I. INTRODUCTION
The Principle Decision No. 2026/1301 of the Personal Data Protection Board (“Board”), dated July 1, 2026, was published in the Official Gazette on July 28, 2026; and the Public Announcement regarding the Principle Decision was shared with the public on the website of the Personal Data Protection Authority on July 27, 2026. The Principle Decision sets out the principles to be followed regarding the sharing of personal data on the internet by public institutions and organizations, as well as municipalities, provincial special administrations, universities, and similar data controllers with public legal personality. As a result of the examination of various complaints and reports submitted to the Authority by the Board, determinations and assessments have been made regarding the risks that such data processing activities pose in terms of the Law No. 6698 on the Protection of Personal Data (“Law”) and the obligations that data controllers must observe.
The fundamental approach of the Principle Decision is that the sharing of personal data by data controllers with public legal personality, while fulfilling their public duties, is not independent of the legality requirements and general principles stipulated in the Law. In this context, the publication of personal data on the publicly accessible internet is not considered merely an announcement or information activity, but rather a personal data processing activity that, under the Law, must be based on a legal basis and carried out in a manner that is relevant to the purpose, limited, and proportionate.
The Principle Decision concretizes the obligations stipulated in the Law specifically regarding the sharing of personal data on the internet. In this context, the Decision requires that sharing be based on a valid processing condition, comply with the general principles of the Law, and in particular be relevant to the purpose, limited, and proportionate; that personal data not be kept accessible for longer than necessary; that existing sharing be reviewed; and that, where possible, secure methods be preferred, allowing only the data subjects to access their own results. In this respect, the Decision establishes a compliance framework that necessitates a reassessment of public institutions' digital announcement and notice practices from the perspective of personal data protection law.
II. EVALUATIONS
The Board's investigations have revealed that data controllers with public legal personality publish numerous personal data on their websites, including: name and surname, mother's and father's names, age, Turkish Republic identity number, address, mobile phone number, place of birth, profession, field of expertise, place of duty, title/status, years of service, registration number, unit worked in, military status, educational information, plot/parcel information regarding real estate, exam application number, KPSS score, acceptance or rejection information, success status, information about the school graduated from, number of correct-incorrect-net answers, position applied for, candidate and student number, reason for not participating in or being rejected from the exam, main-reserve information, information about missing documents, and status of being a former convict. Data related to criminal convictions and security measures, such as status of being a former convict, are considered special categories of personal data, and the special protection regime stipulated in Article 6 of the Law must be taken into account when such data is shared.
The publication of personal data on the internet constitutes a personal data processing activity under the Law, as it results in the data being made accessible and disclosed to third parties. Therefore, any sharing carried out by data controllers with public legal personality must be based on a valid personal data processing condition stipulated in Article 5 of the Law for personal data and Article 6 for special categories of personal data. If a valid processing condition does not exist, personal data should not be shared on the internet; if such sharing already exists, it must be terminated.
The existence of a valid processing condition does not justify the unlimited publication of personal data. Data processing activities must comply with the general principles set forth in Article 4 of the Law; in particular, they must be carried out for a specific, clear, and legitimate purpose, be relevant, limited, and proportionate to the processing purpose, and the data must be retained only for the period necessary for the purpose for which it was processed. In this context, the mere fact that a public institution has the authority to announce a specific result or action does not, by itself, justify the public disclosure of all available information about an individual within the scope of that announcement.
In evaluating the principle of proportionality, it is important to strike a reasonable balance between the purpose of the disclosure and the scope of personal data made public. If the purpose of the announcement or notice can be achieved using more limited data, then personal information such as Turkish Republic identity number, full address, telephone number, or similar details that unnecessarily identify the individual should not be shared; where sharing is necessary, it should be limited to the minimum data required to achieve the purpose, and measures such as masking and anonymization should be used.
Another important aspect emphasized in the Principle Decision is the length of time personal data remains publicly accessible. If the legal basis and purpose of sharing exist only for a specific period, allowing the personal data to remain accessible online after that period expires may be incompatible with the Law's principle of "retention only for the period necessary for the purpose for which they were processed." Therefore, data controllers must determine in advance the duration for which announcements and notices will remain online, terminate access when the processing purpose ceases to exist, and, where necessary, subject the relevant data to processes of deletion, destruction, or anonymization.
The Public Announcement also explicitly states that, regarding personal data to be shared online, the obligation to inform under Article 10 of the Law must be fulfilled, and the burden of proof that this information has been provided rests with the data controller. In this context, the information provided to the data subjects should be evaluated to include the online sharing activity, the purpose of the sharing, and the individuals or recipient groups to whom the data will be accessible.
In addition, pursuant to Article 12 of the Law, necessary administrative and technical measures must be taken to ensure the security of personal data. The Board particularly emphasized that sharing personal data over the internet carries a higher data security risk compared to sharing data in more restricted environments; and stated that data controllers should consider this risk level when determining the administrative and technical measures to be taken.
The Board deems it appropriate to prioritize secure methods that allow only the relevant individuals to access their own results, particularly in announcements such as exam results and lottery results, depending on the specific circumstances of the case. In this context, e-Government platforms or platforms using two-factor authentication methods stand out. In cases where sharing specific data is necessary due to the nature of the specific situation, the scope of sharing must be limited to the minimum data required for a legitimate purpose, and appropriate security measures must be implemented.
The Principle Decision imposes a review obligation on data controllers not only regarding future sharing but also regarding currently accessible content. Accordingly, scanning existing internet content is important; sharing that is not based on a valid processing condition, whose processing purpose has ended, or that does not comply with general principles should be promptly removed or, where necessary, masked. In cases where the reason for processing has completely ceased to exist, the data must be subjected to the relevant data destruction processes.
The Public Announcement also emphasized that data controllers should regularly conduct training and awareness activities to increase the knowledge and awareness levels of all employees, especially those responsible for the use of websites and social media platforms, regarding the protection of personal data. Furthermore, to ensure the sustainable implementation of these obligations, it would be appropriate to establish internal mechanisms within the organization to review the legal basis, purpose, scope of data, method of sharing, and duration of publication before data sharing.
The Public Announcement explicitly states that if non-compliance with the specified obligations is detected, the necessary investigation will be conducted taking into account the specifics of the case, and administrative action will be taken against the relevant data controllers in accordance with Article 18 of the Law. However, a special sanctions regime is foreseen in the fourth paragraph of Article 18 of the Law for public institutions and organizations. If the acts listed in the said article are committed within public institutions and organizations, disciplinary action will be taken against the relevant officials and other public employees according to disciplinary provisions upon notification by the Board, and the outcome will be reported to the Board. Therefore, the Principle Decision should be considered not only as a recommendation for a framework of good practice, but also as a compliance standard that the Board will use in its subsequent reviews when evaluating the data sharing practices of data controllers with public legal personality.
III. CONCLUSION
The Principle Decision considers the publication of personal data on the internet by data controllers with public legal personality not as a natural and unlimited consequence of public activity, but as an independent data processing activity subject to the grounds of legality and general principles stipulated in the Law. According to this approach, the necessity of making an announcement or publication for the fulfillment of a public duty does not eliminate the need for a separate proportionality review regarding the scope of the data to be shared, the duration of accessibility, and the method of sharing.
In this context, it is important for public institutions and organizations to systematically review their existing internet content and announcement processes containing personal data; to determine the applicable processing conditions for each posting; to publish only the minimum data required for the purpose; to apply masking or anonymization in necessary areas; to limit access times; and, where possible, to prefer secure platforms where individuals can only access their own data. Furthermore, it is necessary to fulfill the obligation to inform under Article 10 of the Law regarding online sharing and to take appropriate administrative and technical measures, considering that the internet environment carries a higher data security risk, in accordance with Article 12 of the Law. Furthermore, posts whose processing reason or purpose has ceased to exist must be removed from access and the necessary data destruction processes must be implemented.
The effective implementation of the Principle Decision should not be limited to a one-time review of existing content. In this context, a combined approach involving pre-publication legal compliance checks, periodic content screening, access and publication duration management, staff training, and internal audit mechanisms would be an appropriate compliance method for fulfilling the obligations specified in the Principle Decision in an institutional and sustainable manner. Considering that the Board may take action under Article 18 of the Law as a result of case investigations in case of non-compliance with these obligations, it is deemed appropriate that compliance efforts in line with the Principle Decision be carried out without delay and within the framework of an institutional action plan.