Follow us :
KVKK & Compliance

KVKK's New Data Minimization Ruling: Does It Bind Private Firms?

Official document approval and corporate decision process — Xen Bilişim KVKK & Compliance

Türkiye’s Official Gazette published a KVKK principle decision on 28 July 2026. KVKK is the country’s Personal Data Protection Authority, and this one, dated 1 July 2026 and numbered 2026/1301, sets strict limits on how public legal entities may publish personal data online. The wording is specific: “public.” Three separate clients asked me the same question this week anyway — should we be doing this too?

Short answer: the decision doesn’t bind you directly. The principle inside it already did.

What the decision actually says

Decision 2026/1301 puts three concrete limits on how public institutions publish national ID numbers, exam results, phone numbers, names, addresses, birth dates and qualification records on their websites.

  • Proportionality. No more data than the stated purpose requires; masking, anonymization or deletion should be used wherever possible.
  • A retention clock. Published data needs a predetermined retention period. Once the legal basis expires, the data must come down or be anonymized.
  • Narrower access. Personal results, such as exam scores, should reach only the person concerned — through e-Government login or two-factor verification, not a public list.

The Authority also repeated the standing duty to implement technical and organisational safeguards and to run regular staff training, and noted that violations can trigger an investigation and administrative sanctions under Law No. 6698.

The scope is public, the principle is universal

The addressee is spelled out: “data controllers with public legal personality.” A private logistics company’s website, or an accounting firm’s, isn’t directly policed by this ruling. The Board didn’t invent a new sanction either — it gave a concrete shape to a principle that already existed.

That principle sits in Article 4 of Law 6698: personal data must be “relevant, limited and proportionate” to the purpose it’s processed for. Nothing in that article distinguishes public from private controllers — it applies to both. The examples the Board spelled out for the public sector — ID numbers in the open, indefinite archives, exam results anyone can view — are mistakes I see just as often on private-sector sites.

What I actually run into: a candidate’s résumé sitting in a career-page folder anyone can browse, a client’s phone number and email published in full on a case-study page, an event’s attendee list left online as a downloadable spreadsheet. None of these belong to a public body. But in an audit or a breach notification, the same Article 4 gets cited — the reasoning the Board wrote for the public sector explains your website’s version of the same mistake just as well.

On your websiteRisky?What to do
Candidate CVs sitting in an openly browsable career-page folderYesRestrict access, auto-delete after a set period
Client phone number and email published in full on a case studyYesKeep name and title, remove direct contact details
Event or webinar attendee list visible on a public pageYesShow it only to logged-in users
Blog author bio (name, title, LinkedIn link)NoPublic professional information, outside minimization scope

The real difference is the enforcement path, not the rule

If a public institution breaches this ruling, it gets cited against this specific principle decision. If a private company makes the same mistake, the process runs slightly differently: when a complaint or breach notification lands on a caseworker’s desk, they reach for the same Article 4 text and write up a “violation of the proportionality principle.” The outcome looks much the same in practice — a fine or a corrective order. Only the cited provision differs; the principle doesn’t.

Reading this decision as “public-sector-only, doesn’t concern us” is a comfortable but wrong conclusion. The Board has repeated the same proportionality-and-retention-limit message for three years running, without drawing a public/private line in its reasoning. A future principle decision aimed squarely at the private sector wouldn’t surprise me.

Frequently asked questions

Does this decision create fines for private companies? No. It targets data controllers with public legal personality specifically. It doesn’t open a new sanction for private firms — but the same conduct can already be assessed under Article 4 of Law 6698.

If the data categories on my website change, do I need to update VERBİS? Yes. VERBİS is Türkiye’s Data Controllers’ Registry. If your published data category or retention period changes, you must file the update within seven days.

Does masking require special software? No. A first initial instead of a full name, the last four digits of an ID number instead of the whole thing, a district-level address instead of a street address — all of these count as masking.

Where can I read the full decision? It’s published on kvkk.gov.tr, under Principle Decisions, numbered 2026/1301 and dated 1 July 2026.

What to check this week

Walk through your career page, your case studies and your event or webinar sign-up pages, asking of each piece of data: why is this here, and when does it come down? If something has sat on your site for over a year and you can’t state a clear purpose it still serves, it shouldn’t still be there. A ruling written for public bodies just handed everyone else the same homework.

If you’d like to review your website’s personal data footprint and your VERBİS record together, get in touch.

Share this post
Türkçe oku

Related Posts