Data Protection Board (DPB) Decision on the Practice of Retaining Photocopies of Identity Documents in the Accommodation Sector: A New Standard for the Sector

1. Introduction

Published in the Official Gazette No. 33102 dated 6 November 2025, the Data Protection Board’s (“Board”) “Principle Decision on the Recording of Photocopies of Turkish Identity Cards from Persons Receiving Accommodation Services”, published in the Official Gazette dated 6 November 2025 and numbered 33102, has established an important framework regarding data processing practices that have long been a subject of debate in the tourism and hospitality sector. In this context, the assessments regarding the collection and retention of identity document copies have introduced critical innovations aimed at strengthening compliance with the Personal Data Protection Law No. 6698 (“KVKK”) and ensuring that personal data processing activities in the accommodation sector are subject to clear, proportionate and purpose-related rules.

The Board’s decision in question constitutes a significant turning point both in terms of clarifying the boundaries of statutory obligations and safeguarding the rights and freedoms of data subjects; it necessitates that all accommodation establishments, including hotels, guesthouses and similar businesses, review their data processing procedures.

Legal Assessment of the Conditions for Processing Personal Data Under Article 5 of the KVKK

In the Board’s decision, Article 5 of the KVKK has been placed at the centre. According to this provision, the processing of personal data is, as a rule, subject to the explicit consent of the data subject. However, data processing is permissible without explicit consent in cases where it is expressly provided for by law; where it is directly related to the conclusion or performance of a contract; where it is necessary for the data controller to fulfil a legal obligation; where it is necessary for the establishment, exercise or defence of a legal claim; or where there are legitimate grounds within the scope of the data controller’s legitimate interests.

The Board’s inclusion of this provision in its decision necessitates an analysis of which processing condition the practice of taking a copy of an identity document relates to. Whilst the verification of identity information constitutes an obligation imposed on the data controller under Law No. 1774, the taking of a copy of an identity document does not form part of such an obligation. Consequently, it is clear that the practice in question cannot be assessed under the processing condition of ‘fulfilment of a legal obligation’. On this basis, the Board emphasises that the practice of taking photocopies of identity documents cannot be legally linked to any processing condition and states that it constitutes a breach of the Law in this respect.

  1. Assessment of Risks Related to Special Category Personal Data

One of the critical points highlighted in the decision is the likelihood of processing special category personal data—such as religion and blood type—contained in certain types of identity documents, as a result of the document being reproduced via photocopying. Under Article 6 of the KVKK, special category personal data are defined as data categories that increase the potential for individuals to face discrimination and are therefore subject to stricter protection measures. The processing of such data is strictly contingent upon the existence of exceptions provided for in the Law; these exceptions, other than explicit consent, must be interpreted narrowly and restrictively.

The Board, noting that old-style identity cards are still in use, draws attention to the fact that the practice of taking photocopies of identity documents may result in the processing of special category data without awareness of its nature. This finding demonstrates that the practice in question not only constitutes a breach of the principles of data minimisation and proportionality but is also of a nature that could infringe the legal regime governing information falling within the category of special category data. For this reason, the Board emphasises the necessity for accommodation establishments to reassess their current practices and implement measures to eliminate the risk of processing special category data as soon as possible.

4. The Fate of Data Sets from Previous Periods and the Obligation to Destroy

The decision also includes a comprehensive assessment of the legal status of identity photocopies collected in previous periods and clearly states that, within the framework of Article 7 of the KVKK, the destruction of these data is mandatory if they are retained without a legal basis for processing. In this context, data controllers must systematically review the identity photocopies currently in their possession and eliminate any data that cannot be linked to a processing condition using one of the methods of deletion, destruction or anonymisation. The fulfilment of this obligation is of fundamental importance not only in terms of ensuring data security but also in terms of avoiding any legal and administrative sanctions that the data controller may face in the future.

In this context, it is clear that accommodation establishments must carry out their destruction activities in a manner that is documentable, auditable and consistent with the principles set out in the Board’s decisions and the Authority’s guidelines. The integration of destruction processes into corporate policies, the updating of internal procedures, and the provision of instructions to staff in this regard constitute a natural extension of the data controller’s accountability obligation. Furthermore, the revision of information notices and operational instructions for staff in line with this Decision is a necessity both to fulfil the principle of transparency and to ensure the sustainability of lawful data processing practices.

5. Conclusion

In conclusion, the Board’s Decision sets out the general principles, processing conditions and special categories of personal data as stipulated in both it serves as a significant milestone in clarifying how the general principles, processing conditions and restrictions on special category personal data set out in both the Identity Reporting Act No. 1774 and the Personal Data Protection Act No. 6698 should be applied to this sector. The Decision requires that, for businesses providing accommodation services, data processing procedures be limited solely to identity verification and reporting obligations; that the practice of obtaining non-mandatory identity photocopies be discontinued; and that the data obtained be used in a manner that is appropriate to the purpose, proportionate and transparent at every stage.

Leave a Comment

Your email address will not be published. Required fields are marked *