Turkey’s Personal Data Protection Authority has increased its enforcement activity with 47 new decisions, reflecting evolving compliance risks and heightened scrutiny by regulators across Europe and beyond, especially on biometric data, privacy notices, and AI systems.
Turkey’s Personal Data Protection Authority has stepped up its recent output, publishing 47 fresh decision summaries that touch on unauthorised advertising and marketing, cookies, camera and audio recordings, biometric data, access rights and data breaches. The latest batch underlines how broadly the regulator is interpreting compliance risks and how often familiar operational practices are now being tested against personal data rules.
One of the most immediate deadlines now approaching concerns loyalty card schemes. Under KVKK’s principle decision on such programmes, controllers have a six-month period to adapt their systems, and that window closes on 28 August 2026. The authority expects businesses to put in place safeguards that stop transactions being carried out with someone else’s phone number or card details unless verification has been completed. Acceptable controls include SMS codes, QR or barcode checks, physical cards and passwords, and firms that fail to introduce suitable measures face possible administrative sanctions.
Outside Turkey, European regulators are also focusing on the practical limits of current privacy systems. The European Data Protection Board has asked the European Commission to assess the impact of the US Supreme Court’s ruling on the Federal Trade Commission members’ dismissal on the EU-US Data Privacy Framework. The board said independent and effective supervisory authorities remain central to adequacy decisions and wants the Commission to examine whether the ruling could affect the FTC’s independence and its ability to enforce the framework.
In Germany, Hamburg’s data protection commissioner has said smart glasses could be banned because they may allow covert recording without the knowledge of bystanders. The commissioner argued that recording lights on the devices do not provide sufficient warning. German law already prohibits the sale of recording devices disguised as ordinary objects, which may make such wearables harder to justify in public spaces.
The latest enforcement decisions show that regulators are not limiting themselves to emerging technologies. Turkey’s Advertising Board has imposed separate TL863,580 fines on advertisers accused of promoting legal services that only lawyers are allowed to perform. In Italy, the data protection authority fined a platform €2 million for collecting professional contact information and reselling it through a paid B2B database. The authority said public profiles on sites such as LinkedIn do not mean individuals expect their details to be enriched from other sources and shared for marketing, and it found failures in transparency, data minimisation and privacy by design.
Other recent rulings have narrowed the scope for businesses to rely on consent or broad legal arguments. An Austrian authority fined a digital marketing agency €25,500 for recording job applicants’ calls without valid consent and keeping the recordings indefinitely. In Hungary, a regulator fined an online retailer 15 million forints, about €41,500, for giving unclear information on transfers of personal data to third countries. In Spain, an appeals court overturned Amazon’s €2 million GDPR fine, ruling that a document showing no criminal record was not criminal conviction data under Article 10, while upholding fines against KFC for overly general privacy notices and for failing to appoint a data protection officer in light of broad and systematic monitoring.
The week also brought fresh regulatory movement on advertising and artificial intelligence. Turkey’s updated rules on discount promotions now require the “old price” to be the lowest price charged in the previous 10 days, with separate treatment for store, website and app pricing. In Poland, the data protection authority published draft guidance on handling personal data in AI systems under GDPR, alongside broader material covering both GDPR and the AI Act. In the United States, the Senate Commerce Committee advanced the Kids Online Safety Act and related bills on children’s AI and privacy, while the Justice Department said OpenAI and its subsidiary Statsig had reached a settlement over alleged discrimination in hiring processes under the PERM programme.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





