
The Personal Data Protection Authority has published new policy decisions regarding the supervision of corporate e-mail and communication channels in workplaces.
Personal Data Protection Authority (KVKK) published new policy decisions in the Official Gazette regarding employers' auditing of corporate e-mail and communication channels.
AI-generated summary
The Personal Data Protection Authority has adopted a new principle to ensure the balance between employee inspections and privacy in workplaces.
The Personal Data Protection Authority has taken important policy decisions regarding the supervision of corporate e-mail accounts allocated by workplaces to their employees and communication channels used for business.
The Personal Data Protection Authority (KVKK) has published a principle decision regarding the auditing of corporate e-mail accounts allocated by employers to employees and communication channels used for work.
In the decision published in the Official Gazette, it was stated that the corporate e-mail account allocated to employees is a data source containing the employee's professional and sometimes personal relationship network, work pattern and correspondence contents.
It was pointed out that auditing these accounts by the employer is a personal data processing activity that requires observing the balance between the employer's right to management and the employee's right to request the protection of personal data guaranteed in the Constitution and freedom of communication.
In the decision, "Even the employer's processing of traffic/log records without accessing the content of the employee's e-mail constitutes a personal data processing activity in itself. The mere fact that the communication tools belong to the employer or are present at the workplace does not grant the employer unlimited and absolute control authority." statements were included.
In the institution's principle decision, it was noted that when determining the scope of the audit activity, the distinction between "business use" and "private purpose use" should be taken into account according to the purpose of use of workplace communication tools.
In the decision, it was stated that the employer can determine the rules regarding the private use of workplace communication tools, but these rules should be clear, understandable and knowable by the employee. It was emphasized that if the use of private purposes is prohibited, limited or subject to certain time, scope and method conditions, this should be clearly announced to the employee.
In the decision, it was stated that the fact that the employer has technical authority over a particular device, session, network or corporate system does not mean that the employee can freely access the correspondence contents in the employee's personal e-mail account, personal instant messaging application, social media message box or similar private communication areas.
In the decision, it was emphasized that the employee should be informed about the audit activity in advance, and it was stated that the clarification to be made by the employer should go beyond an abstract and general expression and include the legal reason, purpose, scope of the personal data processing activity, whether the audit will be carried out by examining traffic / log records or content audit, under what circumstances the content can be accessed, and the storage period of the data in a clear, understandable and concrete manner.
In the decision, it was emphasized that the audit should be carried out in accordance with the law and the rules of honesty, based on a specific, clear and legitimate purpose, in connection with this purpose, in a limited and measured manner, and the data obtained should be kept only for the period required by the purpose.
In the decision, which stated that graduality in the control was essential, it was stated that access to the content could only be brought to the agenda in exceptional cases where traffic data control was insufficient and access to the content was mandatory.

KVKK has published a new principle regarding employers' auditing of corporate e-mail and communication channels allocated to employees. The decision requires that the balance between the privacy of employees' private lives and the employer's right to management be maintained during inspections.

The 95th hearing of the IMM case with 436 defendants, including Istanbul Metropolitan Municipality Mayor Ekrem İmamoğlu, is being held in Silivri. İmamoğlu is expected to make his defense next Tuesday.
KVKK published the principle decision regarding employers' monitoring of employees' corporate e-mail and communication channels in the Official Gazette. According to the decision, employers do not have unlimited control authority and employees must be informed in advance.

Istanbul Chief Public Prosecutor's Office announced that ex officio legal action will be taken against those who spread false claims and disinformation about the fund investigation, in accordance with Article 217/A of the TCK.

Within the scope of the lawsuit in New York, TikTok claims that it blocks certain user groups' access to security tools such as 'Algo Refresh' and conducts experiments that increase their exposure to harmful content; The company states that these tests are part of the product development process and that young user safety is a priority.

The issue of the Official Gazette of the Republic of Turkey dated October 8, 2026 and numbered 33394 came to the fore with the decision of the Personal Data Protection Board containing critical limits and principles regarding employers' monitoring of employee e-mails. In addition, regulations regarding the collection of administrative fines for vehicles with foreign license plates from the operation of the Turkish Product Specialized Exchange, railway vehicles type approval penalties and repealed regulations within the Ministry of Internal Affairs were also included.