GRC PERSPECTIVE: DATA PROTECTION & COMPLIANCE NEWSLETTER – MARCH 2026

Contents

WHAT’S HAPPENING IN TURKEY?

The 10th Anniversary of Data Protection: A Future Perspective in Light of the GDPR

Organized in collaboration with the Personal Data Protection Authority (“Authority”) and the Regulatory Compliance Association, and hosted by the Istanbul Technical University (ITU) Artificial Intelligence and Data Science Application and Research Center, the workshop titled “The 10th Anniversary of Data Protection: A Future Perspective in the Light of GDPR” was held on March 13, 2026. At the workshop, which was moderated by our valued team member Ceren Beyen and in which the GRC Legal team participated fully, Authority President Prof. Dr. Faruk Bilir provided important insights regarding the Authority’s activities to date, the GDPR compliance process, and key issues in practice.

Chairman Bilir stated that the GDPR compliance process is projected to be completed by the third quarter of 2026 as part of the medium-term plan. In this context, the absence of explicit provisions in the Law regarding implementation, the lack of definitions for fundamental concepts such as biometric data, genetic data, profiling, and personal data breaches, as well as the fact that mechanisms like transparency, accountability, privacy by design, privacy by default, and Data Protection Impact Assessment (DPIA) are not explicitly regulated in the Law, have been listed among the primary agenda items to be addressed. Additionally, it was noted that the introduction of special provisions regarding children, as well as the establishment of certification and code of conduct mechanisms for data transfers abroad, are also on the agenda.

Notable assessments were also made regarding informed consent and the duty to provide information. Chairman Bilir emphasized that explicit consent is an exceptional legal basis that should only be resorted to when other data processing conditions cannot be applied. Regarding the duty to inform, it was stated that the absence of an exception regime in the Law, as found in the General Data Protection Regulation (“GDPR”), has led to various difficulties in practice. Additionally, following the announcement that a new principle decision regarding the distinction between explicit consent and the duty to inform would be published, it was observed that the said decision was published this month.

It was reported that the Authority has received 1,988 data breach notifications to date, 416 of which have been made public; furthermore, out of a total of 62,343 applications, 59,451 have been resolved, 4,220 standard contract notifications have been filed, and administrative fines totaling 1.344 billion TL have been imposed to date. It was also emphasized at the workshop that having appeals against the Board’s decisions heard by administrative courts would contribute to the formation of more consistent case law in data protection law.

New Principle Decision from the Board: Information and Explicit Consent Processes Must Be Separated!

The Personal Data Protection Board (“Board”), in its Principle Decision No. 2026/347 dated February 18, 2026, provided an important assessment regarding a common error frequently encountered in practice. The Decision clearly states that the practice of data controllers presenting the information notice and the consent form together is unlawful.

The Board emphasized that the obligation to provide information, as set forth in Article 10 of the Law, constitutes an independent obligation to inform data subjects about data processing activities; whereas explicit consent constitutes a condition for data processing under Articles 5 and 6 of the Law. Accordingly, it was noted that these two structures, which have distinct legal functions by their nature, must be regulated separately.

The decision states that the obligation to provide information must be fulfilled in all cases and prior to the data processing activity, even in data processing activities based on explicit consent; it further specifies that even if the information text and the explicit consent text are presented on the same page, they must be structured under different headings and with separate declarations.

The Board also drew attention to certain errors frequently encountered in practice. In this context, it was assessed that using phrases such as “I have read and accept” or “I have read and approve” within the information notice is inappropriate; instead, it was deemed appropriate to obtain only a statement regarding the information provided, such as “I have read and understood.” Furthermore, privacy notices that are not clear, simple, and understandable; contain general and vague expressions; use text belonging to other data controllers verbatim; or are unnecessarily long and complex have also been listed among risky practices.

Board Announcement on VERBIS: No Separate Registry Entry Required for Joint Ventures and Consortia!

The Authority has issued an important public announcement regarding the notification of personal data processed within the scope of activities conducted by structures without legal personality, such as business partnerships, consortia, and general partnerships, to the Data Controllers Registry Information System (VERBİS).

The announcement notes that, in practice, it has been observed that such structures have applied for registration in the Registry under their own names; however, it is stated that this approach is not consistent with the Board’s previous decisions. In this context, referencing the Board’s decision dated June 9, 2021, and numbered 2021/569, it was stated that it is not necessary for these structures without legal personality to establish a separate Registry entry as data controllers.

According to the Board, the responsibility for personal data processed within the scope of activities conducted under a business partnership, consortium, or general partnership lies with the partners constituting such structures. Accordingly, partners subject to the Registry registration obligation must also report information regarding personal data processed within the framework of activities conducted under the partnership, in addition to their own activities, to VERBİS.

In conclusion, the Authority has clearly stated that such structures should not be considered separate data controllers; it has once again emphasized that data processing activities must be conducted through the relevant partners’ VERBIS registrations.

New Documents from the Board Regarding Artificial Intelligence

Agentic AI Document:

The “Agentic AI (‘’Agentic AI’’) document published by the Authority addresses more autonomous systems that, unlike traditional artificial intelligence systems, can plan, make decisions, and take actions toward specific goals. The document examines the operation of AI agents—the core components of these systems—multi-step task management, and various use cases; it also assesses the technical, ethical, and legal risks these systems may pose, as well as potential risk areas regarding the protection of personal data. In this context, particular emphasis is placed on the importance of adhering to fundamental data protection principles—such as data minimization, purpose limitation, transparency, and human oversight—during the use of these systems.

Document on the Use of Generative AI Tools in the Workplace:

The document titled “Use of Generative AI Tools in the Workplace,” published by the institution, focuses on the use of generative AI tools in the workplace and addresses their impact on personal data processing procedures. The document outlines key considerations for data controllers under headings such as the processing of employee data, workplace usage scenarios, data security, privacy, and control mechanisms. Additionally, the document emphasizes that the uncontrolled use of such tools can lead to risks such as data breaches, unauthorized data transfers, and the disclosure of confidential information; therefore, it states that usage policies must be established, access must be restricted, and employee awareness must be increased.

New Principle Decision from the Board: Debt Information Belonging to Apartment Residents Should Not Be Posted in Common Areas!

In the Personal Data Protection Board’s Principle Decision dated March 31, 2026,, it was clearly established that the sharing of information such as the first and last names, apartment numbers, and debt amounts of individuals with outstanding maintenance fees—by apartment and site management—in areas accessible to everyone, such as building entrances, bulletin boards, or elevators, constitutes unlawful disclosure of data under the Law. The Board emphasized that such practices are particularly inconsistent with the principles of data minimization, proportionality, and data security, and stressed that personal data must be processed only to the extent necessary and limited to the purpose of processing; it also noted that even if the data subject’s consent is present, such public display methods may not constitute a valid legal basis in most cases.

The decision states that notifications regarding the collection of maintenance fee debts must be made using methods that are specific to the individual, have limited access, and are secure (such as individual messages, email, or closed systems); it further notes that practices contrary to this may result in administrative fines and other sanctions for data controllers. In this regard, the decision explicitly deems the widespread practice of “posting debtor lists” to be unlawful, thereby highlighting the need for site and apartment management bodies to restructure their data processing procedures in accordance with the fundamental principles of the Law.

GRC LEGAL PERSPECTIVE

Documents recently published by the Board reveal that the regulatory focus is not limited to traditional data protection practices but is also shifting toward artificial intelligence technologies. Indeed, when the assessments conducted during the workshop held with the Authority in March are considered together, it becomes clear that the Authority has adopted an active approach, particularly in the fields of artificial intelligence and next-generation digital technologies.

The documents published in this context indicate that artificial intelligence systems must be evaluated not merely as a technical development area, but within the framework of data protection, risk management, and corporate governance. In particular, the autonomous decision-making and multi-layered data processing capabilities of Agentic AI systems present processes that are more complex and difficult to oversee for data controllers compared to traditional artificial intelligence applications.

On the other hand, it is evident that this approach is progressing in parallel not only at the national level but also with the international regulatory agenda. As noted in our previous issues, assessments published by the UK Information Commissioner’s Office (“ICO”) similarly emphasize that autonomous and goal-oriented AI systems give rise to new risk areas under data protection law. In this regard, the ICO’s relevant documents provide a framework aligned with the AI governance approach taking shape on a global scale.

Consequently, as AI systems become more widespread within organizations, it is necessary to adopt a compliance approach that focuses not only on the outputs of these systems but also on their design, data flows, and decision-making processes. This situation clearly demonstrates that the use of AI has evolved from being merely a technological choice to becoming a direct GRC (Governance, Risk, Compliance) issue.

Additionally, as seen in the recently published principle decision, even practices considered “ordinary” in daily life under the Law can result in serious violations of data protection principles, and data controllers are expected to adopt a more cautious approach centered on proportionality and privacy.

WHAT’S HAPPENING AROUND THE WORLD?

French Council of State Ruling on Criteo: Definition of Personal Data Back in the Spotlight

The decision issued by the French Data Protection Authority (“CNIL”) regarding Criteo, which included a 40 million Euro administrative fine, was upheld by the French Council of State (Conseil d’État) in March 2026. This decision contains significant findings regarding the legality of personal data processing, particularly in the context of online advertising and user tracking activities.

At the core of the decision is Criteo’s practice of tracking users’ online browsing habits as part of its behavioral advertising activities and conducting profiling activities accordingly. Following an investigation conducted by the CNIL, it was determined that the company had failed to establish a valid consent mechanism, had not ensured sufficient transparency regarding the processing of users’ data, and had not adequately addressed requests for access and deletion under data subject rights.

Another notable aspect of the dispute concerns whether the online identifiers (pseudonymous identifiers) used by Criteo constitute personal data. The company argued that since direct identification cannot be made through these identifiers, such data should not be considered personal data. However, the Council of State clearly established that such data cannot be considered anonymous in cases where the risk of re-identification is not practically eliminated. In this context, it was determined that the data retains its status as personal data in situations where the individual can be identified by combining different datasets.

Consequently, the relevant decision constitutes an important precedent regarding the validity of consent mechanisms, the obligation of transparency, and the boundaries of the definition of personal data, particularly in relation to tracking technologies and profiling activities widely used in the online advertising ecosystem.

Biometric Data Processing and the DPIA Obligation: The FC Barcelona Decision

The administrative fine imposed by the Spanish data protection authority on FC Barcelona contains important findings regarding the scope of data protection obligations in biometric data processing activities. Under the decision, the data protection impact assessment (DPIA) prepared regarding the biometric verification system used at the club’s stadium entrances was deemed insufficient.

The investigation revealed that the DPIA document failed to sufficiently define the scope of the processing activity, did not effectively evaluate less intrusive alternatives, and did not present the risk analysis in a concrete and convincing manner. In this regard, the decision emphasizes that, particularly in high-risk data processing activities such as those involving biometric data, merely preparing a DPIA in form is insufficient; rather, the necessity and proportionality of the processing activity must be demonstrated in a concrete manner.

The Limits of the Data Processor Status: The Timegrip Decision

The Timegrip decision issued by the Swedish Data Protection Authority demonstrates that the distinction between data controller and data processor can be assessed based on the actual circumstances. In the case at hand, it was observed that a company providing a time-tracking system refused requests for access to employees’ personal data following the bankruptcy of the company it served.

The Authority determined that the company, which played a decisive role in the elements of data processing activities such as purpose, storage, and access, had effectively assumed the role of data controller and ruled that the data subjects’ right of access had been violated. The decision also establishes that the termination of the data controller’s activities does not eliminate the data subjects’ rights and that the right of access to personal data must be protected in all circumstances.

GRC LEGAL PERSPECTIVE

The Criteo decision once again underscores that the definition of personal data cannot be interpreted narrowly, particularly regarding online advertising and user tracking activities. The fact that pseudonymous online identifiers may be considered personal data to the extent that they can make the data subject identifiable when combined with different datasets requires data controllers to more carefully evaluate the distinction between “anonymization” and “use of pseudonyms.” In this context, particularly in behavioral advertising and profiling activities, the validity of consent mechanisms and the fulfillment of transparency obligations—not merely in form but in substance—are of critical importance.

The FC Barcelona decision, however, demonstrates that the core debate in biometric data processing activities is not limited to explicit consent or technical security measures; rather, the necessity and proportionality of the processing activity must be concretely established. In this regard, it is understood that the data protection impact assessment must be treated not merely as a compliance document but as a control mechanism that tests the legal legitimacy of the processing activity. Especially in high-risk data processing activities, the evaluation of less intrusive alternatives and the realistic analysis of risks have become decisive from the perspective of regulatory expectations.

The Timegrip decision, meanwhile, establishes that the distinction between the data controller and the data processor is not limited to contractual definitions; rather, it is assessed based on actual control over data processing activities and decision-making authority. Particularly in situations where the service relationship has ended, the data controller has ceased operations, or organizational uncertainties have arisen, the failure of parties that actually control personal data to comply with requests regarding data subject rights may result in serious penalty risks. In this context, organizations must assess their roles in data processing activities not only through legal texts but also through operational realities.

The Abuse Threshold in Access Requests Under the ECJ Ruling

The Court of Justice of the European Union (“ECJ”), in its March 19, 2026, decision in Case C-526/24, made significant assessments regarding access requests under Article 15 of the GDPR. The judgment states that even a data subject’s first-time access request may be deemed an abuse of rights in exceptional circumstances; however, for this to apply, the data controller must concretely demonstrate that the request was made not to verify the lawfulness of the data processing activity, but solely to lay the groundwork for a claim for compensation.

In this regard, the CJEU, while granting data controllers a certain scope of defense against strategic access requests, emphasized that this assessment must be based not on general assumptions but on facts specific to the request. Additionally, it was noted that publicly available information regarding similar requests made by the data subject to different data controllers and subsequent compensation claims could also be taken into account.

The second key aspect of the decision concerns the relationship between a violation of the right of access and compensation claims under Article 82 of the GDPR. The CJEU has acknowledged that a violation of the right of access may give rise to a compensation claim, even if the underlying data processing activity is lawful. However, merely having a request for access denied or asserting a sense of loss of control in an abstract manner was not deemed sufficient on its own; it was noted that the data subject must demonstrate that they actually suffered non-material harm and that this harm stemmed from the data controller’s violation.

GRC LEGAL PERSPECTIVE

In our view, the ECJ decision contains a two-fold message for data controllers: The possibility of defending against strategic or malicious access requests is not entirely ruled out; however, it is clearly established that such a defense is subject to a high standard of proof. On the other hand, a violation of the right of access is now assessed not merely as a deficiency in the request process but also, under appropriate conditions, as an independent risk of liability for damages. In this context, it is of critical importance for data controllers to manage data subject requests not with standard response templates but through case-by-case assessment, adequate record-keeping, and robust justification.

Joint Opinion from the EDPB and EDPS on the Proposals for the Cybersecurity Act 2 and NIS 2 Amendments

The European Data Protection Board (European Data Protection Board, “EDPB”) and the European Data Protection Supervisor (European Data Protection Supervisor, “EDPS”), have assessed the two legislative proposals published by the European Commission on January 20, 2026, from a data protection perspective through the Joint Opinion (Joint Opinion 4/2026) they adopted on March 18, 2026. The first of these is the Cybersecurity Act 2 (“CSA2”) ; the second is the Proposal for an Amendment to the NIS 2 (“Network and Information Security”) Directive, which proposes changes aimed at simplification and harmonization.

General Approach to the Relationship Between Data Protection and Cybersecurity

The Joint Opinion particularly emphasizes the two-way nature of the relationship between data protection and cybersecurity. On the one hand, cybersecurity measures serve to protect personal data against the risks of unauthorized access, alteration, or destruction. On the other hand, certain cybersecurity practices may interfere with individuals’ rights to privacy and data protection. For this reason, the EDPB and EDPS remind that cybersecurity measures must be assessed not only based on effectiveness but also within the framework of the principles of necessity and proportionality.

Strengthening ENISA’s Role

The EDPB and EDPS generally support the expansion of ENISA’s scope of activities and the streamlining of certification processes. Under the CSA2 Proposal, the EDPB’s ability to directly request advice from ENISA on cybersecurity issues related to data protection and privacy is viewed positively. However, it is recommended that the EDPS be explicitly included in this advisory mechanism. Additionally, structuring the advisory process to be provided only upon request is considered important for safeguarding the decision-making authority of data protection authorities.

Joint Opinion of the EDPB and EDPS on the Proposals for the Cybersecurity Act 2 and the NIS 2 Amendment

Operational Cooperation and the Processing of Personal Data

The CSA2 Proposal envisions ENISA assuming a more central and operational coordination role. In this context, the processing of personal data—such as IP addresses, user credentials, or compromised account data—may come into play. The EDPB and EDPS emphasize that in scenarios where ENISA will process a significant amount of personal data, the scope, purpose, and safeguards of these processing activities must be clearly defined in the underlying legal framework. Additionally, it is recommended that prior consultation with the EDPS be conducted before determining additional data protection measures.

Single Point of Contact for Incident Reporting

One of the most notable aspects of the Joint Opinion is the support given to the “single point of contact” approach regarding personal data breaches and cyber incident reporting. The EDPB and EDPS view the aim of streamlining different reporting obligations through a single platform positively; they note that this structure could reduce the administrative burden on organizations. However, it is also clearly stated that, due to the sensitive nature of data breach notifications, this system must be protected by high security standards.

The European Cybersecurity Certification Framework and Its Relationship with the GDPR

The CSA2 Proposal envisions including the security of personal data processing among the security objectives of certification schemes. While the EDPB and EDPS view this approach positively, they remind that the GDPR has its own certification mechanism and emphasize that cybersecurity certification differs from GDPR certification. Nevertheless, it is stated that functional synergy can be established between the two areas, and that certification schemes should include controls that are as compatible as possible with the security obligations of the GDPR. It is specifically noted that data protection risks must be taken into account, particularly regarding measures such as logging, deep packet inspection, and user behavior analytics.

GRC LEGAL PERSPECTIVE

The Joint Opinion clearly demonstrates that the data protection dimension is not being sidelined as cybersecurity legislation is being reshaped within the European Union. The emphasis on evaluating cybersecurity measures not only for their effectiveness but also in terms of necessity and proportionality underscores the continuation of a holistic approach aligned with the fundamental principles of the GDPR.

When evaluated alongside the Digital Omnibus Joint Opinion discussed in our February newsletter, it becomes evident that European Union data protection authorities consistently advocate for simplification and support for organizational efficiency while ensuring that fundamental rights protection and accountability are not compromised during this process. This approach, taking shape in the areas of cybersecurity, certification, supply chain security, and incident reporting, indicates that the regulatory framework is increasingly being established through a more holistic GRC perspective.

In our view, these developments should also be closely monitored from Turkey’s perspective. Particularly regarding the secondary legislation to be shaped following the Cybersecurity Law No. 7545, it is assessed that the approaches adopted at the EU level regarding certification, supply chain security, and incident reporting could provide significant reference points. Additionally, the “single point of entry” model serves as a noteworthy example for simplifying reporting processes, given that in the digital world, every personal data breach is likely to also constitute a cyber incident.

GRC CONCEPT OF THE MONTH

Pseudonymization

Pseudonymization refers to the processing of personal data in such a way that it cannot be attributed to a specific natural person without the use of additional information. However, this method does not render the data anonymous; in other words, if the data subject can be re-identified using additional information, the data will continue to retain its status as personal data. Therefore, pseudonymization is not a method that eliminates the scope of data protection law but rather one that reduces the risks arising from data processing activities.

This concept is most often confused with anonymization. However, the goal of anonymization is to ensure that the data can no longer be linked to any specific or identifiable individual in any way. In pseudonymization, however, the link between the data and the individual is not completely severed; it merely makes establishing this link directly more difficult. In this regard, pseudonymization serves as an important technical and administrative measure, particularly in terms of data minimization, security, and the “data protection by design” approach. The Institution’s “Guidelines on the Erasure, Destruction, or Anonymization of Personal Data” also highlights the importance of this distinction by addressing anonymization methods and the risks of compromising anonymity.

The Criteo decision mentioned above also demonstrates just how critical this distinction is in practice. The decision concluded that data associated with online identifiers and other browsing data cannot be considered anonymous merely because it does not directly contain a first and last name; rather, it retains the status of personal data in cases where the risk of re-identification has not been concretely eliminated. This approach is particularly significant in the context of advertising technologies, profiling activities, and data processing operations involving the aggregation of large datasets.