GRC PERSPECTIVE: DATA PROTECTION & COMPLIANCE NEWSLETTER – JUNE 2026

WHAT’S HAPPENING IN TURKEY?

Public Notice Issued Regarding the Use of CCTV Systems in Workplaces

On 6 June 2026, the Personal Data Protection Authority (“the Authority”) published a “Public Notice on Matters to Be Considered Regarding the Use of CCTV Systems in Workplaces”.

The notice emphasises that video recordings made via security cameras in workplaces constitute a personal data processing activity and, as such, such activities must be carried out in accordance with the Personal Data Protection Law No. 6698 (“KVKK” or “the Law”).

In particular, the Authority has stated that the purpose of using CCTV systems must be determined in advance; the processing activity must be carried out for specific, explicit and legitimate purposes; the data processed must be relevant, limited and proportionate to the purpose; and the principle of data minimisation must be observed. In this context, whilst the use of cameras is permissible for purposes such as ensuring workplace security, monitoring occupational health and safety measures, or preventing crime, it has been stated that the use of camera systems for the purpose of monitoring employees’ performance, measuring their productivity, or for general surveillance cannot be considered a legitimate purpose.

The notice also states that the positioning of cameras and their fields of view must be determined in accordance with the principle of proportionality, that employees’ reasonable expectations of privacy must be taken into account, and that camera systems must not be used in areas of a private nature, such as toilets, changing rooms, prayer rooms and rest areas. It was emphasised that systems with audio recording capabilities, due to their more intrusive nature in terms of privacy, may only be used in cases where they are necessary and legally justifiable.

Furthermore, it was reiterated that employees must be properly informed that they are being recorded by cameras; that the necessary technical and administrative measures must be taken to ensure the security of the recordings; that access to the recordings must be restricted to authorised persons; and that the recordings must be retained only for the period necessary to fulfil the purpose of processing, after which they must be deleted, destroyed or anonymised. The Authority has also stated that, should any practices contrary to the specified obligations be identified, administrative sanctions may be imposed on the relevant data controllers under the Personal Data Protection Law (KVKK).

Public Announcement Published on the Use of CCTV Systems in Blocks of Flats

On 8 June 2026, the Authority published a “Public Announcement on Matters to Be Considered Regarding the Use of CCTV Systems in Blocks of Flats”.

The announcement emphasised that the use of cameras for security purposes is permissible, but that such activities must be carried out in accordance with the Act. The Authority has stated that the recording of individuals’ images via camera systems constitutes a personal data processing activity and that apartment block/estate management bodies, in their capacity as data controllers, are subject to the obligations under the Personal Data Protection Law (KVKK).

Furthermore, whilst cameras may be installed in communal areas for security purposes under the Condominium Law No. 634, it was stated that this authority cannot be assessed independently of the provisions of the KVKK. The notice specified that the placement of cameras must comply with the principle of proportionality; private areas (such as the area in front of a door where the interior of a flat would be visible) must not be monitored, additional technologies such as facial recognition or audio recording must not be used, and recordings must not be made on an unnecessarily broad scale.

Furthermore, it was emphasised that recordings must be retained only for as long as necessary, protected against unauthorised access, and that data subjects must be informed in accordance with Article 10 of the KVKK. The Authority has reminded data controllers that they are obliged to take the necessary technical and organisational measures under Article 12 of the KVKK; it has also stated that, failing this, administrative sanctions may be imposed under Article 18.

GRC LEGAL PERSPECTIVE

When both public announcements are considered together, it is evident that the Authority has reiterated the long-standing principles of the KVKK regarding CCTV applications and has drawn particular attention to non-compliance in practice. Rather than introducing new obligations, these points serve as a reminder aimed at ensuring that data controllers effectively implement their existing obligations, in light of increasing complaints and the need for supervision. In this context, the importance of effectively implementing fundamental principles such as data minimisation, proportionality, purpose limitation, retention periods and the duty to provide information remains unchanged.

Constitutional Court Ruling Assessing Publicly Disclosed Personal Data and the Principle of Legality in Criminal Law Published

In the Constitutional Court decision published in the Official Gazette No. 33282 dated 6 June 2026, it was unanimously ruled that the principle of legality in criminal law had been violated in relation to an administrative fine imposed under the Personal Data Protection Law (KVKK).

In the case in question, an administrative fine was imposed by the Personal Data Protection Board because an insurance company had contacted the data subject by telephone for marketing purposes without their explicit consent. The applicant company argued that the data subject’s first name, surname and telephone number were available on a publicly accessible website and that, consequently, the data in question constituted ‘publicly disclosed personal data’ within the meaning of Article 5(2)(d) of the Act.

In response, the Personal Data Protection Board ruled that the mere fact that personal data is accessible online cannot, in itself, be deemed to constitute disclosure; it stated that the data may only be processed in a manner consistent with the data subject’s intention and purpose regarding disclosure, and consequently imposed the administrative fine.

The Constitutional Court, however, assessed that whilst the Act provides that publicised personal data may be processed without explicit consent under certain conditions, it does not contain clear and foreseeable provisions regarding the scope of publicisation, how the intention to publicise is to be determined, or the legal consequences of use for purposes other than publicisation. The Court emphasised that attempting to clarify these matters solely through the non-binding Personal Data Protection Authority Implementation Guide does not constitute a sufficient legal basis for the imposition of administrative sanctions.

In this context, the Constitutional Court concluded that the administrative fine was based on an unforeseeably broad interpretation of the statutory provision and ruled that this constituted a breach of the principle of legality in criminal matters and penalties, as guaranteed by Article 38 of the Constitution; it ordered that the case be referred back to the Istanbul Anadolu 5th Magistrates’ Court for a retrial.

GRC LEGAL PERSPECTIVE

This Constitutional Court ruling clarifies a significant issue that has long been the subject of debate in the application of the Personal Data Protection Act (KVKK). The ruling makes it clear that, whilst the guidelines and best practice documents published by the Board serve as a guide for data controllers, an obligation not explicitly regulated in the Act cannot form the basis for administrative sanctions solely on the basis of these guidelines. This approach confirms that the principles of legality in criminal matters and legal certainty must also be upheld in relation to administrative sanctions under the KVKK.

In particular, the decision emphasises that, with regard to the condition for the processing of ‘publicly available personal data’ set out in Article 5 of the Law, criteria such as ‘intent to make data public’ or ‘use in accordance with the purpose of making data public’ – which are not regulated in the Law – cannot be used as grounds for sanctions solely through the guidelines. In this respect, the decision has the potential to contribute to the establishment of a more predictable framework in practice regarding the processing of public personal data.

However, the decision should not be interpreted to mean that public personal data may be processed freely in all circumstances, or that the Board’s guidelines have lost their significance. The guidelines continue to serve as a guiding framework for data controllers in their compliance processes.

However, the most important principle established by the decision is that the basis for administrative sanctions must be set out clearly and predictably in the provisions of the Act itself. In this context, it is considered that the decision will be regarded as an important precedent based on the principle of legality, particularly in judicial proceedings concerning administrative fines.

Organisation of Turkic States Digital Economy Partnership Agreement Enters into Force

The Digital Economy Partnership Agreement between the Governments of the Member States of the Organisation of Turkic States (OTS), prepared within the framework of the OTS to develop digital trade and establish a common framework for data security, was published in the Official Gazette dated 20 June 2026 the Law on the ratification of the Digital Economy Partnership Agreement was published and the Agreement entered into force. The Agreement in question was signed in Bishkek on 6 November 2024.

Whilst the Agreement aims to strengthen cooperation in the field of the digital economy, it also dedicates a specific regulatory framework to the protection of personal data. In this context, Article 19 of the Agreement requires the contracting states to establish a national legal framework for the protection of personal data or to maintain existing regulations. Furthermore, the establishment of clear rules on cross-border data transfers and the enhancement of transparency regarding data protection practices are among the key obligations.

Furthermore, the contracting states are expected to publish their data protection legislation and practices in a manner that is publicly accessible; to provide information on individuals’ rights of redress and the obligations of data controllers; and to encourage businesses to share their data protection policies and procedures transparently.

Whilst the Agreement recognises the differing legal approaches of the signatory states, it also envisages an increase in the exchange of knowledge and experience in this field. This regulation represents a significant step towards the development of common standards in the digital economy and personal data protection among member states of the Organisation of Turkic States, as well as towards enhancing legal predictability in cross-border data flows.

Public Notice Issued Regarding the Processing of Personal Data in Municipal Live Broadcasts

The Authority has issued a public notice concerning live broadcasts conducted online via cameras installed in public spaces by local authorities for the purpose of promoting tourism.

The Authority has assessed that the fact that images of individuals’ faces and vehicle number plates become visible within the scope of such broadcasts—and are made accessible via the internet even if no recording is made—constitutes a personal data processing activity under the Act. In this context, it has been stated that the authority regarding tourism and promotion set out in the Municipalities Act No. 5393 does not, on its own, constitute a sufficient and clear legal basis for the aforementioned data processing activity; furthermore, the conditions for data processing set out in Article 5 of the Act are not met.

The Authority has also assessed that such practices constitute an interference with individuals’ right to privacy; that they increase the risk of misuse due to the images becoming accessible to an unlimited number of people online; and that it is possible to achieve the same promotional objective through alternative methods that do not involve personal data.

In this context, the Authority has stated that local authorities must immediately cease their current live streaming applications that enable the identification of individuals, switch to alternative methods that do not involve personal data, and take the necessary technical and administrative measures in accordance with Article 12 of the Act. It has also been made public that, failing this, administrative sanctions may be imposed under Article 18 of the Act.

GRC LEGAL PERSPECTIVE

Rather than introducing a new legal approach under the Personal Data Protection Act (KVKK), the relevant announcement demonstrates that the data processing principles, which have been in force for some time, will be applied without compromise to live streaming activities carried out by local authorities. It is assessed that, following a recent increase in complaints in this area, the Authority has stepped up its monitoring and awareness-raising activities aimed at ensuring the implementation of existing obligations.

However, it is observed that the practice continues in some local authorities at present, and it is assessed that this situation may give rise to the risk of administrative sanctions. Within the framework of the Authority’s approach, it is important to prioritise alternative methods that do not involve personal data where it is possible to achieve the same promotional objective.

Personal Data Protection Board Principle Decision No. 2026/921 Published

Published in the Official Gazette No. 33268 dated 2 June 2026, the Personal Data Protection Board’s Principle Decision No. 2026/921 sets out the principles governing the processing of biometric data (fingerprints, facial recognition, iris and retina scans, etc.) by employers for the purpose of monitoring working hours.

The Board has emphasised that biometric data constitutes special category personal data and is subject to a high standard of protection. The Decision assesses that the processing of biometric data for the purpose of working time monitoring may not, on its own, be sufficient due to the imbalance of power in the employer-employee relationship, even where explicit consent is given. Furthermore, the Board stated that such data processing must be assessed in light of the principles of proportionality, necessity and data minimisation; and that where less intrusive alternative methods—such as cards, PINs, RFID/NFC or signatures—are available for time and attendance tracking, biometric methods cannot be deemed mandatory.

Consequently, the Principles Decision has established that employers must review their biometric-based working hours tracking systems for compliance with the Personal Data Protection Law (KVKK); otherwise, they may face administrative sanctions under the Law.

Turkey’s Artificial Intelligence Action Plan Unveiled

Announced by President Recep Tayyip Erdoğan at the Turkey Artificial Intelligence Summit, the 2026–2030 Turkey Artificial Intelligence Action Plan sets out comprehensive objectives aimed at strengthening national capacity in the field of artificial intelligence.

The plan is structured around four key pillars: ‘recognise, utilise, produce and manage’; within this framework, increasing AI literacy and developing human resources are among the priority areas. In this context, the launch of the National Artificial Intelligence Literacy Programme aims to provide training to 5 million citizens within two years through workshops to be established in all 81 provinces, and to train 10,000 advanced artificial intelligence specialists and 100,000 application professionals.

The plan also includes significant measures to strengthen the data infrastructure. It is envisaged that at least 2,000 public data sets, primarily in the fields of health, agriculture, defence and e-commerce, will be made accessible via the National Data Library. In addition, it is planned to allocate at least 2 per cent of public investment to AI projects, to increase data centre capacity to 1 gigawatt (GW) by 2030, and to mobilise at least 10 billion dollars’ worth of investment in AI infrastructure, with a focus on the private sector.

This Action Plan serves as a strategic roadmap for developing Turkey’s artificial intelligence ecosystem, accelerating data-driven transformation and enhancing competitiveness in the digital economy.

Threads Re-launched in Turkey

It has been announced that Meta’s text-based social media platform, Threads, has been re-launched in Turkey after a hiatus of approximately two years, in line with the commitments deemed acceptable by the Competition Authority.

In its statement, the Competition Authority noted that the application regarding the relaunch of the Threads app in Turkey was found to be in line with the commitments accepted by the Competition Board. In this context, it was stated that users would be able to use Threads either via their Instagram account or by creating an account independent of Instagram using only their mobile phone number. Furthermore, it has been stipulated that should users opt for an account independent of Instagram, data collected via Threads will not be combined with Instagram data.

In the investigation conducted by the Competition Authority regarding this process, competition concerns relating to Meta’s data-merging practices were assessed. In this context, the investigation launched in 2023 assessed that Meta holds a strong market position due to its extensive user base and data accumulation; that this situation makes Meta’s services attractive to advertisers; and that it could create a barrier to entry by making it difficult for competitors to access advertising revenue.

In line with these assessments, a decision was taken to impose interim measures restricting data-pooling practices, and it was stipulated that a daily administrative fine would be imposed in the event of non-compliance with the relevant obligations.

Subsequently, the solutions proposed by Meta were assessed by the Competition Authority but were deemed insufficient to address the competition concerns regarding data pooling and were therefore rejected. Ultimately, as the obligations subject to the interim measure decision became moot, the imposition of daily administrative fines was discontinued. This development highlights that cross-platform data integration practices are being closely monitored from a competition law perspective and that the regulatory approach to data usage in digital ecosystems is taking shape within an increasingly stringent framework.

WHAT’S HAPPENING AROUND THE WORLD?

Simultaneous Interim Rulings from Turkey and the EU in the Meta/WhatsApp–Meta AI Investigation

Following the Competition Authority’s decision to impose interim measures in the Meta/WhatsApp-Meta AI case, a similar assessment was also carried out by the European Commission. Both authorities have concluded that there are significant competition concerns regarding access to distribution channels for general-purpose AI services and the impact of such access on competition.

In Turkey, the Competition Authority has investigated allegations that, during Meta’s process of integrating Meta AI into WhatsApp, access to the platform for rival AI providers was made more difficult; having assessed that these practices contained serious findings under Article 6 of Law No. 4054, it has ordered the application of interim measures until a final decision is reached. In this context, Meta has been required to ensure conditions are in place to enable third-party general-purpose generative AI chatbots to provide services via WhatsApp and to refrain from practices that could hinder such services; it is stipulated that these measures must be implemented within one month of the notification of the reasoned decision.

Similarly, the European Commission has also assessed that changes made by Meta under the WhatsApp Business Solution Terms restrict access to the WhatsApp for Business API for rival general-purpose AI chatbots, and has issued a decision on interim measures. The Commission noted that the changes made in October 2025 effectively blocked access, whilst in March access was made subject to a fee; however, it pointed out that this model is not economically sustainable for competitors. In this context, it was stated that Meta must grant rival AI chatbots access to the WhatsApp Business API in a manner that restores the conditions in place prior to October 2025.

No final finding of an infringement has yet been made in either case. However, the interim measures adopted both in Turkey and in the European Union demonstrate that competition law debates regarding access to distribution channels and platform dependency in general-purpose artificial intelligence services have become an increasingly closely monitored area.

Greek DPA Ruling on the Sharing of Former Employees’ Data Under the GDPR

In a ruling issued by the Hellenic Data Protection Authority, administrative fines were imposed on both the data controller company and a former manager for transferring corporate emails containing the personal data of a former employee who had left the company to the former manager without informing the data subject.

In this case, the data subject had requested access to their own emails from the company under Article 15 of the European Union’s General Data Protection Regulation (GDPR) as part of an employment dispute; however, the company stated that the accounts had been deleted and that the relevant emails were no longer present in their systems. Conversely, during the proceedings, it emerged that the emails in question had been obtained from the corporate archive held by the former manager and submitted to the court.

The Authority acknowledged that the former manager was in the position of a third party after leaving the company and could be regarded as an independent data controller due to his retention and sharing of the data. However, it was assessed that the content of the emails constituted personal data and that the data subject must be informed prior to the transfer of such data.

In this context, an administrative fine of 20,000 euros was imposed on the company for breach of the duty to provide information, whilst a fine of 2,000 euros was imposed on the former manager for breach of obligations regarding the processing and sharing of personal data.

GRC LEGAL PERSPECTIVE

The relevant decision clearly demonstrates that corporate email archives may give rise to the risk of ‘uncontrolled data circulation’, particularly in relation to employees who have left the organisation. The mere use of data in a legal proceeding is not deemed sufficient; it is emphasised that the duty to inform continues as a separate and independent obligation, particularly with regard to personal data obtained through third parties.

A notable aspect of the ruling is that a former manager is treated as an independent data controller after leaving the company, and that the existence of a legitimate interest does not negate the duty to inform. This approach undermines the practical assumption among companies that ‘responsibility lies with whoever holds the data’ and shifts data governance towards a more fragmented structure of responsibility.

Compliance Timetable for the EU AI Regulation Updated

The “digital omnibus” regulation, which contains significant changes to the compliance timetable for the EU AI Regulation, has also been approved by the Council of the European Union. Consequently, the amendments previously adopted by the European Parliament have reached the final stage before coming into force.

Under this regulation, it is evident that the implementation dates for certain obligations relating specifically to high-risk AI systems have been postponed, whilst obligations regarding the labelling of content generated by AI have been incorporated into the timetable. Furthermore, an explicit ban on AI systems that generate non-consensual intimate or sexual content is being introduced.

According to the new timetable, transparency and labelling obligations for AI-generated content will come into force on 2 December 2026. On the same date, the use of ‘nudifier’ systems that generate non-consensual intimate content will also be prohibited. It is understood that certain obligations relating to high-risk AI systems have been deferred to 2 December 2027 and 2 August 2028, whilst the process concerning regulatory sandboxes has been postponed to 2 August 2027.

In addition, the regulation reshapes the compliance timetable for AI systems linked to product safety legislation; it also includes structural changes such as the clarification of certain technical definitions and the expansion of the scope of compliance relief measures for SMEs.

GRC LEGAL PERSPECTIVE

This regulation demonstrates that a phased compliance model has been adopted rather than a fully prohibitive approach in the implementation of the AI Act; the postponement of certain obligations means that sectors are granted additional preparation time, particularly with regard to high-risk systems.

Labelling obligations and explicit bans on AI systems that generate content without consent demonstrate that the EU is strengthening its focus on transparency and the protection of fundamental rights; the regulation offers a balanced approach aimed at bringing high-risk use cases under tighter control without unduly restricting the scope for innovation.

GRC CONCEPT OF THE MONTH

Access to AI Distribution Channels (AI Distribution Access)

Access to AI distribution channels refers to the conditions under which AI services can access the platforms through which they reach end-users (e.g. messaging apps, social media networks, operating system ecosystems and API infrastructures), and which actors control this access.

With the strengthening of the platform-based structure of the digital economy, AI services have evolved from being merely a technical software product into an ecosystem component distributed via major platforms and subject to those platforms’ access policies. This situation places the concepts of ‘access control’ and ‘distribution power’ at the centre of competition law, as seen particularly in the Meta/WhatsApp examples.

This concept is particularly significant in terms of whether platforms provide API access to rival AI services, whether they make such access technically or economically difficult, and whether they structure their distribution channels in a way that prioritises their own AI solutions. Within this framework, access conditions are regarded not merely as a technical integration issue, but also as a strategic element that has a direct impact on competition, innovation and market structure.