GRC PERSPECTIVE: DATA PROTECTION & COMPLIANCE BULLETIN – APRIL 2026

WHAT’S HAPPENING IN TURKEY?

Constitutional Court Ruling: Regulation on Name Change Notices Overturned

In a decision published on April 1, 2026, the Constitutional Court (“AYM”) annulled the regulation in Article 27 of the Turkish Civil Code No. 4721, which required court decisions regarding name changes to be published on the Press Announcements Agency’s website, finding it contrary to the right to the protection of personal data. Under the provision subject to annulment, the publication of court decisions regarding name changes involved the public disclosure of personal data such as the individual’s place of residence, date of birth, parents’ names, and their old and new first and last names.

The Court clearly established that the aforementioned practice constituted an interference with the right to the protection of personal data. In this context, it was determined that making personal data accessible to the public through publication is directly linked to the right to respect for private life of the individuals concerned. In its decision, the Constitutional Court acknowledged that the regulation’s purpose was to inform third parties who might be affected by a name change; however, it emphasized that the method chosen to achieve this purpose did not comply with the principle of proportionality. Indeed, the Court stated that a name change already produces legal consequences upon its entry into the population registry and that third parties could be informed of this change through other means.

Furthermore, the absence of any legal limitation on the duration for which the notices must be published was deemed to potentially lead to personal data becoming accessible indefinitely. The Court assessed that this situation could have severe consequences for the interests of the individuals concerned and is incompatible with the principles of data minimization and processing for a limited period.

Consequently, the Constitutional Court concluded that the interference with the right to the protection of personal data was neither in accordance with the requirements of a democratic society nor proportionate, and thus annulled the relevant regulation.

The Constitutional Court’s decision demonstrates that the right to the protection of personal data is not limited solely to data processing procedures; it must also be directly applied to public information mechanisms such as announcements and notices.

The decision particularly emphasizes that applications based on the public sharing of personal data with broad audiences are not sufficient merely to have a legal basis; they must also be assessed separately in terms of the principles of necessity and proportionality.

Furthermore, by drawing attention to the risk that data published in digital environments may become permanently accessible, the importance of the principles of data minimization and processing for a limited period is once again underscored. In this context, it is assessed that data controllers should prefer information methods with more limited access and appropriate to the purpose rather than publicly accessible announcement methods.

Bill Approved by the Turkish Grand National Assembly: New Obligations for Social Media, Identity Verification, and Data Processing Procedures

The bill approved by the Turkish Grand National Assembly, which proposes amendments to the Social Services Law and certain other laws, contains significant regulations regarding data processing procedures for social media platforms and digital service providers.

Under the proposal, social media providers are subject to the obligation to block access to platforms for users under the age of 15; to fulfill this obligation, the establishment of age verification mechanisms is envisaged. It is proposed that this verification process be carried out through a system operating via the e-Government infrastructure, linking users’ identity information with their social media accounts.

Additionally, platforms with daily traffic exceeding a certain threshold are required to conduct proactive content monitoring using artificial intelligence and automated systems to prevent the re-upload of content for which removal or access restriction orders have previously been issued.

The proposal also outlines obligations for foreign-based game distributors, such as maintaining a representative in Turkey, implementing age restrictions, and establishing parental control mechanisms; within this scope, the Information and Communications Technologies Authority is granted the authority to request information regarding data processing procedures and algorithms. In the event of non-compliance with the obligations introduced by the regulation, platforms may face administrative fines, restrictions on advertising revenue, and bandwidth throttling.

Pursuant to the provision added to the Child Protection Law, in order to strengthen the protection of children, individuals with final convictions for certain serious crimes are prohibited from operating workplaces where children are concentrated, working in such places, or assuming any role there. Furthermore, in line with the restrictions based on criminal records and archive records; it is stipulated that licenses shall not be issued to such individuals, the transfer of existing businesses shall be mandatory, and within this scope, employees must submit “fit-to-work” certificates, issued based on their criminal records and archive records, to their employers every six months.

GRC LEGAL PERSPECTIVE

This regulation has the potential to expand the scope of data processing activities on social media and digital platforms. The identity verification mechanism envisaged through e-Government establishes a direct link between user identity and digital activities, requiring careful evaluation in terms of the principles of data minimization and proportionality.

On the other hand, the obligation for automated content filtering may entail the continuous monitoring of user content, potentially giving rise to new obligations regarding transparency and legal boundaries. Additionally, the regulation under the Child Protection Act links the processing of criminal conviction data to a legal basis and imposes periodic data collection and monitoring obligations on employers.

Ministry of Justice 2025 Judicial Statistics: Increase in Crimes Related to Personal Data!

The “Justice Statistics 2025” report published by the Ministry of Justice reveals a notable increase in crimes related to the protection of personal data and the privacy of private life.

According to the report, a total of 120,433 new cases were filed in public prosecutor’s offices under the category of “crimes against privacy and the private sphere.” Within this scope, the highest proportion was accounted for by the crime of unlawfully obtaining data, followed by crimes involving the violation of privacy and the unauthorized recording of personal data. These figures demonstrate that violations of personal data protection are not limited to administrative sanctions or regulatory processes; they have also gained significant prominence in the realm of criminal law.

In this regard, the report highlights that, alongside increasing digitalization, personal data-related crimes are diversifying and becoming more visible to judicial authorities.

Operation Against a Network Facilitating Illegal Access to Personal Data: 177 Million TL Worth of Data Trafficking Uncovered!

As part of a cyber operation coordinated by the National Intelligence Organization, a comprehensive intervention was carried out against a network identified as having illegally accessed the information systems of public institutions and personal data belonging to citizens. As a result of the operation, 11 individuals were arrested, and it was revealed that the network operated through a large-scale digital infrastructure.

Technical investigations revealed that the network had established numerous panels and systems capable of querying personal data; in this context, approximately 40 different systems were taken offline, and a significant amount of digital evidence was recovered.

Additionally, the investigation revealed that systematic access to personal data was achieved through numerous query panels made available to various users.

According to the findings, it was determined that the network offered its personal data query service to third parties through a “franchise system” and established a broad user network via this structure. Financial investigations also revealed that approximately 177 million TL in revenue was generated through these activities, and transactions were conducted using cryptocurrencies to conceal the trail of criminal proceeds.

Within the scope of the investigation, it is stated that the suspects are being prosecuted on various charges related to “the unlawful acquisition and dissemination of personal data,” “interference with computer systems,” and related cybercrimes; that analysis of the obtained data is ongoing, and that new operations may be on the agenda.

GRC LEGAL PERSPECTIVE

This operation demonstrates that personal data has become not only a matter of individual rights but also an asset of high economic value targeted by organized crime structures. In particular, the structure devised through the “franchise system” reveals that data access can be transformed into a scalable service, thereby systematizing data security risks.

Allegations of unauthorized access to public systems, meanwhile, once again highlight the importance of cybersecurity measures. In this context, it is necessary to adopt a multi-layered security approach not only against external threats but also regarding access management, logging, and internal control mechanisms. Additionally, the movement of criminal proceeds through crypto assets strengthens the link between data breaches and the financial system while complicating traceability. This situation demonstrates that the fields of data protection, cybersecurity, and financial regulation are becoming increasingly intertwined.

In this context, it is critically important for data controllers to go beyond mere compliance with the Personal Data Protection Law (KVKK) by developing proactive cybersecurity strategies and regularly auditing their data processing operations.

Furthermore, the investigation revealed that systematic access to personal data was achieved through numerous query panels made available to various users.

According to the findings, it was determined that the network provided its personal data query service to third parties through a “franchise system” and established a broad user network via this structure. Financial investigations revealed that approximately 177 million TL in revenue was generated through these activities, and transactions were conducted using cryptocurrencies to conceal the trail of criminal proceeds.

Within the scope of the investigation, it is stated that the suspects are being prosecuted on various charges related to “the unlawful acquisition and dissemination of personal data,” “interference with computer systems,” and related cybercrimes”; analysis of the obtained data is ongoing, and new operations may be on the agenda.

MASAK 2025 Activity Report: Increase in Suspicious Transaction Reports and Audit Activities!

The 2025 activity report published by the Financial Crimes Investigation Board (“MASAK”) reveals that the scope of data collection, analysis, and audit activities conducted as part of the fight against money laundering and terrorist financing has expanded.

According to the report, a total of 464,010 suspicious transaction reports were received in 2025, and data on approximately 1 million individuals was processed in connection with these reports. While the analysis rate for these reports stood at 71%, the analysis processes resulted in 4,813 reports being submitted to the relevant authorities, and criminal complaints were filed against 422 individuals. It is observed that the vast majority of suspicious transaction reports were submitted electronically, and the group of entities submitting the most reports was banks; followed by payment and electronic money institutions and crypto-asset service providers. In terms of crime categories, fraud, cybercrimes, failure to report transactions conducted on behalf of others, and illegal betting and gambling operations stood out.

Furthermore, the report states that as a result of activities conducted under compliance audits, administrative fines exceeding 3.6 billion TL were imposed, indicating that the effectiveness of oversight mechanisms has been enhanced.

GRC LEGAL PERSPECTIVE

MASAK data reveals that the volume and variety of personal data processed within the financial system are rapidly increasing; this data is processed intensively not only for commercial purposes but also for the prevention and detection of crime.

In particular, the prominence of payment and electronic money institutions, as well as crypto-asset service providers, alongside banks in suspicious transaction reports indicates that these sectors operate under high data processing risks and intense regulatory scrutiny.

Furthermore, the fact that data belonging to millions of individuals is subject to analysis processes indicates that principles of data minimization, purpose limitation, and data security, as well as cybersecurity measures, have become critical. Indeed, in organizations processing data at this scale, risks such as unauthorized access, data breaches, and internal threats can directly lead to serious penalties under both the KVKK and sector-specific regulations.

On the other hand, the imposition of substantial administrative fines demonstrates that compliance with these obligations is not merely a regulatory requirement but has also become a fundamental component of financial, operational, and cybersecurity risk management.

In this context, it is particularly important for financial institutions and fintech companies to structure their suspicious transaction reporting processes, data security measures, cybersecurity infrastructure, and internal control mechanisms by addressing both KVKK and MASAK obligations together.

WHAT’S HAPPENING AROUND THE WORLD?

A Common Template for Data Protection Impact Assessment (“DPIA”) Processes Has Been Published!

A common template for DPIA processes has been adopted to facilitate compliance with the European Union’s General Data Protection Regulation (GDPR) and ensure consistency in its application across Europe.

This template aims to ensure that DPIA processes—which must be conducted when personal data processing activities pose high risks—are carried out in a more systematic, consistent, and documentable manner. In this context, the template provides a structured framework that includes key elements such as describing the nature of data processing activities, conducting a necessity and proportionality assessment, and identifying and mitigating risks to individuals’ rights and freedoms.

While the template is not mandatory, it is noted that it enables data controllers to conduct comprehensive and thorough assessments using predefined fields; in this regard, it contributes to the more effective execution of processes by reducing the risk of errors.

The template is also supported by an explanatory document aimed at clarifying the fundamental concepts of DPIA processes in plain language and addressing potential questions that may arise during implementation. It is noted that the draft text has been opened for public consultation, and following the consultation process, it is planned to be adopted as a “master template” compatible with common standards or national templates by data protection authorities across Europe.

New Guidelines and Certification Steps from the EDPB Regarding Scientific Research and Data Processing Activities

The European Data Protection Board (EDPB) adopted and opened for public consultation a guideline on the processing of personal data for scientific research purposes at its recent plenary meeting.

The guidelines detail the criteria that must be considered for a data processing activity to be evaluated as falling within the scope of “scientific research”; in this context, it is stated that factors such as the systematic and methodological nature of the activities, compliance with ethical standards, transparency, and verifiability are decisive.

The EDPB also noted that data processing activities for scientific research purposes may, under certain conditions, be deemed compatible with the original processing purpose; in this context, it indicated that data controllers may not be required to conduct an additional compatibility test for the purpose. However, it was emphasized that the legal basis for the initial data processing activity must also be valid for subsequent processing.

The guidelines include references to the “broad consent” and “dynamic consent” models regarding explicit consent; it was stated that these approaches may be used together depending on the nature of the research processes. In addition, the EDPB announced the formation of a special working group to expedite the completion of the anonymization guidelines; it highlighted the importance of technical and organizational measures such as anonymization and pseudonymization in data processing processes.

The Board also adopted its opinions on the Europrivacy certification criteria and noted that this certification could serve as a guarantee mechanism for data transfer processes under the European Data Protection Seal.

“Legitimate Interest” Approach Regarding AI Training Data in the EU Digital Omnibus Process Withdrawn!

In the latest compromise text regarding the Digital Omnibus regulatory process being carried out in the European Union, it is observed that the previous regulatory proposal explicitly recognizing the “legitimate interest” legal basis for the processing of personal data in the context of training artificial intelligence systems has been removed from the text.

It is stated that this change was made in line with criticisms raised by the European Data Protection Board and the European Data Protection Supervisor; specifically, the view that evaluating extensive data processing activities in AI training processes under the “legitimate interest” framework poses risks in terms of data protection principles was influential.

This development indicates that the legal grounds for processing personal data in the development and training of artificial intelligence systems may be interpreted more narrowly; it brings to the forefront the need for data controllers to re-evaluate the requirement to rely on explicit consent, a contract, or other legal grounds for such activities. On the other hand, this approach indicates that the balance between AI development processes and data protection law will be addressed within a stricter framework and, in particular, that large-scale data processing activities will be subject to closer scrutiny.

Regulation Introducing Flexibility in the Use of Personal Data for AI Development Processes in Japan

The Japanese government has approved a draft law proposing amendments to legislation regarding the protection of personal data, aimed at accelerating the development of artificial intelligence technologies. Under this regulation, it is anticipated that explicit consent may not be required for the use of personal data in artificial intelligence development processes, provided that the data processing activities do not enable the direct identification of individuals. In this context, a more flexible approach is being adopted, particularly for model training and data set creation activities.

While current regulations require strict consent for the sharing of sensitive personal data with third parties, the new regulation proposes to lift this requirement for data processing activities that do not cause clear harm to individuals’ rights and interests. However, the regulation is not limited to merely facilitating data use; it also strengthens the penalties to be imposed in cases where personal data is obtained or used in violation of the law. In this context, the way is being paved for the imposition of administrative fines proportional to the profits obtained on individuals or organizations processing personal data above a certain threshold.

It is assessed that the regulation was prepared in line with Japan’s goal of enhancing its global competitive strength in the field of artificial intelligence; however, it may lead to a renewed debate on the balance between data protection principles and innovation.

The “Legitimate Interest” Approach Regarding AI Training Data in the EU Digital Omnibus Process Has Been Withdrawn!

In the latest compromise text regarding the EU’s Digital Omnibus legislative process, it is observed that the previous proposal to explicitly recognize the “legitimate interest” legal basis for the processing of personal data in the context of training artificial intelligence systems has been removed from the text.

It is stated that this change was made in line with criticisms raised by the European Data Protection Board and the European Data Protection Supervisor; specifically, the view that evaluating broad-scale data processing activities within the scope of legitimate interest during AI training processes poses risks in terms of data protection principles was influential.

This development indicates that the legal grounds for processing personal data in the development and training of artificial intelligence systems may be interpreted more narrowly; it brings to the forefront the need for data controllers to re-evaluate the requirement to rely on explicit consent, a contract, or other legal grounds for such activities. On the other hand, this approach indicates that the balance between AI development processes and data protection law will be addressed within a stricter framework and, in particular, that large-scale data processing activities will be subject to closer scrutiny.

Important Ruling on the Exercise of the Right of Access in Finland

The Finnish data protection authority, following an investigation into how a credit information agency handled data subjects’ access requests, determined that the company had violated its obligations under the GDPR. In the case at hand, it was determined that data subjects’ access requests submitted via email were not directly responded to; instead, applicants were directed to the company’s own data access platform. The authority assessed that this practice was inconsistent with the obligation to facilitate data subjects’ exercise of their rights.

Additionally, it was determined that the company automatically charged fees to individuals who submitted multiple access requests within a 12-month period. The Authority emphasized that this practice was unlawful, noting that data controllers may only charge fees for access requests if each request is individually assessed and it is demonstrated that the request is clearly unfounded or excessive. The decision states that the right of access must be provided free of charge, and practices that could hinder the exercise of this right constitute a violation of data protection legislation.

GRC LEGAL PERSPECTIVE

This decision demonstrates that data subjects’ right of access is not merely a theoretical right; it is an active obligation that data controllers must effectively facilitate. Redirecting requests to a specific platform or rendering alternative channels effectively ineffective may be considered practices that indirectly hinder the exercise of this right.

On the other hand, it is emphasized that fee-based practices regarding access requests are of an exceptional nature and may only be considered in specific cases where there are “manifestly unfounded” or “excessive” requests. In this context, it is clearly established that automated and blanket fee policies are not compliant with data protection legislation. In line with this decision, it is of critical importance for data controllers to manage data subject requests through multiple channels, simplify the request processes, and, in particular, avoid practices that could hinder the exercise of the right of access.

THE MONTH’S GRC CONCEPT

Data Protection Impact Assessment (DPIA)

A DPIA is a systematic assessment process conducted to identify potential risks and determine necessary measures in situations where personal data processing activities are likely to have significant impacts on the rights and freedoms of data subjects.

Within this process, the scope, purpose, methods used, and potential impacts on data subjects are considered together; appropriate technical and organizational measures are identified to mitigate potential risks. In this regard, DPIA serves as a comprehensive risk management tool that ensures data processing activities are evaluated not only for their legal basis but also in terms of necessity and proportionality.

Particularly in areas such as artificial intelligence systems, big data analytics, profiling activities, and biometric data processing—where the scope and impact of data processing activities have expanded—the effective implementation of DPIA processes is of critical importance. Such activities can give rise not only to data security risks but also to broader impacts such as discrimination, lack of transparency, and loss of control over individuals.

In this regard, the DPIA serves as a concrete manifestation of the “data protection by design” approach, enabling data controllers to anticipate risks and develop proactive measures against them before implementing data processing activities. We believe that the common DPIA templates developed by European data protection authorities also contribute to conducting this process in a more systematic, consistent, and auditable manner.