Regarding the Guide on Common Misconceptions About the Law No. 6698 on the Protection of Personal Data

Author

Eyüboğlu & Büyükatak

Publish Date

20 July 2026

Regarding the Guide on Common Misconceptions About the Law No. 6698 on the Protection of Personal Data - 2

The Personal Data Protection Authority published a guide titled “Common Misconceptions About the Law No. 6698 on the Protection of Personal Data - 2” on its website on 3 January 2022.

In this guide, the Authority aimed to summarize the practical implications of various elements constituting the implementation of the Law No. 6698 on the Protection of Personal Data (“Law”), including explicit consent, the obligation to inform, and registration with the Data Controllers Registry.

Below, we present the main questions and answers included in the relevant guide for your information:


A. Personal Data

QuestionAnswerExplanationAre all data such as voice, image and photographs considered biometric data?NoThe essential criterion is the unique identification or authentication of an individual. Accordingly, while a biometric photograph constitutes biometric data, an ordinary photograph taken with a mobile phone does not constitute biometric data.Is a biometric signature considered special category personal data?YesA biometric signature falls within this scope as it contains unique characteristics of the individual, such as the amount of pressure applied during signing, writing angle, pen speed and acceleration.Are data using pseudonyms covered by the Law?YesSince the use of a pseudonym does not render personal data anonymous, such data remains within the scope of the Law.


B. Personal Data Processing Activities and Explicit Consent

QuestionAnswerExplanationCan a personal data processing activity be carried out based on more than one processing condition stipulated under the Law?YesThe fundamental principle is that personal data should not be processed by relying on explicit consent when another lawful processing condition exists. Obtaining consent where it is not required may mislead the data subject.Does explicit consent have priority over other personal data processing conditions under the Law?NoWhere another legal basis for data processing exists, obtaining explicit consent from the data subject may create a misleading situation. Therefore, it is practically more appropriate to first evaluate the other conditions specified under Articles 5 and 6 of the Law.Can personal data be processed lawfully by providing only an opt-out option instead of an opt-in option?NoAn active consent mechanism is essential for valid explicit consent.Can personal data be transferred abroad based on Convention No. 108?NoTransfers of personal data to a country party to Convention No. 108 may only be carried out if one of the conditions specified under Article 5/2 or Article 6/3 of the Law exists, and provided that the Personal Data Protection Board (“Board”) has determined that the relevant country provides adequate protection, or that the parties provide a written undertaking ensuring adequate protection and the Board grants permission.


C. Obligation to Inform

QuestionAnswerExplanationIf all provisions of Articles 5 and 6 of the Law are listed during the information process, is the obligation to inform considered fulfilled in accordance with the legislation?NoThe specific legal basis relied upon among the processing conditions listed in Articles 5 and 6 of the Law must be clearly stated during the information process.Does obtaining written approval during the information process also constitute explicit consent?NoObtaining a statement such as “I approve” during the information process may create confusion with explicit consent; therefore, obtaining written approval is not recommended.Does including the legal basis in the information notice mean that the purpose of processing has also been specified?NoThe legal basis indicates which provision of Articles 5 or 6 of the Law justifies the processing activity, whereas the purpose of processing indicates why the processing activity is carried out. These two elements must be separately specified.


D. Application to the Data Controller

QuestionAnswerExplanationIf the personal data of the data subject has not been processed by the data controller, may the data controller leave the application unanswered?NoPursuant to the Law, the data controller must either accept the application of the data subject or reject it by explaining the reason.Can the data controller transfer its obligations under personal data protection legislation to the data processor through a contract? Does this eliminate the responsibilities of the data controller?NoWithin the scope of a contractual relationship, the data controller may authorize the data processor to perform certain obligations; however, such authorization does not eliminate the responsibility of the data controller.Can the data controller leave an application unanswered on the grounds that the application is procedurally invalid?NoPursuant to the Law, the data controller must accept the application or reject it by providing justification.Can an application be submitted through an e-mail address previously notified to the data controller?YesApplications made via e-mail must be submitted through an electronic mail address previously notified to and registered in the systems of the data controller.


E. Data Breach Notifications, Complaints to the Board and Sanctions

QuestionAnswerExplanationIf the contact information of data subjects is available to the data controller, does merely publishing the data breach on the website satisfy the obligation to notify the relevant persons?NoIf the contact information of the data subject is available, the data breach notification must be made directly to the relevant person. If the person cannot be reached, the notification may be made through the data controller’s website.If the subject matter of a complaint submitted to the Authority differs from the application made to the data controller, is the complaint evaluated on its merits?NoThe Board does not evaluate complaints concerning matters that were not previously submitted to the data controller.Is there a clear criterion used by the Board when determining administrative fines imposed on data controllers acting contrary to the Law?NoEach violation is evaluated individually by considering factors such as the severity of the unlawful act, the fault of the offender, economic circumstances, the manner in which the violation occurred, whether a large number of individuals were affected, and the nature of the personal data affected.Is compliance of the data controller with the European Union General Data Protection Regulation (“GDPR”) sufficient to fulfill obligations under the Law?NoIn all cases, the data controller must also fulfill the obligations stipulated under national legislation to ensure compliance with the Law.


Conclusion

As can be seen, the implementation of the Law is continuously being developed through the decisions of the Personal Data Protection Board (“Board”), while practical issues arising in the application of the legislation are being addressed through publications issued by the Authority.

Except for a few critical issues, the answers provided in the relevant guide largely consist of principles already established in the Board’s decisions available on the Authority’s website. Therefore, monitoring the decisions of the Board is of great importance in terms of shaping and understanding the practical implementation of the legislation.


For the full text of the relevant Guide:

https://kvkk.gov.tr/SharedFolderServer/CMSFiles/ca752cda-c3df-4645-8d5e-e2a507e63200.pdf

Submitted for your information and consideration.

We Are With You Every Step Of The Way With Legal Support.

We Secure Your Future By Providing Fair Solutions To Your Problems.
Contact Us
settings/cbebef76-2eff-4598-9992-3c52cd415b51.webp

To establish a long-term partnership with our visionary team, we invite you to meet the Eyüboğlu & Büyükatak team.

Eyüboğlu & Büyükatak © 2026 All rights reserved.

Alinsoft