Jump to

The 47 KVKK Decision Summaries Published in August 2026: A Consolidated Review

The 47 KVKK Decision Summaries — Vircon Legal

On 10 August 2026 the Personal Data Protection Board shared with the public the decision summaries it prepared after examining 47 separate companies and institutions in the 2022–2026 period. This article is a holistic assessment of those 47 decisions.

Each decision is addressed in three stages: a brief summary of the incident under examination, the Board’s core assessment of that incident, and the practical consequence the decision produces for companies. Throughout the text, the sections set apart under the heading “Takeaway for companies” contain our own assessment of how the decision translates into practice; they are not part of the text of the decision itself.

Executive Summary

Seven assessments emerging from the 47 decisions examined:

  • Where a valid legal basis already exists, requesting consent in addition can be regarded, on its own, as a ground for a violation. The Board confirmed the same principle in four separate decisions: where a processing condition such as a contract or a legal obligation is already present, additionally requesting explicit consent is found to be misleading for the data subject and is penalised.
  • Remaining silent or showing interest does not amount to a declaration of explicit consent. In the most recent decision examined, the Board made clear, by applying a fine at the highest amount provided for in the Law, that remaining silent during a telephone call cannot be treated as consent.
  • A significant proportion of the highest fines stem from the absence of low-cost security measures. Matters such as a password having been saved in the browser or unrestricted access to administration panels give rise to high-value fines even at large-scale companies.
  • In breaches originating from a service provider, liability remains with the data controller. Even in breaches originating from external service providers (software, hosting, infrastructure), the Board holds the data controller liable on the ground that the supervision obligation was not fulfilled.
  • Video recording and audio recording are subject to separate assessment. In security camera practices, even where video recording is found lawful on the basis of legitimate interest, a separate necessity assessment is required for the audio recording feature of the same system.
  • The existence of explicit consent does not remove the proportionality review. In one decision, the use of biometric data was found disproportionate even though consent had been obtained from students; instead of an administrative fine, an instruction was issued that the practice be halted and that a disciplinary process be opened in respect of the responsible staff.
  • The territorial scope of application of the Law is not limited to the data subject being resident in Türkiye. In one decision, it was held that a company established abroad did not fall within the scope of application of the Law on the ground that the service was not offered in Türkiye.

Summary in Figures

The fine amounts of the 47 decisions examined were compiled by us and summarised in the table below:

Numerical overview of the 47 decision summaries published on 10 August 2026.
Indicator Value
Number of decisions examined 47
Number of decisions in which an administrative fine was imposed 27
Number of decisions in which no administrative fine was imposed 20 (instruction, disciplinary action or no action taken)
Total administrative fines TRY 11,495,179
Highest single fine TRY 1,500,000 (2023/1017)
Number of decisions in which the full fine at the upper limit provided for in the Law (TRY 1,000,000) was applied 4 (2022/1375, 2024/728, 2025/88, 2026/1183)
Average fine amount in decisions carrying a fine approximately TRY 425,747

These figures were produced by our own compilation of the fine amounts disclosed in the 47 decision summaries examined; they do not reflect the official statistics of the Personal Data Protection Board.

Sectoral Risk Map

The decisions examined are distributed as follows according to the sector in which the relevant data controller operates. The table has been prepared so that you can quickly see which types of breaches have previously been penalised in your sector.

Distribution of the 47 decisions by sector and total fine amounts.
Sector Number of decisions Total fines Notable decision
Technology and Software 5 TRY 2,900,000 2023/1017
Manufacturing and Industry 7 TRY 2,530,000 2022/1375
Tourism, Entertainment and Betting 6 TRY 2,090,000 2025/88
Finance and Insurance 7 TRY 2,015,000 2024/728
Retail and E-commerce 5 TRY 700,000 2024/1718
Telecommunications 3 TRY 450,000 2024/282
Healthcare 2 TRY 380,000 2024/1898
Education 2 TRY 265,000 2024/1361
Other / Not sector-specific 4 TRY 125,000 2023/2007
Media and Press 2 TRY 40,179 2024/275
Public sector 4 TRY 0

The sector classification has been made by us according to the field of activity of the data controller named in the decision; the Board decisions do not contain an official sector classification.

The Scope and Methodology of This Article

The decisions examined were grouped by subject matter and addressed under eight main headings: explicit consent, cyber security, use of cameras, biometric data, cookies, companies established abroad, data subject applications and various special situations. Each heading is opened up in detail with the most instructive decisions; decisions of relatively narrower scope are presented in summary tables. All 47 decisions examined appear in one part or another of this article.

The Limits of Explicit Consent

Among the decisions examined, the most consistent line of case law is seen in relation to explicit consent. The Board made an assessment on this heading in six separate decisions: where another valid legal basis (contract, legal obligation, the establishment, exercise or protection of a right) is already present, additionally requesting explicit consent from the data subject is found contrary to the rule of good faith on the ground that it may create the impression in the data subject that the service is conditional upon consent, and gives rise to an administrative fine.

Silence Was Not Accepted as a Declaration of Consent (2026/1183)

In the incident under examination, it was established that a savings finance company, within the scope of a referral programme called “brand ambassadorship”, carried out marketing activity by SMS and telephone calls on third-party data obtained through customers adding the telephone numbers of their acquaintances to the system. The persons called had not been informed in advance; an attempt had been made to construe remaining silent during the call, or showing interest in the campaign, as a declaration of explicit consent.

The Board applied an administrative fine of TRY 1,000,000, emphasising that remaining silent during a telephone call or continuing with the call does not constitute a valid declaration of explicit consent, and that the information must be given before the data is processed and separately.

Takeaway for companies. Companies operating a referral or recommendation programme need to obtain separate and explicit consent before contacting the person recommended; otherwise such programmes carry a serious risk of administrative sanction.

Making a Service Conditional Upon Consent Was Found Unlawful (2023/1610)

In the incident subject to the application, it was established that an online sports betting platform made the use of its “live match broadcast” service conditional upon the user giving consent to commercial electronic messages.

Referring to its own settled case law, the Board confirmed that the free-will element of explicit consent is impaired where consent is made a precondition of a product or service; it applied an administrative fine of TRY 250,000 and issued an instruction that the practice be brought to an end.

Takeaway for companies. The provision of a service should not be made conditional upon a separate consent such as consent to commercial electronic messages; the service and marketing consent should be kept independent of one another.

A Legal Basis Did Not Legitimise the Frequency of Sending (2024/1350)

In the incident under examination, it was established that an electronic communications operator continued to send marketing SMS messages at frequent intervals and with the same content despite an opt-out request; and further that the explicit consent text had been placed in a scattered manner within the body of the contract. Even though the legal obligation on which the messages were based was lawful, the frequency of sending was separately assessed by the Board.

The Board stated that the existence of a lawful processing basis does not mean that that basis may be used without limit; it applied an administrative fine of TRY 100,000 on the ground of breach of the rule of good faith.

Takeaway for companies. Having a legal basis does not place the frequency and content of bulk communication activities beyond review; sending must be stopped immediately in respect of persons who have made an opt-out request.

An Unnecessary Consent Checkbox Was Found Misleading (2024/1393)

In the specific case, it was established that on the wifi login screen of an airline company and the in-flight internet service provider, an explicit consent checkbox was additionally used even though the data processing was already lawful within the framework of the contract and the legal obligation.

The Board decided that this unnecessarily added request for consent was misleading for the data subject and constituted a breach of the rule of good faith; it applied an administrative fine of TRY 90,000 on the internet service provider.

Takeaway for companies. Every consent checkbox in forms and contracts should be reviewed to see whether it genuinely requires a separate legal basis; unnecessary requests for consent are a risk factor in their own right.

An Extra Consent Clause Added to a Contract Was Penalised (2024/282)

In the incident subject to the Board’s assessment, a telecommunications company’s requesting an identity document for a change of subscription and cancelling the service when the document was not submitted was found lawful. However, it was established that the same contract also included an explicit consent provision that was not necessary.

The Board assessed this finding as the fourth similar example seen in the same period and applied an administrative fine of TRY 350,000.

Takeaway for companies. The repeated identification of the same implementation error can be assessed as an aggravating factor by the Board; a single review of contract templates eliminates a recurring risk.

Choosing the Correct Legal Basis Was Found Sufficient (2023/1863)

In the incident under examination, it was seen that a municipal library relied on a contractual relationship rather than explicit consent for its membership system, and that the complainant’s request related not to the absence of explicit consent but to the processing of the data.

Considering that the correct legal basis had been chosen and that the information provided orally and in digital form was sufficient, the Board found no grounds for action.

Takeaway for companies. Explicit consent is not required for every data processing activity; choosing the appropriate legal basis correctly is as important as avoiding unnecessary requests for consent.

Cyber Attacks and Data Security Breaches

25 of the 47 decisions examined concern a data security breach arising from a cyber attack, a technical fault or human error; this forms the broadest group among the decisions examined and the one with the highest total fine amount.

The Absence of Basic Security Measures

A significant proportion of the shortcomings penalised by the Board concern basic security practices that do not require high expenditure: patch management, network segmentation, multi-factor authentication and penetration testing.

The failure to close penetration test findings was treated as an aggravating factor (2022/1375). In the incident under examination, as a result of a ransomware attack on an industrial company, the identity, address, IBAN, telephone, photograph, passport and blood group information of 4,885 persons was obtained. The Board’s examination identified numerous shortcomings, such as a weak password policy, the absence of network segmentation, systems that had not been updated and the failure to close vulnerabilities identified in an earlier penetration test. The fact that the company had notified the breach beyond the statutory period was also separately assessed. An administrative fine of TRY 800,000 for the security shortcomings and a further TRY 200,000 for late notification, TRY 1,000,000 in total, was applied.

Takeaway for companies. Documenting penetration test results is not sufficient on its own; it is also expected that the vulnerabilities identified be shown to have actually been closed.

The fact that no penetration test had ever been carried out became a ground for a high fine (2023/1017). In the specific case, it was established that a digital game platform operating on a global scale was attacked twice through the same security vulnerability and that 90,182 persons from Türkiye (including children) were affected. In the Board’s assessment, the fact that the company had never had a penetration test carried out to date stood out as a determining factor. As a result, an administrative fine of TRY 1,500,000 was applied.

Takeaway for companies. The exploitation of the same security vulnerability for a second time is assessed as an indication that no lessons were drawn from the previous breach and increases the amount of the fine.

The leak being noticed six months later was assessed as a separate shortcoming (2023/412). In the incident under examination, owing to a vulnerability in a third-party management panel used by a hosting firm, the identity, contact, financial and credit card information of 31,179 persons was published on the dark web. The breach was detected not by the company’s own systems but upon a customer notification, and six months after the incident. An administrative fine of TRY 350,000 was applied on account of the absence of an intrusion detection system, of two-step verification and of data minimisation practices.

Takeaway for companies. The assumption that a breach will be noticed of its own accord must be tested; where detection and monitoring mechanisms are absent, breaches can go unnoticed for months.

The failure to take cost-free security measures increased the fine (2024/133). In the incident subject to the application, as a result of an attack on a food ordering platform involving DDoS, deletion of the database and a ransom demand, the data of 1,362 users was affected. The shortcomings identified included the management panel password having been saved in the browser and technical access being possible without IP restriction. Emphasising in particular that security measures do not always require high expenditure, the Board applied an administrative fine of TRY 250,000.

Takeaway for companies. An important precedent for small and medium-sized data controllers: budget constraints do not constitute a justification for neglecting basic security hygiene.

Phishing and Fake Executive E-mail Attacks

Data was leaked through a fake executive e-mail, and late notification was separately penalised (2024/728). In the incident under examination, it was established that at an international professional body, a list containing the information of 217 members was leaked by means of a fake e-mail impersonating the identity of the body’s president. The fact that e-mail verification controls had not been strengthened before the breach and the failure to comply with the statutory notification period were assessed separately. An administrative fine of TRY 750,000 for the absence of a risk analysis and a further TRY 250,000 for late notification, TRY 1,000,000 in total, was applied.

Takeaway for companies. The fake executive e-mail (CEO fraud) is a widespread type of attack; it is recommended that e-mail verification systems (controls of the SPF/DKIM type) be reviewed and that finance teams be informed about this type of attack.

A single employee’s browser record affected more than 500,000 people (2025/88). In the specific case, as a result of the username and password saved in the browser of an employee of the information technology team at a restaurant chain being obtained by means of malicious software, the name and surname, gender, e-mail, telephone and city information of 505,337 customers was affected. It was established that two-step verification was absent and that the security systems had been procured after the breach. An administrative fine of TRY 800,000 for the security shortcomings and a further TRY 200,000 for the failure to notify the data subjects, TRY 1,000,000 in total, was applied.

Takeaway for companies. Passwords saved in the browser can lead to a large-scale data breach through a single device; it is recommended that a password manager be used on corporate devices and that password saving at browser level be disabled.

The absence of two-step verification and a physical security vulnerability were penalised (2022/714, 2024/1523). A similar pattern is seen in two separate decisions. In the first, following the compromise of the e-mail account of a senior executive at a trading company through a phishing attack and the sending of fake debt notices to approximately 1,000 people, an administrative fine of TRY 200,000 was applied on account of the absence of multi-factor authentication. In the second, the data of 450 employees was affected through a staff computer compromised in a phishing attack at a hotel management company; the fact that physical access to the server room was not controlled also drew attention, and an administrative fine of TRY 500,000 was applied.

Takeaway for companies. Multi-factor authentication is now in the nature of a minimum expectation. It is recommended that companies with physical server infrastructure assess physical access control as well as digital security.

Breaches Originating from Service Providers

The decisions under this heading are important for companies that procure services externally (software, hosting, infrastructure): a breach originating from a service provider does not relieve the data controller of liability.

Liability for a breach originating from a supplier remained with the data controller (2022/711). In the incident under examination, as a result of a ransomware attack that began through the compromise of the account of the service provider managing the human resources software of an automotive electronics manufacturer, the data of 660 persons (including special categories of personal data such as blood group and health status) was affected. The Board decided that the data controller was liable even though the attack had taken place through a service provider, and applied an administrative fine of TRY 500,000.

Takeaway for companies. It is recommended that the access rights of external service providers with access to sensitive systems (in particular human resources and accounting) be reviewed regularly.

The supervision obligation was emphasised in a content delivery network fault (2023/1796). In the incident subject to the Board’s assessment, it was established that on the website of a clothing store, customer account and order information was made accessible to third parties owing to a technical fault at the content delivery network (CDN) provider used. Stating that concluding a contract containing a security undertaking with a service provider is not sufficient and that actually supervising that undertaking is likewise an obligation of the data controller, the Board applied an administrative fine of TRY 200,000.

Takeaway for companies. Adding a security undertaking to supplier contracts is the first step; documenting that this undertaking is supervised periodically is the second and equally important step.

The absence of network separation in attacks spreading from abroad was penalised (2024/413, 2024/415). In two separate decisions, it was seen that ransomware attacks on group companies abroad spread to systems in Türkiye as well, owing to the absence of network segmentation. In the first, the information of 56 employees (including health data) at an agricultural machinery manufacturer was affected and an administrative fine of TRY 150,000 was applied. In the second, an attack on France-based servers at an automotive supplier industry company spread to 8 servers in Türkiye and an administrative fine of TRY 430,000 was applied.

Takeaway for companies. It is recommended that companies forming part of an international group make sure their network infrastructure is isolated so that an attack occurring at headquarters does not spread to local systems.

The Breach Notification Process and Transparency

The “the data was not corrupted” defence did not remove the notification obligation (2024/790). In the incident under examination, unauthorised access was gained to the mobile application database of a software start-up; as there was no adequate log infrastructure, the method of access could not be determined. The name, e-mail and telephone information of 7,823 users was affected; the company did not notify the data subjects, on the ground that the content of the data had not changed. Stating that the fact that the integrity of the data had not been impaired does not remove the notification obligation and that the unauthorised access itself was a sufficient ground for notification, the Board applied an administrative fine of TRY 250,000 for the security shortcoming and a further TRY 100,000 for the failure to notify, TRY 350,000 in total.

Takeaway for companies. The fact that data was not altered but merely viewed does not remove the notification obligation; the notification process must be initiated once unauthorised access is detected.

Contradictory statements about the process were assessed against the company (2024/2196). In the specific case, a manufacturer of plastic household goods suffered a ransomware attack; throughout the process it made inconsistent statements about the persons and data categories affected, and was also unable to submit the documents requested. Assessing the company’s lack of transparency negatively, the Board applied an administrative fine of TRY 250,000.

Takeaway for companies. The consistency of the information given during the breach notification process is as important as the process itself; care should be taken to ensure that no contradiction arises between the initial statements and subsequent statements.

A breach requiring a multinational notification process (2024/1718). In the incident under examination, access was gained to the network server of a cosmetics company by means of a Trojan horse virus and a ransom was demanded; 432 persons were affected. Owing to the international dimension of the incident, notification was made to 19 separate data protection authorities in Europe. An administrative fine of TRY 500,000 was applied on account of the threat detection system having been procured after the breach and of no penetration test ever having been carried out.

Takeaway for companies. It is recommended that companies operating in more than one country plan in advance for the possibility that a breach may require a multi-authority notification process.

Other Cases of Limited Scope

In the majority of the following decisions the Board found the measures taken sufficient, assessed the risk as limited, or found no grounds for action on the basis that the allegation was unproven. In some of them, however, an administrative fine was applied on account of the shortcomings identified, despite the relatively narrower scope of the incidents. Taken as a whole, these decisions offer examples both of which practices are accepted as sufficient and of which shortcomings can be penalised even in incidents that appear small in scale.

Cases of limited scope and the Board’s conclusions.
Incident Outcome
An allegation that “data had been leaked” concerning a technology company could not be verified in the examination carried out (2022/1087). No grounds for action were found; an allegation that could not be proven was not characterised as a breach.
In a fraud attempt targeting the customers of a textile company, it was established that the leak did not originate from the company’s systems (2022/1407). The authentication and the response plan were found sufficient.
Owing to a technical fault in an e-commerce application, members were able to access one another’s information for a short period (2022/707). No action was taken on account of the low impact and the rapid response.
Owing to an interface error in a human resources software, the data of 1,522 employees was inadvertently sent in bulk to 1,589 employees (2023/1675). It was assessed that the human error was understandable in the ordinary course of life, and the rapid correction was taken into account.
A ransomware attack occurred at a pharmaceutical company; it was established that some passwords were of a guessable nature (2024/1898). Administrative fine of TRY 350,000: insufficient implementation of the recommendations in the security report.
A marketing account was compromised at a company providing services to European group companies, and 70,000 people were affected through a folder open to access (2024/1899). Administrative fine of TRY 700,000: a high fine was applied on account of systemic vulnerabilities.
A household appliances manufacturer used open copy instead of blind copy in a bulk e-mail, and approximately 500 customers saw one another’s addresses (2025/536). No action was taken; it stands out as a frequently encountered type of error.
Unauthorised access was gained to the newsletter platform of a non-profit organisation, and 15 people were affected (2025/833). No action was taken on account of the low risk and the rapid response.
Owing to a packing error at a textile retailer, one customer’s parcel was delivered to another customer (2024/756). No action was taken on account of the single individual involved and the low risk.

Employee Monitoring by Camera and Audio Recording

Video recording and audio recording were subjected to separate proportionality assessments (2023/2007). In the incident under examination, it was established that the camera in the security booth of a workplace recorded both video and audio; that the audio recording contained an employee’s remarks about their supervisor; and that this recording had been used as evidence in an employment case. The Board found the video recording lawful on the basis of legitimate interest; however, since no separate necessity justification could be shown for the audio recording, it held that part unlawful and applied an administrative fine of TRY 125,000.

Takeaway for companies. It is recommended that it be checked whether security cameras have an audio recording feature and that, where there is no separate necessity justification, this feature be disabled.

It was clarified that special authority is not required in a power of attorney (2024/540). In the specific case, a complaint concerning a security camera installed at the employees’ own request was examined; the use of the camera was found lawful on the basis of legitimate interest. The Board also found insufficient the fact that the privacy notice merely referred to the articles of the Law without giving concrete information, and clarified that the condition of special authority in a power of attorney should not be sought in KVKK applications.

Takeaway for companies. KVKK applications made through a representative should not be rejected on the ground that the power of attorney does not contain a special authority clause.

The Use of Biometric Data

The existence of explicit consent did not remove the proportionality review (2024/197). In the incident under examination, it was established that a university used fingerprints (biometric data) for the purpose of taking attendance in classes and that this practice was made the subject of a complaint even though explicit consent had been obtained from the students. The Board decided that the use of biometric data where a less intrusive alternative such as attendance by signature was available was contrary to the principle of proportionality; it stated that the existence of explicit consent did not change this assessment. No administrative fine was applied; instead, instructions were issued that the processing of biometric data be halted immediately, that the existing data be destroyed, that an alternative method be adopted and that disciplinary proceedings be initiated in respect of the responsible staff.

Takeaway for companies. It is recommended that organisations monitoring employees or students by biometric methods (fingerprint, facial recognition) assess whether they could achieve the same result by a less intrusive method, and that they document that assessment.

Cookies and Marketing Permissions

Cookies running automatically before consent was assessed as a breach (2024/1361). In the incident subject to the Board’s assessment, it was established that on the website of an educational institution, analytics cookies ran automatically without the user’s consent being obtained; and further that the purposes of “information request” and “marketing” were combined in a single consent checkbox in the contact form. (No breach was identified in the camera practice examined in the same decision.) The Board clarified that only cookies strictly necessary for the operation of the site may be used without consent, and that for other cookies the user must actively tick an option that is switched off by default. An administrative fine of TRY 250,000 for the cookie breach and a further TRY 15,000 for the failure to inform, TRY 265,000 in total, was applied.

Takeaway for companies. It is recommended that it be ensured that the cookie consent mechanisms on websites do not run non-essential cookies before the user makes a choice and that they offer separate consent options for different purposes.

Scope of Application for Companies Established Abroad

The Law was not applied because the service was not offered in Türkiye (2025/601). In the incident subject to the application, it was established that a Hong Kong-based hotel company had no legal entity, employees or infrastructure in Türkiye and that all operations were conducted in Hong Kong. A data breach that occurred at the company affected 909 persons resident in Türkiye; however, those persons had received the service in question not in Türkiye but while staying abroad. Deciding that the matter did not fall within the territorial scope of application of the Law, the Board clarified the following distinction: the fact that the data subject is resident in Türkiye is not sufficient on its own; the condition that the product or service be offered in Türkiye must also be met.

Takeaway for companies. It is recommended that companies with structures abroad or a foreign customer base examine both the place of residence of the data subject and the country in which the service is offered together when assessing the applicability of the KVKK.

Data Subject Applications and the Obligation to Inform

Proof of compliance with the obligation to inform rests with the data controller (2023/1818). In the incident under examination, a complaint was made about a security company recording its customer calls. The Board found the taking of the recording itself lawful on the basis of legitimate interest; however, establishing that the company could not prove that it had notified users of this practice sufficiently clearly, it applied an administrative fine of TRY 15,000.

Takeaway for companies. It is recommended that privacy notices state the purpose of the recording and the retention period in concrete terms and that it be possible to prove that this information was provided.

An employee’s right of access to their own data was balanced against customer confidentiality (2024/592). In the specific case, a bank employee requested access to a recording of a call containing insults directed at them, in order to use it in a criminal complaint; the bank rejected this request on grounds of customer confidentiality. The Board stated that the request fell within the scope of the employee’s right of access to their own data and that this did not conflict with customer confidentiality; it decided that the bank should provide the recording to the employee by masking the sensitive parts belonging to the customer. No administrative fine was applied.

Takeaway for companies. Where an application also involves sensitive information belonging to a third party, sharing the relevant parts in masked form may be considered instead of rejecting the request in its entirety.

The following two decisions are of a similar nature and concern application processes of relatively narrow scope:

Data subject applications of narrow scope.
Incident Outcome
An insurance company also used an IBAN detail it had obtained in the course of a traffic accident process for a subsequent payment relating to the same person (2024/1359). No action was taken; the matter was assessed within the scope of the protection of a right and the obligation to submit documents required by legislation.
At a subsidiary of a public institution, it was alleged that the corporate e-mail account of a departing employee had been accessed and that health data had been collected (2024/284). The greater part of the allegations could not be proven; an instruction was issued only that the privacy notice be improved.

Situations Falling Outside the Scope of the Law

A press archive and search engine results were assessed differently (2023/2185). In the incident under examination, a request for the destruction of a news item that had been in a newspaper’s archive for more than twenty years was assessed after the data controller relied on the press exception. The Board decided that the news item in the archive was itself excepted from the Law within the scope of freedom of the press; however, it stated that the correct addressee of the request concerning the appearance of the news item in search engine results when the person’s name is searched was the search engines, and that this request should be raised before the search engines within the framework of the right to be forgotten.

Takeaway for companies. When a right-to-be-forgotten request concerning a piece of content is received, distinguishing whether the request is directed at the archive itself or at search engine visibility is important for directing it to the correct addressee.

In two separate applications concerning penal execution institutions, the Board decided that the matter fell outside its own area of examination:

Applications falling outside the area of examination.
Incident Outcome
A convicted person’s request for access to their own data from a penal execution institution was rejected (2022/1152). Within the scope of the exception relating to judicial/execution processes, the matter was not assessed under the KVKK.
The identity and sentence information of convicted persons appeared openly on the collection receipts of a penal execution institution (2024/2158). No action was taken, within the scope of the same exception.

Sectoral and Special-Situation Decisions

Masking was not treated as equivalent to anonymisation (2024/275). In the incident under examination, it was established that in the election survey results published on the website of a local press organ, names were abbreviated and telephone numbers partly concealed, but that in some records the neighbourhood information was also included. The Board established that the partial telephone number and the neighbourhood information, when assessed together, made the person identifiable and that genuine anonymisation had therefore not been achieved; since information on political opinion was also contained in the content, it applied an administrative fine of TRY 40,179.

Takeaway for companies. Concealing a single field in a data set may not be sufficient; it is recommended that it be separately assessed whether the remaining information, taken together, makes the person identifiable.

The following decisions are relatively narrow in scope and sector-specific examples:

Sector-specific decisions of narrow scope.
Incident Outcome
A person’s Covid-19 test result was sent by SMS to a telephone number that had not been updated (2023/1787). Administrative fine of TRY 30,000: breach of the principle that data be kept accurate and up to date; an instruction was issued that the number be updated and the old data destroyed.
A person’s deletion request before the Credit Registry Bureau was rejected on the ground of the exception for data sharing between banks (2024/292). No action was taken; the response given was found to comply with the legal framework.
The Credit Registry Bureau/Risk Centre did not delete a repaid credit debt within the scope of a “registry amnesty” (2024/444). No action was taken; the ten-year retention period was found to have a statutory basis.

Action Plan for Companies

  1. Reviewing consent checkboxes. Checking, in contracts, forms and membership screens, whether consent is additionally requested for processing that could already be carried out on another legal basis (see The Limits of Explicit Consent).
  2. Testing the cookie consent mechanism. Assessing whether non-essential cookies run without the user’s consent being obtained (see Cookies and Marketing Permissions).
  3. Checking the audio recording feature of camera systems. Disabling this feature where there is no separate necessity justification (see Employee Monitoring by Camera and Audio Recording).
  4. Verifying basic security measures. Confirming multi-factor authentication, access restriction on administration panels and the non-storage of passwords in the browser (see The Absence of Basic Security Measures).
  5. Planning a penetration test. Carrying one out if it has not been done within the last twelve months, and documenting that the vulnerabilities identified have been closed.
  6. Establishing a supplier audit process. Supervising the security undertakings of service providers with access to critical systems not only by contract but in practice (see Breaches Originating from Service Providers).
  7. Clarifying the breach notification procedure. Defining in advance the process relating to the statutory notification period (72 hours) and to the obligation to notify data subjects.
  8. Reviewing the use of biometric data. Assessing and documenting whether a less intrusive alternative is available (see The Use of Biometric Data).
  9. Determining the retention period for log records. Documenting a minimum retention period of one year before a breach occurs.
  10. Assessing structures abroad. Clarifying whether the service is offered in Türkiye (see Scope of Application for Companies Established Abroad).
  11. Simplifying application processes conducted through a representative. Reflecting in internal procedures that special authority is not required.
  12. Making privacy notices concrete. Moving to texts containing concrete information on purpose and duration instead of general statements that merely refer to an article of the Law.

General Assessment

A holistic assessment of the 47 decisions examined reveals two trends. First, the Board’s tolerance of the absence of basic and low-cost security measures is decreasing; even large-scale companies can be exposed to high-value fines on account of the absence of minimum practices such as multi-factor authentication or patch management. Second, the existence of a valid legal basis is not considered sufficient on its own; whether that basis is used reasonably within the framework of the rule of good faith and the principle of proportionality is separately assessed.

As the two most recent decisions (the position of companies established abroad and the rejection of an attempt at indirect consent) indicate, cross-border liability and indirect/implied consent practices may be expected to come to the fore on the Board’s agenda in the coming period. This assessment is in the nature of a prediction made by us and is not based on any official statement by the Board.

In the coming days I will share separate articles going into the details of these decision summaries: I will address each heading in its own context, together with its practical implications.

Parts of the series and publication schedule

All 47 decisions will be covered in ten separate articles grouped by subject. The articles will be published on the schedule below; the titles of published parts become links.

For the compliance programme as a whole you may look at our KVKK + GDPR page, and for the decisions we cover as they are published, at KVKK Tracker.

This article is for general information purposes only and does not substitute for legal advice on a specific matter. The full texts of the decisions can be accessed from the official website of the Personal Data Protection Authority.

Author

  • İrem Alp

    Vircon Legal'de Avukat / Associate at Vircon Legal. Venture transactions · IP and licensing · Tech-sector regulatory

    View all posts
Considering a similar matter?Talk to counsel that moves at the speed of your round.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 13 August 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.