The Turkish Personal Data Protection Board (the “Board”) published a Public Announcement (the “Public Announcement”) on 27 August 2026 concerning its Principle Decision dated 29 April 2026 and numbered 2026/921 on the Processing of Biometric Data for Attendance (the “Principle Decision”).
This Announcement has been prepared to inform the public about the obligations of data controllers under Personal Data Protection Law No. 6698 (the “
Law”) in this regard and to address uncertainties arising in practice concerning this matter
Key Takeaways from the Public Announcement
- Converting biometric data into mathematical code does not alter its biometric nature. The Board stated that data which, as a result of specific technical processing, enables the unique identification or authentication of a natural person qualifies as biometric data, and that converting such data into mathematical codes and storing it in this form does not alter its biometric nature.
- Processing biometric data solely for the purpose of monitoring working hours is incompatible with the principle of proportionality. The Board stated that biometric data processing activities carried out solely for the purpose of monitoring working hours do not rely on any of the conditions for processing special categories of personal data set out under the Law and, furthermore, that even where valid explicit consent has been obtained, such processing would not satisfy the proportionality requirement stipulated under the Law. The Board also noted that there is no explicit statutory provision requiring employers to fulfil their obligation to monitor and document working hours through the use of biometric identification systems and indicated that such practice may therefore be unlawful.
- Biometric data processing in areas subject to heightened security requirements is also subject to a proportionality assessment. The Board stated that certain facilities and areas of activity may warrant a different assessment due to the security risks involved. In such areas, biometric data may be processed for purposes other than attendance tracking, such as ensuring security and protecting critical infrastructure. In such cases, the processing must be limited to the relevant critical areas and individuals, alternative methods must be insufficient, and the processing must be proportionate to the specific security need.
- The use of biometric data is not unlimited, even in respect of activities falling outside the scope of the Law. The Board stated that the flexibility afforded to certain data processing activities that may, under specific circumstances, fall outside the scope of the Law does not permit the unrestricted processing of biometric data. In each individual case, the severity of the security risk, the inadequacy of alternative methods, and the purpose of the data processing must be considered. In this context, the determining factor is whether the processing of biometric data goes beyond the purpose of “monitoring working hours” and is used for the purpose of ensuring public security.
Through the Public Announcement, the Board has clarified the
distinction between biometric data processing activities carried out for the purpose of monitoring working hours and biometric data processing activities carried out for purposes other than monitoring working hours. Accordingly, biometric data processing activities conducted for the purpose of monitoring working hours must be carried out in accordance with the Principle Decision, whereas biometric data processing activities conducted for purposes other than monitoring working hours will not be assessed within the scope of the Principle Decision. Instead, such activities must be assessed separately by data controllers, taking into account their lawfulness, the purpose of the data processing, the nature of the relevant activity, and the specific circumstances of each case.
The Authority’s Public Announcement is available
here. Our previous MORAL legal update on the Principle Decision is available
here.