Home About Us Services Awards Team Insights Career Contact Us TÜRKÇEENGLISH Devin Law & IP — Istanbul
← All Insights
CategoryData Protection
Published16 June 2026
Authors
Uğurcan TekinPartner
İnci ÖzçilsalAttorney at Law

The Constitutional Court’s Viennalife Judgment: Publicly Disclosed Personal Data and the Principle of Legality

The judgment of the Constitutional Court dated 27 January 2026, application no. 2020/32193, concerning Viennalife Emeklilik ve Hayat A.Ş., was published in the Official Gazette of 16 June 2026, No. 33282. One of the most contested processing conditions in personal data protection law is the question of the scope and purposes for which personal data made public by the data subject may be processed.

The spread of internet use, the fact that it has become ordinary for individuals to share their contact details and other personal data publicly through various platforms, and the increasingly intensive use of open-source data in commercial activities, make the legal debates concerning the processing of publicly disclosed data more important with each passing day.

Under Article 5(2)(d) of Personal Data Protection Law No. 6698, personal data made public by the data subject may be processed without seeking explicit consent. Because the Law contains no detailed regulation of the scope, limits and consequences of public disclosure, however, the field of application of that processing condition has been shaped largely through the decisions of the Personal Data Protection Board and the guidance documents published by the Authority.

In the approach developed by the Board over the years and now settled, the fact that the data subject has made personal data public is not in itself regarded as sufficient; it is also accepted that the purpose for which the data was disclosed, and whether the subsequent processing activity is compatible with that purpose, must be assessed. That approach — expressed in practice as the “intention to disclose” and the “purpose of disclosure” — has in recent years become one of the principal foundations of the Board’s decisions.

“The judgment examines the Board’s approach not from the perspective of the substance of data protection law, but from that of administrative sanctions, the law of misdemeanours and the principle of legality in offences and penalties.”

The Constitutional Court’s Viennalife judgment examined that approach not from the perspective of the substance of data protection law but from that of administrative sanctions, the law of misdemeanours and the principle of legality in offences and penalties — and in that respect established case law capable of producing significant consequences in the field of personal data protection.

This note addresses the dispute that gave rise to the judgment, the Constitutional Court’s assessments, and the likely effects of the judgment on practice under the Personal Data Protection Law.

The Court framed the case as a question of legality in sanctions, not of data protection doctrine.

Part One — The Existing Legal Framework

Article 5(2) of the Personal Data Protection Law sets out the exceptional circumstances in which personal data may be processed without the explicit consent of the data subject. One of those exceptions is the case, contained in Article 5(2)(d), of data “having been made public by the data subject”.

By this provision the legislature did not consider it necessary to obtain separate explicit consent in respect of personal data which the data subject has, of its own volition, disclosed to the public or made accessible to all. A legal basis was thereby created for the processing, to a certain extent, of data which the data subject has itself placed in the public domain.

The Law contains no detailed regulation, however, of the scope of the concept of public disclosure, the conditions under which disclosure occurs, the purposes for which disclosed data may be used, or the limits of that processing condition. The text of the Law regards it as sufficient that the data subject has itself made the data public; no further criterion is foreseen. This has given rise to various debates in practice. In particular, the extent to which personal data available on the internet may be used, the degree of freedom to process that is conferred by the data subject having made data public, and whether disclosed data may subsequently be used for different purposes, have frequently been the subject of Board decisions.

In the practice developed by the Board over time, certain additional criteria not expressly contained in the text of the Law have been read into the concept of public disclosure. The Board does not regard it as sufficient that the data subject has made its data accessible to all; it also considers it necessary to assess the purpose for which the data subject disclosed the data and whether the subsequent processing activity is compatible with that purpose.

Indeed, in various guidance documents published by the Board and in the decisions it has given, it has been stated that for personal data to be regarded as public the data subject must have had an intention to disclose it. It has further been assessed that where the data subject has made data public for a particular purpose, that data may be used only within the scope of activities connected with that purpose.

“In the Board’s practice, public disclosure is interpreted not as a processing condition permitting absolute and unlimited use of the data, but as a legal basis confined to the data subject’s purpose in disclosing it.”

On the Board’s approach, for example, a person sharing contact details online in order to publicise professional activities does not mean that those details may be used for every kind of commercial or marketing purpose. In other words, in the Board’s practice public disclosure is interpreted not as a processing condition permitting absolute and unlimited use of the data, but as a legal basis confined to the data subject’s purpose in disclosing it. Although that approach has been consistently adopted in the Board’s practice for many years, the statutory basis of those criteria — and in particular whether they may be taken as the basis of administrative sanctions — has continued to be debated in scholarship.

The Constitutional Court’s judgment arose precisely at that point, raising the question of the extent to which the Board’s “intention to disclose” and “purpose of disclosure” approach may be taken into account for the purposes of an administrative sanction.

A further point deserving attention is that the Law adopts a different systematic treatment for ordinary and special categories of personal data. While Article 5 regulates the data subject having made the data public as a processing condition for ordinary personal data directly, Article 6 — as amended in 2024 — expressly includes, for special categories of personal data, the additional criterion of compatibility with the intention to disclose. Notwithstanding that difference, the Board’s practice has for many years in fact required the criteria of intention and purpose of disclosure in respect of ordinary personal data as well. The fundamental debate giving rise to the judgment stems essentially from that systematic difference.

Part Two — The Dispute and the Proceedings

The subject matter of the dispute. The judgment concerns a dispute arising from the questions of the extent to which personal data made public online by the data subject may be used by third parties, and how the limits on the processing of that data are to be assessed for the purposes of an administrative sanction. At the centre of the dispute lies the scope of the processing condition in Article 5(2)(d) — “having been made public by the data subject”. The core issue is whether, where data shared publicly by the data subject is used for a purpose other than that of disclosure, the processing may be regarded as unlawful and an administrative sanction imposed on that basis.

In that respect the judgment does not concern only the lawfulness of a concrete processing activity; it also raises the broader legal question whether interpretations developed by the Board may constitute the basis of an administrative sanction.

The proceedings before the Board. According to the case file, the data subject A.Y. asserted that he had been telephoned by Viennalife Emeklilik ve Hayat A.Ş. for the purpose of holding a discussion and arranging an appointment in connection with insurance services, and applied to the Personal Data Protection Authority stating that his personal data had been obtained and used without his consent.

In the examination opened upon the complaint, an explanation was sought from the applicant company; in the defences submitted to the Board, the company stated that the data subject’s name, surname and telephone number had been obtained from a website named hizmetburada.com.

The applicant company asserted that the data subject’s contact details had been published on that website in a manner accessible to all, that the data subject had made that data public of his own volition, and that the data could therefore be processed within the scope of Article 5(2)(d). On the company’s case, the data subject having shared his contact details publicly online constituted the legal basis for obtaining and using that data. The applicant further argued that the Law contained no provision to the effect that publicly disclosed data may be used only for particular purposes, so that the data subject having made his data public constituted a sufficient legal ground for processing.

The Board reached a different assessment. In the Board’s view, the presence of the data subject’s contact details online is not in itself determinative. The fact that personal data is publicly available does not mean that it may be used without limit and for every purpose. The Board assessed that the data subject had made those contact details public for a particular purpose, whereas the applicant company had used the data for marketing and appointment-setting purposes within the scope of insurance services. The Board’s decision dwelt in particular on the concepts of intention and purpose of disclosure, and stated that a data subject making data public cannot be regarded as an unlimited permission for that data to be used within the scope of every kind of commercial activity.

The Board’s approach to the intention to disclose. In its decision the Board repeated the approach adopted in its earlier decisions and guidance documents. It stated that public disclosure does not mean merely that the data has become technically accessible to all; the data subject must also have had an intention to make that data public.

The Board further assessed that the field of use of disclosed data is limited by the data subject’s purpose in disclosing it. In the Board’s view, a data subject making data public for a particular purpose does not confer on third parties the authority to use that data for different purposes.

The Board explained that approach in its decision by reference to various examples. A person sharing contact details on a second-hand vehicle sales platform, for instance, does not mean that those details may be used for advertising or marketing purposes. Likewise, a person publishing contact details online for the purpose of offering a particular service does not produce the consequence that the information may be used within the scope of different commercial activities. The Board made a similar assessment in the case at hand and concluded that there was no connection between the data subject’s purpose in sharing his contact details online and his being telephoned in connection with insurance activities. The Board accordingly assessed that the personal data had been processed for a purpose other than that of disclosure and that the processing was unlawful.

The decision of the Magistrates’ Court. The applicant company objected to the administrative fine imposed by the Board before the Magistrates’ Court in Criminal Matters. Following its examination, the Istanbul Anatolia 5th Magistrates’ Court in Criminal Matters found the Board’s fundamental legal approach to be sound. The court assessed that the presence of the data subject’s contact details online would not automatically render the use of that information within the scope of insurance activities lawful, and adopted the Board’s finding that the data had been used for a purpose other than that of disclosure. The court nonetheless considered that the grounds for departing from the lower limit in determining the administrative fine had not been sufficiently established, and reduced only the amount of the sanction. The Board’s legal assessment was thereby preserved, while the amount of the fine was redetermined.

The constitutional dimension. When the dispute was brought before the Constitutional Court by way of individual application, the focus of the debate shifted considerably. In the application, rather than the question whether the processing of personal data was lawful as a matter of substantive law, the constitutional basis of the administrative sanction imposed was called into question. On the applicant’s case, Article 5(2)(d) regulates only the condition that the data “has been made public by the data subject”. By contrast, criteria taken as a basis by the Board — such as “purpose of disclosure”, “intention to disclose”, “use outside the purpose of disclosure” or “use compatible with the purpose of disclosure” — have no counterpart in the text of the Law. The applicant therefore argued that a new obligation not contained in the Law had been created by the Board through interpretation, and that an administrative sanction had then been imposed on the footing that the obligation had been breached. On the applicant’s case, individuals must be able to foresee in advance which of their conduct will be subject to sanction. The subsequent creation of a criterion not expressly contained in the Law by way of administrative interpretation, and the imposition of sanctions on those who act contrary to it, is incompatible with the principles of legal certainty and clarity. The applicant company accordingly asserted a violation of the principle of legality in offences and penalties guaranteed by Article 38 of the Constitution.

The dispute thereby moved beyond a technical debate of interpretation concerning the protection of personal data and became the subject of a constitutional examination as regards the limits of administrative sanctions, the principle of legality and the scope of the Board’s power of interpretation. The Constitutional Court conducted its examination essentially within that framework, assessing not whether the intention-to-disclose approach is sound as a matter of data protection law, but whether that approach can constitute the basis of an administrative sanction.

Part Three — The Court’s Assessment and the Reasoning of the Violation Judgment

In assessing the dispute, the Constitutional Court first defined the scope of the debate and addressed the substance of the application not as a technical debate of interpretation concerning the law on the protection of personal data, but within the scope of the principle of legality in offences and penalties guaranteed by Article 38 of the Constitution.

Within that framework the Court stated that the fundamental issue to be resolved in the case was not whether the data subject’s contact details had been made public, or whether the intention-to-disclose approach adopted by the Board is sound as a matter of data protection law. In the Court’s view, the matter genuinely requiring assessment was whether it is possible to impose an administrative sanction on the applicant on the basis of criteria not expressly regulated in the Law. The Court’s assessment was accordingly shaped essentially around the principle of legality, the limits of administrative sanctions, and whether obligations not contained in the Law may be created by way of interpretation.

The principle of legality in misdemeanours and administrative sanctions. The Court first addressed the scope of the principle of legality in offences and penalties in Article 38 of the Constitution. In the Court’s view, one of the fundamental elements of the rule of law is that individuals be able to foresee in advance which of their acts are subject to legal sanction. The conduct that is the subject of a sanction, and the consequences attached to that conduct, must therefore be regulated with sufficient clarity. The Court emphasised that the principle of legality applies not only in criminal law but also in respect of administrative sanctions and misdemeanours. Administrative fines to be imposed on individuals must accordingly have a statutory basis; the act that is the subject of the sanction must be determined with sufficient clarity; and individuals must be able to foresee in advance which of their conduct will give rise to a sanction.

The Court further stated that the principle of legality does not merely require the existence of a statutory provision in the formal sense; the regulation concerned must also be certain, accessible and foreseeable. Regulations that are not sufficiently clear to enable individuals to direct their conduct lawfully will not satisfy the requirements of the principle of legality.

At that point the Court drew attention in particular to the difficulties, from the perspective of the rule of law, of creating new obligations by way of interpretation or of extending the scope of existing obligations to the detriment of the individual. The Court further emphasised that the principle of legality applies in the law of misdemeanours in a manner similar to criminal law, and stated that the acts subject to sanction and the scope of the sanction must be determined by statute. That approach constitutes a constitutional reflection of the principle of legality contained in Article 4 of the Misdemeanours Law.

Examination of Article 5(2)(d). Having set out the general framework of the principle of legality, the Court examined the provisions applied in the case. It found that Article 5(2)(d) contains only the condition that the data has “been made public by the data subject”.

In the Court’s view, an examination of that provision shows that concepts such as “purpose of disclosure”, “intention to disclose”, “use compatible with the purpose of disclosure” and “use outside the purpose of disclosure” are not expressly regulated in the text of the Law. In other words, the legislature regulated the data subject having itself made the data public as a processing condition, but did not additionally regulate the purpose for which disclosure was made, or the extent to which subsequent processing activities must be connected with that purpose. The Court underlined that point in particular and stated that the approach adopted by the Board cannot be derived directly from the text of the Law.

The Board’s approach and the Court’s assessment of it. The most striking part of the judgment concerns the Court’s assessment of the intention-to-disclose approach adopted by the Board. The Court first set out the approach adopted by the Board in the case: the Board investigates the purpose for which the data subject disclosed the data and assesses lawfulness according to whether the subsequent processing activity is compatible with that purpose. On the Board’s approach, the data subject having made the data public is not in itself sufficient; the purpose for which the data subject opened that data to the public must also be determined. Where the subsequent processing activity is not compatible with that purpose, the Board assesses that the processing cannot be regarded as lawful.

Although the Court set out the Board’s approach in detail, it strikingly made no assessment as to whether that approach is right or wrong as a matter of data protection law. What the judgment dwells upon is the statutory basis of that approach.

“The subsequent creation of an obligation not expressly contained in the Law by way of interpretation, and the imposition of a sanction on the ground that it has been breached, is incompatible with the principle of legality.”

In the Court’s view, the interpretation adopted by the Board essentially produces the result of creating a new criterion not expressly regulated in the Law. Whereas the Law regulates only the condition of “having been made public”, the Board adds the further criteria of “purpose of disclosure”, “intention to disclose”, “use compatible with the purpose of disclosure” and “use outside the purpose of disclosure”. In the Court’s view, although criteria developed by the administration or the judicial authorities through interpretation may in certain circumstances be taken into account in legal assessments, turning those criteria directly into the basis of a sanction requires a separate assessment.

In the case at hand, the principal basis of the administrative fine imposed on the applicant was the assessment that the data had been used outside the data subject’s purpose of disclosure. In the Court’s view, however, the criterion of “use outside the purpose of disclosure” is not expressly regulated in the Law. It was therefore not possible for the applicant to foresee in advance which of its conduct would give rise to a sanction. In other words, a person examining the text of the Law sees only that it is sufficient for the data subject itself to have made the data public; it is not possible for that person to derive from the Law the additional criteria subsequently developed by the Board.

The Court assessed that this situation is problematic from the perspective of the principles of legal certainty and foreseeability. Individuals must be able to foresee in advance the acts for which they may be exposed to an administrative sanction. The subsequent creation of an obligation not expressly contained in the Law by way of interpretation, and the imposition of a sanction on the ground that the obligation has been breached, is incompatible with the principle of legality. The Court accordingly concluded that, irrespective of the correctness of the Board’s approach as a matter of data protection law, that approach cannot be turned into a norm of administrative sanction in the absence of a statutory basis.

The violation judgment. In the light of all of those assessments, the Constitutional Court concluded that the administrative fine imposed on the applicant violated the principle of legality in offences and penalties. The Court did not state in its judgment that the Board’s intention-to-disclose approach is entirely wrong as a matter of data protection law or that it may no longer be applied. Instead, it stated that the approach is not expressly regulated in the Law and cannot for that reason constitute the basis of an administrative sanction.

The Court’s conclusion should not therefore be interpreted as meaning that publicly disclosed personal data may be freely processed in every case, or that the concept of the purpose of disclosure has disappeared entirely from data protection law. The fundamental principle established by the judgment is that a criterion not expressly contained in the Law cannot be created by way of interpretation and made the basis of an administrative fine.

Guidance documents remain authoritative for practice — but not, by themselves, a basis for sanctions.
Article 38 of the Constitution requires foreseeability in administrative sanctions too.

Conclusion and Assessment

Although the Viennalife judgment appears at first sight to concern a dispute about the processing of publicly disclosed personal data, in our view its true significance lies in its delineation of the limits of the principle of legality in respect of administrative sanctions under the Personal Data Protection Law. What the judgment emphasises above all is that a criterion not expressly contained in the Law cannot be created by way of interpretation and made the basis of an administrative fine. In that respect the Court made no assessment as to whether the Board’s “intention to disclose” or “purpose of disclosure” approach is right or wrong as a matter of data protection law; it stated only that the approach cannot be turned into a norm of sanction in the absence of a statutory basis.

One of the judgment’s important consequences is that it points to the need to assess the concept of public disclosure differently for ordinary and special categories of personal data. Following the amendment made in 2024, Article 6 expressly includes, for special categories of personal data, the criterion of compatibility with the intention to disclose, whereas no similar provision was introduced in Article 5 in respect of ordinary personal data. Nevertheless, the Board’s practice has for many years in fact required the criteria of intention and purpose of disclosure for ordinary personal data as well. The judgment thereby opens for debate the limits of applying to ordinary personal data an approach developed for special categories, and is capable of contributing to a clearer assessment of the distinction between Articles 5 and 6 within the existing scheme of the Law.

The judgment also has notable consequences from the perspective of comparative law. Under the EU General Data Protection Regulation, “having been made public” is not regulated as a separate processing condition for ordinary personal data; ordinary public data is in most cases assessed within the scope of the legitimate interests ground. By contrast, the concept of public disclosure is separately regulated under the GDPR for special categories of personal data, where the data subject having “manifestly” made the data public is accepted as an exceptional processing condition. It may therefore be argued that the Board’s requirement of an intention to disclose in respect of ordinary personal data amounts to reflecting onto ordinary data the approach adopted under the GDPR for special categories. The Constitutional Court’s judgment establishes that, at least for the purposes of administrative sanctions, that approach cannot be applied in the absence of an express statutory basis.

It would nonetheless not be sound to interpret the judgment as meaning that publicly disclosed personal data may be processed in every case and without limit. Although it may be assessed that the judgment could create a wider field of manoeuvre in practice as regards the processing of personal data publicly available online, the use of open-source data and web scraping activities, the requirement that processing activities be assessed within the framework of the general principles of the Law and the fundamental rights and freedoms of data subjects continues to apply.

A further important consequence of the judgment concerns the legal nature of the Board’s guidance documents and settled practice. Those documents are undoubtedly important guiding sources for practice. Following the judgment, however, it is to be expected that turning criteria contained only in guidance documents or in the Board’s practice directly into a basis for administrative sanctions will be debated more intensively.

In conclusion, the judgment is regarded as important and precedent-setting case law going beyond a dispute about the processing of publicly disclosed personal data — as regards the statutory basis of administrative sanctions applied under the Personal Data Protection Law, the limits of the Board’s power of interpretation, and the application of the principle of legality in the law of misdemeanours. The judgment is expected to have significant effects in the period ahead both on practices relating to the processing of public data and on the judicial review of Board decisions.