Jump to

Türkiye’s DPA Governs by Principle Decision: What the Accident Data and Guest ID Rulings Tell Product Teams

The Turkish Data Protection Board increasingly delivers its clearest messages through principle decisions. A principle decision does not resolve a single complaint; it is a binding instrument aimed at ending a widespread, recurring practice across a whole sector, and it binds every data controller in its scope from the day it is published. The Board’s two most recent decisions are addressed to two different industries, yet they teach the same principle, and that principle concerns every product that processes personal data.

Accident victims’ data: access rights are purpose-bound

Decision No. 2026/1095 of 20 May 2026 was published in the Official Gazette on 1 July. The background is a stream of complaints about claims consultancy firms, loss adjusters and some lawyers accessing traffic and workplace accident victims’ data through insurance systems, then cold-calling victims and collecting powers of attorney with promises of compensation. The Board lists the practices one by one: accessing data without a valid legal basis, using data obtained from systems to contact victims, calling without any request, steering victims toward powers of attorney, and using data beyond its purpose or disclosing it to third parties are all unlawful. The bill is not only administrative; the Board expressly points to criminal liability under Articles 136 and 137 of the Criminal Code.

The generalisable part is sector-independent: having access to a system does not mean you may use its data for another purpose. Under Article 12, the Board expects technical and organisational measures that tie access to duty and authority, which turns the access matrix showing who reaches which data and why from good practice into the measure itself.

Hotel ID copies: habit is not a legal basis

The second decision is slightly older but only now being felt on the ground: Decision No. 2025/2120 of 6 November 2025 ended the identity photocopy habit in the accommodation sector. The Board’s distinction is elegant: legislation clearly allows hotels to take identity details, and checking a document to verify identity is lawful, but photocopying and storing it is excessive processing with no legal basis. The decision demands two things, ending the practice and lawfully destroying the copies already held. Non-compliance is exposed to administrative fines as a failure of Article 12 measures.

What the two decisions teach product teams

Principle In the decisions In your product
Purpose limitation Data reached through a system cannot be used to make contact Role-based access; a change of purpose triggers fresh legal analysis
Data minimisation Looking to verify is enough; copying and storing is too much Question document storage in onboarding; verify and let go
Security measures (Art. 12) Access restrictions and destruction are the measure itself Access matrix, logs and a retention-destruction calendar ready for audit

The Board’s line has been consistent for a while: the biometric attendance decision ran on the same logic; what is technically possible and convenient for the controller is unlawful if disproportionate. When VERBİS records and inventories are not updated in line with these decisions, the problem doubles at inspection.

And a third before the ink dried: public bodies’ online lists

As this piece was being prepared the Board published one more principle decision: Decision No. 2026/1301 of 1 July 2026, which entered the Official Gazette on 28 July, this time addressed to public bodies. Publishing exam results, draw lists and similar announcements containing personal data openly on the internet was held to be a processing activity; content without a legal basis must come down, and result queries must move to authenticated systems such as e-Devlet. The pattern is the same again: the easiest way to reach information is not the lawful way to process it. For products serving the public sector or integrating with public data, the practical takeaway is to design around authenticated query endpoints rather than open lists.

Do principle decisions bind us too?

Yes. A principle decision binds every data controller within its subject matter and is published in the Official Gazette. Even where your sector is not the decision’s addressee, it shows the Board’s interpretive line and becomes the yardstick of the next inspection; applying the reasoning to your own data flows is the safest reading.

What should we do with old ID copies we already hold?

The decision answers directly: lawful destruction. Destruction itself needs a record; destruction minutes and an updated retention policy are your evidence, in a future inspection, that the practice genuinely ended.

Where to start

Three checks are enough: is the matrix showing which teams access which data in which systems current; does any product flow still store identity or document copies, and are they truly necessary; and does your retention-destruction calendar reflect these two decisions? Put the three answers on one page, and stay out of the Board’s next principle decision.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement.

    View all posts
Considering a similar matter?Talk to counsel that moves at the speed of your round.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 5 August 2026 · last updated: 4 August 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.