- August 1, 2025
Data Protection and Compliance Bulletin – July 2025
Contents
TogglePersonal Data Protection Law, Law No. 6698 on the Protection of Personal Data (“KVKK”) and its secondary regulations constitute a constantly evolving and updated area of law. Practices in this field are not limited to the Law and related regulations; they are shaped and concretized by the decisions, principle decisions, and decision summaries of the Personal Data Protection Board (“Board”). In this context, the KVKK Bulletins, prepared on a monthly basis, serve as a resource for those who wish to follow current developments in the field of data protection, aiming to provide up-to-date information and keep stakeholders informed.
The protection of personal data is of great importance in terms of guaranteeing fundamental rights and freedoms. In this context, it is both an obligation and a requirement of the compliance process for data controllers to act in accordance with the law and the rules of good faith in all kinds of operations involving personal data.
In July 2025, the Personal Data Protection Authority (“Authority”) published three data breach notifications on its website, www.kvkk.gov.tr. In addition, the “Guide on Cookie Practices” published by the Board in June 2022 was updated in July 2025.
DATA BREACH NOTIFICATIONS
Pursuant to Article 12/5 of the KVKK, if personal data processed is obtained by third parties through unlawful means, the data controller is obliged to promptly notify the relevant person and the Board of this situation.
Within the framework of the aforementioned provision, the Board may, if it deems necessary, announce the data breach to the public via its website or by other methods it deems appropriate. This regulation has been introduced to ensure the effective management of data breaches and the timely notification of the relevant persons.
Louis Vuitton Çantacılık Ticaret Anonim Şirketi
According to the data breach notification submitted to the Board by Louis Vuitton Çantacılık Ticaret Anonim Şirketi, acting as the data controller, the breach began on June 7, 2025, and was detected on July 2, 2025. The breach occurred through unauthorized access to a database containing customers’ personal data; it was determined that this situation arose as a result of a service account used by a third-party service provider’s manager being compromised.
Customers and potential customers were affected by the breach, and the categories of personal data affected were identity and contact details. Technical investigations are still ongoing, and it has been reported that 142,995 individuals residing in Turkey were affected by this breach.
Bold LLC
In the data breach notification submitted to the Board by Bold LLC, acting as the data controller, it was reported that on July 12, 2025, it was discovered that a feature enabling users to preview their resumes in real time while editing them as part of the online job search service offered by the company in Puerto Rico was accessible to unauthorized access. Internal investigations revealed that the security vulnerability originated on March 10, 2023, and that unauthorized access occurred only once due to this vulnerability.
The breach affected anonymized names, contact information, and resume data. The scope of personal data contained in resumes varies according to user preferences; while some resumes contain only basic identifying information such as first and last names, others may include contact information, education and employment history, photographs, and other information voluntarily shared. The technical analysis process is ongoing, and it has been reported that a total of 3,168 people, including users and subscribers/members, were affected by the breach.
Investment Finance Securities Inc.
According to the data breach notification submitted to the Board by Yatırım Finansman Menkul Değerler A.Ş., which holds the title of data controller, the breach occurred on July 20, 2025, and was detected on the same day. It was stated that an international and expert attack group carried out a ransomware attack targeting the data controller’s servers and client computers.
The number of individuals affected by the breach, the relevant group of individuals, and the categories of personal data have not yet been determined, and technical investigations are still ongoing in this regard. It has been announced to the public that the individuals concerned can obtain information and support regarding this incident from all branches of the data controller and via the Investor Support Line at 08507235959.
GRC LEGAL COMMENT
The data breaches reported to the Board in July 2025 reveal the diversity and severity of cybersecurity risks faced by companies operating in different sectors. The reports submitted by Louis Vuitton Çantacılık Ticaret A.Ş., Bold LLC, and Yatırım Finansman Menkul Değerler A.Ş. point to different breach scenarios that threaten the security of personal data both locally and internationally.
The breach reported by Louis Vuitton occurred as a result of a service provider’s administrator account being compromised, leading to the exposure of the identity and contact details of a large number of customers. This situation once again highlights the critical role of security measures in contracts with third parties and access controls.
The breach at Bold LLC, which occurred due to a software feature remaining open to the outside during the development process, shows the consequences of launching digital services into production before security testing is complete. The breach demonstrates that it is not only a technical vulnerability but also a risk posed by insufficient consideration of privacy in the design process.
The ransomware attack on Yatırım Finansman Menkul Değerler A.Ş. has once again revealed that the financial sector is a constant target for cyber threats. Although the individuals and data categories affected by the breach have not yet been clarified, the fact that the attack was detected on the same day and promptly reported to the Board points to the effectiveness of incident response processes and the importance of effectively implementing internal procedures in the event of a data breach.
Consequently, data security must be addressed holistically, not only through technical measures but also through process planning, supplier/partner management, and crisis response strategies. Organizations must continuously monitor and update not only their internal systems but also externally sourced services, new software features, and network structures.
GUIDELINE UPDATE
The “Guideline on Cookie Practices” has been updated!
The Guide on Cookie Practices (“Guide”) published by the Board in June 2022 has been updated in July 2025. The updated Guide provides guidance for data controllers who process personal data via cookies through desktop and mobile websites and web applications.
The Guide clarifies the principles regarding obtaining explicit consent from users for cookie use, the fulfillment of the information obligation by data controllers, the classification of cookie types, and the lawful processing of personal data. In addition, it provides concrete recommendations to practitioners by including examples of good and bad practices with visuals.
WHAT’S HAPPENING IN THE NEWS?
Balancing Privacy and Freedom of the Press: A CEO Case
A recent news story that has preoccupied the public and received extensive coverage in the international press has brought the issues of privacy and personal data protection back to the forefront. The detailed reporting of a situation concerning the private life of a large company’s CEO, accompanied by images, has sparked debate in the legal field. This case once again highlights the delicate balance between freedom of the press in publicly accepted areas and the protection of individuals’ private lives under the KVKK.
Freedom of the press, guaranteed by Article 28 of the Constitution, is important in terms of the public’s right to receive information. However, this freedom is not an absolute right; it is limited by the right to privacy of private life, as regulated in Article 20 of the Constitution. For information relating to private life to be included in a news story, there must be a public interest, a direct link between the person’s public profile and the subject of the news story, and the content must be proportionate. Even information about the private lives of individuals who are known to the public due to their professional position may constitute a violation of personal rights and data security if it is reported without the consent of these individuals and without establishing a connection with the public interest.
In this context, the relevant incident holds not only media organizations but also event organizers accountable. Filming individuals without their permission in public spaces such as concerts and reporting on these images may constitute a violation of privacy and personal data security. Therefore, event organizers must fulfill their duty to inform, provide participants with the necessary information texts, create “no photography” areas, and inform media representatives of the filming rules in advance. Today, how these notifications are made is extremely important. Informing individuals about such activities does not imply consent to the activities in question, and it is clear that the explicit consent of individuals must be obtained in a manner specific to the process.
Media organizations are expected to pay the utmost attention to ensuring that personal data is processed only in the public interest and in accordance with the principle of proportionality. In this context, each news content should be evaluated separately within the framework of personal data protection law, and the principle of respect for privacy should be prioritized.
Crisis Caused by Weak Passwords: Cyber Attacks and the Bankruptcy of a 158-Year-Old Company
According to a BBC Turkish report, at KNP, a British company operating in the transportation sector, an employee’s inadequate password security led to access to all company data, the systems being locked, and ultimately, all company data being deleted by cyber attackers. Due to this breach, the company was forced to suspend its operations.
Technical and administrative measures to ensure the security of personal data are among the fundamental obligations of data controllers under the KVKK. Pursuant to Article 12 of the KVKK, data controllers are obliged to take all necessary security measures to prevent unlawful access to the personal data they process. Weak password practices may constitute a breach of this obligation and may lead to administrative sanctions and loss of reputation for data controllers, and even bankruptcy for companies. In this context, the creation of strong password policies and their effective implementation among employees should be considered not only an information technology issue but also a legal requirement.
Another important point mentioned in the news is that many workplaces still allow users to set their own simple passwords and do not periodically check these passwords. Under the KVKK, creating and maintaining secure password policies is among the necessary administrative measures for personal data security. Furthermore, international information security standards such as ISO 27001 also require that password management procedures be clearly defined and regularly audited. In this context, it is extremely critical to renew passwords at specific intervals, enable multi-factor authentication, and periodically train users on password security.
Ultimately, data breaches caused by weak/simple passwords demonstrate that obligations regarding the protection of personal data are directly linked not only to technical infrastructure but also to the level of user awareness. Data controllers must adopt and maintain a culture of security not only at the system level but also at the organizational level. Within the framework of the KVKK, strong password policies have become an urgent necessity today in order to ensure personal data security and avoid facing sanctions for potential data breaches.