Reading a year of Personal Data Protection Board decisions is the cheapest compliance consulting available: the Board tells you, case by case, exactly what it punishes. Halfway through 2026, five enforcement patterns stand out, and each one converts directly into a to-do.
Pattern 1: biometrics with alternatives available
The 2026/921 principle decision is the year’s landmark: biometric attendance systems fail where a less intrusive alternative exists, and explicit consent does not rescue disproportionality. The reasoning generalises to every biometric convenience feature. To-do: necessity memo for each biometric touchpoint, alternatives documented, consent as the second question rather than the first.
Pattern 2: aydınlatma as substance, not ritual
Fines keep landing on privacy notices that exist but fail: wrong layer (buried in ToS), wrong language, generic purposes, missing recipients. The Board reads notices against actual data flows. To-do: re-derive your notice from your VERBIS entry and your real integrations; if the notice and VERBIS disagree, both count against you.
Pattern 3: transfers through undeclared tooling
The modern breach of choice is architectural: analytics SDKs, cloud CRMs, model APIs quietly moving personal data abroad without the transfer paperwork. Post-2024 transfer rules (standard contracts, adequacy paths) made compliance feasible, which makes non-compliance less forgivable. To-do: a transfer inventory that includes your SaaS stack, not just your servers; our internal AI policy piece covers the newest leak vector.
Pattern 4: breach notification timing
The Board’s 72-hour reflex is enforced with little sympathy for internal escalation delays; the clock runs from awareness, and awareness is judged organisationally, not by when legal heard. To-do: an incident path where the first hour is defined (see the dual-clock playbook) and someone owns the notification decision.
Pattern 5: retention by inertia
Keeping everything forever is now a standalone finding: expired customer files, former employees’ data, rejected candidates’ CVs. To-do: retention schedule wired into systems (auto-deletion beats policy PDFs), with the deletion log as your evidence.
Reading the fines
2026 fine bands continue to climb with turnover-sensitive upper limits, but the Board’s real leverage is publication: named decisions are reputational events in a market this size. The cheapest position is the boring one; necessity memos, honest notices, mapped transfers, rehearsed incidents, automated deletion.
We publish every AI- and tech-relevant Board decision as it lands in the KVKK Tracker; the KVKK + GDPR practice page covers the compliance program end-to-end.
This article is for general information only and does not constitute legal advice. It reflects decisions published as of July 2026.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement.
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro call