Jump to

Data Subject Requests and the Obligation to Inform: Procedure in Five Decisions

Data Subject Requests and the Duty to Inform — Vircon Legal

This instalment focuses on the application itself: who may make it, whether a power of attorney must confer special authority, who bears the burden of proving that the obligation to inform was met, which information may be provided in masked form, and who the correct addressee of a request is. The practical value of these decisions is that each translates directly into a compliance team procedure.

This article is part 7 of a ten-part series examining, section by section, the 47 decision summaries published by the Turkish Personal Data Protection Board on 10 August 2026. For the overall assessment of the set, see our review of all 47 decisions.

Every decision follows the same structure: the facts, the Board’s assessment, why the decision matters, and the practical implications for organisations. The “Vircon Legal assessment” headings contain our own commentary apart from the fine amount; they are not part of the text of the decision.

Decisions covered in this article

Data Subject Requests and the Obligation to Inform: Procedure in Five Decisions — the decisions reviewed in this instalment.
Decision Date Subject Outcome
2023/1818 26 October 2023 Confirmed That Proof of the Obligation to Inform Rests With the Data Controller TRY 15,000
2024/540 28 March 2024 Clarified That No Special Authority Is Required in a Power of Attorney for KVKK Applications No administrative fine, instruction issued
2024/592 18 April 2024 Balanced an Employee’s Right of Access to Their Own Data With Customer Secrecy by Way of Masking No administrative fine, instruction issued
2024/284 22 February 2024 Took No Action on Unproven Allegations and Issued an Instruction Only on the Deficiency in Informing No administrative fine, instruction issued
2023/2185 28 December 2023 Distinguished the Correct Addressee as Between the Press Archive and Search Engine Results No administrative fine

The Board Confirmed That Proof of the Obligation to Inform Rests With the Data Controller

Decision no: 2023/1818  ·  Date: 26 October 2023  ·  Outcome: TRY 15,000

The facts

In the incident under examination, a customer who was a subscriber of a company providing alarm and surveillance system services complained to the Board, claiming that the telephone calls conducted with him had been recorded without any written contract existing between them, without any warning or information being given and against his consent, and that these recordings had been used against him.

In its defence, the company argued that a subscription relationship had been continuing between the parties since 2014, that on incoming and outgoing calls a voice announcement stating “Your calls are being recorded for your security” was played before being connected to a customer representative, and that in 2017 an oral information notice had additionally been provided.

What the Board held

The Board found the taking of call recordings as such lawful on the basis of the legal grounds of the establishment and protection of a right and of legitimate interest (Art. 5/2-e, f). It was considered that these recordings are of critical importance in terms of proving the parties’ agreement on the contractual relationship and its performance.

However, the Board established that the voice announcement referred to in the company’s defence and the claim that “layered information was provided” did not amount to information in the technical sense as required by Article 10 of the Law (containing the minimum elements such as the identity of the data controller, the purpose of processing, transfers, the legal ground and the rights of the data subject); and further that the company was unable to prove that information had been provided on past calls. The Board expressly emphasised that the burden of proving that the obligation to inform has been fulfilled rests with the data controller.

Why this decision matters

This decision clearly sets out, in call centre and call recording practices, the distinction that “even if the taking of the recording is lawful, informing is a separate and independent obligation”. The emphasis that the burden of proof lies with the data controller is a finding that increases the importance of documentation in compliance processes.

What organisations should watch for

  • On call centre lines where calls are recorded, it is recommended that voice information be provided at the beginning of the call and that the content of that information (purpose, retention period) be concrete.
  • It is recommended that the provision of information be documented in a provable manner (for example, by the voice announcement appearing in the recordings).
  • The adoption of a “layered information” approach, whereby a short oral notification is followed by a referral to a detailed privacy notice, may be considered good practice.

Vircon Legal assessment

An administrative fine of TRY 15,000 was imposed. Although the amount of the fine is low, the decision’s general principle concerning the burden of proving information is directly applicable to almost every sector operating a call centre.

The Board Clarified That No Special Authority Is Required in a Power of Attorney for KVKK Applications

Decision no: 2024/540  ·  Date: 28 March 2024  ·  Outcome: No administrative fine, instruction issued

The facts

In the specific case, at the employees’ own request, a security camera was placed at a workplace in an area referred to as a “changing room” but in fact consisting merely of a locked locker area, for the purpose of enabling employees to keep their personal belongings (such as clothing and bags) securely. An employee subsequently found this camera practice contrary to the KVKK and lodged a complaint, and also raised the same matter as a ground for justified termination in the action he brought against his employer.

The examination also addressed, as a separate issue, the content of the privacy notice concerning the camera practice and the procedure of the KVKK application made by the complainant to the company through a representative.

What the Board held

The Board found the use of cameras lawful on the basis of legitimate interest, and it found the retention of the footage for 60 days and its subsequent destruction sufficient. However, finding it insufficient that the privacy notice merely referred to articles of the law without providing concrete information and that explicit consent and information were mixed together within the same text, it issued an instruction for correction.

In its decision the Board also made a general procedural clarification and stated that, in respect of representatives acting under a power of attorney in applications within the scope of the KVKK, the requirement of “special authority” should not be sought.

Why this decision matters

The broadest and most generalisable element of the decision is the clarification, independently of the camera practice, that no special authority is required in a power of attorney for KVKK applications. This clarification is not specific to this incident alone but is in the nature of a general procedural rule applicable to all data subject application processes.

What organisations should watch for

  • KVKK applications made through a representative are required not to be rejected merely on the ground that only a general power of attorney has been submitted. It is recommended that internal application procedures be updated accordingly.
  • It is recommended that privacy notices not be limited to a mere reference to an article of the law, but that they contain concrete information such as the purpose and scope of the recording and the retention period.
  • It is recommended that explicit consent and privacy notice texts be presented separately from one another, in a manner that does not give rise to confusion.

Vircon Legal assessment

No administrative fine was imposed; an instruction for correction was issued. It is considered that the clarification that no special authority is required in a power of attorney offers a directly applicable procedural rule for law firms and for compliance teams managing KVKK applications.

The Board Balanced an Employee’s Right of Access to Their Own Data With Customer Secrecy by Way of Masking

Decision no: 2024/592  ·  Date: 18 April 2024  ·  Outcome: No administrative fine, instruction issued

The facts

In the specific case, a member of staff working in the customer services unit of a bank was subjected to insults by a customer during a telephone call conducted in the course of duty. The employee wished to file a criminal complaint about the customer and, for that purpose, requested access to the audio recording of the call in which the insult occurred.

The bank rejected the employee’s request on the ground that the call recording also contained the customer’s banking transactions and account information and therefore fell within the scope of “customer secrecy”. The employee found this refusal contrary to the KVKK and applied to the Board.

What the Board held

The Board stated that the employee’s request fell within the scope of the right of access to their own personal data and that this right does not conflict with the concept of customer secrecy. The Board instructed the bank to provide the recording to the employee by masking the parts belonging to the customer that are in the nature of a secret.

Why this decision matters

The decision is a practical precedent in that it shows that, where an application also contains sensitive information belonging to a third party, the solution of “providing access by masking”, rather than rejecting the request in its entirety, is a balancing method adopted by the Board.

What organisations should watch for

  • Where a data access request contains sensitive information belonging to third parties, it is recommended that providing partial access by way of masking/redaction be considered instead of rejecting the request outright.
  • Employees’ requests for access to their own personal data are required not to be rejected automatically on the ground of third-party secrecy. These two interests are required to be balanced.

Vircon Legal assessment

No administrative fine was imposed; an instruction was issued. It is considered that the decision offers an applicable solution model for the management of data access requests in the employee-employer relationship.

The Board Took No Action on Unproven Allegations and Issued an Instruction Only on the Deficiency in Informing

Decision no: 2024/284  ·  Date: 22 February 2024  ·  Outcome: No administrative fine, instruction issued

The facts

In the incident under examination, a former employee who had left a subsidiary of a public institution alleged that, after his departure, the institution had accessed his corporate e-mail account following the termination of his employment and that his personal correspondence might thereby have been examined. The complainant further argued that the body temperature data obtained through the fever measurement cameras at the entrance of the institution were being processed as a kind of health data by being associated with his identity and that this processing was unlawful.

In connection with the institution, the manner in which the authorisation to access health data was operated and the content of the privacy notice were also included within the scope of the complaint.

What the Board held

The Board, considering that as a result of the examination of the Active Directory access records it had been proven that the e-mail had not been accessed after the termination of employment, and that fever measurement data are not regarded as personal data unless matched with an identity, found these allegations unfounded. On the other hand, finding the privacy notice insufficient and finding it insufficient that the authorisation to access health data was open to a wide group of staff including the general manager, it issued a reminder/instruction on these matters.

Why this decision matters

The decision is instructive in two respects: first, it shows that AD (Active Directory) log records may be used as a strong means of proof in allegations of access to a former employee’s e-mail; second, it demonstrates that measurement data not matched with an identity (such as fever measurement) may not in all circumstances be regarded as personal data.

What organisations should watch for

  • It is recommended that access to the corporate accounts of departing employees be traceable and auditable through access logs. These records constitute a strong means of defence in the event of a possible complaint.
  • It is recommended that authorisation to access sensitive data such as health data be limited for positions for which it is not required by the job (including senior management).
  • It is recommended that privacy notices be updated not merely with general statements but with concrete information on the data category and the purpose.

Vircon Legal assessment

No administrative fine was imposed; an instruction was issued. Although the decision contains case-specific elements, it is considered that its findings on the evidential value of log records and on authorisation for access to sensitive data are generalisable.

The Board Distinguished the Correct Addressee as Between the Press Archive and Search Engine Results

Decision no: 2023/2185  ·  Date: 28 December 2023  ·  Outcome: No administrative fine

The facts

In the incident under examination, in relation to a news item published approximately 20 years earlier in the digital archive on a newspaper’s website in which their name appeared, the person(s) connected with the events of that period applied to the newspaper, stating that when their names were searched this news item continued to appear among the top search results and that this situation disturbed them, and requested that the news item be removed/deleted from the archive together with all its attachments.

The newspaper did not give any response to this application within 30 days and took no action in respect of the request. Following this failure to respond, the data subjects applied to the Board. Within the framework of the examination initiated by the Board, the newspaper, whose defence was requested, argued that it had left the application unanswered because it regarded it not as a right to be forgotten request but as falling within the scope of the Law’s exception relating to press activities (Art. 28/1-c); it further argued in its defence, referring to the Board’s decision No. 2020/481, that right to be forgotten requests must be raised before search engines.

What the Board held

The Board decided that the archived news item itself was exempt from the Law within the scope of freedom of the press and that for this reason no action could be taken under the KVKK. The Board also informed the data subjects, stating that the correct addressee of the request concerning the appearance of the news item in search engine results when the person’s name is searched is the search engines, and that the data subjects must first raise this request before the search engines and exhaust the application route under Articles 13 and 14 of the Law.

In addition to these, the Board separately reminded the data controller that applications to be made by data subjects must be concluded effectively, in accordance with the law and the rule of good faith, with reasons stated and within the applicable time limit, pursuant to the provision of Article 13 of the Law.

Why this decision matters

The decision sets out the balance between freedom of the press and the protection of personal data within an instructive and clean framework, by separating the archive content from the search engine visibility of that content. This distinction is not confined to the media and press sector but is in the nature of a general principle in terms of determining the correct addressee of right to be forgotten requests.

What organisations should watch for

  • Media organisations may assess requests for the destruction of archive content within the framework of the press exception; however, it is recommended that they explain to the applicant that requests concerning search engine visibility do not fall within their own sphere of competence.
  • Where a right to be forgotten request is received, clarifying whether the request is directed at the content itself or at the search engine results is important in terms of directing it to the correct addressee.

Vircon Legal assessment

No action was taken, and the data subject was directed to the correct addressee. It is considered that the decision offers a practical and reusable framework for data controllers in the media sector and for legal teams managing right to be forgotten requests.

Other parts of this series

The starting point of the series is our overall review: The 47 decision summaries published by the KVKK — a consolidated review. A Turkish version of this article is also available: İlgili Kişi Başvuruları ve Aydınlatma Yükümlülüğü: Beş Kararda Usul.

For the compliance programme as a whole, see our KVKK and GDPR compliance page, and for the decisions we cover as they are published, KVKK Tracker.

This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.

Author

  • İrem Alp

    Vircon Legal'de Avukat / Associate at Vircon Legal. Venture transactions · IP and licensing · Tech-sector regulatory

    View all posts
Considering a similar matter?See how we work on KVKK and GDPR compliance, or book a call directly.
Book a call →
Published: 20 August 2026 · last updated: 2 September 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.