Jump to

Two Credit Bureau Decisions and the Full Index of the 47 Decision Summaries

Full Index of the 47 Decision Summaries — Vircon Legal

The final instalment covers two decisions specific to the credit reporting and finance sector, and then brings all 47 decisions reviewed across the nine preceding parts into a single index. The index gives the decision number, date, subject and outcome, and links each decision to the instalment in which it is discussed.

This article is part 10 of a ten-part series examining, section by section, the 47 decision summaries published by the Turkish Personal Data Protection Board on 10 August 2026. For the overall assessment of the set, see our review of all 47 decisions.

Every decision follows the same structure: the facts, the Board’s assessment, why the decision matters, and the practical implications for organisations. The “Vircon Legal assessment” headings contain our own commentary apart from the fine amount; they are not part of the text of the decision.

Decisions covered in this article

Two Credit Bureau Decisions and the Full Index of the 47 Decision Summaries — the decisions reviewed in this instalment.
Decision Date Subject Outcome
2024/292 22 February 2024 Found the Rejection of an Erasure Request Based on the Inter-Bank Data Sharing Exception Sufficient No administrative fine
2024/444 14 March 2024 Found the Ten-Year Statutory Retention Period Valid Against a “Record Amnesty” Request No administrative fine

The Board Found the Rejection of an Erasure Request Based on the Inter-Bank Data Sharing Exception Sufficient

Decision no: 2024/292  ·  Date: 22 February 2024  ·  Outcome: No administrative fine

The facts

In the incident under examination, an individual, not finding the recording in the system of the personal data registered in their name with Kredi Kayıt Bürosu (the Credit Bureau) to be sufficiently justified, requested the erasure of that data. Kredi Kayıt Bürosu rejected this request on the grounds that the data in question was processed within the framework of the regulations on the sharing of inter-bank credit risk information (the statutory exception under Article 5/2) and therefore could not be erased.

Finding this rejection response insufficient, the individual brought the matter before the Board.

What the Board held

The Board found the response given by Kredi Kayıt Bürosu sufficient and found no grounds for action.

Why this decision matters

The decision concerns a narrow area that is specific to the finance sector and whose legal framework is already clear; rather than introducing a new principle, it confirms that the existing legislation (the regulations on inter-bank information sharing) has been applied correctly.

What organisations should watch for

  • It is recommended that financial institutions and credit registration systems communicate to the data subject, clearly and with reasons, the statutory exception on which they rely in their responses to erasure requests.

Vircon Legal assessment

No action was taken. The precedential value of the decision is limited, and it is essentially a confirmatory reference for data controllers in the finance/credit registration sector.

The Board Found the Ten-Year Statutory Retention Period Valid Against a “Record Amnesty” Request

Decision no: 2024/444  ·  Date: 14 March 2024  ·  Outcome: No administrative fine

The facts

In the incident under examination, an individual had fully repaid a loan debt they had in the past; however, the record relating to this debt continued to appear in the risk report kept by Kredi Kayıt Bürosu/the Risk Centre. The individual requested the erasure of this record from their report and based the request on the provision in provisional Article 3 of Law No. 5834, publicly known as the “record amnesty”.

The request was rejected by Kredi Kayıt Bürosu/the Risk Centre on the grounds that the retention period applied had a statutory basis; following this rejection, the individual applied to the Board.

What the Board held

The Board determined that the ten-year retention period applied by Kredi Kayıt Bürosu/the Risk Centre had a statutory basis (Article 5/2-a, the relevant legislation) and found no grounds for action.

Why this decision matters

The decision provides a narrow but clear example of how the scope of a popular and frequently misunderstood provision such as the “record amnesty” is assessed together with statutory retention periods.

What organisations should watch for

  • In finance and credit registration systems, it is recommended that the retention periods prescribed by law (ten years in this example) be explained to data subjects accurately and comprehensibly, with a view to preventing similar requests.

Vircon Legal assessment

No action was taken. The precedential value of the decision, similarly to 2024/292, is essentially specific to the Kredi Kayıt Bürosu/Findeks sector and limited in scope.

Full index of the 47 decisions

All 47 decisions reviewed across the ten parts of this series are listed below in reverse date order. Each decision number links to the instalment in which it is discussed.

Full index of the 47 decision summaries published on 10 August 2026.
Decision Date Subject Outcome Part
2026/1183 10 June 2026 Did Not Treat Silence in Referral Marketing as Consent and Imposed a Fine at the Statutory Upper Limit TRY 1,000,000 Part 5
2025/881 22 May 2025 Treated an Inadvertently Activated Third-Party Integration as a Low-Risk Breach No administrative fine Part 3
2025/833 2 May 2025 Recalled the Use of the Official Notification Form in a Low-Risk Unauthorised Access Case No administrative fine Part 4
2025/601 28 March 2025 Drew the Limits of the Territorial Scope of Application of the KVKK With a Concrete Example No administrative fine Part 6
2025/536 12 March 2025 Found No Grounds for Action in a Bulk E-mail Sending in Which the Recipients Could See One Another No administrative fine Part 9
2025/88 9 January 2025 Assessed a Breach in Which a Single Employee’s Browser Record Affected More Than 500,000 People TRY 1,000,000 Part 2
2024/2196 26 December 2024 Assessed Contradictory Statements Made During the Breach Process Against the Data Controller TRY 250,000 Part 4
2024/2158 19 December 2024 Also Assessed a Complaint About Personal Data on Penal Enforcement Institution Receipts Within the Scope of the Same Exception No administrative fine Part 6
2024/1898 7 November 2024 Assessed the Role of Generic and Predictable Passwords in a Ransomware Attack TRY 350,000 Part 1
2024/1899 7 November 2024 Imposed a High Fine on Account of Systemic Vulnerabilities Despite a Relatively Mild Data Category TRY 700,000 Part 1
2024/1718 9 October 2024 Assessed a Multinational Breach Requiring Notification to 19 Separate Authorities TRY 500,000 Part 4
2024/1523 10 September 2024 Emphasised That Physical Server Access Must Be Audited as Much as Digital Security TRY 500,000 Part 2
2024/1393 15 August 2024 Found a Consent Box Requested for a Processing That Was Already Lawful to Be Misleading Fine imposed (amount not stated in the source) Part 5
2024/1350 8 August 2024 Held That a Legal Basis Does Not Legitimise the Frequency of Sending Not stated in the source Part 5
2024/1361 8 August 2024 Set Out One of the Most Detailed Applicable Frameworks on Cookie Consent and Explicit Consent Granularity TRY 265,000 Part 8
2024/1359 8 August 2024 Found the Use in a Subsequent Processing Activity of Information Obtained for the Purpose of Protecting a Right to Be Lawful No administrative fine Part 6
2024/790 16 May 2024 Held That the “The Data Was Not Corrupted” Defence Does Not Remove the Notification Obligation TRY 350,000 Part 4
2024/728 9 May 2024 Separately Penalised Late Notification in a Data Leak Effected Through a Fake Executive E-mail TRY 1,000,000 Part 2
2024/756 9 May 2024 Found No Grounds for Action in a Low-Risk Packaging Error Affecting a Single Person No administrative fine Part 9
2024/592 18 April 2024 Balanced an Employee’s Right of Access to Their Own Data With Customer Secrecy by Way of Masking No administrative fine, instruction issued Part 7
2024/540 28 March 2024 Clarified That No Special Authority Is Required in a Power of Attorney for KVKK Applications No administrative fine, instruction issued Part 7
2024/444 14 March 2024 Found the Ten-Year Statutory Retention Period Valid Against a “Record Amnesty” Request No administrative fine Part 10
2024/413 6 March 2024 Assessed a Breach That Spread Through Shared Group Infrastructure TRY 150,000 Part 3
2024/415 6 March 2024 Found That the Absence of Network Segmentation Led to an Attack That Spread to Eight Servers TRY 430,000 Part 3
2024/282 22 February 2024 Penalised the Redundant Consent Clause in the Contract on the Fourth Repetition of the Same Breach Fine imposed (amount not stated in the source) Part 5
2024/284 22 February 2024 Took No Action on Unproven Allegations and Issued an Instruction Only on the Deficiency in Informing No administrative fine, instruction issued Part 7
2024/275 22 February 2024 Showed in a Survey News Report That Partial Masking Is Not the Same Thing as True Anonymisation TRY 40,179 Part 8
2024/292 22 February 2024 Found the Rejection of an Erasure Request Based on the Inter-Bank Data Sharing Exception Sufficient No administrative fine Part 10
2024/197 8 February 2024 Gave Concrete Form to the Principle That “Explicit Consent Does Not Legitimise Excessive Data Collection” in a Decision Concerning a University No administrative fine, instruction issued Part 8
2024/133 25 January 2024 Showed That the Absence of Cost-Free Security Measures Can Also Lead to a High Fine TRY 250,000 Part 1
2023/2185 28 December 2023 Distinguished the Correct Addressee as Between the Press Archive and Search Engine Results No administrative fine Part 7
2023/2007 30 November 2023 Subjected the Video and the Audio Recording on a Security Camera to Separate Proportionality Tests TRY 125,000 Part 8
2023/1863 2 November 2023 Showed With a Concrete Example That Explicit Consent Is Not Required for Every Data Processing Activity Not stated in the source Part 6
2023/1818 26 October 2023 Confirmed That Proof of the Obligation to Inform Rests With the Data Controller TRY 15,000 Part 7
2023/1796 19 October 2023 Stated That a Contractual Security Undertaking Is Not Sufficient on Its Own and That an Audit Obligation Exists TRY 200,000 Part 3
2023/1787 19 October 2023 Assessed the Sending of Health Data to a Number That Was Not Up to Date Under the Principle of Accuracy TRY 30,000 Part 8
2023/1675 28 September 2023 Presented an Instructive Framework on When the Human Error Defence Is Sufficient No administrative fine Part 9
2023/1610 21 September 2023 Once Again Confirmed the Principle That a Service Cannot Be Made Conditional on Consent Not stated in the source Part 5
2023/1017 8 June 2023 Treated the Fact That No Penetration Test Had Ever Been Commissioned as the Decisive Factor in Its Decision TRY 1,500,000 Part 1
2023/412 21 March 2023 Assessed the Fact That the Breach Was Noticed Six Months Later as a Separate Shortcoming TRY 350,000 Part 2
2022/1407 28 December 2022 Found the Measures Taken Sufficient in a Fraud Attempt Not Originating from the Company’s Systems No administrative fine Part 9
2022/1375 23 December 2022 Treated Unremediated Penetration Test Findings as an Aggravating Factor TRY 1,000,000 Part 1
2022/1152 20 October 2022 Applied the Statutory Exception Relating to Judicial and Enforcement Processes to an Access Request No administrative fine Part 6
2022/1087 7 October 2022 Did Not Characterise an Unproven “Data Has Been Leaked” Allegation as a Breach No administrative fine Part 4
2022/714 21 July 2022 Treated the Absence of Multi-Factor Authentication as the Cause of a BEC Attack TRY 200,000 Part 2
2022/711 21 July 2022 Left Responsibility With the Data Controller in an Attack Originating From a Service Provider TRY 500,000 Part 3
2022/707 21 July 2022 Found No Grounds for Action in a Low-Impact Technical Error to Which a Rapid Response Was Made No administrative fine Part 9

Other parts of this series

The starting point of the series is our overall review: The 47 decision summaries published by the KVKK — a consolidated review. A Turkish version of this article is also available: Kredi Kayıt Sektöründen İki Karar ve 47 Karar Özetinin Tam Dizini.

For the compliance programme as a whole, see our KVKK and GDPR compliance page, and for the decisions we cover as they are published, KVKK Tracker.

This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.

Author

  • İrem Alp

    Vircon Legal'de Avukat / Associate at Vircon Legal. Venture transactions · IP and licensing · Tech-sector regulatory

    View all posts
Considering a similar matter?See how we work on KVKK and GDPR compliance, or book a call directly.
Book a call →
Published: 23 August 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.