Skip to main content

02 Ekim 2026

Smart Devices and Digital Privacy: From Individual Awareness to Workplace Rules
CottBlog

Yazar Ezgi Anasız, Kategori KVKK - GDPR, Technology

Smart Devices and Digital Privacy: From Individual Awareness to Workplace Rules

The Personal Data Protection Authority has published the May to September 2026 issue of the KVKK Bulletin under the title "Smart Devices and Digital Privacy." The Bulletin is not a binding regulation but a guide intended to raise awareness. Nevertheless, the themes it covers appear worth considering both for individual use and for workplace practices.

CottBlog Abone Ol
CottBlog Subscribe

Digital Privacy Does Not Mean Being Invisible

One of the Bulletin's most striking observations is that digital privacy does not mean being invisible in the digital world. According to the Bulletin, digital privacy means being able to determine the limits of one's visibility while existing in the digital world.

This approach differs from the common perception that equates privacy with keeping information hidden. The issue is not confined to what information we share; the information brought together about us, the conclusions that may be drawn from it and the way those conclusions may affect our lives are also part of privacy.

The Picture That Emerges When Data Is Combined

The Bulletin points out that data which appears ordinary on its own may produce a far more comprehensive picture when combined. Being in certain locations at certain times, using certain applications at certain hours or operating some devices in line with particular habits may allow inferences to be drawn about a person's daily routines.

In the Bulletin's words, what emerges here is information not only about what we do but, to a certain extent, about how we live. The question to be asked is therefore not only which personal data are processed, but what information about the person may be revealed once those data are brought together.

Privacy Begins with Design

Another theme addressed in the Bulletin is privacy by design. Accordingly, it is not sufficient to leave the protection of personal data to measures taken after a product or service has been made available. It is recommended that the data to be processed, who will have access to them, how long they will be retained and which security measures will be applied be assessed at the design stage.

The complementary concept is privacy by default, under which systems are to be offered with default settings that observe privacy, without requiring users to make a separate change to their settings. This matter is of particular importance for smart devices, whose technical features and data processing operations cannot always be followed in detail by users.

Ten Golden Rules for Smart Device Users

The Bulletin sets out a list of ten items for users. In summary:

  • It recommends learning which data the device processes,
  • Not granting unnecessary permissions,
  • Reviewing privacy settings rather than leaving them in their default state,
  • Using strong and unique passwords,
  • Enabling multi-factor authentication,
  • Keeping devices up to date,
  • Removing unused applications and accounts,
  • Controlling data sharing between devices,
  • Logging out of accounts and deleting data before disposing of a device, and
  • Observing privacy while making use of technology.

The final item is tied to a question: "before starting to use a service, asking oneself whether the processing of that data is genuinely necessary for that service".

What to Watch for in Mobile Applications

The Bulletin devotes a separate section to mobile applications. It recommends downloading applications from reliable sources such as official application stores or the provider's official website, checking the developer, and reviewing user comments and ratings. The Bulletin adds a warning here: high ratings and positive comments do not in themselves show that an application is reliable.

It also advises reviewing the application's privacy policy and the permissions it requests, and assessing permissions in applications that seek continuous access to data such as location, audio and images by reference to the purposes for which those data are used. Where a social media account is used to log in to an application, checking which information will be shared is recommended, on the ground that this method may allow accounts across different services to be linked with one another.

Smart Glasses: A Technology That Concerns More Than Its User

The most topical theme in this issue is smart glasses. Since these devices are able to record images, audio and certain additional data, they may produce consequences for the personal data and privacy not only of the user but also of those around them.

The Bulletin recommends keeping the scope and duration of recordings limited to what is needed, bearing in mind that advanced microphones may capture nearby conversations without those concerned being aware, refraining from using recording features in environments where the expectation of privacy is high, and disabling those features in places where recording is not permitted. It also advises assessing the possible effects of sharing images or videos featuring other people and, where necessary, obtaining their consent.

The Bulletin further recalls that making image or audio recordings, or sharing such recordings, may give rise to civil or criminal liability depending on the circumstances of the particular case.

What Does This Mean for Workplaces?

Although the Bulletin focuses on individual awareness, the themes it covers may be considered to have implications for workplace practices as well. Smart devices do not enter the workplace only through equipment supplied by the company; an employee's own phone, watch, headphones and home devices may also become part of business processes.

  • Use of personal devices for work purposes: It is common practice for employees to access corporate email, file sharing platforms or communication applications from their own devices. In such arrangements, matters such as the permissions other applications on the device have to contacts, files or notifications, the backing up of corporate data to personal cloud accounts, and the ability of third-party keyboard applications to process the text typed may warrant assessment. How corporate data is to be removed from the device if it is lost or stolen, or when the employment relationship ends, may also give rise to difficulties if not determined in advance.
  • Wearable devices and recording features: Email and message previews appearing on the lock screens of smart watches may come within the view of third parties in open-plan offices. As regards smart glasses with recording features, a need for separate rules may arise for meeting rooms, production areas, laboratories and work areas where customer data is visible. The same matter may also arise in respect of visitors to the office.
  • Smart equipment in meeting rooms: Speakers with voice assistant features, smart screens and solutions generating automatic meeting summaries are able to record the content of meetings and convert it into text. Where such a feature is to be used, informing participants in advance and clarifying matters such as the purpose for which the recording is kept and how long it will be retained may prove important.
  • Company vehicles and connected vehicle technologies: Connected vehicles are able to generate data relating to location, routes and driving behaviour. In addition, where an employee pairs their own phone with the vehicle, contacts and call records may be copied to the vehicle's system. Deleting such data before the vehicle is returned or transferred may be seen as the workplace equivalent of the Bulletin's recommendation to delete data before disposing of a device.
  • Privacy by design in technology procurement: The Bulletin's emphasis on design is also meaningful for companies that do not develop their own products. When procuring new HR software, a tracking system or a smart device, questions may be asked at the purchasing stage about which data are processed, what the default settings are, how retention periods are configured and how access rights can be limited.
  • Policies and awareness: Some of the matters above may be addressed through an acceptable use policy, rules on the use of personal devices and workplace rules on recording devices. In addition, the ten golden rules and the recommendations on mobile applications may be regarded as content that can be used directly in awareness training for employees.

Conclusion

This issue of the KVKK Bulletin treats digital privacy not as a list of prohibitions but as a way of thinking. As stated in the Bulletin, a culture of privacy develops through a person's ability to ask a few basic questions when faced with requests for data: why is this information being requested, is it genuinely necessary, who will be able to access it, how long will it be retained, and what might it reveal about me when combined with other information?

According to the Bulletin, these questions becoming a natural part of everyday digital behaviour is one of the important indicators of a culture of privacy.

You can review the details in the Smart Devices and Digital Privacy Bulletin. (In Turkish)

Notification!

The content in this article is for general information purposes only and belongs to CottGroup® member companies. This content does not constitute legal, financial, or technical advice and cannot be quoted without proper attribution.

CottGroup® member companies do not guarantee that the information in the article is accurate, up-to-date, or complete and are not liable for any damages that may arise from errors, omissions, or misunderstandings that the information may contain.

The information presented here is intended to provide a general overview. Each specific case may require different assessments, and this information may not be applicable to every situation. Therefore, before taking any action based on the information provided in the article, it is strongly recommended that you consult a competent professional in the relevant fields such as legal, financial, technical, and other areas of expertise. If you are a CottGroup® client, do not forget to contact your client representative regarding your specific situation. If you are not our client, please seek advice from an appropriate expert.

To reach CottGroup® member companies, click here.

About The Author

/tr/blog/kvkk-gdpr/item/akilli-cihazlar-ve-dijital-mahremiyet-bireysel-farkindaliktan-is-yeri-kurallarina