Türkiye’s Personal Data Protection Board (KVKK) has set out how employers may monitor corporate email accounts and the other channels employees use for work. Principle Decision No. 2026/2035, dated 16 September 2026, was published in the Official Gazette on 8 October 2026 (No. 33394). It lists sixteen rules. The main points: the employer owning the system does not give it an unlimited right to monitor, a clause in the employment contract is not enough notice, explicit consent should not as a rule be the legal basis, and reading message content is a last resort. Every company with employees in Türkiye that uses email, chat or a CRM is affected, and the Board says it will take administrative action under Article 18 of Law No. 6698 where the rules are not followed.
Why a principle decision, and why it matters
Under Article 15(6) of Law No. 6698, when the Board finds after a complaint or an ex officio review that a violation is widespread, it adopts a principle decision and publishes it. These decisions are not limited to one controller: they tell the whole market how the Board will read the law. We wrote about this tool in our note on earlier principle decisions, and the Board used it earlier this year to rule out biometric attendance tracking. Decision 2026/2035 was adopted by majority vote.
The Board frames the issue as a balance between the employer’s right to manage and the employee’s rights under Articles 20 (protection of personal data) and 22 (freedom of communication) of the Constitution. It also notes that a corporate mailbox holds more than messages: the employee’s professional and sometimes personal network, work patterns and correspondence content.
What is covered: not only email
The decision applies to monitoring of all channels used to carry out work. The Board names, as examples, in-house messaging applications, corporate instant messaging accounts, customer relationship or ticket management systems, and the chat and recording areas of meeting platforms. Two points of scope matter in practice:
- Logs count. Processing only traffic or log records, without opening content, is itself a processing activity. Monitoring of traffic data and of content are both subject to the general principles (Art. 4), the processing conditions (Arts. 5 and 6), the duty to inform (Art. 10) and data security (Art. 12).
- Ownership is not a licence. The fact that the device or system belongs to the employer, or is used at the workplace, does not give the employer an unlimited monitoring right. Technical access is also not legal access: admin rights over a laptop or session do not allow the employer to read the employee’s personal email, personal messaging app or social media inbox on that device.
The sixteen rules, grouped
| Topic | What the Board says |
|---|---|
| Business and private use (rules 2, 3) | The employer may set rules on private use of work tools, but they must be clear and known to employees. Even where private use is banned, monitoring must be proportionate, and continuous, uninterrupted surveillance is not proportionate. If a breach of the ban can be seen from non-content elements, reading content is not necessary. Where private use is allowed and can be separated, monitoring covers only work communications; where it cannot be separated, the monitoring right is read more narrowly. |
| Technical vs legal access (rule 4) | Technical control over a device, session, network or system does not authorise access to personal email, personal messaging or social media content. |
| Prior notice (rules 5, 6, 7) | Prior information is decisive. The notice must go beyond general statements and state the legal basis, purpose and scope, whether monitoring covers logs or content, when content may be accessed, retention periods and the employee’s rights under Article 11. A statement that the corporate mailbox “may be monitored” meets neither the prior-information requirement nor the Article 10 duty to inform. |
| Legal basis (rule 8) | Given the dependency and power imbalance in employment, explicit consent should not as a rule be the primary basis. Depending on the facts, monitoring may rest on Article 5(2)(ç) legal obligation, (e) establishing, exercising or protecting a right, or (f) legitimate interest. None of these gives an unlimited right. |
| Proportionality and gradation (rules 9, 10, 11) | A specific, explicit and legitimate purpose, limited and proportionate processing, retention only as long as needed. If a less intrusive method achieves the aim, the employer may not use a heavier one. Content access is an exception, only where traffic data is not enough. Where filtering or blocking can prevent misuse, there is no general monitoring right. Content review needs a concrete suspicion and must be limited to the allegation; open-ended, general and continuous review is to be avoided. |
| Special categories and third parties (rule 12) | The risk of special category data in message bodies and attachments, and the effect on correspondents’ data, must be taken into account. |
| Covert monitoring (rule 13) | Hidden methods without prior notice, and tools that record all of an employee’s activity indiscriminately, are unlawful. Monitoring must be within the employee’s knowledge and foreseeable. |
| Access control (rule 14) | Access to data obtained from monitoring limited to a small number of authorised staff, defined by job description, with access logs and confidentiality obligations. |
| Departing employees (rule 15) | As a rule, close the account to the employee’s active use and to new access, prevent irrelevant people from seeing incoming messages, and destroy data with no remaining legal basis. Limited, time-bound, access-controlled and recorded forwarding, auto-reply, archiving or retention may be acceptable for business continuity, defence of legal claims or legal obligations. |
| Enforcement (rule 16) | Where the rules are breached, the Board will review the facts and take administrative action under Article 18. |
Notice in the contract is no longer enough
Many Turkish employment contracts and handbooks contain one line: corporate email is for business use and may be inspected by the company. The Board now says that kind of general statement does not meet the Article 10 duty to inform, and that the notice must describe the monitoring itself: logs or content, on what trigger, for how long the data is kept. The decision also separates two ideas. The Constitutional Court’s case law asks whether the employee was informed; the Board says that this “informing” and the Article 10 duty are not the same concept, although a proper Article 10 notice about the purpose, scope and method of monitoring can also satisfy the prior-information requirement.
This matters because Turkish courts have accepted employer review of corporate email where the employee had been told in advance. In C.O.A. (Application No. 2018/31036, 12 January 2021), the Constitutional Court found no violation of Articles 20 and 22 where the employment contract stated that the corporate account was for business use only and could be inspected by the bank’s management without notice. The decision refers to the case law of both the Constitutional Court and the European Court of Human Rights, which ties the employer’s power to clear prior notice, a legitimate aim, proportionality and the use of less intrusive means first, the approach the Grand Chamber set out in Bărbulescu v. Romania (No. 61496/08, 5 September 2017). Decision 2026/2035 turns those criteria into a KVKK compliance standard that the Board itself will enforce.
Consent forms are the wrong tool
Rule 8 is likely to require the most document changes. Employers often ask new hires to sign an explicit consent for monitoring. The Board says that, given the imbalance of power, consent should not as a rule be the primary basis, and where consent is relied on, whether it was really given freely will be examined case by case. The practical consequence is that the monitoring programme should be built on Article 5(2)(ç), (e) or (f), with a written balancing of the employer’s interest against the employee’s rights, and that the consent form should not be the only thing holding it up.
Where to start
- List every channel employees use for work: email, chat, CRM and ticketing, meeting recordings, shared drives with comments.
- Write or update an acceptable use policy that says whether private use is allowed, banned or limited, and communicate it.
- Rewrite the employee privacy notice: legal basis, purpose, logs or content, the trigger for content access, retention, Article 11 rights.
- Stop relying on monitoring consent; document the legal basis and a legitimate interest assessment instead.
- Default to log-level controls and technical measures (filtering, blocking, data loss prevention) before any reading of content.
- For content review, require a recorded concrete suspicion, limit it to the allegation (sender, period, keywords) and keep a short proportionality note.
- Review endpoint tools: screen capture, keystroke logging or “record everything” agents are hard to defend after rule 13.
- Restrict access to a named small team, keep access logs, bind them to confidentiality.
- Write an offboarding procedure for mailboxes: closure date, auto-reply, time-limited forwarding to a role address, archive and deletion schedule.
- If AI tools summarise or score employee communications, apply the same analysis; see our notes on AI use policies and monitoring at work.
Frequently asked questions
Can an employer in Türkiye read an employee’s corporate email?
Only within limits. Under Principle Decision 2026/2035, the employee must have been informed in advance with a notice that meets Article 10 of Law No. 6698, the monitoring needs a legal basis and a legitimate purpose, and content may be read only where traffic data is not enough, on a concrete suspicion and limited to the allegation.
Is a clause in the employment contract enough?
No. The Board says that a statement that the corporate mailbox may be monitored does not meet the duty to inform. The notice must cover the legal basis, purpose, scope, whether logs or content are monitored, when content may be accessed, retention periods and the employee’s rights.
Should employers ask employees for explicit consent to monitoring?
Consent should not, as a rule, be the primary basis because of the power imbalance in employment. Depending on the facts, monitoring may rest on legal obligation, the establishment or protection of a right, or legitimate interest under Article 5(2)(ç), (e) or (f).
What should happen to a departing employee’s mailbox?
As a rule, the account should be closed to the employee’s use and to new access, and data with no remaining legal basis destroyed. Limited, time-bound and logged forwarding, auto-reply or archiving can be justified for business continuity, legal claims or legal obligations.
Sources. KVKK Principle Decision No. 2026/2035 of 16.09.2026, RG 8.10.2026/33394; Law No. 6698 on the Protection of Personal Data, Arts. 4, 5, 6, 10, 11, 12, 15(6), 18; Constitution of the Republic of Türkiye, Arts. 20, 22; Constitutional Court, C.O.A., Application No. 2018/31036, 12.1.2021; European Court of Human Rights (Grand Chamber), Bărbulescu v. Romania, No. 61496/08, 5.9.2017.
This article is general information and not legal advice; a specific situation should be assessed with counsel.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo