KVKK Principle Decision

KVKK Principle Decision on the Publication of Personal Data on Public Institutions’ Websites

The Turkish Personal Data Protection Board’s Decision No. 2026/1301 sets out key principles for public institutions when publishing announcements, lists and documents containing personal data on their websites.

Adem Akkır5 minutes

The Turkish Personal Data Protection Board’s Principle Decision dated 01.07.2026 and numbered 2026/1301 was published in the Official Gazette dated 28.07.2026 and entered into force. The decision sets out important principles regarding the protection of personal data in announcements, notices, lists and documents published online by public institutions and data controllers with public legal personality. The Board considers the publication of documents and lists containing personal data on websites or similar digital platforms as a personal data processing activity, since such publication makes the relevant data accessible to third parties. Accordingly, any public disclosure must comply with the fundamental principles set out under Law No. 6698 on the Protection of Personal Data.

General Approach of the Decision

The Principle Decision is based on the view that public institutions should not publish personal data on their websites in a publicly accessible manner unless such publication is strictly necessary.

In particular, when publishing exam results, recruitment announcements, appointment and placement results, application assessment lists, primary/reserve candidate lists, missing document or application status lists, training, certificate or course results and similar announcements, institutions should prefer more limited and secure methods instead of making personal data publicly visible.

In this respect, the online publication of data such as name and surname, Turkish identification number, address, telephone number, place of birth, place of duty, title, registration number, applied position, candidate/student number, exam score, success status, acceptance/rejection information, primary/reserve status or data that may qualify as special categories of personal data may create significant risks under the Turkish data protection legislation.

Data Minimisation and Proportionality

The decision particularly emphasises the principles of data minimisation and proportionality. Public institutions should assess whether the publication of the relevant information is truly necessary, whether the same purpose can be achieved with less personal data, and whether a personal result inquiry method can be used instead of publishing a public list.

Institutions should also assess whether direct identifiers such as Turkish identification number, telephone number and address are actually necessary. Where possible, masking, anonymisation or access restriction methods should be preferred.

Publishing lists containing personal data online without such an assessment may create a risk of non-compliance with the principles of lawfulness and fairness, processing for specified, explicit and legitimate purposes, and being relevant, limited and proportionate to the purposes for which the data are processed.

Secure Inquiry Methods Instead of Public Lists

The Principle Decision underlines that results and announcements containing personal data should not be published as publicly accessible lists where it is possible to use methods that allow each individual to access only their own result.

In this context, methods such as e-Government verification, two-factor authentication, viewing results through a user account, limited inquiries using an application number together with additional verification information, and secure portals or closed systems may be considered more appropriate than publicly accessible lists.

Publication Period and Review of Previous Content

Even where the publication of content containing personal data is necessary, it should also be assessed whether such content should remain accessible online indefinitely.

Therefore, institutions should determine publication periods for announcements and notices containing personal data, remove expired content, review historical PDFs, announcements, notices and list archives, erase, mask or anonymise unnecessary personal data, and keep records of content removal and destruction processes.

In particular, exam, application, recruitment, course or certificate results from previous years that are still publicly accessible on institutional websites should be reviewed within the scope of the Principle Decision.

Social Media and Digital Announcement Channels Should Also Be Considered

Although the decision focuses on content published on websites, the principles it sets out are also relevant for social media accounts and other digital announcement channels.

Accordingly, institutions should avoid making personal data unnecessarily visible in social media announcements, observe information notice and explicit consent processes when using photographs or videos in relation to events, trainings, ceremonies or field activities, develop moderation practices to prevent the disclosure of personal data through comments, messages or user interactions, and carry out a data protection review before publishing digital content.

Recommended Actions for Institutions

Following the Principle Decision, public institutions and organisations carrying out activities connected with public services are advised to review their website content and assess current and historical announcements, notices, PDFs, lists and result documents from a data protection perspective.

Lists containing personal data should be removed or access-restricted unless publication is necessary. Where publication is mandatory, masking or limited access methods should be used.

For application, exam, assessment and placement results, secure inquiry screens should be preferred instead of publicly accessible lists. Institutions should also determine in advance how long content containing personal data will remain online and operate a removal/destruction process once the relevant period expires.

In addition, social media posts containing photographs, videos, participant information or candidate/employee information should be reviewed separately. It is also advisable to create a short data protection checklist for teams uploading content to websites or social media accounts and to provide awareness training to employees involved in such processes.

Conclusion

The Turkish Personal Data Protection Board’s Principle Decision establishes an important standard requiring public institutions to reassess their practices regarding the online publication of personal data.

The core message of the decision is clear: personal data should not be published online in a publicly accessible manner unless strictly necessary.

Institutions should strike a fair balance between the need to inform the public and the obligation to protect personal data. Where possible, they should prefer secure, individual and limited-access methods. This approach is important both for ensuring compliance with the Turkish data protection legislation and for protecting the privacy of individuals.

Contact

Let us consider this issue together.

Contact us