
When the “Delete My Data” Email Arrives: Handling Data-Subject Requests
Handling data-subject (DSAR) requests: the 30-day deadline, identity verification, grounds for refusal and the complaint route to the Board.
Insights and updates
From emerging regulation to deal mechanics, we write about the questions founders and investors actually ask: practical analysis you can put to work.

Handling data-subject (DSAR) requests: the 30-day deadline, identity verification, grounds for refusal and the complaint route to the Board.

Data-protection due diligence in funding and M&A: the KVKK red flags that quietly slow or kill a round, and how to clear them first.

How to run a KVKK compliance audit: data inventory, gap analysis, risk scoring and the audit report, step by step.

Short answer: Residential site and apartment managements in Türkiye long struggled with a basic question: who is the “data controller”? …

Türkiye’s Personal Data Protection Board (Principle Decision 2026/921) has ruled that processing employees’ biometric data for attendance tracking is unlawful: even with explicit consent. Why consent no longer saves it, what the proportionality test means, and the steps employers must take now.

Erdem Mümtaz Hacıpaşaoğlu spoke on Türkiye’s data-protection regime (KVKK) at an ELSA event, introducing students to the fundamentals of Law No. 6698.