Home About Us Services Awards Team Insights Career Contact Us TÜRKÇEENGLISH Devin Law & IP — Istanbul
← All Insights
CategoryData Protection
Published5 September 2026
Authors
Uğurcan TekinPartner
İnci ÖzçilsalAttorney at Law
Beyza ErdemirAttorney at Law

Turkish Data Protection Board Decisions — August 2026: Principle Decisions, Data Processing for Marketing Purposes and Workplace Surveillance

This information note has been prepared within the framework of the principle decisions of the Personal Data Protection Board published in the Official Gazette in the June–August 2026 period, the public announcements made by the Authority during this period, and the decision summaries published on the Authority's website on 10 August 2026, for the purpose of presenting the current approach in the field of personal data protection and assessing the legal implications of this approach across different sectors. In the Board's recent practice, it is evident that data processing activities are subject to comprehensive scrutiny not only in terms of the processing condition relied upon, but also with respect to the manner in which explicit consent is obtained, the separation of the privacy notice from explicit consent, the proportionality of the processing activity, and the procedure followed in concluding data subject applications.

The selected decisions have been classified under thematic headings and examined in a manner that reveals the Board's established approach. The purpose of this study is to contribute to ensuring that, in the planning of data processing activities, due consideration is given not only to the provisions of the Personal Data Protection Law No. 6698 but also to the Board's current and consistent practice, thereby supporting the anticipation of potential compliance risks and the development of a preventive legal perspective.

Introduction

Within the scope of this information note, from among the forty-eight decision summaries published by the Authority on 10 August 2026 and the principle decisions published in the Official Gazette in 2026, those decisions that shed light on data processing practices frequently encountered in practice, that are considered to be of precedential value and that provide guidance across different sectors have been selected. The prominent developments of the period are the principle decision on the processing of biometric data for the purpose of tracking working hours and the public announcement dated 27 August 2026 responding to requests for opinions concerning that decision; the principle decision on the processing of the personal data of accident victims by claims consultancy companies; the principle decision on the sharing of personal data on the internet by public legal entities; and the extension of the compliance period envisaged in the loyalty card principle decision until 28 February 2027. As regards the decision summaries, the topics of data processing for marketing purposes, the making of explicit consent a precondition of the service, camera surveillance in the workplace, and the due conclusion of data subject applications carry particular weight. Within the methodology followed in this study, the relevant Board decisions are first set out through short summaries and direct quotations, and the practical implications of these decisions and the fundamental principles they establish are subsequently assessed.

The Board lays down sector-wide rules through principle decisions in areas where widespread infringement is found.

Prominent Board Decisions on a Thematic Basis

The Board's Approach in Terms of Principle Decisions and Public Announcements

The Board made intensive use of the principle decision instrument in 2026. The principle decisions adopted in February, concerning the requirement that explicit consent and privacy notices be drawn up separately (Decision No. 2026/347), the posting of debt lists in the common areas of residential complexes (Decision No. 2026/348) and the verification mechanism in loyalty card transactions (Decision No. 2026/266), were followed in the April–July period by the principle decisions on biometric data in the tracking of working hours (Decision No. 2026/921), the data of accident victims (Decision No. 2026/1095) and the sharing of personal data on the internet by public legal entities (Decision No. 2026/1301). Principle decisions are adopted, pursuant to the sixth paragraph of Article 15 of the Law, where the infringement is found to be widespread, and give rise to directly binding compliance obligations for data controllers.

The Board's established approach: In areas where it identifies widespread infringement, the Board, rather than awaiting individual complaints, lays down rules addressed to the sector as a whole by way of principle decisions; it steers practice by responding through public announcements to the requests for opinions received following the publication of a principle decision, and may extend the compliance period where it finds sectoral requests justified. It is expressly stated in every principle decision that, where practices contrary to the principle decision are maintained, sanctions will be imposed pursuant to Article 18 of the Law.

Processing of Biometric Data for the Purpose of Tracking Working Hours

The Board's principle decision dated 29 April 2026 and numbered 2026/921 was published in the Official Gazette of 2 June 2026. In the public announcement dated 27 August 2026 responding to requests for opinions concerning the decision, the Authority stated that the storage in a database of data obtained through methods such as palm scanning or fingerprinting 'by being converted into a mathematical code' does not remove their character as biometric data; that there is no express statutory provision requiring employers to fulfil their obligation to document working hours through biometric systems; and that, for this reason, 'biometric data processing activities carried out solely for the purpose of tracking working hours are not based on any of the processing conditions set out in Article 6 of the Law and, moreover, even where valid explicit consent exists, such processing activity would not satisfy the proportionality criterion set out in Article 4 of the Law'. The announcement stated that biometric processing carried out for the purposes of identity verification and access control to critical areas in facilities and areas presenting a high security risk falls outside the scope of the principle decision; it emphasised, however, that even in such cases the processing must be limited to the areas and persons for which it is necessary, must apply only where alternative methods prove insufficient, and must be proportionate to the concrete security need. This approach is consistent with the instruction given in the decision dated 8 February 2024 and numbered 2024/197, requiring a university's practice of tracking attendance by fingerprint to be discontinued forthwith and the processed data to be destroyed.

Processing of the Personal Data of Accident Victims

The Board's principle decision dated 20 May 2026 and numbered 2026/1095 was published in the Official Gazette of 1 July 2026. The Board found that organisations operating under names such as 'claims consultancy companies', although not registered on the roll of any bar association, contact victims of occupational and traffic accidents with promises of compensation; that no satisfactory answer is given to the question of how the victims' accident details were obtained; and that data such as identity details, contact details and accident reports are obtained through various channels in the period following the accident. The decision ruled that, where claims consultancy companies, loss adjusters and adjusting firms, and lawyers and law partnerships that unlawfully access data processed in the insurance sector and engage in processing such data do so without relying on any processing condition, data subjects may lodge a complaint with the Board pursuant to Article 13 et seq. of the Law; that the transfer by insurance loss adjusters of data processed in the course of their duties to unauthorised third parties may constitute an offence under Article 136 of the Turkish Penal Code; and that data controllers must establish training for their employees, restrictions on access authorisations, role-based access controls and monitoring mechanisms. Read together with the decisions of the Advertising Board sanctioning 'claims consultancy' promotions in the same period as infringements of the exclusive right of attorneys to practise law, the decision demonstrates that activity in this field is under scrutiny from the standpoint of both advertising law and data protection law.

Sharing of Personal Data on the Internet by Public Legal Entities

The Board's principle decision dated 1 July 2026 and numbered 2026/1301 was published in the Official Gazette of 28 July 2026. Having found that documents published on the websites of public legal entities such as municipalities, special provincial administrations and universities contained data such as names, surnames, Turkish identity numbers, addresses, places of birth, registry numbers, immovable property details and examination results, the Board ruled that sharing on the internet must be based on one of the conditions set out in Article 5 of the Law and, in respect of special categories of personal data, Article 6; that no sharing should take place where no valid condition exists; that, even where processing is based on the condition of being expressly provided for by law, unnecessary data must be removed through destruction, masking and similar measures in accordance with the principle of being relevant, limited and proportionate to the purpose; that examination and draw results must be announced through methods such as e-Devlet or two-factor authentication whereby each data subject can access only his or her own result; and that the same requirements must be observed in sharing carried out through internal correspondence, noticeboards, bulletin boards and similar means.

Extension of the Compliance Period under the Loyalty Card Principle Decision

By its principle decision dated 11 February 2026 and numbered 2026/266, the Board had granted data controllers a six-month compliance period for the establishment of mechanisms verifying that purchases made by stating the loyalty card holder's mobile telephone number or card number at the till are carried out with the knowledge and consent of the data subject. Upon the requests of sector representatives, the Board, by its decision dated 22 July 2026 and numbered 2026/1491, extended the compliance period until 28 February 2027. While this decision affords the retail sector additional time for the technical and operational establishment of verification methods, it does not alter the substance of the obligation.

Board Decisions on Data Processing for Marketing Purposes and the Elements of Explicit Consent

A significant portion of the decision summaries published by the Board on 10 August 2026 concerns the processing of contact data for advertising and marketing purposes. The Board separately assessed contact numbers obtained from third parties in return for a premium, explicit consent checkboxes embedded within contract texts, the sending of messages of identical content at frequent intervals, and the making of the enjoyment of a service conditional upon the giving of explicit consent for commercial communications.

The Board's established approach: Contact data processed without reliance on one of the processing conditions under Article 5 of the Law is characterised directly, without any separate examination of the obligation to inform, as a failure to take the data security measures required under Article 12, and is made the subject of administrative fines. Even messages based on a valid processing condition constitute an abuse of right and a breach of the rule of good faith where they are sent at a frequency exceeding the data subject's reasonable expectations. Explicit consent may not be presented as a precondition of the service; since the element of 'being given by free will' may be vitiated where explicit consent is obtained within a contract text, the explicit consent text must be presented separately from the contract.

Contact Numbers Obtained from Third Parties in Return for a Premium

In the Board's decision dated 10 June 2026 and numbered 2026/1183, the use by a savings finance company of telephone numbers belonging to third parties, obtained from its customers under a 'brand ambassadorship' programme, for marketing SMS messages and calls, and the payment of premiums to the customers transferring the data, were examined. The company argued that its customers were able to recommend, via the application, acquaintances wishing to receive information, and that the required information was provided by the call centre; the Board, however, found that the data subject's data had been 'processed without obtaining lawful explicit consent within the scope of Article 5 of the Law and therefore without any valid data processing condition', imposed an administrative fine of TRY 1,000,000 on the data controller and, in the absence of a valid processing condition, saw no need for a separate examination in respect of the obligation to inform.

Explicit Consent Embedded in the Contract and the Frequency of Messages

In the Board's decision dated 8 August 2024 and numbered 2024/1350, the sending by an electronic communications operator of short messages of identical content concerning the expiry of a campaign period on dates close to one another, and on some days in immediate succession, was examined. While accepting that the messages could be sent within the scope of a legal obligation pursuant to Article 11 of the Regulation on Consumer Rights in the Electronic Communications Sector, the Board found that the operator had 'abused the right it holds by engaging in a processing activity exceeding the reasonable expectations of the Data Subject through the frequent sending of SMS messages of identical content on dates close to one another', and imposed an administrative fine of TRY 100,000; on the ground that the explicit consent checkboxes contained within a sixteen-page subscription contract 'may be of a misleading nature for data subjects and the elements of explicit consent may be vitiated', it reiterated that the explicit consent text must be presented separately from the contract.

Making Explicit Consent a Precondition of the Service

In the Board's decision dated 8 August 2024 and numbered 2024/1361, the mandatory collection, on the contact form of a private education institution's website, of explicit consent for advertising and marketing purposes from persons wishing to obtain information about the service was examined; the Board instructed the data controller 'to separate the matters combined in the explicit consent text and not to make the explicit consent to be obtained in respect of commercial electronic communications concerning advertisements, promotions and various campaigns compulsory as a precondition of the service'. The same principle was applied in the decision dated 21 September 2023 and numbered 2023/1610, in which an online legal games-of-chance platform had made access to live match broadcasts conditional upon the giving of explicit consent for commercial communications; stating that the element of 'being given by free will' had been impaired, the Board imposed an administrative fine of TRY 250,000 together with an instruction to terminate the practice.

Determination of Data Controller Status in Service Partnerships

In the Board's decision dated 15 August 2024 and numbered 2024/1393, the entry of a passenger's surname and seat or ticket number into the service provider's portal for access to the internet service offered during flights, and the verification of those details by the airline's systems, were examined. The Board concluded that, in this structure based on a service and brand partnership agreement, the airline company and the internet service provider were 'two separate data controllers'; it imposed an administrative fine of TRY 90,000 on the internet service provider on the ground that the checkbox concerning data sharing on the login screen had been tied to the condition of explicit consent, and found no grounds for action in respect of the airline company. The Board further stated that it was not procedurally proper for the data subject to raise directly before the Board an allegation not included in the application made to the data controller.

Workplace camera surveillance is reviewed under the legitimate interest condition and the procedural requirements of the obligation to inform.

Board Decisions on Workplace Surveillance and Biometric Data

The Board assesses camera surveillance practices in the workplace within the framework of the legitimate interest condition; in the same decisions, however, it also reviews procedural requirements such as the requirement that the privacy notice be specific, the separation of explicit consent from the privacy notice, and the prohibition on requiring a special authority in applications made through a representative.

The Board's established approach: A camera system installed at the request of the employees following incidents of theft, recording on a closed-circuit basis and retaining the recordings for a limited period, may be based on the legitimate interest condition set out in subparagraph (f) of the second paragraph of Article 5 of the Law. By contrast, a privacy notice that makes only a general reference to the processing conditions by article number is contrary to the Communiqué. Since the personal data protection legislation contains no provision requiring a special authority in a power of attorney, data controllers may not require special authorisation in applications made through a representative.

Camera System Installed at the Request of the Employees

In the Board's decision dated 28 March 2024 and numbered 2024/540, the placement of a camera in an area of a production facility where employees kept their personal belongings and put on their work vests was examined. Taking into account that the cameras had been installed upon the signed request of the employees following incidents of theft, that the area was not designed as a changing room, and that the recordings were retained in a closed-circuit system for a period limited to sixty days, the Board accepted that the processing could be based on the legitimate interest condition; however, it instructed and warned the data controller on the grounds that the privacy notice made only a general reference to Articles 5, 6, 8 and 9 of the Law, that explicit consent was obtained together with the privacy notice, and that a special authority was required in the power of attorney.

Camera Recording in Educational Institutions and the Allegation of Audio Recording

In the Board's decision numbered 2024/1361, the allegation that a private education institution recorded audio and video through its security cameras was also examined; it was stated that video recording fell within the scope of a legal obligation pursuant to Article 11 of the Regulation of the Ministry of National Education on Private Education Institutions, that there was no document indicating that audio recording had been made, and that the audio recording forming the subject of the complaint was understood to have been made by an employee. The Board informed the data subject that a criminal complaint could be filed under the Turkish Penal Code in respect of the employee's act.

Board Decisions on Data Subject Rights and the Application Procedure

Another common feature of the decision summaries is the findings concerning the procedure for applications to the data controller and complaints to the Board. Even in files in which no infringement is ultimately found, the Board makes the giving of oral responses to applications, the late answering of applications as a result of their referral to the wrong unit, and the rejection of applications through a misinterpretation of the Law the subject of reminders or warnings.

The Board's established approach: The right to request information under Article 11 of the Law also encompasses the right of access to personal data; a data subject's request for access to the recording of a conversation to which the data subject was a party must be met by masking the other party's data of the nature of customer secrets. In processing activities based on the condition of being expressly provided for by law, a request for erasure cannot be accepted before the retention period prescribed in the legislation has expired. Since news items in press archives constitute an exception under subparagraph (c) of the first paragraph of Article 28 of the Law, a right-to-be-forgotten request must first be pursued before the search engines.

A Bank Employee's Request for Access to a Conversation Recording

In the Board's decision dated 18 April 2024 and numbered 2024/592, a bank's refusal, on the basis of the Regulation on the Sharing of Information of a Confidential Nature, of its employee's request for access to the recording of a conversation with a customer who had insulted the employee was examined. Stating that the request related not to a customer secret but to the data subject's own data, and that the right of access existed pursuant to Article 20 of the Constitution and Article 11 of the Law, the Board instructed the bank to provide the recording to the data subject 'by masking the third party's banking transaction data of the nature of customer secrets', and reminded the bank that it must exercise the utmost care and diligence in view of its erroneous findings and assessments concerning the Law.

Termination of a Subscription Contract on the Ground of a Missing Identity Document

In the Board's decision dated 22 February 2024 and numbered 2024/282, the data processing activities carried out in connection with a telecommunications company's termination of a subscription contract on the ground of a missing identity document were examined; the Board imposed an administrative fine of TRY 350,000 for the infringement found, and instructed that the sentences in the 'Confidentiality' section of the contract creating the impression that explicit consent had been given be removed, that explicit consent be obtained separately from the contract and the privacy notice, and that a copy of the wet-signed contract and the list of the group companies to which the data had been transferred be provided to the data subject.

The Condition of the Establishment of a Right and the Retention of Credit Registry Data

In the Board's decision dated 8 August 2024 and numbered 2024/1359, an insurance company's obtaining of the IBAN details of a third party involved in an accident in the course of the policyholder's damage notification, and the use of those details in a depreciation payment, were found to be lawful under the General Conditions of Compulsory Motor Third-Party Liability Insurance and to fall within the condition of 'the establishment, exercise or protection of a right'. In the decisions numbered 2024/444 and 2024/292 concerning the Credit Registry Bureau, it was stated that information on closed debts would continue to be processed at the Risk Centre for a period of ten years pursuant to the banking legislation, and no action was found necessary in respect of the erasure requests.

Press Archives and the Right to Be Forgotten

In the Board's decision dated 28 December 2023 and numbered 2023/2185, a request for the destruction of personal data contained in a news item held in a newspaper's archive was examined; it was stated that the news item constituted an exception, within the scope of freedom of the press, under subparagraph (c) of the first paragraph of Article 28 of the Law, and it was ruled that the request that the data no longer be displayed in searches made under the data subjects' names 'must be assessed by the search engines within the scope of the right to be forgotten', and that the application route must therefore first be exhausted before the search engines.

For data controllers established abroad, the territorial scope of the Law is interpreted on the basis of the effects principle.

Board Decisions on the Scope of Application of the Law and Data Breach Notifications

The decision summaries include two decisions concerning the scope of application of the Law in terms of persons and territory, together with a considerable number of decisions on data breach notifications. The Board holds that data processing by penal enforcement authorities within the scope of enforcement operations falls outside the Law, and applies the 'effects principle' in respect of data controllers established abroad.

The Board's established approach: Pursuant to subparagraph (d) of the first paragraph of Article 28 of the Law, data processing by penal enforcement authorities in connection with enforcement operations falls outside the scope of the Law. A data breach occurring at a data controller established abroad gives rise to a notification obligation only where it affects data subjects resident in Türkiye and those persons benefit from the relevant products and services in Türkiye. Where the number of persons affected is limited, the data categories are confined to corporate contact details and the likelihood of the breach producing adverse consequences is low, the Board takes no action at that stage.

Data Processing in Penal Institutions

In the Board's decision dated 19 December 2024 and numbered 2024/2158, a penal institution's express inclusion of the identity details of a convict, and of the relative depositing money, on collection and disbursement receipts was examined ex officio; taking into account that this processing was carried out by a penal enforcement authority within the scope of enforcement operations, it was decided that the provisions of the Law could not be applied pursuant to subparagraph (d) of the first paragraph of Article 28 of the Law and that there was no action to be taken.

Data Controllers Established Abroad and the Effects Principle

In the Board's decision dated 28 March 2025 and numbered 2025/601, the data breach notification of a hotel company incorporated in Hong Kong and having no legal entity, employees or technological infrastructure in Türkiye was examined. Referring to its decision numbered 2019/10, the Board recalled that it interprets the territorial scope of application of the Law 'on the basis of the effects principle rather than the territoriality principle'; taking into account that the data subjects did not benefit from the products and services in Türkiye, it decided that the company was under no notification obligation and that no action was required. In the decision dated 22 May 2025 and numbered 2025/881, the sharing of the corporate contact details of 488 employees with a third-party application company as a result of the inadvertent activation of an application integration was not made the subject of a sanction, taking into account that the breach had been detected immediately and the synchronisation cancelled, and that the employees had received training within the preceding year.

General Assessment and Conclusion

The principle decisions and decision summaries published by the Personal Data Protection Board in the summer of 2026 show that scrutiny is concentrated along two axes. The first axis is the practice of laying down rules addressed to the sector as a whole, by way of principle decisions, in areas where widespread infringement is found: biometric data in the tracking of working hours, access to the data of accident victims, internet sharing by public bodies and loyalty card transactions were made the subject of principle decisions in this period; the Authority resolved uncertainties concerning the implementation of the principle decisions through public announcements, and extended the compliance period upon sectoral requests it found justified. The second axis is the strict scrutiny of the elements of explicit consent in data processing for marketing purposes: contact numbers obtained from third parties, consent checkboxes embedded in contract texts, consent made a precondition of the service, and message frequency exceeding reasonable expectations have been made the subject of administrative fines or instructions.

The salient point in terms of practice is that, even in files in which no infringement is ultimately found, the Board issues reminders and instructions concerning the application procedure, the specificity of the privacy notice, and the separation of explicit consent from the privacy notice. In conclusion, data controllers should review their existing practices concerning biometric systems, marketing permissions and employee monitoring in the light of the principle decisions, separate their explicit consent texts from their contracts and privacy notices, and establish internal processes ensuring that data subject applications are concluded in writing, with reasons and within the statutory period.