Single Blog Title

This is a single blog caption

Unlawful Acquisition and Dissemination of Personal Data

Entrance

In the digital age, personal data has become one of the most important legal assets of individuals. People's names, surnames, phone numbers, national identity numbers, addresses, photographs, email addresses, IP addresses, bank information, health data, social media accounts, location information, and records relating to their private lives are now often stored in digital systems. Therefore, the unlawful acquisition, dissemination, or sharing of personal data with third parties can directly affect not only private life but also a person's reputation, security, economic well-being, and social life.

The unlawful acquisition and dissemination of personal data is a serious violation under Turkish law, with consequences under both criminal law and data protection law. Examples include disclosing a person's phone number on social media, using their photo on a fake account, sharing their address, disclosing their personal information to third parties, a former employee copying customer information, a database being compromised through cyberattacks, or the dissemination of private information in Telegram/WhatsApp groups.

In Türkiye, the protection of personal data is also constitutionally guaranteed. Article 20 of the Constitution stipulates that everyone has the right to request the protection of their personal data; this right includes the rights to be informed about personal data, to access data, to request its correction or deletion, and to learn whether it is being used for its intended purposes. The same provision states that personal data can only be processed in cases prescribed by law or with the explicit consent of the individual.

This issue has become even more important, especially with the rise of social media and internet use. Today, personal data can be illegally obtained or disseminated by former spouses or ex-partners, employees, fake accounts, for fraudulent purposes, or due to security vulnerabilities within companies. Therefore, it is crucial for victims of personal data breaches to know what legal avenues they can pursue, what obligations companies have, and what penalties perpetrators may face.

What is Personal Data?

Personal data is any information relating to an identified or identifiable natural person. This definition is quite broad. For data to be considered personal data, it does not necessarily have to be directly identifying information such as a Turkish national identity number. Any information that directly or indirectly identifies a person can be considered personal data.

Personal data may include name, surname, telephone number, address, email address, photograph, camera footage, audio recording, IP address, vehicle license plate, bank account information, credit card information, customer number, username, social media account, location information, professional information, education information, health information, biometric data, fingerprint, signature, family information, and shopping history.

The concept of personal data is interpreted broadly in the practice of the Supreme Court of Appeals. In a decision by the 12th Criminal Chamber of the Supreme Court of Appeals, it was stated that any information belonging to a specific or identifiable person can constitute the material subject matter of the crime under Article 136 of the Turkish Penal Code; demographic information, telephone numbers, email addresses, bank account information, health information, and similar information are considered personal data. The decision emphasized that information known to everyone or easily accessible can also be considered personal data in a legal sense.

Therefore, defenses such as "this information was already available online," "everyone knew the phone number," or "the photo was shared on social media" do not always guarantee legal compliance. The fact that information has been previously visible somewhere does not mean that it can be used without limit, shared on other accounts, or disseminated to third parties. The purpose of the personal data's use, the scope of consent, the context of sharing, and the grounds for legal compliance must be evaluated separately.

What is the unlawful acquisition of personal data?

Unlawful acquisition of personal data refers to accessing, obtaining, copying, recording, or transferring personal data to third parties without the person's consent or legal authorization. This acquisition can occur digitally or through physical documents.

For example, unauthorized copying of a person's phone book, unauthorized access to email accounts and correspondence, unauthorized access to hospital records, a former employee transferring a company's customer list to a USB drive, unauthorized sharing of identity document photocopies, obtaining bank information via a fake link, copying photos from social media accounts, or exporting information from databases can all be considered unlawful acquisition of personal data.

For this crime to occur, the data does not necessarily have to be confidential or secret. What is important is that the data relates to a real person and is obtained unlawfully. Of course, when dealing with sensitive personal data such as health data, sexual life data, biometric data, political opinions, religious beliefs, or trade union membership, the severity of the violation increases, and a more sensitive assessment is made both under criminal law and the Personal Data Protection Law.

What is the Unlawful Dissemination of Personal Data?

Dissemination of personal data includes the transfer of obtained or possessed personal data to third parties, sharing it on social media, publishing it on a website, sending it to WhatsApp or Telegram groups, distributing it to email lists, posting it on forums, or making it accessible to others in any way.

For example, sharing someone's phone number on social media in a way that targets them, disclosing their address, using their photo on a fake account, sending their personal information to third parties, giving their customer list to a competitor, sharing employees' salary information in an email group, sharing patients' health data with unauthorized persons, or publishing private correspondence online may constitute the unlawful dissemination of personal data.

The 12th Criminal Chamber of the Supreme Court of Appeals, in a decision regarding the use of a victim's profile picture on a fake social media account, accepted that even if the photograph is not considered an image relating to private life, it constitutes personal data and its use as a profile picture on a fake account created in the victim's name can be evaluated within the scope of Article 136 of the Turkish Penal Code.

In another decision by the 4th Criminal Chamber of the Supreme Court of Appeals, it was stated that the act of publishing images created using Photoshop along with a person's name on a website constitutes the crime of unlawfully disseminating personal data under Article 136 of the Turkish Penal Code; and that the provisions of concurrent offenses should be evaluated in terms of the relationship of the same act with the crime of defamation.

Turkish Penal Code Article 135: Unlawful Recording of Personal Data

Crimes against personal data are regulated in a separate section of the Turkish Penal Code. The first of these is the crime of recording personal data, found in Article 135 of the Turkish Penal Code. According to Article 135 of the Turkish Penal Code, a person who unlawfully records personal data shall be sentenced to imprisonment for one to three years. Furthermore, if the personal data relates to individuals' political, philosophical, or religious views, racial origins, unlawful moral inclinations, sexual lives, health status, or trade union affiliations, the penalty shall be increased by half.

The act of "recording" is crucial here. The perpetrator may not have yet disseminated the data; however, if they have unlawfully recorded personal data in a system, file, archive, phone, computer, USB drive, or database, Article 135 of the Turkish Penal Code may come into play. For example, a hospital employee recording patient information for personal purposes, an employer creating an unlawful private data archive about an employee, or a person listing someone else's private information without permission could all be considered within this scope.

Turkish Penal Code Article 136: Unlawfully Disclosing, Disseminating, or Obtaining Data

The most fundamental penal norm regarding the unlawful acquisition and dissemination of personal data is Article 136 of the Turkish Penal Code (TCK). According to this article, a person who unlawfully gives, disseminates, or acquires personal data belonging to another person shall be punished with imprisonment from two to four years. If the subject matter of the crime is statements and images recorded in accordance with the fifth and sixth paragraphs of Article 236 of the Code of Criminal Procedure (CMK), the penalty shall be increased by one-fold.

Article 136 of the Turkish Penal Code (TCK) lists three alternative actions: giving, disseminating, and acquiring. "Giving" is the transfer of personal data to a specific person. "Disseminating" is making the data public or accessible to a wider audience. "Acquisition" is the unlawful acquisition of data by the perpetrator.

For this crime, the victim's personal data does not necessarily have to have economic value. A phone number, photograph, address, email address, social media username, identity information, or private correspondence can also be the subject of the crime. The act must be unlawful. Situations such as legal authority, explicit consent, the use of evidence necessary within the scope of self-defense, or lawful journalistic activity are evaluated separately in each specific case.

Turkish Penal Code Article 137: Aggravating Circumstances

Article 137 of the Turkish Penal Code (TCK) provides for an increase in punishment when crimes related to personal data are committed by certain individuals or by taking advantage of certain privileges. If the crimes defined in Articles 135 and 136 of the TCK are committed by a public official through the abuse of authority granted by their position or by taking advantage of privileges provided by a particular profession or trade, the punishment shall be increased by half.

This provision is particularly important for public institutions, healthcare organizations, banks, law firms, insurance companies, human resources companies, call centers, software companies, e-commerce platforms, and professional groups that process customer data. This is because these individuals may have access to more data than an average person due to their profession or duties. Misuse of this access leads to a more serious criminal penalty.

For example, a public official querying citizens' information from the system and providing it to third parties, a hospital employee disseminating patient information, a bank employee sharing customer information, a company employee transferring a customer list to a competitor, or a professional using data learned in the course of their duties without authorization may constitute an aggravating circumstance under Article 137 of the Turkish Penal Code.

Turkish Penal Code Article 138: Failure to Destroy Data

Article 138 of the Turkish Penal Code (TCK) criminalizes the failure to delete data. Failure by those obligated to delete data from the system, even after the legally prescribed periods have expired, may result in criminal liability. A Constitutional Court ruling also states that Article 138 of the TCK prescribes imprisonment for those who fail to delete data after the legal retention period has expired.

This provision makes it crucial not only to collect personal data lawfully, but also to delete or destroy it after the necessary period. For companies, retention and destruction policies, data inventories, retention periods, and destruction records are therefore important. In particular, employee data, customer records, camera footage, application forms, website logs, and past customer data should not be stored indefinitely.

The Relationship Between the Personal Data Protection Law and Criminal Law

The unlawful acquisition and dissemination of personal data is not only subject to criminal investigation under the Turkish Penal Code, but can also have administrative and private law consequences under the Law No. 6698 on the Protection of Personal Data. The Law imposes obligations on data controllers to prevent the unlawful processing of personal data, to prevent unlawful access to data, and to ensure the preservation of data.

Therefore, if a company's customer data has been leaked, the issue is not simply a matter of "who is the culprit?". Other questions arise, such as: Did the company take the necessary technical and administrative measures? Did it detect the data breach in a timely manner? Did it notify the Board and relevant parties? Were its data security policies adequate? Were employee access rights restricted? Were log records kept?.

The Personal Data Protection Board's decision regarding the data breach notification procedure states that if personal data is obtained by others through unlawful means, the data controller must notify the data subject and the Board as soon as possible; the phrase "as soon as possible" is interpreted as 72 hours for notification to the Board.

What is a data breach?

A data breach is the unauthorized acquisition, disclosure, alteration, loss, deletion, rendering inaccessible, or unlawful access to personal data by unauthorized individuals. Data breaches don't always occur through external attacks. Sending an email to the wrong recipient, an open-access cloud folder, a former employee continuing to access the system, transferring customer information to a competitor, gaining access to a CRM system due to a weak password, or viewing someone else's files due to an authorization error can also constitute a data breach.

Recent GDPR announcements demonstrate the diversity of data breaches in practice. For example, a 2026 GDPR public announcement reported that unauthorized access to third-party damage claims was gained due to insufficient authorization controls and manipulation of query parameters on a company's website.

Another announcement in 2026 stated that attackers had gained access to databases on a server running a retail company's CRM system, compromising identity and contact information, with an estimated 4,500,000 people affected. Such examples demonstrate that data security is critical not only for large technology companies but for all businesses that process customer data.

Dissemination of Personal Data on Social Media

Social media is one of the most common platforms for the unlawful dissemination of personal data. Sharing a person's phone number, disclosing their address, using their photo on a fake account, publishing their personal information as a post, sharing screenshots of their private correspondence, or disseminating their personal information with the aim of targeting them can all lead to criminal liability.

The most common mistake here is the assumption that "the person's profile was already public." Just because someone's photo is on their social media profile doesn't mean that person can use it on a fake account or distribute it to third parties for other purposes. Consent, context, and the intended use are the determining factors.

For example, using a victim's photo taken from their Instagram account on a fake dating account, sharing the victim's phone number with the message "harass them," disclosing their address during an argument, or disseminating their personal data for the purpose of organized lynching could be considered under Article 136 of the Turkish Penal Code. The act may also constitute the crimes of insult, threat, blackmail, or violation of privacy.

The Difference Between Personal Data Crime and Violation of Privacy

In practice, Article 136 and Article 134 of the Turkish Penal Code (TCK) are often confused. Article 136 regulates the unlawful disclosure, dissemination, or acquisition of personal data. Article 134, on the other hand, regulates the crime of violating the privacy of private life. Not every personal data breach is also a violation of the privacy of private life; however, in some cases, both crimes may be relevant together.

For example, using a profile picture of a person in everyday clothes on a fake account might be considered an unlawful dissemination of personal data, not a violation of privacy. Conversely, sharing a person's private photos, private correspondence, images from their home, health information, or data relating to their sexual life could be examined as both a violation of privacy and a personal data crime.

This distinction is crucial for the proper conduct of the investigation and the accurate determination of the nature of the crime. Instead of simply describing the incident in the complaint as "my private life was violated" or "my personal data was disseminated," the complaint should clearly specify which data was obtained, how it was obtained, where it was shared, who received it, and the nature of the data.

What should the victim do?

Individuals whose personal data has been illegally obtained or disseminated must first and foremost preserve the evidence. Social media posts, screenshots, URLs, usernames, dates and times, messages, email subject lines, phone numbers, the group or platform where the posting was made, witnesses, and any payment/blackmail requests should all be recorded.

If the content has been published on social media or a website, simply taking a screenshot may not be sufficient. The full URL, the profile information of the account that shared it, the date of the posting, whether the account is public, and the context in which the data was shared should be recorded. It is important to gather evidence before the perpetrator closes the account or deletes the content.

A criminal complaint can then be filed with the Public Prosecutor's Office. The complaint may request an assessment of the relevant articles of the Turkish Penal Code (TCK), primarily Article 136, but also, depending on the specific circumstances, Articles 135, 137, 138, 134, 125, 106, 107, 243, or 244. If the perpetrator is unknown, requests should be made to obtain IP and log records from the social media platform, IP allocation information from the internet service provider, line information from GSM operators, and digital materials for expert examination.

Complaint Process and Prosecutor's Investigation

The crime of unlawfully disclosing, disseminating, or obtaining personal data, as defined in Article 136 of the Turkish Penal Code, is generally not a crime subject to complaint. Therefore, the public prosecutor's office can initiate an investigation ex officio upon learning that the crime has been committed. However, it is extremely important for the effectiveness of the investigation that the victim submits a detailed criminal complaint, presents evidence, and specifies concrete requests for investigation.

The prosecutor's investigation should particularly focus on the following: How was the personal data obtained? Who shared the data? On what platform was the sharing done? How many people accessed the data? Is the data still available? Is the perpetrator's account real or fake? To whom are the IP records associated? If the data was leaked from a company system, does the company have a security vulnerability? Is the person who shared the data a public official, employee, or someone with professional access privileges?

The answers to these questions determine the classification of the crime and the scope of criminal liability. For example, a regular social media user sharing the victim's phone number is not considered to have the same severity as a public official giving address information obtained from the system to a third party. In the second case, the aggravated form of the offense under Article 137 of the Turkish Penal Code may come into play.

Data Security Obligations of Companies

The unlawful acquisition of personal data is often linked to data security vulnerabilities within companies. E-commerce sites, healthcare organizations, insurance companies, banks, educational institutions, human resources companies, software companies, and call centers process a large amount of personal data. It is essential to take the necessary technical and administrative measures to protect this data.

According to the Turkish Personal Data Protection Law (KVKK), data controllers are obligated to take necessary measures to ensure an appropriate level of security to prevent the unlawful processing and unlawful access to personal data, and to ensure the preservation of data. The Authority states that data security measures should be determined according to the structure, activities, and risks of each data controller; a single model cannot be prescribed.

In this context, companies need to take measures such as access authorization, strong passwords, multi-factor authentication, log recording, encryption, data masking, backup, penetration testing, employee training, confidentiality commitments, data processor agreements, retention-destruction policies, and data breach response plans. Otherwise, in the event of a data breach, not only the attacker but also the data controller who failed to take the necessary precautions may face administrative and legal liability.

Data Breach Notification and the 72-Hour Rule

If a data controller learns that personal data being processed has been obtained by others through unlawful means, they must notify the data subject and the Personal Data Protection Board as soon as possible. According to the Board's decision No. 2019/10, notification to the Board should, as a rule, be made within 72 hours of learning of the breach.

The notification must specify when the breach occurred, when it was detected, which data categories were affected, how many people were affected, the source of the breach, the measures taken, how the affected individuals were informed, and the communication channels through which they can receive information about the breach. The Personal Data Protection Law's breach notification form also requires an explanation for the delay if more than 72 hours have passed.

Late notification can also be grounds for sanctions against the data controller. In one of the summaries of the KVKK's (Personal Data Protection Law) decisions dated 2026, it was stated that if the data controller notified the data subjects with a delay of 17 months and the Board with a delay of 10 months, this exceeded the "shortest period" and was considered a data security breach.

Right to Compensation

Individuals whose personal data has been unlawfully obtained or disseminated may, in addition to criminal proceedings, claim compensation for both material and moral damages. The dissemination of personal data may have damaged the victim's reputation, disrupted their professional relationships, jeopardized their safety, caused economic harm, or resulted in psychological distress.

Monetary compensation arises when concrete damage is proven. For example, if there is a financial loss due to the misuse of personal information, if money is withdrawn using bank details, or if there is a commercial loss due to the dissemination of a customer list, monetary compensation can be claimed. Non-pecuniary damages, on the other hand, arise in cases such as the violation of personal rights, damage to privacy, loss of reputation, and disruption of peace and security.

Under Article 11 of the Personal Data Protection Law (KVKK), individuals have the right to request the deletion or correction of their personal data, its correction if it is incomplete or inaccurate, to learn the purpose of processing, and to claim compensation for damages incurred due to unlawful processing. Therefore, the victim should consider criminal law, KVKK application, and private law compensation avenues simultaneously.

How should evidence be collected?

The evidence gathering process is extremely important in personal data breaches. This is because digital content can be quickly deleted, accounts closed, usernames changed, or data spread to different platforms. Therefore, the victim must first gather legally compliant evidence.

If there is a social media post, the full URL, screenshot, screen recording, username, profile link, date and time information, the content of the post, and who could access it should be recorded. If there is a WhatsApp or Telegram group, the group name, number of participants, message content, and date information should be obtained. If there is an email, not only the email text but also the email header information should be saved. If there is a publication on a website, the page URL, the publication date, and, if possible, a notarized/expert verification should be obtained.

Illegal methods should not be used when gathering evidence. Unauthorized access to someone else's account, secretly examining their phone, cracking passwords, or gaining unauthorized access to private systems can also create criminal risk for the victim. The victim must legally document the content they see on their account, that is sent to them, or that they access publicly.

Defense from the Perspective of the Suspect or Defendant

Defending against data crimes also requires technical and legal analysis. First, it must be examined whether the shared information constitutes personal data, whether the data relates to a real person, whether the victim can be identified, whether the data was obtained illegally, and whether the perpetrator acted with intent.

In some cases, data may have been shared with the explicit consent of the victim. In other cases, data sharing may have been done due to a legal obligation. In some instances, legal grounds such as the right to report, the right to claim and defend, legitimate interest, or providing evidence in a trial may arise. However, these grounds are not limitless. The claim of legality is weaker, especially in cases of targeting, public shaming, revenge, or economic gain on social media.

From the perspective of the defendant's counsel, IP records, account ownership, device usage, who shared the data, who previously knew the data, whether the evidence was obtained lawfully, and whether the mental element of the crime has been fulfilled must be carefully examined.

Conclusion

The unlawful acquisition and dissemination of personal data is one of the most significant criminal and cyber law issues of the digital age. Obtaining, disclosing to third parties, or disseminating online data such as phone numbers, addresses, photographs, identity information, bank data, health information, social media accounts, IP addresses, emails, or private correspondence without consent or legal authorization has serious legal consequences.

According to the Turkish Penal Code, Article 135 regulates the unlawful recording of personal data, Article 136 the unlawful disclosure, dissemination, or acquisition of personal data, Article 137 addresses aggravated circumstances, and Article 138 regulates the crime of failing to destroy data. In addition, depending on the specifics of the case, crimes such as violation of privacy, defamation, threat, blackmail, unauthorized access to an information system, fraud, or system disruption may also come into play.

According to the KVKK (Turkish Personal Data Protection Law), data controllers are obliged to take the necessary technical and administrative measures to prevent the unlawful processing of personal data and unlawful access to personal data. In the event of a data breach, there may be an obligation to notify the Board and the relevant individuals. Data security, retention and destruction policies, access authorization, log records, employee training, and data breach response plans are of great importance, especially for companies.

The most important step for the victim is the swift and lawful preservation of evidence. Posts, URLs, screenshots, messages, usernames, date and time information, and other digital traces should be recorded; then, a detailed criminal complaint should be filed with the Public Prosecutor's Office, and if necessary, applications to the Personal Data Protection Law, content removal, and compensation claims should be considered together.

In conclusion, personal data breaches should not be viewed as a simple internet post or a routine data leak. Personal data is a fundamental part of a person's digital identity and private life. Therefore, in allegations of unlawful acquisition and dissemination of personal data, it is of paramount importance that the process be handled professionally, considering criminal law, GDPR, information technology law, digital evidence, and compensation aspects.

Leave a Reply

Call Now Button