

The unauthorized collection of DNA or fingerprint data is a serious breach of fundamental rights under both Turkish law and international human rights standards. In Turkey, the right to personal data protection is enshrined in Article 20 of the Constitution and regulated in detail by the Law on the Protection of Personal Data (KVKK – Law No. 6698). Collecting biometric data such as DNA or fingerprints without legal grounds, consent, or judicial authorization may amount not only to a violation of privacy but also to an unlawful act giving rise to a claim for compensation. This issue is particularly significant in criminal investigations where individuals are sometimes subjected to forensic procedures without a proper warrant or where consent is obtained under coercive circumstances. The Turkish Criminal Procedure Code (CMK) sets out strict requirements under Articles 75 to 81 for biological sampling and identification, including judicial oversight and relevance to the investigation. If these conditions are not met, the collection is deemed illegal, and any evidence obtained may be excluded. More importantly, the victim may initiate a civil claim under the Turkish Code of Obligations for pecuniary and non-pecuniary damages, citing harm to personal dignity, emotional distress, and reputational damage. Furthermore, victims can also lodge a constitutional complaint under Article 20 (right to privacy) and Article 36 (right to a fair trial) if their biometric data was mishandled by public authorities. For cases where domestic remedies are ineffective, applications can be submitted to the European Court of Human Rights based on violations of Article 8 (right to respect for private and family life). Courts have previously ruled that invasive data collection without legal justification constitutes a violation of human dignity and autonomy. Individuals subjected to unauthorized fingerprinting or DNA swabbing should keep all documentation, including the lack of a warrant or consent form, and seek legal advice immediately to preserve their rights. Additionally, complaints can be filed with the Turkish Data Protection Authority (KVKK Kurumu), which may impose administrative fines and order data erasure.
Biometric data refers to personal data resulting from specific technical processing relating to the physical, physiological, or behavioral characteristics of an individual that allows or confirms their unique identification. Under the Turkish Personal Data Protection Law (KVKK), this includes DNA profiles, fingerprints, retinal scans, and voice patterns. These data types are categorized as “sensitive personal data” and are afforded the highest level of legal protection. Article 6 of KVKK clearly mandates that the processing of sensitive data is prohibited unless expressly permitted by law or based on the explicit consent of the data subject. In criminal investigations, fingerprints and DNA can only be collected with judicial approval or under strict statutory exceptions. Unauthorized collection—even by state authorities—may lead to serious legal consequences, including exclusion of evidence, administrative fines, and liability for damages. In addition, the Constitution protects individuals against arbitrary interference in their private lives. Therefore, any attempt to collect or retain biometric data without lawful authority constitutes a breach of fundamental rights and lays the foundation for compensation claims under both civil and administrative law.
The collection of biometric data becomes unlawful when it occurs without legal basis, informed consent, or judicial authorization. For instance, if a police officer collects a fingerprint sample without a court order in a non-urgent situation, this may constitute a violation of the legal safeguards under the Criminal Procedure Code (CMK). Moreover, the absence of proper documentation, such as a signed consent form or warrant, undermines the legitimacy of the process. The Personal Data Protection Authority (KVKK Kurumu) has issued guidance clarifying that biometric data must only be collected where strictly necessary and proportionate to the purpose intended. In practice, this means that if DNA or fingerprint evidence is gathered when less intrusive means would suffice—or if the person is not a suspect but merely a witness or complainant—the collection may be unlawful. Even in criminal investigations, Article 75 CMK requires clear procedural steps, and failure to follow them can be challenged through legal remedies. Victims of such unauthorized actions are entitled to initiate legal proceedings for compensation, especially when the breach has caused emotional harm, reputational loss, or misuse of private data.
Consent plays a pivotal role in the lawful processing of biometric data. According to Article 5 and Article 6 of the KVKK, sensitive data—including DNA and fingerprint information—can only be processed with explicit and informed consent, unless there is a specific legal provision that overrides this requirement, such as a judicial order. This consent must be given voluntarily, in writing, and with full knowledge of how the data will be used, stored, and for how long it will be retained. In law enforcement settings, consent is often bypassed through court authorization, but in non-criminal contexts—such as employment or medical services—lack of valid consent may lead to a violation. It’s essential to note that consent obtained through intimidation or misunderstanding is not considered legally binding. Individuals who were misled into giving a fingerprint sample, or coerced into providing DNA, may have strong grounds for initiating claims. Courts will closely examine the nature of consent, especially where power imbalances exist, such as between a detainee and police officers. Thus, proving the absence of valid consent is a strategic legal route to assert one’s rights.
No, Turkish criminal procedure law prohibits the use of unlawfully obtained evidence in court. This principle, known as the “fruit of the poisonous tree doctrine,” is established in CMK Article 206 and 217, which prohibit courts from basing decisions on evidence that has been obtained illegally. If a DNA sample or fingerprint was collected without consent or legal authorization, the defense may request its exclusion. In fact, courts have repeatedly ruled that the admissibility of such evidence must be subject to rigorous scrutiny, especially when constitutional rights are at stake. This not only protects the fairness of criminal proceedings but also discourages authorities from circumventing legal safeguards. Moreover, the use of illegally obtained biometric data can be grounds for appeal or even retrial. A successful exclusion can significantly weaken the prosecution’s case and open the door to acquittal or dismissal of charges. Therefore, identifying and challenging unlawfully gathered biometric evidence is a powerful legal tool both for criminal defense and for pursuing civil compensation.
The psychological consequences of having one’s DNA or fingerprints collected without consent can be deeply distressing. Victims often report feelings of violation, anxiety, loss of autonomy, and mistrust toward law enforcement or institutions. In cases where individuals are wrongly associated with a crime due to unlawful collection, the reputational and emotional toll can be severe and long-lasting. This psychological trauma is compensable under Turkish civil law, particularly within the scope of non-pecuniary (moral) damages. Psychological evaluations and expert reports are often submitted during litigation to substantiate these claims. Moreover, courts take into account not just the nature of the act but also the broader social and personal context—such as whether the individual was stigmatized in their community, lost employment, or suffered depression as a result. Compensation for such emotional harm may range significantly depending on the severity and duration of the impact. Mental health should not be overlooked in legal evaluations of biometric rights violations, and claimants are encouraged to document all emotional effects when preparing their case.
Victims of illegal biometric data collection in Turkey can file a civil lawsuit for damages under the general provisions of the Turkish Code of Obligations (TCO), particularly Articles 49 and 58, which cover unlawful acts and moral damage, respectively. The lawsuit is typically brought before the Civil Courts of First Instance and must clearly outline the unlawful conduct, the harm suffered, and the causal link between the two. Evidence such as medical records, expert opinions, or media exposure resulting from the breach can strengthen the claim. The compensation may include both pecuniary losses—like legal fees, loss of income, or therapy costs—and non-pecuniary damages such as emotional distress. Courts evaluate the proportionality of the act, the culpability of the violator, and the extent of the personal harm. Victims must act within the statute of limitations: generally, two years from the date of learning of the breach, and ten years from the date of occurrence. Legal representation is strongly advised to navigate the procedural complexities and maximize the compensation amount.
Individuals whose biometric data has been collected without consent or legal authority have the right to file a formal complaint with the Turkish Personal Data Protection Authority (KVKK Kurumu). According to Article 13 of the KVKK Law, the complaint must first be submitted to the data controller—in this case, often a public institution like the police department or prosecutor’s office—within 30 days of learning about the violation. If no response is received within 30 days or the response is unsatisfactory, the individual can then file a complaint directly with the KVKK within 60 days. The petition should include a detailed description of the violation, supporting documents, and a clear request for investigation or remedy. The KVKK has the power to launch inspections, request documents, interview officials, and issue administrative sanctions, including fines or orders for the deletion of unlawfully obtained data. The complaint process is free of charge and can also serve as vital evidence in any parallel civil lawsuit for compensation. While the KVKK’s decisions can be appealed in administrative courts, most rulings tend to be protective of individual privacy, especially when biometric data is involved.
Under the KVKK Law No. 6698, the Turkish Data Protection Authority has the authority to impose significant administrative fines for violations involving unauthorized processing of sensitive data, including biometric information like DNA and fingerprints. Article 18 of the law outlines penalties ranging from tens of thousands to millions of Turkish Liras, depending on the severity, recurrence, and intent behind the violation. For example, if law enforcement agencies or private actors collect fingerprint data without consent, fail to ensure adequate data protection measures, or retain the data longer than legally permitted, the KVKK can impose fines and issue public reprimands. Additionally, institutions may be ordered to destroy unlawfully obtained data, update internal policies, and retrain staff on data privacy compliance. These sanctions are important not only as deterrents but also as a formal acknowledgment that a data breach has occurred, which can be used to support compensation claims in civil court. Victims are encouraged to request a copy of the administrative decision for their records and potential legal use.
In Turkey, the unauthorized collection, recording, or dissemination of personal data—including biometric data—may constitute a criminal offense under Articles 135 to 140 of the Turkish Penal Code (TPC). Those found guilty of illegally obtaining biometric data such as DNA or fingerprints may face criminal prosecution, which could result in imprisonment of one to three years, and additional penalties if the data was disclosed or sold. Public officials may also face increased penalties due to their breach of trust. Victims of such criminal acts can file a criminal complaint with the public prosecutor, requesting an investigation and, where applicable, criminal prosecution. If found guilty, perpetrators may also be ordered to pay compensation under separate civil proceedings. Criminal convictions can greatly strengthen the civil case for moral damages and set an important legal precedent. Moreover, where data breaches result in widespread harm or involve vulnerable individuals, prosecutors may open ex officio investigations even without a formal complaint from the victim.
When biometric data is illegally collected by public authorities—such as the police or intelligence services—individuals can initiate a full remedy lawsuit (“tam yargı davası”) before administrative courts in Turkey. These lawsuits aim to hold the public administration accountable for unlawful acts that infringe upon constitutional rights, particularly the right to privacy and data protection. The basis for such claims is found in Article 125 of the Turkish Constitution, which ensures judicial review of all administrative acts and the right to compensation. Claimants must demonstrate that the biometric data was collected without a legal basis, that damage was suffered (including emotional or reputational harm), and that there is a causal link between the two. These lawsuits must be filed within one year of learning about the violation and within five years of the act’s occurrence. Successful claimants may be awarded monetary damages and a formal acknowledgment of wrongdoing, which can help restore public trust and personal dignity. Legal representation is highly recommended due to the technical nature of administrative litigation.
Victims of biometric data violations may also apply to the Constitutional Court of Turkey through an individual application (bireysel başvuru). This legal mechanism, available since 2010, allows individuals to challenge violations of fundamental rights guaranteed under the Constitution, such as the right to privacy (Article 20) and the right to a fair trial (Article 36). To apply, the individual must first exhaust all ordinary legal remedies, such as filing a lawsuit or complaint with the relevant courts or the KVKK. The application must be submitted within 30 days of the final domestic decision. The Constitutional Court may rule that the individual’s rights were violated and may award non-pecuniary damages. More importantly, its decisions can serve as binding precedents, requiring systemic changes in how biometric data is handled by public institutions. Filing such a complaint not only benefits the individual applicant but can also lead to broader legal reforms. Applications can be filed electronically and typically require a detailed legal argument supported by documentation and case history.
The European Court of Human Rights (ECHR) has issued several rulings on the unlawful collection and retention of biometric data, providing a valuable legal framework for Turkish claimants. Under Article 8 of the European Convention on Human Rights, every individual has the right to respect for private and family life, which includes the protection of personal data. In the landmark case of S. and Marper v. the United Kingdom, the Court ruled that indefinite retention of DNA and fingerprint data from individuals not convicted of any crime constituted a violation of privacy. These rulings are binding on Turkey as a member of the Council of Europe. Individuals who have exhausted domestic remedies in Turkey and still feel their rights have been violated can apply to the ECHR within six months of the final decision. The Court may award compensation and order systemic changes in national legislation or practices. Thus, international human rights law plays a vital role in protecting against abuses of biometric surveillance and strengthens the legal options available to victims in Turkey.
Special legal protections apply when biometric data is collected from children, individuals with disabilities, or other vulnerable groups. The United Nations Convention on the Rights of the Child, to which Turkey is a signatory, emphasizes that children’s privacy and dignity must be protected at all times. Turkish law reflects this through stricter conditions on processing children’s personal data, especially in criminal investigations. Consent must be obtained from legal guardians, and data collection must be proportional and absolutely necessary. Moreover, the Turkish Constitutional Court has stressed in various rulings that the vulnerability of the data subject is a key factor when assessing whether a right was violated. If biometric data of a child or a mentally disabled person was collected without proper safeguards, courts are likely to award higher compensation and impose stricter scrutiny on the actions of the authorities involved. Legal practitioners handling such cases should highlight the vulnerability aspect in both factual and legal arguments
For individuals seeking to protect their biometric data from unlawful collection, there are several proactive legal steps to follow. First, always ask to see the legal basis for any request to collect fingerprints or DNA—this could be a warrant, a court order, or an informed consent form. Second, never sign consent forms under pressure and ensure you are given a copy for your records. Third, request information about how your data will be used, stored, and for how long, in accordance with KVKK principles. Fourth, if you suspect a breach, act quickly: file a complaint with the KVKK and consult with a lawyer to preserve evidence and meet filing deadlines. Fifth, consider submitting access and deletion requests under KVKK Article 11 to control how your data is managed. Finally, if your rights have been violated, don’t hesitate to pursue administrative, civil, and constitutional remedies. Taking these steps not only protects your individual rights but also contributes to greater accountability and transparency in data processing across Turkey.
For more detailed information and legal assistance, FFK Partner Law Firm provides you with professional support!