Mevzuat Kategorileri
Hukuksal Düzenlemeler
Türkiye’de Kişisel Verilerin Korunması Kanunu, Sosyal Güvenlik Hukuku, Vergi Hukuku, İş Sağlığı ve Güvenliği Mevzuatı, Borçlar Hukuku, İş Hukuku, Ticaret Hukuku, Türk Parası Kıymetini Koruma Mevzuatı, Kambiyo Mevzuatı ve Vatandaşlık ve Göçmenlik Mevzuatı ile ilgili en güncel bilgilerin yer aldığı makalelere buradan ulaşabilirsiniz.
İkili Anlaşmalar
Türkiye ve diğer ülkeler arasında yapılan en güncel uluslararası ikili sosyal güvenlik ve vergi anlaşmalarının tarihlerine ve dokümanlarına buradan ulaşabilirsiniz.
With the Turkish Personal Data Protection Board's ("Board") Principle Decision dated 10 June 2025 and numbered 2025/1072 ("Decision"), published in the Official Gazette dated 26 June 2025 and numbered 32938, the legal nature of sending verification codes via SMS within the scope of product and service delivery processes has been examined, and the corresponding data protection obligations have been clarified.
Upon evaluation of the applications and complaints submitted to the Board, it has been concluded that the act of sending SMS-based verification codes to data subjects during processes such as making payments, creating accounts, submitting offers, making reservations, or completing registrations constitutes a personal data processing activity. The Board emphasized that such activities must be carried out in full compliance with the provisions of the Law on the Protection of Personal Data No. 6698 ("LPPD").
The key determinations set forth in the Decision are summarized below:
When compared with the General Data Protection Regulation ("GDPR"), the approach adopted by the Board reveals a strong alignment. Similar to the LPPD, the GDPR requires that data subjects be provided with clear, comprehensive, and accessible information before the processing of their personal data. In particular, Articles 13, 14, and 22 of the GDPR emphasize the necessity of transparency, accountability, and the right to object to profiling or automated decision-making. In this regard, the Board's Principle Decision serves as an important interpretative tool for implementing these core principles under both legislative frameworks.
In light of the foregoing, it is essential to recognize that SMS-based verification mechanisms—commonly used processes—constitute personal data processing activities and must therefore be designed and managed in accordance with data protection legislation. E-commerce platforms, mobile applications, membership-based services, and similar organizations should review and, where necessary, revise their privacy notices, consent collection procedures, and system infrastructures to ensure compliance with the Decision. Aligning operational practices with the principles of lawfulness, transparency, and accountability will not only support the protection of data subjects' fundamental rights, but will also strengthen institutional compliance and trust.
The full text of the Board's Principle Decision is available here (In Turkish).
Kategori Personal Data Protection Law
Notification!
The content in this article is for general information purposes only and belongs to CottGroup® member companies. This content does not constitute legal, financial, or technical advice and cannot be quoted without proper attribution.
CottGroup® member companies do not guarantee that the information in the article is accurate, up-to-date, or complete and are not liable for any damages that may arise from errors, omissions, or misunderstandings that the information may contain.
The information presented here is intended to provide a general overview. Each specific case may require different assessments, and this information may not be applicable to every situation. Therefore, before taking any action based on the information provided in the article, it is strongly recommended that you consult a competent professional in the relevant fields such as legal, financial, technical, and other areas of expertise. If you are a CottGroup® client, do not forget to contact your client representative regarding your specific situation. If you are not our client, please seek advice from an appropriate expert.
To reach CottGroup® member companies, click here.
About The Author
https://www.cottgroup.com
Personal Data Protection Law (PDPL) in Human Resources Processes: Why is It Important?
Civan Güneş, CottGroup Hukuk ve Mevzuat Ekibi
6 Ekim 2023
Protection of Personal Data in Election Activities
Berfin Erdoğan
4 Nisan 2024
28 January Data Protection Day
CottGroup Hukuk ve Mevzuat Ekibi
27 Ocak 2022
Legitimate Interest of the Data Controller in Data Processing
8 Ocak 2024