Back to Insights

Turkish Personal Data Protection Board’s New Principle Decision on Workplace Communication Monitoring

The Turkish Personal Data Protection Board clarified the limits applicable to employers’ monitoring of corporate e-mail accounts and other communication channels through its Principle Decision No. 2026/2035. The Board emphasized that employees must be informed in advance, monitoring must be limited to specific, legitimate, and proportionate purposes, less intrusive methods should be preferred, and the content of communications should be reviewed only where necessary. Employers should therefore review their existing policies, privacy notices, and access procedures in line with the Principle Decision.

08.10.2026

Turkish Personal Data Protection Board’s New Principle Decision on Workplace Communication Monitoring

Introduction

The Principle Decision dated 16 September 2026 and numbered 2026/2035 (“Principle Decision”), issued by the Turkish Personal Data Protection Board (“Board”), was published in the Official Gazette on 8 October 2026. The Principle Decision sets out the fundamental procedures and principles that employers must comply with when monitoring communication channels used for the performance of work, particularly corporate e-mail accounts allocated to employees.

The Board emphasizes that such monitoring activities must be carried out by striking a fair balance between, on the one hand, the employer’s powers arising from the employment contract and its managerial authority and, on the other hand, the employee’s right to respect for private life, right to request the protection of personal data, and freedom of communication.

Key Provisions

While the Board does not prohibit employers from monitoring corporate communication channels altogether, it expressly establishes that the mere fact that a communication tool belongs to the employer or is used in the workplace does not grant the employer an unrestricted right to monitor it.

In this context:

  • A distinction must be made between business and personal use. When determining the scope of monitoring, the purpose for which the communication tool was provided and the applicable rules governing its use must be taken into account. Even where personal use is prohibited, the employer’s monitoring authority remains subject to the principle of proportionality.
  • Employees must be informed in advance of the monitoring. The legal ground, purpose, scope, and method of the monitoring; the circumstances in which communication content may be accessed; the applicable retention period; and employees’ rights under the Personal Data Protection Law (“PDPL”) must be set out in a clear, comprehensible, and specific manner. A general notification merely stating that a corporate e-mail account may be monitored may not be sufficient.
  • Technical access capability must be distinguished from legal authority to access. The fact that an employer has the technical ability to access a device, session, network, or corporate system does not mean that it may freely access content contained in an employee’s personal e-mail account, personal messaging application, or social media account.
  • Explicit consent is not necessarily the primary legal basis in all circumstances. Given the relationship of dependency inherent in employment and the imbalance of power between the parties, an employee’s explicit consent cannot, in every case, be regarded as the primary legal basis for e-mail monitoring. Where processing is based on explicit consent, it must also be assessed whether such consent has been freely given.
  • Monitoring must be limited to specific, explicit, and legitimate purposes. Monitoring activities must be carried out lawfully and fairly and must be relevant, limited, and proportionate to their purpose. Personal data obtained through monitoring must not be retained for longer than is necessary for the purpose for which they are processed.
  • A graduated approach to monitoring must be adopted. Where the employer’s legitimate objective can be achieved through a less intrusive method, a more intrusive monitoring measure should not be used.
  • Review of communication content must be exceptional and limited. As a rule, the content of correspondence should only be reviewed where there is a concrete suspicion or a legitimate purpose linked to a specific incident, and any such review must be limited to what is necessary for the purpose of the monitoring. Broad, indiscriminate, or continuous review of communication content should be avoided.
  • Special categories of personal data and third-party data must be taken into account. Employers must consider that content monitoring may involve the processing not only of employees’ personal data, but also personal data relating to the other party to the communication or other third parties, as well as special categories of personal data.
  • Access rights must be restricted. Access to data obtained as a result of monitoring must be limited to a restricted number of personnel who have been specifically assigned the relevant duties and authorization. Access logs must be maintained, and appropriate technical and organizational measures must be implemented.

What Happens When the Employment Relationship Ends?

The Principle Decision also contains an important assessment concerning the period following termination of the employment relationship. The legal basis for processing a corporate e-mail account allocated to an employee, as well as any data obtained or retained in connection with that account, must be separately assessed after the employment relationship has ended. The termination of the employment relationship does not mean that the relevant data may remain accessible or continue to be processed indefinitely.

Who Is Affected?

The Principle Decision is particularly relevant to data controller employers that provide their employees with corporate e-mail accounts or other communication channels used for the performance of work. Accordingly, existing practices concerning the monitoring of employees’ corporate communication tools, access to the content of correspondence, review of traffic and log data, or similar monitoring activities should be reassessed in light of the Principle Decision.

What Should Companies Do?

It is important for employers to review their existing practices and internal rules in light of the Principle Decision. In this context, companies should:

  • Review their policies and procedures governing the use of corporate communication tools and update them where necessary;
  • Clearly and comprehensibly define the rules applicable to business and personal use;
  • Review employee privacy notices with regard to the legal ground, purpose, scope, and method of monitoring, the circumstances in which communication content may be accessed, and the applicable retention periods;
  • Establish a graduated monitoring mechanism under which it is first assessed whether less intrusive methods would be sufficient to achieve the relevant purpose;
  • Establish procedures ensuring that communication content is reviewed only where there is a concrete need and a legitimate purpose;
  • Implement authorization and control mechanisms to ensure that technical access capabilities are not treated as constituting legal authority to access data;
  • Restrict access to data obtained through monitoring to a limited number of duly authorized personnel and maintain access logs; and
  • Separately review retention and access processes concerning the corporate e-mail accounts of former employees and the data contained in those accounts.

Where non-compliance with the obligations set out in the Principle Decision is identified, the Board may conduct the necessary examination and assessment in light of the circumstances of the specific case and may take action against the relevant data controllers pursuant to Article 18 of the PDPL.

Conclusion

The Principle Decision makes clear that the fact that corporate communication tools belong to the employer does not mean that communications conducted through those tools may be monitored without limitation. Employers should therefore assess not only their policies and privacy notices, but also their actual monitoring methods, access authorizations, and technical infrastructure in accordance with the principles under the PDPL requiring personal data to be processed lawfully and fairly, for specific, explicit, and legitimate purposes, and in a manner that is relevant, limited, and proportionate to those purposes. In particular, when reviewing communication content, the existence of a concrete suspicion or a legitimate purpose linked to a specific incident, an assessment of whether less intrusive methods would be sufficient, and the prior provision of clear and specific information to employees regarding the scope of monitoring are of particular importance.

You can access the Principle Decision, which is only in Turkish, here.