Patient Privacy and Medical Data Protection in Turkey for Foreign Nationals

Patient Privacy and Medical Data Protection in Turkey for Foreign Nationals

Foreign patients travelling to Turkey for medical treatment frequently provide significantly more personal information than ordinary tourists.

A hospital may obtain the patient’s:

  • passport information;
  • contact details;
  • medical history;
  • diagnoses;
  • laboratory results;
  • radiological images;
  • prescription information;
  • surgical records;
  • photographs;
  • genetic information;
  • payment information;
  • emergency contact details.

A medical tourism company may additionally process flight, accommodation, transfer and interpreter information.

For patients undergoing cosmetic surgery, dental procedures or hair transplantation, clinics may take detailed before-and-after photographs.

For cancer treatment, IVF or genetic testing, the information processed may be exceptionally sensitive.

This raises an important legal question:

What can a Turkish hospital, doctor or medical tourism company legally do with a foreign patient’s medical information?

Turkey has an extensive legal framework protecting patient privacy and medical data.

The principal rules arise from:

Law No. 6698 on the Protection of Personal Data — the KVKK;

the Patient Rights Regulation;

healthcare-specific legislation;

and, for international medical tourists, the International Health Tourism and Tourist Health Regulation.

Foreign nationality does not remove these protections.

The Patient Rights Regulation applies broadly to individuals receiving healthcare through public and private healthcare institutions, and its fundamental principles prohibit discrimination based on matters including language and other personal differences. The Regulation specifically protects patient confidentiality and medical privacy.

Turkey’s international health tourism legislation also expressly covers foreign nationals travelling temporarily to Turkey for healthcare and imposes data-recording obligations on authorised healthcare facilities and medical tourism organisations. Personal health information recorded under that system must be processed in accordance with the KVKK and the healthcare-specific statutory framework.

For foreign patients, this means that receiving treatment in Turkey does not mean giving a clinic unlimited freedom to use medical records, images or personal information.

Medical treatment requires data processing.

Marketing does not automatically justify the same processing.

That distinction is fundamental.


What Is Personal Health Data Under Turkish Law?

Personal health data includes information concerning a person’s physical or mental health and information relating to healthcare provided to that person.

The Turkish Data Protection Authority explains that examples include:

  • medical test results;
  • illnesses;
  • medicines used;
  • other information connected with healthcare services.

Health data is classified as special-category personal data — özel nitelikli kişisel veri.

Genetic and biometric information is also included among the categories receiving enhanced legal protection under Article 6 of the KVKK.

This enhanced protection exists because disclosure of information concerning a person’s illness, fertility, genetics, mental health or other medical condition can create unusually serious consequences.

For example, unauthorised disclosure could affect:

  • employment;
  • insurance;
  • family relationships;
  • reputation;
  • dignity;
  • personal safety.

Medical information is therefore not treated in the same way as an ordinary customer name or telephone number.


Does the KVKK Protect Foreign Citizens?

Yes, potentially.

The protection of personal data under Turkish law is not limited simply to Turkish citizens.

A foreign patient whose personal data is processed in connection with healthcare in Turkey can qualify as a data subject — ilgili kişi for purposes of Turkish data-protection law.

This can include a British patient undergoing rhinoplasty in Istanbul, a German patient receiving dental implants in Antalya, an American patient undergoing cancer treatment in Turkey or another international patient receiving healthcare through a Turkish provider.

The relevant question is generally the personal-data processing activity and its relationship with Turkish law, not merely the patient’s passport nationality.

A foreign patient may therefore potentially exercise the rights granted under Article 11 of the KVKK against a Turkish hospital, clinic or other relevant data controller.


Medical Privacy and Patient Confidentiality Are Separate From the KVKK

Patient privacy in Turkey does not arise only from data-protection legislation.

The Patient Rights Regulation contains an independent and powerful confidentiality framework.

Article 21 states that respect for patient privacy is essential.

This includes conducting medical evaluations confidentially, performing examination and treatment in an appropriately private environment and excluding persons who are not directly involved in treatment from medical interventions except where legally justified.

Importantly, the Regulation expressly states that death does not eliminate the patient’s right to privacy.

Article 23 goes even further.

Information obtained because healthcare has been provided cannot be disclosed except in legally permitted circumstances.

The Regulation also warns that patient consent does not automatically validate every conceivable disclosure if the disclosure would amount to an excessive surrender or limitation of personality rights.

This means patient confidentiality should not be treated as a simple commercial checkbox.


Can a Hospital Tell My Family About My Condition?

Not automatically in every situation.

Turkish patient-rights rules recognise that the patient can control the communication of health information in significant respects.

Article 20 provides that, except where legislation or competent authority measures require otherwise, a person may request that information concerning his or her health condition not be disclosed to:

  • the patient personally in certain circumstances;
  • relatives;
  • or anyone else.

That decision must be recorded in writing and can later be changed by the patient.

For foreign medical tourists, this can matter where:

  • a spouse travels with the patient;
  • a family member pays the hospital bill;
  • a medical tourism coordinator communicates with relatives.

Paying for treatment does not automatically give a relative unlimited access to all medical information.

The legal authority and patient’s wishes should be examined separately.


Can Doctors and Nurses Discuss My Medical Condition With Other People?

Healthcare professionals can of course share relevant information internally where it is legitimately necessary for treatment.

A surgeon may need to communicate with an anaesthesiologist.

An oncologist may need pathology results.

Nursing staff may require information necessary for medication administration.

That is fundamentally different from discussing the patient’s condition with unrelated staff, friends, other patients or members of the public.

The Patient Rights Regulation specifically provides that healthcare records may be viewed only by persons directly connected with treatment, while the broader confidentiality provisions prohibit unauthorised disclosure.

The legal principle can therefore be summarised as:

necessary medical access is not the same as unrestricted access.


Why Can a Hospital Process Medical Data Without Asking for Consent Every Time?

Foreign patients are sometimes surprised when hospitals process medical information without obtaining a separate consent form for each individual internal use.

This does not necessarily mean the processing is unlawful.

Turkish law recognises that healthcare cannot function if every necessary medical action depends on a new marketing-style consent form.

KVKK Article 6 was materially amended in 2024. The current framework contains several legal grounds for processing special-category personal data rather than treating explicit consent as the only possible basis. The Turkish Data Protection Authority issued an updated guide specifically because Article 6 processing conditions were expanded.

Healthcare legislation was also updated in 2025.

Additional Article 19 of the Basic Health Services Law expressly provides that personal information patients must provide when applying to public or private healthcare institutions, together with information relating to the healthcare supplied, may be processed as required by healthcare services. The Ministry of Health may process such information for purposes including healthcare provision, public health, preventive medicine, diagnosis, treatment, care and health-service planning, subject to the KVKK framework.

Therefore, a hospital may have an independent statutory legal basis for processing information genuinely necessary to:

  • diagnose the patient;
  • perform surgery;
  • maintain medical records;
  • provide follow-up care;
  • comply with Ministry reporting requirements.

But this does not mean the same data can automatically be used for completely unrelated purposes.


Treatment Data and Marketing Data Must Be Distinguished

This distinction is one of the most important parts of Turkish health-data law.

Suppose a foreign patient undergoes rhinoplasty.

The hospital may legitimately need photographs for:

  • clinical evaluation;
  • treatment planning;
  • documentation;
  • postoperative comparison.

That does not automatically mean the clinic may upload those photographs to Instagram.

Likewise, the hospital may need to record that the patient has breast cancer for medical treatment.

That does not automatically mean the patient’s cancer story may be used in a promotional video.

The legal basis for healthcare and the legal basis for advertising are different.

The Turkish Personal Data Protection Board has issued important decisions reinforcing this distinction.


Can a Turkish Doctor Post My Before-and-After Photos on Instagram?

Not automatically.

This is particularly important for foreign patients receiving:

  • rhinoplasty;
  • breast surgery;
  • facelift surgery;
  • dental treatment;
  • hair transplantation;
  • weight-loss treatment.

In Decision No. 2022/630, the Personal Data Protection Board considered photographs taken during a patient’s rhinoplasty and later shared on the surgeon’s social-media account.

The hospital argued that the patient had signed consent relating to use of the images.

However, the Board found that the relevant consent had been given to the hospital, while the photographs were published through the individual doctor’s personal social-media account. The patient had not given the necessary consent for that distinct use.

The Board also rejected the suggestion that partially obscuring the patient’s eyes necessarily made the photograph anonymous: other facial characteristics could still make the patient identifiable.

The hospital was fined because it had failed to take adequate administrative and technical measures to prevent the unlawful processing, and the patient was informed that separate judicial remedies could potentially be pursued against the physician.

This decision has major practical importance.

A patient should always ask:

Who exactly has my permission?

The hospital?

The doctor?

The clinic company?

The medical tourism agency?

These are not necessarily the same legal person.


Covering the Eyes Does Not Automatically Anonymise a Patient

Cosmetic clinics often place a black bar, emoji or digital mark over the patient’s eyes.

That does not automatically mean the image has ceased to be personal data.

If the patient remains identifiable from:

  • the rest of the face;
  • distinctive scars;
  • tattoos;
  • body features;
  • accompanying information,

the image may continue to qualify as personal data.

The 2022/630 Board decision specifically concluded that the rhinoplasty photographs remained capable of identifying the patient despite partial masking of the face.

For foreign patients, this is especially important where clinics publish “anonymous” before-and-after photographs together with:

  • nationality;
  • age;
  • procedure;
  • treatment dates;
  • patient testimonials.

The combination may make a person identifiable even where a name is omitted.


Can a Hospital Use Patient Videos for Advertising With Consent?

Even explicit consent does not necessarily make every form of healthcare advertising lawful.

In Decision No. 2023/787, the Personal Data Protection Board examined the use of patient videos and health information for hospital advertising and promotional purposes.

The Board found that the relevant sector-specific rules prohibited demand-generating hospital advertising. It therefore concluded that even though patients had given explicit consent, consent could not provide a lawful basis for data processing that was itself connected with a legally prohibited advertising practice.

The Board also emphasised the data minimisation and proportionality principle: if public education concerning a disease can be achieved without processing identifiable patient health data, publishing individual patients’ health information may be unnecessary and disproportionate.

This creates an important rule:

Patient consent does not automatically override healthcare advertising law.


Clinical Consent and Marketing Consent Should Not Be Confused

Foreign patients frequently sign many documents immediately before treatment.

These may include:

  • treatment consent;
  • anaesthesia consent;
  • KVKK information notice;
  • data-processing consent;
  • photography consent;
  • marketing consent.

These documents serve different purposes.

Consent to surgery does not automatically mean consent to Instagram advertising.

Consent to clinical photography does not automatically mean consent to publication.

Consent to a hospital’s processing does not necessarily authorise an individual doctor’s independent use.

A legally careful healthcare provider should separate these issues rather than hiding them inside one broad document.

The Turkish Data Protection Authority has repeatedly emphasised that the data-controller information obligation and explicit-consent process are legally distinct and should not simply be merged together. A highly current Authority announcement dated 27 August 2026 again stressed that privacy notices must state the controller’s identity, purposes, recipients, collection method, legal basis and data-subject rights in clear and accessible language.


What Information Must the Hospital Give the Patient Under the KVKK?

Article 10 of the KVKK requires the data controller to provide information at the time personal data is obtained.

The information should include:

  • identity of the data controller and representative, where applicable;
  • purposes for which personal data will be processed;
  • persons or recipient categories to whom data may be transferred and purposes of transfer;
  • method and legal basis of collection;
  • Article 11 rights.

The Data Protection Authority’s 27 August 2026 announcement specifically warned data controllers against vague privacy notices, failure to identify legal bases, inadequate explanations of recipient groups and inaccessible privacy information. It emphasised that privacy notices should use clear and understandable language.

This matters greatly for foreign patients.

A document titled:

“Privacy Policy”

that merely says:

“Your data may be shared with necessary persons where required”

may not provide meaningful information about:

  • who receives the data;
  • why;
  • under which legal basis.

Should the Privacy Notice Be in English?

Turkish data-protection legislation does not create a simple rule that every hospital must always provide every KVKK document in English merely because a patient is foreign.

However, international healthcare requires meaningful communication.

From both compliance and evidential perspectives, a healthcare provider serving foreign patients should structure privacy information so the international patient can actually understand the essential processing activity.

A privacy notice that a patient cannot understand is particularly problematic where the hospital simultaneously argues that the patient knowingly gave separate explicit consent for optional marketing or data-sharing activities.

For international health tourism providers, multilingual patient communication also forms part of the wider international service environment.


What Data Does an International Health Tourism Provider Record?

The April 2025 International Health Tourism and Tourist Health Regulation requires healthcare facilities to use a healthcare information management system registered within the Ministry’s system for recording and archiving international health tourism services.

Personal health data recorded by the healthcare facility must be processed in accordance with the KVKK and the healthcare data framework, and relevant information is transferred to the Ministry’s central health data system according to Ministry procedures.

Healthcare facilities and intermediaries also have information and Portal-reporting duties within the international health tourism framework.

Accordingly, the fact that some patient data is transferred to a Ministry system does not automatically mean an unlawful privacy breach has occurred.

The important question is whether the processing and transfer have a lawful statutory basis and remain within the authorised purpose.


Can a Medical Tourism Agency Receive My Medical Records?

Sometimes an intermediary may genuinely need limited information to perform the service it has undertaken.

For example, it may need information necessary to:

  • arrange the healthcare appointment;
  • coordinate an interpreter;
  • organise treatment logistics.

But medical tourism companies should not automatically receive the patient’s complete medical file simply because they arranged airport transfer and hotel accommodation.

The principle of proportionality matters.

Only information reasonably required for the legitimate purpose should be processed.

The Data Protection Board has specifically stressed that explicit consent does not justify excessive data collection and that processing should remain connected, limited and proportionate to the purpose.

Therefore, foreign patients should ask:

Why does the intermediary need this particular medical document?

That can be an entirely appropriate question.


International Transfer of Medical Data

Foreign-patient treatment naturally creates cross-border data-transfer issues.

For example, a Turkish hospital may:

  • send records to the patient’s doctor in Germany;
  • use an overseas cloud provider;
  • transfer information to a foreign parent company;
  • send medical images abroad for specialist consultation.

Turkey substantially reformed its international data-transfer regime in 2024.

The amendments to KVKK Article 9 entered into force on 1 June 2024 and introduced a structured regime involving:

  1. adequacy decisions;
  2. appropriate safeguards;
  3. limited exceptional transfer situations.

Appropriate safeguards can include standard contracts and binding corporate rules.

The Authority maintains official standard contracts for controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller transfers.

As of July 2026, the Authority was continuing to publish detailed guidance concerning the formal requirements of those standard contracts, including signature and documentation requirements.

For international hospitals, cloud systems and medical tourism groups, overseas data transfer should therefore not be treated as legally automatic.


Does Being an EU Citizen Mean Only GDPR Applies?

No.

A German, French, Dutch or other EU citizen receiving treatment in Turkey should not assume that Turkish KVKK rules disappear simply because the patient is European.

KVKK can govern processing taking place within the Turkish healthcare relationship.

The GDPR may separately become relevant depending on the territorial scope and activities of a particular foreign organisation, but European nationality by itself does not replace Turkish data-protection law for a Turkish hospital.

From the patient’s practical perspective, the first question should therefore be:

Which entity processed my information and where?


Can I Access My Medical Records?

Yes.

There are two overlapping legal routes.

First, Article 16 of the Patient Rights Regulation states that a patient can inspect files and records containing health information and obtain copies directly or through an attorney or legal representative.

Article 17 permits the patient to seek completion, explanation or correction of incomplete, unclear or incorrect medical and personal information.

Second, Article 11 of the KVKK gives data subjects extensive rights concerning their personal data.

These include the rights to:

  • learn whether personal data is processed;
  • request information about processing;
  • learn the processing purpose;
  • know recipients in Turkey or abroad;
  • request correction of inaccurate or incomplete data;
  • request deletion or destruction where the legal conditions exist;
  • request that correction/deletion actions be communicated to third parties;
  • object to certain adverse automated decisions;
  • claim compensation for damage caused by unlawful processing.

These routes can be used together depending on the objective.


Can a Foreign Patient Request Deletion of the Entire Medical File?

Not necessarily.

The KVKK contains rights to request deletion or destruction, but this does not mean a patient can always require a hospital to erase all medical history immediately.

The deletion right generally becomes relevant where the conditions justifying processing have ceased.

Healthcare institutions can have separate legal obligations to retain medical records.

Accordingly, a hospital may lawfully refuse immediate deletion of records that must still be preserved under healthcare or legal-retention obligations.

However, optional marketing copies, unlawfully shared photographs or information retained without an ongoing lawful basis present a different issue.

The KVKK deletion regime provides that where all processing conditions cease, the data should be deleted, destroyed or anonymised; requests are generally to be resolved within thirty days.

Therefore, the correct request is often not:

“Delete everything.”

It is:

“Identify the legal basis for continuing to store each category and delete any data for which no valid processing condition remains.”


Can I Find Out Who My Medical Data Was Shared With?

Yes.

Article 11 expressly gives the data subject the right to learn the third parties in Turkey or abroad to whom personal data has been transferred.

For a foreign patient, this may be particularly useful where treatment involved:

  • hospital;
  • surgeon;
  • medical tourism intermediary;
  • interpreter;
  • insurer;
  • laboratory;
  • overseas medical specialist.

A properly drafted KVKK request may therefore ask the data controller to identify the categories or recipients to whom relevant personal data was transferred and the purposes of those transfers.


How Does a Foreign Patient Make a KVKK Request?

A data subject generally addresses Article 11 requests first to the data controller.

Official KVKK guidance provides several methods, including:

  • written application;
  • registered electronic mail (KEP);
  • secure electronic signature;
  • mobile signature;
  • an email address previously notified to and registered by the data controller;
  • designated application software or systems.

Applications through a lawyer should include the relevant power of attorney.

For a foreign patient outside Turkey, using Turkish counsel can therefore be particularly practical where the hospital does not respond informally.


How Long Does the Hospital Have to Respond?

The data controller must generally respond as soon as possible and no later than thirty days, depending on the nature of the request.

The response can:

  • accept the request;
  • or reject it with reasons.

If additional costs arise, limited charges permitted under the applicable tariff can potentially be requested.

For foreign patients, the thirty-day period can be particularly useful where a clinic has ignored repeated WhatsApp requests for records or privacy information.


When Can the Patient Complain to the Personal Data Protection Board?

The KVKK establishes a staged administrative complaint system.

Where the data controller:

  • rejects the request;
  • gives an inadequate response;
  • or fails to answer within the required period,

the patient may potentially complain to the Personal Data Protection Board.

If the data controller responds within thirty days, the complaint should generally be filed within thirty days of learning of that response.

If no response is given, the complaint period generally runs within sixty days from the original application.

The Board’s official guidance explains these deadline calculations in detail.

These periods should be treated seriously.

A foreign patient should not continue exchanging informal emails for months after the statutory complaint period has begun.


Is a KVKK Complaint the Same as a Compensation Lawsuit?

No.

This distinction is extremely important.

A complaint to the Personal Data Protection Board is a regulatory remedy.

The Board can investigate compliance, order corrective measures and impose administrative sanctions within its authority.

But an administrative fine imposed on a hospital is not automatically paid to the patient as compensation.

A patient seeking compensation for unlawful processing may need to pursue an appropriate judicial remedy.

The KVKK expressly preserves compensation rights where unlawful processing causes damage, and official Authority guidance confirms that general judicial compensation rights remain available.

Therefore:

KVKK fine ≠ patient compensation.

They are legally different.


Can a Patient Go Directly to Court?

The procedural distinction is important.

A prior application to the data controller is required before taking the matter to the Personal Data Protection Board.

However, the Authority’s own guidance explains that this staged application requirement does not eliminate the possibility of pursuing judicial remedies for violation of personality rights under general law.

In other words, the administrative KVKK complaint route and civil judicial compensation route should not automatically be confused.

The appropriate legal strategy depends on what the patient wants:

  • deletion;
  • correction;
  • regulatory investigation;
  • injunction-type protection;
  • compensation.

Unauthorised Medical Data Disclosure Can Also Raise Criminal Issues

Certain unlawful personal-data conduct can potentially raise criminal-law questions separately from KVKK regulatory liability.

In the 2022 Board decision concerning the doctor’s unauthorised social-media publication of surgical photographs, the Board specifically noted that Turkish Criminal Code provisions concerning unlawful recording, disclosure or dissemination of personal data could potentially become relevant and informed the data subject of possible judicial remedies.

This does not mean every KVKK breach automatically constitutes a criminal offence.

The elements of any criminal offence must be separately established.

But serious deliberate disclosure of private medical information should not be viewed only as an administrative privacy matter.


What Happens if a Turkish Hospital Suffers a Data Breach?

Healthcare organisations are attractive targets for cyberattacks because their databases can contain:

  • identity information;
  • payment data;
  • diagnoses;
  • laboratory records;
  • highly sensitive health information.

Article 12 of the KVKK requires data controllers to take necessary technical and administrative measures to prevent unlawful processing and access and to protect personal data.

Where personal information is unlawfully obtained by others, the data controller must notify the affected person and the Authority within the applicable framework.

The Personal Data Protection Board interprets the requirement to notify the Authority “as soon as possible” as no later than 72 hours from learning of the breach. Affected data subjects must also be informed within a reasonably prompt period after they are identified.

A foreign patient who receives a breach notice should therefore consider:

  • what categories of information were exposed;
  • whether passport details were affected;
  • whether payment information was compromised;
  • whether sensitive medical data was disclosed;
  • what mitigation steps the hospital has taken.

Can a Hospital Simply Blame a Doctor or Employee for the Leak?

Not necessarily.

The KVKK places data-security responsibilities on the data controller.

The rhinoplasty photograph decision provides a useful example.

The hospital knew that its employed doctor had access to patient photographs and the Board found that the hospital had failed to take adequate administrative and technical measures to prevent unlawful social-media use.

The hospital therefore faced a separate administrative sanction even though the actual publication occurred through the doctor’s account.

This principle has broader significance.

A healthcare institution should implement measures concerning:

  • staff access;
  • permissions;
  • confidentiality;
  • technical security;
  • training;
  • internal controls.

Before-and-After Photos: Practical Rules for Foreign Patients

Patients undergoing cosmetic treatment should pay particular attention to photography.

Before surgery, ask:

Why are the photographs being taken?

Are they solely for my medical file?

Will they be used for training?

Will they be published online?

Which legal entity will publish them?

Will the doctor use them personally?

Can I refuse marketing use without affecting my treatment?

Clinical photography may be legitimately necessary for treatment.

Public publication is an entirely different processing activity.

A hospital should not treat the patient’s need for surgery as leverage for obtaining unnecessarily broad marketing consent.


Can I Withdraw My Marketing Consent?

Where processing genuinely relies on explicit consent, the data subject can generally withdraw consent for future processing.

However, withdrawal does not necessarily mean that every previous processing activity was unlawful at the time it occurred.

Nor does withdrawal automatically require destruction where another legal basis independently requires continued retention.

For marketing photographs or optional promotional use, withdrawal can be especially important.

In the 2022 rhinoplasty photograph dispute, the images were removed after the patient requested withdrawal, although the Board still separately examined whether the earlier processing and the actor using the images had a lawful basis.


Does a WhatsApp Message Count as a Medical Privacy Issue?

Potentially.

Medical tourism clinics frequently use WhatsApp to communicate:

  • diagnosis;
  • photographs;
  • laboratory results;
  • postoperative symptoms.

The fact that WhatsApp is convenient does not eliminate data-protection obligations.

The clinic should still consider:

  • which employees have access;
  • whether the communication is necessary;
  • whether information is sent to the correct patient;
  • whether sensitive material is unnecessarily retained.

An accidental transmission of a patient’s intimate surgical photographs to another patient can therefore become a serious privacy incident.


What About Interpreters?

An interpreter can legitimately require access to certain medical information to translate communication between doctor and patient.

But that does not mean the interpreter needs unlimited continuing access to the patient’s entire medical file.

The principle remains:

access should correspond to the service actually required.

Healthcare providers should also ensure that persons given access to sensitive medical information understand and comply with confidentiality obligations.

For medical tourism providers handling multiple foreign patients, this organisational responsibility is especially important.


IVF, Genetic Testing and Reproductive Health Data

Certain medical fields require particularly strict privacy treatment.

IVF and fertility files can reveal:

  • infertility;
  • reproductive history;
  • sperm information;
  • ovarian reserve;
  • embryo details;
  • genetic testing.

Genetic information and health data are expressly classified as special-category data under the KVKK.

The consequences of wrongful disclosure can therefore be significant.

The patient may be exposed not merely to embarrassment but to disclosure of deeply private genetic or reproductive information affecting family members as well.


Cancer and Other Sensitive Diagnoses

A patient’s cancer diagnosis may be required internally for healthcare.

But it should not casually be shared with:

  • employers;
  • unrelated family members;
  • hotels;
  • transportation providers;
  • marketing teams.

A medical tourism company arranging airport transportation normally does not need detailed pathology information to perform the transfer.

The principle of minimum necessary processing should therefore guide the distribution of health information throughout the medical tourism chain.


Can a Foreign Insurance Company Receive Medical Data?

Potentially, where there is a lawful basis and the disclosure is necessary within the applicable insurance relationship.

But insurance access to medical information is not conceptually unlimited.

Turkish private health insurance rules were also updated in 2025 and expressly require personal-data processing to comply with the KVKK while imposing continuing confidentiality obligations regarding insured persons’ health information.

A patient should therefore distinguish a necessary insurance medical assessment from unrelated or disproportionate disclosure.


What Should a Patient Do After Discovering Unauthorised Disclosure?

A practical approach is:

  1. Preserve evidence immediately.
  2. Take screenshots showing the publication.
  3. Record account names, dates and captions.
  4. Save any consent forms previously signed.
  5. Send a formal request to the relevant data controller.
  6. Request removal where appropriate.
  7. Ask who received the data.
  8. Ask the legal basis for processing and transfer.
  9. Consider a KVKK complaint within the statutory deadlines.
  10. Consider separate judicial remedies if actual damage or violation of personality rights occurred.

Do not rely only on sending an Instagram direct message saying:

“Please delete my photo.”

A traceable legal application can be far more useful if litigation later becomes necessary.


Practical Example 1: Rhinoplasty Photos Used Without Proper Permission

A British patient undergoes rhinoplasty in Istanbul.

Clinical photographs are taken.

The patient later discovers that the surgeon published identifiable before-and-after images through his personal Instagram account.

The patient signed a document permitting the hospital to use certain information but never authorised the surgeon’s personal account.

This resembles the structure examined in KVKK Board Decision No. 2022/630.

The identity of the person or entity receiving consent matters.

The hospital’s responsibility to prevent unlawful employee use can also become relevant.


Practical Example 2: Cancer Diagnosis Shared With Relatives

A foreign patient expressly instructs the hospital not to tell family members about a diagnosis.

The hospital nevertheless provides detailed information to a relative without identifying an applicable legal justification.

Article 20 of the Patient Rights Regulation specifically recognises the patient’s ability to restrict disclosure of health information to relatives, subject to legal exceptions.

This could therefore create a patient-rights and privacy dispute.


Practical Example 3: Medical Tourism Company Receives Complete IVF File

A couple uses an intermediary only to arrange transportation and hotel accommodation.

The hospital sends the company the couple’s complete IVF and genetic file even though such information is unnecessary for those logistical services.

The legal analysis should examine:

  • why the information was transferred;
  • whether a valid legal basis existed;
  • whether the scope was necessary and proportionate.

The principle that personal data processing must remain connected, limited and proportionate to its purpose is particularly relevant.


Practical Example 4: Hospital Database Is Hacked

A private hospital learns that an attacker obtained patient information including passport numbers and medical diagnoses.

The hospital should evaluate the breach under KVKK Article 12.

The Board’s current framework requires notification to the Authority without delay and no later than 72 hours after learning of the breach, while affected persons should also be notified promptly once identified.

A foreign patient can then evaluate whether additional legal remedies are appropriate.


Frequently Asked Questions

Are foreign patients protected by the KVKK in Turkey?

Yes, foreign patients whose personal data is processed within the relevant Turkish legal framework can benefit from KVKK protections. Turkish health-tourism legislation specifically requires foreign-patient health data to be processed in accordance with the KVKK.

Is medical information special-category personal data?

Yes. Health, genetic and biometric data are included among special categories of personal data under Turkish law.

Can a hospital process my medical information without explicit consent?

Potentially, yes, where another lawful statutory processing condition applies. Healthcare law specifically permits processing necessary for healthcare provision and related legally defined purposes, subject to the KVKK.

Can the hospital use the same information for marketing?

Not automatically. Medical treatment and advertising are separate processing purposes.

Can a surgeon post my before-and-after photographs?

Not without a valid legal basis for that particular processing. A consent given to a hospital does not automatically authorise an individual doctor’s personal social-media use.

Is putting an emoji over my eyes enough to anonymise my photo?

Not necessarily. The Personal Data Protection Board has found that partially masked facial images can remain identifiable personal data.

Can a hospital publish my testimonial if I consent?

Consent does not automatically make otherwise prohibited healthcare advertising lawful. The Board has previously sanctioned hospital use of patient health videos for advertising despite patient consent where sector-specific advertising restrictions rendered the processing unlawful.

Can my family automatically obtain my medical information?

Not necessarily. Patients can have significant control over whether relatives receive health information, subject to statutory exceptions.

Can I obtain my medical records?

Yes. Article 16 of the Patient Rights Regulation allows patients to inspect and obtain copies personally or through a lawyer or legal representative.

Can I correct incorrect medical records?

Yes. Article 17 allows patients to seek completion, explanation or correction of incomplete or inaccurate medical and personal records.

Can I find out who received my data?

Yes. Article 11 KVKK includes the right to know third parties in Turkey or abroad to whom personal data has been transferred.

Can I demand deletion?

Potentially, where the conditions for continued processing have ceased. However, statutory medical-record retention duties can prevent deletion of records that healthcare providers remain legally required to preserve.

Can medical information be sent outside Turkey?

Potentially, but international transfers must comply with the current Article 9 framework. Since June 2024, Turkey uses a structured regime based on adequacy, appropriate safeguards and limited exceptions.

Can a hospital use a foreign cloud provider?

Potentially, but if personal data is transferred abroad, the international transfer rules must be considered. Standard contractual safeguards are among the mechanisms recognised by the current framework.

How do I make a KVKK request?

The request can be made through legally recognised methods including written application, KEP, secure electronic signature, mobile signature, certain previously registered email addresses or designated application systems.

How long does the hospital have to answer?

Generally no more than thirty days.

When can I complain to the KVKK Board?

Following the required application to the data controller, a complaint may be made according to Article 14 deadlines. Depending on whether and when a response is received, the relevant periods generally involve thirty days after learning of the response and/or sixty days from the initial application.

Can the KVKK Board award me compensation?

A Board administrative fine is not patient compensation. Compensation for damage caused by unlawful data processing may require judicial remedies.

Can unlawful publication of medical photographs also be a crime?

Potentially, depending on the facts. The KVKK Board has expressly referred patients to judicial remedies concerning Turkish Criminal Code personal-data offences in cases involving unauthorised medical-image disclosure.

What happens after a data breach?

A data controller that learns of unlawful acquisition of personal information must act under Article 12. The Board’s framework requires notification to the Authority without delay and no later than 72 hours after learning of the breach.


Conclusion: Medical Treatment Does Not Mean Giving Up Control of Your Privacy

Foreign patients receiving healthcare in Turkey necessarily provide sensitive information.

A hospital cannot diagnose cancer without processing medical information.

A surgeon cannot safely operate without knowing the patient’s medical history.

A laboratory cannot perform genetic testing without processing genetic data.

Therefore, Turkish law does not require explicit consent for every act of health-data processing where another lawful healthcare basis exists.

The 2024 amendments to KVKK Article 6 modernised and expanded the processing conditions applicable to special-category personal data, while healthcare legislation adopted in 2025 expressly regulates processing of information necessary for healthcare provision.

But necessary healthcare processing should never be confused with unlimited commercial use.

A patient’s medical file exists primarily because healthcare is being provided.

It is not automatically a marketing database.

A patient’s rhinoplasty photographs may be necessary for clinical follow-up.

That does not automatically authorise Instagram publication.

A patient’s cancer diagnosis may need to be shared with the oncology team.

That does not automatically authorise disclosure to family members, hotel personnel or marketing staff.

A medical tourism agency may require limited information to coordinate healthcare.

That does not automatically justify receiving the entire medical history.

Turkish patient-rights law reinforces this distinction.

Article 21 requires respect for patient privacy, while Article 23 establishes a broad confidentiality rule for information obtained through healthcare.

The Personal Data Protection Board has also demonstrated that it will examine healthcare marketing practices critically.

Its 2022 rhinoplasty-photograph decision shows that:

consent must correspond to the actor actually using the data.

Consent granted to a hospital did not automatically authorise the treating doctor’s personal social-media publication.

The hospital itself was sanctioned for failing to prevent the unlawful processing.

Its 2023 hospital advertising decision demonstrates an even broader principle.

Even explicit patient consent cannot automatically legalise personal-data processing where the underlying promotional activity conflicts with healthcare-sector restrictions.

The Board also stressed that identifiable patient health data should not be used where the informational objective can reasonably be achieved without processing it.

These principles are especially important for foreign cosmetic-surgery patients.

A clinic should not assume that a patient who travelled to Turkey for a lower-cost treatment has surrendered privacy rights.

Nor should the patient be required to accept advertising use as a practical condition of receiving medical care.

The current KVKK regime also gives foreign patients practical tools to exercise control over their information.

Under Article 11, a patient can potentially ask:

What information do you have about me?

Why are you processing it?

Who did you share it with?

Did you transfer it outside Turkey?

Is anything inaccurate?

Is there data you no longer have a lawful basis to retain?

The patient can request information, correction, deletion where the statutory conditions exist and compensation for unlawful-processing damage.

The hospital generally has up to thirty days to respond to a properly submitted KVKK request.

If the response is inadequate or absent, the patient may consider the Personal Data Protection Board complaint process within the strict statutory time limits.

International transfer has also become more significant.

Health tourism naturally creates cross-border data movement.

Patients receive second opinions abroad.

Clinics use international software.

Medical tourism organisations operate across borders.

Since 1 June 2024, Turkey has applied a redesigned Article 9 framework governing international transfers, including adequacy mechanisms, appropriate safeguards such as standard contracts and limited exceptional transfer conditions.

Accordingly, a clinic should not simply argue:

“The patient is foreign, so we can send the medical information abroad.”

Foreign nationality is not itself a universal international-transfer legal basis.

Data breaches present another risk.

Hospitals hold some of the most sensitive datasets in modern society.

A cyberattack may expose not merely a telephone number but:

passport information,

diagnoses,

medical photographs,

genetic information,

and treatment history.

Under the Turkish data-breach framework, the data controller must notify the Personal Data Protection Authority without delay and within the Board’s 72-hour interpretation after learning of the breach, while affected individuals must also be notified appropriately.

Foreign patients therefore have meaningful privacy rights before, during and after medical treatment in Turkey.

A strong privacy strategy begins by identifying:

who the data controller is,

what information is being processed,

why it is needed,

who receives it,

whether it leaves Turkey,

and

whether any optional marketing use is genuinely separate from medical treatment.

Patients should preserve:

  • treatment agreements;
  • privacy notices;
  • explicit-consent forms;
  • photography forms;
  • screenshots of social-media publications;
  • correspondence concerning removal requests;
  • hospital responses to KVKK applications.

Where an unauthorised publication or disclosure occurs, preserving evidence quickly is essential because online material can disappear after a complaint is made.

Foreign patients treated in Turkey do not surrender their medical privacy simply because they voluntarily entered a hospital or signed treatment documents. Turkish law distinguishes between information necessary to provide healthcare and optional or unrelated uses of that information. A hospital may lawfully process health data required for diagnosis and treatment, while the same information may be unlawfully processed if it is unnecessarily disclosed, transferred or used for marketing.

For international patients, that distinction is the key to understanding medical data protection in Turkey.

Legal Disclaimer

This article provides general information concerning patient privacy, medical confidentiality and personal-data protection under Turkish law as of September 2026. It does not constitute individual legal advice.

Whether a particular processing, disclosure, international transfer, photograph publication or data-retention practice is lawful depends on the identity of the data controller, nature of the personal data, processing purpose, applicable legal basis, healthcare regulations, consent documentation, security measures and particular facts of the case.

Healthcare providers may also have statutory obligations requiring certain medical information to be processed or retained even where a patient later requests deletion.

International data transfers are subject to the current KVKK Article 9 framework and should be evaluated according to the transfer mechanism actually used.

Foreign patients who believe their health information, medical photographs or records were unlawfully disclosed or processed should preserve evidence promptly and obtain case-specific advice regarding KVKK applications, regulatory complaints and judicial remedies.

Categories:

No Responses

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Our Client

    We provide a wide range of Turkish legal services to businesses and individuals throughout the world. Our services include comprehensive, updated legal information, professional legal consultation and representation

    Our Team

    .Our team includes business and trial lawyers experienced in a wide range of legal services across a broad spectrum of industries.

    Why Choose Us

    We will hold your hand. We will make every effort to ensure that you understand and are comfortable with each step of the legal process.

    Call Now Button