Data Protection and Compliance Bulletin – November 2025

Data Protection Law is a constantly evolving and updating field of law, governed by the Personal Data Protection Law No. 6698 (“KVKK”) and its secondary regulations. Practices in this field are not limited to the Law and relevant regulations; they are shaped and concretised by the decisions, principle decisions, and decision summaries of the Personal Data Protection Board (“Board”).

In this context, the PDPL Bulletins, prepared on a monthly basis, serve as a resource for those wishing to follow current developments in the field of data protection, aiming to provide up-to-date information and keep stakeholders informed.

The protection of personal data is of great importance in terms of guaranteeing fundamental rights and freedoms. In this context, it is both an obligation and a requirement of the compliance process for data controllers to act in accordance with the law and the rules of good faith in all kinds of operations involving personal data.

In November, the Personal Data Protection Authority (‘Authority’) published an ‘Announcement on Permitting the Transfer of Personal Data Abroad with Agreements Not of an International Treaty Nature’ on its website, www.kvkk.gov.tr, which closely concerns data transfer processes abroad. In addition, the ‘Guide on Generative Artificial Intelligence and the Protection of Personal Data (15 Questions),’ one of the most critical topics at the intersection of technology and law, was shared with the public.

Developments in Turkey

Guide on Generative Artificial Intelligence and Personal Data Protection Published!

On 24 November 2025, the Authority published a comprehensive guide detailing the impact of Generative Artificial Intelligence (‘GAI’) systems, which are at the heart of digital transformation and innovation, on personal data protection law.

This Guide, prepared by the Authority, arose from the need to evaluate the ethical, legal, and social risks that accompany the opportunities offered by artificial intelligence technologies. The main purpose of the Guide is to encourage an approach that respects individuals’ privacy in the development and use of PAIs and to provide guidance to actors who are data controllers in terms of personal data processing activities carried out throughout the life cycle of these systems.

The Guide highlights the fundamental models trained on large data sets that underpin the content generation capacity of AI systems, emphasising the great importance of developing and implementing these systems with an approach that is respectful of human rights and fundamental freedoms, transparent, auditable, and human-centred.

The Guide also contains important recommendations for individuals using AI systems. It states that users should be careful when providing personal data such as their name, surname, address, telephone number, and identity information to these systems in order to ensure data security, and should refrain from sharing information about their private lives. Finally, it is recommended that they control their personal data sharing permissions and carefully review the data collection and storage policies of GAI systems.

GRC LEGAL Commentary

The ‘Guide on Generative Artificial Intelligence and the Protection of Personal Data’ published by the Authority is of critical importance as it provides a concrete compliance framework that data controllers have long needed in the rapidly evolving field of technology.

The Guide clearly emphasises that AI systems must be developed and managed in accordance with the ‘Privacy by Design’ principle from the outset, reminding us that this is not only a legal obligation but also a fundamental element of ethics and accountability.

In particular, the requirement to separately determine the legal basis for personal data processing in accordance with the KVKK at different stages, such as the training and operation of the artificial intelligence model, is one of the most important issues that must be carefully managed in practice. In this regard, data controllers are required to conduct comprehensive Impact Assessments and Risk Evaluations in order to proactively manage the risks of algorithmic discrimination and violation of the data minimisation principle that may arise from AI outputs.

The Guide also emphasises that transparency and disclosure obligations must be fulfilled with greater sensitivity due to the complexity of AI processes. It is crucial to provide clear and understandable information to data subjects about whether data is used for development purposes, which data categories are processed, and the system’s default settings. Finally, effective mechanisms must be established without delay to enable users to easily exercise their right to object.

Announcement Published on Permitting the Transfer of Personal Data Abroad under an Agreement that is not an International Treaty!

In its assessment under Article 9/4-a of the Law and Article 11 of the Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad, the Board On 21 October 2025, it decided that the arrangement signed between the Ministry of Interior’s Directorate General of Migration Management and the United Nations High Commissioner for Refugees regarding the transfer of personal data abroad, which is characterised as an “agreement not constituting an international treaty”, could be accepted as a basis enabling transfer within the scope of the relevant article.

GRC LEGAL Commentary

The relevant authorisation constitutes an important example of the application of data transfers carried out through texts that have an international cooperation nature but do not have the status of a traditional international agreement. In this context, it is seen that the Board’s assessment is based on the legal basis for the transfer, the distribution of obligations between the parties, commitments regarding data security, and guarantees regarding the transfer process. The decision is particularly important in that it provides clarity on how personal data transfers between public institutions and international organisations can be legally justified in the context of operational cooperation.

Istanbul Governorate’s 24-Hour Audio and Video Recording Requirement for Businesses in the Context of Food Safety

Following the poisoning incidents in Istanbul, an important regulatory decision was taken for all businesses in the city as a result of the ‘Food Safety Meeting’ chaired by Istanbul Governor Davut Gül. This decision imposes an obligation on businesses to make 24-hour uninterrupted audio and video recordings and to retain these recordings for 30 days.

This regulation, adopted by the Istanbul Governorate and expected to be implemented rapidly, has brought to the fore the intersection between administrative measures aimed at protecting public health and constitutional and legal principles relating to the protection of personal data. Although the Governorate has the authority to regulate in order to maintain public order in the field of food safety, the scope of the obligations imposed has created a new area of debate that needs to be assessed in terms of the principles of proportionality, data minimisation and purpose limitation, which are important in data protection law.

GRC LEGAL Commentary

Extensive obligations, such as recording sound and images 24 hours a day in businesses, are linked to the public authority’s goal of ensuring food safety on the one hand, while on the other hand, they give rise to new debates on how these practices can be reconciled with fundamental data protection principles such as proportionality, data minimisation, and privacy boundaries. At this point, it should be noted that even if the regulation is implemented, data controllers remain obliged to act in accordance with the fundamental principles set out in Article 4 of the KVKK—particularly the principles of purpose limitation, proportionality, and the prohibition of recording in private areas.

In the coming period, how a balance will be struck between public health justifications and constitutional guarantees regarding the protection of personal data, and how this balance will be reflected in practice, has become a topic to be followed both in administrative practice and in doctrine.

Developments from Around the World

Meta Ordered to Pay €479 Million in Damages in Spain for Data Breach

A Spanish court has ordered Meta to pay a total of €479 million in damages to 87 digital media organisations on the grounds that it used user data for personalised advertising activities without explicit consent. The ruling found that Meta tracked user behaviour through its advertising technologies, processed this data to create detailed profiles, and failed to provide sufficient control tools for data usage to the individuals concerned. The court ruled that these practices violated both Spanish data protection legislation and the European Union’s General Data Protection Regulation (GDPR).

GRC LEGAL Commentary

This ruling once again emphasises the importance of transparency in the processing of user data for commercial purposes, the requirement to obtain explicit consent, and the principles of data minimisation in targeted advertising processes. In particular, the extensive data processing activities carried out by large technology companies within the framework of behavioural advertising models are being increasingly scrutinised by European countries.

This decision demonstrates that data protection authorities globally are increasingly inclined to apply broader sanctions by jointly assessing competition law, consumer rights, and personal data protection areas. In this context, it is critically important for data controllers to reassess compliance risks related to consent management, profiling transparency, user control mechanisms, and third-party data sharing processes when designing targeted advertising activities.

LinkedIn’s Decision to Process User Data by Default for Artificial Intelligence Training

LinkedIn, the leading social network for the business world, announced that it will begin using personal data, including user profiles, posts, CVs, and public activities on the platform, to train and develop artificial intelligence models from 3 November 2025. The most notable aspect of this application is that the relevant setting will be enabled by default (opt-in) unless manually disabled by users.

LinkedIn has stated that it considers this default setting to be within the legal framework, particularly in regions where European Union and similar regulations apply, under the legal basis of ‘legitimate interest’. It has been clarified that even if users exercise their right to object, this will only apply to data collected after the date of objection, and previously collected information will remain in the artificial intelligence training environment.

GRC LEGAL Commentary

This decision raises important questions regarding the principles of data minimisation and transparency, which are fundamental principles of data protection law, as well as the effective objection mechanisms provided for in the GDPR and similar legislation. It is anticipated that global data protection authorities will scrutinise the legal basis for the data used to train artificial intelligence systems, the extent to which data controllers assess the risks to the fundamental rights and freedoms of data subjects in this process, and how the limits of the obligation to delete data in the event of an objection will be determined.