GRC PERSPECTIVE: DATA PROTECTION & COMPLIANCE NEWSLETTER – MAY 2026

WHAT’S HAPPENING IN TURKEY?

KVKK 2025 Annual Report Published: Notable Increase in Complaints, Data Breaches and Administrative Fines

The 2025 Annual Activity Report published by the Personal Data Protection Authority (“the Authority”) sets out the Authority’s activities during 2025 relating to investigations, data breach notifications, administrative sanctions, VERBİS and cross-border data transfer processes.

According to the report, a total of 12,512 reports and complaints were received by the Authority during the period from 1 January 2025 to 31 December 2025. Of these submissions, 9,315 were made via CİMER, 2,058 via the e-complaint module and 1,139 by post; within this framework, 75 per cent of submissions were forwarded to the Authority via CİMER, 16 per cent via the e-complaint module and 9 per cent by post.

In terms of the sectoral breakdown of reports and complaints, the highest number of submissions—1,691—was recorded in the services sector. In terms of the subject-based breakdown of submissions, the unlawful processing of personal data ranked first. Accordingly, 52 per cent of submissions related to the unlawful processing of personal data, 22 per cent to the unlawful sharing of personal data with third parties, 11 per cent to unauthorised text messages or calls, 6 per cent to the failure to comply with data subjects’ requests, and 4 per cent to allegations of non-compliance with the obligations regarding erasure, destruction and anonymisation.

With regard to data breach notifications, 328 data breach notifications were submitted to the Authority in 2025. Of these notifications, 296 originated from domestic sources and 32 from overseas; during the same period, 51 data breach notifications were published by the Authority.

As regards administrative sanctions, administrative fines were imposed on a total of 876 data controllers in 2025: 140 in relation to reports and complaints, 142 in relation to data breach notifications, and 594 in relation to the obligation to register and notify the Data Controllers’ Register. The total amount of administrative fines imposed was 352,510,494 TL; of which 45,291,994 TL related to reports and complaints, 90,358,500 TL to data breach notifications, and 216,860,000 TL to breaches of the registration and notification obligations under the Data Controllers’ Register.

The report also included data on data transfer processes abroad; it was stated that in 2025, the number of standard contracts submitted to the Authority pursuant to Article 9/4-c of the Law on the Protection of Personal Data (“the Law”) was 2,497.

GRC LEGAL PERSPECTIVE

The KVKK 2025 Activity Report demonstrates that compliance obligations in the field of personal data protection are not limited to the preparation of policies and documentation; rather, they require a holistic approach encompassing application management, data security, the up-to-date status of VERBİS registrations, cross-border data transfers and data breach response processes.

The increase in the number of notifications and complaints indicates a rising awareness among data subjects regarding their rights over their personal data. Conversely, the fact that a significant proportion of applications were concluded without being examined on their merits due to procedural deficiencies or being outside the scope of the Act highlights the continuing need for awareness regarding the application and complaint mechanisms.

The distribution of applications by subject matter indicates that, for data controllers, the main areas of risk are the assessment of legal grounds and purpose, data sharing with third parties, commercial electronic communications processes, responding to data subjects’ applications, and data erasure obligations. It is therefore important for data controllers to regularly review not only their privacy notices but also their actual data processing procedures and mechanisms for responding to requests.

The fact that the VERBİS registration and notification obligation accounts for the largest share of administrative fines highlights that the registration obligation should not be regarded as a one-off registration process. Similarly, data relating to data breach notifications also indicates that technical and organisational measures, incident response plans and breach notification procedures must be tested periodically.

The figure relating to standard contract notifications, meanwhile, indicates that the new regime for cross-border data transfers is beginning to take effect in practice. However, the standard contractual clause notification must be treated not merely as a formal notification obligation, but as a comprehensive risk analysis process covering the parties to the transfer, data categories, purposes of the transfer, security measures and onward transfers.

15-Year-Old Social Media Regulation Enacted: Age Verification, Child-Specific Services and Parental Control Obligations

Law No. 7578 on Amendments to the Social Services Act and Certain Other Laws was published in the Official Gazette dated 30 April 2026. The Law introduces significant amendments to Law No. 5651 concerning social media providers and gaming platforms.

Under the regulations, social media providers are obliged to not provide services to children under the age of fifteen and to take the necessary measures, including age verification, in this regard. Furthermore, social media providers are required to provide separate services specifically for children aged fifteen and over and to publish the measures taken in this regard on their own websites.

The Act also imposes an obligation on social media providers to provide clear, comprehensible and user-friendly parental control tools. These tools must include mechanisms such as the ability to control account settings, making paid transactions subject to parental consent or approval, and monitoring and limiting usage time. Furthermore, social media providers are required to take measures to block misleading advertisements.

With regard to gaming platforms, the Act provides for age ratings, parental control tools and, for foreign-based gaming platforms with daily access from Turkey exceeding 100,000 users, the obligation to appoint a representative in Turkey. The Information and Communications Technologies Authority may request information from gaming platforms directly relevant to the implementation of the Act, including details of their corporate structure, IT systems and data processing mechanisms.

In the event of non-compliance with these obligations, sanctions such as administrative fines, advertising bans and the throttling of internet bandwidth may be imposed on social media providers and gaming platforms. The regulations will come into force six months after the date of publication of the Act.

GRC LEGAL PERSPECTIVE

The regulation demonstrates that obligations regarding the protection of children in digital environments have been expanded under the headings of age verification, service design tailored to children, parental controls, advertising oversight and platform liability.

In particular, age verification and parental control mechanisms, whilst important for the protection of children, also raise issues concerning personal data processing. It is therefore important for social media providers and gaming platforms to design these processes in accordance with the principles of data minimisation, proportionality, purpose limitation and retention period.

Cybersecurity Council Holds First Meeting: Critical Infrastructure Sectors Identified

The Cyber Security Council held its first meeting on 5 May 2026, chaired by President Recep Tayyip Erdoğan. During the meeting, it was emphasised that cyber security is an integral part of national security; it was stated that the Cyber Security Presidency would continue its activities with the aim of protecting the country’s digital assets, establishing a proactive structure against threats and creating a robust cyber security architecture at the national level.

In this context, the fundamental elements of the national cyber security approach were reviewed; in particular, the protection of critical infrastructure, the security of digital systems and capacity building in domestic and national technologies were identified as priority areas. Furthermore, data sovereignty was addressed as a separate agenda item during the meeting; it was noted that data represents a strategic value beyond being merely a technical element.

As a result of the meeting, it was agreed to strengthen inter-agency coordination, increase domestic and sustainable capacity in critical areas, and develop preparedness and rapid adaptation capabilities against cyber risks. Furthermore, Digital Infrastructure, Digital Services, Electronic Communications, Energy, Finance, Food and Agriculture, Manufacturing, Public Services, Media and Crisis Communication, Post and Parcel, Healthcare, Defence Industry, Water Management, Transport and Space have been identified as critical infrastructure sectors.

GRC LEGAL PERSPECTIVE

The first meeting of the Cyber Security Council demonstrates once again that cyber security is not merely a technical issue; it is a strategic area in terms of national security, data sovereignty, economic continuity and organisational resilience.

It will become increasingly important for organisations operating in critical infrastructure sectors to structure their processes relating to cyber security, data security, incident response, business continuity and supplier risk management in a more holistic manner.

Guidance on the Processing of Personal Data in Reality TV Programmes Published in Collaboration with the Personal Data Protection Authority (KVKK) and the Radio and Television Supreme Council (RTÜK)

The Authority, in collaboration with the Radio and Television Supreme Council (“RTÜK”), has published the Guide on the Processing of Personal Data in Live Reality TV Programmes (“the Guide”), based on feedback received from broadcasters, production companies and academics.

The Guide clarifies the practices regarding the processing of personal data, particularly in programmes broadcast live during the daytime and focusing on real-life events. In this context, the Guide covers the preparation phase of the programmes, the live broadcast process, post-broadcast procedures and the process of rebroadcasting on internet platforms.

The Guidelines highlight that, in programmes of a reality TV nature, in addition to personal data such as identity, contact details, visual and audio recordings, marital status, financial circumstances and educational background, special categories of personal data—such as health, sexual life, criminal convictions and security measures—may also be processed. It is therefore emphasised that broadcasters and production companies must carry out their personal data processing activities in accordance with the general principles and processing conditions set out in Law No. 6698.

The guide also states that, depending on the specific circumstances of the case, broadcasters and production companies may be classified as data controllers, data processors or joint data controllers. Within this framework, compliance recommendations are provided on topics such as the duty to provide information, explicit consent, data security, conditions for domestic and international transfers, requests for erasure, VERBİS obligations, data breach notification and responding to data subject requests.

GRC LEGAL PERSPECTIVE

The Guide clearly establishes that the live broadcast format does not constitute an area where personal data can be processed without restriction. In particular, the sharing of information belonging to third parties during a broadcast, the disclosure of special category personal data, or the inclusion of statements that could infringe upon personal rights may give rise to serious risks under the KVKK.

For this reason, it is important for broadcasters and production companies to jointly assess the processes of information provision, explicit consent, data minimisation, data security and data destruction throughout the entire process, from before the programme begins to after it ends; it is also important to plan in advance the technical and administrative measures aimed at preventing the unlawful sharing of data during live broadcasts.

Announcement Regarding the 2025 Financial Balance Sheet Threshold and Deadline for VERBİS Registration Obligations

The Authority has published a public announcement concerning corporate tax-liable legal entities acting as data controllers who are subject to the obligation to register with VERBİS due to their 2025 financial balance sheet total.

The announcement states that data controllers whose principal activity does not involve the processing of special-category personal data and whose total financial balance sheet is 100 million TL or more, as well as data controllers whose principal activity involves the processing of special-category personal data and whose total financial balance sheet is 10 million TL or more, must assess their VERBİS registration obligation.

In this context, the registration and notification period, which was normally expected to end on 1 June 2026, has been extended until 5 June 2026 by the Board’s Decision No. 2026/1026 dated 13 May 2026.

First Application for Binding Corporate Rules Approved under the KVKK

The Authority has announced that the first application for Binding Corporate Rules (“BCR”) submitted in the context of the cross-border transfer of personal data has been approved.

According to the announcement, the BCR application submitted to the Authority by Sosyo-Plus Information and Communication Technologies Consultancy Services Inc. was assessed under Article 9(4)(b) of the Act and approved by the Board on 20 May 2026.

GRC LEGAL PERSPECTIVE

This decision represents a significant development in that it demonstrates the commencement of the BŞK mechanism’s implementation in Turkey under the new cross-border data transfer regime which came into force in 2024.

Particularly for multinational corporate groups, technology companies and structures involving intensive intra-group data transfers, the BŞK mechanism may be regarded as a long-term, institutional compliance tool for cross-border data transfer processes.

WHAT’S HAPPENING AROUND THE WORLD?

The Irish Data Protection Commission Has Launched an Investigation into SHEIN Regarding Data Transfers to China

The Irish Data Protection Commission (“DPC”), has launched a formal investigation into Infinite Styles Services Co. Ltd., operating as SHEIN Ireland, regarding the transfer of personal data belonging to data subjects in the EU/EEA to China.

As part of the investigation, the DPC will examine SHEIN Ireland’s compliance with its obligations under the GDPR in relation to the data transfers in question. The investigation will in particular assess the principles of personal data processing set out in Article 5 of the GDPR, the transparency obligations under Article 13 of the GDPR, and the provisions of Chapter V of the GDPR relating to data transfers to third countries.

In its statement, the DPC emphasised that where personal data is transferred to a country outside the EU, the data must benefit from a level of protection that is essentially equivalent to that within the EU. It was also stated that data transfers to China have recently come under increased scrutiny by European data protection authorities and that the investigation represents a strategic priority for the DPC.

GRC LEGAL PERSPECTIVE

The investigation launched into SHEIN demonstrates that data transfer processes to third countries, particularly in the context of e-commerce and digital platforms, are being scrutinised ever more closely in Europe.

In particular, for transfers to countries without an adequacy decision, the mere signing of standard contractual clauses is no longer considered sufficient; it is also expected that an assessment will be made as to whether the law and practices in the country to which the data is transferred provide essentially equivalent protection for personal data. It is therefore important for companies to structure their cross-border data transfer processes in accordance with the principles of transparency, legal basis for transfer, additional security measures and accountability.

10 Million Euro Fine Against Uber for Hindering Drivers’ Right of Access to Their Data Upheld

The Dutch Data Protection Authority has rejected the appeal against the 10 million euro administrative fine imposed on Uber for GDPR infringements.

In the proceedings leading to the decision, it was found that Uber had unnecessarily made it difficult for drivers to exercise their right to access their personal data.

Although a digital form enabling drivers to exercise their right of access was available within the app, it was noted that this form was positioned in such a way that it was difficult to access, being hidden under various menus.

The Authority also found that some documents provided by Uber to drivers were written in language that was difficult to understand; furthermore, the privacy policy failed to provide sufficient information regarding the retention periods for drivers’ data and the countries to which the data was transferred.

Although Uber argued during the appeal process that its privacy policy was compliant with the GDPR and that it had subsequently made improvements, the Authority ruled that these improvements did not remedy the previous infringements and upheld both the amount of the fine and the findings of infringement.

New Mexico Seeks $3.7 Billion in Penalties Against Meta in Child Safety Case

The US state of New Mexico has requested the court, in its ongoing child safety case against Meta Platforms, to rule that the company has undermined public health and safety and caused public distress.

As part of the case, the New Mexico Attorney General’s Office alleges that Meta designed its Facebook, Instagram and WhatsApp platforms in a way that fosters addiction among young users and has failed to adequately protect children from the risks of online exploitation.

Accordingly, Meta has been ordered to pay $3.7 billion and to implement comprehensive changes to its platforms to protect child users.

The measures sought include: strengthening age verification mechanisms, redesigning algorithms for child users, and restricting features such as autoplay and infinite scrolling for minors.

Meta, however, has argued that comprehensive measures for child safety already exist on its platforms and has contended that the requested measures constitute a regulatory intervention of such a broad scope that it cannot be imposed through judicial channels.

GRC LEGAL PERSPECTIVE

The case demonstrates that social media platforms can be held accountable not only for content moderation but also for product design, algorithmic steering, age verification and interface features that foster addiction, when it comes to child users.

This development highlights that regulations concerning the protection of children in digital environments are increasingly focusing on platform design and data processing practices on a global scale. It is therefore important for digital platforms to assess privacy, security and user experience processes in relation to child users as a whole.

Guidance from Italy on Deepfake Content

The Italian Data Protection Authority has issued a new warning regarding the production and sharing of deepfake content using images or audio recordings of real individuals.

The Authority has stated that AI-based services that generate content using individuals’ images or voices and facilitate the sharing of such content may pose serious risks to fundamental rights and freedoms, particularly where they are used in a manner that infringes on individuals’ privacy without their consent. It was emphasised that such uses could be subject to sanctions under European data protection legislation, in addition to potential criminal liability.

The statement also recalled that warning decisions had previously been issued regarding similar AI-based services; the Authority stated that broader powers of intervention were required to block access to such platforms from Italy, with a view to preventing the rapid spread of harmful content.

Privacy Recommendations from the CNIL Regarding the Use of Smart Glasses

The French Data Protection Authority (“CNIL”), has published a statement highlighting privacy risks associated with the use of smart glasses.

CNIL has pointed out that smart glasses containing sensors such as microphones and cameras carry the risk of unwittingly recording the images and voices of people in the vicinity. It was emphasised that, as these devices cannot be easily distinguished from conventional glasses, it is difficult for individuals to realise they are being recorded.

The statement noted that smart glasses can operate in conjunction with artificial intelligence systems; in this context, they can offer functions such as analysing the user’s surroundings, capturing video or audio, and generating real-time responses. The CNIL highlighted that this situation could increase the risk of invisible and widespread surveillance in everyday life.

In this context, the CNIL has made recommendations to smart glasses users: to inform people in their vicinity when using the device, to disable recording functions once the need has ceased, to avoid using the device in areas where people do not expect to be recorded, and to obtain the consent of the relevant individuals before sharing images or videos on social media.

GRC LEGAL PERSPECTIVE

The CNIL’s statement demonstrates that wearable technologies give rise to significant data protection risks not only concerning the user but also regarding third parties in the user’s vicinity. The primary risk with regard to smart glasses is that data processing activities are often invisible, and people in the vicinity may not realise that their images or voices are being recorded.

In particular, the processing of visual and audio data in conjunction with artificial intelligence systems requires a more careful assessment in terms of information provision, consent, data minimisation, purpose limitation and expectations of privacy. The use of these devices in public spaces, workplaces, healthcare facilities or private settings may give rise to different privacy risks depending on the specific circumstances of each case.

For this reason, during the development and roll-out of smart glasses, it is important to incorporate not only technical security measures but also privacy-by-design, default privacy settings, recording indicators, data retention periods and transparent mechanisms to protect the rights of third parties.

GRC CONCEPT OF THE MONTH

Data Sovereignty

Data sovereignty refers to having control over in which country, under which legal regime, by whom and with what security measures data is processed. With the acceleration of digitalisation, data has moved beyond being merely a technical or commercial element; it has become an asset with economic, strategic and legal value.

This concept is particularly significant in relation to the cross-border transfer of personal data, cloud services, intra-group data sharing, critical infrastructure, public systems and artificial intelligence applications. The country in which data is stored, who has access to it and the transfer mechanisms through which it is processed constitute a fundamental area of assessment from the perspectives of both personal data protection and corporate risk management.

The data sovereignty approach requires organisations to manage the lifecycle of personal data in a more transparent, auditable and accountable manner. In this context, it is important for data controllers to address data inventories, transfer processes, supplier relationships, access permissions, retention periods and security measures from a holistic compliance perspective.