Home About Us Services Awards Team Insights Career Contact Us TÜRKÇEENGLISH Devin Law & IP — Istanbul
Data Protection/Insights

Lawyers' Data Protection Obligations and Breaches at Data Processors

Avukatların KVKK Yükümlülükleri ve Veri İşleyen Kaynaklı İhlaller
Authors
Uğurcan Tekinİnci ÖzçilsalBeyza ErdemirUğurcan Tekin · İnci Özçilsal · Beyza Erdemir
Published28 September 2026
Reading time20 min
← All Insights
CategoryData Protection
Published28 September 2026
Authors
Uğurcan TekinPartner
İnci ÖzçilsalAttorney at Law
Beyza ErdemirAttorney at Law
In this article
Implementation Guide No. 115Breach notificationsRansomware decisionsGenerative AI
SummaryÖzet

This note examines the Implementation Guide on the Protection of Personal Data in the Professional Activities of Lawyers, published by the Personal Data Protection Authority on 22 September 2026, the processor-originated breach notifications announced by the Board's decisions of 16 and 23 September 2026, and three ransomware decisions of 2024 appearing among the published decision summaries. The guide and decisions examined concern the determination of controller and processor status for each activity, the documentation of the source of data, the processing and transfer of documents uploaded to generative AI tools, and the allocation of liability for breaches at a data processor.

Key takeaway · Kilit sonuç

The Guide treats the lawyer as a data controller as a rule, while the breach announcements and ransomware decisions examined show that a security vulnerability at a data processor does not relieve the controller of its notification obligation or of the risk of sanction.

The three sources of this note and their common outcomeFigure 1
Implementation GuidePDPA Publication No. 115 · 22 September 2026
Breach notificationsBoard announcements · 16 and 23 September 2026
Ransomware decisionsDecision summaries · 2024 · Article 12
Data security: joint responsibilityArticle 12(2) · determination of status · source of data · processor agreement · access logs · 72 hours

The principal development of the period is the 158-page Implementation Guide, prepared by the Authority with the opinions and contributions of the Union of Turkish Bar Associations and published as PDPA Publication No. 115. The Guide addresses the status under the PDPL of those involved in legal practice, from the individual lawyer to the law partnership and from the substituted colleague to trainee lawyers and office staff. Separate chapters examine the legal bases for obtaining and disclosing data, transfers abroad, the use of artificial intelligence tools, the obligations of the data controller and data security. The Guide refers to the decisions the Board has rendered to date concerning lawyers and supports its explanations with those decisions.

In the same period, the Board announced breach notifications that began with the exploitation of a vulnerability in a third-party software library on a data processor's server and affected numerous data controllers in the retail, apparel, cosmetics and electronics sectors. The decision summaries published by the Authority also include three decisions of 2024 in which, following a ransomware attack, the controller's contradictory statements and the technical measures it had failed to take formed the basis of an administrative fine.

01
The Status of Lawyers and Law Partnerships under the PDPLAvukatların ve Avukatlık Ortaklıklarının KVKK Kapsamındaki Sıfatı

The longest chapter of the Guide is devoted to whether a lawyer is a data controller or a data processor. Rather than giving a single answer, the Authority recalls that the concept of data controller is functional and that status must be examined “separately for each personal data processing activity”. The Guide states that the principal obligation under a legal services agreement is “to provide specific legal assistance”; the processing of personal data is an ancillary obligation necessary for performing it. A legal services agreement therefore does not become a “personal data processing agreement”, and a lawyer is not a data processor merely because the lawyer is bound by the client's instructions.

The Guide's explanationRehberdeki açıklama

A lawyer practising independently is, as a rule, the data controller for the data of clients and third parties; it is ultimately the lawyer who decides which data will be processed and for what purpose. Lawyers working together in the same office are, notwithstanding the shared office, separate natural-person data controllers for their own clients. In a law partnership, the status belongs to the partnership, which has legal personality; the lawyers within the partnership are not separately regarded as data controllers. The relationship between the substituting lawyer and the substituted lawyer is, as a rule, one of data controller and data processor. Employed lawyers, trainee lawyers and office staff remain within the data controller's organisation and hold neither data controller nor data processor status.

Independent Lawyers and Law PartnershipsBağımsız Avukat ve Avukatlık Ortaklığı

The Board's decision No. 2023/437 dated 22 March 2023 shows that the characterisation used in the contract is not decisive on its own. Although the agreement between the partnership and the company described the partnership as a “data processor”, the Board treated it as the data controller on the ground that “it is seen that the partnership manages the processing activities to be carried out on the personal data transferred to it by the company, and that, accordingly, within the framework of its legal practice, the law partnership has the authority to decide freely in respect of its personal data processing activities”. In two other decisions, however, the Board treated the lawyer or law partnership as a data processor. In decision No. 2021/115 dated 9 February 2021, a lawyer conducting enforcement proceedings on a bank's instructions was regarded as a data processor. In decision No. 2023/78 dated 19 January 2023, the same conclusion was reached for a law partnership that sent a single text message for debt collection and had no means of verifying the numbers. The Guide positions these decisions as exceptions confined to cases in which the lawyer “has been given clear, detailed and specific instructions to process personal data on behalf of the client” and has no control over the purposes and means.

Substitution, Employed Lawyers and Trainee LawyersTevkil, Bağlı Çalışan ve Stajyer Avukatlar

A substituted lawyer may process data only on the instructions of the colleague who granted the authority and solely for the stated purpose. In the Guide's example, a lawyer substituted for a hearing who uses immovable property information learned from the case file to offer the client representation in other matters exceeds the limits of the instruction and becomes a data controller for that activity. A similar distinction is drawn for the employed lawyer. Even where authorised by substitution, the employed lawyer is deemed to act within the organisation of the employing lawyer; where the employed lawyer takes on files under the mandatory defence counsel scheme, however, the Guide treats them as an independent data controller for those files. In view of this distinction, it is recommended that files taken on by employed lawyers through bar association assignment be kept separate from the office's data inventory.

ActorStatusBasis / limit
Independent lawyerData controller (as a rule)The lawyer ultimately decides purposes and means
Lawyers sharing an officeEach a separate natural-person data controllerFor their own clients
Law partnershipThe partnership (legal person) is the data controllerLawyers within the partnership are not separate controllers
Substituted lawyerData processor (as a rule)Becomes data controller if instructions are exceeded
Employed lawyer, trainee, office staffNeither data controller nor data processorWithin the data controller's organisation
Employed lawyer as mandatory defence counselIndependent data controller for those filesBar assignment; separate inventory recommended
Status under the pdpl: summary by actor
02
Obtaining and Disclosing Personal DataKişisel Verilerin Elde Edilmesi ve Açıklanması

The Guide also addresses how lawyers obtain third-party personal data, namely the sources from which, and the limits within which, data relating to persons other than the client may be collected. The Authority accepts the obligation of the institutions listed in the third paragraph of Article 2 of the Attorneyship Law to provide information and documents to lawyers as “a provision permitting transfer” within the meaning of Article 8 of the PDPL. Decisions of both the Council of State and the Board show, however, that this authority is not unlimited.

The Guide's explanationRehberdeki açıklama

The information and documents a lawyer “needs” do not, as stated in the decision of the First Chamber of the Council of State No. 2002/26 E., 2002/52 K., extend to “the will to demand something arbitrarily and without any reason whatsoever”; the concept coincides with the principle in Article 4 of the PDPL that processing be relevant, limited and proportionate to the purpose. Article 2 of the Attorneyship Law is a general provision and does not confer authority to access ex officio data protected by special legislation, such as criminal records. Using software that queries identity and contact information from data collected by unlawful means is, under Principle Decision No. 2019/308, contrary to Article 12 of the PDPL for lawyers as well.

Obtaining Data through UYAP and TAKPASUYAP ve TAKPAS Üzerinden Veri Elde Edilmesi

According to the Board's decisions No. 2021/511-512-513 dated 20 May 2021, a creditor's counsel who queries on UYAP, once the enforcement proceedings have become final, the files in which the debtor is in turn a creditor relies on the condition of processing being “expressly provided for by law”; the distribution office's provision of this information to the lawyer is lawful under Article 2 of the Attorneyship Law. The Guide also cites, as a legitimate example under the condition that “processing is necessary for the protection of a right”, obtaining from TAKPAS the immovable property information of the defendant former spouse in an action to remove child maintenance. On health data, the Guide contains a reminder: Article 10 of the Regulation on Personal Health Data, which required special authority in the power of attorney, was repealed by the amendment of 3 December 2025. In the Guide's malpractice example, the hospital is expected to hand over the discharge summary and surgical notes to the lawyer without requiring special authority.

Criminal Records and Unlawful Query SoftwareAdli Sicil Kaydı ve Hukuka Aykırı Sorgulama Yazılımları

In decision No. 2021/1111 dated 2 November 2021, the Board imposed an administrative fine on a lawyer, stating that Article 2 of the Attorneyship Law is a “general provision” as against the “special provision” in Article 7 of the Criminal Records Law and that it “does not confer on lawyers the authority to access ex officio the criminal record information of data subjects”. The Guide adds two further examples. In decision No. 2020/429 dated 28 May 2020, obtaining the telephone numbers of the data subject's relatives and colleagues “on the basis of probabilities and in a manner that cannot be conclusively proven” resulted in an administrative fine. In decision No. 2021/228 dated 11 March 2021, sending messages about enforcement proceedings to an unrelated company attracted the same sanction. By contrast, in decision No. 2022/655 dated 7 July 2022, no infringement was found, because membership of the dissolved company's board of directors was public in the Trade Registry Gazette and the lawyer had obtained the data “through lawful platforms operating in accordance with Turkish legislation”.

Publicly Available Sources and Data Made PublicKamuya Açık Kaynaklar ve Alenileştirme

According to the Guide, submitting as evidence in divorce proceedings photographs shared publicly on social networks is lawful under Article 5(2)(d) of the PDPL. Two limits are noted, however: making data public requires “the existence of the person's intention to make it public”, and the data may not be used for a purpose other than that for which it was made public. The same principle applies to information on authorised signatories taken from the Trade Registry Gazette or the company's website; such data may be used only for the conduct of the legal process, to the extent necessary and in a proportionate manner.

Disclosure of Debt Information to Third PartiesBorç Bilgisinin Üçüncü Kişilere Açıklanması

In decision No. 2019/166 dated 31 May 2019, the Board found the sending of the debtor's name, surname and service number to a line belonging to the complainant, understood to be the debtor's nephew or niece, contrary to Article 12(1)(a) of the PDPL. In decision No. 2021/111 dated 9 February 2021, sending a text message to a number known to belong to a relative was found contrary to the same provision; an administrative fine of TRY 50,000 was imposed in each file. The Guide also notes that not all disclosures to third parties are unlawful. Sending a garnishment notice under Article 89 of the Enforcement and Bankruptcy Law, or disclosing the principal debtor's data to the creditor in order to protect the rights of a client who is an ordinary surety, may rest on the condition of “the establishment, exercise or protection of a right”.

03
Transfers Abroad and Generative AI ToolsYurt Dışına Aktarım ve Üretken Yapay Zekâ Araçları

The Guide sets out the three-tier system in Article 9, as amended by Law No. 7499 (adequacy decision, appropriate safeguards, and cases of incidental transfer). It then considers the data transfer implications of uploading client documents to generative AI tools such as ChatGPT, Claude or Gemini.

The Guide's explanationRehberdeki açıklama

Uploading a document containing personal data to an AI tool “should not be regarded merely as obtaining technical support or conducting legal research”. Having regard to the country in which the service provider is resident, the location of the servers and the location of sub-service providers, this operation may constitute a transfer abroad within the meaning of Article 9 of the PDPL. Even where the provider is located within Türkiye, the transfer of documents to it is a transfer within the scope of Article 8 of the PDPL.

Data Security Measures for Generative AI UseÜretken Yapay Zekâ Kullanımında Veri Güvenliği Tedbirleri

In its data security chapter, the Guide offers a concrete list of measures for AI tools. These include masking or anonymising personal data wherever possible, not uploading special categories of personal data to the system, and sharing only the minimum data required for the purpose. The Guide further recommends reading the data retention, model training, human review and sub-processor policies of the tool used, and laying down written rules of use within the office. In this chapter the Authority also refers to its earlier publications, such as the February 2026 publication on the Use of Generative AI Tools in the Workplace and the November 2025 Guide on Generative AI and the Protection of Personal Data.

04
Obligations of the Lawyer as Data ControllerVeri Sorumlusu Avukatın Yükümlülükleri

The Guide explains the scope of the exemption from registration. The exemption of lawyers from registration with the Data Controllers' Registry by the Board's decision No. 2018/32 dated 2 April 2018 has been understood in practice as meaning that “lawyers have no obligations under Law No. 6698”. The Authority emphasises that this understanding is incorrect and that the exemption is confined to registration with, and notification to, the Registry.

The Guide's explanationRehberdeki açıklama

Where data has not been obtained directly from the data subject, the privacy notice must be provided at the latest at the moment of first contact or first transfer, and applied in stages from receipt of the request for legal assistance through to the advisory process. Requests for erasure and destruction must be assessed together with the three-year document retention obligation under Article 39 of the Attorneyship Law and possible liability proceedings; where a request is refused, the basis and duration of the retention obligation must be set out clearly in writing to the data subject. Since most complaints reaching the Board centre on “wishing to know by what means their personal data was obtained by lawyers”, being able to document the source of the data both to the data subject and to the Board is important.

Data Subject Applications and Accessibilityİlgili Kişi Başvuruları ve Erişilebilirlik

In the Guide's example, when a person against whom enforcement proceedings have been initiated applies to the creditor's counsel, the lawyer is expected to explain whether the data was obtained “from the client, from the enforcement file, from public institutions or from publicly available sources”. The Guide also addresses keeping contact details current: offices with a website must keep the contact details on the site up to date, and lawyers without one must keep the details on the bar association roll up to date. Otherwise, the thirty-day period for responding may be missed because the application never reaches the lawyer.

Data Breach Notification and the Announcement PeriodVeri İhlali Bildirimi ve İlan Süresi

Using the example of a case file lost on the way back from the courthouse, the Guide explains that the lawyer must assess the affected persons and data categories and notify the Board within seventy-two hours under Board decision No. 2019/10. It also recalls that, by the Board's decision No. 2025/2451 dated 25 December 2025, breach announcements are limited to sixty days and are removed where it is documented that the data subjects were notified earlier. The Guide states the range of administrative fines applicable in 2026 for breach of the data security obligation as TRY 256,357 to TRY 17,092,242.

05
Breaches at Data Processors and Ransomware DecisionsVeri İşleyen Kaynaklı İhlaller ve Fidye Yazılımı Kararları

By its decision No. 2026/2039 dated 16 September 2026 and its decision No. 2026/2081 dated 23 September 2026, the Board announced on the Authority's website the breach notifications of a large number of data controllers affected by unauthorised access to the systems of a shared data processor. Most of the notifications contain the same wording: the breach occurred as a result of “unauthorised access to a server in the data processor's systems through the exploitation of a security vulnerability in a third-party software library in use”, and the data controllers learned of it on 10 September 2026 through the data processor's notification.

Where personal data is processed on behalf of the controller by a data processor, the controller and the processor are jointly responsible for taking the necessary security measures (Article 12(2) of the PDPL). The obligation to notify the breach to the Board and to the data subjects rests, under Article 12(5), with the data controller; in a breach originating from a shared processor, the affected controllers therefore each notify separately for their own data subjects. The administrative fine for breach of the data security obligation is, under Article 18, imposed on data controllers that are natural persons or private-law legal persons.

The Board's assessmentKurulun değerlendirmesi

In the ransomware decisions examined, the Board treated the controller's contradictory statements about the affected persons and data categories, its failure to submit to the Authority sample documents affected by the breach and its personal data processing inventory, the unavailability of log records and the absence of network segmentation as facts showing that the technical and organisational measures required by Article 12 of the PDPL had not been taken.

Mass Breach Notifications in Retail and E-CommercePerakende ve E-Ticaret Sektöründe Toplu İhlal Bildirimleri

The most extensive notification is that of Yeni Mağazacılık A.Ş., covering 6,263,305 persons among Eve Kozmetik customers. The notification states that, although Eve Mağazacılık had merged with Yeni Mağazacılık, the systems were kept separate and the breach covered only the name, surname, e-mail and telephone details of Eve Kozmetik customers. Shaya Mağazacılık A.Ş. reported that the name, surname, e-mail and address details of 2,298,726 employees and customers were affected. Samsonite Seyahat Ürünleri disclosed that, in addition to identity and contact details, “account authentication information (stored password values)” had been leaked. Desa Deri, Bilen Mağazaları, Locco Elektronik and numerous apparel, cosmetics and electronics retailers made notifications arising from the same source. In the authors' assessment, these notifications call for controllers that outsource their e-commerce infrastructure to examine how the security, audit and breach notification clauses of their data processor agreements are performed in practice.

Notifications by a Controller Established Abroad and a Professional AssociationYurt Dışında Yerleşik Veri Sorumlusu ve Meslek Kuruluşu Bildirimleri

Canva Pty Ltd reported that, following unauthorised access to a third-party tool, data associated with 424 organisations in Türkiye had been affected; the affected data comprised the business e-mail addresses and telephone numbers of customer employees together with contracts, invoices and data protection agreements. The Board resolved to announce the notification by its decision No. 2026/2037 dated 16 September 2026. The notification of the Association of Tax Inspectors, announced by decision No. 2026/2082 dated 23 September 2026, states that the Turkish identity numbers, dates of birth, passwords and contact details of up to 9,462 members were affected following unauthorised access to data processor systems. In membership structures where the identity number and the password are held in the same system, a security vulnerability at the processor concerns an area for which the controller is jointly responsible under Article 12(2) of the PDPL. In the authors' assessment, the controller's oversight of the processor's security measures carries particular weight in such structures.

Contradictory Statements and Measures Not Taken in Ransomware AttacksFidye Yazılımı Saldırılarında Çelişkili Beyanlar ve Alınmayan Tedbirler

The ransomware decisions examined in this note date from 2024 and appear among the decision summaries published by the Authority. In the incident that was the subject of the Board's decision No. 2024/2196 dated 26 December 2024, the systems of a company manufacturing plastic household goods were encrypted by ransomware. In its initial notification the company stated that employee and customer data had been affected; in subsequent letters it declared that no personal data had been affected; and in its criminal complaint it admitted that the data had been seized by the attackers. Considering these three statements together, the Board identified the contradiction. Recalling that “where data belonging to a legal person identifies or renders identifiable any natural person, such data is likewise protected under the Law”, the Board stated that the claim that invoice details were not personal data could not be accepted without sample documents being submitted. The penetration of the system despite a vulnerability test producing no findings was attributed to the inadequacy of the test; the enabling of two-factor authentication only after the breach, and the fact that nine companies were affected at once, were attributed to the absence of network segmentation. The Board resolved to impose an administrative fine of TRY 250,000 on the data controller.

Publicly Accessible Folders and Remote Desktop ServicesHerkese Açık Klasörler ve Uzak Masaüstü Servisleri

In decision No. 2024/1899 dated 7 November 2024, the marketing user account of a company providing corporate support services to its group companies in Europe was compromised from a blacklisted IP address. The attacker accessed folders set to “public” and the FTP server, and the data of approximately 70,000 persons was affected. The Board treated the inability to determine even the start date of the breach, and the retention of access logs for only ninety days before the breach, as a deficiency in monitoring and control, and resolved to impose an administrative fine of TRY 700,000. Decision No. 2024/1898 of the same date concerns a company in the pharmaceutical and health products field. In that incident the server was encrypted by ransomware; the decision summary states that 520 persons were affected. Having regard to the possibility that entry was gained by brute force through a remote desktop service that should not have been exposed to the internet, and to the deletion of the server log records, an administrative fine of TRY 350,000 was imposed. In both decisions, the log-keeping, access authorisation matrix and strong password principles under the heading “Monitoring of Personal Data Security” in the Personal Data Security Guide served as the concrete criteria for the sanction.

FileDecisionAffectedOutcome
Yeni Mağazacılık (Eve Kozmetik)2026/2039 – 2026/20816,263,305 personsAnnounced; processor-originated
Shaya Mağazacılık2026/2039 – 2026/20812,298,726 employees and customersAnnounced; processor-originated
Canva Pty Ltd2026/2037424 organisations in TürkiyeAnnounced; third-party tool
Association of Tax Inspectors2026/2082Up to 9,462 membersAnnounced; identity number and password
Plastic household goods manufacturer2024/2196Employee and customer dataTRY 250,000; contradictory statements, no segmentation
Corporate support company2024/1899Approximately 70,000 personsTRY 700,000; public folders, short log retention
Pharmaceutical and health products company2024/1898520 personsTRY 350,000; remote desktop, deleted logs
Processor-originated breach announcements and ransomware decisions
06
The Authority's Other AnnouncementsKurumun Diğer Duyuruları

The Authority's Selected Recent Developments bulletin of 10 September 2026 records the following developments. The Medium-Term Programme (2027–2029), published in the Official Gazette of 6 September 2026, envisages that the alignment of Law No. 6698 with the European Union General Data Protection Regulation will be completed in the third quarter of 2027. The Authority has also published the Guide on Compliance with the Personal Data Protection Law for Public Institutions and Organisations and Professional Organisations with Public Institution Status. The circular on the Türkiye Artificial Intelligence Action Plan (2026–2030) appeared in the Official Gazette of 18 August 2026. In the Board decision summaries and principle decisions sections, there has been no new content since the publication of 10 August 2026.

07
Assessment and ConclusionGenel Değerlendirme ve Sonuç
“Read together, the Guide and the decisions examined point to two priority compliance steps: documenting the source of the data a lawyer processes, and monitoring in practice the security and notification clauses of data processor agreements.”

The Guide addresses the data processing operations involved in legal practice together with the Board's existing decisions and explains systematically matters ranging from the lawyer's status to the use of AI tools. In the authors' assessment, one consequence of the Guide that stands out for practice is its express statement that exemption from registration does not mean exemption from other obligations. In the light of that statement, law firms are advised to set their privacy notice, retention and destruction, application and breach notification processes down in written policies. Since the complaints reaching the Board concentrate on the source of the data, those policies should give priority to a record-keeping system that shows where each item of data was obtained. For generative AI tools, converting the Guide's list of measures into written in-house rules is regarded as a sufficient starting point.

The breach announcements and the 2024 ransomware decisions examined in this note show how liability is allocated for breaches at data processors. Although the controller and the processor are jointly responsible for security measures, the notification obligation and the administrative fine fall on the controller; in the decisions examined, contradictory statements, unsubmitted inventories and documents, and missing log records were the grounds for the fine. In the authors' assessment, this places data processor agreements and incident response plans among the priority elements of a compliance programme. In conclusion, law firms are advised to translate the Guide's explanations into written policies and a record-keeping system that shows the source of the data. Controllers that outsource their e-commerce or membership infrastructure would do well to review their processor audits, network segmentation, log retention periods and seventy-two-hour notification workflow in the light of the decisions examined in this note.

Legislation and Decisions CitedAtıf Yapılan Mevzuat ve Kararlar

Law No. 6698 on the Protection of Personal Data, Arts. 4, 5/2(d), 8, 9, 12/1(a), 12/2, 12/5, 18 · Law No. 7499 · Attorneyship Law No. 1136, Arts. 2/3, 39 · Criminal Records Law No. 5352, Art. 7 · Enforcement and Bankruptcy Law No. 2004, Art. 89 · Regulation on Personal Health Data, Art. 10 · PDPA Publication No. 115 (Implementation Guide) · Board decisions 2018/32, 2019/10, 2019/166, 2019/308 (Principle Decision), 2020/429, 2021/111, 2021/115, 2021/228, 2021/511-512-513, 2021/1111, 2022/655, 2023/78, 2023/437, 2024/1898, 2024/1899, 2024/2196, 2025/2451, 2026/2037, 2026/2039, 2026/2081, 2026/2082 · Council of State, 1st Chamber, E. 2002/26, K. 2002/52

This article has been prepared for general information purposes only and does not constitute legal advice. The board decisions, guides and announcements referred to are based on sources published on the relevant authorities' websites as at the date of publication; findings recorded in decision summaries are those of the Boards and do not reflect the views of Devin Law & IP. This article does not create an attorney-client relationship and contains no undertaking as to its updating. 28 September 2026.

Full briefing noteDownload the bilingual PDF version of this briefing note, with tables and decision summaries.
Download PDF