- October 22, 2025
PERSONAL DATA PROTECTION STRENGTHENS IN THE INSURANCE SECTOR: AMENDMENT TO THE REGULATION ON PRIVATE HEALTH INSURANCE PLANS
Contents
Toggle1. Introduction
Significant amendments have been made with the Regulation on Amendments to the Private Health Insurance Regulation published in the Official Gazette dated October 20, 2025 and numbered 33053. In this context, amendments made to Article 16 of the Private Health Insurance Regulation (“Regulation”) Article 16 of the Regulation (Regulation on Amendments to the Private Health Insurance Regulation, Article 14), have introduced important innovations aimed at strengthening compliance with the Personal Data Protection Law No. 6698 (“KVKK”) and establishing clear rules for personal data processing activities in the insurance sector.
2. Changes Made
| Protection of Personal Data and Confidentiality Obligation |
(1) | (1) In individual and group contracts, the person’s insurance records and health information are kept on an individual basis. |
(2) | (2) In personal data processing activities carried out under this Regulation, compliance with the procedures and principles set forth in the Personal Data Protection Law No. 6698 dated March 24, 2016, and in the legislation enacted based on this Law is mandatory. |
(3) All individuals and legal entities privy to the insured’s secrets are responsible for keeping these secrets confidential. | (3) In accordance with this Regulation, insurance records and health information kept by the Center shall be retained for 10 years following the termination of the individual’s insurance coverage. Upon the expiration of this period, the Center shall automatically delete, destroy, or anonymize this data in accordance with Law No. 6698. |
(4) All individuals and legal entities subject to the confidentiality obligation listed in Article 31/A of Law No. 5684, who are privy to secrets concerning the insured, are responsible for keeping these secrets confidential. This obligation continues even after the termination of the aforementioned status and duties. |
Additionally, the phrase “health information obtained with the written consent of the insured” in the previous article has been repealed. With this amendment, it is envisaged that the processing of health data by private health insurers will be based on the conditions for processing special categories of personal data set out in the KVKK, rather than solely on written consent. As is known, following the KVKK updates last year, substantial changes have occurred in the conditions for processing special category personal data. This regulation is also an appropriate change to ensure compliance with the current KVKK legislation. In this context, insurance companies can now base their data processing activities on the legitimate and legal grounds set out in Article 6 of the KVKK; therefore, they can evaluate other legal reasons appropriate to the process, apart from explicit consent.
- Under the previous regulation, health information could only be shared with the Insurance Information and Supervision Center (“SBGM” or “Center”) and the relevant competent authorities; beyond that, transfer to third parties was possible only to a very limited extent, even with the consent of the insured. However, with the new regulation, this approach has been abandoned.
Under this regulation, it has become mandatory for all personal data processing activities related to private health insurance to be carried out in accordance with the procedures and principles set out in the secondary regulations issued under the KVKK. In other words, the relevant regulation stipulates that compliance with the KVKK must be ensured at every stage of personal data processing activities (collection, recording, storage, modification, transfer, etc.).
- The previous regulations did not contain any explicit provisions regarding how long insurance records and health data should be stored or what should be done at the end of this period. With the new regulation, it has been stipulated that insurance records and health information kept by the SBGM shall be retained for ten years from the date of termination of insurance. Upon expiry of this period, the SBGM is obliged to delete, destroy, or anonymize the personal data in question ex officio in accordance with Article 7 of the KVKK. The regulation only clarifies the Center’s storage and destruction processes. However, it would not be wrong to say that other entities processing health data under the relevant Regulation must also carry out their storage and destruction processes in accordance with the provisions of Article 16/2, taking into account the measures envisaged by the KVKK.
- With the new article, natural and legal persons subject to confidentiality obligations are explicitly based on Article 31/A of the Insurance Law No. 5684. Accordingly, all natural and legal persons who have access to information about the insured person covered by the article are responsible for protecting this information under confidentiality obligations. In addition, the regulation stipulates that this obligation shall continue even after the termination of the duty or capacity.
Article 31/A of the Insurance Law No. 5684, which regulates the confidentiality obligation, defines the relevant scope as follows:
“Those involved in the implementation and supervision of the implementation of this Law, the employees and officials of the institutions subject to this Law, persons subject to this Law and those working alongside them, and those working in the insurance sector through external service procurement, may not disclose the secrets of persons and organizations operating within the scope of this Law, their affiliates, organizations, and persons related to insurance contracts, which they have learned due to their capacity and duties, to anyone other than the authorities expressly authorized by law in this regard, nor may they use them for their own or others’ benefit. This obligation continues even after the termination of the relevant positions and duties.
- As can be seen, the relevant regulation creates a permanent confidentiality obligation not only for insurance companies but also for many other parties, such as agents, brokers, reinsurance companies, and insurance experts. In this context, it may be important for all stakeholders in the insurance sector to update their documentation, such as confidentiality agreements and data processing agreements with their employees and business partners, in line with the new updates.
3. Conclusion
The regulations introduced by the Regulation aim to bring the framework for the protection of personal data in the field of private health insurance into full compliance with the KVKK; it raises the necessity for insurance companies to carry out a comprehensive check-up in terms of the KVKK.
In this context, the fundamental compliance steps that insurance companies must take include updating data processing inventories, revising information texts, reviewing data processing agreements and confidentiality commitments, strengthening technical and administrative measures for the protection of special category data, and establishing internal and external audit mechanisms for data security.