Share on LinkedInShare on LinkedIn

ARTICLE · 22 SEPTEMBER 2026

Two-Minute Recap Data Protection Law Matters In Türkiye

Gen Temizer Erdogan Girgin Attorney Partnership
Gen Temizer Erdogan Girgin Attorney Partnership
Contributor
Gen Temizer Erdogan Girgin Attorney Partnership

Gen Temizer Erdogan Girgin Attorney Partnership

Firm Overview Gen Temizer is a leading independent corporate law firm located in the financial...

View firm profile
Explore more from Gen Temizer Erdogan Girgin Attorney Partnership

On 27 August 2026, Turkish Personal Data Protection Authority (“DPA”) published a public announcement clarifying its Personal Data Protection Board’s (“Board”) Principal Decision No. 2026/921 of 29 April 2026 on the processing of biometric data for employee attendance tracking.

TurkeyPrivacy
Ebru Temizer
Ebru Temizer
Irmak Seymen Varat
Irmak Seymen Varat
Sinan Abra
Sinan Abra
Seray Apak Başaran
Seray Apak Başaran
Lorin Tutci
Lorin Tutci
Author LinkedIn connections

Turkish DPA Clarifies That Biometric Data Cannot Be Used for Attendance Tracking

On 27 August 2026, Turkish Personal Data Protection Authority (“DPA”) published a public announcement clarifying its Personal Data Protection Board’s (“Board”) Principal Decision No. 2026/921 of 29 April 2026 on the processing of biometric data for employee attendance tracking.

The DPA reiterated that processing biometric data solely for attendance-tracking purposes does not rely on any of the processing conditions, even where valid explicit consent exists, such processing fails the proportionality requirement under the general principles. It also clarified that converting fingerprints, palm scans or similar data into mathematical codes does not prevent them from qualifying as biometric data. Drawing on both Turkish legislation and EU General Data Protection Regulation, the DPA also confirmed that converting fingerprints, palm scans or similar data into mathematical codes before storage does not remove their biometric nature.

Revised Advertising Regulation Imposes New Rules on AI and Targeted Advertising

Amendments to Turkish Regulation on Commercial Advertising and Unfair Commercial Practices took effect on 1 August 2026, introducing new obligations concerning artificial intelligence and targeted advertising practices that involve the processing of personal data.

Under the amended regulation, advertisers must disclose the use of artificial intelligence in generating advertising content, and personalised or targeted advertisements based on the processing of personal data are subject to new transparency requirements. Targeted advertising to children using personal data-based profiling is prohibited.

Savings Financing Company Fined over Reliance on Implied Consent for Marketing

On 10 June 2026, the Board imposed a TRY 1 million fine on a savings financing company for processing telephone numbers obtained through its “brand ambassador” referral programme without a valid legal basis. Under the programme, existing customers shared third parties’ telephone numbers with the company in return for a premium, after which the individuals were contacted for marketing purposes.

The company argued that the complainant had consented by continuing the call and expressing interest in its campaign. However, the Board found that this conduct amounted only to “implied consent” to continue the marketing conversation and did not constitute valid explicit consent for the processing of personal data. It emphasised that explicit consent must be specific, informed and freely given, and must be obtained before processing begins. The Board also warned that its assessment was not limited to the complainant and applied equally to other individuals whose contact details had been collected through the referral programme.

Compliance Period for Loyalty Card Verification Mechanisms Extended Until 28 February 2027

On 13 August 2026, the DPA announced that, following requestsfrom industry representatives concerning the secure and sustainable implementation of the required verification mechanisms, the Board had extended the original six-month compliance period until 28 February 2027.

The Board had previously decided on 11 February 2026 that data controllers must establish mechanisms to verify that such use during purchases takes place with the loyalty card holder’s knowledge and consent, granting them six months from the decision’s publication to comply. Following requests from industry representatives concerning the secure and sustainable implementation of these mechanisms, the Board extended the compliance period by its decision of 22 July 2026.

Turkish DPA Publishes Smartphone Readiness Checklist for Children

On 21 August 2026, the DPA published a checklist to help parents assess whether their children are ready to use smartphones. The ten-question assessment covers personal data protection, digital privacy, application permissions, online contacts, password security and other online risks, while emphasising the continued importance of parental guidance.

The DPA Announced the Following Data Breach Notifications in August

Data Controller ( and sector)

Affected Data Subjects

Affected Personal Data Categories

Number of Data Subjects

Anadolu Anonim Türk Sigorta Şirketi

Employees and job applicants

» Application Data

» Identity Data

» Contact Data

764 people

Uludağ Elektrik Dağıtım A.Ş.

Third parties with no connection to the applications

» Identity Data

» Contact Data

3150 people

Hyundai

Motor Türkiye Otomotiv A.Ş.

Employees and job applicants

» Application Data (username, password),

» Identity Data (name,surname, passport number),

» Contact Data (address/of residence, email address, phonenumber)

Estimated to be at most 422 people

Data subjects seeking further information

about the incident may contact the

[email protected] and [email protected]

Çorum Belediye Başkanlığı

Citizens of Çorum

» Identity Data (name,surname, ID number),

» Contact Data (address/of residence, email address, phone number)

Estimated to be around

200.000 people

Red Galaxy Game (Doğunay Ürgüplüoğlu)

Employees, users, subscribers, and

customers/potential customers

» Application Data

» Personal Data (Texts between users)

» Payment Data

7507 people

Tamer Tanca Mağazacılık

Sanayi ve Ticaret A.Ş.

Customers/potential customers

Not yet been determined

Estimated to be around

50.000 people

Data subjects seeking further information

about the incident may contact the

(0 850 800 08 62)

 

Data Controller ( and sector)

Affected Data Subjects

Affected Personal Data Categories

Number of Data Subjects

Travelport

International Operations

Limited

Customers/potential customers (child customers counted)

» Identity Data (name,surname, ID number, passport number, birth

date and place, ),

» Contact Data (address/of residence, email address, phone number)

» Travel and Booking Data (departure point, booking reference, including

PNR, and other general reservation information)

» Request and Complaint Data

(complaints concerning flight delays

or cancellations, including any assistance required)

2.774 people

Data subjects seeking further information

about the incident may contact the

[email protected]

Mega Enerji Güç

Sistemleri Jeneratör Pazarlama Sanayi ve Ticaret A.Ş.

Employees,

users, students, customers,

and potential customers

» Identity Data

» Communication

» Location

» Personnel Related

» Legal Transaction

» Physical security,

» Transaction security,

» Risk management,

» Financial information,

» Professional experience,

» Audio-visual records.

Not yet been determined

Novaform Makine Sanayi ve Ticaret A.Ş.

Employees, users, students, customers, and potential customers

» Identity Data

» Physical area security, transaction security, risk management

» Legal transaction and customer transaction data

» Marketing Data

Not yet been determined

Emsa Enerji Pazarlama ve Dış

Ticaret A.Ş.

Employees,

users, students, customers,

and potential customers

» Identity Data

» Visual and audio recordings

» Financial Data

» Physical area security, transaction security, risk management

» Legal transaction and customer transaction data

Not yet been determined

Tamer Tanca Mağazacilik

Sanayi Ve Ticaret A.Ş.

Customers and potential

customers

» Identity Data

» Contact Data

» Data regarding customer orders

Estimated to be around 50.000

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See more popular content from