Company phone, private messages: The Court of Cassation draws the line on employer surveillance — moral damages upheld for unauthorised reading of WhatsApp conversations
With its unanimous decision dated 12 January 2026, issued under case file number 2025/9161 and decision number 2026/2, the 9th Civil Chamber of the Court of Cassation (the “Court”) upheld the rulings of the first instance court and the Regional Court of Appeal (6th Civil Chamber). The landmark decision confirms that an employer’s unauthorised reading of an employee’s private WhatsApp messages on a company-issued phone may violate the right to privacy, render a dismissal unjustified and give rise to moral damages liability. It is significant under both Turkish labour law and data protection principles, particularly where personal communications are accessed and used in disciplinary or employment proceedings. The Court accordingly upheld the employee’s entitlement to severance pay, notice pay and moral damages.
Background
An engineer employed by the defendant company for approximately five years was dismissed after the employer demanded the return of the company-issued mobile phone. When the employer examined the phone, it accessed private WhatsApp conversations containing critical remarks about the company's managers, projects director and colleagues. The employer also discovered that the employee had secretly photographed three female colleagues eating in the workplace cafeteria and sent the photograph to another employee, describing them as “three devils”. These matters were recorded in official minutes, and the employee was asked to provide a written defence, which he did not submit. The employer then terminated the employment contract under Article 25/II-(b) of Labour Law No. 4857, on the basis of acts contrary to honesty and loyalty. The employee claimed severance pay, notice pay, annual leave pay, premium payments, minimum living allowance, bad faith compensation and moral damages, arguing that the unauthorised reading and recording of private messages violated his personal rights and privacy. The employer argued in response that all wages had been paid through banking channels, that no premium system existed and that no further employment-related amounts were due.
The Court’s Reasoning
The first instance court held that the employer had no right to read the employee’s private messages with third parties, record them in official minutes or use them as grounds for termination, regardless of their content. The ownership of a device did not grant the employer the right to access the employee’s private life, read personal messages or record them. On that basis, the dismissal was found to be unjustified. Because the termination had been carried out after the employee’s WhatsApp messages were read in violation of the privacy of private life, the court also awarded moral damages in the employee’s favour.
The Regional Court of Appeal (6th Civil Chamber) upheld the first instance decision on both procedural and substantive grounds. The employer then filed a cassation appeal, arguing that (i) the termination was for just cause, (ii) wages had been paid in full and no premium system existed, and (iii) moral damages should not have been awarded. The Court of Cassation rejected all three grounds, finding that the decision was consistent with the applicable law and procedural rules.
On the bad faith compensation issue, the first instance court rejected the employee’s claim because employees covered by job security provisions cannot claim bad faith compensation. It also found no separate evidence in the record showing that the manner of dismissal independently involved bad faith.
Practical Implications for Employers
The decision confirms that employees retain a constitutional expectation of privacy in relation to personal messages and data stored on company-issued devices. This protection is grounded in Article 20 of the Turkish Constitution, which protects private and family life, and Article 22, which protects the secrecy of communication. Ownership of the device does not, by itself, entitle an employer to access private communications, and evidence obtained through unauthorised inspection cannot properly be relied upon in judicial proceedings. Such conduct may also expose employers to moral damages liability and undermine the validity of a dismissal decision.
The more significant lesson, however, concerns the distinction between unlawful monitoring and a lawfully established monitoring framework. Constitutional Court jurisprudence, reflecting the principles developed in the Barbulescu v. Romania line of reasoning and adopted in Turkish constitutional case law, indicates that monitoring should be grounded in a legitimate purpose, communicated transparently, limited to what is necessary and proportionate, and accompanied by appropriate safeguards against arbitrary access. Employers need not necessarily obtain separate consent each time an inspection takes place, provided employees have previously been informed through a clear contractual provision or acknowledged written policy setting out the purpose, scope and duration of monitoring. Any such framework should also comply with the Personal Data Protection Law numbered 6698 (the “PDPL”), including requirements concerning a defined processing purpose, appropriate information, data minimisation, access controls, retention and security. In this case, the decisive factor was the absence of an adequate framework. Employers should therefore ensure that device use and monitoring arrangements are clearly documented and acknowledged before any inspection occurs, particularly where information obtained from company-issued devices may later be relied upon in disciplinary or employment proceedings.
Key Takeaways
- Implement clear BYOD and company-device policies that distinguish business use from personal communications and explain any monitoring.
- Obtain written acknowledgement from employees describing the scope, purpose, duration and safeguards of any monitoring.
- Give employees a genuine opportunity to delete or separate personal data before a company device is returned or inspected.
- Do not rely on unlawfully obtained messages, photographs or other personal data as grounds for termination or disciplinary action.
- Ensure ongoing compliance with the PDPL and consider appointing a data controller representative where appropriate.
For further information regarding this decision and its implications for your employment practices, workplace policies and data protection compliance in Türkiye, please contact your CMS Partner or local CMS Experts: Dr. Döne Yalçın or Erdinç Dalar.