Our article assesses the Turkish data protection watchdog's Principle Decision No. 2026/2035 of 8 October 2026: why monitoring is data processing, the duty to inform, proportionality, graduated review, the insufficiency of consent and the effect on internal investigations.
The Principle Decision of the Turkish Personal Data Protection Board, the country's data protection watchdog, dated 16 September 2026 and numbered 2026/2035 was published in the Official Gazette of 8 October 2026, issue 33394. The decision sets out the principles to be observed in monitoring the communication channels used for the conduct of business, foremost among them the corporate email accounts allocated by employers to their employees. The understanding settled in practice has been that the employer's ownership of the communication tool permits any form of monitoring of that tool. The decision expressly rejects that understanding and separates ownership from the power to access the data. Its practical effect is not confined to a narrow compliance matter; internal investigations, information leak inquiries, non-compete breach examinations, disciplinary processes and dismissal files will henceforth carry the risk both of administrative sanction and of the unlawfulness of the evidence obtained, where they are not conducted within this framework. This article assesses the scope of the decision, the characterisation of monitoring as personal data processing, the duty to inform, the principles of proportionality and graduated review, the position of explicit consent, the period following the end of the employment relationship, the effect on internal investigations and the obtaining of evidence, the parallel with the case law of the European Court of Human Rights, and the concrete measures employers should take.
1. The Scope of the Decision
The Principle Decision is not confined to corporate email accounts. It covers the communication channels used for the conduct of business generally, and makes the subject of its assessment operations carried out over those channels such as monitoring, accessing the content of correspondence, examining traffic and log records, filtering and conducting routine checks. This breadth of scope matters in practice; corporate messaging applications, internal communication platforms, communication conducted through devices belonging to the employer and the records kept on those devices must likewise be assessed within this framework. That an employer has adopted an email policy alone does not mean it is exempt from the same obligations as regards other channels. A further important point as to scope is that technical ability to access does not create a legal power of access; an employee's personal email account, private messages or social media communications may not be freely examined even where they are accessible through the employer's device or network. The practice frequently encountered in the field, of glancing at personal accounts left open on a company laptop, is not defensible against this finding.
2. Separating Ownership from the Power of Access
The starting point of the decision is that the employer's ownership of the corporate email account or of other communication tools does not confer on the employer an unlimited power of monitoring over employees' communication activities. This finding addresses directly the most widespread misconception in practice. That an account, computer, network or corporate system belongs to the employer does not mean that all communication carried out by employees over those systems may be monitored without any limitation. On the same line, that the employer has adopted a rule to the effect that corporate email may be used for business purposes only does not of itself create a right of continuous surveillance. This distinction reflects the basic logic of data protection law; the ownership of the medium in which the data is held and the protection attaching to that data are independent of one another. A comparable distinction exists in property law; ownership of a safe does not confer a power of free disposal over documents belonging to a third party kept inside it. Even within its own system, the employer may process an employee's personal data only within the conditions laid down by the Law.
3. Monitoring as Personal Data Processing
The watchdog characterises the monitoring activities conducted by the employer as personal data processing. This characterisation clarifies a point frequently overlooked in practice; it is not necessary that the content of correspondence has been accessed for monitoring to qualify as personal data processing. The examination of the traffic or log records alone of the corporate email accounts allocated to employees itself constitutes a personal data processing activity. The consequence is that, without any content being viewed, examining records of who corresponded with whom and when, collecting connection records or analysing communication traffic likewise falls within the scope of the Law and requires compliance with the conditions for data processing. This finding bears directly on the use of information security tools; data loss prevention systems, email archiving solutions, endpoint monitoring software and network traffic analysis tools process personal data even where they read no content, and that processing requires a legal basis and disclosure. Many systems installed by IT departments on security grounds fail to meet this obligation where they are deployed without the knowledge of the legal function.
4. Compliance with the General Principles
The decision emphasises that monitoring activities must be conducted in conformity with the provision of the Law governing the general principles. Within that framework, processing must be lawful and in accordance with the rules of good faith, must rest on a specific, explicit and legitimate purpose, and must be connected with, limited to and proportionate to the purpose of processing. The counterpart of these principles in the monitoring context is concrete. The requirement of a specific and explicit purpose obliges the employer to define in advance the purpose for which it conducts the monitoring; a general justification of security or productivity does not satisfy this requirement. The requirements of connection and limitation oblige the monitoring to be confined to data serving the determined purpose. The requirement of proportionality obliges the employer, where more than one method is available to achieve the purpose, to choose the method interfering least with personal data. That the employer must have a legitimate purpose, and that the method applied must be connected with that purpose and proportionate, are the core criteria the decision repeats. These criteria also set out the checklist to be used in assessing the lawfulness of any monitoring activity.
5. The Duty to Inform and the Insufficiency of General Notices
The part of the decision that will generate most work in practice concerns the duty to inform. For monitoring to be regarded as lawful, employees must be informed in advance and in clear terms. The watchdog draws a concrete line here; general notices to the effect that the corporate email account may be monitored by the employer do not satisfy the information requirement and are not treated as discharging the provision of the Law governing the duty to inform. The practical consequence is that the single-sentence monitoring clauses widely found in existing employment contracts and workplace policies are inadequate. The information provided is expected to set out comprehensibly on which channels, for which purpose, by which methods and with what frequency monitoring will be carried out, which data will be processed, who will have access and what the retention periods are. Employers must review their existing privacy notices and workplace directives against this standard. That review must be conducted not only as regards new recruits but also as regards existing employees, and the fact that the information was given must be recorded in a manner capable of proof.
6. The Prohibition on Covert Monitoring and Indiscriminate Recording
The decision expressly treats two monitoring methods as unlawful. The first is covert monitoring methods of which the employee has not been informed in advance. The second is monitoring carried out by tools that record all of an employee's operations without distinction. What these two prohibitions have in common is the breach of the principles of proportionality and foreseeability. Covert monitoring removes the employee's ability to regulate its own conduct accordingly; indiscriminate and continuous recording nullifies the principle of purpose limitation. In practice these prohibitions bear directly on internal investigation practices. Scanning all of an employee's past correspondence without its knowledge upon a suspicion of an information leak carries serious risk within the framework of the decision. Likewise keystroke logging software, tools collecting periodic screenshots and systems archiving all communication without distinction will constitute unlawfulness where they are used without passing through the filters of prior information and proportionality. The nuance requiring attention here is that what is prohibited is not the installation of such tools but their operation without notification to the employee and without limitation.
7. Graduated Review and the Exceptional Nature of Content Access
The decision provides that a graduated method must be followed in monitoring employees' communication channels. On this approach, access to content is not the first step of monitoring but the last. It must first be assessed whether the result can be reached by less intrusive methods, and content must be accessed only where there is a concrete suspicion and access is necessary. In practice this gradation requires the following sequence; first, direct methods such as speaking with the employee and requesting information, then the examination of non-content data, and at the final stage a limited and targeted examination of content. Even where examination of content is reached, the examination is expected to be kept as narrow as possible in terms of subject matter, time frame and persons. In practice this means determining search terms in advance, limiting the date range to be examined and not displaying content falling outside the scope. In workplaces where private use is permitted a further limit applies; where business correspondence can be separated from personal correspondence, monitoring must be confined to business-related communication.
8. Why Explicit Consent Is Not Sufficient on Its Own
The decision contains an important finding as to the position of explicit consent in the employment relationship. It draws attention to the inequality of power between employee and employer and states that the employee's consent cannot be regarded as sufficient on its own. This approach reflects a principle settled in data protection law; for explicit consent to be valid it must be given by free will, whereas the relationship of dependence in employment renders that freedom questionable. The practical consequence is that pre-printed documents obtained from the employee at the recruitment stage stating that it consents to monitoring cannot of themselves constitute the legal basis of the monitoring. The employer must base its processing on one of the other processing conditions laid down in the Law and must be able to establish that the condition genuinely exists in the concrete case. The watchdog further emphasises that the existence of one of those conditions does not confer on the employer an unlimited right of monitoring; the presence of a legal basis does not remove the review for proportionality and purpose limitation. Legal basis and proportionality are two separate thresholds, and both must be crossed.
9. Restricting Access Rights and Data Security
The decision also imposes a limit as regards access to the data obtained as a result of monitoring. Only a limited number of personnel assigned to that task may access such data. This regulation seeks to prevent the monitoring activity from spreading within the organisation and the information obtained from being seen by unrelated persons. In practice this requires that those to whom monitoring authority is granted within the organisation be determined in writing, that access logs be kept and that the assigned personnel be placed under a confidentiality obligation. The decision further states that employers must take the necessary technical and administrative measures within the scope of their monitoring activities. Those measures include storing the data obtained in a secure environment, determining retention periods and destroying the data at the end of those periods, access controls and recording the monitoring process. A matter frequently overlooked in practice is the distribution of monitoring findings within the organisation to senior management or to unrelated units; that distribution may constitute a separate breach even where the monitoring itself was lawful.
10. The Period After the Employment Relationship Ends
The decision also governs the period following the end of the employment relationship between employee and employer. The legal basis of the data processing activity relating to the corporate email account allocated to a departing employee must be reassessed. This finding bears directly on two practices widespread in the field. The first is keeping the departing employee's account active indefinitely and monitoring incoming messages. The second is redirecting the account to another employee or transferring its contents. Both practices must be restructured having regard to the fact that the legal basis for processing changes once the employment relationship has ended. The approach that may be adopted in practice is to close the account at the end of a reasonable period, to send automatic notifications to senders during that period, and to separate and archive content that must be retained for business purposes. Determining the period and the method in advance and notifying the employee at the exit stage prevents disputes arising later. This matter should be addressed within a single procedure together with the other measures taken in employee exit processes.
11. The Effect on Internal Investigations and the Obtaining of Evidence
The most critical practical effect of the decision is on internal investigation processes. In investigating allegations of trade secret leakage, breach of a non-compete undertaking, irregularity and conduct contrary to good faith, the principal source to which the employer turns is the employee's corporate communication records. The decision does not remove access to that source but binds it to strict procedural rules. Before an investigation is commenced, the concrete suspicion must be documented, the decision to monitor must be reduced to writing together with its reasons, the scope must be limited as to persons, subject matter and time, and the process must be recorded. Omitting these steps gives rise to two distinct risks. The first is the risk of an administrative fine. The second, and from the employer's standpoint often the graver, is the risk that information obtained by unlawful means cannot be used as evidence in proceedings. Having evidence relied upon in a dismissal or compensation action excluded from assessment on this ground may leave even an employer that is substantively in the right without a result. The decision is therefore not merely a compliance matter but a matter of litigation strategy.
12. The Parallel with the Case Law of the European Court of Human Rights
The framework adopted by the Turkish watchdog aligns with the settled approach of the European Court of Human Rights in this field. The case of Bărbulescu v. Romania, decided by the Grand Chamber, assessed an employer's monitoring of an employee's instant messaging account used in the workplace from the standpoint of the right to respect for private life and found a violation. The judgment set out the criteria national authorities must observe; whether the employee was notified before the monitoring, the extent of the monitoring and the degree of intrusion into privacy, whether the employer had legitimate reasons justifying the monitoring, whether less intrusive methods were possible, the consequences of the monitoring for the employee and the safeguards afforded to the employee are among those criteria. The parallel between those criteria and the principles introduced by the Decision is striking; prior notification, legitimate purpose, proportionality, preference for the less intrusive method and the provision of safeguards occupy a central place in both instruments. This alignment shows that the Court's case law may be used as a source of interpretation in applying the decision, and carries particular value for multinational companies.
13. The Sanctions Dimension and Compliance Risk
The watchdog states that, where it is established that the obligations determined have not been complied with, the necessary examination will be carried out having regard to the features of the concrete case. Since principle decisions set out the interpretative framework the Board applies in its supervisory activity, departure from the principles determined by this decision will be made the direct subject of assessment in complaint or ex officio examination processes. Among the sanctions data controllers may face are the administrative fines provided for failure to discharge the duty to inform, breach of the obligations relating to data security and failure to comply with Board decisions. In addition, the unlawful processing of data in the course of an internal investigation may also lay the ground for a compensation claim by the data subject and, where the conditions are met, for criminal liability in respect of the unlawful obtaining or dissemination of personal data. Compliance risk is therefore threefold; administrative sanction, private law liability and criminal liability. Assessing these three layers together makes it essential that the legal function be involved in the preparation of monitoring policies from the outset.
14. Measures Employers Should Take
The decision indicates that employers must reassess their monitoring policies on corporate email and other workplace communication tools within the framework of the principles of legal basis, prior information, proportionality, purpose limitation and data security. The concrete steps to be taken within that framework are as follows. First, the general monitoring clauses in existing employment contracts and workplace regulations must be reviewed and a detailed policy on the use and monitoring of communication tools must be prepared. Second, privacy notices must be updated so as to cover the monitoring activity, and the information must be given in a manner capable of proof. Third, the legal basis of the monitoring must be determined and a basis not resting on explicit consent must be identified. Fourth, an inventory of the monitoring and recording tools in use must be drawn up and assessed for proportionality. Fifth, access rights must be restricted and determined in writing. Sixth, the internal investigation procedure must be reduced to a written protocol, and the reasons, scope and method must be recorded in each investigation. Seventh, the rules on account closure and archiving in employee exit processes must be determined. Eighth, the personal data inventory and the retention and destruction policy must be updated so as to cover these activities.
15. Conclusion and Assessment
The Principle Decision does not remove the employer's power of monitoring; it places that power within the general framework of data protection law. The framework the watchdog introduces may be summarised as follows. Ownership of the communication tool and the power to access its content are distinct; even where the tool belongs to the employer, monitoring is not unlimited. Monitoring constitutes personal data processing and is subject to the general principles of the Law even where no content is accessed and only traffic and log records are examined. Employees must be informed in advance and in clear terms; general notices do not discharge the duty to inform. Covert monitoring and systems recording indiscriminately are unlawful. A graduated method must be followed, and access to content must be confined to cases of concrete suspicion and necessity. Explicit consent does not constitute a basis on its own by reason of the inequality of power in the employment relationship, and the existence of a legal basis does not remove the proportionality review. Access to the data obtained must be restricted to a limited number of assigned personnel, and technical and administrative measures must be taken. Once the employment relationship ends, the basis for processing relating to the account must be reassessed. The decision aligns substantially with the criteria adopted by the European Court of Human Rights, and that alignment is instructive in interpretation. Employers reviewing their existing policies without delay will not only reduce the risk of administrative sanction but will also secure the usability in proceedings of evidence obtained in internal investigations.
The decision is closely connected with the other fields concerning employee relations and the protection of commercial information. Our article on non-compete undertakings under Turkish law, which addresses the obligations arising on employee exit, our analysis of protecting trade secrets and know-how under Turkish law, which concerns the detection and protection of information leaks, and our article on unfair competition under Turkish law, which examines breaches occurring through employee transfers, address the matters connected with this decision.
For advisory services on the preparation of workplace communication monitoring policies, the updating of privacy notices, the structuring of internal investigation processes and data protection compliance work, you may contact us at info@guzeloglu.legal.