fineConcludedTRY 500,000

KVKK (Turkish Data Protection Authority) Employer (data controller, redacted)

August 4, 2022 · Turkey

KVKK fined a data controller TRY 500,000 for unlawfully processing employees' biometric data via a facial-recognition system for workplace entry/exit control, lacking a valid legal basis and freely-given consent.

Key takeaway — how to prevent this

Biometric data (faces, iris, fingerprints) needs an explicit lawful basis or consent. Scraping or capturing it without one is unlawful across the EU/UK and many US states (e.g. Illinois BIPA) — and draws the largest fines.

Inclusion does not imply wrongdoing or liability. Status reflects the latest information we have — always check the official source for current status.