In a significant share of the decisions reviewed, no administrative fine was imposed. These five show which factors have to come together for that outcome: limited impact, rapid detection and response, training and confidentiality measures already in place, and a documented response.
This article is part 9 of a ten-part series examining, section by section, the 47 decision summaries published by the Turkish Personal Data Protection Board on 10 August 2026. For the overall assessment of the set, see our review of all 47 decisions.
Every decision follows the same structure: the facts, the Board’s assessment, why the decision matters, and the practical implications for organisations. The “Vircon Legal assessment” headings contain our own commentary apart from the fine amount; they are not part of the text of the decision.
Decisions covered in this article
| Decision | Date | Subject | Outcome |
|---|---|---|---|
| 2023/1675 | 28 September 2023 | Presented an Instructive Framework on When the Human Error Defence Is Sufficient | No administrative fine |
| 2025/536 | 12 March 2025 | Found No Grounds for Action in a Bulk E-mail Sending in Which the Recipients Could See One Another | No administrative fine |
| 2024/756 | 9 May 2024 | Found No Grounds for Action in a Low-Risk Packaging Error Affecting a Single Person | No administrative fine |
| 2022/1407 | 28 December 2022 | Found the Measures Taken Sufficient in a Fraud Attempt Not Originating from the Company’s Systems | No administrative fine |
| 2022/707 | 21 July 2022 | Found No Grounds for Action in a Low-Impact Technical Error to Which a Rapid Response Was Made | No administrative fine |
The Board Presented an Instructive Framework on When the Human Error Defence Is Sufficient
Decision no: 2023/1675 · Date: 28 September 2023 · Outcome: No administrative fine
The facts
In the incident under examination, a member of staff working in the human resources department of a company wished to send a bulk information SMS to employees via the HR software in use. Owing to a confusion in the menus of the software’s interface, the member of staff inadvertently sent an SMS containing the identity and address information of 1,522 employees, which should have been sent only to a particular group, to a recipient list of 1,589 people covering the company’s entire personnel.
The error was noticed within a short time; the company obtained letters of consent from the recipients for the deletion of the data and requested the software provider to correct the interface so that it would not give rise to confusion.
What the Board held
The Board found the rapid detection and intervention, the records of the training provided to employees, the confidentiality undertakings obtained, the interface correction requested from the software provider and the letters of consent to data deletion obtained from the affected persons to be sufficient, and found no grounds for action. The Board also stated that an error of this kind is understandable in the ordinary course of life and that it is difficult to foresee at the design stage.
Why this decision matters
This decision provides a rare and instructive framework as to the conditions under which the “human error” defence may be accepted: where the source of the error not being reasonably foreseeable, rapid intervention, training and confidentiality measures taken in advance and the request for a correction from the software provider are assessed together, the outcome of no penalty may be reached.
What organisations should watch for
- It is recommended that a review be carried out as to whether the interfaces used for bulk sending in human resources software are designed in such a way as to make the selection of the wrong recipient difficult.
- The documentation of regular data security training for employees constitutes an important element of defence in the event of a possible human error.
- It is recommended that software providers be requested to correct risks arising from the interface/design and that this request be followed up.
Vircon Legal assessment
No administrative fine was imposed. It is considered that the decision has a high reference value, particularly in that it gives concrete shape to the limits of the “human error” defence in HR and employee data processes.
The Board Found No Grounds for Action in a Bulk E-mail Sending in Which the Recipients Could See One Another
Decision no: 2025/536 · Date: 12 March 2025 · Outcome: No administrative fine
The facts
In the incident under examination, a manufacturer of small household appliances sent information e-mails concerning a product campaign to its customers in bulk. The sending was carried out without using a method ensuring that the recipients were hidden from one another, in a total of 14 separate e-mails and in such a way as to form groups of between 29 and 65 people in each of them; for this reason, the recipients in each sending were able to see the e-mail addresses of the other recipients on the same list.
As a result of this error, the e-mail addresses of a total of approximately 500 customers became visible to the other customers in the same sending group. The company noticed the error and notified the Board of the matter.
What the Board held
The Board, taking into account that the incident was low-risk (only a limited data category such as the e-mail address being affected), found no grounds for action.
Why this decision matters
Although this decision does not in itself introduce a new principle, since bulk e-mail sending in which the recipients can see one another (also known as “CC/BCC confusion”) is a classic and extremely widespread type of error, it constitutes a preventive warning for almost every company engaged in marketing and customer communication.
What organisations should watch for
- It is recommended that a method preventing recipients from seeing one another’s addresses in bulk e-mail sendings (the blind copy/BCC field or a bulk sending tool) be made a standard process.
- It is recommended that a second control step (the four-eyes principle) be applied before sending in the case of bulk e-mails sent manually.
Vircon Legal assessment
No administrative fine was imposed. Although the outcome involved no penalty, it is recommended that, on account of the prevalence of the error, this decision be regarded as a low-cost but high-impact reminder of preventive measures for companies conducting customer communication.
The Board Found No Grounds for Action in a Low-Risk Packaging Error Affecting a Single Person
Decision no: 2024/756 · Date: 9 May 2024 · Outcome: No administrative fine
The facts
In the incident under examination, a member of staff working in the warehouse/packaging unit of a textile retail company inadvertently mixed up the orders of two separate customers while preparing them; the invoice and parcel belonging to one customer, including the address information, were mistakenly delivered to another customer.
After the error was noticed, the company retrieved the wrongly delivered document from the correct customer and notified the data subject and the Board of the situation.
What the Board held
The Board, taking into account that the number of affected persons was limited to one person and that the general level of risk was low, found no grounds for action.
Why this decision matters
In showing that isolated and low-risk operational errors are assessed proportionately, separately from a systemic security deficiency, the decision indicates that the Board does not assess every human error with the same weight.
What organisations should watch for
- It is recommended that there be a final control step at which the recipient information is checked in physical product/document delivery processes.
- It is recommended that even isolated errors be recorded and made the subject of process improvements that will prevent their recurrence.
Vircon Legal assessment
No administrative fine was imposed. Although the precedent value of the decision is limited, it offers an example of how the principle of proportionality operates in low-risk/isolated operational errors.
The Board Found the Measures Taken Sufficient in a Fraud Attempt Not Originating from the Company’s Systems
Decision no: 2022/1407 · Date: 28 December 2022 · Outcome: No administrative fine
The facts
In the incident under examination, a customer of a textile company notified the company that they had received a telephone call demanding payment of a fictitious shipping fee from them, giving the impression that there was a genuine order process. The fact that the caller appeared to have the customer’s order information gave rise to the suspicion that this information might have been leaked from the data controller‘s systems, and the company notified the Board of the matter.
As a result of the technical examination carried out by the company and the independent penetration tests, it was concluded that the information used in the fraud may have been obtained not from the data controller’s own systems but from another source that could not be identified.
What the Board held
The Board found the measures possessed by the company, such as three-layer authentication, regular penetration testing, a breach response plan and confidentiality undertakings, to be sufficient and found no grounds for action.
Why this decision matters
This decision is valuable in that it offers a positive example as to “which measures are deemed sufficient”; it shows that the Board assesses not only breaches but also the adequacy of the measures taken.
What organisations should watch for
- The existence of multi-layer authentication, regular penetration testing and a written breach response plan is among the elements that may limit a company’s liability in a possible externally sourced fraud attempt.
Vircon Legal assessment
No administrative fine was imposed. It is considered that the decision may be cited as a “good practice” example in the establishment of internal compliance policies.
The Board Found No Grounds for Action in a Low-Impact Technical Error to Which a Rapid Response Was Made
Decision no: 2022/707 · Date: 21 July 2022 · Outcome: No administrative fine
The facts
In the incident under examination, it was established that, owing to a caching error that arose in the mobile application of an e-commerce/retail company, the name and surname, telephone and e-mail information of another member, together with a masked credit card number, were displayed on the screens of some members using the application at the same time, instead of their own information.
The problem was noticed within a short time upon complaints received from members and the company remedied the error.
What the Board held
The Board, taking into account that the impact was limited and short-lived and that the problem was rapidly detected and remedied, found no grounds for action.
Why this decision matters
In showing that speed and proportionality are decisive in the Board’s assessment in the case of low-impact breaches arising from technical error, the decision points to the importance of the speed of breach response processes.
What organisations should watch for
- It is recommended that caching mechanisms in mobile and web applications be tested in such a way that they do not give rise to data confusion between user sessions.
- It is recommended that, where a technical error is detected, a rapid response be made and that the response be documented.
Vircon Legal assessment
No administrative fine was imposed. It is considered that the decision offers a limited but replicable example of the importance of rapid response in low-impact breaches arising from technical error.
Other parts of this series
- Part 1 — Ransomware and Unauthorised Access: Which Technical Measures Does the Board Expect?
- Part 2 — Authentication, Email and Physical Access: The Security Standard in Five Decisions
- Part 3 — Service Provider Related Breaches: Why Does Liability Stay With the Data Controller?
- Part 4 — Breach Notification: Five Decisions on the 72-Hour Deadline, Procedure and Transparency
- Part 5 — Explicit Consent: Marketing Permissions, Tick Boxes and Service Conditions
- Part 6 — Where Explicit Consent Is Not Required, and the Limits of the Law: Five Decisions
- Part 7 — Data Subject Requests and the Obligation to Inform: Procedure in Five Decisions
- Part 8 — The Proportionality Test: CCTV, Audio, Biometrics, Cookies and Masking
- Part 9 — When Does the Board Take No Action? Five Low-Risk Breach Decisions (this article)
- Part 10 — Two Credit Bureau Decisions and the Full Index of the 47 Decision Summaries
The starting point of the series is our overall review: The 47 decision summaries published by the KVKK — a consolidated review. A Turkish version of this article is also available: Kurul Ne Zaman İşlem Yapmıyor? Düşük Riskli Beş İhlal Kararı.
For the compliance programme as a whole, see our KVKK and GDPR compliance page, and for the decisions we cover as they are published, KVKK Tracker.
This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.
Author
-
View all postsVircon Legal'de Avukat / Associate at Vircon Legal. Venture transactions · IP and licensing · Tech-sector regulatory