Türkiye’s New KVKK Rule for Publishing Personal Data on Public Websites

Türkiye’s New KVKK Rule for Publishing Personal Data on Public Websites




Last updated:
2026-08-03

The decision does not prohibit every online publication containing personal data. It requires covered organizations to establish a valid processing condition, publish only the minimum information necessary, define how long the information will remain accessible, provide an appropriate privacy notice, take security measures and review existing online content without delay.

It also encourages authenticated access—such as e-Devlet or a system using identity verification—where examination, recruitment, lottery or similar results primarily need to be communicated to the individuals concerned.

An important scope distinction should be made at the outset: the principle decision directly concerns data controllers possessing public legal personality, including municipalities, provincial special administrations, universities and other public institutions. It is not a new website-publication rule written specifically for every private company, although the underlying KVKK principles already apply to private-sector data controllers as well.

shows decision path before publishing a document

What did the KVKK Board decide?

The Personal Data Protection Board adopted Principle Decision No. 2026/1301 on 1 July 2026. It was published in the Official Gazette dated 28 July 2026, issue No. 33323, under the title “Principle Decision on the Sharing of Personal Data on the Internet by Data Controllers Possessing Public Legal Personality.”

The decision followed complaints and investigations involving public institutions that had placed personal data in publicly accessible documents. The Board identified information such as:

  • Names and surnames
  • Mother’s and father’s names
  • Turkish identity numbers
  • Addresses and telephone numbers
  • Dates or places of birth
  • Employee numbers and organizational units
  • Education and military-service information
  • Profession, title, workplace and length of service
  • Property block and parcel details
  • KPSS and other examination scores
  • Correct, incorrect and net answer counts
  • Acceptance, rejection and success information
  • Candidate, application and student numbers
  • Reasons for exclusion from an examination or application
  • Principal and reserve-list status
  • Missing-document information
  • Former-convict status

The Board did not declare that all these fields can never be published. Its position is that every publication must have a valid legal basis and must remain connected, limited and proportionate to its purpose. Information that is unnecessary for that purpose should be removed, masked or otherwise protected.

The decision contains no separate transition period. Instead, it calls for personal data already available online to be reviewed urgently and for non-compliant publications to be removed or corrected.

Which organizations are directly covered?

The principle decision directly addresses public-law legal entities acting as data controllers. Examples expressly identified by the Board include:

  • Central and local public institutions
  • Municipalities
  • Provincial special administrations
  • Public universities
  • Other organizations possessing public legal personality

The legal classification of an organization matters. A company providing services to a public institution does not become a public-law legal entity simply because it operates a government website or communications account.

However, hosting companies, software providers, communications agencies and outsourced website administrators may still process personal data on behalf of the public body. Their contractual role and technical access therefore form part of the public body’s compliance and security responsibilities.

The published decision does not create sector-specific exemptions for universities, municipalities, procurement authorities, healthcare bodies or other categories. Nor does it remove publication duties imposed by other legislation. The correct approach is to apply the specific transparency or publication obligation together with the KVKK principles of lawful processing, minimization, proportionality, security and limited retention.


Why uploading a document is personal-data processing

A common operational mistake is to treat the upload of an existing PDF, spreadsheet, meeting decision or candidate list as a communications activity rather than a personal-data processing operation.

Under the KVKK, processing includes actions such as recording, storing, disclosing, transferring, making data available and preventing its use. When a document is uploaded to a website, the personal data inside it is disclosed and made available to third parties.

This remains true where:

  • The document was originally created for an internal administrative process.
  • The information was already known to employees or applicants.
  • Publication is handled by a communications department rather than a privacy team.
  • The file is linked from a page but is not prominently displayed.
  • The document is technically difficult to find.
  • A search engine has not yet indexed the file.

The question is not whether publication was the document’s original purpose. The question is whether making the information available online is itself lawful and proportionate. The Board expressly treats internet publication of a document containing personal data as a processing activity.

Establishing a lawful processing condition

Before publishing personal data, the organization must identify at least one applicable processing condition under Article 5 of the KVKK. Where special-category personal data is involved, the stricter conditions under Article 6 must be assessed.

For a public institution, the most relevant conditions may include:

  • Processing expressly provided for by law
  • Processing necessary for the institution to comply with a legal obligation
  • Processing necessary for the establishment, exercise or protection of a right
  • Another processing condition demonstrably applicable to the specific activity

Consent should not be used merely to compensate for an unclear publication practice. In many public-sector relationships, the imbalance between the institution and the individual may also make reliance on consent difficult. More importantly, obtaining consent does not remove the obligation to comply with purpose limitation, minimization, proportionality and security.

A lawful basis for conducting an examination, recruitment process, allocation procedure or procurement does not automatically establish a lawful basis for publishing every associated data field to the entire internet.

The publication step must be assessed separately.

Public website publication decision matrix
Situation What must be established Safer publication approach
Situation The law expressly requires public online publication. Establish The exact legal provision, required channel, mandatory fields and publication period. Safer approach Publish only the required fields and automatically remove the content when the required period ends.
Situation The law requires a result or decision to be announced but does not require unrestricted internet access. Establish The intended audience and whether public access is genuinely necessary. Safer approach Use e-Devlet, an authenticated portal, individual notification or participant-only access.
Situation Publication supports transparency but is not expressly required. Establish The public-interest purpose, applicable processing condition and proportionality assessment. Safer approach Publish a minimized summary, statistics or appropriately masked information instead of the complete file.
Situation Publication is based only on habit, convenience or an inherited template. Establish A valid processing condition and a demonstrable need for public disclosure. Safer approach Pause publication until the legal basis, audience, fields and duration have been approved.
Situation No valid processing condition exists. Legal position There is no lawful basis for making the personal data publicly available. Required action Do not publish the personal data. Use a non-personal announcement or direct communication instead.

When is publication legally mandatory rather than merely customary?

The distinction between a legal duty and an established administrative habit is central to the decision.

A legal publication obligation

Publication is more likely to be mandatory where a law, regulation or other binding provision clearly specifies:

  • That the information must be announced publicly
  • The platform or publication channel
  • The information that the announcement must contain
  • The relevant audience
  • The publication or objection period

Even in this situation, the institution should publish only what the rule requires. A requirement to announce an award, decision or result does not necessarily authorize the inclusion of identity numbers, home addresses, telephone numbers or unrelated application details.

A general requirement to announce a result

Some rules require results to be “announced” or “published” without specifying that all information must be placed on a public website.

In that case, the institution should assess whether the duty can be satisfied through a less intrusive method, such as:

  • An authenticated candidate portal
  • e-Devlet
  • Individual electronic notification
  • A restricted system accessible only to participants
  • A public notice containing limited or properly masked information

Earlier Board decisions concerning academic and student examination results support the use of identity verification and limited access instead of permanently searchable public lists.

A customary publication practice

Statements such as these do not establish a lawful basis by themselves:

  • “We have always published the list.”
  • “Other municipalities do the same.”
  • “Applicants expect to see everyone’s score.”
  • “The template was inherited from the previous administration.”
  • “The document is already public under transparency principles.”
  • “Publication prevents allegations of unfairness.”

These considerations may help describe an operational purpose, but they do not replace the need for a valid processing condition and a proportionality assessment.

Transparency, procurement and administrative publication duties

Transparency and data protection are not mutually exclusive. Transparency normally concerns whether a decision was taken lawfully, how public resources were allocated and whether a process can be scrutinized. It does not automatically require unrestricted disclosure of every personal detail collected during that process.

Procurement

Public procurement legislation may require notices, tender information and contract results to be published through official channels such as EKAP or the Public Procurement Bulletin.

The institution should use the prescribed channel and required information rather than uploading complete application files, signature documents, identity records, contact lists or internal evaluation sheets to an additional public page without a separate need.

The same distinction applies between information concerning a corporate supplier and personal information concerning its representatives, employees, experts or shareholders.

Recruitment and examinations

Where legislation requires recruitment or examination results to be announced, the organization should determine:

  1. Whether results must be visible to the general public.
  2. Whether only the applicant must receive their own result.
  3. Whether participants need limited visibility of other results to scrutinize the process.
  4. Which identifiers are genuinely required.
  5. How long an objection or review period lasts.

An administrative requirement to announce a result should not automatically be interpreted as authorization to publish a searchable spreadsheet containing names, identity numbers, scores, rejection reasons and reserve-list status.

Administrative decisions and public notices

Certain decisions may need to be published to become effective, inform affected parties or satisfy administrative-law requirements.

In such cases, the organization should document:

  • The exact legal provision
  • The mandatory content
  • Whether personal identification is required
  • The legally required publication channel
  • The applicable publication period
  • Whether the public version can be separated from the complete administrative record

A full version may need to be retained in the institution’s records even where only a minimized version is suitable for public access. Removing a document from the public website does not necessarily mean deleting the underlying official record where another law requires retention.

Purpose limitation and proportionality

Having a processing condition answers only the first question: whether processing may occur at all.

The next question is whether the particular form of publication is proportionate.

The Board requires organizations to publish the minimum amount of personal data needed to achieve the purpose. This involves examining both the fields included and the exposure created by the chosen channel.

A document visible to any internet user, downloadable without authentication, indexable by search engines and available for several years creates substantially more exposure than a result displayed temporarily inside an authenticated portal.

A useful proportionality assessment should consider:

  • Who genuinely needs to see the information?
  • Does that audience need the complete document?
  • Does every field contribute to the publication purpose?
  • Could an individual result be communicated privately?
  • Could the same objective be achieved through masking?
  • Could the publication lead to discrimination, fraud, profiling or unwanted contact?
  • Is the file downloadable, searchable and reusable at scale?
  • Could separate data points identify a person when combined?
  • How long does the purpose remain valid?

Common data fields and safer treatment
Data field Typical exposure Safer treatment
Data field Turkish identity number Typical exposure Enables direct identification and may increase fraud or account-verification risks. Safer treatment Remove unless expressly required. Where an identifier is necessary, use suitable masking or authenticated access.
Data field Home address, mobile number or personal email Typical exposure May enable unwanted contact, profiling, harassment or fraud. Safer treatment Exclude from public documents and use controlled internal or individual communication channels.
Data field Full name Typical exposure Connects the individual to the result and may make the information searchable by name. Safer treatment Consider authenticated access, appropriate masking or a participant-specific identifier.
Data field Candidate, application or student number Typical exposure May remain identifiable to the institution, the individual or other participants. Safer treatment Treat it as pseudonymous personal data. Limit both the audience and publication period.
Data field Scores, rankings and pass or fail status Typical exposure Reveals academic or professional performance and may affect the individual’s reputation. Safer treatment Prefer individualized access. Use participant-only visibility only where broader scrutiny is genuinely necessary.
Data field Rejection, exclusion or missing-document reason Typical exposure May reveal personal circumstances or create unfair inferences about the applicant. Safer treatment Publish only the outcome where necessary and provide detailed reasons directly to the applicant.
Data field Health, criminal-conviction or other special-category information Typical exposure Creates significant privacy and discrimination risks and is subject to stricter processing conditions. Safer treatment Do not place it in a public document without a specific legal assessment establishing necessity and compliance.
Data field Property block or parcel information Typical exposure May identify or profile an individual when combined with address, allocation or applicant information. Safer treatment Publish only the property details required for the process and separate them from unnecessary personal identifiers.

Data fields that commonly create unnecessary exposure

The new principle decision provides a broad list of fields found in public-sector documents. Several deserve particular attention.

Turkish identity numbers

Publishing a complete Turkish identity number will rarely be necessary for a general public announcement. Even partial identity numbers require a context-based assessment because other information in the document may still make the individual identifiable.

Contact and address information

Home addresses, mobile numbers and personal email addresses typically contribute little to the transparency of an examination, recruitment or procurement result. Their disclosure can create risks of fraud, harassment or unwanted contact.

Rejection and disqualification reasons

A statement that an applicant was rejected due to missing documents, ineligibility, former-convict status or another personal circumstance may reveal considerably more than is required to announce an outcome.

Detailed reasons can normally be communicated directly to the applicant.

Scores and performance information

Scores, correct and incorrect answer counts, evaluation rankings and pass/fail information are personal data. Publishing them may affect an individual’s professional or academic reputation even when they are not special-category data.

Candidate and application numbers

Replacing a name with a candidate number is not automatically anonymization. The number remains personal data where it can be connected to an individual by the organization, the applicant, other candidates or information published elsewhere.

In a small recruitment process, even a heavily masked identifier may be sufficient for colleagues or competitors to infer a person’s identity.

Masking, pseudonymization and anonymization are not the same

These techniques should not be treated as interchangeable.

Masking

Masking hides part of a field—for example, replacing letters or numbers with asterisks.

In its 2019 academic recruitment decision, the Board gave examples such as A**** B**** and 11*******11. These examples demonstrate a possible masking approach, but they should not be treated as a universal safe-harbour standard. The remaining information, size of the candidate group and availability of other datasets must still be considered.

Pseudonymization

Pseudonymization replaces a direct identifier with a code, candidate number or other reference.

The data remains personal data where the code can be linked back to a person. Access controls, key separation and limited publication remain necessary.

Anonymization

Under the KVKK deletion regulation, anonymization requires personal data to become incapable of being associated with an identified or identifiable person, even when combined with other relevant data.

Removing a name from a row does not achieve anonymization where the person can still be recognized from a unique job title, property parcel, score, department or combination of attributes.

For most individualized examination or recruitment results, authenticated access is more reliable than attempting to anonymize a detailed public list.

Publication periods and removal workflows

The Board has not imposed a single publication period that applies to every notice.

Each organization must determine the period according to:

  • Any duration expressly required by law
  • The purpose of the announcement
  • Objection, appeal or review periods
  • The need for participants to scrutinize a result
  • The risk created by continued availability
  • Applicable archival and record-retention requirements

A publication workflow should require an expiry date before content goes live.

At the end of the approved period, the organization should:

  1. Remove the public page or replace it with a non-personal notice.
  2. Remove direct file URLs and duplicate uploads.
  3. Check social-media accounts and third-party publication channels.
  4. Purge relevant website and content-delivery caches.
  5. Confirm that the document is not accessible through an old attachment path.
  6. Apply the appropriate deletion, destruction or anonymization process where the processing conditions have ended.
  7. Record the action taken, date, responsible person and retained evidence.

The deletion regulation requires deletion and anonymization operations to be recorded. It also distinguishes between making data inaccessible to relevant users, destroying it so that nobody can retrieve it, and anonymizing it so that it cannot be linked to a person.

Public availability and internal retention are different issues

A document may no longer need to remain publicly available while still needing to be retained internally under an archival, employment, procurement or administrative recordkeeping obligation.

The institution should therefore define separate periods for:

  • Public website availability
  • Restricted operational access
  • Official record retention
  • Backup retention
  • Final deletion, destruction or anonymization

“Retain for ten years” does not necessarily mean “publish on the website for ten years.”

Do archived and search-engine-cached copies require remediation?

The 2026 principle decision does not specifically prescribe a search-engine cache or de-indexing procedure. Removing the source document should nevertheless be treated as only the first remediation step.

A defensible response should normally include:

  • Removing or correcting the original content
  • Removing duplicate and attachment URLs
  • Clearing CMS, proxy and content-delivery-network caches
  • Returning an appropriate status such as 404 or 410 where the page has been permanently removed
  • Using noindex where a page must remain accessible but should not appear in search results
  • Requesting accelerated search-result or cached-copy removal where necessary
  • Checking institutional social-media accounts and document mirrors
  • Recording which copies are controlled by the institution and which are held by third parties

Google’s removal tools can temporarily remove a page from search results, but the source content must also be removed or blocked for lasting remediation.

The Board has separately recognized that search-engine indexing is itself a personal-data processing activity and that individuals may request de-indexing under the criteria established in Decision No. 2020/481. This does not mean every old result must automatically be de-indexed; a case-specific balance between privacy and public interest remains necessary.

A public body cannot guarantee that every downloaded or independently republished copy will disappear from the internet. It should, however, take proportionate steps concerning systems and recipients under its control and document any reasonable follow-up action concerning identifiable third-party copies.


Examination, lottery and recruitment results

The principle decision specifically addresses examinations, lotteries and similar processes.

Where the circumstances require participants to inspect a broader result—for example, to verify a ranking or allocation process—the institution may provide access only to the relevant participants and apply suitable minimization measures.

Where broader participant access is unnecessary, each individual should generally be able to see only their own result.

The Board identifies suitable e-Devlet services and methods using two-factor identity verification as appropriate options.

A strong result-publication model might therefore use:

  • e-Devlet authentication
  • A secure applicant portal
  • Two-factor authentication
  • A one-time result access code
  • Participant-only access during the objection period
  • Individual electronic notification
  • A public statistical summary without personal identifiers

Open spreadsheets, downloadable PDFs and public social-media images should not be the default merely because they are operationally easy.

Privacy notices and proof of notice

The Board expressly requires the Article 10 privacy-notice obligation to be fulfilled for online publication activities. It also emphasizes that the data controller carries the burden of proving that notice was provided.

The notice should accurately explain, where applicable:

  • The identity of the data controller
  • The purpose of publication
  • The personal-data categories involved
  • The processing condition
  • The publication or recipient channel
  • The collection method
  • The individual’s KVKK rights
  • How the organization can be contacted

As an operational improvement, organizations should also explain the intended publication duration and whether access will be public, participant-only or individualized.

A generic website privacy notice placed in the footer may not adequately cover a separate recruitment, examination or lottery publication. The relevant notice should be delivered at a suitable point in the process—for example, during application or before the data is collected for the activity.

Notice and consent must also remain separate concepts. Providing notice does not create a processing condition, and requesting consent does not replace the notice obligation.

Useful evidence may include:

  • Timestamped application notices
  • Portal acceptance or viewing logs
  • Signed forms
  • Version-controlled notice texts
  • Email-delivery records
  • Recruitment-platform records
  • Screenshots or archived copies of the notice shown at collection

Website and social-media governance

The decision is not limited to website administrators. It requires governance across the units that create, approve and publish content.

A practical publication process should include the following controls.

A publication register

Record every recurring publication process, including its:

  • Responsible department
  • Legal basis
  • Data fields
  • Audience
  • Platform
  • Approval owner
  • Publication period
  • Removal method
  • Processor or contractor involvement

A pre-publication review

Before publication, the content owner should answer:

  • Does this document contain personal data?
  • Is online publication necessary?
  • What exact rule permits or requires it?
  • Can fields be removed or masked?
  • Should access require authentication?
  • Has the publication period been entered?
  • Has the privacy notice been delivered?
  • Has a second person checked the final file?

Approved templates

Recruitment lists, examination results, procurement notices and council announcements should use approved templates that exclude unnecessary fields by default.

This is safer than asking employees to redact every new document manually.

Technical restrictions

Depending on the purpose, controls may include:

  • Authentication and role-based access
  • Automatic expiry
  • Download restrictions
  • Search-engine indexing controls
  • Access logging
  • Secure file storage
  • Separation of public and internal document repositories
  • Alerts for files containing identity-number patterns
  • Version control and approval records

Training

The decision expressly calls for training and awareness work, particularly for employees who manage websites and social-media platforms.

Training should also cover communications teams, human resources, procurement, student affairs, information technology, legal affairs, records management and external agencies.

Who is responsible when a contractor manages the website?

The public body will generally remain the data controller where it determines why the information is published, which information is used and how the publication process operates.

A hosting provider, website developer or communications agency may act as a data processor where it handles the information solely on the public body’s documented instructions.

Outsourcing publication does not outsource accountability.

Under Article 12, where personal data is processed on behalf of a data controller, the controller and processor share responsibility for taking the necessary data-security measures. The controller must also conduct or commission appropriate audits.

Contracts with service providers should therefore address:

  • Permitted processing and publication instructions
  • Authorized personnel
  • Confidentiality
  • Access controls
  • Security requirements
  • Subcontracting
  • Incident reporting
  • Backup and cache handling
  • Removal requests
  • Return or deletion at contract termination
  • Audit rights
  • Evidence and log retention

A contractor that independently decides to reuse, analyze, republish or retain the information for its own purposes may become a separate data controller for that activity. The classification depends on the actual decisions and conduct, not only the contractual label.

Enforcement consequences

The principle decision states that failure to take the identified measures may lead to a case-specific Board investigation and proceedings under Article 18 of the KVKK.

For public institutions and public professional organizations, Article 18 provides for the Board to notify the relevant institution so that disciplinary proceedings can be initiated against responsible officials and other public personnel. The outcome must be reported back to the Board.

The Board may also instruct the data controller to correct a processing operation, redesign a result-publication system, remove content or implement other appropriate measures. Previous cases involving public universities demonstrate that public-sector status does not remove the obligation to comply with Board instructions.

Immediate remediation checklist

Covered organizations should not wait for the next recruitment or examination cycle. The decision expressly calls for an urgent review of existing online content.

Immediate remediation checklist
Step Action Evidence to retain
01 Inventory public content Evidence to retain Website crawl, document inventory, subdomain list, social-media review and named content owners.
02 Identify personal-data fields Evidence to retain Review records showing identifiers, sensitive fields, pseudonymous data and affected groups.
03 Map the processing condition Evidence to retain The exact legal provision or documented Article 5 or Article 6 assessment.
04 Test necessity and proportionality Evidence to retain The purpose, audience, required fields and reasons less intrusive options were rejected.
05 Remove or correct unjustified publications Evidence to retain Before-and-after copies, approval records, removal dates and responsible personnel.
06 Check duplicate and cached copies Evidence to retain File-path checks, cache-purge logs, search-removal requests and third-party notices.
07 Set publication periods Evidence to retain Approved duration, legal source, expiry date and assigned removal task.
08 Redesign examination and recruitment results Evidence to retain Authentication design, access rules, masking assessment and participant-access rationale.
09 Review privacy notices Evidence to retain Version-controlled notices, delivery records, timestamps and proof of notice.
10 Review contractors and system access Evidence to retain Processor terms, access lists, deletion duties, security controls and audit results.
11 Train publishing teams Evidence to retain Training materials, attendance records, assessments and role-specific instructions.
12 Introduce recurring audits Evidence to retain Audit schedules, sample reviews, findings, corrective actions and closure records.

The first review should cover more than the website’s current navigation. Teams should search:

  • The main website
  • Subdomains
  • Old website platforms
  • PDF and spreadsheet directories
  • Media libraries
  • Search-engine results
  • Social-media accounts
  • Archived press releases
  • Departmental microsites
  • Recruitment and examination portals
  • Third-party agency platforms
  • Public cloud-storage links

Priority should be given to files containing complete identity numbers, contact details, special-category data, rejection reasons, detailed examination information and lists that have remained online beyond their operational purpose.

Key questions before publishing personal data

Before approving a new public document, the responsible team should be able to answer all of the following:

  1. What is the exact purpose of publication?
  2. What processing condition supports making the data available online?
  3. Does legislation require public internet publication, or only notification?
  4. Who needs access?
  5. Which fields are essential for that audience?
  6. Could authenticated or individual access achieve the purpose?
  7. Could the individual be reidentified after masking?
  8. Does the document contain special-category data?
  9. When must the content be removed?
  10. Who owns the removal task?
  11. How will removal from attachments, caches and social media be verified?
  12. How was the privacy notice delivered and recorded?
  13. Which contractors can access or publish the information?
  14. What evidence will demonstrate that the review took place?

A publication that cannot answer these questions should not proceed unchanged.

Conclusion

Türkiye’s 2026 principle decision does not establish a complete ban on public bodies publishing personal data. It requires them to stop treating public website publication as an automatic final step in an administrative process.

The practical rule is straightforward:

Establish the legal need, identify the necessary audience, publish the minimum data, limit the exposure period and remove the information when the purpose ends.

For examination, lottery and recruitment results, the direction is particularly clear. Publicly downloadable lists should give way, where practical, to authenticated and individualized access.

Public bodies should now inventory existing publications, remove unjustified content, redesign recurring workflows and clarify responsibility across communications, human resources, procurement, information technology, records management and external service providers.

Organizations should obtain qualified legal advice where a sector-specific publication duty, transparency requirement or administrative procedure affects the correct interpretation.

How Kooch can help

Kooch Cybersecurity & Compliance can support organizations and public-sector service providers with:

  • Website and social-media personal-data reviews
  • KVKK processing-condition and minimization assessments
  • Publication and removal workflow design
  • Privacy-notice review
  • Contractor and data-processor control reviews
  • Technical and administrative remediation planning
  • Ongoing privacy and security governance

The objective is not simply to redact documents after problems appear. It is to establish a repeatable process that prevents unnecessary personal data from reaching public systems in the first place.

Suggested internal links

  • KVKK and GDPR Gap Analysis
  • Ongoing Compliance Services
  • What Is Data Minimization Under the KVKK?
  • Authentication Versus Authorization
  • Personal Data Retention and Deletion Under the KVKK
  • How to Manage Data Processors and Service Providers
  • KVKK Privacy Notice Requirements

Sources and references

  • Kişisel Verileri Koruma Kurulu, Principle Decision No. 2026/1301, dated 1 July 2026 and published in Official Gazette No. 33323 on 28 July 2026.
  • Kişisel Verileri Koruma Kurumu, public announcement concerning Principle Decision No. 2026/1301.
  • Kişisel Verileri Koruma Kurulu, Decision No. 2019/389 concerning publication of academic recruitment scores.
  • Kişisel Verileri Koruma Kurulu, Decision No. 2019/188 concerning publicly accessible university examination results.
  • Kişisel Verileri Koruma Kurumu, Regulation on the Erasure, Destruction or Anonymization of Personal Data.
  • Kişisel Verileri Koruma Kurumu, data-security obligations of data controllers and processors.
  • Kişisel Verileri Koruma Kurulu, Decision No. 2020/481 and announcement concerning de-indexing requests.
  • Google Search Central, official documentation on removing or preventing indexing of website information.
Masoud Salmani