Skip to main content

KVKK - GDPR

17 Eylül 2026

Transition to the ISO/IEC 27701:2025 Revision: Deadline and Key Changes

Kategori KVKK - GDPR, Work Life

Transition to the ISO/IEC 27701:2025 Revision: Deadline and Key Changes

The ISO/IEC 27701:2025 revision has introduced an important transition process for organizations implementing a privacy information management system, requiring existing systems to be reassessed in accordance with the new requirements. The standard was published on October 14, 2025, and the transition process is expected to be completed by October 31, 2028.

In this context, organizations certified according to ISO/IEC 27701:2019 are required to align their existing certificates, processes, documentation, and audit preparations with the requirements of ISO/IEC 27701:2025 within the three-year transition period.

16 Eylül 2026

ISO 9001:2026 Published: What Has Changed in the Quality Management System?

Kategori KVKK - GDPR, Work Life

ISO 9001:2026 Published: What Has Changed in the Quality Management System?

The International Organization for Standardization (ISO) published ISO 9001:2026, the new version of ISO 9001, one of the world’s most widely used standards for quality management systems, on September 16, 2026.

As the sixth edition of ISO 9001, the new standard replaces ISO 9001:2015 and aims to enable quality management to respond more effectively to changing business conditions. While largely preserving the existing core structure, the new version includes important updates regarding leadership, quality culture, the management of risks and opportunities, and the integrated structure of management systems.

30 Mart 2026

CJEU Decision on the Limits of the Right of Access under the GDPR

Kategori KVKK - GDPR

CJEU Decision on the Limits of the Right of Access under the GDPR

The Court of Justice of the European Union (CJEU), in its judgment dated March 19, 2026 in Case C-526/24 (Brillen Rottler) ("Decision"), has established an important precedent regarding the limits of data subject rights under the GDPR. The Decision clarifies under which conditions the right of access under Article 15 GDPR may be restricted within the framework of Article 12(5) GDPR, while also reassessing the scope of the right to compensation under Article 82 GDPR.

23 Mart 2026

What Is the Right to Erasure? GDPR, Turkish Data Protection Law (KVKK), and Back-Up Compliance in Light of the EDPB Report

Kategori KVKK - GDPR

What Is the Right to Erasure? GDPR, Turkish Data Protection Law (KVKK), and Back-Up Compliance in Light of the EDPB Report

The European Data Protection Board (EDPB) has published a comprehensive report under the 2025 Coordinated Enforcement Framework (CEF), examining how the right to erasure, as regulated under Article 17 of the GDPR, is implemented across Europe. Within the scope of this study, 764 controllers were assessed through investigations conducted by 32 data protection authorities, and the structural challenges encountered in the implementation of the right to erasure, as well as examples of good practices, were identified.

06 Mart 2026

New Principle Decision from the Turkish Data Protection Authority on Loyalty Programs: Six-Month Compliance Period for Data Controllers

Kategori KVKK - GDPR

New Principle Decision from the Turkish Data Protection Authority on Loyalty Programs: Six-Month Compliance Period for Data Controllers

The Personal Data Protection Board's (Kişisel Verileri Koruma Kurulu) Principle Decision No. 2026/266 (In Turkish), published in the Official Gazette dated February 28, 2026 and numbered 33182, has significantly clarified both the legal nature of loyalty card programmes and the obligations incumbent on data controllers.

04 Mart 2026

What Is Quishing? QR Code–Based Phishing and an Assessment from a Data Protection Law Perspective

Kategori KVKK - GDPR

What Is Quishing? QR Code–Based Phishing and an Assessment from a Data Protection Law Perspective

QR code technology has become one of the key tools of the digital economy. From restaurant menus to public services, from e-commerce to financial transactions, QR codes are used across a wide range of contexts and—because they are fast and practical—have become a natural part of user behaviour. However, this widespread adoption also creates an exploitation ground with a low level of suspicion from the attacker’s perspective.

In its Information Note dated 26 February 2026 titled “The Risk Coming with QR Codes: Quishing” (“Information Note”), the Turkish Data Protection Authority (“KVKK”) examines phishing attacks carried out via QR codes in detail and assesses this threat from a personal data security perspective. The Information Note clearly demonstrates that the issue is not merely a technical cybersecurity risk; it is also an area that must be addressed directly within the scope of data protection law.

24 Şubat 2026

Artificial Intelligence in Recruitment Processes and the Protection of Personal Data

Kategori KVKK - GDPR, Work Life, Technology

Artificial Intelligence in Recruitment Processes and the Protection of Personal Data

Recruitment processes have become one of the areas most rapidly transformed by digitalization. Today, many organizations rely on artificial intelligence–enabled systems in candidate screening and evaluation stages. CV-screening algorithms, video interview analytics tools, and automated scoring mechanisms increasingly shape decisions such as shortlisting, interview invitations, and candidate rejection through data-driven models.

13 Ocak 2026

Clarification on the Application Principles of VERBİS Registration Exemptions

Kategori KVKK - GDPR

Clarification on the Application Principles of VERBİS Registration Exemptions

With the decision of the Turkish Personal Data Protection Board dated December 25, 2025 and numbered 2025/2393, the application principles regarding exemptions from the VERBIS (Data Controllers' Registry Information System) registration obligation have been clarified. The decision aims to eliminate uncertainties arising from the implementation of the Board's decision dated September 4, 2025 and numbered 2025/1572, which amended the scope of VERBIS registration exemptions.

Pursuant to Article 16 of the Turkish Personal Data Protection Law No. 6698, data controllers processing personal data are required to register with VERBIS. However, the Board may grant exemptions from this obligation based on objective criteria such as the nature and volume of personal data processed, and the characteristics of the data processing activities.

03 Ekim 2025

Changes in Exceptions to the Obligation to Register with VERBİS

Kategori KVKK - GDPR

Changes in Exceptions to the Obligation to Register with VERBİS

With the Decision of the Personal Data Protection Board published in the Official Gazette dated October 1, 2025 and numbered 33034, amendments have been made to the exemption criteria regarding the obligation to register with VERBİS (Data Controllers' Registry Information System), which is carried out pursuant to Article 16 of the Law on the Protection of Personal Data No. 6698.

[1] 2 3 4  >>