KVKK principle decision: owning the corporate email account does not give employers an unlimited right to monitor staff communications
Türkiye's Personal Data Protection Board adopted principle decision 2026/2035 on September 16, 2026, and it was published in Official Gazette issue 33394 on October 8, 2026. It sets out when employers may monitor the corporate email accounts and other work channels they give to staff: owning the tool does not mean unlimited authority, and a generic warning is not enough.
A principle decision born from complaints reaches the Official Gazette
The Board (Kurul) took the decision on September 16, 2026. The text ran in Official Gazette issue 33394 on Thursday, October 8, 2026 under the Board Decision heading, and the Personal Data Protection Authority (KVKK) posted an announcement on its website dated the same day. The legal basis is Article 15(6) of Law No. 6698, which lets the Board adopt and publish a principle decision when a complaint or an own-initiative review shows a violation is widespread. The decision was adopted by majority vote.
KVKK's announcement describes what led to it. Reviewing complaints and tip-offs, the Board found that channels assigned to employees, corporate email in particular, were being monitored: message contents were read, traffic and log records examined, filtering or routine checks run, and the resulting data used in disciplinary proceedings or to end employment contracts. Employees, meanwhile, had not been told about any of this in an adequate, clear and concrete way. According to the Gazette text the scope goes beyond email. Depending on the case, internal messaging apps, corporate instant messaging accounts, customer relationship and request management systems, and the chat and recording areas of meeting platforms can all count as work communication channels.
Logs are personal data, and technical access is not legal authority
The starting point is that an employer who never opens a message but processes only traffic and log records is already processing personal data. Every form of email monitoring is therefore bound by the general principles in Article 4 of the Law, the processing conditions in Articles 5 and 6, the information duty in Article 10 and the data security duty in Article 12. KVKK states that the tool belonging to the employer, or being used at the workplace, does not hand the employer unlimited oversight of how staff communicate. When setting the scope of monitoring, business use and private use have to be told apart; where they cannot be separated, the employer's authority must be read more narrowly. Holding technical rights over a device, session, network or corporate system does not entitle the employer to browse an employee's personal email, personal messaging app or social media message box. In KVKK's framing, being technically able to access something and being legally allowed to are two separate questions.
The bar for notice rises as well. Simply telling staff that the employer may monitor the account does not discharge the Article 10 information obligation. The notice has to set out, clearly and concretely, the legal basis, the purpose and scope, whether monitoring works through log review or content review, the circumstances in which content may be opened, the retention period, and the employee's rights under Article 11. On consent the decision is firm: because of dependence and the power imbalance in employment, an employee's explicit consent should as a rule not serve as the primary basis for email monitoring. Depending on the facts, the employer may instead rely on sub-paragraphs (ç), (e) and (f) of Article 5(2), covering legal obligation, establishing, exercising or protecting a right, and legitimate interest. None of these grounds grants unlimited authority either.
Monitoring has to be graduated, and covert surveillance is out
The decision treats monitoring as a ladder. If a lighter method achieves the legitimate aim, the employer may not climb to a heavier one, and opening content only comes into play in exceptional cases where traffic data review has fallen short. If misuse of work tools can be stopped technically, for example through filtering or blocking, no general monitoring right arises. Content review must stay tied to a concrete suspicion and limited to that allegation, avoiding open-ended, blanket or continuous sweeps. Employers also have to allow for special category data in message bodies or attachments, and for the personal data of the people on the other side of the conversation. Monitoring through covert methods the employee was never told about, or through tools that record everything the employee does without distinction, will be treated as unlawful.
Access and departures get written rules too. Only a limited number of staff specifically assigned to the task should reach the collected data, their permissions should follow from their job descriptions, access should be logged and those with access should be under a confidentiality obligation. When employment ends, the account should as a rule be taken out of active use and closed to new access, incoming mail should not be visible to unrelated people, and data with no remaining legal basis should be destroyed. For business continuity, defence in a legal dispute or statutory duties, limited and time-bound arrangements such as forwarding, an auto-reply, archiving or retention can be assessed case by case, provided access rights are defined and the arrangement is recorded. Where the Board finds these obligations unmet, administrative action will follow under Article 18 of the Law.
What the decision means in practice for employers in Türkiye
This is a Türkiye story at its core: a Board principle decision under Article 15(6) of Law No. 6698, addressed to employers who, as data controllers, monitor employee communications. In its reasoning the Board relies on Articles 20 and 22 of the Turkish Constitution and on case law from the Constitutional Court and the European Court of Human Rights. That case law ties the legitimacy of monitoring to clear prior notice, a legitimate aim, a limited and proportionate approach and a preference for less intrusive means, and it stresses that looking at content needs a stronger justification than looking at traffic data.
A to-do list read off the decision itself (this part is UNALSOFT commentary, not legal advice; talk to your lawyer or data protection adviser about your own situation): existing generic notices that only say the mailbox may be checked should be rewritten around the elements the decision lists; a private-use rule should be set out clearly enough for staff to know it; a graduated procedure separating log monitoring from content review, including when content may be opened, should be put in writing; the people who may access the data, the access log and confidentiality undertakings should be pinned down; and closing, forwarding and deletion steps for a departing employee's account should be defined. The decision itself sets no separate transition period and names no fine amount. We covered the volume of applications and complaints reaching KVKK on October 4.
UNALSOFT's take
For us the most concrete part of the decision is its list of channels: internal messaging, customer relationship and request management systems, chat areas on meeting platforms. Any setup that drops enquiries from your website's contact form into a panel or a shared inbox is also a place where employee correspondence piles up. That is why, on web design projects, we suggest settling at build time which inbox a form feeds, who can reach it and whether that access is logged. We also think AI assistants or agents that read company email deserve a review against the same logic of proportionality and record-keeping; that last point is our assessment, not something the decision says.
Are the systems where staff correspondence collects ready for this decision?
A short conversation is enough to review your form flows, panel access and where your privacy notices sit on the site.