Single Blog Title

This is a single blog caption

Protection of Employees' Personal Data and Employer's Responsibility

Entrance

The protection of employees' personal data is one of the most important areas of intersection between labor law and personal data protection law. Employers process a wide range of personal data belonging to employees, starting with the candidate before the employment relationship is established, throughout the employment contract, and even after the employment relationship ends. Identity information, contact information, personnel files, salary and bank information, social security records, health reports, criminal record information, camera footage, vehicle tracking records, email correspondence, performance evaluations, disciplinary records, payrolls, leave forms, workplace accident records, and biometric data may fall within this scope.

Therefore, it is often unavoidable for employers to process employee data. However, this does not give employers unlimited data processing authority. Employers may only process data in a proportionate and limited manner for lawful purposes such as establishing and maintaining employment relationships, fulfilling legal obligations, occupational health and safety, payroll and personnel processes, workplace safety, proving claims, and the legitimate interests of the business.

According to the Personal Data Protection Authority, any operation performed on personal data, such as obtaining, recording, storing, preserving, modifying, disclosing, transferring, making accessible, or preventing its use, is considered a personal data processing activity. Therefore, an employer keeping personnel records for an employee, recording camera footage, opening an email account, or preparing payroll records are all personal data processing activities.

What is Employee Personal Data?

Employee personal data is any information that identifies or makes an employee identifiable. This scope is not limited to name, surname, and Turkish Republic identity number. An employee's address, telephone number, email address, bank account information, salary information, marital status, information about children, social security registration number, signature, photograph, camera footage, entry and exit times, leave records, performance scores, disciplinary records, work accident documents, health reports, disability information, union membership, criminal conviction information, biometric data, and user activity in corporate systems may also be considered personal data.

According to Article 6 of the Turkish Personal Data Protection Law (KVKK), health data, biometric and genetic data, trade union membership data, criminal conviction data, and data related to security measures are considered special categories of personal data. Stricter legal requirements and stronger security measures are needed when processing this data.

The processing of employee data by an employer is often necessary due to the nature of the employment relationship. For example, identity and employment information may be processed for social security declarations, bank account information for salary payments, certain health information for occupational health and safety, and leave records for tracking annual leave. However, data that is "necessary" should be distinguished from data collected out of "interest" or "may be needed in the future." In accordance with the fundamental principles of the Personal Data Protection Law (KVKK), employee data must be processed in a manner that is relevant to the purpose, limited, and proportionate.

Is the employer the data controller?

In most cases, the employer acts as the data controller, as they determine the purposes and means of processing employees' personal data. The employer decides which personnel data will be collected, in which system this data will be stored, which departments will have access to it, and which data will be shared with accounting firms, social security institutions, payroll companies, occupational health and safety firms, banks, lawyers, auditors, or public institutions.

Therefore, the employer's obligations under the Personal Data Protection Law (KVKK) are not limited to "obtaining explicit consent from the employee." The employer must also inform the employee, correctly determine the legal basis, avoid collecting unnecessary data, protect sensitive personal data more strictly, restrict access rights, store employee data securely, enter into contracts with data processors, and make the necessary notifications in case of a data breach.

According to Article 12 of the KVKK (Law on Protection of Personal Data), the data controller is obliged to take the necessary technical and administrative measures to ensure an appropriate level of security to prevent the unlawful processing of personal data, to prevent unlawful access to personal data, and to ensure the preservation of personal data. Furthermore, if the data is processed on behalf of the data controller by another person or company, the data controller may be held jointly responsible with the data processor for taking the necessary measures.

Protecting Candidate Data During the Recruitment Process

Data protection for employees begins not after the employment contract is signed, but during the job application process. Employers may request resumes, contact information, educational background, previous work experience, references, certificates, foreign language skills, and professional qualification documents from job applicants. However, the information requested must be relevant and appropriate to the position applied for.

For example, requesting professional experience, education, and references from a candidate for an accounting position may be reasonable. However, requesting data unrelated to the position, such as family information, personal details, health information, political views, religious beliefs, or union membership, poses a legal risk. The employer's justification that "this is our standard form" does not legitimize the practice of collecting unnecessary data.

Candidates should also be informed during the job application process. The purpose for which candidate data is processed, with whom it will be shared, how long it will be stored, and the candidate's rights should be clearly stated. According to the Communiqué on the Obligation to Inform, the data controller must inform the data subject about the identity of the data controller, the purpose of processing, the recipient groups to whom the data will be transferred, the collection method, the legal basis, and the data subject's rights when collecting personal data.

Data of candidates whose job applications were unsuccessful cannot be stored indefinitely. If the employer wishes to retain this data in a candidate pool for future suitable positions, they must clearly inform the candidate and evaluate the legal basis for this. Archiving resumes indefinitely without the candidate's consent or without specifying a reasonable retention period is problematic under the Personal Data Protection Law (KVKK).

Personnel File and Personnel Records

Maintaining a personnel file for an employee is a requirement of labor law. However, the personnel file should only contain necessary documents; unnecessary and excessive data should not be collected. Documents that can be included in a personnel file include: employment contract, identity information, social security registration form, payroll, leave records, disciplinary reports, training documents, health reports, occupational health and safety documents, wage and bank information.

However, access to personnel files should be restricted. Not every manager, every HR employee, or every department employee should have access to all personnel files. Documents containing salary information, health reports, disciplinary records, or sensitive personal data should only be viewed by those who need to access them as part of their duties.

If personnel files are stored electronically, secure access, passwords, authorization matrices, log recording, backup, and encryption measures must be implemented. Physical files should be stored in locked cabinets or areas with restricted access. It is not sufficient for the employer to simply say, "Personnel files are kept in human resources"; who accesses them, when they access them, and how the data is protected are crucial.

Employee Health Data

Employee health data is considered special category personal data. Examples include pre-employment health reports, periodic medical examination records, workplace accident reports, disability information, pregnancy information, occupational disease documents, medication reports, and sick leave documents. Such data must be specially protected as it can increase the risk of discrimination or harm to the employee.

The processing of health data by an employer may be mandatory in some cases in terms of occupational health and safety obligations. However, the processing, access, and storage of this data must be handled with much greater care. Health data should not be shared with all managers; it should be limited to only the occupational physician, authorized human resources officers, and those legally entitled to access it.

For example, emailing an employee's medical report to all team managers, sharing an employee's illness information in a group chat, or unnecessarily announcing a disability can all constitute a data breach. The employer can obtain the necessary information for work planning; however, they cannot share the details of the illness with the entire workplace.

Biometric Data, Fingerprint and Facial Recognition Systems

Fingerprint, facial recognition, retina scanning, or palm print systems can be used for tracking entry and exit in workplaces. However, since biometric data is considered special categories of personal data, employers must be very careful when using these systems. Article 6 of the Turkish Personal Data Protection Law (KVKK) classifies biometric and genetic data as special categories of personal data.

The fundamental issue in biometric data processing is proportionality. Employers have the right to track working hours or control workplace entry; however, this right does not necessarily require the use of fingerprint or facial recognition systems. If the same purpose can be achieved through less intrusive methods such as card access, passwords, employee cards, turnstile registration, or signatures, then biometric data processing may carry legal risks.

Therefore, before implementing a biometric system, employers should ask themselves these questions: Is this system truly necessary? Are there less intrusive alternatives? Has the employee been clearly informed? If explicit consent is required, was it given freely? Is biometric data stored as raw data or processed as template data? Is the data encrypted? Who has access to it? How long is the data stored? Is the biometric data of an employee who leaves the company immediately deleted?

Due to the power imbalance between employee and employer, whether explicit consent is given freely is always debatable. Therefore, obtaining only a signed explicit consent form should not be considered sufficient for biometric data processing; an analysis of necessity, proportionality, and alternative methods should also be conducted.

Workplace Camera Recording and Surveillance

Recording footage with cameras in the workplace constitutes the processing of employees' personal data. Camera footage is considered personal data because it makes the person's identity identifiable. Employers may use camera systems for legitimate purposes such as workplace safety, occupational health and safety, crime prevention, detection of workplace accidents, or business security. However, camera use is not unlimited.

In its announcement dated June 8, 2026, regarding the use of security cameras in workplaces, the Personal Data Protection Authority (KVKK) stated that camera systems can be used for purposes such as occupational health and safety, prevention of workplace accidents, monitoring working conditions, workplace security, and crime prevention; however, excessive and unauthorized use of cameras beyond the specified purposes may interfere with the privacy of private life and lead to the unlawful processing of personal data.

Therefore, the purpose of installing a camera system must be clearly defined. Using cameras in areas where privacy is highly valued, such as changing rooms, restrooms,休息 areas, prayer rooms, and breastfeeding rooms, generally carries significant legal risks. The camera angle should only cover the necessary area and should not be intended for continuous and intrusive monitoring of employees.

The employer must inform employees about the camera system. The purpose of the camera recordings, who has access to them, how long they will be stored, under what circumstances they may be shared with third parties, and employees' rights should be clearly stated. Camera recordings should not be stored for unnecessarily long periods, access rights should be restricted, and recordings should be securely stored.

Corporate Email and Computer Auditing

When an employer provides employees with corporate email accounts, computers, phones, vehicles, software accounts, or internal communication systems, discussions about personal data processing and communication privacy arise. The employer has a certain degree of control over employees to ensure the smooth running of operations, protect information security, monitor workplace discipline, and fulfill legal obligations. However, this control is not unlimited.

In the E.Ü. application to the Constitutional Court, it was ruled that the employee's right to protection of personal data and freedom of communication were violated due to the employer's examination of the employee's corporate email account. While the court acknowledged the employer's right to audit, it emphasized the need for the employee to be adequately informed beforehand, for the audit to serve a legitimate purpose, to be proportionate, and for an assessment to be made of whether the objective could be achieved through less drastic means.

In contrast, in the Celal Oraj Altunörgü case, the Constitutional Court ruled that the employment contract stipulated that the corporate email account would be used solely for business purposes and could be monitored by the employer; in this specific case, the employer's monitoring did not violate the right to protection of personal data and freedom of communication.

When these two decisions are considered together, the conclusion is this: Employers can monitor corporate email or computer systems; however, they cannot do so arbitrarily, without limits, secretly, or excessively. Employees must be clearly informed beforehand, a usage policy must be established, the purpose of the monitoring must be specific, only necessary data should be reviewed, and private correspondence should not be unnecessarily interfered with.

Performance Monitoring, GPS and Vehicle Tracking Systems

Employers can use digital tracking systems to evaluate employee performance or manage field activities. Examples include sales personnel location tracking, company vehicle GPS tracking, call center call recordings, production line performance records, computer usage reports, and activity logs in project management software.

However, performance monitoring should also be measured. An employer does not have the right to monitor an employee at all times, interfere with their private life, or track their non-work-related activities. For example, installing a GPS system in a company car might be reasonable for route and delivery security during working hours. However, continuous location tracking of a vehicle used privately outside of working hours should be evaluated separately.

Similarly, using software on remote employees' computers that takes screenshots, records keyboard activity, or requires them to constantly turn on their cameras poses serious risks to their personal data and privacy. Employers should choose the least intrusive method for performance measurement and clearly inform the employee.

Transfer of Employee Data to Third Parties

Employers may be required to share employee data with third parties in certain situations. These recipients may include the Social Security Institution (SGK), tax offices, the Turkish Employment Agency (İŞKUR), courts, enforcement offices, banks, occupational health and safety firms, payroll service providers, independent auditors, lawyers, accountants, insurance companies, and group companies.

However, every data transfer must have a legal basis and purpose. Employee data should not be shared with group companies, business partners, or managers' personal email addresses simply for convenience. Data minimization principles must be observed during data transfers. For example, a bank may request information necessary for salary payments, but it does not need to request the employee's medical report or disciplinary file.

If data transfer abroad is involved, the provisions of Article 9 of the KVKK (Turkish Personal Data Protection Law) should be evaluated separately. Sending employee data to a group company abroad, using foreign human resources software, and storing employee data in a global e-mail and cloud infrastructure may result in data transfer abroad. In this case, mechanisms such as standard contracts, binding company rules, adequacy decisions, or incidental transfer exceptions should be examined.

Obligation to Provide Information Regarding Employee Data

Employers must inform employees about the processing of their personal data. This information should be provided upon hiring and updated whenever data processing activities change. The employee information notice should clearly state the employer's identity, the categories of data processed, the purposes of data processing, the legal grounds, the recipient groups to whom the data will be transferred, the data collection method, and the employee's rights.

The data protection notice should not be general, long, or unclear. Employees must truly understand which of their data is being processed and why. For example, simply stating "your data is processed for the purpose of carrying out business processes" may not be sufficient. Topics such as payroll, social security, occupational health and safety, performance, security camera footage, email system, disciplinary process, training records, and workplace safety should be explained separately.

Obtaining explicit consent from an employee for every transaction is not a proper approach. Data processing activities necessary for the employer's legal obligations or the performance of the employment contract should be based on the relevant legal processing conditions, not explicit consent. Explicit consent should only be used in cases where it is genuinely required, not mandatory, and the employee can make the decision freely.

Employee Data After Termination of Employment Relationship

Employee data may not be immediately and completely deleted after the termination of an employment contract. Employers may need to retain certain documents for purposes such as severance pay, notice pay, wage arrears, overtime, annual leave, workplace accidents, social security audits, tax audits, lawsuits, and enforcement proceedings. However, the retention period and scope must be clearly defined.

The corporate email account, system privileges, access control privileges, cloud file access, and application accounts of the departing employee must be immediately terminated. Allowing the former employee continued access to the system poses a risk to both trade secrets and personal data security.

Furthermore, the personal data of departing employees should not be unnecessarily retained in active employee lists and should be updated on the website, team page, or customer contact lists. If the former employee's photograph and name are to continue to be used in company promotional materials, a separate legal assessment should be conducted.

Data Security and Employer's Technical and Administrative Measures

Employers are required to take technical and administrative measures to protect employee data. Technical measures may include password policies, multi-factor authentication, access restrictions, log recording, encryption, data masking, secure backups, firewalls, antivirus software, penetration testing, device management, and data loss prevention systems.

Administrative measures include providing GDPR training to employees, obtaining confidentiality agreements, creating an authorization matrix, preparing a retention and destruction policy, establishing data processor agreements, creating a breach response plan, including data security provisions in disciplinary procedures, and regularly auditing human resources processes.

The organization states that data security measures should be determined in accordance with the structure, activities, and risks of each data controller; that no single model can be foreseen, and that the size of the company and the nature of the data processed are also important.

Employer's Liability in Case of Data Breach

Data breaches can occur when employee data is obtained by third parties, sent to the wrong person, published online, copied by a former employee, when a human resources system is hacked, or when payroll information is disclosed. In such a case, the employer should not limit themselves to simply making technical corrections.

According to Article 12 of the KVKK (Law on Protection of Personal Data), if personal data processed is obtained by others through unlawful means, the data controller must notify the data subject and the Board as soon as possible. In the Board's practice, this period is considered to be 72 hours for notification to the Board.

In the case of an employee data breach, the employer must first determine the scope of the breach. Which employees were affected? Which data categories were leaked? Is there any sensitive data, such as health, union, or biometric data? Is the breach ongoing? Who had access? What technical measures were taken? What should be communicated to the employees? Is it necessary to file a criminal complaint with the prosecutor's office? These questions must be answered quickly.

Employer's Legal, Administrative and Criminal Liability

Unlawful processing of employee data can result in administrative fines, liability for damages, labor law sanctions, and in some cases, criminal law consequences for the employer. Violation of the obligation to inform under Article 18 of the Personal Data Protection Law, breaches of data security obligations, non-compliance with Board decisions, or failure to fulfill VERBİS obligations carry the risk of administrative sanctions.

An employee can claim compensation if they have suffered material or moral damage due to the unlawful processing of their personal data. For example, the dissemination of health information in the workplace, the unauthorized sharing of disciplinary records, the unlawful use of camera recordings, the excessive examination of email correspondence, or the improper processing of biometric data may constitute a violation of the right to privacy.

Furthermore, crimes related to the unlawful recording, disclosure, dissemination, or acquisition of personal data may arise under the Turkish Penal Code. If employer managers or human resources personnel have unlawfully disclosed employee data to third parties, their criminal liability will be assessed separately.

Employee Rights

Employees have the right, under the Personal Data Protection Law (KVKK), to learn whether their personal data is being processed, to request information regarding this processing if it is, to learn the purpose of the processing and whether it is being used appropriately, to know the third parties to whom the data has been transferred, to request the correction of incomplete or inaccurate data, to request its deletion or destruction if the conditions are met, and to request compensation for damages incurred due to unlawful processing.

To exercise these rights, the employee may first apply to the employer, who is the data controller. The employer must respond to the application within the specified time and with justification. If no response is given, an incomplete response is given, or the request is rejected, the employee may consider filing a complaint with the Authority.

However, employee rights are not unlimited. For example, payroll, social security, tax, workplace accident, or court documents that the employer is legally obligated to retain may not be immediately deleted simply at the employee's request. In this case, the employer must clearly explain which data is being retained and on what legal grounds.

GDPR Compliance Checklist for Employers

To ensure employers comply with employee data regulations, a personnel data inventory must first be created. Recruitment, personnel files, payroll, social security, occupational health and safety, security cameras, email, performance, discipline, training, vehicle tracking, benefits, termination, and archiving processes should be examined separately.

Next, an employee information document should be prepared or updated. Processes requiring explicit consent should be defined separately; unnecessary explicit consent should not be obtained. Additional security measures should be implemented for sensitive personal data. Separate policies and information should be provided for cameras, email monitoring, vehicle tracking, and biometric systems.

From a data security perspective, access rights should be restricted, human resources and managers should be trained, system access for former employees should be terminated, contracts should be established with data processors, retention and destruction periods should be determined, and a data breach response plan should be created.

Conclusion

Protecting employees' personal data is not a process that can be completed simply by having them sign the Personal Data Protection Law (KVKK) text. Employers must process employee data lawfully, proportionally, for specific purposes, and securely at every stage of the employment relationship. Candidate data during recruitment, personnel and payroll records during employment, occupational health and safety documents, camera footage, email monitoring, performance data, biometric systems, and post-termination storage processes should all be evaluated separately.

Employers have the right to monitor and manage; however, this right does not negate employees' right to privacy, freedom of communication, and protection of their personal data. The Constitutional Court's decisions regarding corporate email monitoring also demonstrate that employers can conduct monitoring that is legitimate, informed in advance, proportionate, and necessary; however, arbitrary and unlimited monitoring may lead to violations of rights.

In conclusion, employee data protection is a multifaceted area encompassing labor law, the Personal Data Protection Law (KVKK), privacy, freedom of communication, occupational health and safety, criminal law, and liability for damages. It is crucial for employers to establish data inventories, information notices, data security measures, access management, camera and email policies, sensitive data procedures, retention and destruction policies, and data breach response plans. Failure to manage this process correctly can lead to risks such as administrative fines, compensation claims, labor disputes, reputational damage, and criminal liability for employers.

Leave a Reply

Call Now Button