These five decisions share one question: does having a legal basis for processing mean the processing is proportionate? The Board’s answer is no. The justification accepted for video is required separately for audio, obtaining explicit consent does not legitimise the collection of biometric data, and partial masking is not anonymisation.
This article is part 8 of a ten-part series examining, section by section, the 47 decision summaries published by the Turkish Personal Data Protection Board on 10 August 2026. For the overall assessment of the set, see our review of all 47 decisions.
Every decision follows the same structure: the facts, the Board’s assessment, why the decision matters, and the practical implications for organisations. The “Vircon Legal assessment” headings contain our own commentary apart from the fine amount; they are not part of the text of the decision.
Decisions covered in this article
| Decision | Date | Subject | Outcome |
|---|---|---|---|
| 2023/2007 | 30 November 2023 | Subjected the Video and the Audio Recording on a Security Camera to Separate Proportionality Tests | TRY 125,000 |
| 2024/197 | 8 February 2024 | Gave Concrete Form to the Principle That “Explicit Consent Does Not Legitimise Excessive Data Collection” in a Decision Concerning a University | No administrative fine, instruction issued |
| 2024/1361 | 8 August 2024 | Set Out One of the Most Detailed Applicable Frameworks on Cookie Consent and Explicit Consent Granularity | TRY 265,000 |
| 2024/275 | 22 February 2024 | Showed in a Survey News Report That Partial Masking Is Not the Same Thing as True Anonymisation | TRY 40,179 |
| 2023/1787 | 19 October 2023 | Assessed the Sending of Health Data to a Number That Was Not Up to Date Under the Principle of Accuracy | TRY 30,000 |
The Board Subjected the Video and the Audio Recording on a Security Camera to Separate Proportionality Tests
Decision no: 2023/2007 · Date: 30 November 2023 · Outcome: TRY 125,000
The facts
In the incident under examination, it emerged that the camera placed in the security booth at the entrance point of a workplace recorded, unlike standard security cameras, not only video but also audio. That audio recording contained words uttered by an employee directed at his superior; the employer subsequently submitted this recording as evidence in an employment case (relating to the termination of the employment contract) between it and the employee.
The employee complained to the Board, arguing that the taking of such an audio recording of him and the use of that recording in the course of the proceedings were contrary to the KVKK.
What the Board held
The Board found the video recording in the security booth lawful on the basis of a legitimate interest in ensuring workplace security. However, since no separate and concrete justification of necessity could be shown for the audio recording feature of the same system, it deemed that part unlawful.
Why this decision matters
This decision clearly demonstrates that video recording and audio recording are assessed by the Board as two separate and independent data processing activities and that each is subjected to its own proportionality/necessity test. Considering that the great majority of the security cameras sold on the market have an audio recording feature and that this feature is not separately assessed by most employers, it is considered that the decision has a very broad field of application.
What organisations should watch for
- It is recommended that it be checked technically whether the security cameras used have an audio recording feature.
- If there is no separate and concrete justification of necessity for audio recording, it is recommended that this feature be disabled in the device settings.
- In the exceptional areas where audio recording is needed (for example certain security points), it is recommended that the justification for this need be documented.
Vircon Legal assessment
An administrative fine of TRY 125,000 was imposed. It is considered that, because the decision is directly applicable to almost every workplace using security cameras and can be turned into a concrete compliance check, it is one of the decisions with the broadest field of application among the decisions examined.
The Board Gave Concrete Form to the Principle That “Explicit Consent Does Not Legitimise Excessive Data Collection” in a Decision Concerning a University
Decision no: 2024/197 · Date: 8 February 2024 · Outcome: No administrative fine, instruction issued
The facts
In the incident under examination, a university monitors attendance at classes by means of a fingerprint scanning system instead of the traditional methods of signature or card swiping. Students take part in the roll call by scanning their fingers on a device at the start of the class; during this operation the student’s fingerprint is processed. Before beginning this practice, the university had the students sign an explicit consent form.
Notwithstanding that explicit consent had been obtained, a student complained to the Board, finding the processing of his biometric data in this manner disproportionate.
What the Board held
The Board found that the existence of explicit consent is not sufficient on its own, and that the use of biometric data while a less intrusive alternative such as taking attendance by signature was available was contrary to the principle of proportionality under Article 4(2)(ç). In the Board’s reasoning, the principle that explicit consent does not legitimise excessive and disproportionate data collection was expressly emphasised.
Instead of an administrative fine, an instruction was issued for the biometric data processing to be halted immediately, for the existing data to be destroyed, for a transition to an alternative method, and for disciplinary proceedings to be initiated against the responsible personnel pursuant to Article 18(3).
Why this decision matters
This decision contains one of the most generalisable and most important principles among the decisions examined: the existence of explicit consent does not remove the proportionality review. This principle is not limited to biometric data alone but is capable of being extended to every kind of excessive/disproportionate data collection practice.
The issuing of an instruction to halt the processing and to initiate disciplinary proceedings against the responsible personnel instead of an administrative fine is a rarely seen and instructive type of sanction; this shows that the Board does not resort to an administrative fine in every infringement and is also able to use proportionate and deterrent alternative sanctions.
What organisations should watch for
- It is recommended that organisations which monitor employees or students by biometric methods such as fingerprint or facial recognition assess whether the same purpose could be achieved by a less intrusive method (card, signature, PIN).
- Documenting this assessment (the proportionality analysis) in writing is important in terms of being able to demonstrate, in a possible review, the justification for preferring the biometric method.
- It must be expressly reflected in internal compliance policies that the fact that explicit consent has been obtained does not remove the obligation to comply with the principle of proportionality.
Vircon Legal assessment
Although no administrative fine was imposed in the decision, the halting of the biometric data processing and the disciplinary instruction may, in the final analysis, give rise to a more severe operational impact than an administrative fine. It is expected that this decision will be frequently cited in the coming period for educational institutions and for workplaces using biometric access/attendance monitoring.
The Board Set Out One of the Most Detailed Applicable Frameworks on Cookie Consent and Explicit Consent Granularity
Decision no: 2024/1361 · Date: 8 August 2024 · Outcome: TRY 265,000
The facts
In the incident subject to the Board’s assessment, the complaint concerning an educational institution contains three separate matters. The first relates to the institution’s security camera practice and to an alleged audio recording; as a result of the examination it was established that the video recording complied with the relevant legislation (Ministry of National Education regulations) and that the alleged audio recording was not part of an institutional system but the individual act of an employee.
The second matter is that the analytics cookies used on the institution’s website began to operate automatically as soon as the site was opened, without the user giving any consent. The third matter is that the contact form on the site was designed in such a way that, even where the visitor wished only to send an “information request”, the same consent checkbox would mean that consent had also been given to “advertising/marketing/campaign” communications.
What the Board held
The Board clarified that only cookies strictly necessary for the operation of the website do not require explicit consent, and that for functional, performance or advertising cookies an “opt-in” mechanism (switched off by default, requiring the user actively to tick it) is mandatory.
It further stated that a single consent checkbox combining two purposes of different character, such as a one-off service like an “information request” and “continuous marketing”, undermines the element of explicit consent being “related to a specific matter” and affects the element of free will.
Why this decision matters
This decision constitutes one of the most detailed and directly applicable frameworks on cookie management and explicit consent granularity among the decisions examined. For almost every company operating a website, it has the character of a concrete checklist concerning the technical design of the cookie consent mechanism.
The finding that the use of a single consent checkbox for different purposes may undermine the validity elements of explicit consent is a principle that is not limited to cookies alone but is capable of being extended to every kind of multi-purpose consent form.
What organisations should watch for
- It is recommended that it be ensured that the website cookie consent mechanism runs only strictly necessary cookies without consent and offers an opt-in that is switched off by default for all other cookie categories.
- It is recommended that separate consent options be offered for different purposes (such as information requests, marketing, newsletter subscription) and that a single general consent checkbox not be used.
- In relation to security cameras, it is recommended that it be ensured that the audio recording feature is active as the result of an institutional decision and not as the result of the individual act of an employee, and that internal control on this matter be strengthened.
Vircon Legal assessment
An administrative fine of TRY 250,000 for the cookie infringement and a further TRY 15,000 for the failure to inform, amounting to a total of TRY 265,000, was imposed. It is considered that the decision is particularly valuable because it offers a concrete technical checklist that can be put into practice immediately by the teams responsible for digital marketing and website management.
The Board Showed in a Survey News Report That Partial Masking Is Not the Same Thing as True Anonymisation
Decision no: 2024/275 · Date: 22 February 2024 · Outcome: TRY 40,179
The facts
In the incident under examination, a local press organ published on its website, on a participant-by-participant basis, the results of an election survey it had conducted in its region. In the published records, the participants’ name and surname information was partially concealed by transposing/abbreviating the letters, and their telephone numbers in such a way that only the last four digits were visible. However, in some records, information as to the neighbourhood in which the participant lived was also included.
The survey results also contained information as to which party the participants had voted for, and this information is regarded as special category data, as data on political opinion, under the KVKK. The matter was addressed not upon a complaint but within the framework of an examination initiated by the Board of its own motion (ex officio).
What the Board held
The Board found that where the partial telephone number and the neighbourhood information are assessed together the person becomes identifiable, and that for this reason the masking applied did not provide true anonymisation. It further decided that, because the content included information on political opinion (special category data) and because the consent obtained by message did not bear the elements of explicit consent, there was no valid legal basis under Article 6.
Why this decision matters
The decision is instructive in that it shows by a concrete example that the concepts of “masking” and “anonymisation” are not the same thing. The principle that the coming together of indirect identifiers (such as a partial telephone number + neighbourhood information) may render a person re-identifiable is generalisable for all sectors carrying out surveys, research and data analytics.
What organisations should watch for
- It is recommended that it be noted that the concealment of a single field in a data set (for example, of part of a telephone number) may not be sufficient, and that it be separately assessed whether the remaining fields together render the person identifiable.
- In the publication of survey results that may contain special categories of personal data such as political opinion, the principle of data minimisation is required to be applied with particular care.
- It is recommended that it be separately assessed whether consents obtained by message or similar short routes bear the statutory elements of explicit consent (specificity, being based on information, free will).
Vircon Legal assessment
An administrative fine of TRY 40,179 was imposed. The relatively low amount of the fine is probably related to the economic scale of the data controller; however, it is considered that the principle of “masking ≠ anonymisation” contained in the decision is an important reference for every sector that publishes or shares data sets.
The Board Assessed the Sending of Health Data to a Number That Was Not Up to Date Under the Principle of Accuracy
Decision no: 2023/1787 · Date: 19 October 2023 · Outcome: TRY 30,000
The facts
In the incident under examination, a healthcare institution notified the result of a Covid-19 test taken by a person to the telephone number in its records by SMS. However, that registered number was not the data subject‘s current number but a number belonging to a third party (the person’s maternal uncle), which had been recorded during an application in the past and had not been updated since that date.
For this reason, the test result, which constitutes health data falling within the special categories of personal data, reached not the data subject himself but a third party. The data subject, having noticed the situation, applied to the Board, finding the transmission of health data to the wrong person contrary to the KVKK.
What the Board held
The Board assessed the incident not so much within the scope of explicit consent as an infringement of the principle that “personal data shall be kept accurate and up to date” under Article 4(2)(b). The decision also contains an instruction for the telephone number to be updated and for the old data to be destroyed.
Why this decision matters
The decision is instructive in that it offers a rarely seen but concrete application of the principle of accuracy (one of the data quality principles). The fact that a sensitive data category such as health data reached the wrong person by means of contact information that was not up to date shows that data quality processes are as important as security.
What organisations should watch for
- It is recommended that the currency of the contact details (telephone, e-mail) used in the communication of sensitive data categories such as, in particular, health data be verified periodically.
- It is recommended that contact detail updating processes be integrated into patient/customer registration systems in a manner that is easily accessible and can be regularly updated.
Vircon Legal assessment
An administrative fine of TRY 30,000 was imposed. Although the amount of the fine is low, it is considered that the decision offers a concrete example drawing attention to the importance of data quality and currency checks for organisations processing health data.
Other parts of this series
- Part 1 — Ransomware and Unauthorised Access: Which Technical Measures Does the Board Expect?
- Part 2 — Authentication, Email and Physical Access: The Security Standard in Five Decisions
- Part 3 — Service Provider Related Breaches: Why Does Liability Stay With the Data Controller?
- Part 4 — Breach Notification: Five Decisions on the 72-Hour Deadline, Procedure and Transparency
- Part 5 — Explicit Consent: Marketing Permissions, Tick Boxes and Service Conditions
- Part 6 — Where Explicit Consent Is Not Required, and the Limits of the Law: Five Decisions
- Part 7 — Data Subject Requests and the Obligation to Inform: Procedure in Five Decisions
- Part 8 — The Proportionality Test: CCTV, Audio, Biometrics, Cookies and Masking (this article)
- Part 9 — When Does the Board Take No Action? Five Low-Risk Breach Decisions
- Part 10 — Two Credit Bureau Decisions and the Full Index of the 47 Decision Summaries
The starting point of the series is our overall review: The 47 decision summaries published by the KVKK — a consolidated review. A Turkish version of this article is also available: Ölçülülük Sınavı: Kamera, Ses, Biyometri, Çerez ve Maskeleme Kararları.
For the compliance programme as a whole, see our KVKK and GDPR compliance page, and for the decisions we cover as they are published, KVKK Tracker.
This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.
Author
-
View all postsVircon Legal'de Avukat / Associate at Vircon Legal. Venture transactions · IP and licensing · Tech-sector regulatory
More from Vircon Insights
Türkiye's DPA Draws the Line on Biometrics: Attendance Is Out, Security Access Is Conditional
August 27, 2026Can You Answer a KVKK Data Subject Request by Phone? The Authority's 1 October 2026 Announcement
October 1, 2026The Medium-Term Programme Puts a Date on KVKK-GDPR Alignment: What Changes for Compliance Programmes Caught Between Two Laws
September 8, 2026Two Credit Bureau Decisions and the Full Index of the 47 Decision Summaries
August 23, 2026When Does the Board Take No Action? Five Low-Risk Breach Decisions
August 22, 2026Data Subject Requests and the Obligation to Inform: Procedure in Five Decisions
August 20, 2026Related Practice Areas
Employment Law
Employment contracts, ESOP, termination, non-compete, work permits.
View service →Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →US Company Formations & Flip-Ups
Delaware C-Corp, flip-up structures, SAFE/convertible notes, 83(b).
View service →