Home About Us Services Awards Team Insights Career Contact Us TÜRKÇEENGLISH Devin Law & IP — Istanbul
← All Insights
CategoryData Protection
Published6 February 2026
Authors
Uğurcan TekinPartner
İnci ÖzçilsalAttorney at Law

Establishing an Internal Personal Data Protection Board Within the Company

Under Personal Data Protection Law No. 6698, companies holding the status of data controller are obliged to conduct their personal data processing activities in compliance with the applicable legislation and to manage the related processes within a transparent and traceable framework. This obligation is not limited solely to the preparation of written policies and procedures; it also encompasses the ability to demonstrate how personal data is actually processed, monitored and managed within the company in practice.

The fact that personal data processing activities within companies are carried out by different departments — such as human resources, legal, finance, information technologies and operations — may cause the process to become fragmented and difficult to control. This may hinder the continuity of legal compliance and may also complicate the holistic management of the process in the event of a potential data breach. In this context, addressing personal data protection processes within a centralised and systematic structure, under the knowledge and supervision of company management, stands out as an effective approach in practice.

Accordingly, the establishment of a Personal Data Protection Board within the company provides a structure that enables personal data processing activities to be reviewed on a regular basis, decisions taken to be recorded in writing and, where necessary, reported to company management. Beyond supporting the sustainable management of regulatory compliance, such a board structure also contributes to the early identification of legal and operational risks.

The Board convening at regular intervals — such as on a quarterly basis — and the recording of the decisions taken during its meetings in written minutes, preserved in a manner allowing submission when required, constitute important elements demonstrating corporate accountability, particularly in audits that may be conducted before the Personal Data Protection Authority. The documented and systematic conduct of board activities also creates a defensible position that may be taken into account in favour of companies in the determination of administrative monetary fines.

With respect to group companies, since each company holds the status of a separate data controller, adopting a separate Board structure for each company represents a sounder approach. Nevertheless, for reasons of operational efficiency, holding board meetings in a single session while preparing separate board decision minutes for each company is considered a practical and functional method in practice.

A board that meets, decides and records is what turns a policy document into demonstrable compliance.

General Assessment and Purpose

Under the Personal Data Protection Law, companies holding the status of data controller are required to conduct their personal data processing activities in compliance with the applicable legislation and to manage those activities within an organisational structure capable of demonstrating compliance at all times. In this respect, pursuant to Article 12 of the Law, which specifically regulates obligations concerning data security, companies are responsible for taking the necessary technical and administrative measures to ensure an adequate level of security and for ensuring the effective implementation of those measures.

The execution of personal data processing activities by different departments within companies may hinder the centralised monitoring and management of those processes. For this reason, addressing personal data protection processes on a regular basis under the knowledge and supervision of company management constitutes a functional approach in terms of ensuring legal compliance and preventing potential risks. The guidelines and principle decisions published by the Personal Data Protection Authority are among the primary sources guiding practice with respect to how data controllers should fulfil their obligations under the Law. In particular, the Personal Data Security Guide (Technical and Administrative Measures) explicitly emphasises that merely drafting data security policies is not sufficient; rather, such policies must be integrated into internal company operations, regularly monitored and kept up to date. This approach necessitates the management of personal data protection processes under a specific organisational structure in a manner that ensures continuity.

Within this framework, a Personal Data Protection Board structure, which enables the systematic monitoring of personal data processing activities, the recording of decisions taken and the submission of those decisions to company management where necessary, stands out as an organisational model commonly preferred in practice.

Scope and Internal Function of the Board

Establishing the Board as a structure in which units that intensively process personal data are represented enables data processing activities to be addressed not solely on the basis of written regulations, but also by taking actual business processes into account. Including departments specific to the company’s field of activity — primarily human resources, legal, finance, information technologies and operations — contributes to the management of personal data protection processes in alignment with the company’s actual operational practices.

Within this framework, the Board functions as a coordination mechanism that regularly reviews data processing activities carried out within the company, monitors changes occurring in those processes, and allows for the early identification of potential legal and operational risks. Through this structure, the protection of personal data ceases to be a fragmented area managed solely by specific departments and instead becomes a process that is monitored and managed across the company as a whole.

Meetings, Minutes and the Record-Keeping System

The effective functioning of the Board depends on its convening at regular intervals and on the written recording of the decisions taken. Meetings at predefined periods — such as on a quarterly basis — provide a functional approach for reviewing the current status of personal data processing activities and assessing newly emerging risks.

The recording of decisions adopted during meetings in written minutes, and the preservation of those minutes in a manner that allows them to be submitted to company management when required, supports the traceability and auditability of the process. In this respect, the preparation of an informational memorandum setting out the duties and working principles of the Board, together with the drafting of sample board decision minutes, contributes to the concretisation and proper documentation of the Board’s activities.

Quarterly minutes are what an audit actually examines.

Accountability and the Burden of Proof in Audits

Pursuant to the principle of accountability, which constitutes one of the fundamental principles of the Personal Data Protection Law, it is essential for companies holding the status of data controller to operate within a structure capable of demonstrating that they have duly fulfilled their obligations regarding the protection of personal data. In audits conducted by the Personal Data Protection Authority, the assessment is not limited to the mere existence of written policies and procedures; rather, how those arrangements are implemented in practice within the company, and through which mechanisms they are monitored, is also taken into consideration.

The existence of a regularly functioning Board within companies, together with the maintenance of records relating to its activities, constitutes a significant basis evidencing that compliance efforts are carried out in practice. This approach provides a framework demonstrating that the company manages the process in a systematic manner in the event of a potential audit or an investigation concerning a personal data breach.

Administrative Measures, Organisational Risks and Incident Management

In the guidelines and guidance documents published by the Personal Data Protection Authority — most notably the Personal Data Security Guide (Technical and Administrative Measures) — it is explicitly stated that merely identifying administrative and technical measures relating to data security is not sufficient. Rather, such measures must be integrated into companies’ operational processes, regularly monitored and kept up to date. The approach adopted in the guidelines is based on the principle that personal data processing activities should be managed not on an ad hoc basis, but within a structure ensuring continuity.

Through the establishment of a Board structure, changes occurring in business processes can be reviewed on a regular basis, and in the event of a potential personal data breach the steps to be followed can be managed within a predefined framework. This contributes both to the reduction of operational uncertainties and to the balanced distribution of responsibilities and workload among employees.

The Criminal Law Aspect

Acts such as the unlawful recording, acquisition, disclosure or transfer of personal data may, depending on the circumstances, fall within the scope of criminal offences regulated under Turkish criminal law. For this reason, processes relating to the protection of personal data should be addressed not only from the perspective of administrative sanctions, but also, in certain cases, with regard to their criminal law implications.

In practice, it is observed that during investigations concerning personal data breaches, consideration is given to whether companies have adopted the necessary organisational and administrative measures and whether personal data processing processes are monitored in a systematic manner. In this context, the Board structure provides a framework that contributes to the handling of duties and responsibilities relating to the protection of personal data within an institutional structure and to the more orderly conduct of audit and review processes.

Structuring the Board for Group Companies

The structuring of the Board stands out as a tool that supports the sustainability of compliance efforts carried out within companies and strengthens internal coordination. Even where an organic relationship and operational integration exist among group companies, it should not be overlooked that each group company has a separate legal personality and, accordingly, holds the status of an independent data controller before the law. Due to this distinction in legal status, the preparation of board decisions, risk assessments and meeting minutes relating to compliance processes separately for each company constitutes the most sound approach in terms of the proper operation of procedures and the discharge of the burden of proof.

Board or Committee? Assessing the Structuring Model

There is no explicit provision in the legislation mandating the establishment of a structure under a specific title within companies. Nevertheless, the guidelines and guidance documents published by the Personal Data Protection Authority clearly set out the expectation that data controllers establish the necessary organisational structure to ensure data security.

Within this framework, while it is possible to establish such a structure in the form of a committee or working group, a structure organised at the level of a Personal Data Protection Board, authorised through an internal company directive, offers a framework that is more directly integrated into decision-making processes. With regard to the minimum number of members and the structuring model, practice indicates that a structure composed of at least two or three members, representing units that play an active role in personal data processing processes, is functional. Taking into account academic opinion and the practices of the Authority, a board structure consisting of a limited number of members with clearly defined authority and responsibilities provides an appropriate framework in terms of the effectiveness of decision-making processes, ensuring coordination and sustaining the activities of the Board.

Conclusion and General Assessment

The process of personal data protection does not constitute a compliance area independent of companies’ activities; rather, it is an integral part of their operations. The regular, traceable and sustainable management of that process is only possible through a systematic organisational structure. The Personal Data Protection Board structure provides a mechanism that responds to this need and enables companies to address their personal data protection processes within a defined framework.

In this respect, the implementation of a Personal Data Protection Board structure is considered a practice that supports companies’ legal security, ensures preparedness for audit processes and contributes to the more effective monitoring of risks at management level. This approach also offers a framework aligned with the implementation principles set forth in the guidelines and guidance documents of the Personal Data Protection Authority.