Legislative Amendments and Compliance Guide on the Processing of Sensitive Personal Data
Introduction
With the publication of Law No. 7499 (“Amendments”) in the Official Gazette dated 12 March 2024 (No. 32487), Türkiye’s data protection landscape has entered a new chapter. The Amendments reshape the framework governing sensitive personal data under the Law on the Protection of Personal Data No. 6698 (“LPPD”), introducing fresh processing conditions designed to address long-standing practical uncertainties. In step with these changes, the Personal Data Protection Authority (“Authority”) has issued a Guideline on the Processing of Sensitive Personal Data (“Guideline”) — a hands-on compliance resource that equips data controllers with clear, actionable direction for meeting their obligations.
1. Amendments Regarding the Scope of Sensitive Personal Data
1.1 Definition of Sensitive Personal Data
Article 6 of the LPPD draws a clear boundary around what qualifies as sensitive personal data through an exhaustive, closed list. The categories span a broad spectrum: race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, clothing, membership in associations, foundations, or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data.
1.2 Newly Introduced Processing Conditions
Before the Amendments, the legal grounds for processing sensitive personal data were narrow: either the data subject’s explicit consent or a specific statutory authorisation. The Amendments have significantly broadened this landscape by introducing the following additional grounds:
- If the data subject is unable to provide consent or does not have legally valid consent, data may be processed to protect the life or physical integrity of the data subject or another person.
- If the data subject has made their personal data public, such data may be processed in line with the purpose of the disclosure.
- If the processing of personal data is necessary for the establishment, exercise, or protection of a legal right, such data may be processed without the need for explicit consent.
- Data may be processed to fulfil legal obligations relating to occupational health and safety, social security, social services, and social assistance.
- Foundations, associations, or other non-profit organisations established for political, religious, or trade union purposes may process personal data of their members or former members within the scope of their legitimate activities.
2. Principles and Obligations Set Out in the Guideline
2.1 Principle of Lawfulness
At its core, the Guideline reinforces a familiar but essential set of principles: sensitive personal data must be processed lawfully and fairly, for purposes that are specific, explicit, and legitimate. Processing activities should remain relevant, limited, and proportionate — no more data than what the purpose demands. Equally important, personal data must be kept accurate, updated where necessary, and retained no longer than the processing purpose requires.
2.2 Obligations of Data Controllers
To align with the updated framework, data controllers should turn their attention to the following practical obligations:
- All processes related to the processing of sensitive personal data must be reviewed, and the data processing inventory must be updated accordingly.
- Data processing activities based on explicit consent must be duly organised, and the legal validity of the consent must be ensured.
- The obligation to inform data subjects must be fully complied with, and any necessary updates to the information provided must be made.
- Data controllers must review and update their policies and procedures regarding the retention and destruction of personal data.
- Technical and administrative measures must be implemented to protect against unauthorised access, data breaches, and data leaks.
3. Considerations in the Compliance Process
The Amendments undoubtedly give data controllers more room to manoeuvre when processing sensitive personal data — but that flexibility comes with responsibility. The general principles and security obligations of the LPPD remain firmly in place. Data controllers must therefore anchor every processing activity in either explicit consent or a clearly identified lawful basis under the applicable legislation.
Particular vigilance is warranted for biometric and genetic data, which by their very nature demand robust safeguards. Deploying fit-for-purpose technical and administrative measures — and continuously strengthening defences against unauthorised access and data breaches — remains a central expectation of the LPPD.
4. Conclusion
The Amendments mark a meaningful step forward, granting data controllers a wider toolkit for processing sensitive personal data while leaving the LPPD’s foundational principles and security standards fully intact. Navigating this expanded landscape successfully hinges on strict adherence to the new rules and a proactive approach to compliance. The Guideline, published by the Authority, stands as an indispensable reference — and data controllers would be well advised to finalise their alignment efforts without delay.
To explore how the Guideline may affect your organisation and to discuss tailored next steps, reach out to your CMS partner or local CMS expert: Dr. Döne Yalçın.