KVKK has received 72,500 applications since 2017 and concluded about 69,000
The chairman of Türkiye's Personal Data Protection Authority (KVKK), Prof. Dr. Faruk Bilir, says the authority has taken in 72,500 data protection applications since 2017, counting those routed through the CİMER public complaints channel, and has concluded roughly 69,000. He described examinations as the authority's most important duty, with sanctions and administrative fines as possible outcomes.
The authority's chairman shared a running total
Bilir spoke to an Anadolu Agency (AA) reporter at TEKNOFEST, held at Şanlıurfa GAP Airport. In AA's report of October 4, 2026, bylined Beyza Nur Eryılmaz and Okan Coşkun, he said that since 2017 the authority has been receiving and handling citizens' applications about the protection of their personal data. The total he gave was 72,500, a figure that includes applications forwarded via CİMER.
Of those, he said, around 69,000 have been concluded. ekonomim.com ran the same story the same day and credited AA, so both records trace back to a single agency report rather than two independent confirmations. The statement does not announce a new regulation or policy change. It summarises the workload to date and what the authority does.
Examinations, sanctions, guides and awareness work
Among the many duties the law assigns to the authority, Bilir singled out examinations as the most important. He said applications arrive as complaints or tip-offs, and examinations follow from them. Where an examination warrants it, the authority imposes sanctions and administrative fines. He also stressed that protection of personal data is a fundamental right set out in Türkiye's Constitution.
The second big strand is information and awareness. According to Bilir, the authority writes guides explaining how the law applies to particular sectors, and the latest ones are for lawyers and for diagnostic laboratories. We looked at the lawyers' guide in a separate piece on September 22. The authority also runs seminars, conferences and meetings for the public, along with digital literacy work aimed at children.
The right to complain is being used
A figure above 72,000 shows that people in Türkiye actively use their personal data rights. In the process Bilir describes, a single complaint or tip-off can become an examination, and an examination can end in a sanction or an administrative fine. For any business acting as a data controller, exposure does not only come from a large breach; one individual's application is enough to start the process.
It is also worth being clear about what the numbers leave out. The report gives no total or count of administrative fines, no breakdown of applications by year or sector, and no indication of how many concluded files ended with a violation finding. So the 72,500 figure cannot tell you how often fines are issued or which sectors carry more risk. It describes overall volume.
A Türkiye story, with our commentary marked separately
This is a domestic story. The facts from the sources are these: KVKK has received 72,500 applications since 2017, CİMER included, and concluded about 69,000; its most recent sector guides cover lawyers and diagnostic laboratories; and the statement was made at TEKNOFEST in Şanlıurfa.
What follows is UNALSOFT commentary. For small and mid-sized businesses that collect customer data through website forms, booking systems, newsletter sign-ups or ad tracking tags, this points to a practical risk-management task: keep the privacy notice current, make sure cookie consent actually works, and have an internal process for answering a person's request about their data. The unknowns, listed one by one: fine amounts, the sector breakdown of applications, the share of files that ended with a violation finding, and the number of data breach notifications are not part of this statement.
The UNALSOFT view
We read this less as an alarm and more as a reminder about the technical hygiene of business websites. Personal data is often collected on a site without anyone noticing: a contact form, a WhatsApp button, analytics and advertising tags. That is why, in web design projects, we treat the privacy notice, the cookie preference screen and a clear map of which form sends which data where as part of building the site itself. This article is not legal advice; specific obligations call for a legal adviser.
Do you know what data your website collects?
A short call is enough to review your forms, cookie screen and privacy notice side by side.