Decision of the Personal Data Protection Board Regarding the WhatsApp Application

Author

Eyüboğlu & Büyükatak

Publish Date

20 July 2026

Decision of the Personal Data Protection Board Regarding the WhatsApp Application

The Personal Data Protection Board conducted an ex officio examination regarding WhatsApp (as the data controller) following the determination that the Terms of Service and Privacy Policy, which were updated as an agreement between the user and WhatsApp and included obtaining users’ explicit consent for the processing of personal data and its transfer to third parties located abroad, had been amended.

Regarding the Processing of Personal Data

The Board made the following findings:

  • Users were provided with a single explicit consent mechanism for both the processing of their personal data and the transfer of such data to third parties located abroad, without being offered separate choices regarding these rights. Furthermore, the process appearing to be an approval of the Terms of Service actually involved obtaining explicit consent incorporated into the agreement, which undermined the requirement that explicit consent must be provided through a “freely expressed will.”

  • Since the processing of the collected data was not proportionate and limited in line with the stated purposes, such processing was found to be contrary to the principles of “processing for specific, explicit and legitimate purposes” and “being connected with, limited to, and proportionate to the purposes for which the data is processed.”

  • The processing of personal data through cookies for profiling purposes without obtaining explicit consent was found to be unlawful.

Regarding the Transfer of Personal Data Abroad

The Board made the following findings:

  • Since the functionality of the application was made conditional upon the transfer of personal data, users’ interests and reasonable expectations were disregarded. This situation was considered contrary to the principle of “compliance with law and the rules of good faith.”

  • Since the servers of the data controller are not located in Türkiye, the transfer of personal data abroad is subject to explicit consent. The failure of the data controller to submit an undertaking application to the Board was considered contrary to Article 9 of the Personal Data Protection Law.

Based on the above assessments, it was determined that the data controller had failed to take all necessary technical and administrative measures to ensure an adequate level of security in order to prevent unlawful processing of personal data.

Accordingly, an administrative fine of TRY 1,950,000 was imposed on the data controller.

We Are With You Every Step Of The Way With Legal Support.

We Secure Your Future By Providing Fair Solutions To Your Problems.
Contact Us
settings/cbebef76-2eff-4598-9992-3c52cd415b51.webp

To establish a long-term partnership with our visionary team, we invite you to meet the Eyüboğlu & Büyükatak team.

Eyüboğlu & Büyükatak © 2026 All rights reserved.

Alinsoft