The final instalment covers two decisions specific to the credit reporting and finance sector, and then brings all 47 decisions reviewed across the nine preceding parts into a single index. The index gives the decision number, date, subject and outcome, and links each decision to the instalment in which it is discussed.
This article is part 10 of a ten-part series examining, section by section, the 47 decision summaries published by the Turkish Personal Data Protection Board on 10 August 2026. For the overall assessment of the set, see our review of all 47 decisions.
Every decision follows the same structure: the facts, the Board’s assessment, why the decision matters, and the practical implications for organisations. The “Vircon Legal assessment” headings contain our own commentary apart from the fine amount; they are not part of the text of the decision.
Decisions covered in this article
| Decision | Date | Subject | Outcome |
|---|---|---|---|
| 2024/292 | 22 February 2024 | Found the Rejection of an Erasure Request Based on the Inter-Bank Data Sharing Exception Sufficient | No administrative fine |
| 2024/444 | 14 March 2024 | Found the Ten-Year Statutory Retention Period Valid Against a “Record Amnesty” Request | No administrative fine |
The Board Found the Rejection of an Erasure Request Based on the Inter-Bank Data Sharing Exception Sufficient
Decision no: 2024/292 · Date: 22 February 2024 · Outcome: No administrative fine
The facts
In the incident under examination, an individual, not finding the recording in the system of the personal data registered in their name with Kredi Kayıt Bürosu (the Credit Bureau) to be sufficiently justified, requested the erasure of that data. Kredi Kayıt Bürosu rejected this request on the grounds that the data in question was processed within the framework of the regulations on the sharing of inter-bank credit risk information (the statutory exception under Article 5/2) and therefore could not be erased.
Finding this rejection response insufficient, the individual brought the matter before the Board.
What the Board held
The Board found the response given by Kredi Kayıt Bürosu sufficient and found no grounds for action.
Why this decision matters
The decision concerns a narrow area that is specific to the finance sector and whose legal framework is already clear; rather than introducing a new principle, it confirms that the existing legislation (the regulations on inter-bank information sharing) has been applied correctly.
What organisations should watch for
- It is recommended that financial institutions and credit registration systems communicate to the data subject, clearly and with reasons, the statutory exception on which they rely in their responses to erasure requests.
Vircon Legal assessment
No action was taken. The precedential value of the decision is limited, and it is essentially a confirmatory reference for data controllers in the finance/credit registration sector.
The Board Found the Ten-Year Statutory Retention Period Valid Against a “Record Amnesty” Request
Decision no: 2024/444 · Date: 14 March 2024 · Outcome: No administrative fine
The facts
In the incident under examination, an individual had fully repaid a loan debt they had in the past; however, the record relating to this debt continued to appear in the risk report kept by Kredi Kayıt Bürosu/the Risk Centre. The individual requested the erasure of this record from their report and based the request on the provision in provisional Article 3 of Law No. 5834, publicly known as the “record amnesty”.
The request was rejected by Kredi Kayıt Bürosu/the Risk Centre on the grounds that the retention period applied had a statutory basis; following this rejection, the individual applied to the Board.
What the Board held
The Board determined that the ten-year retention period applied by Kredi Kayıt Bürosu/the Risk Centre had a statutory basis (Article 5/2-a, the relevant legislation) and found no grounds for action.
Why this decision matters
The decision provides a narrow but clear example of how the scope of a popular and frequently misunderstood provision such as the “record amnesty” is assessed together with statutory retention periods.
What organisations should watch for
- In finance and credit registration systems, it is recommended that the retention periods prescribed by law (ten years in this example) be explained to data subjects accurately and comprehensibly, with a view to preventing similar requests.
Vircon Legal assessment
No action was taken. The precedential value of the decision, similarly to 2024/292, is essentially specific to the Kredi Kayıt Bürosu/Findeks sector and limited in scope.
Full index of the 47 decisions
All 47 decisions reviewed across the ten parts of this series are listed below in reverse date order. Each decision number links to the instalment in which it is discussed.
| Decision | Date | Subject | Outcome | Part |
|---|---|---|---|---|
| 2026/1183 | 10 June 2026 | Did Not Treat Silence in Referral Marketing as Consent and Imposed a Fine at the Statutory Upper Limit | TRY 1,000,000 | Part 5 |
| 2025/881 | 22 May 2025 | Treated an Inadvertently Activated Third-Party Integration as a Low-Risk Breach | No administrative fine | Part 3 |
| 2025/833 | 2 May 2025 | Recalled the Use of the Official Notification Form in a Low-Risk Unauthorised Access Case | No administrative fine | Part 4 |
| 2025/601 | 28 March 2025 | Drew the Limits of the Territorial Scope of Application of the KVKK With a Concrete Example | No administrative fine | Part 6 |
| 2025/536 | 12 March 2025 | Found No Grounds for Action in a Bulk E-mail Sending in Which the Recipients Could See One Another | No administrative fine | Part 9 |
| 2025/88 | 9 January 2025 | Assessed a Breach in Which a Single Employee’s Browser Record Affected More Than 500,000 People | TRY 1,000,000 | Part 2 |
| 2024/2196 | 26 December 2024 | Assessed Contradictory Statements Made During the Breach Process Against the Data Controller | TRY 250,000 | Part 4 |
| 2024/2158 | 19 December 2024 | Also Assessed a Complaint About Personal Data on Penal Enforcement Institution Receipts Within the Scope of the Same Exception | No administrative fine | Part 6 |
| 2024/1898 | 7 November 2024 | Assessed the Role of Generic and Predictable Passwords in a Ransomware Attack | TRY 350,000 | Part 1 |
| 2024/1899 | 7 November 2024 | Imposed a High Fine on Account of Systemic Vulnerabilities Despite a Relatively Mild Data Category | TRY 700,000 | Part 1 |
| 2024/1718 | 9 October 2024 | Assessed a Multinational Breach Requiring Notification to 19 Separate Authorities | TRY 500,000 | Part 4 |
| 2024/1523 | 10 September 2024 | Emphasised That Physical Server Access Must Be Audited as Much as Digital Security | TRY 500,000 | Part 2 |
| 2024/1393 | 15 August 2024 | Found a Consent Box Requested for a Processing That Was Already Lawful to Be Misleading | Fine imposed (amount not stated in the source) | Part 5 |
| 2024/1350 | 8 August 2024 | Held That a Legal Basis Does Not Legitimise the Frequency of Sending | Not stated in the source | Part 5 |
| 2024/1361 | 8 August 2024 | Set Out One of the Most Detailed Applicable Frameworks on Cookie Consent and Explicit Consent Granularity | TRY 265,000 | Part 8 |
| 2024/1359 | 8 August 2024 | Found the Use in a Subsequent Processing Activity of Information Obtained for the Purpose of Protecting a Right to Be Lawful | No administrative fine | Part 6 |
| 2024/790 | 16 May 2024 | Held That the “The Data Was Not Corrupted” Defence Does Not Remove the Notification Obligation | TRY 350,000 | Part 4 |
| 2024/728 | 9 May 2024 | Separately Penalised Late Notification in a Data Leak Effected Through a Fake Executive E-mail | TRY 1,000,000 | Part 2 |
| 2024/756 | 9 May 2024 | Found No Grounds for Action in a Low-Risk Packaging Error Affecting a Single Person | No administrative fine | Part 9 |
| 2024/592 | 18 April 2024 | Balanced an Employee’s Right of Access to Their Own Data With Customer Secrecy by Way of Masking | No administrative fine, instruction issued | Part 7 |
| 2024/540 | 28 March 2024 | Clarified That No Special Authority Is Required in a Power of Attorney for KVKK Applications | No administrative fine, instruction issued | Part 7 |
| 2024/444 | 14 March 2024 | Found the Ten-Year Statutory Retention Period Valid Against a “Record Amnesty” Request | No administrative fine | Part 10 |
| 2024/413 | 6 March 2024 | Assessed a Breach That Spread Through Shared Group Infrastructure | TRY 150,000 | Part 3 |
| 2024/415 | 6 March 2024 | Found That the Absence of Network Segmentation Led to an Attack That Spread to Eight Servers | TRY 430,000 | Part 3 |
| 2024/282 | 22 February 2024 | Penalised the Redundant Consent Clause in the Contract on the Fourth Repetition of the Same Breach | Fine imposed (amount not stated in the source) | Part 5 |
| 2024/284 | 22 February 2024 | Took No Action on Unproven Allegations and Issued an Instruction Only on the Deficiency in Informing | No administrative fine, instruction issued | Part 7 |
| 2024/275 | 22 February 2024 | Showed in a Survey News Report That Partial Masking Is Not the Same Thing as True Anonymisation | TRY 40,179 | Part 8 |
| 2024/292 | 22 February 2024 | Found the Rejection of an Erasure Request Based on the Inter-Bank Data Sharing Exception Sufficient | No administrative fine | Part 10 |
| 2024/197 | 8 February 2024 | Gave Concrete Form to the Principle That “Explicit Consent Does Not Legitimise Excessive Data Collection” in a Decision Concerning a University | No administrative fine, instruction issued | Part 8 |
| 2024/133 | 25 January 2024 | Showed That the Absence of Cost-Free Security Measures Can Also Lead to a High Fine | TRY 250,000 | Part 1 |
| 2023/2185 | 28 December 2023 | Distinguished the Correct Addressee as Between the Press Archive and Search Engine Results | No administrative fine | Part 7 |
| 2023/2007 | 30 November 2023 | Subjected the Video and the Audio Recording on a Security Camera to Separate Proportionality Tests | TRY 125,000 | Part 8 |
| 2023/1863 | 2 November 2023 | Showed With a Concrete Example That Explicit Consent Is Not Required for Every Data Processing Activity | Not stated in the source | Part 6 |
| 2023/1818 | 26 October 2023 | Confirmed That Proof of the Obligation to Inform Rests With the Data Controller | TRY 15,000 | Part 7 |
| 2023/1796 | 19 October 2023 | Stated That a Contractual Security Undertaking Is Not Sufficient on Its Own and That an Audit Obligation Exists | TRY 200,000 | Part 3 |
| 2023/1787 | 19 October 2023 | Assessed the Sending of Health Data to a Number That Was Not Up to Date Under the Principle of Accuracy | TRY 30,000 | Part 8 |
| 2023/1675 | 28 September 2023 | Presented an Instructive Framework on When the Human Error Defence Is Sufficient | No administrative fine | Part 9 |
| 2023/1610 | 21 September 2023 | Once Again Confirmed the Principle That a Service Cannot Be Made Conditional on Consent | Not stated in the source | Part 5 |
| 2023/1017 | 8 June 2023 | Treated the Fact That No Penetration Test Had Ever Been Commissioned as the Decisive Factor in Its Decision | TRY 1,500,000 | Part 1 |
| 2023/412 | 21 March 2023 | Assessed the Fact That the Breach Was Noticed Six Months Later as a Separate Shortcoming | TRY 350,000 | Part 2 |
| 2022/1407 | 28 December 2022 | Found the Measures Taken Sufficient in a Fraud Attempt Not Originating from the Company’s Systems | No administrative fine | Part 9 |
| 2022/1375 | 23 December 2022 | Treated Unremediated Penetration Test Findings as an Aggravating Factor | TRY 1,000,000 | Part 1 |
| 2022/1152 | 20 October 2022 | Applied the Statutory Exception Relating to Judicial and Enforcement Processes to an Access Request | No administrative fine | Part 6 |
| 2022/1087 | 7 October 2022 | Did Not Characterise an Unproven “Data Has Been Leaked” Allegation as a Breach | No administrative fine | Part 4 |
| 2022/714 | 21 July 2022 | Treated the Absence of Multi-Factor Authentication as the Cause of a BEC Attack | TRY 200,000 | Part 2 |
| 2022/711 | 21 July 2022 | Left Responsibility With the Data Controller in an Attack Originating From a Service Provider | TRY 500,000 | Part 3 |
| 2022/707 | 21 July 2022 | Found No Grounds for Action in a Low-Impact Technical Error to Which a Rapid Response Was Made | No administrative fine | Part 9 |
Other parts of this series
- Part 1 — Ransomware and Unauthorised Access: Which Technical Measures Does the Board Expect?
- Part 2 — Authentication, Email and Physical Access: The Security Standard in Five Decisions
- Part 3 — Service Provider Related Breaches: Why Does Liability Stay With the Data Controller?
- Part 4 — Breach Notification: Five Decisions on the 72-Hour Deadline, Procedure and Transparency
- Part 5 — Explicit Consent: Marketing Permissions, Tick Boxes and Service Conditions
- Part 6 — Where Explicit Consent Is Not Required, and the Limits of the Law: Five Decisions
- Part 7 — Data Subject Requests and the Obligation to Inform: Procedure in Five Decisions
- Part 8 — The Proportionality Test: CCTV, Audio, Biometrics, Cookies and Masking
- Part 9 — When Does the Board Take No Action? Five Low-Risk Breach Decisions
- Part 10 — Two Credit Bureau Decisions and the Full Index of the 47 Decision Summaries (this article)
The starting point of the series is our overall review: The 47 decision summaries published by the KVKK — a consolidated review. A Turkish version of this article is also available: Kredi Kayıt Sektöründen İki Karar ve 47 Karar Özetinin Tam Dizini.
For the compliance programme as a whole, see our KVKK and GDPR compliance page, and for the decisions we cover as they are published, KVKK Tracker.
This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.
Author
-
View all postsVircon Legal'de Avukat / Associate at Vircon Legal. Venture transactions · IP and licensing · Tech-sector regulatory