Principle Decision Published On The Verification That Each Transaction Conducted Under Loyalty Card Programmes Belongs To The Relevant Data Subject

In its Principle Decision dated 11 February 2026 and numbered 2026/266, published in the Official Gazette No. 33182 dated 28 February 2026, the Personal Data Protection Board (the “Board”) has set out the principles and procedures to be observed in order to prevent the use, during retail transactions, of a loyalty card holder’s mobile telephone number or loyalty card number by unauthorised third parties.

  1. Factual Background Underlying the Principle Decision

The factual matrix underpinning the Principle Decision concerns the operation of loyalty card schemes administered by various data controllers across different sectors. In the case at hand, a third party was able to complete a purchase by providing, at the point of sale, the mobile telephone number belonging to the relevant data subject who held the loyalty card membership. The transaction recorded against the loyalty account was processed by the cashier without the entry of any transaction verification or approval code into the system.

Notwithstanding that the relevant data subject was not physically present at the checkout, and neither informed of nor consenting to the transaction, the data controller enabled the use of the data subject’s personal data—namely, their mobile telephone number—by a third party for the purposes of effecting a purchase through the loyalty card account. Furthermore, the invoice and related documentation pertaining to the transaction were issued in the name of the relevant data subject.

  1. Legal Issue Identified in the Principle Decision

In its Principle Decision, the Board identified the following legal issues:

  • The completion of a purchase in the name of the relevant data subject, by a third party disclosing at the checkout the data subject’s mobile telephone number or loyalty card number without the data subject’s knowledge or consent, cannot be justified on the basis of any of the data processing conditions set out under Article 5 of the Law on the Protection of Personal Data (the “Law”). Such practice therefore gives rise to unlawful processing of personal data.
  • The issuance of an invoice or similar documentation in the name of the relevant data subject in respect of a transaction not carried out by the data subject personally, and of which the data subject had neither knowledge nor consent, together with the recording of customer transaction data (such as the store location, date of purchase, and products acquired) in the data subject’s records or membership account by reference to the data subject’s mobile telephone number or loyalty card number, constitutes processing in breach of the principle of “accuracy and, where necessary, up-to-dateness” enshrined in Article 4 of the Law.
  • Although data controllers may, under the terms of the loyalty card membership agreement, impose upon members an obligation not to permit third parties to use a loyalty card issued for their personal use, such contractual allocation of responsibility does not absolve the data controller from its statutory obligation under Article 12 of the Law to ensure the security of personal data in the course of its processing activities.
  1. Obligations to be Observed by Data Controllers pursuant to the Principle Decision

In its Principle Decision, the Board set out the procedures and principles with which data controllers operating loyalty card programmes are required to comply. These may be summarised as follows:

  • The immediate discontinuation of any practice deemed unlawful under the Law whereby a purchase may be completed through a loyalty card account merely by a third party communicating the relevant data subject’s mobile telephone number or loyalty card number to the cashier, without the data subject’s knowledge or consent.
  • The adoption of the necessary technical and organisational measures, as required under Article 12 of the Law, in order to ensure that personal data processing activities relating to transactions carried out via loyalty card programmes are conducted in compliance with the Law.
  • The establishment of appropriate verification mechanisms by data controllers to ensure that a loyalty card holder’s mobile telephone number or loyalty card number is authenticated not only at the time of enrolment in the loyalty programme, but also whenever the loyalty card is used for any other purpose (including, without limitation, the accrual or redemption of points, or the benefit of discounts and promotions). Such mechanisms may include, inter alia:
  1. the communication to the cashier of a one-time verification code sent by SMS to the data subject’s registered mobile telephone number;
  2. the scanning at the point of sale of a barcode or QR code generated via the relevant mobile application or website;
  • the physical presentation and/or scanning of the loyalty card at the checkout;
  1. the entry of the loyalty card password into the transaction device at the point of sale; and
  2. in circumstances where the loyalty card is linked to an online membership account created within the scope of the loyalty programme, the provision to data subjects of an express “opt-in” mechanism enabling them to determine which specific transactions (such as the accrual of points, the use of points, or the benefit of discounts or promotions) may be carried out at the time of purchase solely upon the communication of their mobile telephone number.
  3. Compliance Period

The verification mechanisms in question must be duly implemented by data controllers within a period of six (6) months from 28 February 2026, being the date of publication of the Principle Decision.

  1. Conclusion and Summary

By virtue of the Principle Decision, data controllers operating loyalty card programmes are required to establish mechanisms capable of evidencing that, not only at the point of enrolment but in respect of every transaction in which a membership number or mobile telephone number is used, the individual utilising such number is indeed the lawful holder thereof.

Accordingly, the practice of processing transactions solely on the basis of the provision of a membership number or mobile telephone number, without any supplementary authentication measure, must be discontinued without delay.

Data controllers are afforded a period until 28 August 2026 to design and implement the requisite verification mechanisms.

Related persons
You can contact us for detailed information.

Profile Card
Profile Photo

Tolga Poyraz

Partner

ÇEREZ POLİTİKASI
Hello there
Hello there
Hello there
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI
ÇEREZ POLİTİKASI