ARTICLE
8 October 2026

New Personal Data Protection Guide For Lawyers

E
Egemenoglu

Contributor

Egemenoglu is one of the largest full-service law firms in Turkey, advising market-leading clients since 1968. Egemenoğlu who is proud to hold many national and international clients from different sectors, is appreciated by both his clients and the Turkish legal market with his fast, practical, rigorous and solution-oriented work in a wide range of fields of expertise. Egemenoğlu has been considered worthy of various rankings by the world’s most leading and esteemed rating institutions and legal guides. We have been ranked as Recognized in “Project and Finance” and “Mergers and Acquisitions” areas by IFLR 1000. We also take place among the top- tier law firms of Turkey at the rankings of Legal 500, at which world’s best law firms are regarded, in “Employment Law” and “Real Estate / Construction” areas. Also our firm is regarded as significant by Chambers& Partners in “Employment Law” area as well.
The Personal Data Protection Authority (“Authority”) published the “Implementation Guide on the Protection of Personal Data in Lawyers’ Professional Activities” (“Guide”) on 22 September 2026.
Turkey Privacy

The Personal Data Protection Authority (“Authority”) published the “Implementation Guide on the Protection of Personal Data in Lawyers’ Professional Activities” (“Guide”) on 22 September 2026.

The Guide addresses the status of lawyers, law firms and employees of lawyers under the Personal Data Protection Law No. 6698 (the “Law”), as well as the principles governing personal data processing activities carried out in the course of professional activities.

By its very nature, the legal profession requires the processing of various personal data relating not only to clients, but also to prospective clients, opposing parties and other third parties. The Guide approaches the protection of personal data not merely as a standalone obligation arising under the Law, but as a matter closely intertwined with the principles of confidentiality, trust and due care inherent in the legal profession.

1. Are Lawyers Considered “Data Controllers”?

The Guide states that lawyers act as data controllers under the Law in respect of the personal data they process. It further assesses this status in the context of various scenarios.

a. Assessment Based on the Existence of Legal Personality

Under the Attorneyship Law, where multiple lawyers practice together in the same office, their arrangement is considered an ordinary partnership and does not have legal personality. The Guide states that, in such “Law Firms” without legal personality, while responsibility rests primarily with the partners, liability in respect of personal data does not automatically extend to all partners. Accordingly, the partners of a Law Firm will not be jointly and severally liable towards third parties. Instead, each lawyer will be responsible for the personal data that they process.

By contrast, an “Attorney Partnership” has legal personality and is therefore subject to a different regime. Under the Attorneyship Law, an Attorney Partnership bears unlimited and primary liability for all acts undertaken in connection with the partnership by its partners and the lawyers they employ, while the partners themselves bear secondary liability. Accordingly, the Attorney Partnership is considered the data controller.

b. Status of the Delegated Attorney

With respect to the delegation relationship, the Guide states that where the Delegated Attorney processes the personal data shared with them in accordance with the purposes and instructions determined by the Delegating Attorney, the Delegating Attorney will qualify as the “data controller”, while the Delegated Attorney will qualify as the “data processor”. However, under the Attorneyship Law, the Delegating Attorney’s liability does not cease upon delegation but continues alongside that of the Delegated Attorney.

c. Status of Employed Lawyers and Trainee Lawyers

The Guide states that an employed lawyer does not qualify as a “data controller”, as they do not determine the purposes and means of processing personal data on behalf of the employing lawyer. As an employed lawyer operates within the organisational structure established by the employing lawyer, they are not separately considered a “data processor” either.

Similarly, the Guide states that trainee lawyers do not qualify as either “data controllers” or “data processors”, as they act under the supervision and responsibility of the lawyer with whom they are undertaking their traineeship and as part of the organisational structure established by that lawyer.

2. Professional Secrecy or Personal Data Protection?

One of the fundamental obligations of the legal profession is the duty of confidentiality. Under Article 36 of the Attorneyship Law, lawyers are prohibited from disclosing information entrusted to them or obtained in the course of performing their professional duties.

However, the Guide specifically emphasises that the concepts of professional secrecy and personal data differ in scope. Under the Law, personal data encompasses any information relating to an identified or identifiable natural person, whereas professional secrecy may have a narrower scope. Accordingly, information may constitute personal data without necessarily being subject to professional secrecy.

This distinction is also significant in the context of a lawyer’s duty of care. According to the Guide, this duty extends to personal data processing activities carried out in the course of the lawyer’s professional activities. Accordingly, it is not sufficient for a lawyer merely to prevent the disclosure of information subject to professional secrecy; the lawyer must also ensure that the personal data they process is processed and protected in accordance with the procedures and principles set out under the Law. Depending on the circumstances of the particular case, a violation of the right to the protection of personal data may constitute a breach of the lawyer’s duty of care and may give rise not only to disciplinary liability but also to claims for compensation by data subjects whose personal data has been unlawfully processed.

3. Are Judicial Proceedings Exempt from the Law?

Article 28 of the Law sets out the circumstances in which the provisions of the Law do not apply, either in whole or in part. In this context, pursuant to Article 28(1)(d), the provisions of the Law do not apply where personal data is “processed by judicial authorities or enforcement authorities in connection with investigation, prosecution, judicial proceedings or enforcement proceedings.” The Guide states that, for this exemption to apply, two conditions must be satisfied cumulatively: the personal data processing activity must relate to investigation, prosecution, judicial proceedings or enforcement proceedings, and it must be carried out by judicial authorities or enforcement authorities. Accordingly, the exemption under Article 28(1)(d) of the Law does not apply to personal data processing activities carried out by lawyers in the course of their professional activities.

Accordingly, a lawyer’s collection, recording, storage, use or transfer of personal data relating to a client, opposing party, debtor or other third party in the context of litigation or enforcement proceedings is not exempt from the Law merely because such processing takes place within the context of judicial proceedings.

4. Can Lawyers’ Use of Artificial Intelligence Result in a Breach of the Law?

The Guide states that where client files, case documents or other documents containing personal data are uploaded to generative AI tools such as ChatGPT, Claude and Gemini, the data in question may be processed through the service provider’s technical infrastructure.

In this context, uploading a file or document containing personal data to a generative AI tool should not be regarded merely as obtaining technical assistance or conducting legal research. The Guide notes that where the service provider is located abroad, the servers used are located outside Türkiye, or the data is processed through sub-processors located abroad, such use may constitute a cross-border transfer of personal data within the meaning of Article 9 of the Law.

The Guide further emphasises that, before using an AI service provider, lawyers should review the applicable terms of use and privacy policy, the conditions governing data processing, information on where the data is stored and the countries in which it is processed, provisions concerning sub-processors, and any applicable cross-border data transfer mechanisms. Where it is determined that personal data is transferred abroad, such transfers must comply with the requirements for cross-border data transfers set out in Article 9 of the Law.

However, the fact that the service provider is located in Türkiye or that the data is processed in Türkiye does not, in itself, preclude a personal data transfer. The transfer of files or documents containing personal data to a domestic AI service provider may also constitute a transfer of personal data under the Law. In such cases, pursuant to Article 8 of the Law, the legal basis and purpose of the transfer, the categories of data to be transferred, and the proportionality of the transfer must each be assessed separately.

These considerations are relevant not only to data transfers but also to data security. The Guide emphasises that where the personal data of clients, prospective clients or employees is processed through such tools, lawyers remain obliged under Article 12 of the Law to implement the necessary technical and organisational measures to prevent the unlawful processing of and unauthorised access to personal data, and to ensure its secure storage.

Accordingly, the Guide recommends that personal data to be shared with generative AI tools be masked or anonymised to the extent possible, that the uploading of special categories of personal data to such systems be avoided, and that only the minimum amount of data necessary for the intended purpose be shared.

5. Conclusion

The Guide serves as an important reference for lawyers and law firms when reviewing their existing personal data processing activities, data transfer practices and data security measures. The protection of personal data is not merely a matter of compliance with the Law, but also an integral part of the duties of confidentiality, trust and due care that underpin the legal profession.

In particular, the increasing digitalisation of legal practice and the growing use of AI tools in the provision of legal services give rise to new considerations regarding the protection of personal data. The Guide emphasises that personal data processing activities carried out by lawyers in the course of their professional activities cannot be considered independently of the requirements of the Law and must be conducted in accordance with the legal bases and general principles set out therein.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More