The Turkish Data Protection Board increasingly delivers its clearest messages through principle decisions. A principle decision does not resolve a single complaint; it is a binding instrument aimed at ending a widespread, recurring practice across a whole sector, and it binds every data controller in its scope from the day it is published. The Board’s two most recent decisions are addressed to two different industries, yet they teach the same principle, and that principle concerns every product that processes personal data.
Accident victims’ data: access rights are purpose-bound
Decision No. 2026/1095 of 20 May 2026 was published in the Official Gazette on 1 July. The background is a stream of complaints about claims consultancy firms, loss adjusters and some lawyers accessing traffic and workplace accident victims’ data through insurance systems, then cold-calling victims and collecting powers of attorney with promises of compensation. The Board lists the practices one by one: accessing data without a valid legal basis, using data obtained from systems to contact victims, calling without any request, steering victims toward powers of attorney, and using data beyond its purpose or disclosing it to third parties are all unlawful. The bill is not only administrative; the Board expressly points to criminal liability under Articles 136 and 137 of the Criminal Code.
The generalisable part is sector-independent: having access to a system does not mean you may use its data for another purpose. Under Article 12, the Board expects technical and organisational measures that tie access to duty and authority, which turns the access matrix showing who reaches which data and why from good practice into the measure itself.
Hotel ID copies: habit is not a legal basis
The second decision is slightly older but only now being felt on the ground: Decision No. 2025/2120 of 6 November 2025 ended the identity photocopy habit in the accommodation sector. The Board’s distinction is elegant: legislation clearly allows hotels to take identity details, and checking a document to verify identity is lawful, but photocopying and storing it is excessive processing with no legal basis. The decision demands two things, ending the practice and lawfully destroying the copies already held. Non-compliance is exposed to administrative fines as a failure of Article 12 measures.
What the two decisions teach product teams
| Principle | In the decisions | In your product |
|---|---|---|
| Purpose limitation | Data reached through a system cannot be used to make contact | Role-based access; a change of purpose triggers fresh legal analysis |
| Data minimisation | Looking to verify is enough; copying and storing is too much | Question document storage in onboarding; verify and let go |
| Security measures (Art. 12) | Access restrictions and destruction are the measure itself | Access matrix, logs and a retention-destruction calendar ready for audit |
The Board’s line has been consistent for a while: the biometric attendance decision ran on the same logic; what is technically possible and convenient for the controller is unlawful if disproportionate. When VERBİS records and inventories are not updated in line with these decisions, the problem doubles at inspection.
And a third before the ink dried: public bodies’ online lists
As this piece was being prepared the Board published one more principle decision: Decision No. 2026/1301 of 1 July 2026, which entered the Official Gazette on 28 July, this time addressed to public bodies. Publishing exam results, draw lists and similar announcements containing personal data openly on the internet was held to be a processing activity; content without a legal basis must come down, and result queries must move to authenticated systems such as e-Devlet. The pattern is the same again: the easiest way to reach information is not the lawful way to process it. For products serving the public sector or integrating with public data, the practical takeaway is to design around authenticated query endpoints rather than open lists.
Do principle decisions bind us too?
Yes. A principle decision binds every data controller within its subject matter and is published in the Official Gazette. Even where your sector is not the decision’s addressee, it shows the Board’s interpretive line and becomes the yardstick of the next inspection; applying the reasoning to your own data flows is the safest reading.
What should we do with old ID copies we already hold?
The decision answers directly: lawful destruction. Destruction itself needs a record; destruction minutes and an updated retention policy are your evidence, in a future inspection, that the practice genuinely ended.
Where to start
Three checks are enough: is the matrix showing which teams access which data in which systems current; does any product flow still store identity or document copies, and are they truly necessary; and does your retention-destruction calendar reflect these two decisions? Put the three answers on one page, and stay out of the Board’s next principle decision.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement.
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro callMore from Vircon Insights
Gaming Law in Türkiye: A Guide for Studios, Publishing Deals and Esports Teams
July 17, 2026Türkiye's First Official RWA Move: The Digital Precious Metals Communiqué Opens a Third Lane for Tokenization
August 11, 2026Türkiye's 12th Judicial Package Through a Technology Lens: The Full Map of Law No. 7589
August 10, 2026Türkiye Raises the Fintech Capital Bar Again: New Minimum Equity Floors for Payment and E-Money Institutions
August 7, 2026The Sensor on the Worker's Wrist Reaches the Courts: Türkiye's First Cassation Ruling on Workplace Wearables
August 6, 2026Türkiye Writes Gaming into Law No. 5651: A Guide to the New Platform Regime
August 4, 2026Related Practice Areas
Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →US Company Formations & Flip-Ups
Delaware C-Corp, flip-up structures, SAFE/convertible notes, 83(b).
View service →Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →