Name/Surname
Signature
Date

Annex 1: Good Practice Template (Single Page)

(..Title/name of the data controller..)
PRIVACY NOTICE ON THE PROCESSING AND PROTECTION OF PERSONAL DATA

This text has been prepared by (..title/name of the data controller..) in order to fulfil the obligation to inform concerning the processing of the personal data of customers shopping at our clothing stores, within the scope of Article 10 of the Personal Data Protection Law No. 6698 (KVKK).

1. IDENTITY OF THE DATA CONTROLLER: Title, MERSİS Number, Address, Telephone, E-mail, Registered Electronic Mail (KEP)

2. PERSONAL DATA PROCESSED, PURPOSE AND LEGAL BASIS OF PROCESSING

3. PURPOSE OF TRANSFER OF PERSONAL DATA AND RECIPIENT GROUPS

4. METHOD OF COLLECTING PERSONAL DATA

5. YOUR RIGHTS UNDER THE KVKK: You may at any time submit your requests under Article 11 of the KVKK concerning your personal data processed by us to the addresses below, in accordance with the Communiqué on the Principles and Procedures for the Request to Data Controller, in writing or by using a registered electronic mail (KEP) address, a secure electronic signature, a mobile signature or the e-mail address that you have previously notified to us and that is registered in our system: e-mail: KEP: Address:
Date of update: …

I have read and understood the privacy notice concerning the processing of my personal data.
Name-Surname/Signature/Date

EXPLICIT CONSENT TEXT

As (..title/name of the data controller..), if you give your explicit consent, we would like to inform you regarding … processes.

If you give your explicit consent to the processing of your personal data, your personal data are collected and processed for the purposes of … . We inform you that, if you give explicit consent, you may withdraw the explicit consent you have given at any time.

To the processing and sharing of my personal data for the purpose of …
I give explicit consent
I do not give explicit consent

Name-Surname/Signature/Date

Annex 2: Bad Practice Template

PRIVACY NOTICE CONCERNING EXPLICIT CONSENT
(Where explicit consent is obtained, the explicit consent text and the privacy notice must be drawn up separately.)

1. Introduction
This privacy notice has been prepared within the scope of Article 10 of the Personal Data Protection Law No. 6698 (the Law) and the Communiqué on Principles and Procedures to be Followed in Fulfilment of the Obligation to Inform (the Communiqué). (The identity of the data controller has not been included.)

2. Which of Your Personal Data Are Processed?
In accordance with the Law and other relevant legislation, the following personal data of yours will be processed within the scope of the purposes and legal bases set out in the Privacy Notice: your user account information, your customer transaction information, your delivery information, your payment information, your transaction security information. (The personal data under the categories have not been listed clearly and explicitly.)

3. What Are the Purposes of Processing Your Personal Data, the Methods of Collecting Your Personal Data and the Legal Bases?
Your personal data are collected by our Company, by fully or partially automated means or by non-automated means provided that they form part of a data filing system, in electronic form via the websites belonging to our Company; in electronic form via live help, call centre or e-mail channels; and in physical form where they are conveyed to our Company by printed forms, notification or post, or are served by legal authorities. Your processed personal data are processed within the scope of Articles 5 and 6 of the Law.
Processes Based on Explicit Consent: Your account, customer transaction, delivery and payment information are processed on the legal basis of the data subject’s explicit consent, for the purposes of carrying out activities aimed at developing products and services and of being able to present advantageous and special offers to you. (The processing conditions on which the personal data processing activities are based have not been stated clearly and explicitly. Although information has been given on processes based on explicit consent, no separate explicit consent text has been drawn up.)

4. Transfer of Personal Data
Your personal data are shared by our Company with the relevant party within the country. (The processing conditions on which the personal data transfer activity is based have not been stated clearly and explicitly. The recipient groups to which transfers are made have not been stated clearly and explicitly.)

5. Your Rights Regarding the Protection of Your Personal Data
By applying to our Company through the methods set out in the “Contact for Your Rights and Requests” section of this privacy notice, you have, under Article 11 of the Law, the rights to learn whether your personal data are processed; to request information about it if they have been processed; to learn the purpose of processing of your personal data and whether they are used in accordance with their purpose; to know the third parties to whom they are transferred within the country or abroad; to request the rectification of your personal data if they have been processed incompletely or inaccurately; to request the erasure or destruction of your personal data within the framework of the conditions laid down in the Law; to request that the operations carried out pursuant to your above-mentioned rights of rectification, erasure and destruction be notified to the third parties to whom the personal data have been transferred; to object to the occurrence of a result to your detriment through the analysis of your processed personal data exclusively by automated systems; and to request the compensation of your damage if you suffer damage due to the processing of your personal data in breach of the relevant legislation.

6. Contact
You may submit your questions and requests concerning your personal data in accordance with the conditions set out in the Communiqué on the Principles and Procedures for the Request to Data Controller. (Adequate guidance has not been given, and the identity and address details of the data controller have not been included.)

I have read and accept the privacy notice concerning the processing of my personal data.
(Although this is a privacy notice, the route of obtaining explicit consent from data subjects has been taken.)
Name-Surname/Signature/Date

13 — Principle Decision dated 18/02/2026 and numbered 2026/348 on posting the debt information of apartment/housing-complex residents in the common areas of collective buildings

Subject: Principle Decision on posting the debt information of apartment/housing-complex residents in the common areas of collective buildings.

As is known, various personal data processing activities are carried out in apartment/housing-complex management processes. In this context, it is known that, in particular for the purposes of making announcements concerning the dues/advances/fixture expenses and similar debts of apartment residents and informing the other apartment residents, lists/documents containing information qualifying as personal data, such as these persons’ first name, surname, flat number information, amount of the debt, length of the payment delay, number of periods of payment delay and flat ownership/tenancy information, are posted in common areas such as elevators, building entrances and building corridors; and it has become necessary to inform the public on this matter and for the Personal Data Protection Board (Board) to take a principle decision on the subject.

Within this framework, when the provisions of the relevant legislation are examined;

  • In Article 3(1)(d) of the Personal Data Protection Law No. 6698 (Law), “personal data” is defined as “any information relating to an identified or identifiable natural person”; in subparagraph (e), “processing of personal data” as “any operation which is performed on personal data, wholly or partially by automated means or non-automated means which provided that form part of a data filing system, such as collection, recording, storage, protection, alteration, adaptation, disclosure, transfer, retrieval, making available for collection, categorization, preventing the use thereof”; in subparagraph (ğ), “data processor” as “the natural or legal person who processes personal data on behalf of the data controller upon its authorization”; in subparagraph (h), “data filing system” as “the system where personal data are processed by being structured according to specific criteria”; and in subparagraph (ı), “data controller” as “the natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data filing system”.

  • Article 4 of the Law, titled “General Principles”, provides that personal data may only be processed in compliance with the procedures and principles laid down in this Law and in other laws, and that it is mandatory, in the processing of personal data, to comply with the principles listed as “a) Lawfulness and fairness. b) Being accurate and kept up to date where necessary. c) Being processed for specified, explicit and legitimate purposes. ç) Being relevant, limited and proportionate to the purposes for which they are processed. d) Being stored for the period laid down by relevant legislation or the period required for the purpose for which the personal data are processed.” As is clearly understood from the said provision, compliance with the general principles listed in Article 4 of the Law in the processing of personal data is a legal requirement in all cases and circumstances. In this context, it should be noted that, according to the principle of personal data “being relevant, limited and proportionate to the purposes for which they are processed”, the personal data processed must be suitable for achieving the specified purposes, and personal data that are not related to the achievement of the purpose of processing must not be processed. The principle of proportionality, in turn, means establishing a reasonable balance between the processing of personal data and the purpose sought to be achieved, that is, that the processing of personal data be to the extent that achieves the purpose.

  • Article 5 of the Law, in turn, provides that personal data may not be processed without the explicit consent of the data subject and, in its second paragraph, that it is possible to process personal data without seeking the explicit consent of the data subject where one of the conditions set out in that paragraph (-It is expressly provided for by the laws, -It is necessary for the protection of life or physical integrity of the person himself/herself or of any other person, who is unable to explain his/her consent due to the physical disability or whose consent is not deemed legally valid, -Processing of personal data of the parties of a contract is necessary, provided that it is directly related to the establishment or performance of the contract, -It is necessary for compliance with a legal obligation to which the data controller is subject, -Personal data have been made public by the data subject himself/herself, -Data processing is necessary for the establishment, exercise or protection of any right, -Processing of data is necessary for the legitimate interests pursued by the data controller, provided that this processing shall not violate the fundamental rights and freedoms of the data subject) exists.

  • Article 12(1) of the Law, titled “Obligations concerning data security”, provides that the data controller is obliged to take all necessary technical and administrative measures to ensure an appropriate level of security for the purposes of preventing the unlawful processing of personal data and unlawful access to personal data and ensuring the protection of personal data. At this point it should be noted that the obligation “…preventing unlawful processing of personal data…” arising from Article 12(1) of the Law requires that personal data be processed on the basis of a valid personal data processing condition, by relying on any of the legal grounds regulated in the Law according to the type of personal data processed; and, under the obligation “…preventing unlawful access to personal data…” arising from the same paragraph, data controllers must take the necessary technical and administrative measures to prevent the personal data they process from being shared with unauthorised third parties. The obligation “Ensuring protection of personal data…”, in turn, means ensuring compliance with the Law in all processes relating to the processing of personal data and preventing sharing and access that would in any way constitute a breach of the provisions of the Law.

  • As regards the Condominium Law No. 634 (Law No. 634);

  • Article 18 of Law No. 634, titled “Obligations of condominium owners”, provides: “Condominium owners are mutually obliged, when using both their independent units and the annexes and common areas, to abide by the rules of honesty, in particular not to disturb one another, not to infringe one another’s rights, and to comply with the provisions of the management plan.

    The provisions of this law concerning the obligations of condominium owners shall also apply to tenants and holders of the right of residence (sükna) in independent units, or to those who benefit from these units on a continuous basis in any manner; those who do not fulfil these obligations shall be jointly and severally liable together with the condominium owners.”,

  • Article 20 of Law No. 634, titled “Contribution to the general expenses of the main property”, provides: “Unless otherwise agreed among them, each of the condominium owners:

    a) equally, to the expenses of the doorkeeper, the boiler operator, the gardener and the watchman, and to the advance to be collected for them;

    b) in proportion to his/her own land share, to the insurance premiums of the main property, to the maintenance, protection, strengthening and repair expenses of all common areas and to other expenses such as the manager’s salary, to the operating expenses of the common facilities, and to the advance to be collected for these expenses;

    Is obliged to contribute.

    c) Condominium owners may not avoid paying their share of these expenses and advances by waiving their right of use over the common areas or facilities, or by asserting that, owing to the situation of their own independent unit, there is no need or necessity to benefit from them.

    Each of the other condominium owners or the manager may bring an action, and may initiate enforcement proceedings, against a condominium owner who does not pay his/her share of expenses or advances, in accordance with the management plan, this Law and the general provisions. A condominium owner who does not pay the entire share of expenses and advances is obliged to pay late-payment compensation calculated at five per cent per month for the days on which payment is delayed.

    Where the expenses in the first paragraph have been caused by a faulty act of one of the condominium owners or of a person benefiting in any manner from his/her independent unit, those contributing to the expenses have a right of recourse, for the payments they have made, against that condominium owner or against those who caused the expense.”,

  • Article 22 of Law No. 634, titled “Security for common expenses”, provides: “Those who benefit on a continuous basis from one of the independent units on the basis of a lease agreement, a right of residence (sükna) or any other reason are also jointly and severally liable for the expense and advance debt falling to the condominium owner’s share under Article 20 and for the late-payment compensation. However, the tenant’s liability is limited to the amount of rent he/she is obliged to pay, and the payment he/she makes is deducted from the rent debt.

    If the condominium owner’s debt cannot be collected in this way either, a statutory mortgage right shall be registered for the amount of this debt, in favour of the other condominium owners, on the independent unit of the condominium owner who does not pay his/her debt as determined by the court, upon the written request of the manager, if any, or otherwise of one of the condominium owners. The provision of the last paragraph of Article 893 of the Turkish Civil Code No. 4721 shall also apply here.

    The receivables of the condominium owners from the condominium owner or the other liable persons who do not pay the expense debt are preferential.”,

  • Article 27 of Law No. 634, titled “General assembly”, provides: “The main property is managed by the condominium owners’ assembly, and the manner of management is decided by this assembly, provided that the mandatory provisions of the laws are reserved.”,

  • The first paragraph of Article 34 of Law No. 634, titled “Appointment”, in Part (D) titled “Manager”, provides: “The condominium owners may entrust the management of the main property to a person or to a three-person board whom they will elect from among themselves or from outside; this person is called the (Manager), and the board the (Management board).”, while the fifth paragraph of the same article provides: “The manager is reappointed every year at the statutory annual meeting of the condominium owners’ assembly; the former manager may be reappointed.”

  • Article 38 of Law No. 634, in turn, regulates the liability of the manager, and the first paragraph of this article provides: “The manager is liable to the condominium owners exactly like an agent.”

  • Article 39 of the same Law regulates the manager’s obligation to render accounts, and the said article reads: “The manager is obliged to render to the condominium owners’ assembly, at the times written in the management plan or, if no such time is written, within the first month of each calendar year, an account of the income obtained and the expenses incurred up to that date in respect of the main property.

    If half of the condominium owners so request, whatever their land shares may be, the manager may be asked to present the accounts also outside the times written in the management plan.”

  • The first paragraph of Article 41 of Law No. 634, titled “Supervision of management”, contains the provision: “The condominium owners’ assembly continuously supervises the manager’s conduct in this office and may replace him/her at any time if a just cause arises.”

When an overall assessment is made within the framework of the legislative provisions set out above, it is seen that in apartment/housing-complex and similar collective buildings, meeting the common expenses is the responsibility of all condominium owners, and, where such debts are not performed, the other condominium owners have certain rights and means arising directly from Law No. 634 to ensure the performance of the debt, and further that, as is frequently seen in practice with respect to such collective buildings, dues/advances/fixture expenses and similar payments are collected by managers, that managers are liable to condominium owners like an agent and have an obligation to render accounts of income and expenses to condominium owners at certain intervals, and also that condominium owners have the right and authority to supervise the manager continuously.

Therefore, it is understood that, for the purpose of providing the necessary information regarding the dues/advances/fixture expenses and similar debts of apartment residents, information qualifying as personal data, such as these persons’ first name, surname, flat number information, amount of the debt, length of the payment delay, number of periods of payment delay and flat ownership/tenancy information, needs to be shared with the other condominium owners, and that the personal data processing activity carried out in this way is carried out within the scope of the conditions in Article 5(2)(a) of Law No. 6698, “It is expressly provided for by the laws”, and, for securing the condominium owners’ right to receivables, in subparagraph (e), “Data processing is necessary for the establishment, exercise or protection of any right.” Nevertheless, the procedures and methods to be preferred, in particular when these notifications are made, are of importance in terms of Law No. 6698. This is because even when an information obligation arising from the laws is being fulfilled, it must be ensured that the notification does not contain more personal data than necessary and accordingly complies with the general principles regulated in Article 4 of the Law, and access to such personal data by unrelated/unauthorised third parties must be prevented.

In practice, it is frequently seen that lists/documents concerning the dues/advances/fixture expenses and similar debts of condominium owners are posted in common areas of collective buildings such as elevators, building entrances and building corridors. Indeed, such lists contain the information not only of those who have debts, but of all the owners/tenants/holders of the right of residence (sükna) of the independent units of the collective buildings. As is known, common areas of collective buildings such as elevators, building entrances and building corridors are areas where guests who do not reside/live in that collective building, cargo personnel, couriers and even persons wholly unknown to the apartment residents may frequently be present, and it is evident that the announcements/documents/lists in these areas can also be seen by such persons. Indeed, even if these lists do not contain the first names and surnames of the owners/tenants/holders of the right of residence (sükna) of the independent units, the information contained in the lists qualifies as personal data. This is because, given that the lists contain debt information associated with flat numbers and that the concept of “personal data” is defined in the Law as “any information relating to an identified or identifiable natural person”, it is possible to identify these persons from the relevant flat numbers even if their first names and surnames are not included. Accordingly, it is clear that, with respect to the personal data contained in documents/lists posted in such common areas, a breach of the obligation arising from Article 12 of the Law to take all necessary technical and administrative measures to ensure an appropriate level of security will be caused. This is because lists containing personal data that are posted in common areas of collective buildings will have been disclosed to an indeterminate public, thereby causing personal data to be processed in breach of the Law, unrelated/third persons to access such data and, consequently, personal data not to be protected in compliance with the Law.

As a result of the assessment made by the Board, since the opinion has been reached:

  • that the personal data processing activity carried out by posting lists/documents containing information qualifying as personal data, such as the first name, surname, flat number information, amount of the debt, length of the payment delay, number of periods of payment delay and flat ownership/tenancy information of apartment residents, for the purposes of making announcements concerning their dues/advances/fixture expenses and similar debts and informing the other apartment residents, in common areas such as elevators, building entrances and building corridors is not based on any of the processing conditions set out in Article 5 of the Law,

  • that, since lists containing personal data that are posted in common areas of collective buildings are disclosed to an indeterminate public and thereby cause personal data to be processed in breach of the Law, this situation constitutes a breach of the obligation to take the necessary technical and administrative measures to ensure data security regulated in Article 12 of the Law

  • that, in this context, in order for such notifications to be carried out in compliance with Article 12 of the Law, procedures/methods that do not involve access by persons in the position of third parties, such as closed e-mail or messaging groups or applications dedicated to this service, must be used

it has been concluded that the following are required:

  • Ending such practices immediately,

  • Removing such announcements/lists/documents immediately from the common areas of collective buildings,

  • Applying, for the announcements/notifications to be made to condominium owners on these matters, another procedure/method that complies with Article 12 of the Law and that only the persons concerned can access.

As is known, Article 15(6) of the Law provides: “As a result of the examination made upon complaint or ex officio, in cases where it is determined that the infringement is widespread, the Board shall take a resolution on this matter and publishes this resolution.”, while Article 18(1)(b) of the Law provides that an administrative fine shall be imposed on those who fail to fulfil the obligations relating to data security under Article 12 of the Law.

Within this framework, it has been decided unanimously that the public be informed that the matters set out above are among the technical and administrative measures that must be taken by data controllers pursuant to Article 12(1) of the Law to ensure the lawful processing and the security of personal data, and that, where it is determined that the said matters have not been complied with, action shall be taken against the relevant data controllers pursuant to Article 18 of the Law; and, in this context, that a Principle Decision be taken pursuant to Article 15(6) of the Law and published in the Official Gazette and on the Authority’s website.

14 — Principle Decision dated 29/04/2026 and numbered 2026/921 on the processing of biometric data for the purpose of working-time tracking

Subject: Principle Decision on the processing of biometric data for the purpose of working-time tracking.

One of the issues most frequently encountered in the tip-offs and complaints conveyed to the Personal Data Protection Authority (Authority) is that institutions and organisations are increasingly turning to biometric identification systems in order to digitise employee attendance tracking and increase security.

Although biometric identification systems (such as fingerprint, facial recognition, and iris and retina scanning) appear attractive owing to their fast, accurate and manipulation-resistant features, they constitute an extremely sensitive area in the context of personal data protection law. In particular, the structural imbalance of power that exists in the employee-employer relationship gives rise to serious doubts as to whether explicit consent is based on free will. For this reason, biometric data processing activities must comply not only with a legal basis but also with the principles of proportionality, necessity and data minimisation.

Accordingly, it has become necessary to inform the public on the processing of biometric data for the purpose of working-time tracking and for the Personal Data Protection Board (Board) to take a Principle Decision on the subject.

Within this framework, when the legislative provisions relating to the subject are examined;

  • The special categories of personal data regulated in Article 6 of the Personal Data Protection Law No. 6698 (Law), titled “Conditions for processing of special categories of personal data”, have been determined by the legislator by way of an exhaustive list, and it is not possible to extend them by analogy. These are data relating to persons’ race, ethnic origin, political opinion, philosophical belief, religion, religious sect or other belief, appearance, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and their biometric and genetic data.

  • Although there is no comprehensive definition in national legislation of the concept of biometric data, which is accepted as special category personal data under the Law, biometric data is defined in subparagraph (ff) of Article 3, titled “Definitions”, of the Population Services Law No. 5490 as “fingerprints, vein prints and person-specific data obtained from the palm of the hand, taken for the purpose of enabling identity determination and identity verification procedures to be carried out through electronic systems”.

  • In the European General Data Protection Regulation (GDPR), which entered into force on 25/05/2018, biometric data is seen to be defined as “personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data”.

In this context, a person’s fingerprint and retina/iris data may be given as examples of physiological biometric data; facial and hand geometry as examples of physical biometric data (which, unlike physiological characteristics, are visible to the eye); and voice timbre, signature dynamics and keyboard usage habits as examples of behavioural biometric data.

Owing to the sensitive nature and irreversible structure of such biometric data (it being impossible to change or revoke them if they are seized), their protection is of great importance since, as also stated in the Law’s statement of reasons, there is a possibility that data subjects will suffer harm if these data become known.

  • Article 6(3) of the Law, titled “Conditions for processing of special categories of personal data”, provides that the processing of special categories of personal data is prohibited, but that the processing of such personal data is possible where one of the cases listed in that paragraph exists (a) Data subject has given his/her explicit consent, b) It is explicitly provided by laws, c) It is necessary for the protection of life or physical integrity of the person himself/herself or of any other person who is unable to explain his/her consent due to the physical disability or whose consent is not deemed legally valid, ç) It relates to personal data that have been made public by the data subject, and processing is in consistent with data subject’s intention to make such data public, d) It is necessary for the establishment, exercise or protection of any right, e) It is necessary for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, and for the planning, management and financing of health-care services by persons subject to legal obligation of confidentiality or by competent public institutions and organizations, f) It is necessary for the fulfilment of legal obligations in the fields of employment, occupational health and safety, social security, social services, and social assistance, g) It relates to the current or former members and affiliates of foundations, associations, and other non-profit organizations established for political, philosophical, religious, or trade union purposes, or to individuals who are in regular contact with these organizations, provided that such processing complies with the applicable legislation governing these organizations and their objectives, is limited to the organizations’ fields of activity, and does not involve disclosure of data to third parties). In addition, in the processing of special categories of personal data, the “Adequate Measures to be Taken by Data Controllers in the Processing of Special Categories of Personal Data” determined by the Board’s decision dated 31/01/2018 and numbered 2018/10 must also be taken.

However,

  • Article 63 of the Labour Law No. 4857 regulates general working time, and Article 67 of the said Law provides that the start and end times of daily work and rest periods shall be announced to employees at workplaces. Article 75 of the said Law states that the employer shall prepare a personnel file for each employee and keep in this file the documents and records concerning the employee that are required by law to be kept. In addition, Article 9 of the By-Law on Working Hours Relating to the Labour Law, published in the Official Gazette dated 06/04/2004 and numbered 25425, provides that the employer is obliged to document employees’ working hours by appropriate means.

Although these provisions draw a legal framework for the employer’s tracking and documenting of working hours, since there is no explicit statutory provision providing for the tracking to be carried out by biometric identification systems, carrying out working-time tracking through the processing of biometric data may constitute unlawfulness.

Within this framework, since none of the processing conditions in subparagraphs (b), (c), (ç), (d), (e), (f) and (g) of Article 6(3) of the Law finds application in biometric data processing activities for the purpose of working-time tracking, it is seen that in practice such activities are preferably carried out on the basis of the explicit consent condition in subparagraph (a).

  • Pursuant to Article 3(1)(a) of the Law, explicit consent means “freely given, specific and informed consent”.

In this context, where a personal data processing activity is to be carried out on the basis of the explicit consent of data subjects, the consent must relate to a specific matter, be based on information and be expressed with free will.

Within this framework, in employment relationships in which the parties are not in an equal position, one of the parties has influence over the other or there is an imbalance of power between the parties, where the employee is not effectively offered the possibility of not giving consent or of withdrawing consent, or where not giving consent may give rise to possible adverse consequences for the employee, it cannot be said that the employee has a genuine choice, and it will therefore not be possible to speak of the consent being based on free will either.

Furthermore, since the possibility of withdrawing consent would undermine the continuity and applicability of biometric identification systems, processing biometric data for the purpose of working-time tracking solely on the basis of the explicit consent condition will not, as a rule, constitute a sufficient legal ground either.

  • In the Decision of the Plenary of the Constitutional Court dated 10/03/2022 concerning Application No. 2018/11988, made in respect of working-time tracking by means of a fingerprint registration system, it was stated that, under Article 20 of the Constitution, it is clear that personal data may be processed “only in cases envisaged by law or by the person’s explicit consent”, and that in Article 6 of Law No. 6698 the legislator, owing to their importance, made the processing of the special categories of personal data it lists exhaustively subject to stricter rules. In the case subject to the Decision, the applicant, who was working as a civil servant within a Municipality (Administration), filed an action for the annulment of the administrative act in question when working-time tracking by means of a fingerprint system was introduced at the workplace; when the Regional Administrative Court decided that there was no unlawfulness in the administration’s tracking of working hours by means of a fingerprint registration system, the applicant brought the matter before the Constitutional Court by way of an individual application, alleging that the right to request the protection of personal data, within the scope of the right to respect for private life, had been violated because working hours were tracked by means of a fingerprint registration system. The Constitutional Court held that the right to request the protection of personal data had been violated, on the ground that the interference subject to the application did not satisfy the requirement of legality, since neither the Civil Servants Law No. 657 nor the Municipality Law No. 5393 contains a provision setting out the fundamental rules and principles concerning the processing of special categories of personal data for the purpose of working-time tracking and, in this context, the use of biometric-data-based tracking systems.

However,

  • Article 4 of the Law, titled “General Principles”, provides that personal data may only be processed in compliance with the procedures and principles laid down in this Law and in other laws, and that it is mandatory, in the processing of personal data, to comply with the principles listed as “a) Lawfulness and fairness. b) Being accurate and kept up to date where necessary. c) Being processed for specified, explicit and legitimate purposes. ç) Being relevant, limited and proportionate to the purposes for which they are processed. d) Being stored for the period laid down by relevant legislation or the period required for the purpose for which the personal data are processed.”; compliance with these general principles in the processing of personal data is a legal requirement in all cases and circumstances.

Within this framework, the biometric data processing activity in working-time tracking must be assessed separately in terms of the suitability of the method for the purpose (being relevant to the purposes for which they are processed), whether alternative methods have been exhausted (being limited to the purposes for which they are processed) and the extent of the interference (being proportionate to the purposes for which they are processed); a practice that does not meet these criteria will be deemed unlawful even if the data subject’s explicit consent exists.

The principle of being relevant and limited to the purposes for which they are processed requires that the personal data processing activity be the least intrusive method for achieving the purpose. When assessed in terms of working-time tracking, it is seen that alternative methods exist in practice, such as encrypted card or PIN-based systems, traditional signature and paper-based attendance sheets, RFID/NFC identity cards or manual entry overseen by a supervisor. The existence of these alternatives clearly demonstrates that biometric data processing is not necessary.

The proportionality assessment, in turn, questions whether there is a reasonable balance between the intensity of the interference and the legitimate aim sought to be achieved. In this context, working-time tracking is a limited administrative purpose and, in most cases, falls short of justifying so intensive a data processing interference. In addition, considering also the possibility that such personal data may be combined with other personal data processing activities and used for different purposes, or misused, processing biometric data for the purpose of working-time tracking will amount to a breach of the principle of proportionality.

  • In the case subject to the Decision of the 12th Chamber of the Council of State with Docket No. 2021/3870 and Decision No. 2023/2548, the plaintiff Trade Union sought the annulment of the defendant Establishment’s act concerning the enrolment in the palm-vein reader to be applied in working-time tracking and the creation and use of a record in the system. In the legal assessment made by the Council of State in respect of the Decision, it was stated that Article 4 of Law No. 6698 makes it mandatory, in the processing of personal data, to comply with the principle of being relevant, limited and proportionate to the purposes for which they are processed, and that Article 6 of the Law, by listing special categories of personal data exhaustively, makes the processing of these data subject to stricter conditions than data of a general nature. By its Decision with Docket No. 2024/225 and Decision No. 2024/2625, the Plenary of the Administrative Law Chambers of the Council of State, examining the said Decision on appeal, held that the Decision of the 12th Chamber of the Council of State with Docket No. 2021/3870 and Decision No. 2023/2548 was lawful, stating that the Personal Data Protection Board had made an assessment, based on the principles in Article 4 of Law No. 6698, on the necessity of processing special categories of personal data for working-time tracking, and that, accordingly, by its decision dated 01/12/2020 and numbered 2020/915, the said Board had emphasised that, within the framework of the principle of “being relevant, limited and proportionate to the purposes for which they are processed”, one of the principles in Article 4 of the Law titled “General Principles”, the processing of personal data that are not related to the achievement of the purpose or that are not needed must be avoided in special category personal data processing activities.

In conclusion,

  • that, considering that, although the legislation contains provisions on the tracking of working hours, there is no explicit provision on how the tracking is to be carried out or that the tracking must be carried out through the processing of biometric data, in the current situation it cannot be accepted that biometric data processing activity is carried out on the basis of the condition of being explicitly provided for by laws,

  • that, accordingly, since none of the processing conditions in subparagraphs (b), (c), (ç), (d), (e), (f) and (g) of Article 6(3) of the Law finds application in biometric data processing activities for the purpose of working-time tracking, such activities are preferably carried out on the basis of the explicit consent condition in subparagraph (a), but that, owing to the imbalance of power in the employee-employer relationship, there is doubt as to whether explicit consent is based on free will and, in this respect, it does not on its own constitute a sufficient legal ground,

  • that the principle of proportionality is an important criterion in the assessment of personal data processing activities and that, in the face of the existence of alternative, less intrusive methods, processing biometric data for the purpose of working-time tracking will not satisfy the proportionality criterion within the scope of the general principles in Article 4 of the Law even if the explicit consent of data subjects exists

have been assessed; accordingly, it is brought to the attention of the public that biometric data processing for the purpose of working-time tracking is carried out without relying on any of the processing conditions in Article 6 of the Law, that, even if valid explicit consent exists, such processing activity will not satisfy the proportionality criterion within the scope of the general principles in Article 4 of the Law, and that, for this reason, working-time tracking must be ensured through alternative means, such as encrypted card or PIN-based systems, traditional signature and paper-based attendance sheets, RFID/NFC identity cards or manual entry overseen by a supervisor, instead of biometric identification systems.

As is known, Article 12(1) of the Law provides: “The data controller is obliged to take all necessary technical and organizational measures to provide an appropriate level of security for the purposes of: a) preventing unlawful processing of personal data, b) preventing unlawful access to personal data, c) ensuring protection of personal data.”, and Article 15(6) of the Law provides: “As a result of the examination made upon complaint or ex officio, in cases where it is determined that the infringement is widespread, the Board shall take a resolution on this matter and publishes this resolution.”

Within this framework, it has been decided unanimously that the public be informed that the matters set out above are among the administrative and technical measures that must be taken by data controllers pursuant to Article 12(1) of the Law to ensure the lawful processing of personal data, and that, where it is determined that the said matters have not been complied with, action shall be taken against the relevant data controllers pursuant to the provisions of Article 18 of the Law; and, in this context, that a Principle Decision be taken pursuant to Article 15(6) of the Law on the processing of biometric data for the purpose of working-time tracking, and that the said Principle Decision be published in the Official Gazette and on the Authority’s website in the form set out in the annex to the Decision.

15 — Principle Decision dated 20/05/2026 and numbered 2026/1095 on the processing of personal data of accident victims

Subject: Principle Decision regarding the processing of personal data of accident victims.

A number of complaints and tip-offs have been conveyed to the Personal Data Protection Authority (Authority) to the effect that victims of occupational accidents, traffic accidents or similar adverse events are contacted against their wishes by representatives of organisations operating as damage consultancy companies or under similar names, by attorneys, or by persons who present themselves as attorneys but who, when the bar roll is checked, are found not to be attorneys. In this context, it is stated that the persons contacted are promised that they will receive compensation if they grant a power of attorney and are told that the necessary applications can be made, while no satisfactory answer is given to the questions raised by the victims as to how the information about them and the accident was obtained. It is seen that, following conversations with victims, in some cases powers of attorney were obtained as a result of persistent calls and intimidation about possible loss of rights, and in other cases acts and transactions were carried out on behalf of victims even though no information or instruction had been given. As a result of the examinations carried out by the Personal Data Protection Board (Board), it has been understood that documents such as accident reports containing the identity and contact information and other personal data of victims could be accessed by the above-mentioned persons through different channels in the post-accident process. Owing to the widespread nature of these unlawful personal data access and subsequent processing activities, it has become necessary for the Board to take a Principle Decision.

As is known, Article 2 of the Attorneyship Law No. 1136 regulates the purpose of the legal profession; Article 35 specifies the work that may be performed only by attorneys; Article 48 provides for the prohibition of intermediation and the related criminal sanctions; Article 55 sets out the prohibition of advertising; and Article 63 regulates unauthorised practice of law and the sanctions attached to it. In addition, Article 14 of the Union of Turkish Bar Associations By-Law on the Attorneyship Law sets out the work that only attorneys may perform, while Article 8 of the Union of Turkish Bar Associations Professional Rules provides that attorneys shall refrain from any conduct in the nature of soliciting work for themselves.

On the other hand, Additional Article 6 of the Insurance Law No. 5684 (Law No. 5684) regulates by whom the compensation receivable to be claimed from institutions or organisations engaged in insurance, or from the Account, may be claimed, and provides that the compensation receivable may be paid only to the right holder or his/her attorney and that this receivable may not be assigned to anyone; and Article 7 of the Circular on the Implementation of Additional Article 6 of the Insurance Law No. 5684 provides that any contract or transaction to the contrary is contrary to Law No. 5684 and absolutely null and void under the Turkish Code of Obligations No. 6098.

Within this framework, it being clear that compensation receivables arising from Law No. 5684 may be pursued only by the persons provided for in Additional Article 6 of Law No. 5684, and considering that these receivables cannot be assigned to other persons, institutions or organisations either, that, in this respect, entities operating as damage consultancy companies or under similar names within the scope of the tip-offs conveyed to our Authority may, under the provisions set out above, operate only directly or indirectly through attorneys, that a situation to the contrary may breach the relevant legislative provisions set out above, and further that it may give rise to the aggravated form, regulated in Article 137, of the offence of “Unlawful Delivery or Acquisition of Data” regulated in Article 136 of the Turkish Penal Code No. 5237 (TPC), it is assessed that, taking into account that the matter may constitute an offence with respect to activities involving the processing of personal data contrary to the provisions of Laws No. 1136 and 5684, a criminal complaint may be filed with the Chief Public Prosecutors’ Offices and, administratively, the matter may be referred to the relevant Ministries and to the presidencies of bar associations.

In addition, where damage consultancy companies that unlawfully access personal data processed through different channels within the insurance sector and carry out processing activities under the provisions of the Personal Data Protection Law No. 6698 (Law No. 6698), and loss adjusters/loss adjusting firms/attorneys/law partnerships that exceed the limits of the authority granted to them, carry out personal data processing activities without relying on any processing condition, and their status as data controller can be established, data subjects may lodge a complaint with the Board by following the procedure regulated in Article 13 et seq. of the Law.

On the other hand, the personal data processing activities of insurance loss adjusters are limited to, and directly linked with, the performance of statutory duties such as damage assessment, reporting and the conduct of compensation processes within the framework of the Insurance Law No. 5684 and secondary legislation. In performing their duties, insurance loss adjusters may process personal data on the basis of the processing conditions set out in the Personal Data Protection Law No. 6698 of “being expressly provided for by the laws”; “being necessary for compliance with a legal obligation to which the data controller is subject”; or “being directly related to the establishment or performance of a contract”.

In this context, insurance loss adjusters must use the personal data entrusted to them only within the scope of their duties, must not share them with unauthorised third parties, must assume the obligations relating to data security and must comply with the obligation of professional secrecy.

Unlawful personal data processing activities carried out by going beyond the legal framework and the limits of the legislation may give rise, in addition to administrative liability under the Personal Data Protection Law No. 6698, to criminal liability under the relevant articles of the Turkish Penal Code No. 5237.

In the processes following occupational accidents, traffic accidents or similar adverse events, personal data relating to victims may be processed within the scope of Articles 4, 5 and 6 of the Law in order to carry out processes such as conducting post-accident judicial and/or administrative investigations, treating victims and repairing the vehicles involved in the accident. However, data controllers that process personal data relating to victims by reason of their duties and fields of activity must comply with the legal framework set out above, and these personal data may be made subject to processing only for the purpose of managing post-accident processes.

Furthermore, Article 12(1) of the Law, titled “Obligations concerning data security”, provides:

“(1) The data controller is obliged to take all necessary technical and organizational measures to provide an appropriate level of security for the purposes of: a) preventing unlawful processing of personal data, b) preventing unlawful access to personal data, c) ensuring protection of personal data.”

Pursuant to the said provision, data controllers are obliged to take the necessary measures to ensure the security of personal data, taking into account their organisational structures, their fields of activity, the nature of the personal data they obtain and the risks that may arise to fundamental rights and freedoms in the context of the processing of such data. It should also be noted that Article 12(4) of the Law provides that persons carrying out personal data processing activities within the data controller may not disclose the personal data they have learned to others contrary to the provisions of the Law or use them for purposes other than the purpose of processing, and that this obligation continues after they leave office. In addition, persons working in different fields of business, in particular the provision of health services, insurance and the legal profession, are also subject to professional secrecy obligations regulated separately and specifically in the legislation. In the same vein, it is important that data controllers take the necessary measures to ensure that personal data obtained within the scope of their activities are not used for purposes other than their intended purpose by persons within their own organisations and are not unlawfully transferred to other persons, institutions and organisations.

In light of all these assessments;

  • that, where damage consultancy companies that unlawfully access personal data processed through different channels within the insurance sector and carry out processing activities under the provisions of Law No. 6698, and loss adjusters/loss adjusting firms/attorneys/law partnerships that exceed the limits of the authority granted to them, carry out personal data processing activities without relying on any processing condition, and their status as data controller can be established, data subjects may lodge a complaint with the Board by following the procedure regulated in Article 13 et seq. of the Law,

  • that insurance loss adjusters may carry out personal data processing activities in line with the statutory duty imposed on them by insurance legislation, but that there will be a breach of the Law if they transfer the personal data they process by virtue of their duties to unauthorised third parties, and that personal data processing activities carried out by insurance loss adjusters without relying on the processing conditions provided for in the Law may give rise to the offence of unlawfully delivering personal data provided for in Article 136 of Law No. 5237,

  • that all necessary technical and administrative measures must be taken pursuant to Article 12 of the Law to ensure the security of personal data by data controllers that hold/process personal data relating to accident victims within the framework of their activities, in particular carrying out training and awareness activities for their employees on the protection of personal data and establishing authorisation restrictions within the framework of the principle of least privilege regarding access to personal data, role-based access controls and monitoring mechanisms,

  • that action shall be taken, within the framework of the provisions of Article 18 of the Law, against data controllers that are found to continue this practice in breach of the provisions of the Law by failing to take the said measures and not to act in accordance with the matters set out in this Principle Decision

it has been decided unanimously that the public be informed of these matters and that this Principle Decision, taken pursuant to Article 15(6) of the Law, be published in the Official Gazette and on the Authority’s website.

Subject: Principle Decision on the sharing of personal data on the internet by data controllers having public legal personality.

As is known, Article 15(6) of the Personal Data Protection Law No. 6698 (“Law No. 6698”) provides: “As a result of the examination made upon complaint or ex officio, in cases where it is determined that the infringement is widespread, the Board shall take a resolution on this matter and publishes this resolution.” Furthermore, subparagraphs (e), (f) and (g) of Article 22(1) of Law No. 6698, which regulates the duties and powers of the Personal Data Protection Board (“Board”), respectively regulate the power to carry out regulatory acts on matters concerning the Board’s field of duty and the operation of the Authority, for the purpose of determining obligations relating to data security, and on the duties, powers and responsibilities of the data controller and its representative.

The Board has made the following findings and assessments regarding personal data shared on the internet by public institutions and organisations and various other data controllers having public legal personality (municipalities, special provincial administrations, universities, etc.).

According to Article 1 of Law No. 6698, the purpose of the Law is to protect fundamental rights and freedoms of persons, particularly the right to privacy, with respect to the processing of personal data, and to regulate the obligations of natural and legal persons who process personal data and the procedures and principles they shall comply with.

In subparagraph (e) of Article 3(1) of Law No. 6698, titled “Definitions”, “personal data” is defined as “any information relating to an identified or identifiable natural person”, and “processing of personal data” as “any operation which is performed on personal data, wholly or partially by automated means or non-automated means which provided that form part of a data filing system, such as collection, recording, storage, protection, alteration, adaptation, disclosure, transfer, retrieval, making available for collection, categorization, preventing the use thereof”.

Special categories of personal data, in turn, are listed in Article 6(1) of Law No. 6698 as “Personal data relating to the race, ethnic origin, political opinion, philosophical belief, religion, religious sect or other belief, appearance, membership to associations, foundations or trade-unions, data concerning health, sexual life, criminal convictions and security measures, and the biometric and genetic data”.

Processing of personal data is a broad concept, and every activity carried out on personal data in the process starting from the initial obtaining of personal data until their destruction is regarded as processing of personal data within the scope of Law No. 6698.

In this context, where documents containing personal data are announced by being published on the internet, since this results in the disclosure of personal data and, further, in personal data being made available to third parties in this way, the fact that documents published on the internet contain personal data indicates the existence of a personal data processing activity.

The findings made by the Board show that various documents published on websites by data controllers having public legal personality within the scope of activities carried out in their own fields of duty and authority may contain personal data such as first name, surname, mother’s name, father’s name, age, T.R. identity number, address, mobile phone number, place of birth, profession, field of specialisation, place of duty, title/status, years of service, registry number, unit worked in, military service status information, educational status, information on immovable properties subject to draws carried out by public institutions (block/parcel, etc.), application numbers processed within the scope of various examinations, KPSS score, information on acceptance/rejection or success/failure status, information on schools graduated from, information on the examination taken such as the number of correct/incorrect/net answers/success score, the position applied for, candidate number, student number, the reason for not being able to take the examination/not being accepted, examination attendance status information, principal/substitute information, missing documents information, status as a former convict, and similar personal data.

Where data controllers having public legal personality are to carry out personal data processing activities by sharing personal data on the internet, compliance with the provisions of Law No. 6698 and secondary legislation must be ensured.

In order to ensure such compliance;

  • that the sharing of personal data on the internet must be based on a valid personal data processing condition or conditions set out in Article 5 of Law No. 6698 and, in the case of special categories of personal data, in Article 6 thereof,

  • that, where there is no valid processing condition, it would be appropriate for data controllers not to share personal data on the internet,

  • that, even where the sharing of personal data on the internet is based on a valid processing condition (for example, where the processing condition “it is expressly provided for by the laws” or “it is necessary for compliance with a legal obligation to which the data controller is subject” exists because it is based on a provision of legislation, or where other processing conditions are relied upon), it is mandatory to act in accordance with the General Principles regulated in Article 4 of Law No. 6698,

  • that, in order to ensure compliance with the principle of “being relevant, limited and proportionate to the purposes”, one of the General Principles, it is important that personal data be shared at the minimum level that will ensure the achievement of the purpose, that personal data that are not necessary for the achievement of the purpose not be included on the internet and, in this context, that the necessary destruction, masking and similar measures be taken by data controllers,

  • that, in order to ensure compliance with the principle of “being stored for the period laid down by relevant legislation or the period required for the purpose for which the personal data are processed”, one of the General Principles, the period for which posts containing personal data will be shared must be determined with due regard to that principle, and the necessary acts and actions must be put in place by data controllers to end the posts at the end of the relevant periods,

  • that the obligation to inform arising from Article 10 of Law No. 6698 in respect of personal data to be shared on the internet is expected to have been fulfilled in accordance with the provisions of that article and of the Communiqué on Principles and Procedures to be Followed in Fulfilment of the Obligation to Inform, which entered into force upon publication in the Official Gazette dated 10/03/2018 and numbered 30356, and that the burden of proving that the obligation to inform has been fulfilled lies with the data controller,

  • that the necessary administrative and technical measures relating to data security must be taken by data controllers under Article 12 of Law No. 6698; that ensuring data security requires measures to be taken by taking into account also the possible risks and potential breaches in the personal data processing activity carried out by the data controller; that a personal data processing activity carried out by sharing personal data on the internet will entail a greater data security risk than sharing the data in a more limited environment and with a more limited number of persons; and further that data controllers are obliged to carry out, or have carried out, the necessary audits in order to ensure the implementation of the provisions of the Law within their own organisation,

  • that it would be appropriate for data controllers to review urgently the personal data currently shared on the internet and to remove from the internet the posts that are not based on a valid processing condition and do not comply with the general principles, or to apply masking and similar arrangements to them; and, where the reasons requiring the processing of the personal data contained in such posts have ceased to exist, for data controllers to carry out the necessary acts and actions relating to the destruction of personal data in accordance with the provisions of Article 7 of Law No. 6698 and of the By-Law on Erasure, Destruction or Anonymization of Personal Data, which was published in the Official Gazette dated 28/10/2017 and numbered 30224 and entered into force on 01/01/2018,

  • that, in cases of examination results, draw results and similar situations, posts may be made, where the concrete case so requires, in a way that also allows scrutiny by the persons concerned, such that only those who participated in the examination, draw or relevant activity can access them, or, where the concrete case does not require this, such that only the data subject can access the results of his/her own examination, draw or relevant activity, and again by methods in which measures compliant with the general principles have been taken; and that in such cases it would be appropriate to use suitable e-Government platforms or methods and means that ensure identity verification through two-factor authentication,

  • that, considering that such posts are made extensively through websites and social media platforms, data controllers must carry out training and awareness activities to increase the knowledge and awareness of all employees, in particular the employees responsible for the use of such platforms within data controllers, about personal data protection legislation and the matters to be observed in practice,

  • that, on the other hand, sharing containing personal data by data controllers having public legal personality is not carried out only on the internet, and in this vein these matters must also be observed in respect of personal data sharing carried out through means such as intra-institutional or inter-institutional correspondence, e-mail messages, announcements, closed electronic environments used within the institution, and display boards and notice boards,

  • that the matters set out above are among the technical and administrative measures that must be taken by data controllers, pursuant to Article 12(1) of Law No. 6698, to ensure an appropriate level of security for the purposes of preventing the unlawful processing of personal data, preventing unlawful access to personal data and ensuring the protection of personal data; and, on the other hand, that the other obligations relating to data security regulated in Article 12 of Law No. 6698 must also be observed by data controllers,

  • that, where it is determined that the said measures have not been taken, action shall be taken against the relevant data controllers pursuant to the provisions of Article 18 of Law No. 6698, by making a concrete-case assessment within the scope of the Board’s power of examination

it has been decided unanimously that the public be informed of these matters and, in this context, that a Principle Decision be taken pursuant to Article 15(6) of the Personal Data Protection Law No. 6698 and that this Principle Decision be published in the Official Gazette and on the Authority’s website.

ESKİ ADRES /post/personal-data-protection-board-principle-decisions Bu not, önceki sitede yukarıdaki adreste yayımlanıyordu; o adres artık bu sayfaya yönlendirilmektedir.