Özgün Law Firm

Özgün Law Firm

THE LEGAL DIMENSIONS OF PROCESSING LOCATION DATA IN MOBILE APPLICATIONS

THE LEGAL DIMENSIONS OF PROCESSING LOCATION DATA IN MOBILE APPLICATIONS

1. Introduction

The rapid developments in digital technologies have made mobile applications an integral part of everyday life. While a wide range of services including social media, transportation, banking, e-commerce and navigation are provided through mobile applications, these applications process various categories of users’ personal data depending on the nature of the services they offer. Among the personal data processed, location data is of particular importance, as it not only indicates the point at which an individual is located but also enables significant inferences to be drawn regarding the individual’s daily life, habits, and social environment.

In Turkish law, the right to the protection of personal data is safeguarded under Article 20 of the Constitution, and, as the statutory manifestation of this constitutional protection, the Personal Data Protection Law Nr. 6698 (“PDPL”) was enacted. Although the Law does not contain a specific definition of location data, information concerning an individual’s location that can be associated with an identified or identifiable natural person is generally considered to constitute personal data. Accordingly, the processing of location data by mobile applications must be carried out in compliance with the data processing conditions prescribed under the PDPL and the obligations imposed on data controllers.

In this study, the legal nature of location data processed by mobile applications will be examined within the framework of the Law Nr. 6698. The obligations of data controllers concerning the provision of information to data subjects, data security, and the deletion, destruction, and anonymization of personal data will be examined. Subsequently, the administrative, civil, and criminal consequences of the unlawful processing of location data will be evaluated in light of the relevant applicable regulations, decisions of the Personal Data Protection Board, and judicial decisions.

2. The Legal Nature of Location Data in Mobile Applications

Although the personal data processed by mobile applications varies depending on the services provided by the respective application, location data has become one of the most frequently processed categories of data today. In particular, navigation, transportation, social media, and online ordering applications may access users’ real-time or continuous location information to provide their services. In practice, however, it can also be observed that certain applications request access to location data even where such access is not necessary for the provision of the service. This makes it necessary to properly determine the legal nature of location data and to ensure that data processing activities are carried out within the boundaries prescribed by law. 

Article 3(1)(d) of the Personal Data Protection Law Nr. 6698 defines personal data as “any information relating to an identified or identifiable natural person.” Although the Law does not contain a separate definition specifically addressing location data, location information that can be associated with an identified or identifiable natural person is considered to constitute personal data. Indeed, location data collected over a certain period of time may enable detailed inferences to be drawn regarding an individual’s place of residence, professional life, daily routines and social environment. In this respect, location data constitutes personal data that is directly connected with an individual’s private life.

The Personal Data Protection Authority has likewise emphasized under the guidelines it has published concerning data processing activities carried out through mobile applications that data controllers should process only the location data necessary for the provision of the service, clearly and comprehensibly inform the data subject of the purpose of the processing, and act in accordance with the principle of proportionality. Accordingly, the processing of location data should take into account not only technological capabilities but also the fundamental rights and freedoms of individuals. [1]

The impact of location data on private life has also been recognized in the judgments of the European Court of Human Rights. In its judgment in “Uzun v. Germany”, the Court held that location tracking carried out through GPS could constitute an interference with the right to respect for private life under Article 8 of the European Convention on Human Rights and made the following assessment:

“... In the Court’s view, GPS surveillance is, by its very nature, distinguishable from other methods of visual or acoustic surveillance, which are, as a rule, more likely to interfere with an individual’s right to respect for private life, as they may disclose more information about a person’s behavior, opinions or feelings. Nevertheless, having regard to the principles established in its case-law, the Court considers the factors set out above sufficient to conclude that the surveillance of the applicant by means of GPS, in the circumstances of the case, and the processing and use of the data thereby obtained in the manner described above, constituted an interference with his private life protected under Article 8/1.” [2]

The aforementioned judgment demonstrates that location data should not be regarded merely as technical information, but rather as personal data capable of enabling comprehensive inferences to be drawn concerning an individual’s private life. Therefore, ensuring that the processing of location data by mobile applications is carried out in compliance with the data processing conditions and fundamental principles set forth in the Personal Data Protection Law Nr. 6698 is of particular importance for the effective protection of the right to the protection of personal data.

3. Obligations of the Data Controller

In the processing of location data through mobile applications, data controllers are responsible not only for processing personal data lawfully but also for fulfilling the obligations set forth under the Personal Data Protection Law Nr. 6698. The Law imposes a number of obligations on data controllers aimed at protecting the fundamental rights and freedoms of data subjects at every stage of the personal data processing process. In the context of mobile applications, the principal obligations include the obligation to provide information, the obligation to ensure data security, and the obligation to delete, destroy, or anonymize personal data.

3.1. Obligation to Provide Information

Pursuant to Article 10 of the Personal Data Protection Law Nr. 6698, the data controller is obliged, at the time of obtaining personal data, to inform the data subject about the identity of the data controller, the purposes for which the personal data will be processed, the persons to whom the data may be transferred, the legal basis for the collection of the data, and the rights of the data subject set forth under Article 11 of the Law. This obligation is independent of explicit consent and is intended to ensure that data processing activities are carried out in a transparent manner.

In the context of mobile applications, the obligation to provide information is generally fulfilled through privacy policies or information notices. However, merely providing such texts as a matter of form is not sufficient. Users must be able to learn, in a clear, comprehensible, and easily accessible manner, for what purposes their location data is being processed.

Indeed, in its Principle Decision, numbered 2026/347 and dated 18.02.2026, the Personal Data Protection Board stated that merely fulfilling the obligation to provide information in a formal manner is not sufficient and emphasized that data subjects must be effectively informed about data processing activities. According to the Decision:

“... Where the processing of personal data is carried out on the basis of explicit consent, the information notice and the explicit consent text should be prepared as separate documents under distinct headings;

... Clear, comprehensible, and plain language should be used in the texts; general, ambiguous, incomplete, misleading, or inaccurate information should not be included;

Overly detailed, complex, and lengthy texts should not be used;

The personal data processed and the categories of such data, together with the purposes and legal basis of the personal data processing activity, should be stated clearly and explicitly under the information notices.” [3]

In line with this Decision, mobile application developers are required, as a matter of the transparency principle under the Personal Data Protection Law Nr. 6698, to prepare information notices that users can readily understand, rather than lengthy and complex texts.

3.2. Ensuring Data Security

Pursuant to Article 12 of the Personal Data Protection Law Nr. 6698, the data controller is obliged to take all necessary technical and administrative measures to prevent the unlawful processing of and access to personal data and to ensure the secure retention of personal data. Accordingly, location data must be stored securely, unauthorized access must be prevented, access privileges must be restricted, and the necessary security measures must be implemented against potential data breaches.

The Personal Data Protection Board has also emphasized in various decisions that data security is not limited to establishing a technical infrastructure, and that data controllers are also required to take appropriate organizational measures. Indeed, in several of its decisions concerning personal data breaches, the Board has imposed administrative sanctions on data controllers that failed to implement the necessary security measures. This demonstrates that data security constitutes not only a technical but also a legal obligation.

3.3. Deletion, Destruction, and Anonymization of Personal Data

Pursuant to Article 7 of the Personal Data Protection Law Nr. 6698, where the reasons requiring the processing of personal data cease to exist, the data controller is obliged to delete, destroy or anonymize such data ex officio or upon the request of the data subject.

In the context of mobile applications, this obligation is particularly significant with regard to location data. Indefinitely retaining location information obtained for the purpose of providing a service after that purpose has ceased is incompatible with the fundamental principles set forth under the Law. Accordingly, data controllers are required to establish personal data retention and destruction policies and to destroy, without any undue delay, personal data for which the purpose of processing has ceased to exist.

The “Guideline on the Deletion, Destruction or Anonymization of Personal Data” published by the Personal Data Protection Authority likewise establishes that data controllers are required to carry out these processes in a planned and auditable manner.

“The deletion of personal data is the process of rendering personal data completely inaccessible and unusable by the relevant users. The data controller is obliged to take any and all necessary technical and administrative measures to ensure that deleted personal data is inaccessible and unusable by the relevant users …

The destruction of personal data is the process of rendering personal data completely inaccessible, irretrievable and unusable by anyone in any manner. The data controller is obliged to take any and all necessary technical and administrative measures in relation to the destruction of personal data …

For personal data to be considered anonymized, the data must be rendered incapable of being associated with an identified or identifiable natural person, even through the use of appropriate techniques, having regard to the recording medium and the relevant field of activity, such as reversing the anonymization process by the data controller or recipient groups and/or matching the data with other data. The data controller is obliged to take any and all necessary technical and administrative measures to anonymize personal data. The anonymization of personal data shall be carried out in accordance with the principles set forth in the personal data retention and destruction policy, using the following methods.” [4]

Thus, the aim is to prevent personal data from being retained for longer than necessary and thereby to protect the private lives of data subjects.

4. Consequences of the Unlawful Processing of Location Data

Where location data processed through mobile applications is unlawfully obtained, processed or disclosed to any third parties, data controllers may incur administrative, civil and criminal liability. Given that location data may reveal extensive information concerning an individual’s private life, the unlawful processing of such data may give rise to various sanctions not only under the Personal Data Protection Law Nr. 6698, but also under the Turkish Code of Obligations and the Turkish Penal Code.

4.1. Administrative Liability

Article 18 of the Personal Data Protection Law Nr. 6698 sets forth the administrative sanctions that may be imposed where data controllers violate the obligations prescribed under the Law. Pursuant to this provision:

“ARTICLE 18- (1) Under this Law:

(a) Those who fail to fulfill the obligation to provide information prescribed under Article 10 shall be subject to an administrative fine ranging from TRY 5,000 to TRY 100,000;

(b) Those who fail to fulfill the obligations concerning data security prescribed under Article 12 shall be subject to an administrative fine ranging from TRY 15,000 to TRY 1,000,000;

(c) Those who fail to comply with the decisions issued by the Board pursuant to Article 15 shall be subject to an administrative fine ranging from TRY 25,000 to TRY 1,000,000;

(ç) Those who fail to comply with the obligation to register with and notify the Data Controllers’ Registry as prescribed under Article 16 shall be subject to an administrative fine ranging from TRY 20,000 to TRY 1,000,000;

(d) (Supplemented: 2/3/2024 – 7499/Art.35) Those who fail to fulfill the notification obligation prescribed under Article 9(5) shall be subject to an administrative fine ranging from TRY 50,000 to TRY 1,000,000.”

(2) (Amended: 2/3/2024 – 7499/Art.35) The administrative fines prescribed under subparagraphs (a), (b), (c) and (ç) of paragraph 1 shall be imposed on data controllers, whereas the administrative fine prescribed under subparagraph (d) shall be imposed on data controllers or natural persons and private-law legal entities acting as data processors.

(3) (Supplemented: 2/3/2024 – 7499/Art.35) An action may be brought before the administrative courts against administrative fines imposed by the Board.

(4) Where any of the acts specified in paragraph 1 are committed within public institutions and organizations or professional organizations having the status of public institutions, disciplinary proceedings shall be initiated, upon notification by the Board, against civil servants and other public officials employed by the relevant public institutions and organizations, as well as persons employed by professional organizations having the status of public institutions, in accordance with the applicable disciplinary provisions, and the outcome thereof shall be notified to the Board.”

In particular, administrative fines may be imposed on data controllers where they fail to fulfill the obligation to provide information, fail to take the necessary technical and administrative measures concerning data security, or act contrary to decisions of the Board.

Accordingly, Decision, numbered 2021/361 and dated 13.04.2021, of the Personal Data Protection Board constitutes an important example with regard to data processing activities carried out through mobile applications. In the case at issue, the Board initiated an investigation after a bank sent promotional messages to a data subject through its mobile application without duly obtaining the data subject’s explicit consent. Following its examination, the Board rendered the following decision:

“... On the basis of the assessment that the data controller’s unlawful processing of personal data by sending promotional messages without duly obtaining the explicit consent of the data subjects demonstrated that the data controller had failed to take the necessary technical and administrative measures to ensure an appropriate level of security, as referred to in paragraph (1) of Article 12 of the Law;

Considering that the processing of the data subject’s personal data by the data controller for the purpose of sending promotional messages through mobile applications without duly obtaining explicit consent was unlawful, it was concluded that the data controller had failed to take the necessary technical and administrative measures to ensure an appropriate level of security within the meaning of paragraph (1) of Article 12 of the Law, and that accordingly, an administrative fine be imposed on the data controller pursuant to subparagraph (b) of paragraph (1) of Article 18 of the Law;

Furthermore, the data controller be instructed to arrange the processes of the mobile applications under its control in such a manner as to ensure that explicit consent could be duly obtained, and the Board be informed of the outcome of this process.” [5]

The aforementioned decision demonstrates that, in the context of mobile applications, obtaining users’ explicit consent for the processing of their personal data alone is not sufficient; data controllers are also obliged to design their data processing processes in compliance with the Personal Data Protection Law Nr. 6698 and to take any and all necessary technical and administrative measures.

4.2. Civil Liability

The unlawful processing of personal data may also give rise to the data controller’s liability under private law. Pursuant to Article 11 of the Personal Data Protection Law Nr. 6698, data subjects may, upon learning that their personal data have been unlawfully processed, request the rectification or deletion of such data, as well as compensation for any damage they have suffered. In addition, claims for pecuniary and non-pecuniary damages may be brought under the provisions of the Turkish Code of Obligations concerning tortious acts. Indeed, in its judgment, 13.02.2025, and bearing the Basis number 2022/3953 and the Decision number 2025/2404, the 4th Civil Chamber of the Court of Cassation emphasized that damages arising from the unlawful processing of personal data may be compensated under the general provisions of law.

“The PDPL has refrained from introducing specific provisions concerning the compensation of damages arising from the unlawful processing of personal data and has instead opted to refer to the general provisions by expressly preserving the right to compensation of persons whose personality rights have been infringed. In this context, Article 11/ğ of the PDPL, which sets forth the rights of data subjects, provides that data subjects have the right to request compensation for damages arising from the unlawful processing of their personal data. Furthermore, Article 14/3 expressly provides that the right to compensation of persons whose personality rights have been infringed is reserved in accordance with the general provisions of law. Accordingly, it follows that the PDPL makes reference to the provisions of the Turkish Civil Code concerning the protection of personality rights. The PDPL does not distinguish between pecuniary and non-pecuniary damages. Although the Turkish Civil Code does not contain a provision directly concerning the protection of personal data, given that personal data overlap with personality values and fall within the scope of protection afforded to personality rights, the provisions of the Turkish Civil Code protecting personality rights shall also apply to the protection of personal data.” [6]

In particular, the disclosure of location data to any third parties or its use for purposes other than those for which it was collected, without the data subject’s knowledge or a valid legal basis, may constitute an infringement of personality rights and consequently give rise to the data controller’s liability for damages. Accordingly, data controllers must carry out data processing activities not only in compliance with the formal requirements of the Law but also in accordance with the general principles of law concerning the protection of personality rights.

4.3. Criminal Liability

The unlawful processing of personal data may, in certain circumstances, constitute a criminal offense under the Turkish Penal Code. Accordingly, particular importance should be attached to the offense of recording personal data set out under Article 135 of the Turkish Penal Code, the offense of unlawfully giving or obtaining personal data set out under Article 136, and the offense of failing to destroy personal data set out under Article 138.

Indeed, in one of its judgments, the 12th Penal Chamber of the Court of Cassation made the following assessment concerning the unlawful disclosure of personal data:

“... Given that the provisions concerning the protection of personal data under Articles 135 and 136 of the Turkish Penal Code contain no provision limiting such protection solely to personal data of a confidential nature, and, conversely, that the reasoning of Article 135 states that any information relating to a natural person should be regarded as personal data, the acts of unlawfully giving, disseminating, or obtaining any personal data constitute the offense of unlawfully giving or obtaining personal data under Article 136 of the Turkish Penal Code. Accordingly, personal information that is known to the public and/or readily accessible and knowable by anyone is also regarded as ‘personal data’ within the meaning of law. However, in order to prevent the scope of application of the offense of unlawfully giving or obtaining personal data from being expanded beyond its intended purpose, thereby resulting in uncertainty in practice and the undesirable consequence of virtually every act constituting a criminal offense, a careful assessment must be made in light of the circumstances of the specific case. It must be determined whether there is any ground of justification recognized under any branch of law or any other circumstance that may be taken into consideration in this context, and it must also be established that the perpetrator knew or was in a position to know that her/his conduct was unlawful.” [7]

This approach of the Court of Cassation demonstrates that the unlawful transfer or dissemination of location data obtained through mobile applications to any third parties may also give rise to criminal liability. Accordingly, it is of great importance that data controllers act in compliance not only with the provisions of the Personal Data Protection Law Nr. 6698, but also with the provisions of the Turkish Penal Code concerning the protection of personal data.

5. Conclusion

Location data processed by mobile applications has become an integral part of digital life as a natural consequence of technological developments. Nevertheless, the fact that location data may reveal extensive information concerning an individual’s daily life, habits, and private life renders the processing of such data particularly significant from the perspective of personal data protection law. Therefore, in the processing of location data, a balanced approach must be adopted that reconciles the protection of individuals’ fundamental rights and freedoms with technological developments.

The Personal Data Protection Law Nr. 6698 imposes significant obligations on data controllers to ensure the lawful processing of personal data. In particular, fulfilling the obligation to provide information, taking any and all necessary technical and administrative measures, and deleting, destroying or anonymizing personal data for which the purpose of processing has ceased to exist are among the fundamental obligations that data controllers are required to fulfill. Decisions of the Personal Data Protection Board and judicial precedents further demonstrate that these obligations must be fulfilled not merely as a matter of form, but effectively and in practice.

On the other hand, the unlawful processing of location data does not merely result in administrative fines; depending on the circumstances of the specific case, it may also give rise to liability for damages and criminal sanctions. This makes it necessary for data controllers, when fulfilling their obligations concerning the protection of personal data, to take into account not only the provisions of the Personal Data Protection Law Nr. 6698 but also the practice shaped by judicial decisions.

In conclusion, with the increasing prevalence of mobile applications, legal disputes concerning the processing of location data are also expected to increase. In this process, it is of great importance that data controllers conduct their data processing activities in accordance with the principles of lawfulness, proportionality, transparency, and data security, while users act consciously with regard to their rights over their personal data. In this way, it will be possible both to make effective use of the opportunities offered by digital technologies and to ensure the effective protection of the right to the protection of personal data guaranteed by the Constitution and the Personal Data Protection Law Nr. 6698.

Ceren Nur Aplak, Law Student Intern

References:

1. The Personal Data Protection Authority’s Guide: “Recommendations for the Protection of Privacy in Mobile Applications”

2. European Court of Human Rights, Application No. 35623/05, Uzun v. Germany, Date of Judgment: 02.09.2010

3. Principle Decision, numbered 2026/347 and dated 18.02.2026, of the Personal Data Protection Board

4. The Personal Data Protection Authority’s “Guideline on the Deletion, Destruction or Anonymization of Personal Data”

5. Decision, numbered  2021/361 and dated 13.04.2021, of the Personal Data Protection Board

6. Decision, bearing the Basis number 2022/3953, the Decision number 2025/2404 and dated 13.02.2025, of the 4th Civil Chamber of the Court of Cassation

7. Decision, bearing the Basis number 2019/12886, the Decision number 2020/513 and dated 15.01.2020, of the 12th Penal Chamber of the Court of Cassation

MAKALEYİ PAYLAŞIN
MAKALEYİ YAZDIRIN