- February 10, 2026
GRC PERSPECTIVE: DATA PROTECTION & COMPLIANCE NEWSLETTER – JANUARY 2026
Contents
ToggleWHAT’S HAPPENING IN TURKEY?
Data Breach Notifications
Köfteci Yusuf Ready Meals, Cleaning, Live Animals, Meat Products, Integrated Food Import-Export Industry and Trade Inc. reported a data breach to the Personal Data Protection Board (“Board”); occurred as a result of an external intervention into the local SQL database hosting payroll software and online food ordering systems, leading to the encryption of the systems and the blocking of access. The breach affected employees and customers; a total of approximately 163,000 people, comprising 13,000 employees and 150,000 customers, were affected by the breach. The affected data includes customers’ identification, contact and order details, as well as employees’ identification, contact and personnel records.
Codeway Digital Services Limited reported the data breach to the Authority; it occurred between 15 January 2026 and 20 01.2026 and was detected on 20.01.2026. It occurred due to a vulnerability in the authorisation configuration of the Google Firebase (Firestore and Storage) infrastructure used in the “Chat & Ask AI” mobile application, which allowed attackers to gain unauthorised access to user data and the file repository. Application users were affected by the breach, with an estimated 3,700 individuals impacted; efforts to determine the exact number of affected individuals are ongoing. It has been reported that the breach involved users’ email addresses, usernames selected during registration, and post content shared during the use of the application.
The data breach reported to the Board by Özbeyler Health and Private Hospital Medical Import Export Industry and Trade Inc. occurred on 20 January 2026 and was detected on the same day; it resulted from a ransomware attack that blocked access to servers within the virtualisation infrastructure and encrypted system files. The breach has affected a large number of relevant groups, including employees, students, patients, customers and potential customers, although the exact number of affected individuals has not yet been determined. Data categories include identity, contact, personnel, physical premises security, transaction security, finance, professional experience, and visual and audio records, as well as health information falling under the scope of special category personal data, biometric data, race and ethnic origin, religion, denomination and other beliefs, philosophical beliefs, dress and attire, sexual life, criminal convictions and data relating to security measures; as well as titles, signature details, number and ages of children, marital status, military status and travel information may have been affected by the breach.
The data breach reported to the Board by Docplanner Technology Inc.; commenced on 08 January 2026 and was detected on 15 January 2026, and occurred through unauthorised access to files within the code base of software developed by the data processor to support internal communication and certain human resources functions, as well as to the scripts of the text editor, thereby altering the operation of the application. Although it has not yet been confirmed whether actual access was gained to personal data stored on the data controller’s systems or whether any operations such as copying were performed on this data, it is assessed that data confidentiality may have been breached. The breach has affected employees and former employees, with 525 individuals reported to have been affected. It has been stated that identity data (first name, surname) and contact details (email address and telephone number) may have been compromised.
The data breach reported to the Board by Erciyes University began on 26 December 2025 and was detected on 5 January 2026; it occurred through the unauthorised access and publication of personal data belonging to the data subjects on a website not belonging to the data controller. It was reported that the breach was detected whilst the current software contract used for managing the university’s access control systems was nearing its end and preliminary investigations were being conducted regarding the tender process for the new term. In the notification submitted to the Board, it was stated that definitive findings regarding the groups of data subjects affected by the breach, the number of affected individuals, and the types of personal data involved had not yet been provided, and that investigations into these matters were ongoing.
The data breach reported to the Board by Eurail B.V. occurred as a result of a cyberattack on the data controller’s systems, commencing on 26 December 2025 and being detected on 5 January 2026. The breach affected customers who purchased train tickets, and it was reported that 8,823 individuals residing in Turkey were affected by the breach. The scope of the breach included: identity data (name, surname, gender, date of birth and/or age, passport number, country of issue and expiry date) as well as contact details (address and place of residence, email address, telephone number) and customer transaction data (country, city, travel dates and times relating to train journeys) were affected; it was stated that technical investigations and further inquiries into the incident are ongoing.
Public Announcement Regarding the Application of Exemptions from the Obligation to Register with VERBİS
As is known, pursuant to Article 16 of the Law No. 6698 on the Protection of Personal Data (“KVKK” or “ Law”) requires natural and legal persons processing personal data to register with the Data Controllers’ Registry Information System (“VERBİS”) prior to commencing data processing; however, exceptions to this obligation may be granted within the framework of objective criteria determined by the Board. In this context, by virtue of the Board’s Decision No. 2025/1572 dated 4 September 2025, the exemption provisions previously set out in Decision No. 2018/87 have been updated; and it has been re-established that data controllers of a certain scale, based on the criteria of annual number of employees and total annual financial balance sheet, shall be exempt from the obligation to register with VERBİS. However, in practice, uncertainties have arisen regarding how the “total annual financial balance sheet” criterion should be assessed, particularly for data controllers who do not maintain accounts on a balance sheet basis.
Following an assessment of these uncertainties, clarity has been provided through the Board’s Decision No. 2025/2393 dated 25 December 2025. Accordingly, it has been announced to the public that, for data controllers maintaining accounts on a balance sheet basis, both the annual number of employees and the annual financial balance sheet total criteria will be taken into account cumulatively when determining the VERBIS exemption; whereas, for data controllers not maintaining accounts on a balance sheet basis, as information on the annual financial balance sheet total is not available, only the annual number of employees criterion will be applied.
GRC LEGAL COMMENT
The clarification of the exemption criteria regarding the VERBİS registration obligation based on accounting methods is considered a prudent step, particularly in resolving uncertainties experienced in practice by small-scale businesses and data controllers who do not maintain accounts on a balance sheet basis.
However, benefiting from the VERBIS exemption does not imply that data controllers are exempt from other obligations under the KVKK; it is essential that the fundamental obligations, such as data security and the duty to provide information, continue to apply in practice.
Public Announcement Regarding Push Notifications Sent via Mobile Applications
In the case addressed in the public announcement dated 14 January 2026, it was determined that the push notification consent obtained from users during the installation of a mobile application was structured as a single consent covering multiple data processing purposes. The investigation revealed that operational notifications directly linked to the provision of the service, such as order status updates, were combined with marketing notifications containing campaign and advertising content under the same consent mechanism; consequently, users were compelled to accept marketing-related notifications in order to access a basic service such as order tracking.
In the assessment conducted by the Board, it was reiterated that for explicit consent to be valid, it must be expressed freely, based on information provided, and relate to a specific matter. It was emphasised that making the provision of a service conditional upon consent to another data processing purpose not directly linked to that service eliminates the element of free will in explicit consent; this situation is incompatible with the principle of ‘granularity’ in data protection law.
The notice also highlighted that these legal requirements must be supported not only at the textual level but also through the technical architecture of the application. It was stated that failing to provide users with the opportunity to choose which types of notifications they wish to receive via in-app settings or device settings undermines the data subject’s right to control their personal data.
GRC LEGAL COMMENT
In services provided via mobile applications, the distinction between operational notifications and marketing-related notifications is of critical importance not only from the perspective of user experience but also regarding the validity of explicit consent. The Board’s announcement once again highlights the need to consider legal principles alongside technical implementation when designing explicit consent mechanisms. In this context, it is assessed that mobile application providers’ review of their notification approval processes and application architectures in line with the principles of ‘segmented explicit consent’ and ‘free will’ remains important for mitigating compliance risks.
60-Day Time Limit for Data Breach Notifications under the KVKK
In the public announcement published by the Board on 20 January 2026; it was reiterated that, in the event that personal data processed is obtained by others through unlawful means, the data controller is obliged to notify the data subject and the Board of this situation as soon as possible. It was stated that the primary purpose of this obligation is to prevent or minimise, as soon as possible, any adverse consequences that may arise for data subjects as a result of a data breach. The notice further stated that when deciding whether to publish data breach notifications on the Authority’s website, criteria such as the groups of data subjects affected and the number of individuals, the nature and scope of the personal data affected, the manner in which the breach occurred, the sector in which the data controller operates, and whether notifications have been made to the data subjects are taken into account.
In this context, by virtue of the Board’s Decision No. 2025/2451 dated 25 December 2025, the practice of publishing data breach notifications on the Authority’s website without a time limit has been discontinued; it has been decided that such notifications shall be published for a maximum period of 60 days. Furthermore, it has been announced to the public that, where the data controller can demonstrate that affected individuals have been notified of the breach, the publication period may be shorter than 60 days.
GRC LEGAL COMMENTARY
The Board’s current approach to data breach notifications establishes a balanced assessment framework that does not view data controllers’ obligations as limited solely to the act of notification; rather, it focuses on the timing, scope, and whether the notification was directed to the relevant individuals. It is understood that the Board’s imposition of a 60-day time limit on data breach notifications, as a reflection of this approach, aims to balance the potential long-term reputational impacts on data controllers with the objective of ensuring that affected individuals are informed in a timely manner, whilst ensuring that breach notifications remain accessible indefinitely.
In this context, it is considered that data controllers should not limit their breach management processes solely to notifications to the Board; rather, they must establish an effective breach response mechanism that includes timely, clear and verifiable notifications to data subjects affected by the breach.
Public Announcement Regarding the Use of Overseas Communication Applications in Public Institutions
In the public announcement published by the Personal Data Protection Authority on 29 January 2026, explicit reference was made to the Presidential Decree No. 2019/12 dated 6 July 2019 (Measures for Information and Communication Security); the provision in Article 4 of the aforementioned Decree “With the exception of domestic mobile applications developed by institutions authorised by legislation to conduct encrypted or coded communication, the sharing of classified data and communication via mobile applications shall not be permitted.” and the provision in Article 6: “The use of domestic applications for social media and communication platforms shall be preferred.”
In this context, it has been specifically emphasised that the sharing of classified or critically important official data via foreign-origin communication applications such as WhatsApp is inappropriate, particularly given the absence of a data centre within the country.
The announcement further states that the mobile phone numbers of individuals whose personal data is processed are also considered personal data, and that communication and data processing activities conducted by public institutions via WhatsApp and similar applications using mobile phone numbers belonging to public sector employees must be assessed as personal data processing activities. It was emphasised that should such activities fail to comply with the processing conditions set out in Articles 5 and 6 of the Personal Data Protection Law No. 6698, they may be subject to investigation by the Board either on its own initiative or following a complaint; furthermore, public officials found to be liable may be subject to administrative sanctions in accordance with Article 18(4) of the Personal Data Protection Law.
GRC LEGAL COMMENTARY
The assessments contained in the public announcement reflect the approach that cybersecurity is not merely a technical or administrative matter, but must be treated as an integral part of national security. Indeed, in line with this principle explicitly adopted in the Cyber Security Law No. 7545, the restrictions imposed on the use of foreign-origin communication applications within public institutions are assessed as a natural consequence of addressing cyber security through the prism of national security.
WHAT’S HAPPENING AROUND THE WORLD?
Failure to Close an Ex-Employee’s Email Account Found to Be in Breach of the GDPR!
In a decision published by the Belgian Data Protection Authority on 06.01.2026, it was ruled that keeping corporate email accounts belonging to a former employee active for an extended period constitutes a breach of the General Data Protection Regulation (“GDPR”).
In the case in question, the data subject discovered approximately two years after leaving the company that two corporate email addresses belonging to them had not been closed and were still active. Consequently, they requested access to the email accounts and demanded the deletion of their personal data stored therein. However, the former employer rejected both the former employee’s request for access and the request for deletion, arguing that keeping the email accounts active constituted a legitimate interest in terms of the technical operation of the company’s email infrastructure. Following the data subject’s complaint, the matter was investigated by the Belgian Data Protection Authority.
In the assessment, it was accepted that keeping email addresses active for a reasonable period following termination of employment could be considered a legitimate interest aimed at ensuring the continuity of the company’s operations. However, it was noted that continuing to keep email accounts active despite a significant period of time having elapsed could not be justified on the grounds of legitimate interest; the data processing had lost its characteristics of being relevant, limited and proportionate to the purpose. Furthermore, it was emphasised that the continued existence of email addresses and the technical maintenance of active accounts constituted, in itself, a personal data processing activity.
In this context, the authority ruled that the employer’s continued processing of personal data by keeping the email accounts open constitutes a breach of GDPR Article 5(1)(a) (lawfulness and fairness) and Article 6(1)(f) (legitimate interest); it also ruled that Article 15 and Article 17(1) due to the failure to delete personal data. A reprimand sanction was imposed on the company under the GDPR.
EU Prepares to Grant the US Access to Biometric Data
According to a report on Euractiv, European Union (“EU”) countries are preparing to allow US authorities access to national databases containing biometric data, such as fingerprints and facial scans, in exchange for the continuation of the visa-free travel regime for US citizens. It is noted that Washington’s request in this regard was first raised in 2022, and the process is referred to by the US as the Enhanced Border Security Partnerships (“EBSP”).
In this context, it is envisaged that the European Commission will lead “framework” negotiations with the US within 2026; following the establishment of this framework, which sets out general principles, member states are expected to negotiate bilateral agreements with the US. It is stated that Denmark and Ireland will remain outside this framework due to the exceptions in the EU treaties and their Schengen membership status.
It is planned that the EU-level framework agreement will broadly define the types of databases and data categories to which the US will have access; however, which national databases and which individuals’ data will be shared is to be decided separately by each member state. According to the report, EU capitals have generally reached an agreement on granting the Commission negotiating authority.
Documents outlining the Commission’s negotiating position state that data on ethnic origin, political opinions, religious beliefs, as well as genetic and biometric data, may fall within the scope of sharing; however, such transfers may only be made for the purposes of combating crime and terrorism, provided they are necessary and proportionate. It is also stated that limitations on data retention periods and additional safeguards will apply.
Meanwhile, the European Data Protection Supervisor, Wojciech Wiewiórowski, has noted that the EBSP regulation will set an important precedent for large-scale transfers of personal data to third countries; he emphasised that data transfers should be limited solely to individuals travelling to the US and that the categories of data to be transferred must be defined in a clear and narrow manner. The report also notes that the US expects the data access provisions to be effectively implemented by the end of the year.
GRC LEGAL COMMENTARY
When the European Union’s legislative agenda on digital infrastructure is considered alongside the process involving the transfer of biometric data under the visa-free travel scheme to the US, a striking dichotomy emerges in EU–US relations regarding digital independence and data transfer. On the one hand, the Digital Infrastructure package presented by the European Commission aims to reduce the EU’s dependence on the US-centred technology ecosystem in terms of cloud services, semiconductors, networks and critical digital infrastructure; whilst on the other hand, the transfer of highly sensitive personal data, including biometric data, to US authorities is being discussed in exchange for the continuation of visa-free travel.
The fact that multiple new regulations—such as the Digital Networks Act, the Cloud and AI Development Act, the revision of the Chips Act, and the Quantum Act—have come to the fore simultaneously within the scope of digital infrastructure initiatives demonstrates that the EU is continuing a wave of intensive and comprehensive regulation in the digital sphere. These regulations, whilst focusing on topics such as supply chain security, certification, risks arising from third-country service providers, and digital independence, reveal that data security and infrastructure control are being addressed at the level of public policy.
Conversely, the possibility of granting the US access to biometric databases under the EBSP framework raises legal debates regarding international data transfers, the principle of purpose limitation and the principle of proportionality. Indeed, the fact that this transfer is of a large-scale and systematic nature raises the question of how it can be reconciled with the strict data transfer approach adopted by the European Union to date. In this regard, the cautious approach of data protection authorities, which advocates for the scope of the transfer to be kept narrow and restricted by robust safeguards, is noteworthy.
When these two developments are considered together, it becomes apparent that, whilst the EU is striving to enhance its strategic independence in the fields of digital infrastructure and technology, it is simultaneously compelled to strike exceptional and delicate balances regarding data sharing with the US due to geopolitical positioning and travel policies.
New Regulatory Proposals from the European Commission Regarding EU Cybersecurity Legislation
The European Commission (‘’Commission’’) has put forward recommendations to update existing provisions in EU legislation with the aim of strengthening the European Union’s cybersecurity capabilities in the face of growing cyber threats and risks to digital infrastructure. In this context, it is envisaged that the 2019 EU Cybersecurity Act (“Cybersecurity Act”), which establishes a common cybersecurity certification framework for digital products, services and processes across the EU, will be revised.
The proposals put forward by the Commission aim to achieve the following objectives:
- Enhancing the security of the EU’s information and communication technology supply chains: The aim is to reduce risks arising from third-country suppliers that raise cybersecurity concerns.
- Making security testing processes for digital products and services more effective: By clarifying the rules and simplifying the procedures within the European Cybersecurity Certification Framework, the aim is to ensure that digital products and services used by EU citizens undergo security testing more efficiently.
In addition to the revision of the Cybersecurity Act, it is noted that the measures proposed by the Commission include the following additional steps:
- Facilitating companies’ compliance with cybersecurity rules: The aim is to simplify rules relating to areas of competence and to harmonise data collection processes regarding ransomware attacks.
- Strengthening the European Union Agency for Cybersecurity (“ENISA”): The aim is for ENISA to provide more effective support to Member States in understanding common cyber threats, preparing for them, and responding to them.
China-Linked Hacker Group Hacked US Congressional Staff Email Systems!
According to a report in Reuters, a cyberattack group allegedly linked to China has gained unauthorised access to the email systems used by staff working in certain influential committees within the US House of Representatives. It is reported that the attack targeted staff working with committees within the US Congress that are particularly active in the fields of international relations, foreign policy, intelligence and the armed forces.
According to reports, the hacker group known as “Salt Typhoon” is said to have gained access to the email systems of staff working on the House China Committee, as well as some advisers working on the committees for foreign affairs, intelligence and the armed services. However, it has been stated that details regarding which staff members were directly targeted have not been shared with the public, and it remains unclear whether the attackers gained access to the emails of members of Congress.
The report also highlights that US lawmakers, and in particular Congress staff overseeing military and intelligence agencies, have long been among the primary targets of cyber espionage activities. In this context, it is recalled that similar allegations regarding cyber operations linked to various countries have surfaced in the public domain in previous years.
It is stated that the Salt Typhoon group has been closely monitored within US intelligence circles for some time; the group is alleged to be linked to Chinese intelligence and accused of targeting communication data belonging to high-ranking US politicians and public officials. Chinese authorities, however, systematically deny the allegations regarding these cyber espionage activities.
GRC LEGAL COMMENT
The recent allegations of cyberattacks targeting the US Congress demonstrate that cybersecurity is no longer merely a technical IT issue; it has become a field of critical importance for state institutions, democratic processes and corporate governance. In particular, the targeting of public authorities clearly highlights the strategic dimension of cyber threats.
In light of these developments, the European Union’s approach appears to focus on addressing cybersecurity within a stricter regulatory framework whilst ensuring compliance processes remain manageable. Steps such as the revision of the Cybersecurity Act and the strengthening of ENISA’s role aim to ensure that cybersecurity is addressed in a more coordinated and standardised manner across the EU.
On the other hand, the regulations on the Commission’s agenda, referred to as the ‘omnibus’ package, also reflect the objective of simplifying the heavy regulatory burden faced by companies. Clarifying jurisdictional rules, streamlining reporting and notification processes, and ensuring consistency in implementation are crucial to ensure that compliance is not merely a formality.
In this context, industry representatives also emphasise that cybersecurity regulations must be workable and predictable in practice. Indeed, in its assessment of the Cybersecurity Act revision, DIGITALEUROPE highlights the importance of positioning cybersecurity certification not as an additional burden for companies, but as a tool that facilitates compliance. Key expectations highlighted by the sector include the ability of certifications to establish a ‘presumption of conformity’ with EU legislation, the reduction of repetitive obligations, and the achievement of timing and governance alignment between the NIS2 (‘Network and Information Security’) Directive, the Cyber Resilience Act (‘CRA’), the GDPR and sector-specific regulations. This approach also reflects the delicate balance that must be struck between cybersecurity objectives and Europe’s competitive strength.
AI-Gents: Artificial Intelligence as a Personal Shopping Assistant
In a report published by the Information Commissioner’s Office (“ICO”) on 8 January 2026, it is assessed that the new generation of artificial intelligence systems, referred to as agentic AI, could significantly transform digital shopping practices in the coming years. According to the report, personal shopping assistants capable of making decisions on behalf of individuals and acting independently are expected to pave the way for a new era that could be defined as agentic commerce.
Agentic artificial intelligence refers to systems that are not limited to merely responding to user commands, but can anticipate shopping needs based on past preferences and behaviour, and make purchasing decisions on their own initiative. In this context, it is anticipated that personal AI agents will be able to assess whether a purchase falls within financial limits by monitoring the user’s bank account and budget status, schedule purchases by tracking seasonal discounts and promotional periods, and even negotiate prices directly with sellers.
In its assessment of the report, the ICO emphasises that whilst the potential benefits of such systems are significant, robust safeguards regarding the secure and lawful processing of personal data are required for the public to trust agentic artificial intelligence. In this context, it is stated that a robust legal framework based on data protection will be decisive in the safe widespread adoption of agentic artificial intelligence systems.
GRC LEGAL COMMENT
The structure of agentic artificial intelligence systems, which can make decisions on behalf of individuals and act proactively, significantly increases the scope and impact of personal data processing. Consequently, as highlighted by the ICO, trust in such systems is founded on the secure, proportionate and lawful processing of personal data; it is evident that data awareness and the avoidance of inadvertent data sharing are of critical importance for both individuals and the organisations developing and using AI systems.
CONCEPT OF THE MONTH: GRC
Granular Consent
Granular consent refers to the practice of granting the data subject the freedom to make separate choices for each specific purpose when personal data is processed for multiple purposes within the scope of a mobile application, website or service. In this regard, rather than grouping both notifications that are a natural part of the service (e.g. order/delivery process) and marketing-related notifications (campaigns/discounts) under a single consent, users should be given the option to consent to or refuse each purpose separately.
This approach also aligns with the fundamental risk highlighted in the Authority’s public announcement regarding push notifications in mobile applications. Combining operational notifications with marketing content under a single consent increases the risk of undermining the “free will” element of consent.
On the European Union side, the Guidelines 05/2020 on consent under Regulation 2016/679 state that where a service processes data for multiple purposes, individuals should not be forced into an “all-or-nothing” consent package; in appropriate cases, separating the purposes and obtaining separate consent for each is critical to the validity of consent.
The Guidelines provide an example where requesting consent for both email marketing and data sharing with group companies in the same consent text weakens the validity of the consent.