Home About Us Services Awards Team Insights Career Contact Us TÜRKÇEENGLISH Devin Law & IP — Istanbul
← All Insights
CategoryData Protection
Published31 March 2026
Authors
Uğurcan TekinPartner
İnci ÖzçilsalAttorney at Law

Sharing Data With Third Parties and the Rules Governing Debt Payment Processes

The law on the protection of personal data guarantees that individuals have control over data relating to them and are able to determine their own future within the scope of the right to information. Financial information in particular, being directly connected with an individual’s economic situation and private life, is addressed with particular sensitivity within the personal data protection regime.

Debt information contains data enabling direct inferences to be drawn about a person’s economic situation, spending habits and capacity to pay, and falls within the individual’s sphere of financial privacy. The sharing of such information with third parties therefore gives rise to legal risks that must be carefully assessed both by data controllers and by practitioners.

This note addresses the nature of debt information as personal data under Personal Data Protection Law No. 6698, the obligations of companies when faced with third-party requests, the standards of practice in the light of decisions of the Personal Data Protection Board and of the courts, and the consequences under the Turkish Code of Obligations of processes for paying a debt on behalf of another.

Debt information sits at the intersection of financial privacy, customer secrecy and data security obligations.

Debt Information as Personal Data and Financial Privacy

Under Article 3 of the Law, personal data means “any information relating to an identified or identifiable natural person”. Data concerning a debt relationship falls directly within that definition. The principal debt, the amount of interest, the payment plan, default information, enforcement files and the source of the debt all enable assessments to be made about an individual’s financial discipline and economic situation. Such information is therefore regarded in scholarship as falling within the scope of financial privacy.

Court decisions and the case law under the Law establish conclusively that a person’s debt information — the amount of the debt, the creditor institution, the enforcement file and so forth — constitutes personal data and may not be shared with third parties without the explicit consent of the data subject. That prohibition extends to the debtor’s closest family members — mother, father, spouse, sibling, child — and to friends.

“Debt information is not merely economic data; it discloses the individual’s financial position and is, in that respect, personal and private information requiring legal protection.”

Prohibition on sharing with family members and relatives. In its decision of 14 January 2020, numbered 2020/26, the Board found that an attorney’s transmission of debt information by SMS to the debtor’s sibling — even though the sibling’s telephone number had been provided to the attorney by another person — was contrary to the data security obligation under Article 12, and imposed an administrative fine. Similarly, in its decision of 28 May 2020, numbered 2020/429, the sending of messages containing debt information to the debtor’s elder brother and work colleagues, and in its decision of 4 March 2022, numbered 2022/184, the sending of such messages to telephones belonging to the debtor’s sibling and spouse, were found unlawful. The Constitutional Court’s judgment of 30 April 2025, application no. 2022/5840, likewise treated the sending of a message to a child’s telephone concerning a father’s debt as a data breach.

Unlawful use of communication channels. In its decision of 9 February 2021, numbered 2021/111, the Board found a violation where an SMS was sent notwithstanding that the number was recorded in the Legal Follow-Up System as “belonging to a relative”. Further, in its decision of 19 January 2023, numbered 2023/78, the sending of messages to the corporate lines of company employees in connection with a shareholder’s debt was likewise found contrary to the conditions for processing.

Banking secrecy and breach of contract. In its decision of 11 March 2019 (Case No. 2017/5213 E., 2019/2006 K.), the 11th Civil Chamber of the Court of Cassation characterised a bank’s sharing of customer account statements with a third party as a breach of contract and an infringement of personality rights. In the same vein, in its decision of 13 February 2025 (Case No. 2022/3953 E., 2025/2404 K.), the 4th Civil Chamber held that banks providing more information than requested, even to competent authorities, is contrary to the principle of data minimisation and to the duty of secrecy.

The Prohibition on Sharing With Family Members and Relatives

One of the requests most frequently encountered in practice is that of persons stating that they are the debtor’s spouse, family member or relative and seeking information about the data subject’s debt position. There is, however, no provision of Turkish law conferring any automatic, implied or general authority to share personal data on the basis of marriage, kinship or social proximity.

For the purposes of the Personal Data Protection Law, the status of spouse, mother, father, child, sibling or friend does not alter third-party status before the data controller; sharing data with those persons is possible only where one of the grounds of lawfulness foreseen in the Law is present.

That approach has been consistently adopted in the decisions of the Board. The Board has assessed the sending by an attorney of debt information by SMS to the debtor’s sibling as a breach of the data security obligation, and has likewise treated the sending of messages containing debt content to the debtor’s elder brother, spouse or work colleagues as unlawful disclosure of data.

The Constitutional Court has likewise characterised the sending of a message to a child’s telephone by reason of a debt belonging to the father as an interference with the right to the protection of personal data, and held that the practice violated the constitutionally guaranteed right to the protection of private life.

The Board’s practice further accepts that even implying the existence of a debt relationship through third parties — without expressly disclosing it — may constitute unlawful processing. Communications indirectly revealing the existence of a debt have accordingly been assessed as constituting an interference with the data subject’s fundamental rights and freedoms.

Obligations of Companies Faced With Third-Party Requests

The room for manoeuvre available to companies faced with persons applying in order to learn the debt of a spouse, friend or family member is determined by the data security provisions of Law No. 6698. Data controllers are obliged not merely to refrain from providing information to unauthorised persons, but to establish a system preventing unlawful access to personal data from the outset.

Companies should accordingly not share debt information in the absence of the debtor’s explicit consent, a duly executed power of attorney, or express statutory authority. Because debt information is assessed both as financial personal data relating to an individual’s economic situation and as customer secrecy, sharing it with third parties may result in a data security breach.

Two-factor verification. In the Board’s decisions it is expressly stated that the use of a single verification element in debt enquiry systems — for instance the Turkish identification number alone — is not sufficient, and that the application of two-factor verification methods such as SMS verification or a person-specific password is a requirement of the data security obligation.

Indeed, in the Board’s decision of 25 February 2021, numbered 2021/140, it was expressly established that enabling access to individuals’ debt information by the entry of a single item of information in debt and property enquiry systems operated by municipalities was contrary to the obligation under Article 12 to prevent unlawful access to personal data.

That approach was given further concrete form by the Board’s Principle Decision of 21 April 2022, numbered 2022/388, which stated that single-stage verification methods are not sufficient for data security in systems providing remote access to personal data, and that data controllers must establish a risk-based security model taking into account the nature of the personal data, its degree of confidentiality and the harm that may arise in the event of a breach.

Data security therefore denotes an active compliance responsibility in which technical infrastructure, access control and organisational measures operate together, rather than a passive duty of confidentiality.

Single-factor debt enquiry screens have repeatedly been found to breach the obligation to prevent unlawful access.

Exceptional Cases of Lawful Sharing

Although the sharing with third parties of personal data relating to a debt relationship or enforcement proceedings is as a rule regarded as unlawful, where express statutory authority or a legal necessity exists the transfer of data may exceptionally be regarded as lawful.

Attachment notices sent through enforcement offices under Article 89 of the Enforcement and Bankruptcy Law form part of the statutory enforcement procedure directed at identifying and protecting the debtor’s rights and receivables held by third parties. The Board accepts that processing carried out in that context may rest on the grounds of its being “expressly provided for by law” under Article 5(2)(a) and of processing being “mandatory for the establishment, exercise or protection of a right” under Article 5(2)(e).

The existence of a statutory basis does not, however, confer an unlimited field for data sharing. Lawfulness can arise only in respect of a transfer of data that is limited to, and proportionate with, the purpose of the transaction.

The Court of Cassation has likewise made clear that even in responding to a request from a competent court, a data controller may not share personal data going beyond the scope of what has been requested. In the decision of the 4th Civil Chamber of 13 February 2025 (Case No. 2022/3953 E., 2025/2404 K.), it was held that submitting bank account movements relating to periods not requested by the court was contrary to the data controller’s duty of care and violated the principle that personal data must be “connected with, limited to and proportionate to the purpose”.

Accordingly, even in data sharing carried out on the basis of enforcement or judicial processes, the sharing must remain limited to the data requested, unnecessary disclosure of personal data must be avoided, masking or narrowing methods should be applied where possible, and the principle of data minimisation must be observed in concrete terms.

Third-party payment is permitted; disclosure of the debtor’s financial data is not.

Paying a Debt on Behalf of Another and Its Legal Consequences

Under the Turkish Code of Obligations, unless the creditor has a particular interest in performance by the debtor personally, performance by a third party is possible. In monetary debts in particular, third-party performance is as a rule valid, and the creditor’s ability to refuse to accept that performance may arise only in exceptional cases.

A critical distinction. A third party’s right to pay a debt and a right of access to the debtor’s financial data are different legal categories. A third party may contribute to the extinction of the debt by performing a particular amount on the debtor’s behalf; that possibility does not, however, of itself legitimise the data controller disclosing information concerning the amount of the debtor’s debt, its payment history or the scope of the debt relationship.

In practice, where a third party applying to make a payment knows the amount of the debt and wishes to perform a particular sum, the creditor may accept that payment. Where the third party does not know the amount and requests that it be disclosed, however, that information — being personal data — cannot be shared in the absence of the data subject’s explicit consent or one of the other processing conditions foreseen in the Law.

For a payment made by a third party to extinguish the debt, it is essential that the payment be made to the correct person and to the correct place. Court decisions have accordingly made clear that where a company debt is paid into a third party’s personal account rather than the company account, the debt will not be extinguished (Istanbul Anatolia 8th Commercial Court of First Instance, Case No. 2023/73 E., 2024/1003 K.).

Subrogation and recourse. Under Article 127 of the Code of Obligations, a third party who performs to the creditor is in certain circumstances subrogated to the creditor’s rights to the extent of that performance. A third party paying the debt does not, however, produce the consequence of subrogation in every case. Where the conditions of subrogation under Article 127 are not satisfied, the payment made by the third party may give rise to a right of recourse against the debtor. The legal nature of that right of recourse may be assessed, according to the features of the particular case, within the framework of the provisions on agency without authority or unjust enrichment.

Documenting a payment made by a third party is important both for the transparency of the debt relationship and for the prevention of future disputes. The receipt issued should state clearly to which debt the payment relates and that the payment was made “on behalf of the debtor”. In determining the content of the receipt, however, the principle of data minimisation must also be observed; personal data unrelated to the payment should not be included.

Conclusion and Assessment

When the legislative provisions, the decisions of the Board, the case law and the assessments in scholarship are considered together, the fundamental principle that emerges is clear: debt information is not merely economic data but personal and private information disclosing an individual’s financial position and requiring legal protection in that respect.

In practice, a significant proportion of data breaches is seen to arise not from bad-faith conduct but from good-faith disclosures made out of trust in a family relationship, with the intention of helping, or with a view to facilitating payment of the debt. The determinative element in the law on the protection of personal data is, however, not intention but the legal consequence of the processing activity.

The approach to be followed in practice is that debt information should not be shared with third parties in the absence of explicit consent or a statutory obligation; the status of spouse, family member or relative should not be accepted as legal authority for access to data. Although third parties may make payment on behalf of another, that does not require the disclosure of the debtor’s financial information. For companies, the safe approach is to refuse to share information, to communicate only with the authorised person, and to conduct payment processes in accordance with the principle of data minimisation.

Sharing of this kind with unauthorised persons may give rise not only to administrative sanctions but also to liability in damages and criminal liability. The unlawful sharing of personal data with third parties is regulated as an offence under Article 136 of the Turkish Criminal Code, and the case law expressly accepts that such disclosures may give rise to criminal liability.

The Turkish legal system permits payment by a third party in order to facilitate performance of the debt, but has by contrast foreseen a deliberate and strict limitation on access to, and sharing of, debt information. Assessed in the light of current case law, the essential approach to be adopted in the sharing of debt information is that ease of payment may be facilitated, but privacy of data cannot be compromised.