The mirror image of the previous instalment, these five decisions show where explicit consent is not sought or where the Law does not apply at all: processing expressly provided for by statute, processing necessary for the establishment or protection of a right, exceptions concerning judicial and enforcement proceedings, and the territorial limit of the Law.
This article is part 6 of a ten-part series examining, section by section, the 47 decision summaries published by the Turkish Personal Data Protection Board on 10 August 2026. For the overall assessment of the set, see our review of all 47 decisions.
Every decision follows the same structure: the facts, the Board’s assessment, why the decision matters, and the practical implications for organisations. The “Vircon Legal assessment” headings contain our own commentary apart from the fine amount; they are not part of the text of the decision.
Decisions covered in this article
| Decision | Date | Subject | Outcome |
|---|---|---|---|
| 2023/1863 | 2 November 2023 | Showed With a Concrete Example That Explicit Consent Is Not Required for Every Data Processing Activity | Not stated in the source |
| 2024/1359 | 8 August 2024 | Found the Use in a Subsequent Processing Activity of Information Obtained for the Purpose of Protecting a Right to Be Lawful | No administrative fine |
| 2022/1152 | 20 October 2022 | Applied the Statutory Exception Relating to Judicial and Enforcement Processes to an Access Request | No administrative fine |
| 2024/2158 | 19 December 2024 | Also Assessed a Complaint About Personal Data on Penal Enforcement Institution Receipts Within the Scope of the Same Exception | No administrative fine |
| 2025/601 | 28 March 2025 | Drew the Limits of the Territorial Scope of Application of the KVKK With a Concrete Example | No administrative fine |
“Not stated in the source” means the summary published by the Board contains no information about an administrative fine; it should not be read as meaning that no fine was imposed.
The Board Showed With a Concrete Example That Explicit Consent Is Not Required for Every Data Processing Activity
Decision no: 2023/1863 · Date: 2 November 2023 · Outcome: Not stated in the source
The facts
In the incident under examination, a person who was a member of a library affiliated with a municipality lodged a complaint concerning the processing of their identity and contact information within the scope of the library membership system. The complainant’s request related not to the fact that explicit consent had not been obtained, but directly to the processing of their data in this manner being directed at them. The library collects the identity and contact information necessary for the establishment and conduct of the membership relationship by providing information to members orally together with fulfilling the obligation to inform through a link available at the library desk and on its website.
The library argued that, for this data processing activity within the scope of the membership relationship, it relied not on explicit consent but on the legal ground of the establishment and performance of a contract.
What the Board held
The Board considered that, given the nature of the membership relationship, the legal ground of the establishment and performance of a contract (Art. 5/2-c) was the correct choice; it also found the layered information provided by the library orally and by way of a digital link to be sufficient. The fact that the data had been destroyed in accordance with the proper procedure was also taken into account as a positive element in the assessment.
Why this decision matters
This decision is an instructive precedent against a very frequently encountered misconception -“explicit consent must be obtained for every data processing activity”-. The Board showed in concrete terms that explicit consent is only one of the six legal grounds listed in the Law, and that choosing the correct legal ground is as important as avoiding an unnecessary request for consent.
What organisations should watch for
- Before resorting to explicit consent in membership, subscription or similar contractual relationships, it is recommended that an assessment is made as to whether the other legal grounds under Art. 5/2 (contract, legal obligation, establishment of a right) are sufficient.
- It should not be forgotten that structures in the nature of affiliates attached to public institutions (such as a municipal library) are also fully subject to the obligations under the KVKK.
Vircon Legal assessment
The decision constitutes a valuable reference in that it contains a principle which is rarely seen in the public sector but which can be transposed directly to membership/subscription models in the private sector.
The Board Found the Use in a Subsequent Processing Activity of Information Obtained for the Purpose of Protecting a Right to Be Lawful
Decision no: 2024/1359 · Date: 8 August 2024 · Outcome: No administrative fine
The facts
In the incident under examination, a traffic accident involving material damage occurred between the data subject and the owner of a vehicle insured by an insurance company. Following the accident, a damage notification was submitted to the data controller, which was the insurer of the counterparty; in order for the damage amount to be paid, the data subject’s IBAN information was shared with the data controller not by the data subject but by the policyholder who was the counterparty to the accident. In order to verify identity, the data controller confirmed at this stage, by means of the “IBAN Verification Service” offered by the Credit Registration Bureau (KKB), that this IBAN genuinely belonged to the data subject, and paid the damage amount into that account.
Subsequently, when a separate compensation application was made in respect of the “diminished value” arising in the vehicle as a result of the same accident, the insurance company, instead of requesting a new IBAN, carried out the diminished value payment using the same IBAN information that had already been verified during the damage process. The data subject applied to the Board, claiming that their bank account information had been accessed without their knowledge and against their consent and that this information had been processed.
What the Board held
The Board found the initial obtaining of the IBAN information (during the damage notification process) lawful within the framework of the obligation to submit documents provided for in Article 99 of the Highway Traffic Law and in the General Conditions of Compulsory Financial Liability Insurance. It assessed the re-use of the same IBAN information in the subsequent diminished value payment as a separate processing activity and, stating that this was based on the condition under Art. 5/2-e that “data processing is mandatory for the establishment, exercise or protection of a right”, found no grounds for action.
The Board further issued a separate reminder to the data controller that, since the data controller had responded late to the data subject’s application, applications are to be concluded within the time limit and with reasons pursuant to Article 13 of the Law.
Why this decision matters
The decision is a practical example of how the scope of the purpose of data processing may be interpreted, in that it shows that the re-use of data obtained on a legal ground in a subsequent processing activity relating to the same person and constituting a continuation of the same legal relationship may not be regarded as unlawful in so far as it is connected with the purpose.
What organisations should watch for
- If it is planned to re-use data obtained on a legal ground in a subsequent processing activity, it is recommended that an assessment is made as to whether that use is reasonably connected with the purpose of the initial collection.
- The use of identity/account verification services (such as KKB) in payment processes may be considered a good practice that reduces the risk of payment to the wrong person.
Vircon Legal assessment
No administrative fine was imposed. It is considered that the decision offers a limited but concrete reference as to the limits of the use of data in recurring payments, particularly in insurance and compensation processes.
The Board Applied the Statutory Exception Relating to Judicial and Enforcement Processes to an Access Request
Decision no: 2022/1152 · Date: 20 October 2022 · Outcome: No administrative fine
The facts
In the incident under examination, a person held as a convict in a penal enforcement institution requested access to certain records and personal data kept about them by the institution. The enforcement institution rejected this request outright; upon the rejection decision, the data subject applied to the Board, claiming that the right of access under the KVKK had not been afforded to them.
What the Board held
The Board decided that the exception under Art. 28/1-d of the Law applied in respect of personal data processed in judicial and enforcement processes, and that for that reason the complaint could not be assessed within the scope of the KVKK.
Why this decision matters
The decision, while having a narrow sectoral scope limited to judicial and enforcement processes, provides a general framework as to how the exception provisions are interpreted, in that it shows a concrete application of the exceptions under Art. 28.
What organisations should watch for
- In data processing activities connected with judicial and enforcement processes, it should be explained to data subjects that KVKK applications may be assessed within the scope of this exception.
Vircon Legal assessment
No action was taken. Together with decision no. 2024/2158 discussed below, the decision constitutes a repeated application of the same exception principle.
The Board Also Assessed a Complaint About Personal Data on Penal Enforcement Institution Receipts Within the Scope of the Same Exception
Decision no: 2024/2158 · Date: 19 December 2024 · Outcome: No administrative fine
The facts
In the incident under examination, a person who was a convict in a penal enforcement institution lodged a complaint claiming that their Turkish identity number and information relating to their sentence status appeared openly on the collection and refund receipts issued at the institution, and that these receipts could also be seen by staff having no direct connection with the matter. In its defence, the institution did not accept this claim; it stated that the receipts in question were seen only by staff working in the relevant unit and were delivered only to the data subject.
What the Board held
The Board did not enter into the substance of the matter (the accuracy of the claim as to by whom the receipts could be seen); assessing that the data processing activity relating to the collection and refund receipts fell within the exception for enforcement processes under Art. 28/1-d, it decided that no action could be taken without examining the substance of the claim.
Why this decision matters
This decision is in the nature of a repetition of the same principle as decision no. 2022/1152 and shows that the exception relating to enforcement processes is applied consistently not only in access requests but also in complaints concerning data security.
What organisations should watch for
- It may be recommended as good administrative practice, even if it falls outside KVKK supervision, that public institutions consider reducing unnecessary data visibility in practice through document design (for example partial masking), even in processes falling within the statutory exception.
Vircon Legal assessment
No action was taken. The precedential value of the decision is considered limited, since it consists of no more than a repetition of the same principle as 2022/1152 in a narrow sector (penal enforcement).
The Board Drew the Limits of the Territorial Scope of Application of the KVKK With a Concrete Example
Decision no: 2025/601 · Date: 28 March 2025 · Outcome: No administrative fine
The facts
In the incident subject to the application, a hotel company headquartered in Hong Kong was subjected to a data breach, and a large number of guests worldwide were affected by that breach. Those affected also include 909 persons resident in Türkiye; however, according to the Board’s finding, these persons did not benefit in Türkiye from the products and services offered by the data controller.
The examination carried out established that the hotel company had no legal entity, employees, office or technical infrastructure in Türkiye, and that all reservation and data processing activities were conducted through Hong Kong-based systems.
What the Board held
Applying to this incident the “effects principle” adopted in its decision no. 2019/10, the Board stated that, in order for the territorial scope of application of the Law to be engaged, it is not sufficient for the data subject merely to be resident in Türkiye; in addition, the condition that the product or service is offered in Türkiye or is actually benefited from by persons in Türkiye must also be met. Since in the specific case the service was not offered in Türkiye, it was decided that the scope of application of the Law was not engaged.
Why this decision matters
This decision is a rare and valuable example which concretely draws the limits of the applicability of the KVKK to companies abroad. It offers a concrete framework for the question whether the KVKK will apply in respect of companies established abroad which have no legal entity in Türkiye but which provide services to, or come into contact with, Turkish citizens.
What organisations should watch for
- It is recommended that companies with structures abroad, serving a foreign customer base or operating across borders examine, when assessing the applicability of the KVKK, not only the place of residence of the data subject but also, together with it, where the service is actually provided.
- It is recommended that Turkish companies which provide legal advice to foreign companies or do business jointly with them reflect this distinction in their contracts and compliance processes.
Vircon Legal assessment
No administrative fine was imposed and it was decided that the scope of application of the KVKK was not engaged. It is considered that this decision constitutes a critical precedent for lawyers and compliance teams with structures abroad or working with foreign companies, and that it will frequently be cited in cross-border data processing relationships.
Other parts of this series
- Part 1 — Ransomware and Unauthorised Access: Which Technical Measures Does the Board Expect?
- Part 2 — Authentication, Email and Physical Access: The Security Standard in Five Decisions
- Part 3 — Service Provider Related Breaches: Why Does Liability Stay With the Data Controller?
- Part 4 — Breach Notification: Five Decisions on the 72-Hour Deadline, Procedure and Transparency
- Part 5 — Explicit Consent: Marketing Permissions, Tick Boxes and Service Conditions
- Part 6 — Where Explicit Consent Is Not Required, and the Limits of the Law: Five Decisions (this article)
- Part 7 — Data Subject Requests and the Obligation to Inform: Procedure in Five Decisions
- Part 8 — The Proportionality Test: CCTV, Audio, Biometrics, Cookies and Masking
- Part 9 — When Does the Board Take No Action? Five Low-Risk Breach Decisions
- Part 10 — Two Credit Bureau Decisions and the Full Index of the 47 Decision Summaries
The starting point of the series is our overall review: The 47 decision summaries published by the KVKK — a consolidated review. A Turkish version of this article is also available: Açık Rıza Gerekmeyen Hâller ve Kanunun Kapsamı: Beş Karar.
For the compliance programme as a whole, see our KVKK and GDPR compliance page, and for the decisions we cover as they are published, KVKK Tracker.
This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.
Author
-
View all postsVircon Legal'de Avukat / Associate at Vircon Legal. Venture transactions · IP and licensing · Tech-sector regulatory
More from Vircon Insights
When Does the Board Take No Action? Five Low-Risk Breach Decisions
August 22, 2026Data Subject Requests and the Obligation to Inform: Procedure in Five Decisions
August 20, 2026Explicit Consent: Marketing Permissions, Tick Boxes and Service Conditions
August 18, 2026Breach Notification: Five Decisions on the 72-Hour Deadline, Procedure and Transparency
August 17, 2026Authentication, Email and Physical Access: The Security Standard in Five Decisions
August 15, 2026Two Credit Bureau Decisions and the Full Index of the 47 Decision Summaries
August 23, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →Mergers & Acquisitions
End-to-end M&A: due diligence, structuring, documentation, negotiation.
View service →