- February 2, 2026
Data Protection and Compliance Bulletin – December 2025
Contents
ToggleData Protection Law is a constantly evolving and updating area of law, governed by the Personal Data Protection Law No. 6698 (“KVKK” or “the Law”) and its secondary regulations. Practices in this field are not limited to the Law and related regulations; they are shaped and concretised by the decisions, principle decisions, and decision summaries of the Personal Data Protection Board (“Board”). In this context, the KVKK Bulletins, prepared on a monthly basis, serve as a resource for those wishing to follow current developments in the field of data protection, aiming to provide up-to-date information and keep stakeholders informed.
In December, the Personal Data Protection Authority (‘Authority’) published six data breach notifications and the ‘Policy Decision on Recording Photocopies of Turkish Identity Cards of Persons Receiving Accommodation Services in the Tourism and Hospitality Sector’ on its website, www.kvkk.gov.tr.
DATA BREACH NOTIFICATIONS
Pursuant to Article 12/5 of the KVKK, if personal data processed is obtained by third parties through unlawful means, the data controller is obliged to promptly notify the relevant person and the Board of this situation.
Within the framework of the aforementioned provision, the Board may, if it deems necessary, announce the data breach to the public via its website or by other methods it deems appropriate. This regulation has been introduced to ensure the effective management of data breaches and the timely notification of the relevant persons.
Beyçelik Holding A.Ş. and Group Companies
According to the notifications submitted to the Board by Beyçelik Holding A.Ş. and its group companies, which are data controllers, the breach occurred on 4 December 2025 as a result of ransomware being installed on the servers of Beyçelik Gestamp Otomotiv Sanayi A.Ş., one of the group companies, and the systems being encrypted.
According to the notification, due to the encryption of data on the servers affected by the attack, it is technically impossible at this stage to separate the categories of personal data; the groups of individuals affected by the breach and the number of individuals have not yet been identified, and investigations into the matter are ongoing.
Dem İlaç Sanayi ve Ticaret A.Ş.
In the notification submitted to the Board by Dem İlaç Sanayi ve Ticaret A.Ş., acting as the data controller, it was stated that the data controller was subjected to a ransomware attack on 07.12.2025. According to the notification, the cyber threat actor claims to have obtained approximately 1 TB of sensitive data.
Since it was stated that the threat actor had access to all systems, the categories of data affected by the breach are extensive. in this context, identity, communication, location, personal data, legal transactions, customer transactions, physical premises security, transaction security, risk management, finance, professional experience, marketing, visual and audio recordings, health information, criminal convictions and security measures data may also have been affected.
It was reported that employees, users, and customers/potential customers were affected by the breach, but the number of individuals affected has not yet been determined; investigations into the matter are ongoing within the data controller. It was also stated that individuals could obtain information via www.demilac.com.tr or the call centre.
In the notification submitted to the Board by DMR Otomotiv Kiralama Sanayi ve Ticaret Ltd. Şti., acting as the data controller, it was stated that the data controller was subjected to a ransomware attack on 7 December 2025, but that the breach essentially occurred at the group company Dem İlaç Sanayi ve Ticaret A.Ş.
In the incident, where it is alleged that the cyber threat actor obtained approximately 1 TB of sensitive data, the categories of data affected are extensive due to access being gained to all systems;
In this context, it was stated that identity, communication, location, personal information, legal transactions, customer transactions, physical location security, transaction security, risk management, finance, professional experience, marketing, visual and audio recordings, health information, criminal convictions and security measures data were affected. It was communicated to the Board that employees, users, and customers/potential customers were affected by the breach, that the number of affected individuals has not yet been determined, and that investigations are ongoing.
Balıkesir Uludağ Turizm Taş. İnş. Tic. Ltd. Şti.
In the notification submitted to the Board by Balıkesir Uludağ Tourism Transport Construction Trade Ltd. Co., which holds the status of data controller, it was stated that the breach occurred between 01.12.2025 – 05.12.2025 and was detected on 06.12.2025. According to the notification, the breach occurred as a result of a brute-force attack on the authorised user account on the portal management login page, which resulted in unauthorised access to the system; the attackers sent SMS messages to company managers informing them that they had obtained the data.
Although the data controller stated that the affected data consisted of identity and contact information, according to the attackers’ claim, the data included bus routes (departure/arrival bus stations, date, time), personal data of passengers on bus routes, SMS data logs, Turkish ID numbers, telephone numbers, first names, surnames, passwords and membership numbers of all members, job application logs, employee information and lost property data were also compromised.
It was reported to the Board that employees, subscribers/members and customers were affected by the breach; although the exact number of people affected is unknown, it is alleged that more than 10 million pieces of data were compromised by the attackers.
Uludağ Electricity Distribution Inc.
In the notification submitted to the Board by Uludağ Electricity Distribution Inc., acting as the data controller; the breach occurred on 05.08.2025 and on 18.08.2025, a data set containing the information of the company’s data controller subscribers was detected on a platform used by threat actors on the dark web for file sharing.
The data set in question contained 57 different data categories, including mostly technical data such as subscriber number, name and surname, partial address, consumption information, and meter information, as well as personal data. It was stated that the breach occurred when threat actors gained unlawful access to the system, which could be accessed with a password and SMS verification code.
It was reported to the Board that subscribers/members were affected by the breach, and although the exact number of individuals affected could not be determined, 899,890 queries were performed on the system. It was stated that the individuals concerned could contact dpo@uedas.com.tr to obtain information about the data breach.
GRC LEGAL Comment: When examining the data breaches reported to the Board in December, it is seen that cyber attacks were carried out using destructive methods (ransomware) that targeted not only the confidentiality of the data but also its accessibility, and that these attacks created a ‘chain reaction’ within the holding structures.
This scenario reaffirms that compliance with the Personal Data Protection Law is not merely a documentation process on paper, but rather an active risk management process. The ransomware attacks on Beyçelik Holding and Dem İlaç demonstrate that cyber threats expose data controllers not only to the risk of ‘data loss’ but also to the risk of ‘operational blindness’.
In particular, the inability to determine the number of individuals affected and the categories of data due to encryption highlights the need for companies to develop not only cyber attack prevention capabilities but also post-attack emergency response and forensic analysis capabilities.
The breach experienced by Dem Pharmaceuticals, which directly affected its group companies DMR Automotive and Pharmada Pharmaceuticals, highlights the risk posed by integrated IT infrastructures between group companies. This situation proves how critical it is to implement network segmentation between group companies and to separate authority matrices on a company basis in order to prevent the spread of the crisis.
The breaches experienced by Balıkesir Uludağ Turizm and Uludağ Elektrik Dağıtım A.Ş. contain complementary critical lessons regarding account security and threat tracking. The ‘brute force’ attack in the Balıkesir example highlights the necessity of Multi-Factor Authentication (MFA) systems on panels open to the outside world, while the Uludağ Elektrik example points to a sophisticated threat environment where even SMS-based authentication can be bypassed. In particular, the discovery of Uludağ Elektrik data on the Dark Web demonstrates that companies must address cyber security not only within their own internal systems but also through ‘Threat Intelligence’ mechanisms that monitor the cyber threat landscape.
Consequently, the December table clearly shows that data security is not merely a technical task to be delegated to an organisation’s IT department; rather, it is a holistic ‘Data Governance’ issue involving legal, management, and process owners. It is not sufficient for companies to simply establish technological barriers against cyber incidents; they must also simultaneously strengthen the legal basis for these barriers, employee awareness, and control mechanisms.
BOARD DECISION
Principle Decision No. 2025/2120 on Recording Photocopies of Turkish Identity Cards of Persons Receiving Accommodation Services in the Tourism and Hospitality Sector
The Principle Decision No. 2025/2120, dated 06.11.2025, published by the Board, introduces binding regulations regarding the practice of obtaining/scanning copies of identity documents, which is frequently resorted to in the tourism and hospitality sector on the grounds of ‘data security procedures’.
The Decision confirms that the processing of guests’ identity information (name, surname, Turkish ID number, etc.) for the purpose of reporting to law enforcement authorities in accordance with the Identity Reporting Law No. 1774 is lawful. However, it is emphasised that there is no legal basis for physically photocopying identity documents or scanning them using optical readers and recording them in the system, and that this practice violates the principle of ‘data minimisation’.
The Board ruled that data controllers must perform identity verification procedures by physically inspecting the document only; identity photocopies archived up to this date must be destroyed in accordance with Article 7 of the Law. It was stated that practices contrary to this would be subject to sanctions under Article 18 of the Law. For our detailed legal assessment on this matter, please click here
DEVELOPMENTS IN TURKEY
Decision No. 2025/458 K.
2025/536 and dated 25.09.2025; in the context of an inheritance case, the court ruled that the bank, which submitted more than the requested and current account movements to the file, was liable for moral damages in accordance with the provisions of the KVKK and the Turkish Civil Code regarding the protection of personality. In the case in question, the court requested the relevant persons’ account movements for the previous 10 years due to the inheritance case, but the bank exceeded the requested limits and also submitted the relevant persons’ current account movements to the file. When the data in question was leaked from the case file and published on a website, the plaintiffs sought non-pecuniary damages on the grounds that data constituting ‘customer confidentiality’ had been disclosed.
Although the court of first instance and the Regional Court of Appeal dismissed the case on the grounds that the bank’s action was ‘inadvertent’ and there was no intent, the Supreme Court of Appeals, considered the process from the perspective of the data controller’s responsibility; that banks are ‘trust institutions’ and are obliged to ensure data security in accordance with Article 12 of the KVKK, that the bank did not exercise due care in protecting sensitive information constituting customer confidentiality and personal data, and that the bank, in its capacity as data controller, violated its obligation to protect data and process it in accordance with the law.
In light of these findings by the Court of Cassation, the Istanbul Commercial Court of First Instance, complying with the reversal decision, deemed the submission of unsolicited data to the file as an infringement of personal rights and awarded moral damages totalling 100,000 TL, 50,000 TL for each of the natural person plaintiffs. On the other hand, in its assessment regarding the corporate plaintiffs, the court rejected the compensation claims of the corporations, citing that the scope of protection under the KVKK is limited to natural persons and that the relevant companies did not have the status of direct customers under the Banking Law.
GRC LEGAL Comment: This precedent-setting decision by the Court of Cassation clearly demonstrates that data controllers cannot compromise the principle of ‘data minimisation’ even when responding to requests from official authorities. In this context, companies must carefully analyse the scope of the requested data (date range, data type, etc.) when responding to court summonses or official correspondence and establish the discipline of ‘not sharing more than is necessary’ as a corporate procedure. Otherwise, even cooperation made in good faith can lead to serious compensation risks and loss of reputation.
Regulation on Personal Health Data Amendments
The amendment to the regulation published in the Official Gazette dated 3 December 2025 introduces fundamental innovations in the processing and access of personal data in the healthcare sector. The amendments redefine critical issues such as linking access to past health data to the processing conditions under Article 6/3 of the Personal Data Protection Law, the scope of physician access in emergencies, the limits of parental access to children’s data in cases of divorce, access to the data of individuals with disabilities by their carers, and extending the storage period of deceased persons’ health data to 30 years.
The regulation aims to establish a more transparent balance between the uninterrupted provision of healthcare services and data security, and to eliminate uncertainties in its application. For our detailed study on this subject, please click here.
GLOBAL DEVELOPMENTS
Digital Legislation Reform in the EU: ‘Digital Omnibus’ and Simplification Discussions [2]
The European Commission has presented the ‘Digital Omnibus’ proposal, which aims to revise the fundamental regulations in the digital field (the General Data Protection Regulation (“GDPR”), the Artificial Intelligence Act (‘AI Act’), and the Data Act (“Data Act”) under a single umbrella. While the proposal aims to facilitate compliance processes, particularly in technology and data-focused sectors, a group of Member States led by Germany, the Netherlands and Denmark within the Council of the EU considered the current proposal insufficient and argued that the regulations should be simplified much more comprehensively. The key proposed changes that have emerged at the negotiating table and are being debated in legal circles are as follows:
Relaxation of the Definition of Personal Data: It is proposed that the GDPR’s definition of ‘personal data’ (Article 4/1) be approached with a ‘relative’ rather than an absolute approach; if the party holding the data has no reasonable means of re-identifying the individual, that data should not be considered personal data for that organisation.
Legal Basis for Artificial Intelligence: The aim is to provide additional legal clarity to the GDPR so that companies can rely on the ‘legitimate interest’ processing condition instead of explicit consent in the training and development processes of artificial intelligence models.
Consolidation of Reporting Processes: In the event of a cybersecurity incident or data breach, it is planned to establish a common mechanism that will enable companies to report through a ‘single point of contact’ rather than having to report separately under different regulations such as the GDPR, NIS2 Directives (Network and Information Security Directives) and DORA (Digital Operations Resilience Act).
Extension of Compliance Deadlines: Extending the compliance deadlines for high-risk systems under the Artificial Intelligence Act (‘AI Act’) is another important item on the agenda.
GRC LEGAL Commentary: The European Union’s digital legislation reform efforts indicate that the balance between ‘current standards’ and ‘economic feasibility’ in data protection discipline is being reopened for discussion. In particular, proposals to approach the definition of personal data from a more ‘relative’ perspective and to establish the ‘legitimate interest’ condition in artificial intelligence processes on a legal basis have the potential to affect operational processes for data controllers and may alter the scope of legal assessments required in each specific case. This approach tends to transform regulatory compliance from a static set of rules into a dynamic process determined by impact analyses and balancing tests.
On the other hand, the initiative to consolidate notification obligations arising from different regulations such as GDPR, NIS2 and DORA stands out as a technical necessity in terms of eliminating duplication between regulations. While this model, which aims to simplify administrative processes, seeks to enable companies to allocate their resources directly to risk management rather than bureaucratic procedures, how authority sharing and coordination between different authorities will be achieved in practice will be decisive for the success of the regulation. The process can be said to be an important test of the extent to which the EU can relax its regulatory structure while maintaining its level of data protection.
[1] Beyçelik Holding AŞ, Bak Energy Production AŞ, Ber Energy Production AŞ, BEWEN Energy AŞ, Beyçelik Elawan Renewable Energy Production AŞ, Beyçelik Gestamp Automotive Industry AŞ, Beyçelik Gestamp Chassis Automotive Industry AŞ, Beyçelik Gestamp Technology and Mould Industry AŞ, Beyçelik Insurance Brokerage Services Inc., Çelikform Gestamp Automotive Inc., Gesbey Energy Turbine Tower Production Industry and Trade Inc., Gescrap Turkey Metal Industry and Trade Inc., Sabaş Electricity Production Inc., Warmhaus Heating and Cooling Systems Industry and Trade Inc., YGT Electricity Production Inc.
[2] https://www.euractiv.com/news/councils-simplification-hawks-smell-blood-on-ripping-up-tech-rules/ E.T. 23.12.2025
https://iapp.org/news/a/eu-digital-omnibus-analysis-of-key-changes E.T. 23.12.2025