Home About Us Services Awards Team Insights Career Contact Us TÜRKÇEENGLISH Devin Law & IP — Istanbul
Data Protection/Insights

Turkish Data Protection Board Decisions — October 2026: Form of Response to Data Subject Applications and the Breach Notifications of 30 September 2026

Kişisel Verileri Koruma Kurulu Kararları — Ekim 2026: İlgili Kişi Başvurularına Cevabın Bildirim Usulü ve 30 Eylül 2026 Tarihli İhlal Bildirimleri
Authors
Uğurcan Tekinİnci ÖzçilsalBeyza ErdemirUğurcan Tekin · İnci Özçilsal · Beyza Erdemir
Published5 October 2026
Reading time10 min
← All Insights
CategoryData Protection
Published5 October 2026
Authors
Uğurcan TekinPartner
İnci ÖzçilsalAttorney at Law
Beyza ErdemirAttorney at Law
SummaryÖzet

This legal update reports the “Public Announcement on the Method of Notifying the Response to Applications by Data Subjects” published by the Personal Data Protection Authority (“the Authority”) on 1 October 2026, and nine data breach notifications published on the Authority's website pursuant to the decisions of the Personal Data Protection Board (“the Board”) dated 30 September 2026. The update covers announcements published on the Authority's website between 26 September 2026 and 4 October 2026.

01
Introduction

In its public announcement dated 1 October 2026, the Authority stated that complaint examinations had shown that certain data controllers respond to data subject applications solely by telephone, in-person briefings or similar oral means of communication. The announcement explains that oral communication is not accepted as the response required under Article 13 of Law No. 6698 on the Protection of Personal Data (“PDPL”) and Article 6 of the Communiqué on the Procedures and Principles for Applications to the Data Controller (“the Communiqué”).

On 30 September 2026, the Board decided to publish nine data breach notifications, and the notices were published on the Authority’s website on the same date. Five of the notifications were published by the same Board decision and concern unauthorised access to, or a security incident in, data processor systems. The remaining notifications concern a phishing attack targeting the data processor abroad of a brokerage firm, a security vulnerability in the application system of a data controller established abroad, unauthorised access to a search service and a malware attack affecting employee data. The notices state that the examination of the matter is ongoing. The publication decisions do not include any sanction in respect of the breaches.

The Authority announced that the final response to data subject applications must be notified in writing or by electronic means; by five decisions dated 30 September 2026, the Board published nine data breach notifications.
02
Announcements and Decisions of the Period
Method of Notifying the Response to Data Subject Applications

Basis of the Announcement

The announcement recalls that Article 11 of the PDPL sets out the rights of data subjects, while Article 13 provides that requests to exercise those rights may be submitted to the data controller. According to the announcement, the data controller is obliged to conclude the requests in the application as soon as possible, depending on the nature of the request, and within thirty days at the latest. The data controller either accepts the request or rejects it by stating its reasons, and notifies its response to the data subject in writing or by electronic means. The announcement states that Article 6 of the Communiqué likewise provides that the data controller is obliged to take the necessary administrative and technical measures to conclude applications effectively, lawfully and in accordance with the principle of good faith.

Nature of Oral Communication

The announcement states that, in the course of assessing an application, data subjects may be contacted by telephone, in person or by similar means in order to request additional information or documents, to clarify the application or to provide information about the process.

The Authority's announcement: In the Authority's public announcement, the nature of this communication is explained as follows: “However, oral communication carried out in this context is not accepted as the response required under Article 13 of the Law and Article 6 of the Communiqué.”

The announcement states that notifying the response in writing or by electronic means ensures that whether the request has been accepted, the reasons for rejection where it is rejected, any actions taken within the scope of the application and the date on which the response was notified to the data subject are “set out in a clear, verifiable and provable manner”. The Authority stated that this is important for data subjects to exercise their rights effectively, for the conduct of complaint and examination proceedings before the Board and for documenting the application process in any judicial proceedings.

Four Points Addressed to Data Controllers

The announcement lists four points for data controllers. These are: concluding applications in accordance with the procedures and principles set out in the PDPL and the Communiqué; notifying the final response to applications to the data subject in writing or by electronic means; bearing in mind that telephone calls, in-person briefings or similar oral means of communication will not be accepted as the response required under the legislation; and stating clearly the extent to which the requests in the application have been met, while setting out the reasons for any rejected requests in a clear and comprehensible manner.

The legislation provides: Under Article 14(1) of the PDPL, where the application is rejected, the response is found insufficient or the application is not answered in due time, the data subject may file a complaint with the Board within thirty days of the date on which they learn of the data controller's response and, in any event, within sixty days of the date of application.

Breaches Occurring in Data Processor Systems

Five Notifications Published by the Same Decision

By the Board's decision No. 2026/2137 dated 30 September 2026, the notifications of five data controllers were published. The notifications of Deve Yükü Dayanıklı Tüketim Malları Limited Şirketi and Bambi Deri Mamülleri A.Ş. state that the breach occurred as a result of unauthorised access to a server in the data processor's systems holding the data controller's data. The notification of Unigen Yapı Malzemeleri AŞ states that the unauthorised access was gained by exploiting a security vulnerability in a third-party software library in use. In the notifications of Walke Spor Ürünleri Dış Ticaret A.Ş. and Efece Ayakkabıcılık Mağazacılık Sanayi ve Dış Ticaret Limited Şirketi, the breach is attributed to a security incident in the systems of the e-commerce infrastructure service provider.

In all five notifications, the breach was detected upon notification by the data processor to the data controller. The date of that notification is stated as 21 September 2026 for Bambi and 24 September 2026 for Deve Yükü and Unigen; the Walke and Efece notices do not state a date. The number of affected data subjects was reported as 353,811 for Efece, an estimated 323,052 for Bambi, an estimated 133,031 for Deve Yükü and 3,642 for Walke. The Unigen notification states the number of affected end customers as 27,163 and the number of affected administration panel accounts as 11.

The affected data vary across the notifications and include name, surname, e-mail address, telephone number and address information. The Bambi notification states that login credentials were hashed with MD5, the Efece notification that password information was hashed, and the Unigen notification that the stored password values of customers and administration panel users were affected. The Deve Yükü notification also lists order and delivery information among the affected data. The notifications dated 16 and 23 September 2026 reported in the September 2026 legal update also concerned unauthorised access to a data processor's server.

Phishing Attack on a Brokerage Firm's Data Processor Abroad

The notification of Papara Menkul Değerler AŞ, published by the Board's decision No. 2026/2144 dated 30 September 2026, states that a socially engineered phishing e-mail was sent to employees of the data processor located abroad, as a result of which unauthorised access was gained to Okta, the data processor's multi-factor single sign-on platform. According to the notification, the breach began on 4 September 2026, was detected by the data processor on 5 September 2026, ended on 6 September 2026 and was notified to the data controller on 18 September 2026.

The notification states that the affected data were customers' name, surname, e-mail, telephone, address, investment profile and tax status information determined under the FATCA rules, that the data accessed were encrypted, and that this information did not include bank details or credentials for access to financial services. It is reported that whether the data were exfiltrated has not yet been confirmed.

Publications of 30 September 2026: breaches at data processors (Board decision No. · Data controller · Source of the breach · Affected persons)

  • 2026/2137 — Deve Yükü Dayanıklı Tüketim Malları Limited Şirketi — Unauthorised access to data processor's server — Estimated 133,031
  • 2026/2137 — Bambi Deri Mamülleri A.Ş. — Unauthorised access to data processor's server — Estimated 323,052
  • 2026/2137 — Unigen Yapı Malzemeleri AŞ — Exploitation of a third-party software library vulnerability — 27,163 end customers; 11 administration panel accounts
  • 2026/2137 — Walke Spor Ürünleri Dış Ticaret A.Ş. — Security incident in service provider's systems — 3,642
  • 2026/2137 — Efece Ayakkabıcılık Mağazacılık Sanayi ve Dış Ticaret Limited Şirketi — Security incident in service provider's systems — 353,811
  • 2026/2144 — Papara Menkul Değerler AŞ — Phishing attack on data processor abroad — not stated
Breaches Occurring in the Data Controller's Own Systems

Data Controller Established Abroad: Unauthorised Access to Application Documents

The notification of Spirit Cultural Exchange, Inc., published by the Board's decision No. 2026/2140 dated 30 September 2026, states that, owing to a security vulnerability in the application upload subsystem of its website, authentication could not be performed on URL addresses, and the stored application documents were obtained by an unauthorised third party through automated requests. The breach began on 4 September 2026 and was detected on 9 September 2026. The number of affected persons was reported as 7,591.

The affected data include passport information, signatures, information relating to financial sponsors, diplomas and transcripts, employment and reference letters, and photographs. The notification further states that data relating to criminal convictions and security measures, consisting of criminal record and security clearance documents, were affected. This category of data is listed among the special categories of personal data in Article 6 of the PDPL.

Unauthorised Access to a Search Service and Malware

The notification of Ofix Ofis Malzemeleri AŞ, published by the Board's decision No. 2026/2139 dated 30 September 2026, states that unauthorised access was gained to the Elasticsearch service used by the data controller by means of a credential (key) obtained through unlawful means, and that personal data in customer records were accessed. The breach began on 15 September 2026 and was detected on 21 September 2026. The affected data were reported as name, surname and e-mail address, and the number of affected persons as 183,873.

The notification of Akkoyunlar Otomotiv İletişim Tekstil San ve Dış Ticaret Anonim Şirketi, published by the Board's decision No. 2026/2138 dated 30 September 2026, states that the data controller was subjected to a cyber attack by means of malware originating from a third-party application. The breach began on 23 September 2026 and was detected on 24 September 2026. The affected group of data subjects is employees, and the affected data categories are identity, contact, and visual and audio recordings. The number of affected persons was reported as an estimated 1,690, and the data controller stated that its detailed review is continuing owing to duplicate records.

Publications of 30 September 2026: breaches in data controllers' own systems (Board decision No. · Data controller · Source of the breach · Affected persons)

  • 2026/2140 — Spirit Cultural Exchange, Inc. — Vulnerability in the application upload subsystem — 7,591
  • 2026/2139 — Ofix Ofis Malzemeleri AŞ — Unauthorised access to Elasticsearch service — 183,873
  • 2026/2138 — Akkoyunlar Otomotiv İletişim Tekstil San ve Dış Ticaret Anonim Şirketi — Malware originating from a third-party application — Estimated 1,690
Obligations Relating to Breach Notification

The legislation provides: Article 12(5) of the PDPL provides: “Where the processed personal data are obtained by others through unlawful means, the data controller shall notify the data subject and the Board of this situation as soon as possible. Where necessary, the Board may publish this situation on its own website or by any other method it deems appropriate.”

Pursuant to the Board's decision No. 2019/10 dated 24 January 2019, the data controller must notify the Board without delay and within 72 hours at the latest from the date on which it becomes aware of the breach, and the data processor must notify the data controller without delay of any breach occurring within its organisation. In all nine publications reported in this update, it is stated that the examination of the matter is ongoing.

03
Conclusion

In its public announcement dated 1 October 2026, the Authority stated that the final response to data subject applications must be notified in writing or by electronic means, and that oral methods such as telephone calls and in-person briefings are not accepted as the response required under Article 13 of the PDPL and Article 6 of the Communiqué. The announcement states that the response must clearly set out the extent to which the requests have been met and the reasons for rejection.

By its decisions Nos. 2026/2137, 2026/2138, 2026/2139, 2026/2140 and 2026/2144 dated 30 September 2026, the Board published nine data breach notifications. In six of the notifications the breach occurred at a data processor, and five of these were published by decision No. 2026/2137. In the notices that state a figure, the number of affected data subjects ranges from 1,690 to 353,811. In one notification, data relating to criminal convictions and security measures are also among the affected data. All of the notices state that the examination of the matter is ongoing.

Full briefing noteDownload the bilingual PDF version of this briefing note.
Download PDF