
Last updated: 2026-08-03
The decision does not prohibit every online publication containing personal data. It requires covered organizations to establish a valid processing condition, publish only the minimum information necessary, define how long the information will remain accessible, provide an appropriate privacy notice, take security measures and review existing online content without delay.
It also encourages authenticated access—such as e-Devlet or a system using identity verification—where examination, recruitment, lottery or similar results primarily need to be communicated to the individuals concerned.
An important scope distinction should be made at the outset: the principle decision directly concerns data controllers possessing public legal personality, including municipalities, provincial special administrations, universities and other public institutions. It is not a new website-publication rule written specifically for every private company, although the underlying KVKK principles already apply to private-sector data controllers as well.

The Personal Data Protection Board adopted Principle Decision No. 2026/1301 on 1 July 2026. It was published in the Official Gazette dated 28 July 2026, issue No. 33323, under the title “Principle Decision on the Sharing of Personal Data on the Internet by Data Controllers Possessing Public Legal Personality.”
The decision followed complaints and investigations involving public institutions that had placed personal data in publicly accessible documents. The Board identified information such as:
The Board did not declare that all these fields can never be published. Its position is that every publication must have a valid legal basis and must remain connected, limited and proportionate to its purpose. Information that is unnecessary for that purpose should be removed, masked or otherwise protected.
The decision contains no separate transition period. Instead, it calls for personal data already available online to be reviewed urgently and for non-compliant publications to be removed or corrected.
The principle decision directly addresses public-law legal entities acting as data controllers. Examples expressly identified by the Board include:
The legal classification of an organization matters. A company providing services to a public institution does not become a public-law legal entity simply because it operates a government website or communications account.
However, hosting companies, software providers, communications agencies and outsourced website administrators may still process personal data on behalf of the public body. Their contractual role and technical access therefore form part of the public body’s compliance and security responsibilities.
The published decision does not create sector-specific exemptions for universities, municipalities, procurement authorities, healthcare bodies or other categories. Nor does it remove publication duties imposed by other legislation. The correct approach is to apply the specific transparency or publication obligation together with the KVKK principles of lawful processing, minimization, proportionality, security and limited retention.
A common operational mistake is to treat the upload of an existing PDF, spreadsheet, meeting decision or candidate list as a communications activity rather than a personal-data processing operation.
Under the KVKK, processing includes actions such as recording, storing, disclosing, transferring, making data available and preventing its use. When a document is uploaded to a website, the personal data inside it is disclosed and made available to third parties.
This remains true where:
The question is not whether publication was the document’s original purpose. The question is whether making the information available online is itself lawful and proportionate. The Board expressly treats internet publication of a document containing personal data as a processing activity.
Before publishing personal data, the organization must identify at least one applicable processing condition under Article 5 of the KVKK. Where special-category personal data is involved, the stricter conditions under Article 6 must be assessed.
For a public institution, the most relevant conditions may include:
Consent should not be used merely to compensate for an unclear publication practice. In many public-sector relationships, the imbalance between the institution and the individual may also make reliance on consent difficult. More importantly, obtaining consent does not remove the obligation to comply with purpose limitation, minimization, proportionality and security.
A lawful basis for conducting an examination, recruitment process, allocation procedure or procurement does not automatically establish a lawful basis for publishing every associated data field to the entire internet.
The publication step must be assessed separately.
The distinction between a legal duty and an established administrative habit is central to the decision.
Publication is more likely to be mandatory where a law, regulation or other binding provision clearly specifies:
Even in this situation, the institution should publish only what the rule requires. A requirement to announce an award, decision or result does not necessarily authorize the inclusion of identity numbers, home addresses, telephone numbers or unrelated application details.
Some rules require results to be “announced” or “published” without specifying that all information must be placed on a public website.
In that case, the institution should assess whether the duty can be satisfied through a less intrusive method, such as:
Earlier Board decisions concerning academic and student examination results support the use of identity verification and limited access instead of permanently searchable public lists.
Statements such as these do not establish a lawful basis by themselves:
These considerations may help describe an operational purpose, but they do not replace the need for a valid processing condition and a proportionality assessment.
Transparency and data protection are not mutually exclusive. Transparency normally concerns whether a decision was taken lawfully, how public resources were allocated and whether a process can be scrutinized. It does not automatically require unrestricted disclosure of every personal detail collected during that process.
Public procurement legislation may require notices, tender information and contract results to be published through official channels such as EKAP or the Public Procurement Bulletin.
The institution should use the prescribed channel and required information rather than uploading complete application files, signature documents, identity records, contact lists or internal evaluation sheets to an additional public page without a separate need.
The same distinction applies between information concerning a corporate supplier and personal information concerning its representatives, employees, experts or shareholders.
Where legislation requires recruitment or examination results to be announced, the organization should determine:
An administrative requirement to announce a result should not automatically be interpreted as authorization to publish a searchable spreadsheet containing names, identity numbers, scores, rejection reasons and reserve-list status.
Certain decisions may need to be published to become effective, inform affected parties or satisfy administrative-law requirements.
In such cases, the organization should document:
A full version may need to be retained in the institution’s records even where only a minimized version is suitable for public access. Removing a document from the public website does not necessarily mean deleting the underlying official record where another law requires retention.
Having a processing condition answers only the first question: whether processing may occur at all.
The next question is whether the particular form of publication is proportionate.
The Board requires organizations to publish the minimum amount of personal data needed to achieve the purpose. This involves examining both the fields included and the exposure created by the chosen channel.
A document visible to any internet user, downloadable without authentication, indexable by search engines and available for several years creates substantially more exposure than a result displayed temporarily inside an authenticated portal.
A useful proportionality assessment should consider:
The new principle decision provides a broad list of fields found in public-sector documents. Several deserve particular attention.
Publishing a complete Turkish identity number will rarely be necessary for a general public announcement. Even partial identity numbers require a context-based assessment because other information in the document may still make the individual identifiable.
Home addresses, mobile numbers and personal email addresses typically contribute little to the transparency of an examination, recruitment or procurement result. Their disclosure can create risks of fraud, harassment or unwanted contact.
A statement that an applicant was rejected due to missing documents, ineligibility, former-convict status or another personal circumstance may reveal considerably more than is required to announce an outcome.
Detailed reasons can normally be communicated directly to the applicant.
Scores, correct and incorrect answer counts, evaluation rankings and pass/fail information are personal data. Publishing them may affect an individual’s professional or academic reputation even when they are not special-category data.
Replacing a name with a candidate number is not automatically anonymization. The number remains personal data where it can be connected to an individual by the organization, the applicant, other candidates or information published elsewhere.
In a small recruitment process, even a heavily masked identifier may be sufficient for colleagues or competitors to infer a person’s identity.
These techniques should not be treated as interchangeable.
Masking hides part of a field—for example, replacing letters or numbers with asterisks.
In its 2019 academic recruitment decision, the Board gave examples such as A**** B**** and 11*******11. These examples demonstrate a possible masking approach, but they should not be treated as a universal safe-harbour standard. The remaining information, size of the candidate group and availability of other datasets must still be considered.
Pseudonymization replaces a direct identifier with a code, candidate number or other reference.
The data remains personal data where the code can be linked back to a person. Access controls, key separation and limited publication remain necessary.
Under the KVKK deletion regulation, anonymization requires personal data to become incapable of being associated with an identified or identifiable person, even when combined with other relevant data.
Removing a name from a row does not achieve anonymization where the person can still be recognized from a unique job title, property parcel, score, department or combination of attributes.
For most individualized examination or recruitment results, authenticated access is more reliable than attempting to anonymize a detailed public list.
The Board has not imposed a single publication period that applies to every notice.
Each organization must determine the period according to:
A publication workflow should require an expiry date before content goes live.
At the end of the approved period, the organization should:
The deletion regulation requires deletion and anonymization operations to be recorded. It also distinguishes between making data inaccessible to relevant users, destroying it so that nobody can retrieve it, and anonymizing it so that it cannot be linked to a person.
A document may no longer need to remain publicly available while still needing to be retained internally under an archival, employment, procurement or administrative recordkeeping obligation.
The institution should therefore define separate periods for:
“Retain for ten years” does not necessarily mean “publish on the website for ten years.”
The 2026 principle decision does not specifically prescribe a search-engine cache or de-indexing procedure. Removing the source document should nevertheless be treated as only the first remediation step.
A defensible response should normally include:
404 or 410 where the page has been permanently removednoindex where a page must remain accessible but should not appear in search resultsGoogle’s removal tools can temporarily remove a page from search results, but the source content must also be removed or blocked for lasting remediation.
The Board has separately recognized that search-engine indexing is itself a personal-data processing activity and that individuals may request de-indexing under the criteria established in Decision No. 2020/481. This does not mean every old result must automatically be de-indexed; a case-specific balance between privacy and public interest remains necessary.
A public body cannot guarantee that every downloaded or independently republished copy will disappear from the internet. It should, however, take proportionate steps concerning systems and recipients under its control and document any reasonable follow-up action concerning identifiable third-party copies.
The principle decision specifically addresses examinations, lotteries and similar processes.
Where the circumstances require participants to inspect a broader result—for example, to verify a ranking or allocation process—the institution may provide access only to the relevant participants and apply suitable minimization measures.
Where broader participant access is unnecessary, each individual should generally be able to see only their own result.
The Board identifies suitable e-Devlet services and methods using two-factor identity verification as appropriate options.
A strong result-publication model might therefore use:
Open spreadsheets, downloadable PDFs and public social-media images should not be the default merely because they are operationally easy.
The Board expressly requires the Article 10 privacy-notice obligation to be fulfilled for online publication activities. It also emphasizes that the data controller carries the burden of proving that notice was provided.
The notice should accurately explain, where applicable:
As an operational improvement, organizations should also explain the intended publication duration and whether access will be public, participant-only or individualized.
A generic website privacy notice placed in the footer may not adequately cover a separate recruitment, examination or lottery publication. The relevant notice should be delivered at a suitable point in the process—for example, during application or before the data is collected for the activity.
Notice and consent must also remain separate concepts. Providing notice does not create a processing condition, and requesting consent does not replace the notice obligation.
Useful evidence may include:
The decision is not limited to website administrators. It requires governance across the units that create, approve and publish content.
A practical publication process should include the following controls.
Record every recurring publication process, including its:
Before publication, the content owner should answer:
Recruitment lists, examination results, procurement notices and council announcements should use approved templates that exclude unnecessary fields by default.
This is safer than asking employees to redact every new document manually.
Depending on the purpose, controls may include:
The decision expressly calls for training and awareness work, particularly for employees who manage websites and social-media platforms.
Training should also cover communications teams, human resources, procurement, student affairs, information technology, legal affairs, records management and external agencies.
The public body will generally remain the data controller where it determines why the information is published, which information is used and how the publication process operates.
A hosting provider, website developer or communications agency may act as a data processor where it handles the information solely on the public body’s documented instructions.
Outsourcing publication does not outsource accountability.
Under Article 12, where personal data is processed on behalf of a data controller, the controller and processor share responsibility for taking the necessary data-security measures. The controller must also conduct or commission appropriate audits.
Contracts with service providers should therefore address:
A contractor that independently decides to reuse, analyze, republish or retain the information for its own purposes may become a separate data controller for that activity. The classification depends on the actual decisions and conduct, not only the contractual label.
The principle decision states that failure to take the identified measures may lead to a case-specific Board investigation and proceedings under Article 18 of the KVKK.
For public institutions and public professional organizations, Article 18 provides for the Board to notify the relevant institution so that disciplinary proceedings can be initiated against responsible officials and other public personnel. The outcome must be reported back to the Board.
The Board may also instruct the data controller to correct a processing operation, redesign a result-publication system, remove content or implement other appropriate measures. Previous cases involving public universities demonstrate that public-sector status does not remove the obligation to comply with Board instructions.
Covered organizations should not wait for the next recruitment or examination cycle. The decision expressly calls for an urgent review of existing online content.
The first review should cover more than the website’s current navigation. Teams should search:
Priority should be given to files containing complete identity numbers, contact details, special-category data, rejection reasons, detailed examination information and lists that have remained online beyond their operational purpose.
Before approving a new public document, the responsible team should be able to answer all of the following:
A publication that cannot answer these questions should not proceed unchanged.
Türkiye’s 2026 principle decision does not establish a complete ban on public bodies publishing personal data. It requires them to stop treating public website publication as an automatic final step in an administrative process.
The practical rule is straightforward:
Establish the legal need, identify the necessary audience, publish the minimum data, limit the exposure period and remove the information when the purpose ends.
For examination, lottery and recruitment results, the direction is particularly clear. Publicly downloadable lists should give way, where practical, to authenticated and individualized access.
Public bodies should now inventory existing publications, remove unjustified content, redesign recurring workflows and clarify responsibility across communications, human resources, procurement, information technology, records management and external service providers.
Organizations should obtain qualified legal advice where a sector-specific publication duty, transparency requirement or administrative procedure affects the correct interpretation.
Kooch Cybersecurity & Compliance can support organizations and public-sector service providers with:
The objective is not simply to redact documents after problems appear. It is to establish a repeatable process that prevents unnecessary personal data from reaching public systems in the first place.