GRC PERSPECTIVE: DATA PROTECTION & COMPLIANCE NEWSLETTER – JULY 2026

WHAT’S HAPPENING IN TURKEY?

A Policy Decision on the Sharing of Personal Data Online by Data Controllers with Public Legal Personality Has Been Published!

The ‘Principle Decision on the Sharing of Personal Data on the Internet by Data Controllers with Public Legal Personality’ was published in the Official Gazette dated 28 July 2026.

The Personal Data Protection Board (“Board”) has issued a decision regarding the sharing of personal data online by data controllers with public legal personality, such as local authorities, provincial special administrations and universities, in documents published on their websites, including first name and surname, Turkish Republic identity numbers, addresses and mobile phone numbers, place of work and job title, educational and military service status, plot/parcel information, KPSS scores and examination results, and information on main and reserve candidate status; it emphasised that the publication of documents containing personal data on the internet constitutes, in itself, a personal data processing activity.

The ruling stated that the sharing of personal data online must be based on a valid condition for the processing of personal data as set out in Article 5 of the Law on the Protection of Personal Data (“Law”) (or Article 6 in the case of special categories of personal data); it was further noted that, in the absence of such conditions, it would be appropriate not to share the data. Furthermore, it was stated that even where a valid condition for processing exists, compliance with the general principles set out in Article 4 of the Act is mandatory. In this regard, it was emphasised that only the necessary and minimum amount of personal data should be shared; unnecessary personal data should be protected by means of masking or destruction; the duration of the sharing should be determined in advance; and the sharing should cease upon the expiry of this period.

The Board also reiterated that, under Article 10 of the Act, data controllers must fulfil their duty to provide information in accordance with the relevant provisions of the Communiqué, and that the burden of proof regarding the fulfilment of this duty rests with the data controller. Under Article 12 of the Act, it was stated that, given the higher data security risks posed by the internet, the necessary administrative and technical measures must be taken, and that data controllers must carry out the necessary audits within their own organisations or ensure that such audits are carried out.

The ruling states that documents containing personal data currently published online must be reviewed without delay; content of an unlawful nature must be removed or redacted; and, where the purpose of processing personal data no longer applies, data must be destroyed. Furthermore, it was noted that, except in exceptional circumstances dictated by the specific case, it would be appropriate for examination and lottery results to be published in such a way that only the individual concerned can access their own result; in this context, it was stated that the e-Government Portal or similar methods providing two-factor authentication should be preferred.

Furthermore, it was emphasised that training and awareness-raising activities should be carried out regularly for all staff, particularly those responsible for the use of the relevant platforms. The Board has stated that the aforementioned principles and measures apply not only to data shared on websites but also to the sharing of personal data in internal and inter-organisational correspondence, email messages, announcements, closed electronic environments, and on noticeboards and bulletin boards.

Finally, the Board stated that should a failure to fulfil the specified obligations be identified, each specific case would be assessed in light of its own circumstances, and the necessary administrative proceedings would be initiated against the relevant data controllers in accordance with Article 18 of the Act.

GRC LEGAL PERSPECTIVE

This principle decision clearly demonstrates that the long-standing practice of public institutions publishing documents online requires reassessment from the perspective of data protection law.

Whilst emphasising that the principles of transparency and accountability must be applied in a manner that strikes a balance with the right to the protection of personal data, the decision requires public bodies to review their current practices regarding matters such as data minimisation, retention periods and access authorisation. In particular, the approach of designing announcements, examination results and similar notices so that they are accessible only to the relevant individuals demonstrates the growing importance of a ‘privacy-by-design’ approach in the digitalisation of public services.

Public Notice Published on the Use of Personal Data Obtained from Third Parties for Advertising and Marketing Purposes!

The Personal Data Protection Authority (‘’Authority’’) has published the “Public Notice on the Use of Personal Data Obtained from Third Parties for Advertising and Marketing Purposes”.

The notice states that the Authority has received a large number of complaints regarding data controllers using contact details obtained from their existing customers or third parties—through methods such as referrals, recommendations, customer suggestions or brand ambassadorship—in their advertising and marketing activities.

Investigations revealed that marketing calls and text messages were sent without the necessary information having been provided to the data subjects and without their explicit consent having been obtained.

The Authority has emphasised that the fact that personal data has been obtained from third parties does not, in itself, constitute a legal basis for the processing of such data for advertising and marketing purposes. In this context, it has been stated that the conditions for the processing of personal data set out in Article 5 of the Act must be assessed separately for each specific case where personal data is to be used in advertising and marketing activities.

The announcement also stated that, in cases where personal data is not obtained directly from the data subject, data controllers must, in accordance with the Communiqué on the Procedures and Principles to be Followed in Fulfilment of the Duty to Inform: they are obliged to inform the data subject within a reasonable period following the collection of personal data; if the data is to be used to contact the data subject, this must be done at the time of the first contact; and if the data is to be transferred to third parties, this must be done no later than the time of the first transfer.

Furthermore, whilst it has been observed in practice that behaviours such as the data subject not ending the conversation, continuing to listen to the campaign, requesting information, or failing to reply ‘no’ to a text message are often interpreted as constituting explicit consent; it has been particularly emphasised that such implicit behaviours do not constitute valid explicit consent within the meaning of the Act.

The Authority has once again reiterated that explicit consent must be a declaration of intent relating to a specific matter, based on information provided and expressed of one’s own free will, and that the duty to provide information and the process of obtaining explicit consent are separate obligations.

Consequently, the Authority has stated that, in the processing of personal data obtained from third parties within the scope of advertising and marketing activities, actions must be taken in accordance with the Law and relevant legislation, the duty to provide information must be fulfilled in accordance with the prescribed procedures, and, where necessary, explicit consent must be obtained separately; it has also announced to the public that sanctions may be imposed on the relevant data controllers should any practices contrary to these obligations be identified.

GRC LEGAL PERSPECTIVE

This announcement clearly demonstrates that the practice of ‘obtaining contact details through referrals’, which has long been widely used in marketing activities, cannot automatically be deemed lawful under the KVKK.

In particular, it has once again been emphasised that commercial expectations and obligations regarding the protection of personal data must be assessed independently of one another, especially in customer acquisition processes. For this reason, it is important for companies to review not only their marketing communication processes but also their lead generation, referral programmes and brand ambassador schemes from the perspective of data protection law.

Regulation Amending the Regulation on Personal Health Data Published!

The “Regulation Amending the Regulation on Personal Health Data”, published in the Official Gazette dated 4 July 2026, introduces amendments regarding the rectification and reassessment of personal health data.

With these amendments to the Regulation, the title of Section Four has been changed to “Confidentiality, Rectification, Re-evaluation, Destruction and Transfer of Personal Health Data”, thereby incorporating new provisions regarding the re-evaluation of personal health data into the scope of the Regulation.

In accordance with the amendments, it is stipulated that the procedures established by the General Directorate regarding requests for the correction of personal health data must also be carried out in the database of the relevant healthcare provider. Furthermore, it has been stipulated that the question of whether the necessary procedures will be carried out in the databases of other institutions and organisations processing the data shall be assessed by the relevant institution or organisation in accordance with the provisions of the relevant legislation.

Article 13/A, added to the Regulation, grants individuals the right to request that health diagnoses previously made about them be reassessed on the basis of their current state of health. Accordingly, diagnoses made by a single doctor shall be reassessed by a three-doctor medical board; diagnoses made by a three-doctor medical board or a fully-fledged medical board shall be reassessed solely by a fully-fledged medical board. Should the reassessment determine that the relevant diagnosis is not present in the individual’s current state of health, a medical board report stating this finding shall be issued.

Furthermore, it has been explicitly stipulated that no action may be taken based on diagnoses determined by a medical board report to be absent from the individual’s current state of health. In this context, it has been stipulated that diagnoses established in the past but found not to be present in the current state of health, as evidenced by a medical board report, shall not be taken into consideration—particularly in recruitment processes; instead, the medical board report stating the current status, issued as a result of the re-evaluation, shall serve as the basis.

Principle Decision on the Processing of Personal Data of Accident Victims Published!

The Principle Decision, published by the Authority in the Official Gazette dated 01.07.2026, sets out findings and assessments regarding the unlawful processing of personal data belonging to victims following incidents such as road traffic and workplace accidents.

The Decision states that certain individuals and organisations operating under the guise of ‘damage consultancy’, as well as persons presenting themselves as solicitors but lacking actual authorisation, have contacted accident victims without their consent; it is further noted that, during this process, the victims’ identity and contact details were obtained unlawfully through various channels.

The Board emphasised that such activities may breach the limits of authorisation set out under the Lawyers’ Act No. 1136 and the Insurance Act No. 5684; furthermore, it stressed that a clear breach would occur if the legal conditions required for the processing of personal data under the provisions of the Act were not met. The Principle Decision also states that activities carried out using personal data obtained or shared without authorisation may constitute an offence under Article 136 of the Turkish Penal Code, and that legal proceedings may be initiated depending on the specific circumstances of each case.

With regard to insurance adjusters and similar authorised actors, it was stated that personal data processing activities may only be carried out within the framework of duties defined by legislation, for example, for the purposes of damage assessment and the conduct of insurance processes; it was further noted that exceeding these limits would constitute a breach of the Personal Data Protection Law (KVKK).

The Board also emphasised that data controllers are obliged to ensure data security under Article 12 of the Law; in this context, it is mandatory to prevent unauthorised access, establish role-based access controls, train staff and take the necessary technical and administrative measures.

Finally, it was stated that administrative sanctions may be imposed under Article 18 of the Act on data controllers who act in breach of these obligations; furthermore, it was noted that such cases may be reported to the judicial authorities and other competent bodies.

GRC LEGAL PERSPECTIVE

The amendment to the Regulation treats not only the proper storage of health data but also the maintenance of its up-to-date status as a key element of data protection law. Whilst this approach aims to prevent past health diagnoses from having lasting consequences for individuals, it also necessitates that healthcare providers and employers review their processes relating to health data in line with the new regulations.

The Principle Decision, meanwhile, reaffirms that responsibility for the protection of personal data extends to all actors within the data ecosystem. In this context, it is crucial for organisations to regularly review their data-sharing processes and access authorisations, and to strengthen their technical and administrative measures, in order to prevent similar breaches.

Administrative Fine of 1 Million TL Imposed by the Board for Commercial Messages Sent Without Explicit Consent

The Board has issued a significant administrative penalty decision regarding the sending of commercial electronic messages without explicit consent as part of marketing activities and the unlawful processing of contact details.

In the case under the Board’s consideration, it was established that a savings finance company had sent text messages and made telephone calls to the individual concerned for marketing purposes, whilst the individual had lodged a complaint with the Authority, stating that they had not given any consent to these communication activities. During the investigation, the company stated that the telephone number had been entered into the system by an existing customer and that the relevant records had been deleted following the complaint.

The Board established that the mere fact that personal data had been obtained through third parties does not, in itself, constitute a legal basis for data processing; it emphasised that, in communication activities carried out for advertising and marketing purposes, the provisions of both the Law and the legislation on electronic commercial communications must be assessed together. In this context, it was determined that marketing activities carried out without the data subject’s valid, explicit consent—given freely and after having been informed—were unlawful, and it was decided to impose an administrative fine of 1 million TL on the company in question.

Important Ruling by the Constitutional Court Regarding the Offence of Unlawful Disclosure or Acquisition of Personal Data

In a decision published in the Official Gazette on 14 July 2026, the Constitutional Court unanimously rejected the application seeking the annulment of the provision in the Turkish Penal Code which provides for the ex officio investigation of the offence of unlawfully disclosing or obtaining personal data, without the need for a complaint.

In the case giving rise to the application, the court examining the appeal argued that, whilst the offence of violating the privacy of private life is investigated only upon complaint, the ex officio investigation of the offence of unlawfully disclosing or obtaining personal data led to a different application for acts of a similar nature, and claimed that the provision was contrary to the Constitution.

The Constitutional Court, however, emphasised that a fundamental principle of criminal proceedings is that an investigation must be initiated ex officio upon the discovery of a suspicion of a crime; it stated that the legislature possesses the discretion to determine which offences are subject to a complaint, taking into account criteria such as the nature of the offences, the legal values to be protected and the public interest.

The ruling further noted that acts involving the unlawful disclosure or acquisition of personal data are of such a nature that they may affect not only the individual interests of the victim but also public confidence in the protection of personal data and public order. For this reason, it was assessed that not making the investigation into the offence in question subject to a complaint serves a legitimate aim in terms of preventing the unlawful circulation of personal data and ensuring effective criminal justice.

In line with these grounds, the Constitutional Court ruled that the contested provision was not contrary to the Constitution and unanimously rejected the application for annulment.

GRC LEGAL PERSPECTIVE

When assessing the Board’s decision to impose an administrative fine, it highlights the importance of companies establishing processes not only to monitor consent for sending communications but also to verify the source and legal basis from which contact details are obtained. In particular, the joint assessment of data processing conditions and obligations arising from relevant legislation prior to the use of contact details obtained through customer recommendations, referral schemes or similar methods in marketing activities is of critical importance in terms of mitigating compliance risks.

An assessment of the Constitutional Court’s ruling reveals that the protection of personal data is treated not merely as an individual right, but also as a legal value concerning public order. This approach demonstrates that the effective investigation of unlawful acts concerning personal data—regardless of whether a complaint has been lodged by the victim—is viewed as a key tool for ensuring the deterrent effect of the data protection regime and maintaining public confidence.

Regulations on the Storage and Destruction of Genetic Data in the Code of Criminal Procedure Have Come into Force!

With the Act adopted by the General Assembly of the Grand National Assembly of Turkey and referred to in public discourse as the “12th Judicial Package”, the provisions in the Code of Criminal Procedure concerning the recording, storage, use and destruction of genetic analysis results have been revised.

The amendment has been implemented in line with the Constitutional Court’s annulment ruling on the matter. Under the new regulations, the results of genetic analyses obtained within the scope of criminal proceedings will be recorded in a dedicated system, separated from personal identification details; furthermore, a copy will be retained in the investigation or prosecution file to ensure that they retain their evidential value. The Act also sets out clear rules regarding the circumstances under which genetic data must be destroyed.

Accordingly, data recorded in the system shall be destroyed immediately in the event of a final decision that there are no grounds for prosecution, the rejection of an appeal, an acquittal, or a final decision that there are no grounds for imposing a sentence. In all other cases, the records shall be retained for a period of twenty years from the date the court decision becomes final and, at the end of this period, shall be destroyed following the drawing up of a record under the supervision of the Public Prosecutor.

The regulation also grants individuals whose genetic data has been recorded in the system the right to request the deletion of their data under certain conditions. The individual may apply to a judge or court, arguing that the purpose justifying the retention of the data no longer exists or that there is a valid reason for its deletion.

Furthermore, it has been stipulated that genetic data held in the system may only be used for the purpose of establishing the material truth in an ongoing investigation or prosecution, and only upon the decision of a court, a judge or the public prosecutor. It has been provided that the procedures and principles regarding the retention, use and destruction of such records shall be determined by a regulation to be jointly issued by the Ministry of Justice and the Ministry of the Interior.

GRC LEGAL PERSPECTIVE

The amendment aims to enhance legal certainty regarding genetic data used in criminal proceedings and to strengthen safeguards for the protection of sensitive personal data. In particular, it is anticipated that the explicit regulation at statutory level of retention periods, destruction procedures and the rights of data subjects to lodge complaints will contribute to establishing a more balanced framework between the right to the protection of personal data and the effective administration of criminal justice.

Powers of the Cyber Security Presidency Expanded Under the Cyber Security Act!

Significant amendments have been made under the Cyber Security Act and the Act No. 5651 on the Regulation of Publications Made on the Internet, pursuant to Law No. 7590 on Amendments to Certain Laws and Decrees with the Force of Law, which was adopted by the Grand National Assembly of Turkey and entered into force upon its publication in the Official Gazette dated 31 July 2026. These amendments expand the scope of the duties and powers of the Presidency of Cyber Security (“SGB”), whilst providing for the consolidation within the SGB of certain powers and responsibilities previously exercised by the Information and Communications Technologies Authority (“BTK”).

With regard to the duties and powers transferred to the SGB under the new regulations, the existing legislation will continue to apply until secondary legislation is enacted by the Presidency; references in the relevant legislation to the BTK Telecommunications and Communications Directorate and their decision-making bodies shall be deemed to refer to the SGB and the President of the Cyber Security Presidency, in accordance with the scope of the transfer of duties.

Under the Act, the transition process regarding the transfer to the Presidency of movable property, IT infrastructure, data centres, technical equipment, records and documents used in the performance of the duties and powers transferred from the BTK to the SGB, as well as the rights, receivables, liabilities and obligations relating to these activities, has been safeguarded. Furthermore, the provisions concerning the transfer of relevant staff to the Presidency remain in force.

The regulation has further strengthened the SGB’s role in the management of internet domain names, regulations concerning internet infrastructure, and the exercise of certain powers under Law No. 5651. In this context, the powers to determine strategies and policies regarding internet domain names and to regulate this field will be exercised by the SGB.

Furthermore, Law No. 7590 has introduced amendments to various provisions of the Cyber Security Act; in particular, provisions concerning enforcement powers, transitional provisions and the remit of the Cyber Security Presidency have been updated. The amendments came into force on the date of their publication.

GRC LEGAL PERSPECTIVE

These amendments represent a significant step towards centralising regulatory and enforcement powers in the field of cyber security within the Cyber Security Presidency. In this context, whilst the Presidency’s role in relation to electronic communications, internet infrastructure, domain name management and critical information systems has been strengthened, it is anticipated that public bodies and private sector organisations will need to reassess their compliance processes and existing technical and administrative measures in line with the secondary regulations to be published.

Regulation Amending the Regulation on Commercial Advertising and Unfair Commercial Practices Published!

The Regulation Amending the Regulation on Commercial Advertising and Unfair Commercial Practices was published in the Official Gazette dated 01 July 2026. The amendments to the Regulation, which came into force on 1 August 2026, have introduced significant regulations concerning digital advertising, social media marketing, artificial intelligence applications, environmental claims and consumer reviews.

Firstly, the amendments to the Regulation define the concepts of environmental claims, social media, social media influencers and consumer reviews; thereby broadening the legal framework, particularly in relation to digital marketing practices. It has been made mandatory for claims used in advertisements containing claims of environmental benefit or sustainability to be verifiable by competent authorities or independent organisations; the use of general and vague environmental statements without any explanation has been prevented.

The rules governing advertisements for discounted sales have also been revised. Accordingly, the period to be taken as the basis for determining the pre-discount price and the method to be applied across different sales channels have been clarified; it has been made clear under what circumstances advertisements relating to loyalty programmes and campaigns contingent upon the fulfilment of specific conditions will be subject to the provisions on discounted sales.

Significant innovations have been introduced in the field of digital advertising. It has become mandatory to state clearly and comprehensibly in advertisements where artificial intelligence or similar technologies are used in a manner that could influence consumers’ economic behaviour; furthermore, a ban has been imposed on the use in advertisements of digital replicas of real persons created using artificial intelligence in a way that gives the impression that they have experienced or recommended a product or service in a manner contrary to reality.

The Regulation also sets out detailed rules regarding commercial communications carried out through social media influencers. The use of the terms ‘Advertisement’ or ‘Promotion’ in content of an advertising nature has been made mandatory; procedures and principles have been established to ensure that the advertising relationship is disclosed in a manner that is immediately apparent to consumers.

Furthermore, targeted advertising has been defined in the Regulation for the first time, and new obligations regarding advertising activities based on personal data have been introduced. Whilst it is mandatory to inform users of the criteria used to display an advert to a particular consumer, profiling activities based on personal data targeting children have been prohibited.

The rules governing consumer reviews published online have also been significantly updated. Accordingly, only reviews from consumers whose purchase of the product or service can be verified may be published; new obligations have been introduced requiring reviews to be published based on objective criteria, without distinguishing between positive and negative comments, and ensuring that false reviews are not created for commercial purposes.

GRC LEGAL PERSPECTIVE

The amendments to the relevant Regulation are reshaping the digital advertising ecosystem not only in terms of advertising content but also with regard to data usage, artificial intelligence applications, influencer collaborations and the management of online consumer experiences. It is therefore essential for businesses to review their marketing activities through a holistic compliance approach covering consumer law, data protection, e-commerce and advertising legislation, and, in particular, to update their internal approval and audit mechanisms relating to digital campaigns.

WHAT’S HAPPENING AROUND THE WORLD?

The European Commission has imposed a total fine of 890 million euros on Google under the Digital Markets Act!

The European Commission has concluded two separate investigations into Google under the Digital Markets Act (DMA) and has determined that the company breached its obligations regarding the Google Search and Google Play services. As a result, Google has been fined a total of 890 million euros: 460 million euros for Google Search and 430 million euros for Google Play. These decisions mark the first fines imposed on Google under the DMA.

In the decision concerning Google Search, the Commission found that Google had positioned its own services – such as shopping, hotels, transport and sport – more favourably in search results compared to third-party services. According to the decision, the company breached the DMA’s obligation to ensure fair, transparent and non-discriminatory ranking by placing its own services higher up and more prominently in search results, whilst failing to provide the same conditions to rival platforms offering similar services.

In its assessment of Google Play, the Commission concluded that practices restricting app developers from directing users to alternative purchase channels or more competitively priced offers are incompatible with the DMA. Furthermore, it was assessed that the scope and duration of the fees charged by Google in return for its steering activities exceeded the limits set out in the Act.

The Commission has granted Google 60 days to comply with the decisions; it has stated that, should compliance not be achieved within this period, additional fines calculated on the basis of the company’s global turnover may be imposed. However, it was noted that the Commission is continuing to assess the compliance proposals submitted by Google regarding search results, Google Play policies, and the ‘AI Overviews’ and ‘AI Mode’ applications. Google, for its part, has stated that it does not agree with the decisions and has informed the public that it may seek legal redress.

GRC CONCEPT OF THE MONTH

Algorithmic Transparency

Algorithmic transparency refers to providing relevant individuals with sufficient information regarding which data is used by artificial intelligence systems and other algorithmic decision-making mechanisms, how they operate, and how they affect individuals. With the proliferation of digital services and artificial intelligence applications, algorithms have evolved beyond being mere technical tools; they have become decision-making mechanisms that guide consumer preferences, determine content rankings and shape the products, services and advertisements presented to individuals.

Recent regulations, rather than banning the use of algorithmic systems, aim to ensure that these systems are operated in a manner that is comprehensible and verifiable from the perspective of consumers and users. The requirement to clearly label advertising content generated by artificial intelligence, the disclosure of the criteria used to target consumers in targeted advertising, and the audits conducted by the European Union regarding digital platforms’ algorithmic ranking practices are concrete examples of this approach.

Algorithmic transparency is becoming a fundamental compliance principle not only in relation to artificial intelligence applications but also in the context of advertising technologies, e-commerce platforms, search engines, recommendation systems and personalised digital services. In this context, businesses’ need to establish mechanisms capable of explaining algorithmic decision-making processes, to assess the legal implications of automated systems, and to strengthen their processes for informing users is becoming increasingly important in terms of consumer law, data protection and compliance with digital regulations.