The Turkish Data Protection Authority Publishes Principle Decision on the Processing of Personal Data of Accident Victims

The Turkish Data Protection Authority (the Personal Data Protection Board) published its Principle Decision No. 2026/1095, dated 20 May 2026, on the Processing of Personal Data of Accident Victims (the "Principle Decision") in the Official Gazette dated 1 July 2026 and numbered 33297.

The Principle Decision provides, in summary, the following key assessments:

  • It has been determined that entities operating under the name of damage consultancy companies, as well as unauthorized individuals falsely presenting themselves as attorneys despite not being registered with a bar association, have been contacting victims of workplace and traffic accidents without their consent. These individuals were found to have obtained unauthorized access, through various channels, to accident reports containing victims' identity and contact information following the occurrence of the accident.
  • It was further observed that victims were promised compensation in exchange for granting powers of attorney, subjected to persistent telephone calls and intimidation through claims that they would suffer a loss of rights if they did not act immediately, and, in certain cases, legal actions were even initiated on behalf of victims without any instructions from them.
  • Referring to the provisions of the Attorneyship Law No. 1136, the Principle Decision reiterates that only licensed attorneys are authorized to perform legal representation activities and recalls the prohibition on attorney advertising. It further emphasizes that, pursuant to Additional Article 6 of the Insurance Law No. 5684, compensation claims may only be paid to the rightful claimant or the claimant's attorney. Such claims cannot be assigned to third parties or institutions, and any agreement or assignment to the contrary made with damage consultancy companies is deemed absolutely null and void under the Turkish Code of Obligations No. 6098. The Decision also states that damage consultancy companies may only operate lawfully through attorneys, whether directly or indirectly.
  • The Board also evaluates that personal data processing activities carried out in violation of the applicable legislation may constitute the criminal offence of "unlawfully obtaining or disclosing personal data" under Article 136 of the Turkish Criminal Code No. 5237, together with the aggravated circumstances regulated under Article 137. In this context, the Decision notes that victims may file criminal complaints with the Public Prosecutor's Office and may also submit administrative complaints to the relevant ministries and bar associations.
  • The Principle Decision further requires data controllers that hold or process accident victims' personal data (such as through accident reports and similar documentation) to implement appropriate technical and administrative measures in accordance with Article 12 of the Personal Data Protection Law No. 6698 in order to ensure data security. In particular, data controllers are expected to:
    • provide regular employee training and awareness activities on personal data protection;
    • restrict access to personal data in accordance with the principle of least privilege;
    • implement role-based access controls; and
    • establish regular monitoring and auditing mechanisms within their information systems.
  • Finally, the Turkish Data Protection Authority reminds data controllers that those who fail to comply with the requirements set out in the Principle Decision and continue unlawful personal data processing activities by failing to implement the necessary administrative and technical safeguards may be subject to administrative fines pursuant to Article 18 of the Personal Data Protection Law No. 6698.

You can access full text of the Principle Decision here.