Follow us :
KVKK & Compliance

Can an Employer Read Staff Email? Türkiye's KVKK Principle Decision

Hand holding an envelope among floating email icons — Xen Bilişim

KVKK is Türkiye’s personal data protection law (Law No. 6698), and its regulator is the Personal Data Protection Board. On 16 September 2026 the Board adopted principle decision 2026/2035, published in the Official Gazette (no. 33394) on 8 October 2026. It covers how employers may monitor corporate email accounts and other work communication channels. It has 16 articles, was adopted by majority vote, and rests on Article 15/6 of the Law, which allows a principle decision once a violation is found to be widespread.

This is not legal advice. I look after mailboxes and logs, so I keep the summary brief and focus on IT. Have a lawyer review any policy text.

What the decision says

It is not only about email. Without naming products, it lists internal messaging applications, corporate instant messaging accounts, customer relationship or ticket systems, and the chat and recording areas of meeting platforms. Tools like Teams would fall under that description, but that is my reading; the decision does not name any product.

Key points:

  • Processing only traffic or log records, without opening content, is still personal data processing (Art. 1). Owning the tool does not give unlimited monitoring power.
  • Having technical access to a device or network does not mean you may read an employee’s personal email or personal messaging account (Art. 4).
  • You can set rules on private use, but they must be clear and communicated. Even with a ban, constant and uninterrupted surveillance is not proportionate (Art. 2-3).
  • The notice to employees must be concrete: purpose, scope, whether monitoring means logs or content, retention and employee rights. A single line saying corporate email may be monitored is not enough (Art. 5-7).
  • Because of the power imbalance, explicit consent should not be the primary legal basis (Art. 8).
  • Escalation is gradual. Content access is exceptional, only when traffic review falls short and it is necessary (Art. 10). If misuse can be stopped by filtering or blocking, no general monitoring right arises.
  • Content review needs concrete suspicion and stays limited to the allegation (Art. 11).
  • Hidden monitoring, and tools that record everything an employee does without distinction, are unlawful (Art. 13).

The decision names no fine amount and no compliance deadline. If non-compliance is found, the Board examines the case and may take administrative action under Article 18 of the Law (Art. 16).

Decision article, what to check in IT

The right-hand column is my own practical suggestion, not something the decision orders.

ArticleWhere to look in IT
Art. 14Which accounts hold full-access or delegate rights on someone else’s mailbox? List them and remove what is not needed.
Art. 14Is audit logging of admin mailbox access on, and how long is it kept?
Art. 11, 14Who holds roles that can run content searches? Is the request, approval and record process written down?
Art. 15For leavers: sign-out, time-limited auto-reply, time-limited and logged forwarding, then an archive or deletion schedule.
Art. 13Is screen-recording or keystroke-logging software installed? If so, review it.
Art. 10If the problem is spam, data leakage or banned sites, can a filter or block rule solve it first?
Art. 6Does the privacy notice match what IT actually does?

Leavers’ mailboxes

This is where most companies slip. Article 15 says the account is closed to the employee’s active use and to new access, and incoming messages must not be seen by unrelated people. For business continuity, defense of legal claims or statutory duties, limited and time-bound forwarding, auto-reply, archiving or retention is allowed, with defined access rights and records. The decision gives no number of days or months, so the company must set and document its own period.

A pattern I see often: the departed employee’s mailbox is handed to a manager “just for a while” and stays open for months. That conflicts with the permission list, the logs and the notice all at once.

Filter first, content last

Read through Article 10, my approach is this: if a spam filter, attachment rule or outbound block solves the problem, nobody needs to open a mailbox. If an incident does require a look, I start with traffic records. Message bodies can also hold special-category data and details of third parties on the other side of the conversation (Art. 12), so who sees search results matters.

Frequently asked questions

Can an employer always read company email? No. The decision asks for a gradual approach: content access is exceptional, tied to concrete suspicion, and narrow in scope.

What if an employee opens personal email on a work PC? Technical reach does not create legal authority (Art. 4). For apps that suit personal use, the decision also looks at whether the account was assigned for work, whether it is the employee’s personal account, and the reasonable expectation of privacy.

Can we just collect consent? The decision does not treat explicit consent as the primary basis because of the power imbalance. Other conditions exist, such as legal obligation, protecting a right and legitimate interest, but none gives unlimited power.

If you want a list of your mailbox permissions and log settings, get in touch.

Share this post
Türkçe oku

Related Posts