Home About Us Services Awards Team Insights Career Contact Us TÜRKÇEENGLISH Devin Law & IP — Istanbul
← All Insights
CategoryData Protection
Published14 February 2026
Authors
Uğurcan TekinPartner
İnci ÖzçilsalAttorney at Law

The Turkish Data Protection Board’s Ex Officio and On-Site Inspection Powers

The Personal Data Protection Board is charged with carrying out supervisory and regulatory activities in relation to the protection of personal data in the manner prescribed by Personal Data Protection Law No. 6698. There are two principal routes through which the Board may exercise its supervisory power: investigation upon complaint, initiated by an application from a data subject, and ex officio investigation, in which the Board acts of its own motion without any application. Article 15 of the Law further empowers the Board to conduct an on-site inspection at the premises of the data controller where it deems it necessary.

The Board’s decisions show that supervision is not conditional on a complaint being filed.

The Ex Officio Investigation Power

As set out in Article 15 of the Law: “The Board shall carry out the necessary examination in matters falling within its remit, either upon complaint or ex officio where it becomes aware of an allegation of infringement.” The provision does not limit the Board’s ex officio power to any particular subject matter or condition. Where the Board becomes aware of an allegation of infringement in a matter falling within its remit, it may open an investigation.

The Board’s ex officio power ensures effective supervision in the field of personal data protection in situations that do not depend on an application. Any form of information relating to a data breach — a complaint, a report, a news item, a notification or intelligence — may trigger the exercise of that power.

Although the Board most frequently initiates proceedings upon complaint, it also makes effective use of its ex officio power in breaches falling outside the complaint mechanism. Awareness of an allegation of infringement may arise through the Board’s own sources of information, reports, media coverage, social media posts, or repeated complaints and notifications.

Ex Officio Investigations in Practice

Decision No. 2021/426 of 27 April 2021. Following a bulk authorisation error on an e-commerce platform which enabled third-party firms to access one another’s help-desk records, the Board opened an ex officio investigation. The matter was taken up following a notification made by a partner firm.

Decision No. 2023/1430 of 17 August 2023. Upon a report that a meal-card application was requesting Turkish identification numbers during the user registration process, the Board opened an ex officio investigation in the absence of any direct complaint. The investigation identified the categories of personal data requested in the mobile application and the matching operations carried out using the Turkish identification number. This decision demonstrates that applications made by third parties who are not directly affected by the breach may also be treated as a “report” for these purposes.

Decision No. 2023/134 concerning TikTok Pte. Ltd. The Board opened an ex officio investigation into the TikTok application on the basis of news reports and complaints published on the internet and on social media platforms to the effect that explicit consent was not being obtained in accordance with procedure. This decision shows that the Board does not rely solely on individual applications; it may also act of its own motion on the basis of information and allegations that have entered the public domain.

Taken together, these decisions show that the Board has assumed a proactive supervisory function, acting both on information reflected in the public domain and on its own findings.

News coverage, social media posts and third-party reports can all trigger an ex officio file.

The On-Site Inspection Power

Under Article 15/3 of the Law: “With the exception of information and documents qualifying as State secrets, the data controller shall be obliged to send, within fifteen days, the information and documents requested by the Board in connection with the subject matter of the investigation, and to make it possible for an on-site inspection to be carried out where necessary.”

The conduct of an on-site inspection where the Board considers it necessary is not merely a power; it is a mandatory process giving rise to a duty of cooperation on the part of the data controller.

Conditions of Application and the Board’s Discretion

The Law does not expressly regulate the stages at which an on-site inspection is to be deployed, its limits or its procedure; the power is left to the Board’s discretion. In practice, on-site inspection is preferred as a complementary method in the following circumstances:

  • Where written information and documents are found to be insufficient
  • Where technical complexity can be established only in the field
  • Where security measures need to be observed in actual operation
  • Where the accuracy of the parties’ statements must be verified
  • Where the integrity of the evidence must be secured

Board Decisions and Examples from Practice

Decision No. 2023/1645 of 28 September 2023. Finding that the information and documents submitted by the data controller were not capable of forming a definite view on the transfer of personal data abroad, the Board decided that on-site inspections should be conducted both at the data controller’s office and at the headquarters of the service provider. This decision shows that on-site inspection is used not only as a means of confirming a breach but also as a tool for completing incomplete or contradictory evidence.

Decision No. 2021/78 of 3 February 2021. The data controller itself requested an on-site inspection in order to demonstrate that the allegations directed against it were unfounded. The Board considered it appropriate to conduct an on-site inspection in order to verify the data controller’s defence. This shows that an inspection is not solely a process initiated by the Board of its own motion; it may also arise on the basis of the parties’ own submissions.

Decision No. 2021/426 of 27 April 2021 — detailed application. As a result of the on-site inspection carried out at a data controller providing help-desk panel services, it was established that:

  • The data breach had occurred as a result of a faulty SQL script executed on the database
  • That error had made unauthorised access possible
  • The authorisation had been removed immediately upon detection of the breach
  • The software infrastructure was processed in a standard manner for all users

It is clear that findings of this kind can be made not through written submissions alone but by way of on-site technical inspection. The Board ordered an on-site inspection precisely so that the technical infrastructure and the authorisation processes could be examined directly.

Assessed as a whole, the Board’s decisions show that the on-site inspection power is not only a means of confirming a breach but also a complementary supervisory method serving the purposes of technical determination, system analysis and the preservation of evidential integrity.

On-site inspection may be applied both in investigations initiated by the Board of its own motion and in proceedings conducted upon complaint or upon the statements of the parties. It comes to the fore as the most effective means of establishing the truth, particularly where the operation of technical infrastructure, software systems and security mechanisms must be assessed in situ.

“On-site inspection enables decisions to be taken on the basis of objective technical findings rather than abstract statements.”
Data inventories and documented measures are what an on-site inspection tests.

Recommendations for Data Controllers

Where a breach is established as a result of the investigation, the Board may impose an administrative fine, issue instructions directed at remedying the breach, or order the suspension of the data processing activity. Failure by the data controller to comply with its obligation to submit information and documents within the fifteen-day period may likewise be the subject of a separate sanction.

Against that background, keeping data inventories up to date, documenting technical and administrative measures, systematically archiving records capable of being produced in a possible on-site inspection, and defining in advance the internal procedures that will manage communication with the Board are of critical importance for the sound conduct of the process.

A comparable trend can be observed in comparative law: in the application of the GDPR, data protection authorities use on-site inspections as a standard tool, particularly in verifying assertions concerning technical infrastructure. The published summaries of decisions indicate that the Board will likewise exercise this power with increasing frequency and in an increasingly systematic manner.

Conclusion

On-site inspection is, from the Board’s perspective, one of the most effective instruments of the administrative investigation process, serving both a supervisory and a verification function. In exercising this power the Board does not confine itself to documents and statements; where necessary it conducts the investigation in the field, obtaining direct access to technical systems, databases and physical environments.

Under Article 15/3 of Law No. 6698, no limitation is foreseen in respect of on-site inspection other than for information falling within the scope of “State secrets”. This grants the Board a wide margin of discretion while imposing on data controllers a duty of cooperation in the inspection process. At the same time, the exercise of the on-site inspection power must be balanced against the principles of proportionality, purpose limitation and the safeguarding of data security.

The practice of on-site inspection plays a critical role, particularly in technical data breaches, not only in confirming the breach but also in determining its scope, preserving the integrity of the evidence and identifying system vulnerabilities. In this respect, on-site inspection enables the Board to base its decision-making on objective technical findings rather than abstract statements.

In conclusion, the absence to date of detailed secondary legislation on the procedures and principles governing on-site inspection allows the practice to be shaped by the particular features of each case. The practice now settling in the Board’s decisions will, however, contribute in the period ahead to greater clarity as to the scope, method and limits of on-site inspection.