When data becomes the commodity: The Board’s crackdown on unlawful processing of accident victims’ personal data
By its Principle Decision No. 2026/1095 dated 20 May 2026, published in the Official Gazette dated 1 July 2026 and numbered 33297, the Personal Data Protection Board (the “Board”) has addressed the widespread unlawful processing and sharing of personal data belonging to victims of traffic accidents, workplace accidents and similar incidents. The decision follows numerous complaints received by the Personal Data Protection Authority (the “Authority”) indicating that accident victims were being persistently contacted, without their consent, by representatives of damage consultancy firms, lawyers or persons misrepresenting themselves as lawyers, who promised compensation in exchange for a power of attorney. Victims reported that they could not obtain satisfactory answers as to how their personal information had been obtained. In some cases, persistent calls were accompanied by intimidation that victims might suffer a loss of rights, while in others, proceedings were initiated on victims’ behalf even though no instruction or information had been provided. The Board’s investigation confirmed that identity data, contact information and other personal data contained in accident reports and similar documents were being accessed through various channels in the post-accident process. The Principle Decision was adopted unanimously and took effect upon its publication in the Official Gazette.
Key Findings and Regulatory Framework
The Board situated its analysis within the broader legislative framework, drawing on the Law on Attorneys numbered 1136, including Article 2 on the purpose of attorneyship, Article 35 on activities reserved to attorneys, Article 48 on the prohibition on intermediation and related sanctions, Article 55 on the prohibition on advertising, and Article 63 on unauthorised practice and related sanctions. The Board also relied on the Insurance Law numbered 5684, the Turkish Criminal Law numbered 5237 (the “TCC”) and the Personal Data Protection Law numbered 6698 (the “PDPL”).
In particular, the Board noted that:
Under Additional Article 6 of the Insurance Law, compensation claims against insurance institutions or the Guarantee Account (Güvence Hesabı) may only be paid to, and pursued by, the rights holder or their attorney, and such claims cannot be assigned to any other person or entity. Article 7 of the Circular on the Application of Additional Article 6 provides that any contract or transaction to the contrary is null and void under the Turkish Code of Obligations No. 6098, in addition to being contrary to the Insurance Law.
Damage consultancy firms and similar structures may only lawfully operate directly or indirectly through licensed attorneys. Operating otherwise may breach the relevant provisions of the Law on Attorneys, including the prohibition on intermediation and on the unauthorised practice of law.
Insurance experts may only process personal data within the scope of their statutory duties, such as loss assessment, reporting and claims management, and must rely on a valid legal basis under Article 5 of the PDPL. The decision identifies three relevant processing conditions: processing being explicitly stipulated by law; processing being necessary for the data controller to fulfil its legal obligation; and processing being directly related to the establishment or performance of a contract. Insurance experts are bound by professional confidentiality obligations and may not share personal data with unauthorised third parties.
Personal data of accident victims may lawfully be processed for the conduct of post-accident processes, such as judicial or administrative investigations, the treatment of victims and the repair of damaged vehicles. However, such data may only be processed for the limited purpose of managing these post-accident processes and in full compliance with the conditions set out in Articles 4, 5 and 6 of the PDPL. Article 12(1) of the PDPL further requires data controllers to take all necessary technical and administrative measures to ensure an appropriate level of security, including measures to (a) prevent unlawful processing, (b) prevent unlawful access and (c) ensure the retention and security of personal data.
Article 12(4) of the PDPL also provides that persons who process personal data within a data controller’s organisation may not disclose that data to third parties in breach of the PDPL or use it beyond the purpose for which it was processed. These obligations continue after the individual leaves their position. In addition, professionals working in healthcare, insurance and legal practice are subject to sector-specific professional secrecy obligations under their respective legislation.
Consequences and Enforcement
The Board emphasised that the unlawful obtaining, transfer or disclosure of personal data may constitute a criminal offence under Article 136 of the TCC, potentially in its aggravated form under Article 137. Depending on the circumstances, criminal complaints may be filed with the relevant Public Prosecutor's Office, while the matter may also give rise to administrative proceedings before competent ministries, professional bodies and bar associations. Where the relevant actors qualify as data controllers, data subjects may additionally exercise their rights under the PDPL, including by lodging complaints with the Board pursuant to Article 13 et seq. The Board specifically warned that data controllers failing to comply with this Principle Decision will face proceedings under Article 18 of the PDPL, which provides for administrative fines.
The decision is notable not merely because it addresses unlawful personal data processing, but because it targets a broader business model that monetises the vulnerability of accident victims. In practice, complaints received by the Authority suggest a recurring pattern in which victims are contacted shortly after an incident by individuals claiming access to compensation services, despite having had no prior relationship with the victim and no obvious lawful basis for obtaining the relevant information. The Board's findings indicate that personal data collected during post-accident processes has, in some cases, been diverted to purposes wholly unrelated to the original reason for collection, turning a moment of acute vulnerability into a source of commercial opportunity and directly conflicting with the purpose limitation principle under the PDPL.
The decision should also be viewed against the backdrop of broader regulatory efforts to restrict the commercialisation of accident compensation claims. Additional Article 6 of the Insurance Law already provides that compensation claims against insurance institutions and the Guarantee Account may be pursued only by the rights holder or their attorney and may not be assigned to third parties. Data protection law and insurance law therefore work in tandem: the Insurance Law closes the assignment route, while the PDPL cuts off the unlawful data flows that serve as the oxygen supply for these business models. By denying unauthorised access to accident-victim data, the Board’s approach indirectly reinforces the Insurance Law’s non-assignment rule and makes clear that personal data cannot be used as a workaround for statutory restrictions.
This broader trend is not unique to Türkiye. On 25 June 2026, the Court of Justice of the European Union confirmed in Case C-277/25 that Member States remain free to restrict or prohibit the assignment of accident-compensation claims under national law. While the Board's decision is grounded entirely in Turkish data protection law, it nevertheless forms part of a wider European regulatory movement towards greater scrutiny of claims-management and damage-consultancy activities, particularly where personal data, legal services regulation and consumer protection concerns intersect.
Practical Implications
For insurers, insurance experts, claims-management service providers and other organisations operating within the post-accident ecosystem, the decision serves as a reminder that access to personal data collected during claims processes does not create a general entitlement to reuse or disclose that information for commercial purposes. The Board's findings reinforce the importance of purpose limitation, the minimum privilege principle, access controls and accountability throughout the data lifecycle.
Businesses handling accident-related data should in particular consider:
- reviewing who has access to accident reports, claims files and related records, and whether that access remains consistent with operational necessity;
- assessing whether existing technical and organisational measures adequately prevent unauthorised sharing or extraction of personal data;
- implementing the minimum privilege principle through role-based access controls and tracking and audit mechanisms for access to personal data;
- reviewing contractual arrangements with external service providers, experts and intermediaries that may have access to claims-related information;
- conducting training and awareness activities on personal data protection, including confidentiality obligations and lawful processing requirements under the PDPL;
- ensuring that post-employment confidentiality obligations are addressed in policies and contractual arrangements, recognising that Article 12(4) duties continue after the working relationship ends; and
- ensuring that any use of accident-victim data remains strictly connected to the purpose for which that data was originally collected.
The decision also illustrates a broader enforcement trend. Organisations should expect increasing regulatory scrutiny not only of how personal data is collected, but also of how information moves through complex claims, insurance and service-provider ecosystems. In practice, the greatest compliance risk may arise not from the original collection of personal data, but from unauthorised secondary use or onward disclosure once that data has entered the system. The Board has put data controllers on notice: non-compliance with the Principle Decision will trigger enforcement proceedings under Article 18 of the PDPL.
For more information regarding the implications of these developments or their potential impact on your data protection compliance framework in Türkiye, please contact your CMS Partner or local CMS Data Protection Expert: Dr. Döne Yalçın or Erdinç Dalar.