- March 10, 2026
GRC PERSPECTIVE: DATA PROTECTION & COMPLIANCE NEWSLETTER – FEBRUARY 2026
Contents
ToggleWHAT’S HAPPENING IN TURKEY?
Ex Officio Investigation by the Authority into Digital Platforms and Artificial Intelligence Systems
The Personal Data Protection Authority (“Authority”) announced in three separate public notices published in February that it had launched ex officio investigations into artificial intelligence systems, voice assistant applications and social media platforms.
Ex Officio Investigation Regarding the GROK Artificial Intelligence Assistant
Following allegations that the artificial intelligence platform named Grok, developed by
X.AI Corporation, was used to produce sexually explicit images and videos—including those involving children—without the consent of the individuals concerned, and that such content was circulated, the European Commission has launched an investigation. In light of these developments, the Board has decided to initiate an ex officio investigation into X Internet Unlimited Company and X.AI Corporation on the grounds that the necessary technical and administrative measures under the Law on the Protection of Personal Data No. 6698 (“KVKK” or “the Law”) were not taken during the development and implementation of the aforementioned platform, and that personal data was processed in breach of the law.
Ex Officio Investigation Regarding Google Assistant
Following reports that Google’s voice assistant service, Google Assistant, which is supposed to activate only upon specific trigger phrases (“Hey Google/Ok Google”), had inadvertently recorded users’ private conversations due to false triggers and that this data was used for different purposes, it was announced that an ex officio investigation has also been initiated against Google LLC. Within this scope, the Board will assess whether the technical and administrative measures required under the KVKK have been implemented.
Investigation into Children’s Use of Social Media and Platforms
The Board has also initiated an ex officio investigation into TikTok, Instagram, Facebook, YouTube, X and Discord regarding the protection of children’s personal data in the context of their social media use; specifically, concerning the risks children may face in the digital environment and the data processing practices of these platforms. It has been stated that the investigation will be conducted with due regard to the best interests of the child, focusing on data processing procedures and the technical and administrative measures taken.
GRC LEGAL PERSPECTIVE
The protection of children’s personal data is a matter at the heart not only of data protection law but also of children’s rights law and public policy. In an era where digital platforms are used extensively by children, issues such as the protection of privacy, the validity of consent mechanisms, profiling activities and behavioural targeting must be assessed specifically within the framework of the principle of the best interests of the child. In this context, the ex officio investigations launched against social media platforms and artificial intelligence systems, as announced in public statements in February, appear to reflect an increasing regulatory response aimed at protecting children in the digital environment.
Indeed, it can be argued that this approach aligns with the objective of “Developing Protective and Preventive Mechanisms” envisaged under the 2026–2030 Action Plan for Empowering Children in the Digital World.
The Board’s decision to focus its scrutiny on the most frequently visited social media platforms and artificial intelligence applications indicates a more proactive approach to oversight regarding the content risks to which children may be exposed, data processing practices, and the adequacy of technical and administrative measures.
On the other hand, deepfake content, unauthorised image generation and manipulative digital content—which have emerged alongside the development of artificial intelligence technologies—are of a nature that could lead to far more serious consequences for children. Such risks must be assessed not only in terms of the unlawful processing of personal data but also with regard to the child’s dignity, safety and psychological well-being. Consequently, the protection of privacy and the assurance of data security have become fundamental elements in safeguarding children’s presence in the digital world.
In our view, the Board’s recent active and thematic review approach indicates that Turkey’s data protection regime has entered a period of stricter oversight, particularly regarding children’s data and artificial intelligence applications. In this context, the need for digital platform providers and artificial intelligence developers to reassess mechanisms such as child-focused design, data minimisation, age verification and content moderation is growing in importance, not only in terms of regulatory compliance but also from the perspective of corporate responsibility.
New Document from the Authority: Risks Associated with QR Codes – Quishing
The Authority has published an information document titled “Risks Associated with QR Codes: Quishing”. The document provides a detailed examination of quishing, a phishing method carried out via QR codes.
QR codes are widely used in many areas of daily life, ranging from accessing restaurant menus and making payments to redirecting users to websites and providing promotional and informational content. This widespread use, combined with the ability to scan them quickly via mobile devices, creates a new avenue for attack by malicious individuals.
“Quishing” refers to the practice of redirecting users to malicious websites via fake or tampered QR codes. Through this method, individuals may be redirected to fake login pages, persuaded to share their identity and payment details, or encouraged to download malicious software onto their devices.
The document specifically highlights the risks associated with dynamic QR codes. These codes, where the redirect address can be updated without altering the visual structure, allow a QR code that initially appears trustworthy to subsequently redirect users to malicious content. It is emphasised that quishing attacks can be carried out both in physical environments (posters, leaflets, public spaces) and via digital communication channels (email, text messages, social media), and are often supported by messages designed to evoke a sense of urgency, panic or curiosity.
The Board states that the website address to which one is redirected after scanning a QR code should be carefully examined, the domain name verified, and caution exercised regarding pages requesting personal data. Furthermore, the document highlights the importance of basic security measures such as being vigilant against unexpected file downloads, using strong passwords, and, where possible, employing multi-factor authentication. The document demonstrates that whilst QR codes are a practical tool, their unconscious use can pose serious risks to personal data security.
Principle Decision on the Use of Telephone Numbers on Loyalty Cards by Third Parties
The Personal Data Protection Board’s “Principle Decision No. 2026/266”, published in the Official Gazette on 28 February 2026, addresses the use of a person’s mobile phone number or loyalty card number by third parties during shopping transactions where the individual holds a loyalty card membership.
The decision relates to practices such as transactions being carried out, points being earned, or a purchase record being created in the name of the relevant individual, even though the individual is not present at the till, by means of a third party providing their mobile phone number or loyalty card number. In this context, it has been stated that situations such as the issuance of an invoice, the creation of a transaction record, or the use of a membership account in the individual’s name without their knowledge or consent may constitute personal data breaches.
The Board has assessed that such data processing activities cannot be justified on the basis of any of the conditions for data processing set out in Article 5 of the KVKK. It has been stated that the execution of transactions by third parties using a telephone number or loyalty card number without the data subject’s explicit consent and without reliance on a legal ground for processing cannot be accepted as a lawful data processing activity under the Act.
In this context, the Board emphasised the need to establish verification mechanisms to prevent transactions from being carried out without the data subject’s knowledge or consent in the use of loyalty cards; it noted that technical and administrative measures, such as SMS verification, approval via a mobile application or similar secure methods, must be implemented. In accordance with the Principle Decision, data controllers have been granted a six-month period to complete the necessary compliance work in this regard.
GRC LEGAL PERSPECTIVE
The document published regarding QR codes demonstrates that the Board places emphasis not only on post-breach intervention but also on fostering a culture of preventive awareness and cyber hygiene. The fact that QR codes exist at the intersection of physical and digital environments gives rise to risks that are distinct from and less visible than traditional phishing methods. Consequently, for organisations, data security strategies must encompass not only technical security measures but also employee and customer awareness, verification practices, and secure usage guidelines.
The Decision on Loyalty Cards, however, addresses the matter directly within the framework of the legal basis for data processing activities and data security. The Board’s approach treats transactions carried out by third parties using a telephone number or loyalty card number not merely as a security vulnerability, but directly within the context of the legal conditions for lawful data processing. The creation of a transaction record or the issuance of an invoice in a person’s name without their knowledge or consent results in the data processing activity not being able to be based on any of the conditions set out in Article 5 of the KVKK.
Furthermore, the decision clarifies the data controller’s obligation under Article 12 of the Law to prevent the unlawful processing of and access to personal data. A system design that facilitates transactions by third parties is assessed in terms of the adequacy of technical and organisational measures. In this context, the absence of verification mechanisms could result in the data security obligation not being fulfilled as required.
Consequently, the Principle Decision does not concern loyalty programmes themselves; rather, it establishes that the data processing procedures carried out within the scope of these programmes must be structured in accordance with the data security obligation set out in Article 12 of the KVKK. The six-month period granted by the Board to data controllers for compliance constitutes a critical transition period, particularly for chain businesses with extensive customer networks, in terms of technical transformation and process revision. At the end of this period, the risk of inspection and sanctions is likely to increase for systems where verification mechanisms have not been established.
Important Ruling from the Constitutional Court on Personal Data and Freedom of the Press
In its decision dated 16 September 2025, Individual Application No. 2022/58084, the Constitutional Court examined an appeal against an administrative fine imposed by the Authority on an online news site under the Personal Data Protection Law (KVKK). The Court ruled that freedom of expression and press freedom had not been violated in the specific case.
The background to the case was as follows: in a news article published on an online news site regarding university placement results, a student’s examination result certificate was included; the certificate clearly disclosed the student’s full name, photograph, the university and programme they had been placed in, and their placement score. Following a complaint by the individual concerned, the Personal Data Protection Authority imposed an administrative fine of 30,000 TL; the objections lodged were rejected by the Magistrates’ Courts, and the matter was referred to the Constitutional Court via an individual application.
The applicant argued that the publication should be assessed within the scope of press and freedom of expression, that certain sections of the document had been redacted, and that the content had already been published on another website. In response, the Institution stated that the individual’s data had not been made public by the individual themselves; that personal data had been obtained and published in breach of the law; and that the news item had not been removed immediately despite the individual’s request.
The Constitutional Court assessed that, whilst the news article concerned a student’s academic achievement, it did not make a meaningful contribution to public debate. Furthermore, it was determined that the explicit publication of the individual’s name, surname, photograph, university and marks was not necessary, and that no sufficient justification had been provided for the sharing of this data.
Whilst acknowledging that there had been an interference with freedom of expression, the Court concluded that the administrative fine imposed was based on a legitimate aim, necessary and proportionate; it ruled that freedom of expression and press freedom had not been violated. The decision is considered to constitute an important precedent regarding the balance that must be struck between the right to the protection of personal data and press freedom.
You can access the Board decision referred to in this ruling here.
WHAT’S HAPPENING AROUND THE WORLD?
Warning from the Italian Data Protection Authority to Employers: Vehicle Tracking Found to Be Illegal!
The Italian Data Protection Authority has ruled that an employer’s monitoring of employees’ driving behaviour via a satellite-based telematics system installed in company vehicles is unlawful, ordering the deletion of the collected data and the imposition of an administrative fine of €120,000.
In this specific case, it was established that Pioneer Hi-Bred Italia had monitored its employees’ driving data via telematics devices installed in its vehicles; however, the information notice provided to employees did not clearly specify the data controller, data recipients, processing purposes and legal basis, and therefore failed to provide transparent and comprehensive information. Following an investigation initiated upon a staff member’s complaint, it was established that whilst the company had based its data processing activities on the legal ground of legitimate interests, it had failed to carry out the necessary balancing test between the fundamental rights and freedoms of staff and the company’s interests, and had not conducted a sufficient Data Protection Impact Assessment (DPIA).
Furthermore, it was assessed that employees’ data was shared with managers and administrative staff at group companies without any data processing agreement or written instructions; this was deemed to be in breach of Articles 6 and 28 of the General Data Protection Regulation (“GDPR”). Furthermore, it was concluded that the retention of driving data for 13 months was inconsistent with the principles of purpose limitation and data minimisation.
On these grounds, the Authority ruled that the data processing was unlawful and ordered the deletion of all data collected via telematics systems, as well as the imposition of an administrative fine of €120,000 on the company.
Sharing a Resignation Message in a WhatsApp Group: Warning from the DPA to the Employer
The Belgian data protection authority launched an investigation into an employer after a manager shared an employee’s resignation message in a workplace WhatsApp group and issued a warning decision to the data controller.
In this specific case, an employee (a student) had informed their manager of their resignation via WhatsApp; however, the manager shared screenshots of this exchange in a workplace-related WhatsApp group. The screenshots clearly displayed the employee’s name and the content of the exchange. The individual concerned lodged a complaint with the authority, stating that they had not given any consent for the sharing in question.
The Authority noted that the person who shared the screenshot was an employee of the data controller and that, pursuant to Article 29 of the GDPR, data processing activities carried out by employees are, as a rule, deemed to have taken place under the authority and supervision of the data controller. Consequently, it was stated that the manager’s action could not be assessed independently of the data controller.
During the investigation, it was found that although the data controller claimed to have taken the necessary technical and organisational measures, the sharing in question did not rely on a valid legal basis for processing under Article 6(1) of the GDPR. Furthermore, the authority assessed that the data controller was at risk in terms of its accountability obligation (Article 5(2)) and its obligation to implement appropriate technical and organisational measures (Article 24(1)).
On these grounds, a formal warning decision was issued to the data controller to ensure compliance with Articles 5(2) and 24(1) of the GDPR in the future.
GRC LEGAL PERSPECTIVE
When both decisions are considered together, it is evident that the boundaries of the “corporate control sphere” in data processing activities concerning employees are interpreted quite broadly. Whether regarding telematics vehicle tracking systems or sharing via WhatsApp, employees’ actions were not assessed independently of the data controller but were addressed directly within the scope of the company’s organisational responsibility.
Particularly in cases where the legitimate interest basis is invoked, the failure to conduct the balancing test in a concrete and documentable manner presents a significant compliance risk. Furthermore, it is clear that “routine practices” in areas such as data retention periods, transfers between group companies, and the control of internal communication channels are not defensible under data protection legislation.
In our view, these decisions demonstrate that employers must not merely content themselves with publishing policies; they must establish an active data governance and audit mechanism that encompasses daily operational practices such as internal communication tools, location systems and messaging groups. The principle of accountability is no longer an abstract principle; it has evolved into a concrete expectation of organisational control.
At this point, it should not be forgotten that the decisions of the European Union’s data protection authorities, although not directly binding, serve as an important reference for the Turkish data protection regime in terms of application practice and interpretation methods. In particular, it is assessed that the approach outlined regarding accountability, the limits of legitimate interest, and the adequacy of technical and organisational measures provides a guiding framework for the practices of the Personal Data Protection Authority.
The “Omnibus” Debate in the EU: Joint Opinion from the EDPB and EDPS
The draft AI Digital Omnibus Regulation (2025/0359/EU) prepared by the European Commission (“Draft”) is a package of amendments aimed at simplifying certain obligations introduced under the European Union’s Artificial Intelligence Regulation (“AI Act”) and other key regulations such as the GDPR and NIS2, and at reducing the administrative burdens arising in practice.
Known as the “Omnibus”, the draft envisages simultaneous amendments to various provisions of the AI Act; it specifically aims to introduce regulations in areas such as high-risk systems, record-keeping obligations, supervisory powers, AI literacy and the implementation timetable.
In relation to this draft, Joint Opinion 1/2026, adopted by the European Data Protection Board (“EDPB”) and the European Data Protection Supervisor (“EDPS”), highlights the most critical risk areas from a data protection perspective.
Whilst both bodies support the draft’s overall aim of simplification, they have issued significant warnings that certain amendments could weaken the protection of fundamental rights and create legal uncertainty.
1- Processing of Special Categories of Data for the Purpose of Detecting and Correcting Bias
The draft expands the legal basis for the processing of special category data for the purpose of detecting and addressing discrimination. Whilst the EDPB and EDPS support this expansion in principle, they state that it should be limited to ‘strictly necessary’ cases and that a clearer framework must be established in relation to Articles 6 and 9 of the GDPR.
2- Registration Obligation for High-Risk Systems
It is proposed that the obligation for certain providers to register with the EU database be removed. The opinion states that this change could reduce accountability and lead to the exception being interpreted too broadly.
3- Extension of Privileges Granted to SMEs to Mid-Sized Companies
The draft proposes that certain administrative simplifications granted to small and medium-sized enterprises (SMEs) should also be extended to medium-sized (small mid-cap) companies that exceed the SME threshold. The EDPB and EDPS caution that company size alone is not directly proportional to potential risk.
4- AI Regulatory Sandboxes at EU Level
The draft envisages an AI regulatory sandbox mechanism at EU level, in addition to national-level sandboxes. Whilst the EDPB and EDPS welcome this approach in principle, they note that certain structural gaps must be addressed to ensure legal certainty.
5- AI Literacy Obligation
It is proposed that the AI literacy obligation for providers and deployers regarding their employees be removed. The opinion argues that this obligation should be retained.
6- Timetable Change for High-Risk Systems and Transparency Obligations
The draft proposes postponing the entry into force of obligations relating to high-risk AI systems by up to 16 months. Whilst the EDPB and EDPS acknowledge the practical challenges of implementation, they warn that this postponement could result in more systems falling outside the scope of the AI Act, thereby posing a risk of weakening the protection of fundamental rights and creating legal uncertainty.
GRC LEGAL PERSPECTIVE
The AI Digital Omnibus draft constitutes a simplification package aimed at reducing companies’ compliance costs and the administrative challenges they face during implementation. It seeks to alleviate the operational burden of the regulation by providing flexibility in areas such as high-risk systems, registration obligations and the implementation timetable.
The joint opinion, however, draws particular attention to the potential impact of easing these obligations on fundamental rights. Whilst acknowledging the legitimacy of the simplification objective, the opinion emphasises that accountability, legal certainty and data protection standards must not be undermined.
Furthermore, within the scope of the cybersecurity package announced by the European Commission on 20 January 2026, significant changes are also envisaged under the NIS2 (“Network and Information Security”) Directive and the Cybersecurity Act. In particular, when interpreted alongside the Omnibus developments, new regulations concerning critical infrastructure, supply chain security and certification mechanisms indicate that the EU is moving towards restructuring its cyber resilience and data governance architecture.
From Turkey’s perspective, these developments should also be closely monitored. Whilst secondary legislation is expected to be finalised within a year following the entry into force of Law No. 7545 on Cybersecurity in March 2025, the fact that the European Union is undertaking comprehensive revisions to its regulatory framework—which serves as a model—demonstrates that the regulatory framework remains dynamic and evolving.
A New Era for Critical Infrastructure in Switzerland
On 18 February 2026, the Swiss Federal Council announced the launch of a new legislative process aimed at enhancing the resilience and data security of the country’s critical infrastructure.
The proposed regulations will:
- Introduce binding resilience and reliability standards for critical infrastructure operators,
- Clarify the obligations regarding the protection of security-critical digital data held by the federal government, cantons and critical infrastructure operators,
- Address existing sectoral gaps to create a more comprehensive cybersecurity framework.
The regulation, which covers key sectors essential to the functioning of society such as electricity, healthcare and telecommunications, is planned to be drafted in the form of two separate bills by the end of 2026.
GRC CONCEPT OF THE MONTH
Shadow Data
Shadow data refers to any data created, stored or shared outside the centralised and secure data management framework. In an organisational context, it refers to data sets that are not included in the official data inventory, record systems or under the direct control of IT, but are actually produced by employees/departments or via third-party tools and are scattered across different environments as we see here.
Shadow Data can arise as a result of employees transferring data for convenience onto personal devices, into cloud storage without security measures, or within overlooked tables in a database.
- Processing activities not included in the data inventory (loss of visibility)
- Files outside retention and disposal controls
- Third-party platforms vulnerable to unauthorised access and cyberattacks
- Inability to rapidly identify the scope and impact of a data breach (increased response time/costs)
This is not merely a cybersecurity issue; it is also directly linked to accountability and the obligation to implement data security measures under data protection legislation.
For these reasons, it is of critical importance for companies to make their data flows visible not only at the policy and contractual level but also in terms of actual implementation. In this context;
- The creation and regular review of an up-to-date and dynamic data inventory,
- The periodic review of access permissions and the actual implementation of retention and disposal processes
are among the fundamental steps for mitigating the risk of shadow data.