Skip to main content
08October2026

The KVKK Principle Decision on the Monitoring of Corporate E-Mail Accounts and Workplace Communication Channels: Employers' Obligations

The KVKK Principle Decision on the Monitoring of Corporate E-Mail Accounts and Workplace Communication Channels: Employers' Obligations

Principle Decision No. 2026/2035 of the Personal Data Protection Board ("Board"), dated September 16, 2026, titled "Principle Decision on the Procedures and Principles to Be Complied With in Personal Data Processing Activities Carried Out Through the Monitoring of Communication Channels Used for the Conduct of Business, Primarily Corporate E-Mail Accounts Allocated to Employees by Employers" ("Principle Decision"), was published in the Official Gazette dated October 8, 2026 and numbered 33394.

The starting point of the Principle Decision is the finding, under Article 15/6 of the Personal Data Protection Law No. 6698 ("Law"), of a widespread unlawfulness in practices concerning the monitoring of employee communications. The decision was adopted by majority vote.

In this article, we assess the framework introduced by the Principle Decision and its practical consequences for employers.

The Scope of the Principle Decision Is Not Limited to Corporate E-Mail

The Board stated that the corporate e-mail account allocated to employees constitutes, beyond a means of communication, a data source containing the employee's professional and at times personal network of relationships, working patterns and correspondence content.

The scope is not confined to e-mail accounts. Internal messaging applications, corporate instant communication accounts, customer relations or request management systems, and the chat and recording areas of meeting platforms are also listed among the communication channels that may be subject to monitoring depending on the characteristics of the specific case.

As regards applications that are also suitable for personal use, three criteria come to the fore. Whether the account in question has been allocated by the employer for business purposes, whether it is used through the employee's personal account and whether the employee has a reasonable expectation of privacy must be assessed separately.

Processing Traffic and Log Records Is Also a Personal Data Processing Activity

An approach frequently encountered in practice is that the examination of records of a metadata nature only, such as the sender, recipient, date, time and connection information, is not regarded as falling within the scope of data protection legislation.

The Board did not accept this approach. Processing traffic and log records alone without accessing content still constitutes a personal data processing activity in its own right. Accordingly, whether e-mail monitoring is directed at traffic data or at content, it is subject to the general principles, the processing conditions, the obligation to inform and the data security obligations set out in the relevant articles of the Law.

The Fact That the Communication Tool Belongs to the Employer Does Not Confer Unlimited Monitoring Power

The fundamental approach of the Principle Decision is that the fact that communication tools belong to the employer, or are located at the workplace, does not in itself confer an unlimited and absolute monitoring power on the employer.

In reaching this assessment, the Board relied on the decisions of both the Constitutional Court and the European Court of Human Rights on the subject. In those decisions, the employer's monitoring power is made subject to the criteria that the employee be informed clearly and in advance, that the monitoring rest on a legitimate aim, that it be limited to and proportionate to that aim, and that less intrusive means take priority. Monitoring of content, on the other hand, requires a weightier justification compared with the monitoring of traffic data.

The Distinction Between Business Use and Personal Use

The Board stated that, in determining the scope of the monitoring activity, the distinction between business use and personal use must be taken into account by reference to the purpose for which workplace communication tools are used. Whether personal use has been prohibited by the employer, permitted within certain limits, or left without any express regulation may produce different outcomes in the assessment of the lawfulness of the monitoring.

The employer may lay down rules on personal use within the scope of its managerial prerogative. However, those rules must be clear, comprehensible and capable of being known by the employee. Where personal use is prohibited, restricted or made subject to conditions as to time, scope and method, this must be expressly announced to the employee.

Even where personal use has been prohibited, the employer's monitoring power remains limited by the principle of proportionality. The Board expressly stated that monitoring carried out in the form of continuous and uninterrupted surveillance cannot be regarded as proportionate. Where a breach of the prohibition on personal use can be understood from elements other than the content, separate access to the content of the correspondence will not be regarded as necessary and proportionate.

Where personal use is permitted, the distinction is more pronounced. Where business communication and personal communication can be separated from one another, the monitoring must be limited to business communication alone and the employee's private correspondence must be left outside the monitoring. Where the two cannot be separated, the employer's monitoring power must be construed more narrowly.

Technical Access Capability Does Not Amount to Legal Access Authority

Another matter emphasized in the Principle Decision is that technical capability and legal authority must be distinguished from one another.

The fact that the employer holds technical authority over a particular device, session, network or corporate system does not mean that it may freely access the correspondence content held in the employee's personal e-mail account, personal instant messaging application, social media message box or similar private communication areas.

This finding directly addresses a debate that frequently arises where an employee logs into personal accounts from a company computer. The fact that the device belongs to the employer does not render the personal communication areas accessed through that device open to monitoring.

Prior Information and the Obligation to Inform

The Board stated that, in assessing the lawfulness of the monitoring, the fact that the employee was informed in advance about the monitoring activity is one of the decisive factors.

Nevertheless, the information required under the case law of the Constitutional Court and the obligation to inform regulated under Article 10 of the Law are not identical concepts. Not every act of informing may qualify as an obligation to inform within the meaning of the Law; however, a privacy notice drawn up in accordance with the required procedure that carries the elements set out in Article 10 and contains clear information on the purpose, scope and method of the monitoring activity may also satisfy the condition that the employee be informed in advance about the monitoring.

As regards the content of the privacy notice, the Board has set out concrete expectations. Going beyond an abstract and general statement, the notice must contain, in a clear, comprehensible and concrete manner, the legal ground, purpose and scope of the processing activity, whether the monitoring will be carried out through the examination of traffic and log records or through content monitoring, the cases in which content may be accessed, the retention period of the data, and the rights of the data subject under Article 11 of the Law.

By contrast, general notifications merely stating that the corporate e-mail account may be monitored by the employer will not satisfy the condition of informing and will not result in the obligation to inform being fulfilled. It may be considered that the single-sentence statements added in practice to employment contracts or information security policies do not meet this criterion.

Explicit Consent Does Not as a Rule Constitute a Legal Basis

The Board stated that, having regard to the dependency inherent in the employment relationship and the imbalance of power between the parties, the employee's explicit consent should as a rule not be relied on as the primary legal basis for e-mail monitoring. Where explicit consent is relied on, whether the consent was given by free will must be assessed separately in the light of the specific case.

Depending on the circumstances of the specific case, the personal data processing activities carried out within the scope of the monitoring may be based on the conditions set out in the relevant article of the Law, namely that processing is mandatory for the data controller to fulfil its legal obligation, that processing is mandatory for the establishment, exercise or protection of a right, and that processing is mandatory for the legitimate interests of the data controller provided that it does not harm the fundamental rights and freedoms of the data subject. However, the Board further emphasized that the existence of these processing conditions likewise does not confer an unlimited monitoring power on the employer.

The Principle of Gradation and the Limits of Content Monitoring

One of the headings of the Principle Decision expected to have the greatest practical effect is the finding that gradation is essential in monitoring. Where the employer can attain the legitimate aim it pursues by a less intrusive means, it may not resort to a more intrusive monitoring method.

Access to content may arise only in exceptional cases where the monitoring of traffic data falls short and access to content is mandatory. Where the misuse of the communication tools allocated to the employee within the scope of business activity can be prevented by technical means such as filtering or blocking, no general right of monitoring will arise for the employer.

As monitoring of content constitutes the most intensive interference with the employee's private life and freedom of communication, it requires a stronger and more concrete legitimate justification. Content monitoring must be resorted to only where there is concrete suspicion and in a manner limited to the allegation, and content examination that is indeterminate in scope, general and continuous must be avoided.

Two risks must additionally be observed when content monitoring is carried out. There is a risk that special categories of personal data within the meaning of the relevant article of the Law may be processed in the body of, or in the attachments to, the message subject to monitoring. Furthermore, as correspondence frequently also contains personal data belonging to the counterparties, the effect the monitoring will have on the data of third parties must be taken into account.

The Prohibition on Covert Surveillance and the Restriction of Access Authority

The Board stated that monitoring carried out through covert surveillance methods of which the employee has not been informed in advance, and through tools that record all of the employee's actions without distinction, will be regarded as unlawful. The monitoring must be carried out with the employee's knowledge and within a foreseeable framework.

Concrete measures have also been prescribed as regards access to the data obtained as a result of the monitoring. Access to the data obtained through corporate e-mail accounts and the communication channels used for the conduct of business must be restricted to a limited number of personnel authorized for that task alone, the access authority must be determined through job descriptions, access records must be kept, and the persons accessing the data must be placed under a confidentiality obligation.

The Corporate E-Mail Account Following the Termination of the Employment Relationship

The Principle Decision also addresses a matter that frequently gives rise to problems in practice. Following the termination of the employment relationship, the legal basis for the data processing activities relating to the corporate e-mail account allocated to the employee must be assessed separately.

As a rule, the account in question must be closed to the employee's active use and to new access, the messages received by the account must not be made available for viewing by unrelated persons, and personal data for which there is no longer a legal basis must be destroyed.

Nevertheless, the Board stated that, for the purposes of ensuring business continuity, preventing disruption to corporate communication, enabling the right of defense to be exercised in legal disputes, or fulfilling obligations arising from the relevant legislation, limited and time-bound forwarding, automatic reply, archiving or retention practices relating to the corporate e-mail account, with defined and recorded access rights, may be assessed according to the circumstances of the specific case.

This approach is in line with the decision of the Italian data protection authority that we addressed in our previously published article titled "Retention of Employee E-Mails for Five Years and the Conditions of Access: The Garante Decision." It may be considered that practices under which a departing employee's account is kept open indefinitely, or messages received by the account are forwarded to managers without limitation, should be reconsidered in the light of the Principle Decision.

Sanctions

The Board stated that, where it is established that these obligations have not been complied with, the necessary examination will be carried out taking into account the characteristics of the specific case, and administrative action will be taken against the relevant data controllers pursuant to the relevant article of the Law. You can review the 2026 KVKK Administrative Fines page for information on this matter.

Actions to Be Taken by Data Controllers

Following the Principle Decision, it is important for companies to review the following matters:

  • Drawing up an inventory of the communication channels used in the workplace. In addition to corporate e-mail, internal messaging applications, instant communication accounts, request management systems and the chat and recording areas of meeting platforms should also be included in that inventory.
  • Determining which type of monitoring is carried out on which channel, and separating monitoring at the level of traffic and log records from content monitoring.
  • Setting out the rules on personal use in writing. Whether such use is prohibited, whether it is permitted within certain limits, and the conditions as to time, scope and method to which it is subject must be expressly regulated and announced to employees.
  • Updating privacy notices so as to include the elements prescribed in the Principle Decision. The purpose, scope and method of the monitoring, the cases in which content may be accessed, the retention period and the rights of the data subject must appear in the text in concrete terms.
  • Reviewing monitoring practices based on explicit consent and redetermining the processing condition according to the specific case.
  • Where content monitoring is resorted to, documenting in writing the concrete suspicion and the reasons why less intrusive methods fall short, and carrying out that assessment before the monitoring.
  • Reviewing the use of surveillance software leading to continuous and uninterrupted surveillance and of tools that record all actions without distinction.
  • Restricting the authority to access monitoring data through job descriptions, keeping access records, and placing the personnel holding access authority under a confidentiality obligation.
  • Setting out in a written procedure the process applicable to the corporate e-mail accounts of employees whose employment relationship has ended. The time at which the account is to be closed, the duration and scope of any forwarding to be applied, the text of the automatic reply and the retention period of the archived data should be determined in that procedure.
  • Updating the personal data processing inventory, the retention and destruction policy, and the information security and acceptable use policies in line with this framework.

Examples of Good Practice

The framework introduced by the Principle Decision calls for a review of certain habits that have become established in practice. Although single-sentence statements added to employment contracts or staff handbooks, under which the employee accepts that the corporate e-mail account allocated to them may be monitored, are widespread, it may be considered that they are not sufficient in the light of the Principle Decision. In place of a contractual provision reading "The employee accepts, declares and undertakes that the e-mail account and other communication tools allocated to them may be monitored by the employer", a provision reading "The procedures and principles concerning the use and monitoring of the corporate communication tools allocated to the employee are set out in the Policy on the Use and Monitoring of Corporate Communication Tools and in the privacy notice annexed to that policy. The employee acknowledges that the said documents have been served on them and that they have been informed of their content" may be preferred. The result of this choice is that the contractual record ceases to be a declaration of consent and becomes a record serving to prove that prior information was given.

Abstract expressions should likewise be avoided in the privacy notice itself. In place of a statement reading "Your personal data is processed in compliance with the legislation for the purpose of ensuring information security", a concrete formulation setting out the purpose of the monitoring, the channels it covers, its method, the cases of access to content and the retention period may be preferred, reading "The traffic and log records relating to the communications you carry out through the corporate e-mail account, the internal messaging applications and the other corporate communication channels allocated to you by our Company are processed for the purposes of ensuring information security and fulfilling our Company's legal obligations. The content of messages is accessed only where there is concrete suspicion and the examination of traffic and log records falls short, and such access is limited to the subject matter of the suspicion. The data in question may be accessed only by personnel authorized for this purpose, and the records are retained for the period determined in our policy". In the same way, instead of the explicit consent form signed among the onboarding documents, determining the processing condition on which the monitoring rests, documenting the balancing test in writing where legitimate interest is relied on, and removing the consent form from the process may be considered.

Arrangements that continuously scan all employees' outgoing messages against keywords and automatically forward the content of any matching message to human resources may amount to continuous and uninterrupted surveillance. It may instead be recommended to establish a graduated structure that detects anomalies at traffic and volume level at the first stage, does not access content at all where misuse can be prevented by filtering or blocking, and conducts content examination only within a file opened on the basis of concrete suspicion. As regards reflecting this structure in the policy, in place of a provision reading "The Company reserves the right to monitor corporate communication tools at any time without prior notice", a provision setting out the stages may be preferred, reading "The Company may carry out monitoring on corporate communication tools for the purposes of ensuring information security and fulfilling its legal obligations. The monitoring is carried out in a graduated manner. At the first stage, only traffic and log records such as the sender, recipient, date, time, volume and connection information are examined. The content of messages is accessed where the examination of traffic and log records falls short and the conditions set out in this policy are met. Continuous monitoring that records all of the employee's actions without distinction is not applied".

Tolerating personal use in practice while the rule that corporate e-mail is to be used for business purposes only is set out in writing may produce an outcome unfavorable to the employer in the assessment of the lawfulness of the monitoring. For this reason, expressly permitting limited personal use and determining in the policy a method that keeps those areas outside the monitoring, such as collecting personal messages in a designated folder or separating them through a label in the subject line, may be regarded as a workable solution. Similarly, as taking a screenshot of a personal messaging application left open on a company computer and placing it in a disciplinary file is an example of confusing technical access capability with legal access authority, expressly stating in the policy that personal communication areas are kept outside the scope of monitoring and, where necessary, blocking access to those areas by technical means would be a safer approach.

Having the human resources or information technology unit open a mailbox directly upon request makes it impossible to establish subsequently the justification for, and the limits of, the monitoring. It may instead be recommended to create a written monitoring request form specifying the concrete suspicion, the date range, the keywords and the counterparties, to make the request subject to the joint approval of the legal and information technology units, to log the access and to record the outcome of the examination in a written report.

Keeping a departing employee's account open for a long period and forwarding all incoming messages to a manager results in the manager also being able to see past correspondence. For this reason, in place of a provision reading "Where the employee leaves employment, the corporate e-mail account is forwarded to their manager", a provision setting out the period, the scope and the access authority may be preferred, reading "As of the date on which the employee leaves employment, the corporate e-mail account is closed to active use and to new log-in operations. Messages received by the account after the departure date may be forwarded so as to be accessible to the relevant unit manager, for a period not exceeding that determined in the policy, for the purpose of ensuring business continuity. The forwarding covers only the messages received after the departure date and does not provide access to the employee's past correspondence. An automatic reply is set up informing the sender that the account is not in use and indicating the address to which communications should be directed. At the end of that period the account is closed entirely, and the archive relating to the account is subject to the period set out in the Personal Data Retention and Destruction Policy".

Finally, as allowing the entire information technology team to access every mailbox with administrator privileges does not satisfy the criterion that access authority be limited to the task concerned, the monitoring and discovery authority must be granted to a limited number of named individuals and access records must be reviewed at regular intervals. Keeping the recording and automatic summary features on meeting platforms disabled by default, notifying participants where recording is started and determining the retention period of the recording must be assessed within the same framework.

Conclusion

The Principle Decision brings together in a single text the court decisions and the Board's approach that were previously scattered across the subject of monitoring employee communications, and gives concrete form to the framework with which employers must comply.

The fundamental approach emerging from the decision may be summarized as follows: the employer does hold a monitoring power, yet that power arises not from ownership of the tool or from technical access capability but from a legitimate aim, and it is limited by the principle of proportionality. Monitoring must be carried out in a graduated manner, access to content must remain the method of last resort, and each stage must rest on the employee having been informed in advance.

For this reason, it is important for companies not to confine themselves to updating policy texts but also to verify whether their monitoring practices are technically carried out in line with this framework. It may be considered that, where the scope of the monitoring applied, its justification and the authorized personnel have not been documented in a way that can be established subsequently, a risk may arise in terms of an examination to be carried out by the Board.

You can find further details in the "Principle Decision on the Procedures and Principles to Be Complied With in Personal Data Processing Activities Carried Out Through the Monitoring of Communication Channels Used for the Conduct of Business, Primarily Corporate E-Mail Accounts Allocated to Employees by Employers" published in the Official Gazette. (In Turkish)

Category Personal Data Protection Law

  • Notification!

    The content in this article is for general information purposes only and belongs to CottGroup® member companies. This content does not constitute legal, financial, or technical advice and cannot be quoted without proper attribution.

    CottGroup® member companies do not guarantee that the information in the article is accurate, up-to-date, or complete and are not liable for any damages that may arise from errors, omissions, or misunderstandings that the information may contain.

    The information presented here is intended to provide a general overview. Each specific case may require different assessments, and this information may not be applicable to every situation. Therefore, before taking any action based on the information provided in the article, it is strongly recommended that you consult a competent professional in the relevant fields such as legal, financial, technical, and other areas of expertise. If you are a CottGroup® client, do not forget to contact your client representative regarding your specific situation. If you are not our client, please seek advice from an appropriate expert.

    For contact and company information, please visit the CottGroup® Member Companies page.

About The Author

/tr/mevzuat/item/kurumsal-e-posta-hesaplarinin-ve-is-yeri-iletisim-kanallarinin-denetlenmesine-iliskin-kvkk-ilke-karari-isverenlerin-yukumlulukleri