- October 1, 2025
Data Protection and Compliance Bulletin – September 2025
Contents
ToggleData Protection Law is a constantly evolving and updating field of law, governed by the Personal Data Protection Law No. 6698 (“KVKK” or “Law”) and its secondary regulations. Practices in this field are not limited to the Law and related regulations; they are shaped and concretized by the decisions, principle decisions, and decision summaries of the Personal Data Protection Board (“Board”). In this context, the KVKK Bulletins prepared on a monthly basis serve as a resource for those who wish to follow current developments in the field of data protection, aiming to provide up-to-date information and keep stakeholders informed.
In September 2025, one data breach notification was published on the website of the Personal Data Protection Authority (“Authority”) at www.kvkk.gov.tr.
Additionally, the Medium-Term Program for 2026-2028 (“Program”), published in the Official Gazette dated 07.09.2025 and numbered 33010, announced that the work to harmonize the KVKK with the European Union General Data Protection Regulation (“General Data Protection Regulation”, “GDPR”). The Program envisages the harmonization of the Law with the European Union Artificial Intelligence Regulation, the preparation of necessary regulations in the field of cybersecurity taking into account the European Union acquis, and the establishment of a national policy framework to accelerate the transition to a data economy. In this context, it has been stated that umbrella legislation and infrastructure related to data governance will be established, and a National Data Strategy and Action Plan that protects data privacy and security will be implemented.
DATA BREACH NOTIFICATION
Pursuant to Article 12/5 of the KVKK, if personal data processed is obtained by third parties through unlawful means, the data controller is obliged to promptly notify the relevant person and the Board of this situation.
Within the framework of the aforementioned provision, the Board may, if it deems necessary, announce the data breach to the public via its website or by other methods it deems appropriate. This regulation has been introduced to ensure the effective management of data breaches and the timely notification of the relevant persons.
Sinch AB[1]
According to the data breach notification submitted to the Board by Sinch AB, acting as the data controller, the breach occurred between August 28, 2025, and August 30, 2025, through computer hacking.
Users were affected by the breach; the personal data disclosed included names, email addresses, addresses, the last 4 digits of credit cards, card types (Visa, Mastercard, etc.), and credit card expiration dates. While investigations into the matter are ongoing, it has been reported that a total of 716 people were affected by the breach.
GRC LEGAL Comment: The data breach reported by Sinch AB once again highlights the sensitivity of financial data. The exposure of credit card information (even if only limited data such as the last four digits and card type) is critical in terms of user security and financial fraud risks. This situation makes it mandatory for all companies that process payment systems and user account information to implement advanced security measures against cyber attacks. Furthermore, considering that companies operating internationally also process the data of users in Turkey, it is once again clear that the obligations under the KVKK must be considered not only locally but also on a global scale.
WHAT’S HAPPENING IN THE NEWS?
NEWS FROM TURKEY
Public Audit Institution’s Decision: “Personal Information on Institution Cards Must Be Hidden”
According to a September 5, 2025, report by Anadolu Agency, the Public Audit Institution (“KDK”) found the applicant requesting the concealment of personal information on their identity card issued by their employer to be justified, contacted the relevant institution, and ensured that a new identity card without personal data was issued.
In this specific case, an individual working for a public institution with a special budget applied for a replacement identity card after losing their original card. They expressed discomfort with the fact that information such as their mother’s name, father’s name, date of birth, and place of birth were clearly visible on the card and requested that the new card only include their first name, last name, title, province of employment, and institution registration number. The relevant institution rejected the request; upon the applicant’s appeal to the KDK, the Authority found the applicant to be justified, contacted the relevant institution to have the request met, and as a result of the KDK’s initiative, the institution prepared and delivered a new institutional ID card to the applicant that did not contain personal information.
GRC LEGAL Comment: This decision by the KDK once again clearly highlights the importance of the principle of data minimization. The inclusion of personal data that does not serve the purpose, such as parents’ names, full date of birth/place of birth, on tools that are constantly visible and at high risk of loss/theft, such as ID cards, can pose serious risks if the card is lost or seen by third parties and can lead to data breaches. It would be appropriate for institutions to limit the information on ID card designs to the minimum necessary, such as name, surname, photo, title/unit, institution name, personnel/registration number, and validity date. If additional information is required, it should be displayed only to authorized persons via QR/NFC with role-based access.
Cybersecurity Law Applied for the First Time: Investigation into the Acquisition and Sale of Personal Data
According to a report published by Hürriyet on September 15, 2025, the Ankara Chief Public Prosecutor’s Office has filed an indictment against seventeen suspects for illegally obtaining the personal data of millions of citizens and high-level bureaucrats and selling and sharing it on a website. It has been stated that the suspects used images of President Tayyip Erdoğan, as well as celebrities such as Oğuzhan Uğur and Haluk Levent, to create fake advertisements.
Following the incident, nine suspects were detained, and they face up to 15 years in prison for “personal data violation, possession of prohibited devices and programs, and violation of the Cyber Security Law.”
The indictment found that the website hosted malicious software links, stolen credit card information, unauthorized access attempts to public institution systems, and the sharing of personal data for monetary gain, prompting the launch of an investigation. It was determined that the site was established in 2021 and remained active until 2023, that its IP location information was in the Netherlands, that it had 24,188 members, and that the suspects’ devices contained a set of personal data belonging to approximately 101 million Turkish citizens. These sets included data such as Turkish ID numbers, addresses, Social Security and bank records, vehicle license information, title deeds, education, and professional information.
The indictment stated that the suspects not only sold data but also had private message transcripts, sexually explicit images, and confidential documents on their devices; it was noted that this content was systematically used for blackmail. Additionally, it was understood that they produced fake diplomas, mastery, or apprenticeship certificates by infiltrating the critical systems of public institutions.
The indictment interpreted the concept of “cyberspace” to include not only the internet but also closed-circuit systems connected to the internet, emphasizing that the unlawful acquisition of data within this scope constitutes a crime.
GRC LEGAL Comment: This case is noteworthy as it is the first time the Cyber Security Law, which came into force in March 2025, has been the subject of an indictment; it is an important turning point at the intersection of personal data protection and cyber security legislation. While the unlawful acquisition of personal data is currently subject to severe penalties under the KVKK, with the new Cyber Security Law, such actions are now assessed within a broader framework and under the threat of higher penalties.
WORLD NEWS
European Union Data Act Enters into Force
According to a statement by the European Commission, the European Union Data Act (“EU Data Act”), which was adopted on June 28, 2023, and has been in preparation for a long time, entered into force on September 12, 2025. The regulation aims to ensure the fair use of data in the digital economy, facilitate user access to data generated by their devices, and promote more transparent data sharing.
The regulation covers data obtained from Internet of Things (“IoT”) devices such as smart home products, wearable technologies, industrial machines, and connected vehicles. This will give users the right to directly access the data generated by their devices and share this data with third parties if they wish. Public authorities will also be able to access private sector data in exceptional circumstances, enabling faster and more effective solutions to be developed for public services.
The Commission emphasizes that the regulation will also create a competitive advantage for SMEs, prohibit unfair contract terms relating to data sharing, and facilitate easier migration between cloud services. Provisions regarding the protection of trade secrets and the blocking of unlawful data requests from outside the European Union are also included in the regulation.
GRC LEGAL Comment: The implementation of the EU Data Act as of September 12, 2025, demonstrates that the data economy in the European Union has been reorganized around the axes of “user access, fair sharing, and portability.” At the same time, it introduces comprehensive rules on the use of device and industrial data, independent of personal data, and takes on the role of being an important precursor to steps that will be taken to regulate the data economy and increase competition.
[1] The relevant data breach was published on the Authority’s website on September 23, 2025.