Introduction
Compensation for unlawful use of personal data in Turkey is an increasingly important legal remedy for individuals whose personal information is collected, stored, used, transferred, disclosed, analyzed, profiled, marketed, published, or retained without a lawful basis. In modern business and public life, personal data is used by employers, hospitals, clinics, hotels, banks, insurance companies, e-commerce platforms, mobile applications, schools, universities, call centers, travel agencies, real estate companies, public institutions, and technology providers. When this use exceeds legal limits, the data subject may have the right to claim compensation.
Unlawful use of personal data is broader than a data breach. A data breach usually refers to unauthorized access, leakage, hacking, or disclosure. Unlawful use may occur even if there is no hacking and no third-party cyberattack. For example, a company may use customer phone numbers for marketing without a lawful basis, an employer may process biometric data without proper conditions, a hospital may use patient photographs for advertising without valid consent, a hotel may share passport details with unauthorized persons, or an online platform may use personal data for profiling beyond the disclosed purpose.
The constitutional foundation of this protection is Article 20 of the Constitution of the Republic of Turkey, which recognizes the right to request protection of personal data, including the rights to be informed, access personal data, request correction or deletion, and learn whether the data is used in line with its intended purposes. Personal data may be processed only in cases provided by law or with explicit consent, and the principles and procedures must be regulated by law.
The main statutory framework is the Personal Data Protection Law No. 6698, known in Turkish practice as KVKK. The official English text states that the purpose of the law is to protect fundamental rights and freedoms, particularly privacy, in the processing of personal data and to regulate the obligations, principles, and procedures binding natural or legal persons who process such data.
What Is Unlawful Use of Personal Data?
Unlawful use of personal data means using personal information in a way that is not permitted under Turkish data protection law. It may involve processing without explicit consent where consent is required, processing without another legal basis, using data for a purpose different from the original purpose, collecting excessive data, retaining data longer than necessary, transferring data to unauthorized third parties, using personal data for direct marketing unlawfully, profiling a person without proper legal grounds, or refusing to delete data after the reason for processing no longer exists.
KVKK defines personal data as any information relating to an identified or identifiable natural person. It defines processing very broadly, including collection, recording, storage, protection, alteration, disclosure, transfer, retrieval, making available, categorization, and preventing the use of personal data. Therefore, “use” is not limited to active publication. Even storing, analyzing, transferring, or categorizing data may qualify as processing.
This broad definition is very important for compensation claims. A person may seek compensation not only when data is leaked online, but also where a company uses their identity details, photographs, health records, phone number, e-mail address, location data, biometric data, or employment information for an unlawful purpose.
Lawful Processing Conditions Under KVKK
The general rule under Article 5 of KVKK is that personal data cannot be processed without the explicit consent of the data subject. However, the law also allows processing without explicit consent in certain limited cases, such as where processing is expressly provided by law, necessary for protecting life or physical integrity, directly related to establishment or performance of a contract, necessary for the data controller’s legal obligation, made public by the data subject, necessary for establishment or protection of a right, or necessary for legitimate interests provided that fundamental rights and freedoms are not violated.
A common legal mistake is assuming that every signed consent form makes processing lawful. Under KVKK, explicit consent is defined as freely given, specific, and informed consent. If consent is hidden inside a general contract, obtained under pressure, not specific to the processing purpose, or not based on proper information, it may be challenged.
Another common mistake is relying on “legitimate interest” too broadly. Legitimate interest cannot override the fundamental rights and freedoms of the data subject. For example, a company may have a commercial interest in marketing, but that does not automatically justify using personal data for advertising without proper legal basis and notice.
General Principles of Personal Data Processing
Even where there is a legal basis, processing must comply with the general principles under Article 4 of KVKK. Personal data must be processed lawfully and fairly, be accurate and kept up to date where necessary, be processed for specified, explicit, and legitimate purposes, be relevant, limited, and proportionate to the purposes, and be stored only for the period required by law or by the purpose of processing.
These principles are central in compensation claims for unlawful use of personal data. A company may have collected data lawfully at first, but later use it unlawfully. For example, a customer may provide a phone number for delivery, but the company may later use it for unrelated marketing. A patient may provide photographs for medical records, but the clinic may later use them in advertisements. An employee may provide biometric data for security purposes, but the employer may use it for broader monitoring beyond necessity.
A strong compensation claim should therefore identify not only the data collected, but also the purpose originally disclosed, the later use, why the later use was unlawful, and how the data subject suffered damage.
Special Categories of Personal Data
Special categories of personal data receive stronger protection. Article 6 of KVKK includes data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other belief, appearance, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, biometric data, and genetic data. The 2024 amendments revised the processing conditions for special categories of personal data, and processing remains prohibited unless one of the listed legal conditions is met.
Unlawful use of special categories of personal data may justify stronger compensation arguments because the risk of personal harm is higher. A health record, genetic test result, biometric record, sexual life information, criminal conviction data, or union membership information can affect a person’s dignity, reputation, employment, family life, insurance status, and social relations.
For example, if a private hospital uses patient photographs in promotional materials without valid explicit consent, this may violate both health data protection and personality rights. If an employer shares an employee’s health report with unauthorized managers, the employee may claim moral compensation. If biometric data is collected disproportionately and used beyond the declared access-control purpose, the employee may challenge the processing and seek remedies.
Data Controller Liability
The data controller is the natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system. In most compensation claims, identifying the data controller is the first strategic step.
The data controller may be a company, hospital, employer, hotel, clinic, school, platform, bank, insurance company, app operator, public institution, association, foundation, or professional service provider. A processor may process data on behalf of the controller, such as a payroll company, cloud provider, call center, software vendor, marketing agency, or HR platform. Under Article 12, if processing is carried out by another person on behalf of the controller, the controller is jointly responsible with that person for data security measures.
This is important because companies often attempt to shift responsibility to vendors. A data subject should not accept a simple answer such as “our software provider did this” or “our marketing agency sent the message.” The controller’s duty to select, supervise, audit, and restrict processors may still be examined.
Unlawful Use for Marketing and Advertising
One of the most common forms of unlawful personal data use is marketing misuse. This may include using phone numbers, e-mail addresses, customer profiles, purchase history, location data, or social media information for advertising without proper legal basis.
Examples include sending promotional messages to customers who only provided their data for delivery, using medical patients’ before-and-after photographs in advertisements without valid consent, using hotel guest data for unrelated campaigns, sharing customer data with business partners for promotions, or using website behavior for profiling without adequate notice and lawful basis.
Marketing misuse can cause both material and moral harm. Material harm may arise if the person suffers fraud, unwanted charges, business loss, or costs of changing phone numbers or accounts. Moral harm may arise from distress, loss of control over personal information, repeated disturbance, embarrassment, or exposure of sensitive interests.
A compensation claim should preserve marketing messages, consent records, privacy notices, opt-out requests, screenshots, e-mails, call records, and any response from the controller.
Unlawful Use of Employee Personal Data
Employers process significant personal data: identity records, bank details, payroll, performance files, health reports, criminal record documents where lawfully required, biometric data, CCTV images, disciplinary records, e-mails, vehicle tracking, entry-exit logs, and sometimes family information.
Unlawful employee data use may occur where an employer processes excessive data, uses health data without legal basis, monitors employees disproportionately, shares salary or disciplinary data with unauthorized people, transfers employee data abroad without proper safeguards, uses biometric access systems without necessity, or keeps employee data after the employment relationship ends without a valid retention reason.
Employee data claims may involve KVKK, employment law, personality rights, labor court procedure, and sometimes criminal law. The employee may request information from the employer, seek deletion or correction, file a complaint with the Personal Data Protection Board, and claim compensation if damage arises from unlawful processing.
Evidence may include HR documents, e-mails, internal announcements, biometric system records, camera notices, privacy notices, employment contracts, disciplinary correspondence, witness statements, and data subject application responses.
Unlawful Use of Patient and Health Data
Health data misuse is one of the strongest grounds for compensation. Hospitals, clinics, doctors, dentists, laboratories, pharmacies, medical tourism companies, insurance companies, and digital health platforms must treat health data with strict confidentiality.
Unlawful use may include sharing test results with unauthorized persons, using patient photos for advertisements, disclosing diagnosis to an employer, transferring medical files to third parties without legal basis, using medical records for marketing, or failing to delete patient data after the lawful retention purpose ends.
Article 6 of KVKK treats health data as a special category of personal data, and processing is permitted only under the conditions set out in the law and subject to adequate measures determined by the Board. This makes health data misuse particularly sensitive.
A patient may claim material damages if the misuse causes financial loss, treatment expenses, loss of employment, or identity fraud. The patient may also claim moral compensation for humiliation, anxiety, fear, loss of dignity, damage to reputation, and violation of medical privacy.
Unlawful Use of Biometric and Genetic Data
Biometric and genetic data are among the most sensitive data categories. Biometric data may include fingerprints, face recognition templates, iris scans, voice patterns, palm vein data, and similar identifiers. Genetic data may reveal biological, familial, and health-related information.
Unlawful use of biometric data may occur in workplaces, gyms, schools, residential sites, hotels, hospitals, or security systems. A controller must show a lawful basis, proportionality, necessity, adequate measures, and compliance with processing principles. Biometric processing can be challenged where a less intrusive method would achieve the same purpose.
Genetic data misuse may cause long-term risks because it may reveal predisposition to diseases, family relationships, ancestry, and sensitive biological information. If genetic data is used without lawful basis, transferred to third parties, used for insurance or employment decisions, or stored insecurely, compensation claims may be significant.
Cross-Border Transfer and Unlawful Use Abroad
Personal data transferred abroad may be misused by foreign group companies, cloud providers, software vendors, international platforms, call centers, or marketing partners. Article 9 of KVKK was amended in 2024 and now regulates cross-border transfers through adequacy decisions, appropriate safeguards such as binding corporate rules, standard contracts, written commitments, and limited incidental transfer grounds. Standard contracts must be notified to the Authority within five business days after signature.
Unlawful cross-border transfer may support a compensation claim where the transfer causes damage or increases the risk of misuse. For example, a Turkish company may transfer customer data to a foreign marketing provider without proper safeguards, or a health tourism agency may transfer patient data to foreign partners beyond the disclosed purpose.
A strong claim should ask where the data was transferred, for what purpose, under which legal basis, whether an adequacy decision or safeguard existed, whether the data subject was informed, and whether the transfer caused or contributed to harm.
Right to Claim Compensation Under KVKK
Article 11 of KVKK gives each person the right to claim compensation for damage arising from unlawful processing of their personal data. This is the central legal basis for compensation for unlawful use of personal data in Turkey.
The right to compensation may cover both material damages and moral compensation, depending on the facts. Material damages require proof of financial loss. Moral compensation may be claimed where unlawful use causes emotional distress, humiliation, fear, loss of dignity, reputational harm, or violation of personality rights.
The data subject should not confuse administrative fines with personal compensation. A Board decision may lead to administrative consequences for the controller, but fines are not automatically paid to the data subject. A person seeking monetary recovery generally needs a civil compensation claim, settlement, or another legally enforceable route.
Material Damages for Unlawful Use of Personal Data
Material damages are financial losses caused by unlawful data use. Examples include identity theft losses, unauthorized transactions, costs of replacing identity documents, legal expenses, digital security expenses, loss of business, loss of employment opportunity, medical expenses caused by psychological harm, costs of changing phone numbers or addresses, and financial damage resulting from profiling or unlawful disclosure.
For example, if a company unlawfully shares customer data with a third party and the customer later suffers fraud directly connected to that misuse, financial compensation may be claimed. If an employer unlawfully discloses an employee’s health data and the employee loses a job opportunity, material damages may be evaluated. If a clinic unlawfully publishes patient photographs and the patient suffers professional loss, material damages may be added to moral compensation.
Material damages must be documented. Bank records, police complaints, invoices, screenshots, employment records, customer correspondence, tax documents, expert reports, and data controller responses may be necessary.
Moral Compensation for Unlawful Use of Personal Data
Moral compensation is often the main remedy in personal data misuse cases. Many unlawful uses do not immediately cause measurable financial loss but seriously affect dignity, privacy, reputation, emotional peace, and personal autonomy.
The Turkish Code of Obligations contains general tort provisions and moral compensation rules for personality rights violations. Article 49 establishes liability for damage caused by faulty and unlawful conduct, while Article 58 allows monetary moral compensation where personality rights are damaged.
Unlawful use of personal data may violate personality rights because personal data is closely linked to identity, private life, honor, autonomy, and reputation. A person may feel exposed, humiliated, watched, profiled, manipulated, or deprived of control over their personal identity.
The strongest moral compensation claims usually involve sensitive data, public exposure, repeated misuse, intentional conduct, refusal to delete data, unlawful publication, reputational damage, health data, biometric data, children’s data, or use of photographs in advertising.
Criminal Aspects of Personal Data Misuse
Unlawful use of personal data may also have criminal consequences. Turkish Criminal Code provisions include violation of private life, unlawful recording of personal data, and unlawful delivery, publication, or acquisition of personal data. Constitutional Court materials quote Article 136 of the Turkish Criminal Code as punishing a person who unlawfully gives personal data to another, publishes it, or acquires it.
A criminal complaint may be useful where data was intentionally disclosed, published, sold, obtained, or used for blackmail, harassment, fraud, stalking, or reputational harm. However, criminal proceedings and civil compensation are different. A criminal investigation may support evidence collection and fault analysis, but a data subject seeking money damages should also evaluate civil compensation routes.
Application to the Data Controller
Before applying to the Personal Data Protection Board, the data subject generally must apply to the data controller. Article 13 of KVKK states that requests relating to implementation of the law must be made to the controller in writing or by other methods determined by the Board, and the controller must respond as soon as possible and at the latest within thirty days.
A data subject application should be precise. It may request whether personal data is processed, the purpose of processing, legal basis, recipients, transfers abroad, correction, erasure, destruction, restriction of unlawful use, information on automated processing, and compensation position.
This application is also important evidence. If the controller refuses to respond, gives a vague answer, denies obvious processing, or fails to explain the legal basis, this may strengthen later complaint and litigation strategy.
Complaint to the Personal Data Protection Board
If the controller rejects the request, gives an insufficient answer, or does not respond within the legal time, the data subject may complain to the Personal Data Protection Board. Article 14 provides that a complaint must be lodged within thirty days from learning the controller’s response and in any event within sixty days from the request date; it also states that a complaint cannot be made before the controller application route is exhausted.
The Board may investigate the complaint, request documents, order the controller to remedy violations, and take measures under KVKK. However, the Board process does not replace a civil compensation claim. If the data subject seeks monetary damages, the Board decision may be used as supportive evidence, but compensation may need to be claimed before the competent court.
Evidence Required for Compensation Claims
Evidence is decisive in unlawful personal data use cases. The claimant should preserve privacy notices, consent forms, contracts, screenshots, advertising materials, marketing messages, e-mails, call records, data subject application documents, controller responses, Board complaint records, breach notices, witness statements, online publications, metadata, bank records, fraud reports, employment records, medical reports, and expert opinions.
If unlawful use occurs online, screenshots should show the URL, date, time, platform name, account identity, content, and visibility. Notarial determination or technical expert preservation may be useful where content can be deleted quickly.
If the case involves marketing misuse, the claimant should preserve each message and opt-out request. If it involves health data, the patient should obtain medical records and consent documents. If it involves employee data, HR records and internal communications may be important. If it involves biometric data, the system’s purpose, method, retention, access controls, and alternatives should be examined.
Burden of Proof and Causation
The claimant must generally prove unlawful processing, damage, and causal link. In practice, this may be difficult because much of the evidence is held by the data controller. Therefore, the data subject application is important because it forces the controller to explain the processing activity.
Causation is especially important in material damage claims. If the claimant alleges fraud after unlawful use of data, the claimant should connect the leaked or misused data to the fraudulent transaction. If the claimant alleges job loss after disclosure of health data, the claimant should show how the disclosure affected the employment decision.
For moral compensation, the focus is usually the seriousness of the unlawful use, the sensitivity of the data, the scope of disclosure, the controller’s fault, the emotional impact, and the continuing risk.
Limitation Periods
Limitation periods must be evaluated according to the legal basis of the claim. KVKK provides the right to claim compensation, while civil compensation claims may also rely on general tort and personality rights provisions. For tort-based claims, Article 72 of the Turkish Code of Obligations generally provides a two-year period from the date the injured party learns of the damage and the liable person, and a ten-year long-stop period from the date of the act; if the act also constitutes a criminal offense subject to a longer limitation period, the longer criminal period may apply.
Board complaint deadlines are different from civil limitation periods. The Article 13 controller application and Article 14 complaint deadlines must be followed carefully if the data subject wants administrative review. Civil compensation timing should be analyzed separately.
The safest approach is to act quickly. Digital evidence may disappear, systems may be updated, employees may leave, records may be deleted, and data may continue to circulate.
Claims by Foreigners in Turkey
Foreign nationals may claim compensation for unlawful use of personal data in Turkey if their data is processed by a Turkish data controller or the violation has sufficient connection with Turkey. This may include foreign patients in medical tourism, tourists in hotels, foreign employees, international students, foreign customers of Turkish e-commerce platforms, expatriates, investors, or business visitors.
Foreign claimants should preserve passports, contracts, treatment files, hotel forms, booking records, consent documents, e-mails, screenshots, marketing messages, invoices, employment records, and evidence of harm. If documents are issued abroad, sworn translation and apostille or legalization may be required depending on the procedure.
A Turkish lawyer can usually pursue controller applications, Board complaints, criminal complaints, settlement negotiations, and civil lawsuits through a properly issued power of attorney.
Common Mistakes in Personal Data Compensation Claims
One common mistake is assuming that every privacy discomfort automatically leads to compensation. The claimant must show unlawful processing, damage, and causal connection.
Another mistake is filing a Board complaint without first applying to the data controller. Article 14 requires exhaustion of the controller application route before complaint.
A third mistake is failing to preserve evidence. Unlawful posts, marketing messages, data use records, and online advertisements may disappear quickly.
A fourth mistake is focusing only on administrative fines. Administrative fines do not automatically compensate the data subject.
A fifth mistake is signing a broad consent or settlement after the violation without understanding its consequences.
A sixth mistake is ignoring special categories of personal data. Health, biometric, genetic, criminal, union-related, and similar sensitive data may require stronger legal analysis and higher compensation arguments.
Why Work With a Turkish KVKK Lawyer?
Compensation for unlawful use of personal data in Turkey requires knowledge of KVKK, constitutional privacy rights, civil compensation law, personality rights, technology evidence, criminal law, employment law, healthcare confidentiality, consumer law, and administrative procedure.
A Turkish KVKK lawyer can identify the data controller, determine the unlawful processing activity, prepare data subject applications, file Board complaints, preserve digital evidence, evaluate criminal complaint options, calculate material damages, prepare moral compensation claims, negotiate settlement, and file civil lawsuits.
For companies, legal advice is equally important. A company accused of unlawful data use must review processing purposes, consent records, privacy notices, legal bases, retention periods, cross-border transfers, processor agreements, data security measures, and response strategy. Poor handling may increase administrative, civil, criminal, and reputational risk.
Conclusion
Compensation for unlawful use of personal data in Turkey protects individuals whose identity, privacy, dignity, autonomy, reputation, financial security, or sensitive information has been harmed by unlawful processing. The protection is rooted in Article 20 of the Constitution and regulated mainly by KVKK. The law gives data subjects the right to learn whether data is processed, learn the purpose of processing, know recipients, request correction, request deletion or destruction, object to certain automated results, and claim compensation for damage arising from unlawful processing.
Unlawful use may occur through marketing misuse, employee monitoring, health data disclosure, biometric processing, unauthorized transfer, profiling, publication of photographs, data use beyond the original purpose, excessive retention, or cross-border transfer without proper safeguards. A successful claim requires clear evidence, careful legal basis, proof of damage, and a strategy combining KVKK applications, Board complaints, civil compensation, and where necessary, criminal complaint.
Anyone whose personal data has been unlawfully used in Turkey should act quickly, preserve evidence, apply to the data controller, observe Board complaint deadlines, and obtain legal advice before signing any consent, waiver, or settlement. A carefully prepared personal data compensation claim can make a decisive difference in protecting privacy, dignity, and financial rights.
Yanıt yok