- November 1, 2025
Data Protection and Compliance Bulletin – October 2025
Contents
TogglePersonal Data Protection Law is a constantly evolving and updating area of law, governed by the Personal Data Protection Law No. 6698 (“KVKK” or “Law”) and its secondary regulations. Practices in this area are not limited to the Law and related regulations; they are shaped and concretized by the decisions, policy decisions, and decision summaries of the Personal Data Protection Board (“Board”). In this context, the KVKK Bulletins, prepared on a monthly basis, serve as a resource for those who wish to follow current developments in the field of data protection, aiming to provide up-to-date information and keep stakeholders informed.
In October, recognized globally as Cyber Security Awareness Month, the Personal Data Protection Authority (“Authority”) published four data breach notifications on its website, www.kvkk.gov.tr, and issued a “Public Announcement Regarding the Exception Criteria for the VERBİS and provided recommendations regarding Cybersecurity Awareness Month.
CYBER SECURITY AWARENESS MONTH
October is the official awareness period in the European Union, during which cyber awareness events are held every year as part of the European Cybersecurity Month (“ECSM”). ECSM, coordinated by the European Union Agency for Cybersecurity (“European Union Agency for Cybersecurity”, “ENISA”) and the European Commission, highlights themes of cyber hygiene, best practices, and preparedness against current threats for citizens and organizations. Throughout the month, training sessions, seminars, exercises, and public events are organized across Europe.
#THINKB4UCLICK: Under the ECSM, ENISA particularly emphasizes that phishing attacks are still the most common initial intrusion method, with the motto “think before you click.” It reminds us that in 60% of cyber security incidents, initial access is gained through fake emails/SMS/messages, making pre-click checks and awareness of suspicious content critical.
The Personal Data Protection Authority (“Authority”) draws attention to the direct link between cybersecurity and the protection of personal data with its recommendations for cybersecurity awareness month and emphasizes the implementation of basic cybersecurity hygiene steps in conjunction with KVKK obligations.
DATA BREACH NOTIFICATIONS
Pursuant to Article 12/5 of the KVKK, if personal data processed is obtained by third parties through unlawful means, the data controller is obliged to promptly notify the relevant person and the Board of this situation. Within the framework of the aforementioned provision, the Board may, if it deems necessary, announce the data breach to the public via its website or by other means it deems appropriate. This regulation has been introduced to ensure the effective management of data breaches and the timely notification of the relevant persons.
Mango
Mango T.R. Tekstil Tic. Ltd. Şti., acting as the data controller, has notified the Board that some customer data has been accessed by unauthorized persons as a result of a cyber attack on its digital marketing infrastructure. According to the report, the breach occurred between October 6, 2025, and October 10, 2025, and was detected on October 10, 2025. It was determined that the breach occurred as a result of the leakage of administrator credentials used to access the API of the digital marketing email system platform used by Mango, and that unauthorized access to customer data was gained through this method. It was stated that the attack targeted Mango’s headquarters in Spain and affected customers in many countries, including Turkey.
It was stated that the personal data affected by the breach included name (excluding surname), country, postal code, phone number, and email address; there was no breach of passwords, financial data, or payment information. Mango Turkey reported to the Board that 4,349,620 individuals were affected by the breach.
Following the incident, Mango announced that it had notified the AEPD (Spanish Data Protection Authority), that the company’s infrastructure and corporate systems were not affected by the attack, and that online operations continued uninterrupted. Customers were also warned to be cautious against fraud attempts that could be carried out through phishing and social engineering methods.
Cleverbridge GmbH
In the notification submitted to the Board by Cleverbridge GmbH, acting as the data controller, it was stated that the breach occurred on September 10, 2025, and was detected on September 15, 2025, that the data breach occurred as a result of unauthorized access to the customer database, and that access was blocked due to unusual use of the API. The personal data affected by the breach included name, company, email, payment method, last 4 digits of the card, card expiration date, and product and billing details. The Board was informed that customers and potential customers were affected by the breach, with a total of 1,235 individuals affected by the data breach.
Haydigiy E-Ticaret Tekstil Sanayi ve Ticaret Limited Şirketi
In the notification sent to the Board by Haydigiy E-Ticaret Tekstil Sanayi ve Ticaret Ltd. Şti., acting as the data controller, it was stated that the exact start date of the breach could not yet be determined, but that the incident was detected on October 15, 2025. The data controller reported that, upon investigating suspicious transaction reports submitted by some customers, it had determined that an unauthorized access had been gained to an administrator account and code had been added to the site through this account. It was stated that subscribers/members, customers, and potential customers were affected by the breach; the categories of personal data subject to the breach were communication, location, and financial information.
İstanbul Golf İhtisas Spor Kulübü
In the notification submitted to the Board by the Istanbul Golf Specialized Sports Club, acting as the data controller, it was stated that the breach was detected on October 15, 2025, upon the appearance of a message containing a ransom demand on the data controller’s computer. It was stated that an attempt was made to encrypt the files on the computer, but this process was not completed. It was reported that subscribers/members were affected by the breach and that the personal data subject to the breach included identity (Turkish ID number), contact (email, mobile/office phone), location (address), personal (marital status, criminal record), and professional experience information.
GRC LEGAL Comment: In this period, where the importance of cybersecurity awareness is once again being emphasized, looking at the data breaches reflected in the public domain, it can be seen that unauthorized access related to API and account security, compromise of administrator accounts, and ransomware attacks are being encountered. This picture shows that, although the initial intrusion vectors may appear different, the breaches essentially share common denominators such as weak authentication, inadequate access controls, and lack of cybersecurity preparedness.
In this context, it is crucial that the technical and administrative measures envisaged under Article 12 of the KVKK are not limited to documentation; strong authentication policies must be implemented, supplier security must be assessed using a risk-based approach, response plans for cybersecurity incidents and data breaches must be tested regularly, and employee awareness must be maintained through periodic training.
However, it is evident that the obligations introduced by the Cybersecurity Law No. 7545 directly intersect with personal data protection obligations. Companies must design their KVKK compliance in an integrated manner, not separately from their cybersecurity strategies; they must address data protection, information security, and business continuity management systems together. Otherwise, addressing technical system security independently from the KVKK and data protection processes independently from information security creates weak links in the defense chain. Even a seemingly minor password vulnerability can lead not only to data breaches but also to damage to corporate trust and operational continuity.
DEVELOPMENTS IN TURKEY
VERBİS Registration Obligation Exemptions Expanded!
With the Board’s decision dated 04.09.2025 and numbered 2025/1572, a new exemption has been introduced regarding the VERBİS registration obligation for data controllers whose main activity is the processing of special category personal data. Accordingly, data controllers with fewer than 10 employees and an annual balance sheet total of less than 10 million TL will now also be exempt from the VERBİS registration obligation. Thus, the scope of the exemption previously granted only to small-scale data controllers whose main activity was not the processing of special category personal data has been expanded. Following the relevant decision, the Data Controllers Registry Information System (VERBİS) Guide and the VERBİS Guide with Questions have also been updated accordingly.
GRC LEGAL Comment: This regulation aims to reduce the administrative and financial burden, particularly for micro-scale entities such as medical practices, dental clinics, pharmacies, psychological counseling centers, laboratories, imaging centers, and dietitians, and is expected to provide significant practical benefits. However, it should be noted that the exemption from VERBIS registration does not eliminate other obligations under the KVKK, such as the data controller’s obligation to provide information, the implementation of technical and administrative measures, ensuring data security, carrying out storage and destruction processes, and responding to data subject requests.
KVKK Amendments in the Private Health Insurance Regulation
The Regulation Amending the Private Health Insurance Regulation, published in the Official Gazette dated October 20, 2025, introduces important innovations regarding the protection of personal data in the insurance sector. The amendments aim to ensure the preservation of health data, determine storage periods, observe the conditions for processing special categories of personal data, ensure confidentiality obligations, and achieve full compliance with the KVKK. The regulation appears to aim to create a structure consistent with the amendments made to the KVKK last year. You can click here to access our detailed study on the subject.
WORLDWIDE DEVELOPMENTS
IKEA Fined for Camera Placement
The Austrian Data Protection Authority ruled that a surveillance system consisting of nine cameras used in an IKEA store violated Articles 5/1-a, 5/1-c, and 6/1 of the European Union General Data Protection Regulation (“GDPR”) by recording customer movements over a wide area and PIN entries at payment points to an excessive degree, and imposed a fine of €1,500,000 on the company. – “GDPR”) Articles 5/1-a, 5/1-c, and 6/1, and imposed an administrative fine of €1,500,000.
The investigation was initiated following an anonymous complaint and found that the recordings were made between March 2022 and May 2022, during which time the PIN entries of approximately 637 customers were viewed. The Authority determined that the surveillance was not proportionate to the purpose, that it violated the principle of data minimization, and that there was no valid legal basis for the processing. Furthermore, the fact that the surveillance areas included high-traffic public transit zones was also criticized.
Although the company argued in its appeal that some of the recordings did not constitute personal data, that the security objective outweighed other considerations, and that the penalty was disproportionate, the Administrative Court found the appeal justified only with regard to the positioning of two cameras and ruled that the violation continued with respect to the other seven cameras.
The court deemed the choice of continuous, wide-angle surveillance, despite the availability of less intrusive surveillance options, to be excessive; it also characterized the company’s failure to remedy known problems for weeks as “gross negligence.”
French Data Protection Authority Fines Company Using Hidden Cameras
The French Data Protection Authority (“CNIL”) decided to impose an administrative fine of €100,000 on a retail company that installed cameras disguised as smoke detectors with audio recording capabilities in storage areas for unlawfully processing employees’ personal data.
Following an investigation initiated by an employee’s complaint, it was determined that five hidden cameras with microphones installed in storage areas had been recording video and audio of employees for several weeks. After employees noticed the devices, removed them, and accessed the SD cards, the company reported the data breach to the CNIL.
In its defense, the company argued that the cameras were used as part of a “test installation” to analyze the risk of theft, that they were not intended for employee monitoring, that it was unaware of the microphone feature, and that the system should not be considered “hidden cameras.” However, the CNIL did not find these defenses valid. The following findings were highlighted in the CNIL’s decision:
- The installation of hidden cameras violates the principles of data minimization and transparency.
- • Audio recording clearly violates the principle of proportionality.
- • Failure to involve the Data Protection Officer (DPO) in the process in a timely manner constitutes a violation of GDPR Article 38(1).
- • The principles of fair processing and transparency have been violated due to the failure to inform employees.
- • The use of hidden cameras is only possible in exceptional and temporary circumstances, in accordance with the case law of the European Court of Human Rights.