Bizimle İletişime Geçin
Ana Sayfa/Yayınlar & İçgörüler/Duyurular/Issue No. 12 of the Personal Data Protection Authority Bulletin Has Been Published: Smart Devices and Digital Privacy
Duyurular

Issue No. 12 of the Personal Data Protection Authority Bulletin Has Been Published: Smart Devices and Digital Privacy

29.09.2026
Issue No. 12 Of The Personal Data Protection Authority Bulletin Has Been Published: Smart Devices And Digital Privacy | Metin–Çiçek Avukatlık Ortaklığı · Attorney Partnership

The Personal Data Protection Authority has published the 12th issue of the KVKK Bulletin covering the period from May to September 2026. The theme of this issue is “Smart Devices and Digital Privacy,” and the Bulletin covers: the concept of digital privacy, a privacy-by-design approach, the Internet of Things, data generated by smart devices and AI-powered inferences, ten golden rules for smart device users, recommendations regarding the use of mobile applications and smart glasses, and children’s digital privacy. The Bulletin also compiles national and international regulatory developments from May to September 2026.

While the Bulletin is primarily awareness-focused and aimed at individuals, it also contains a clear message for data controllers: The protection of personal data cannot be left to measures taken after a product or service has been made available. The Authority emphasizes that it is not sustainable to build a culture of privacy by having an app request as much data as possible from the user and then expecting the user to be mindful of this.

 

Scope of the Bulletin

The Bulletin covers a wide range of devices, from smartphones to wearable technologies, and from smart home systems to connected vehicles. The central finding is that the information revealed about an individual is no longer limited solely to the information they choose to share. When data regarding the time spent on a website, locations visited, apps used, or a device’s usage patterns is evaluated alongside other data obtained at different times and from different sources, it can form a profile of the individual’s behaviors, preferences, and habits.

In this context, the Bulletin notes that in the digital age, the question of privacy is not merely “what information am I sharing?” but also involves the increasingly important questions: “what information about me is being compiled?”, “what conclusions can be drawn from this information?”, and “how might these conclusions affect my life?” From the perspective of data controllers, the Bulletin emphasizes that the assessment should not be limited to the question “what personal data is being processed,” but must also consider the question “what information about an individual can be derived when this data is combined.”

 

Highlights from the Bulletin

  • Privacy starts with design. It is stated that the principles regarding the protection of personal data must be taken into account from the very beginning of the design and development processes of products, services, and systems. The bulletin states that protecting privacy requires the design of systems that request only as much data as necessary, explain why the data is requested in a clear manner, and offer users a genuine choice.
  • Data security is a key concern in Internet of Things (IoT) applications. It is emphasized that the intense data flow in Internet of Things systems may contain personal data, including special-category personal data; and that taking technical and administrative measures to protect the integrity, confidentiality, and availability of data is of particular importance in terms of the obligations under Article 12 of Law No. 6698.
  • AI-powered inferences can go beyond personalization. The use of AI-based functions in smart devices and connected services enhances the capacity to analyze data and draw inferences from it. The bulletin notes that inferences can also be made about a person’s characteristics, preferences, or behaviors that they have not directly shared, and reminds readers that processed data must be relevant to the purpose, limited, and proportionate, and that the processing of unnecessary data must be avoided.
  • Ten golden rules have been established for smart device users. These include finding out what data the device processes, not granting unnecessary permissions, regularly reviewing privacy settings, using strong and unique passwords along with multi-factor authentication, installing updates promptly, deleting unused apps and accounts, controlling data sharing between devices, and erasing data and restoring the device to factory settings before disposing of it are listed.
  • Separate recommendations are provided regarding mobile apps. It is recommended to download apps from official app stores, verify the authenticity of the developer and app name, review the privacy policy and the permissions requested, be cautious of apps that request constant access to data such as location, audio, and video, and check what information will be shared when logging in with a social media account.
  • Smart glasses and children’s digital privacy are addressed under separate headings. The Bulletin reprints the information on smart glasses previously published by the agency. With regard to children, the Bulletin emphasizes that posts made by parents on behalf of their children can contribute to the formation of a digital identity that the child has not yet established themselves; it recommends adopting an inquiry- and responsibility-centered approach rather than one focused on fear and prohibition.

 

Notable Regulatory Developments

  • The ICO’s final guidance on Internet of Things (IoT) products for consumers provides direction to manufacturers and developers. The guidance explains how to obtain consent and ensure transparency; it recommends safeguarding privacy from the design phase onward, offering privacy-protective settings as the default, limiting data collection to only what is strictly necessary, conducting a data protection impact assessment, and maintaining security measures throughout the product’s lifecycle.
  • The EDPB’s guidelines on web scraping in the context of generative AI and anonymization are open for public comment. Comments on both guidelines may be submitted until October 30, 2026. The document on web scraping addresses the definition of the activity, the determination of roles and responsibilities under the GDPR, processing principles, legal basis, and the processing of special categories of personal data. The EDPB has also published the final version of its guidelines on the processing of personal data via blockchain technologies.
  • The EDPS highlights the risk of “shadow AI.” It notes that employees’ use of AI tools without the organization’s approval could render data protection and security measures ineffective; which could lead to personal data breaches, non-compliance with regulatory requirements, and operational disruptions. It is therefore recommended that AI governance policies be established, approved and legally compliant platforms be provided, and technical control and monitoring mechanisms be implemented.
  • CNIL’s guidance on employee monitoring and electronic commercial communications stands out. It is emphasized that employers have the authority to monitor employees’ activities and the use of work equipment within the scope of their managerial authority; however, this authority must be exercised in a proportionate, justified manner that respects employees’ rights and freedoms. CNIL has also published guidance on defining the roles and responsibilities of actors in the cloud computing sector.
  • Smart glasses are on the agenda of multiple authorities. The CNIL announced the launch of an action plan on the subject, warning users to inform those around them and to disable recording functions when no longer needed; the AEPD shared best practices regarding the use of smart sunglasses; and the CNPD published a document addressing potential obligations for manufacturers, suppliers, and professional users.
  • The European Commission’s common approach to age verification technologies is taking center stage. The recommendation, which is said to pave the way for access to tools based on anonymous age verification technologies, aims to ensure that EU citizens have access to privacy-preserving age verification tools by December 31, 2026. The European Parliament’s Research Service has also addressed the issue of setting a minimum age limit for children’s access to social media.
  • A joint initiative is being launched to address the intersection of competition law and data protection law. It has been announced that European Commission units and the EDPB will conduct a joint study focusing on selected cases to develop a consistent approach between the two areas.
  • AI compliance is on the agenda in terms of oversight and liability. The Hong Kong Privacy Commissioner for Personal Data (PCPD) has published the findings of compliance audits it conducted at 60 organizations regarding the impact of AI use on the privacy of personal data. Singapore’s regulatory authority (IMDA), meanwhile, has published a document opening the discussion on legal liability in the context of AI intermediaries through fault-based and strict liability models.
  • The national agenda on AI and data protection is dynamic. Turkey’s AI Action Plan (2026–2030) has entered into force; the Medium-Term Program (2027–2029) projects that the harmonization of Law No. 6698 with the GDPR will be completed in the third quarter of 2027; the Ministry of Justice has announced the UYAP AI Decision Support System; and the Ministry of National Education has sent a ten-point memo to all provinces regarding measures to be taken under the framework of personal data protection.

 

Recommended Steps

  • Adopting a privacy-by-design approach in product and service development processes from the outset; configuring default settings to protect users, limiting requested permissions to the necessary functions, and explaining the rationale for permission requests to users in an understandable manner.
  • Creating an inventory of smart devices (including wearables, smart glasses, connected vehicles, and smart office systems) assigned to employees by the company or permitted for use in the workplace; identifying the legal basis, retention period, and recipients of location, audio, video, and usage data processed through these devices.
  • Create a list of approved AI tools to mitigate the risk of “shadow AI”; implement technical controls and monitoring mechanisms to restrict employees from using such tools without organizational approval; and provide awareness training on the subject.
  • Re-evaluating employee monitoring activities in terms of proportionality and necessity, and documenting the rationale in writing; informing employees about these activities and the methods used.
  • For organizations offering mobile applications or connected products, reviewing app permissions, privacy policies, and data flows occurring through third-party software development kits.