The DPL Board Issues a Principle Decision on the Processing of Personal Data of Accident Victims
- Jul 3
- 2 min read
Selin Çetin Kumkumoğlu
Of Counsel
Yaren Alparslan
Associate
Buse Sığın
Legal Intern
Introduction
The Personal Data Protection Board (the “Board”) published its Principle Decision No. 2026/1095 dated 20 May 2026 (the “Principle Decision”), addressing unlawful access to and processing of personal data belonging to accident victims following occupational accidents, traffic accidents, and similar incidents, based on complaints and notifications submitted to the Board.
The Board’s Assessment
In the Principle Decision, the Board referred to the Attorneys' Act No. 1136 and the Insurance Act No. 5684, emphasizing that insurance compensation claims may only be pursued by the persons authorized under the applicable legislation and may not be assigned to third parties.
The Board further noted that unlawful access to and processing of personal data may not only result in administrative sanctions under the Personal Data Protection Law No. 6698 (the “DPL”), but may also give rise to criminal liability under the Turkish Criminal Code.
Key Considerations for Data Controllers
The Principle Decision reminds data controllers processing the personal data of accident victims that they are required to effectively implement the necessary technical and administrative measures pursuant to Article 12 of the DPL. In this context, the Board emphasized the importance of increasing employee awareness, restricting access to personal data in line with employees’ duties and responsibilities, implementing role-based access controls and maintaining access logs, as well as adopting organizational measures to prevent employees from using or disclosing personal data without authorization.
Conclusion and Assessment
The Principle Decision reminds data controllers of their significant obligations regarding the processing of the personal data of accident victims and sets out the Board’s supervisory and enforcement approach in this area. In particular, data controllers operating in the insurance, healthcare and legal sectors that process personal data within the scope of accident-related matters should review not only the legal grounds for their personal data processing activities, but also their data security policies, access authorization procedures and employee awareness practices.



