The Personal Data Protection Authority Published a Practical Guide on Lawyers’ Professional Activities
The “Practical Guide on the Protection of Personal Data in the Professional Activities of Attorneys”, prepared by the Personal Data Protection Authority with input and contributions from the Union of Turkish Bar Associations, was published on the Authority’s official website on September 22, 2026. The Guide addresses the legal status of attorneys, appointed attorneys, attorney staff, and relevant individuals under Law No. 6698; the legal basis and conditions for personal data processing activities carried out by attorneys; the transfer of personal data within the country and abroad; the use of generative artificial intelligence tools; general principles; the obligations of the data controller; and data security issues; It also provides solutions to problems encountered in practice and examples of best practices.
The two most significant findings of the Guide from a practical standpoint are that the personal data processing activities conducted by attorneys within the scope of their professional duties do not fall under the full exemption provided for in Article 28 of the Law and that the VERBIS registration exemption granted to attorneys does not constitute an exemption from the Law. The Guide directly addresses these two misconceptions frequently encountered in practice.
Scope of the Guide
The Guide applies to lawyers practicing independently under the Lawyers’ Act, lawyers working together in the same law firm, and law firms. Personal data processing activities within this scope are not limited to clients but also include data pertaining to potential clients, debtors and defendants involved in a dispute, witnesses, and other third parties connected to the matter; it covers the entire process from the receipt of a request for legal assistance to the closure of the case and the end of retention periods.
The Guide is advisory in nature. However, the fact that its content is largely based on Board decisions lends the Guide practical significance in demonstrating the approach adopted by the Board in applications and complaints filed against attorneys.
Key Findings in the Guide
· Lawyers’ professional data processing activities do not fall under the full exemption provided for in Article 28 of the Law. The application of the exemption requires the simultaneous fulfillment of two conditions: the processing must relate to investigative, prosecutorial, judicial, or enforcement proceedings, and it must be carried out by a judicial authority or an enforcement authority. The Guide explicitly states, with reference to the Board’s Decision No. 2020/26 dated January 14, 2020, that lawyers are not considered judicial authorities in this sense and that their professional activities cannot benefit from this exception.
· As a general rule, a lawyer is the data controller; in exceptional cases, they may be considered a data processor. Because their independence prevails and they determine the purposes and means of data processing, lawyers are generally considered data controllers. Conversely, it is stated—with reference to the Board’s Decisions No. 2021/115 and 2023/78—that a lawyer may qualify as a data processor in cases where they act within the framework of the client’s explicit, detailed, and specific instructions and have no control over the purposes or means of the processing.
· In a law firm, the data controller is the firm’s legal entity. In activities conducted under a power of attorney issued on behalf of the firm, the firm is the data controller, and the individual attorneys within the firm cannot be considered separate data controllers. However, for attorneys working together in the same office, since there is no legal entity, each attorney is an independent natural person acting as a data controller with respect to activities concerning their own clients. In the Board’s decision dated March 22, 2023, No. 2023/437, it was emphasized that the mere inclusion of the term “data processor” in a contract is not, by itself, determinative.
· When the attorney acting on behalf of another attorney exceeds the scope of the instructions, they become the data controller. While a lawyer acting within the scope of the instructing lawyer’s instructions is considered a data processor, if the lawyer processes personal data for a different purpose by going beyond those instructions, exercises independent authority to determine the purposes and means of processing, or evaluates the data separately within the scope of their own professional activities, they will be deemed a data controller with respect to that processing activity.
· Attorneys employed by a firm, law clerks, and support staff do not hold a separate legal status. Since the employer attorney determines the purposes and means of the processing activities carried out by an employed (staff) attorney, such activities are deemed to have been performed by the employer attorney; these individuals do not qualify as either data controllers or data processors. However, if a salaried attorney takes on their own cases under mandatory defense obligations independently of the attorney or law firm with whom they work, they will be considered a data controller with respect to those activities.
· The VERBIS exemption does not imply an exemption from the Law. The exception granted to attorneys by the Board’s Decision No. 2018/32 dated April 2, 2018, pertains solely to the obligation to register with and report to the Data Controllers Registry. Obligations regarding information provision, data security, retention and destruction, responding to requests, and compliance with general principles remain in full force. The Guide also notes that this exemption has led to the mistaken belief in practice that “lawyers have no obligations under the Law.”
· The primary legal basis is the establishment, exercise, or protection of a right; explicit consent should not be obtained unnecessarily. The processing of data belonging to third parties directly related to the subject matter of a lawsuit or legal proceeding is generally based on Article 5, paragraph 2(e) of the Law. The Guide explicitly states that in cases where processing is based on a condition other than explicit consent, seeking the data subject’s explicit consent would not be legally appropriate.
· The scope of “relevant individuals” is not limited to the client. The Guide lists not only the client and potential clients but also the opposing party and its employees, the client’s spouse and other family members, witnesses, third parties to whom a notice of attachment has been sent, and individuals working alongside the attorney as “relevant individuals.” If data belonging to a legal entity identifies or makes any natural person identifiable, such data also falls within the scope of the Law.
· Article 2 of the Attorney’s Law does not grant unlimited access authority. Pursuant to the aforementioned article, the provision of information and documents to a lawyer by institutions and organizations constitutes a transfer of data; accordingly, in accordance with the decision of the 1st Chamber of the Council of State dated April 10, 2002, No. 2002/26 E., 2002/52 K., the lawyer must justify their request. In the Board’s Decision No. 2021/1111 dated November 2, 2021, it was stated that Article 2 of the Attorney’s Act constitutes a general provision in relation to Article 7 of the Criminal Records Act and does not grant attorneys the authority to access criminal records ex officio; consequently, an administrative fine was imposed.
· Obtaining data from publicly available sources is lawful only to the extent that it serves the purpose of disclosure. While data obtained from publicly accessible social media accounts, websites, or the Commercial Registry Gazette may be based on the condition of disclosure, the data may not be used for any purpose other than disclosure, and processing must still be limited to the extent required by the legal process.
· The use of unlawful search software is prohibited. Pursuant to the Board’s Principle Decision No. 2019/308 dated October 18, 2019, querying identity and contact information through such software, programs, or applications constitutes a violation of Article 12 of the Law; this is subject to administrative sanctions as well as mandatory reporting to the Public Prosecutor’s Offices. In the Board’s decisions No. 2020/429 dated May 28, 2020, and No. 2021/228 dated March 11, 2021, administrative fines were imposed on attorneys who processed communication data whose method of acquisition could not be verified.
· The retention obligation may limit requests for deletion. Pursuant to Article 39 of the Lawyers’ Act, a lawyer is obligated to retain documents entrusted to them for a period of three years following the termination of the attorney-client relationship; if the client has been notified in writing that the documents have been retrieved, this period ends three months after such notification. The Guide states that in the event of a full or partial rejection of a request for deletion or destruction, the grounds for the rejection, the basis for the retention obligation, and the retention period must be clearly communicated to the data subject.
· A tiered system is applied for cross-border transfers. Pursuant to Article 9, as amended by Law No. 7499, an adequacy decision is first required; if no adequacy decision exists, one of the appropriate safeguards (an agreement not constituting an international treaty, binding corporate rules, a standard contract, or a letter of commitment) must be relied upon; and if none of these can be provided, the cases listed in the article may be invoked only on an ad hoc basis. The Authority must be notified within five business days of the signing of the standard contract.
· Uploading files to generative AI tools may constitute data transfer. Uploading client files, case documents, or documents containing personal data to generative AI tools may constitute a transfer abroad under Article 9 of the Law, taking into account the country where the service provider is domiciled, the location of the servers, and the location of sub-service providers. Even in cases where the service provider is domiciled within the country, the activity may be considered a domestic transfer under Article 8. The Guide emphasizes that this use should not be evaluated as “merely obtaining technical support or conducting legal research.”
· It is of critical importance to be able to verify the source from which personal data was obtained. The Guide notes that the majority of complaints filed with the Authority regarding attorneys focus on how the data was obtained; however, attorneys are often unable to meet these requests and cannot verify the source from which they obtained the data. Requests from data subjects must be resolved free of charge within thirty days at the latest, in accordance with Article 13 of the Law and the Communiqué on the Procedures and Principles for Applications to the Data Controller.
· A data security breach entails both the risk of administrative sanctions and compensation claims. Violation of the obligations under Article 12 of the Law is subject to an administrative fine pursuant to Article 18; The Guidelines specify the statutory range for such violations as between 15,000 TL and 1,000,000 TL, and note that these amounts are increased annually at the revaluation rate specified in Article 17 of the Offenses Act No. 5326. Furthermore, obligations regarding data security constitute ancillary obligations under the attorney-client agreement and may give rise to a claim for damages in the event of a breach.
· A 72-hour deadline applies for reporting a data breach to the Board. Pursuant to the Board’s Decision No. 2019/10 dated January 24, 2019, the phrase “as soon as possible” in the fifth paragraph of Article 12 of the Act is interpreted as 72 hours; affected data subjects must be notified within the shortest reasonable time. The Guide lists physical circumstances, such as the loss of a file upon return from court, among the examples that may require reporting a breach.
· Keeping contact channels up to date is part of the compliance obligation. The Guide states that, to ensure data subject requests are resolved in a timely and effective manner, the contact information listed on the law firm or partnership’s website—or, in cases where no website exists, the contact information on the bar association’s roster—must be kept up to date.
· Information must be provided in stages, beginning at the point of contact. The best practice example in the guide recommends that during the initial phone call, basic information regarding the data controller’s identity, the purpose of processing, and data subject rights be provided; prior to a face-to-face meeting, a detailed written information notice should be presented, and at this stage, only the minimum data necessary for scheduling the appointment should be processed.
Recommended Steps
· It should be determined in writing within the law firm or partnership which party holds the status of data controller for which activities (the partnership as a legal entity, an independent attorney, the instructing attorney, or the retained attorney); in agency relationships, the scope and limits of the instructions given should be clarified via a letter of authorization or separate correspondence.
· Preparing separate privacy notices for clients, potential clients, opposing parties, and other third parties; providing information in stages starting from the first point of contact; and complying with the timeframes set forth in Article 6 of the Privacy Notice in cases where personal data is not obtained directly from the data subject.
· Recording the source from which personal data processed in each case was obtained; establishing a request management process to ensure that data subject requests are resolved within thirty days, and designating a person within the firm responsible for this process.
· A retention and disposal policy must be established by taking into account both the three-year period specified in Article 39 of the Attorney’s Act and other retention obligations arising from legislation; in the event of a refusal to comply with requests for erasure or destruction, the grounds for the refusal and the retention period must be communicated to the data subject in writing.
· Establishing written rules regarding the use of generative AI tools within the firm; reviewing the policies of the tools used regarding data retention, model training, human review, sub-processors, and server location; ensuring data is masked or anonymized to the greatest extent possible; and refraining from uploading special-category personal data to these systems.
· Given that the processing of special-category personal data is highly likely in the course of legal practice, implementing the adequate safeguards set forth in Board Decision No. 2018/10 dated January 31, 2018; taking simple yet effective measures regarding the physical security of files, such as ensuring that information regarding the parties and the type of case is not visibly displayed on file covers.