Mevzuat Kategorileri
Hukuksal Düzenlemeler
Türkiye’de Kişisel Verilerin Korunması Kanunu, Sosyal Güvenlik Hukuku, Vergi Hukuku, İş Sağlığı ve Güvenliği Mevzuatı, Borçlar Hukuku, İş Hukuku, Ticaret Hukuku, Türk Parası Kıymetini Koruma Mevzuatı, Kambiyo Mevzuatı ve Vatandaşlık ve Göçmenlik Mevzuatı ile ilgili en güncel bilgilerin yer aldığı makalelere buradan ulaşabilirsiniz.
İkili Anlaşmalar
Türkiye ve diğer ülkeler arasında yapılan en güncel uluslararası ikili sosyal güvenlik ve vergi anlaşmalarının tarihlerine ve dokümanlarına buradan ulaşabilirsiniz.
Principle Decision No. 2026/921 of the Personal Data Protection Board ("Board") dated April 29, 2026 on the Processing of Biometric Data for Attendance Tracking Purposes ("Principle Decision") was published in the Official Gazette dated June 2, 2026. Following the publication of the Principle Decision, various requests for opinion were submitted to the Personal Data Protection Authority ("Authority") by data controllers operating in different sectors, and these requests gave rise to the need to clarify certain matters.
By way of the public announcement published on August 27, 2026, the Authority resolved these uncertainties and clarified the scope of application of the Principle Decision.
In our previously published article titled "KVKK Principle Decision: Processing of Biometric Data for Attendance Tracking Purposes" we addressed the scope of the Principle Decision, the regime to which biometric data is subject as a special category of personal data, the assessment that explicit consent does not constitute a sufficient legal basis on its own due to the imbalance of power in the employer and employee relationship, and the court decisions referred to by the Board. In this article, we assess the matters clarified by the announcement and their practical consequences for data controllers.
The use of biometric identification systems has become increasingly widespread for the purposes of carrying out employee attendance tracking digitally and enhancing workplace security, and the Authority has established that this practice is among the unlawful practices most frequently raised in the reports and complaints submitted to it.
Special categories of personal data are exhaustively regulated under Article 6 of the Personal Data Protection Law No. 6698 ("Law"), and biometric data falls within this scope. It is not possible to extend the categories of special categories of personal data listed in the Law by analogy.
Although employers are under an obligation to track and document working hours pursuant to Article 9 of the Regulation on Working Times Relating to the Labor Law, titled "Documentation of Working Time," there is no explicit statutory provision requiring this obligation to be fulfilled through the use of biometric identification systems. For this reason, the Principle Decision concluded that biometric data processing activities carried out solely for attendance tracking purposes do not rely on any of the processing conditions set out in Article 6 of the Law, and that even where valid explicit consent exists, such processing would not satisfy the proportionality criterion regulated under Article 4 of the Law.
In the requests for opinion submitted to the Authority, it was argued that data obtained through methods such as palm scanning or fingerprint collection should not be regarded as biometric data.
The Authority did not accept this approach. Although the legislation does not contain a comprehensive definition of biometric data, Article 3 of the Civil Registration Services Law No. 5490 defines biometric data as person-specific data obtained from fingerprints, vein patterns and the palm of the hand for the purposes of identification and authentication through electronic systems.
The announcement further refers to Recital 51 of the European Union General Data Protection Regulation, stating that data rendered capable of uniquely identifying or authenticating a natural person through the use of a specific technical method constitutes biometric data. Accordingly, converting such data into a mathematical code and storing it in a database does not remove its nature as biometric data.
This finding directly addresses a defense frequently encountered in practice. The fact that the system stores only a template or hash value rather than the raw fingerprint image does not result in the processing activity being assessed outside the regime applicable to special categories of personal data.
The second matter clarified by the announcement concerns the scope of the Principle Decision. The Principle Decision addresses biometric data processing activities carried out for employee attendance tracking purposes.
Biometric data processing activities falling outside attendance tracking will not be assessed within the scope of the Principle Decision. The lawfulness of such activities is to be assessed by the data controllers themselves, taking into account the purpose of the processing, the nature of the business and the characteristics of the specific case. As regards reports or complaints submitted to the Authority on this matter, the Board will carry out a separate assessment for each specific case.
This clarification rules out the interpretation that the Principle Decision prohibits biometric data processing altogether. However, falling outside the scope does not amount to a presumption of lawfulness. On the contrary, the burden of assessment remains with the data controller, and it is important that this assessment be documented in accordance with the principle of accountability.
The Authority stated that certain facilities and fields of activity are distinguished from the general assessment on account of the security risk they carry and the consequences that potential breaches may give rise to.
In such areas, biometric identification systems cease to be a tool serving attendance tracking alone and become an inseparable part of multi-layered security processes such as authentication, authorization and control of access to critical areas. Accordingly, in such areas the purpose of processing biometric data is not the monitoring of personnel working hours but, in most cases, directly ensuring security and the security of critical infrastructure.
Nevertheless, this distinction does not grant unlimited discretion. Biometric data processing activities carried out in such areas must also be limited to the necessary critical areas and persons, alternative methods must be insufficient, and the processing activity must be proportionate to the concrete security need.
The point requiring attention in practice is the use of biometric data collected for the purpose of controlling access to critical areas also for attendance tracking purposes. Such use may bring the processing activity back within the scope of the Principle Decision. For this reason, it is important that the system operated for security purposes and the attendance and timekeeping processes be separated in terms of data flow.
The announcement recalls that, pursuant to subparagraph (ç) of the first paragraph of Article 28 of the Law, data processing activities carried out for the protection of national defense, national security, public safety, public order or economic security may, under certain conditions, fall outside the scope of the Law.
While this exception provides significant flexibility for large-scale public security institutions, it does not render the use of biometric data unlimited. An assessment must be carried out for each specific case, taking into account the gravity of the security risk, the insufficiency of alternative methods and the purpose of the processing activity.
In the Authority's words, the decisive matter for compliance with the Principle Decision relates to whether the processing of biometric data goes beyond the purpose of attendance tracking and is used for ensuring public security.
Following the announcement, it is important for companies to review the following matters:
As previously emphasized by the Board, these matters fall within the administrative and technical measures to be taken by data controllers pursuant to the first paragraph of Article 12 of the Law. Where it is established that these matters have not been complied with, action will be taken against the relevant data controllers pursuant to the provisions of Article 18 of the Law.
The public announcement does not alter the obligations set out in the Principle Decision; it clarifies its scope and the limits of its application. Following the announcement, the position may be summarized as follows: processing biometric data for attendance tracking purposes is unlawful even where explicit consent has been obtained. Purposes other than attendance tracking fall outside the scope of the Principle Decision, yet the assessment of proportionality and necessity in those cases rests directly with the data controller.
Companies should therefore ask the following fundamental control question: what is the actual purpose of our system processing biometric data, can that purpose be met through a less intrusive method providing the same level of security, and has this assessment been documented?
If there is no clear answer to this question based on a written assessment, the existing practice should be reconsidered within the scope of the Principle Decision and the announcement.
You can access the relevant announcement here. (In Turkish)
Kategori Personal Data Protection Law
Notification!
The content in this article is for general information purposes only and belongs to CottGroup® member companies. This content does not constitute legal, financial, or technical advice and cannot be quoted without proper attribution.
CottGroup® member companies do not guarantee that the information in the article is accurate, up-to-date, or complete and are not liable for any damages that may arise from errors, omissions, or misunderstandings that the information may contain.
The information presented here is intended to provide a general overview. Each specific case may require different assessments, and this information may not be applicable to every situation. Therefore, before taking any action based on the information provided in the article, it is strongly recommended that you consult a competent professional in the relevant fields such as legal, financial, technical, and other areas of expertise. If you are a CottGroup® client, do not forget to contact your client representative regarding your specific situation. If you are not our client, please seek advice from an appropriate expert.
To reach CottGroup® member companies, click here.
About The Author
https://www.cottgroup.com
The Electronic Submission Deadline for CPA Counter-Examination Minutes Has Been Extended to 2027
Selma Kıy
24 Ağustos 2026
Beneficial Ownership Notification for General, Ordinary & Non-Share Limited Partnerships
7 Ağustos 2026
Reduced Security Requirement for Tax-Compliant Taxpayers
5 Ağustos 2026