Tales Event

Guide · 8 min read

Is Event Photography Legal Under Turkey's KVKK? Consent, Notices and the 2026 Rule Change

Short answer: yes, on two conditions. If a guest's face is recognisable in the frame, that image is personal data under Turkey's Law No. 6698, and if you plan to publish it on social media, in an aftermovie or in corporate communications, you need explicit consent, because the other processing grounds in Article 5 rarely cover a marketing purpose. The second condition has nothing to do with consent: the duty to inform applies in every case, at the moment the data is collected, and there is no exemption from it. The procedure changed in 2026. The Personal Data Protection Board's principle decision dated 18 February 2026 and numbered 2026/347 was published in the Official Gazette on 24 March 2026, and it explicitly bans presenting the privacy notice and the consent text in the same content, nested together or under a single approval. So the one-page form your registration desk has used for years is probably no longer compliant. Below: when a photograph counts as personal data, when explicit consent is required, what the new principle decision means in practice, a workable setup for the registration desk, speaker and employee consent, facial recognition check-in, the clauses for your photographer's contract, retention periods and the 2026 fine levels.

Is an event photograph personal data?

Article 3 of Law No. 6698 defines personal data as any information relating to an identified or identifiable natural person. A frame in which a guest's face is recognisable sits right in the middle of that definition. The Board settled the question in its decision dated 27 April 2021 and numbered 2021/422: a data controller who kept publishing a former employee's photographs on a company social media account was found to have relied on no lawful processing ground, an administrative fine was imposed under Article 18(1)(b), and the Board ordered the images taken down and properly erased. Recognisability is the dividing line. A wide shot taken from above a ballroom where nobody can be picked out is one thing, a portrait of the front row is another. Do not underestimate the volume either. At a 600-guest gala, a photographer produces hundreds of recognisable frames in one night, and every one of them joins the pile of data you are answerable for.

Do you need explicit consent, or will another ground do?

Article 5(2) lists the grounds that remove the need for explicit consent: an express provision in law, necessity for the performance of a contract, a legal obligation of the data controller, the establishment of a right, legitimate interest and a few others. Event photography rarely passes through any of them. Keeping a guest list is contract performance, but publishing a guest's portrait on a brand's social account is marketing, and in most cases the legitimate interest balance tips towards the individual's fundamental rights. That is why explicit consent is the working rule for anything you intend to publish. Article 3 defines it as consent relating to a specific matter, based on information and expressed with free will. Miss any of the three and the consent is invalid. The Authority has also stated publicly that a service cannot be made conditional on explicit consent, so turning away a guest who declines, or excluding them from the prize draw, undermines the consent you collected. One point causes regular confusion. Article 86 of the Law on Intellectual and Artistic Works treats pictures showing general gatherings that the depicted people attended as an exception to the consent requirement. That exception belongs to its own regime and does not cancel your obligations under Law 6698. The two run in parallel.

What changed on 24 March 2026?

The Board's principle decision dated 18 February 2026 and numbered 2026/347 was published in the Official Gazette on 24 March 2026, and it goes straight at the most common mistake in the field: bundling the privacy notice and the consent text into one document with a single tick box. Here is what it requires of data controllers. The duty to inform must be discharged on its own, before processing begins, whichever processing ground you rely on. Where processing rests on explicit consent, the notice and the consent text must be drafted as separate documents under different headings; if both appear on the same page, they must sit one below the other with their own headings and their own statements. Where the legal basis is not explicit consent, no consent text is presented at all, only the notice. For the notice you may collect confirmation that it was read, but not approval of its content, which is why the wording on the form should be read and understood rather than I approve. Texts must not be copied from other controllers; they are written for the organisation's own activity, in clear, plain, straightforward language, and kept from becoming excessively long or complex. The categories of data processed, the purposes and the legal basis must be stated openly. Non-compliance is assessed under Article 18.

How do you actually collect consent at the registration desk?

The workable setup has three parts. Visibility first: put the notice at the entrance, somewhere a guest can read it while checking in, in a legible size. A board behind the registration desk, a QR code on a screen and a printed copy on the table work well together. Then the separate form: under the new principle decision, consent for filming and publication needs its own heading and its own signature field, apart from the notice. Then a colour code: give guests who consent to being photographed one colour of lanyard or wristband and those who decline another, and walk the crew through the difference during the briefing. Define a camera-free area as well. Declare one part of the room off limits for filming, mark it with signage, and mention that the area exists in the notice at the entrance. The burden of proof is yours, so file the forms properly after the event. If you cannot show which guest read which text on which date, you have not discharged the duty to inform.

What about speakers, employees and the live stream?

A consent form is the wrong instrument for a speaker on stage. Write into the speaker agreement which channels the audio and video recording will be used in and for how long; this is a contractual relationship and its scope is set in advance. Employees are a separate matter. The Board has stressed that in employment relationships, where the parties are not equally placed and a power imbalance exists, an employee cannot be said to have a genuine choice, so the consent cannot be treated as freely given. If you plan to publish photographs from the year-end party on corporate accounts, an employee who declines needs a real no with no consequences attached. On a live stream you cannot pull the recording back. Build the camera plan around your consent setup: shoot the room from angles that keep the camera-free area out of frame, reduce facial detail in crowd shots, and check every framing during a rehearsal pass before you go live. If the stream will be archived and reused afterwards, say so in the notice.

What changes if you install facial recognition check-in?

Systems that promise faster entry through facial recognition are doing the rounds at corporate events. The legal threshold rises here. According to the Authority's guidance on processing biometric data, what matters is not the image itself but how it is processed. A photograph printed on a badge is ordinary personal data; the same photograph processed through technical means that single out an individual and used for matching becomes biometric data and falls under the special category regime in Article 6. In that regime explicit consent is the rule, the security measures are heavier and a breach costs more. For a 500-guest event there are far cheaper ways to shorten the queue: QR coded invitations, alphabetical desk allocation, extra registration staff. If a client genuinely wants facial recognition, put the decision to your legal team in writing and ask the vendor to document where the system stores its template data.

Photographer, agency and cloud: what belongs in the contract?

In this relationship the photographer or production agency is the data processor and the brand is the data controller. Article 12(2) is direct about it: where personal data is processed by another natural or legal person on the controller's behalf, the controller is jointly liable with that person for putting the security measures in place. If the photographer's drive is stolen, the bill reaches the brand too. Put these clauses in the contract: where the raw files are stored and for how long, deletion after delivery, whether the photographer may use the material in their own portfolio, subcontractor use subject to approval, and the notification deadline to the brand in case of a breach. The cloud is its own line item. Uploading images to a storage or sharing service whose servers sit abroad is a transfer abroad. Article 9, as amended by Law No. 7499 and in force since 1 June 2024, provides the standard contract as one of the appropriate safeguards, and Article 9(5) requires the standard contract to be notified to the Authority within five working days of signature. Decide in the contract who files that notification.

How long do you keep the images, and what does a breach cost?

The purpose sets the retention period, and the period has to be written down. The Regulation on the Deletion, Destruction or Anonymisation of Personal Data was published in the Official Gazette on 28 October 2017; for controllers that maintain a retention and destruction policy it caps the periodic destruction interval at six months and requires records of destruction operations to be kept for at least three years. If a guest asks for an image to be removed, Article 11 gives them that right and Article 13 requires the request to be resolved within thirty days at the latest. When a request lands, the social account is not the only place to look: the aftermovie edit, presentation decks, press release attachments and the agency archive are all on the list. The numbers carry weight too. After the 25.49 per cent revaluation rate announced in General Communiqué No. 585 on the Tax Procedure Law, published in the Official Gazette on 27 November 2025, the 2026 fine for failing to discharge the duty to inform runs from 85,437 TL to 1,709,200 TL, and the fine for failing to meet data security obligations runs from 256,357 TL to 17,092,242 TL. According to the Authority's 2025 activity report, it received 12,512 complaints and reports that year, was notified of 328 data breaches, and imposed roughly 352.5 million TL in administrative fines on 876 data controllers. Before event day, tick off five lines: notice posted at the entrance and a separately headed consent form on the desk, lanyard colours defined for consent status, camera-free area marked with signage, crew and stream director briefed, data processor clauses signed with the photographer. Tales Event is based in Istanbul and runs stage, sound, lighting, LED screen and video production with a single team for dealer meetings, launches, openings, gala nights and graduation ceremonies across Turkey; we set up the registration flow and the filming plan together from the start. Send us the event date, the guest count and where you plan to publish the images, and we will map the flow from the registration desk to publication day.

Let's talk about your event

Tell us your idea and we will prepare the concept and quote.