Article · Data Protection

Penalties and enforcement decisions for breaches of Data Protection Law in Türkiye

Penalties for breaches of data protection law in Türkiye — prison sentences, administrative fines and compensation — together with the Board's principle decisions and a selection of enforcement decisions on data security, transfers abroad and breach notifications.

11 October 202125 dk okumaBy Sven Köksal · Data Protection
Köksal Attorney Partnership — data protection compliance under KVKK and the GDPR

Penalties

Certain breaches of data protection law carry a prison sentence under Turkish law:

  • the Criminal Code punishes the unlawful collection, processing and transfer of personal data with imprisonment of six months to four years, or with a judicial fine;
  • Article 60 of the Criminal Code allows security measures to be imposed on legal persons, including cancellation of an operating licence and confiscation of the goods used in or obtained through the offence, or of the benefits derived from it;
  • administrative fines under the Data Protection Law are revalued each calendar year. For 2026 they range from TRY 85,437 to TRY 17,092,242, depending on which limb of Article 18(1) is engaged, and Law 7499 added a further band in Article 18(1)(d) for failure to notify a standard contract;
  • an individual whose personal data have been unlawfully collected or processed may claim compensation under the Civil Code, Law No. 4721 (as amended) (available in Turkish only here); and
  • sector-specific rules provide for administrative fines of their own. The Regulation on Administrative Sanctions of the Information and Communications Authority (available in Turkish only here), for example, allows fines of up to 3% of the preceding calendar year’s net sales to be imposed on authorised operators — service providers, network providers and infrastructure operators — that breach personal data and security obligations.

Enforcement decisions

The Board issues principle decisions setting out the core requirements that data controllers must observe. Those decisions are described in detail under Board decisions below; their main points are these:

  • all processing must satisfy the conditions for processing personal data in Articles 5 and 6 of the Data Protection Law, and anyone processing personal data must also comply with the Law’s other requirements;
  • organisations serving the public at counters, tills and service desks must ensure that only authorised staff are present, and must take the measures needed to prevent those being served from seeing or hearing one another’s personal data;
  • data controllers must take all technical and organisational measures necessary for an appropriate level of data security, so as to stop and prevent unauthorised access and abuse of authority;
  • advertising that makes unlawful use of data subjects’ contact details must stop;
  • the use by individuals and organisations of software that allows personal data to be queried against data obtained by various means is unlawful, and such use is dealt with under Turkish criminal law; and
  • reasonable steps must be taken to verify the contact details declared by data subjects, for example by sending a verification code or link to the telephone number or e-mail address given.

Alongside those principle decisions, the following decisions of the Board are particularly useful in clarifying practice:

  • In Decision 2020/559 the Board fined a data controller TRY 900,000 for transferring personal data abroad without a valid legal basis. The controller argued that Convention 108 was in itself sufficient for transfers between the parties to it; the Board rejected that argument. Being a party to Convention 108 does not make a country a safe country, and transfers abroad made in reliance on the Convention alone do not meet the requirements of the Data Protection Law (available in Turkish only here);
  • In Decision 2019/157 the Board held that taking e-mail services from a provider whose servers or data centres are outside Türkiye is a transfer of data abroad. Storage services obtained from controllers or processors whose servers are abroad must therefore also comply with Article 9 of the Data Protection Law (available in Turkish only here);
  • In Decision 2020/746 the Board held that the right to request information includes the right of access, and that a data subject’s request to be given his or her personal data is lawful. Where the record also contains personal data of others, the third parties’ data may be masked and/or the record supplied in an alternative form, such as a transcript or the recording itself (available in Turkish only here);
  • In Decision 2020/494 the Board found it lawful for an employer to put camera recordings in evidence in reinstatement proceedings brought by an employee whose contract had been terminated (available in Turkish only here);
  • In Decision 2021/115 the Board fined a data controller TRY 175,000 for recording the telephone number of a debtor’s brother as an alternative contact number on the ground that the bank had previously made contact on that number (available in Turkish only here);
  • In Decision 2020/755 the Board held that a property manager acting as data controller had not breached the Data Protection Law by giving a data subject’s landlord certain personal data on request, including a statement of unpaid service charges and a mobile telephone number: the processing was necessary for the landlord to exercise the rights conferred by Article 22 of Property Ownership Law No. 634 (available in Turkish only here);
  • Decision 2021/111 concerned contact made with a debtor’s relatives about the debt. The Board imposed three fines: TRY 50,000 on the first law firm, which processed personal data with no ground for doing so; TRY 115,000 on the company that passed those data to a second law firm without checking their accuracy; and TRY 100,000 on the law firm that made contact even though it knew the data belonged to the debtor himself (available in Turkish only here);
  • In Decision 2020/407 the Board fined a hospital, as data controller, TRY 100,000 for sending a data subject’s health data by e-mail to a third party as well as to the data subject (available in Turkish only here);
  • In Decision 2020/404 the Board imposed fines totalling TRY 250,000 on a data controller that had failed to give proper notice, had processed special categories of personal data — biometric data such as fingerprints taken on entry to and exit from the workplace — without valid consent, and had transferred personal data abroad (available in Turkish only here); and
  • In Decision 2020/335 the Board fined a data controller TRY 50,000 for making express consent a condition of its car rental service and refusing to serve a customer who withheld that consent (available in Turkish here).

Board decisions

The Board also issues decisions that clarify the Data Protection Law, the secondary legislation and practice. The principal ones are:

  • Decision 2018/10, on the adequate measures to be taken when processing special categories of personal data (available in Turkish only here): data controllers must adopt a separate policy and procedure for the protection of special categories of personal data. The Board stressed the importance of applying the measures already set out in the Personal Data Security Guide.
  • Decision 2017/62, on data security in service areas (available in Turkish only here): organisations serving the public at counters, tills and service desks must ensure that only authorised staff are present, and must take the measures needed to prevent those being served from seeing or hearing one another’s personal data. The Board referred in particular to banks and healthcare organisations.
  • Decision 2017/61, on telephone directory services (available in Turkish only here): websites and applications that allow searches by telephone number or name and that share personal data without a justification recognised by the Data Protection Law or other legislation must cease those activities immediately or face administrative or criminal sanctions. The decision underlines that all processing must satisfy the conditions for processing personal data in Articles 5 and 6 of the Data Protection Law, and that those processing personal data must also comply with the Law’s other requirements.

The principle decisions published by the Board include:

  • Decision 2018/63, on unauthorised access to and use of data (available in Turkish only here): data controllers must take all technical and organisational measures necessary for an appropriate level of data security, so as to stop and prevent unauthorised access and abuse of authority.
  • Decision 2018/119, on advertising that makes unlawful use of data subjects’ contact details (available in Turkish only here): such advertising must stop. The Board added that those advertising by e-mail, SMS and telephone call must stop as well, and that it would impose sanctions on those who did not.
  • Decision 2019/308, on individuals and institutions using software that allows personal data to be queried (available in Turkish only here): the Board found that individuals and organisations were using software that allowed personal data to be queried against data obtained by various means, and referred in particular to attorneys, law firms, and individuals and organisations operating in the finance, real estate and insurance sectors. Use of such software does not comply with Article 12 of the Data Protection Law, and data processors that use it are dealt with under Turkish criminal law.
  • Decision 2020/966, on the technical and administrative measures data controllers must take to verify the contact details supplied by data subjects (available in Turkish only here): so that personal data are kept accurate and, where necessary, up to date, reasonable steps must be taken to verify the contact details declared by data subjects, for example by sending a verification code or link to the telephone number or e-mail address given.
  • Decision 2019/125, setting the criteria for identifying countries with an adequate level of protection (available in Turkish only here), issued under Article 9 of the Data Protection Law;
  • Decision 2019/10, on the procedure and principles for notifying a personal data breach (available in Turkish only here);
  • Decision 2019/9, on the procedure for applying to the data controller and the time limits for complaining to the Board (available in Turkish only here);
  • Decision 2019/225, on the obligation of data controllers established outside Türkiye to register with the Data Controllers’ Registry (‘the Registry’) (available in Turkish only here). A controller established outside Türkiye may be required to register with VERBIS if it processes personal data in Türkiye, whether directly or through a branch or liaison office;

The decisions on exemptions from the obligation to register with the Data Controllers’ Registry are:

  • Decision 2018/32 (available in Turkish only here);
  • Decision 2018/68 (available in Turkish only here);
  • Decision 2018/75 (available in Turkish only here);
  • Decision 2018/87 (available in Turkish only here);
  • Decision 2019/353 (available in Turkish only here);
  • Decision 2020/315 (available in Turkish only here); and
  • Decision 2018/88, on registration deadlines (available in Turkish only here).

The decisions on registration deadlines are:

  • Decision 2019/265 (available in Turkish only here);
  • Decision 2019/387 (available in Turkish only here);
  • Decision 2020/482 (available in Turkish only here); and
  • Decision 2021/238 (available in Turkish only here).

The Personal Data Protection Authority also publishes summarised and anonymised decisions of the Board. They help to clarify the legislation and practice in this developing area and give some insight into how the Board approaches particular questions of processing, transfer and security breaches. The points that stand out are these:

  • Decision 2020/481, on the right to be forgotten (available in Turkish only here): search engines that operate on data collected from third-party websites are data controllers carrying out processing activities. The Board treated requests for delisting from search engines as an aspect of the right to be forgotten. Such a request calls for a balancing exercise between the data subject’s fundamental rights and freedoms and the public interest in obtaining the information, and the Board published a list of 13 criteria for that exercise.
  • notifying data subjects of a personal data security breach 17 months after the event exceeds the reasonable period and is itself a breach of data security (available in Turkish only here);
  • where another ground for processing exists, taking the data subject’s express consent as well amounts to an abuse of right on the controller’s part, and express consent cannot be made a precondition of the service (available in Turkish only here);
  • transferring more personal data to a court than it has asked for breaches the principle of data minimisation (available in Turkish only here);
  • the Board warned data controllers that fail to answer data subjects seeking to exercise their rights within 30 days (available in Turkish only here);
  • the Board warned a company that had kept personal data for ten years on the basis of its legal obligations for processing those data for purposes beyond those obligations (available in Turkish only here);
  • the Board sanctioned a data controller that had sent one customer’s personal data to another customer of the same name, treating the error as evidence that the necessary technical and administrative measures were not in place (available in Turkish only here);
  • adding an employee’s home address to specimen contracts sent to third parties, with no legal basis for doing so, is a breach (available in Turkish only here);
  • the Board refused a data subject’s request to have his or her name removed from a newspaper column, holding that freedom of the press prevailed over the right to privacy (available in Turkish only here);
  • the Board sanctioned a data controller that had obtained additional documents containing personal data that were not necessary for the transaction in question (available in Turkish only here);
  • in Decision 2019/122 the Board required disciplinary proceedings against employees of a bank who had failed to answer a data subject’s application, and required the bank to bring the privacy notice on its official website into line with the Communiqué on the Obligation to Inform (available in Turkish only here).
  • in Decision 2019/82 the Board held that a company’s loyalty card scheme was designed as a marketing tool, so that seeking consent to process special categories of personal data was neither connected with, limited to, nor proportionate to the controller’s activities (available in Turkish only here);
  • in Decision 2018/90 the Board stated that a data controller must discharge its obligation to inform and obtain the data subject’s express consent as two separate exercises (available in Turkish only here);
  • in Decision 2018/106 the Board stated that a person or persons whose identity is unknown cannot be treated as a data controller (available in Turkish only here);
  • in Decision 2018/156 the Board held that applications to the Authority on matters falling within the jurisdiction of the judicial authorities are outside the scope of the Data Protection Law (available in Turkish only here);
  • the Board announced that Microsoft had notified it on 8 May 2019 of a breach in the company’s systems. Microsoft reported that third parties had obtained, without authorisation, the identity information of a customer support manager working for one of its service providers, and that the manager had breached Microsoft’s policy by sharing his or her account login details with 13 support representatives. As a result, third parties were able to gain partial access to the e-mail accounts of Microsoft users between 1 January 2019 and 28 March 2019 (available in Turkish only here);
  • the Board announced that Microsoft had notified it on 29 January 2020 of a misconfiguration in its security systems that led to a breach and to the unlawful disclosure of Microsoft customer records;
  • the Board issued two decisions on biometric data, numbered 2019/81 and 2019/165, imposing administrative sanctions on two data controllers, both operating fitness centres, that processed members’ biometric data on entry and exit. The Board found that express consent had been presented to members as a precondition of the service, so that it could not be regarded as freely given and was invalid. It also held that requiring members to use their fingerprints as the compulsory and only means of entering the centre did not comply with the principle of proportionality, which requires the data collected to be kept to a minimum so far as possible. The Board stated expressly that obtaining express consent does not make the collection of excessive personal data lawful, and that collection must be limited to, and proportionate to, the purpose of processing (available in Turkish only here);
  • in Decision 2019/296 the Board held that refusing a data subject’s access request because the application had not been sent through a notary public or by e-mail bearing a secure electronic signature imposes a financial burden for which neither the Data Protection Law nor the Communiqué on Applications provides. That prevents the data subject from making a proper application and breaches the requirement of lawfulness and good faith set out in Article 6 of the Communiqué on Applications (available in Turkish only here);
  • in Decision 2020/13 the Board set out its view on how the right of access is to be applied (available in Turkish only here);
  • in Decision 2020/173 the Board held that express consent cannot be folded into a general privacy notice and must be obtained before personal data are transferred. Taking the data subject’s approval through an opt-in box does not satisfy the requirements for express consent, and transfers made on that basis are unlawful (available in Turkish only here);
  • in Decision 2020/649 the Board drew a distinction between the wet-ink signature and the biometric signature. Biometric signature solutions are not defined by reference to any particular standard, they have different design features, and they are not treated as equivalent to a wet-ink signature. The signature provisions of the Turkish Code of Obligations No. 6098 govern the classical signature and the electronic signature and do not extend to the biometric signature. As the biometric signature is special-category personal data, it may be processed only where one of the grounds in Article 6(3), as amended by Law 7499, is present and the adequate measures determined by the Board under Article 6(4) have been taken (the decision predates the 2024 amendment). The provisions of the Turkish Code of Obligations No. 6098 do not satisfy the requirement of being ‘clearly prescribed by the law’ (available in Turkish only here);
  • in Decision 2020/927, on a data subject’s request to be excluded from search engine results, the Board held that the request was a matter for the trial court and fell outside the scope of the Data Protection Law (available in Turkish only here);
  • in Decision 2020/93 the Board found no ground for erasing or amending health data, including mental health data. Those data had been processed by the Ministry, which satisfies the requirement of ‘the authorised institutions and establishments’, and they had been processed for the purpose of ‘protection of public health, preventive medicine, medical diagnosis, provision of health care services and treatment, planning, and management of health care services and their financing’ (available in Turkish only here);
  • in Decision 2020/508 the Board held that processing personal data that have been made public for a particular purpose, for that same purpose, does not breach the Data Protection Law. Because the personal data posted on attorney search websites are processed for the same purpose as by the Turkish Bar Association, that processing is not unlawful (available in Turkish only here);
  • in Decision 2020/667 the Board held that, because special categories of personal data must be obtained in order to renew an insurance policy, it was lawful for the insurer to ask its client for express consent to process those data (available in Turkish only here);
  • Decision 2020/710 concerned the processing of personal data in the course of enforcement proceedings. Article 89 of the Enforcement and Bankruptcy Law (available in Turkish only here) allows a creditor in an enforcement proceeding to pursue recovery against non-debtor third parties who may be in possession of the debtor’s assets; processing the data of those third parties for that purpose therefore does not breach the Data Protection Law (available in Turkish only here);
  • in Decision 2020/212, on CCTV systems that record both sound and image, the Board stressed that each such practice must be assessed on its own facts against the principle of proportionality (available in Turkish only here);
  • in Decision 2020/307 the Board considered the practice of the trade registry offices and the principle that trade registry records are public. The documents recorded by those offices contain personal data relating to individual representatives, so the offices must supply the documents and information requested to third parties with the parts containing personal data redacted. The Board noted that the trade registry offices owe a duty of confidentiality in respect of the personal data they hold, and that they are not the body authorised to supply civil registry information under Civil Registry Services Law No. 5490 (available in Turkish only here);
  • in Decision 2020/507 the Board held that the legal heirs of a deceased person are entitled to obtain records containing personal data relating to health (available in Turkish only here);
  • Decision 2020/504 concerned an airline customer who asked for the recording of his conversation with the call centre. Because the recording contained personal data of third parties as well as the customer’s own, the airline supplied him with a redacted transcript of the conversation. The Board noted that the right to information includes the right to obtain the data in question, provided that this does not infringe the rights of third parties. Where it would, supplying the content in an alternative form — such as a transcript containing all the detail relating to the data subject — is an acceptable way of meeting the request (available in Turkish only here); and
  • the Board held that the purpose of a data breach notification is to create an opportunity to avert or minimise, quickly, the harm that the breach may cause data subjects. In Decision 2019/271 it accordingly set out the minimum content of such a notification (available in Turkish only here).

The Board has imposed fines on:

  • a hospital that could not provide an adequate level of protection for patients’ personal data (available in Turkish only here);
  • a careers platform that shared an applicant’s personal data with other applicants with no legal basis (available in Turkish only here);
  • a company that shared an applicant’s CV with other group companies over a shared electronic platform, without the applicant’s consent (available in Turkish only here);
  • a technical service provider that failed to take the technical and administrative measures needed to protect its customers; the Board later fined the same company a second time for not complying with its earlier decision (Decision 2019/52, available in Turkish only here);
  • a social media platform (Facebook) that failed to prevent unlawful access to users’ image data. The breach was caused by an ‘API bug’ that let third-party applications reach user photographs for 12 days. The fine came to TRY 1.65 million in two parts: the Board first imposed TRY 1,100,000 on Facebook for failing to act in time to take the necessary technical and administrative measures, and then a further TRY 550,000 for failing to notify the Board as soon as possible after the API bug was detected (Decision 2019/104, available in Turkish only here);
  • three companies in the transport and lodging sectors: the Board fined each of the transport companies TRY 550,000 and a hotel TRY 1.45 million for failing to take the necessary administrative and technical measures and for failing to notify the Board and the data subjects of the breach as soon as possible (Decision 2019/144, available in Turkish only here);
  • an asset management company that sent a data subject repeated text messages about the same matter without his or her express consent (Decision 2019/159, available in Turkish only here);
  • a data controller that sent commercial electronic messages without the data subject’s express consent. The Board held that sending a commercial electronic message to a data subject is a processing activity and must satisfy the conditions for processing set out in Article 5 of the Data Protection Law (Decision 2019/162, available in Turkish only here);
  • a data controller that failed to discharge its obligation to prevent the unlawful processing of personal data; the fine was TRY 50,000 (Decision 2019/166, available in Turkish only here);
  • a social media platform (Facebook) that failed to prevent unlawful access to user data. This breach was caused by the complex interaction of several bugs affecting three different Facebook features, and Facebook did not notify it to the Board as the Data Protection Law requires. The Board therefore opened an investigation of its own motion under Article 15(1) of the Data Protection Law and, at the end of it, fined Facebook TRY 1.6 million for failing to take the technical and administrative measures needed to prevent breaches and for failing to notify the Board of the breach (Decision 2019/269, available in Turkish only here);
  • a data controller that failed to maintain an adequate level of administrative and technical measures to protect personal data, and which received a second fine for breaching the obligation to notify the Board and the data subjects of the breach as soon as possible (Decision 2019/222, available in Turkish only here);
  • an airline that asked a data subject for both sides of his identity card when he applied to change the username and password for his loyalty membership: the health and religion data on the card — special categories of personal data — were processed without his express consent. The Board also found that the controller had processed personal data in a way that was not relevant to, limited to or proportionate to the purposes for which they were processed (Decision 2019/294, available in Turkish only here);
  • a data controller that processed personal data made public by the data subject in a way inconsistent with the purpose for which they were made public (Decision 2019/331, available in Turkish only here);
  • a newspaper that disclosed a special category of the data subject’s personal data in a column without his express consent. The Board held that the data had been disclosed contrary to the conditions for processing personal data, and fined the newspaper for failing to prevent the unlawful processing of personal data (Decision 2019/372, available in Turkish only here);
  • a bank that failed to take adequate administrative and technical measures to protect personal data when delivering a credit card, and that made no sufficient or reasonable effort to keep the data subject’s data up to date. The Board held that the courier was not a data controller for the data inside the envelope, but was a data controller for the data it used in order to provide its service, such as the names of sender and recipient (available in Turkish only here);
  • a gaming company that failed to maintain an adequate level of administrative and technical measures to run proper vulnerability testing. The unauthorised access was detected through the company’s log records, but the company had not picked up the risk of a breach from those records. Preventive technical measures were taken only after users’ data had been breached, and no notification was made to the Board (Decision 2020/286, available in Turkish only here);
  • a media company that published a formal notice concerning a rectification request without masking the parts containing personal data (Decision 2020/145, available in Turkish only here);
  • a car rental company that used credit card details obtained on an earlier rental to take payment for another. Terms in its customer agreements allowing card details to be used for any future transaction were treated as unfair terms, and such terms do not satisfy the requirements for express consent (Decision 2020/166, available in Turkish only here);
  • a private school that administered the CAS (Cognitive Assessment System) test to assess its pupils’ planning skills and attention processes without the express consent of the pupils’ guardians. Because the results contain information on the pupils’ mental assessment, which counts as a special category of personal data, the school had to discharge its obligation to inform and to obtain the guardian’s express consent (Decision 2020/255, available in Turkish only here);
  • a car rental company that made its customers’ express consent a precondition of its services (Decision 2020/335, available in Turkish only here);
  • a company that operated a fingerprint system at its workplace. The Board held that the special category of personal data had been processed contrary to the conditions for processing personal data, and fined the company for breaching its obligations to inform and to obtain express consent (Decision 2020/404, available in Turkish only here); and
  • a bank that contacted its debtor’s sibling about the debt. The Board held that the personal data had been processed contrary to the conditions for processing personal data, and fined the bank for failing to obtain express consent. It did not fine the bank’s attorney, who had made the call on the bank’s behalf in order to recover the debt, because the attorney had used contact details supplied by the bank and ended the conversation as soon as he or she realised that the person contacted was not the bank’s debtor (Decision 2021/115, available in Turkish only here).

The Board has ordered disciplinary action in the following case:

A public university that made students’ examination results accessible to third parties by publishing them online. The Board stated that the results of students who sat the examination years earlier cannot remain accessible to third parties with no limit of time, and found that the data controller had not responded in time to the Board’s request for information and documents (Decision 2019/188, available in Turkish only here).

This content is for general information only and does not constitute legal advice. Please contact our team for an assessment of your specific circumstances.
Sven Köksal

Author

Sven Köksal

Legal Engineer

Advisory on legal technology, process design and digital business models.

Related Areas of Work

Explore this publication together with the relevant services, practice areas, focus areas, sectors and desks.

Services

Areas of work directly connected to this publication.

See all

Practice Areas

The legal disciplines the topic sits within.

See all

Focus Areas

Focus areas assessed together according to the client's needs.

See all

Sectors

The sectors this topic touches most often.

See all

Regional Desks

Regional desks that follow the matter with a cross-border or specialist focus.

See all
Knowledge Centre

Get a legal assessment on this matter.

Get in touch with our team for an assessment of your specific situation.