Knowledge Commons
HomeAboutGuidesPopularContact

The Aydo Software Operation

The Anatomy of a Union Software and What Ought to Be, Through a Computing Worker's Eyes

Author: Oğuz Demirkapı
The Aydo Software Operation

Whose Hands Hold the Membership List? The Aydo Software Operation, the Anatomy of a Union Software and What Ought to Be, Through a Computing Worker's Eyes

Dear Young Comrades,

Look closely at this figure: 2,000,000+.

This figure is not from an intelligence report, it is from a company's own promotional page. Aydo Yazılım, in Ankara, boasts of "25+ unions," "175+ KVKK-consultancy clients," "500,000+ mobile-app users" and "2,000,000+ people managed." That is, the membership records of the great majority of unionised public-sector workers in Turkey pass through a single private company's software.

On the morning of 16 September 2026 MİT, the Cybersecurity Presidency and the Gendarmerie ran a joint operation on this company. Five people, including the company owner, were detained; computers, phones and digital material were seized at homes and workplaces (BirGün, Diken). The allegation is this: a "special query interface" had been embedded in the software sold to unions, through which even citizens who were not members could be queried by Turkish ID number; the data being queried is not pulled live from the state's system, it comes from data sets leaked onto the internet years ago; and there are people under the age of eighteen in the records.

In this piece we will ask three questions:

  1. Whose hands held the union members' data? The union's, the company's, or now the state's?
  2. What was the "query interface" querying, and where did that data come from?
  3. How does a KVKK consultant turn into a data seller?

And a fourth, the real concern of this piece: through a computing worker's eyes, how ought this work to have been done? Because the affair will be told as a "scandal" and passed over; yet there is a technical structure here, and until that structure changes the next Aydo is already ready.

Six days ago, when we discussed KVKK's "80s Trend" warning, we wrote that in the same week 31 lawyers had been detained for using a "query panel," and said "the right address of the problem is the data of ours in the state's hands." This piece is the continuation of that one: there we looked at the state's data, here we look at the union's. You will see the two meeting in the same Telegram channel.


Chronology: One Morning, Three Institutions, Five Detentions

4 September 2026. 31 lawyers were detained on the allegation that, with query panels named "HukukBİS" and "AsistBİS," they had queried people for whom they had no power of attorney and sent blackmail messages (Euronews Turkish).

10 September. KVKK told the citizen "read the permissions when you upload an '80s photograph."

16 September. Operation on Aydo Yazılım, coordinated by MİT. According to the official narrative the findings are these (Sabah): a "special query interface making it possible to access information belonging to third parties who are not union members" had been added to the union software; old data sets leaked onto the internet could be queried through this interface; queries by Turkish ID number returned population records; the system logs carry the label "NVİ" (Directorate of Population and Citizenship Affairs) but the data had not been taken directly from that system; there are people under eighteen in the database. The company also gives KVKK consultancy to institutions under the name "Clock&Wise."

The same day, in the afternoon. Türkiye Kamu-Sen announced that it had "no contract, commercial relation, software-service agreement or institutional tie with the company, past or present" (Memurlar.net). Memur-Sen confirmed that it worked with the company; but said "it is technically and legally impossible for any person, institution or organisation to access the data held within our unions" and stated that the data was verified through a protocol with Population and Citizenship Affairs (İz Gazete). Eğitim Sen announced that it had taken service from this company "for many years, like a great many unions"; said "there is no verified finding that our members' personal data was obtained unlawfully or shared with third parties," and added that a technical and legal examination was continuing (BirGün).

One day. Three institutions. Five detentions. And two million people.

At the time this piece is being written the prosecutor's statement is not known, nor which unions used the interface to what extent, why non-members were queried, or how many people's data in total was queryable. The headline circulating in the press, "2 million civil servants' data stolen," is not a verified finding; it is the company's own advertising figure translated into news language. Distinguish this: the number of people the company manages and the number of records leaked are not the same thing. But do not forget that the two sat on the same server.

Who Is the Company, Who Is the Client: Read the Reference List

The company's own references page is the class map of this affair. The unions named on the page are these (it is the company's own declaration; some of the unions have confirmed the relation, some have not yet issued a statement):

  • Affiliated to Memur-Sen: Eğitim-Bir-Sen, Sağlık-Sen, Diyanet-Sen, Büro Memur-Sen, Bem-Bir-Sen, Birlik Haber-Sen, Toç Bir-Sen, Kültür Memur-Sen, Ulaştırma Memur-Sen, Enerji Bir-Sen, Bayındır Memur-Sen, Emekli Memur-Sen.
  • Affiliated to KESK: Eğitim Sen, SES, Tüm Bel-Sen, Kültür Sanat-Sen.
  • Affiliated to Birleşik Kamu-İş: Eğitim-İş.
  • Others: Hürriyetçi Eğitim Sen, Türk Harb-İş, Öz Orman-İş, Sağlık Mil-Sen, Yeni Sendika.

Kamu-Sen's "we have no relation" statement is consistent with the list; none of that confederation's unions is on the page. Look at the rest: according to the Ministry of Labour's July 2026 figures Memur-Sen has 1.13 million members, Birleşik Kamu-İş 199 thousand (Genç Gazete). Add KESK's hundreds of thousands of members. The company's "2 million+" figure is not an exaggeration; if anything it is short.

See one thing clearly here: the confederation close to the government, the opposition confederation and the secular-national union are all using the same company's same software. The membership lists of unions that are politically enemies of one another were sitting on the same server, in the same database engine, behind the same administrator's password. For an employer, a ministry or a data merchant there is no more valuable picture than this: which teacher is in which union, which nurse in which confederation, who last year moved from which union to which.

And look at the company's other line of work: KVKK consultancy. A firm giving more than 175 organisations a lesson in "how you protect your personal data" was, according to the allegation, at the same time running a query service over leaked population data. That the watchman and the thief are the same person is not an exception; in this sector it is the business model. Whoever knows the data best sells the data best. We said this of Palantir as well; here the scale is small, the logic is the same.

What Is a "Query Interface"? In a Computing Worker's Account

Young comrades, newspaper language says "query interface" and moves on. Let us open it a little, because we cannot talk about what ought to be without understanding the mechanism.

A union membership-tracking software has a legitimate need: to verify that the identity number written on the membership form belongs to a real person and that the name and surname match. For this, public institutions and authorised bodies are given a right of query through the Identity Sharing System (KPS); this is the "protocol with NVİ" in Memur-Sen's statement. A correctly designed verification works like this: you send the identity number and the name, the system says "yes, they match" or "no." No data comes back, no data is copied, a log record remains in the system.

Now look at the structure in the allegation. There is a data source labelled "NVİ," but the data is not coming from the live system; it is coming from a table sitting on the company's own server. In that table, when an identity number is entered, forename, surname, mother's and father's names, place and date of birth, and address come back. Non-members come back as well. Eighteen-year-olds come back as well. Everyone in Turkey who works with computing knows what that table is: the MERNİS copy that dropped onto the internet in 2016 and the leaks stacked on top of it in later years. The basic identity data of about 50 million citizens has been circulating as a file since that day; query panels are nothing more than putting a search box on top of that file. We told this at length in the KVKK piece.

So the "query interface," technically, is a search screen put on top of a leaked database. The difference is where it sits: the same panel that is sold on Telegram for a monthly subscription, this time inside a union's management software, under the name "population integration," behind a legitimate button.

Think what this button is for at the union desk. A union officer types the identity number of a teacher who is not yet a member; sees the address, the date of birth, the mother's and father's names. A "convenience" for organising work. A "convenience" for the details of a rival union's workplace representative. A "convenience" for learning who is who at the workplace. The user may not know that this is stolen data; the screen says "NVİ," it looks official. The leak is legitimised by the interface. That is the real danger: when unlawful data becomes part of a lawful workflow, no one sees it as unlawful.

The best hiding-place for stolen data is not the dark web, it is the menu of a legitimate software.

Why Union Data Is Not Ordinary Data

Article 6 of Law No. 6698 counts "trade-union membership" as special-category personal data; in the same category as health data, biometric data and political opinion. This is not an accident. Union-membership information has three customers, and all three stand opposite the worker.

The employer. An employer who knows which employee is in which union draws up the dismissal list, the promotion list, the exile list accordingly. For the public-sector worker the "employer" is the ministry; the provincial directorate; the head teacher. Teachers know how the pressure to change union works in Turkey: "move to that union, your posting will come through."

The state. Public-sector unions already notify membership lists to the Ministry; but notification is one thing, and the whole of membership movements, dues flow, meeting attendance and mobile-app use sitting on a single server is another. And today that server, by reason of the operation, is in MİT's hands. We will talk about this separately in section 6.

The rival union and the data merchant. Competition among unions in Turkey is hard and intertwined with the state. Who is a member at which workplace, who has resigned, who is undecided: this information has many buyers.

That is why a union's membership list is not the union's cash-box, it is the union itself. When a strike fund loses money it is renewed; when the membership list passes into the employer's hands the union is finished at that workplace. What Marx called "the combination of the workers" is, in the concrete, the knowledge of who stands in the same rank with whom; if this knowledge is in the enemy's hands, the combination has been dispersed before it was even formed.

Risks Through a Computing Worker's Eyes: Eight Structural Faults

Now we come to the real subject. This affair will be told as a "bad company" story. Yet when you look as a computing worker, the structure that produced this result is made of eight faults, and not one of them is peculiar to Aydo.

1. One supplier, many tenants. More than 25 unions are using a single software, probably running on the same server cluster, the same database engine, of the same company. In computing this is called a "multi-tenant" architecture; it is economical, because the company writes once and sells to everyone. But a single leak, a single malicious administrator, a single seizure, opens all the tenants' data at once. That rival unions' data sits in the same table, moreover, leaves the risk of leakage between unions to the conscience of one of the company's employees.

2. Supplier and consultant being the same person. The company that writes the software is at the same time the consultant that audits "KVKK compliance." This is like the book-keeper being the inspector. The three questions we asked when we discussed Amodei's "independent auditor" hold here as well: who chooses the auditor, who pays them, does the auditor have a power of sanction? If the answer to all three is "the company itself," there is no audit.

3. Closed code, invisible feature. The union does not know what is inside the software it has bought. The "query interface" is a menu item; which data source is behind it is invisible to the union officer. In closed-source software the customer knows only what is shown to them. This means the union cannot fulfil its responsibility to its own member: a union that says "we protect your data" is in fact saying "the company says it protects it."

4. Confusing verification with querying. We described this above: the right design returns "yes/no"; the wrong design returns the person's entire record. The second looks more "useful" to the user and sits better in the sales meeting. The breach of the principle of data minimisation (collect only what is needed, show only what is needed) is not a mistake, it is a marketing preference.

5. Data appetite. Does a union need its member's mother's and father's names, place of birth, address history? No. But if the field is there it is filled, once filled it is stored, once stored it leaks. When the software is designed as "the one that keeps everything," the size of the leak is as large as the software's appetite.

6. Half a million phones. The company speaks of "500,000+ mobile-app users." A mobile application is more than an identity number: device identity, notification token, and if permission was given location, contacts, photographs. How many union leaderships checked which permissions these applications asked for, and to which server those permissions carried data? The code of these applications is closed as well.

7. No log, or the log in the company's hands. Who queried whom, when? The answer to this question (the log) is either not kept or is only at the company. The union cannot know whether its own officer misused the interface; the member never knows who looked at their record. Yet the simplest principle of data protection is this: the one who looks must be visible.

8. The invisibility of the contract. The contracts between the unions and the company are not public. Where the data is held, whether a subcontractor is used, how it will be proved that the data is deleted when the contract ends: none of this was ever told to the members. The member gave their data to the union; the union, without asking the member, handed it to a company. The chain of consent broke at the first link.

The common ground of these eight faults is this: the union is not the subject of its own data, it is the customer. And the one who is the customer takes what is put up for sale.

The Operation Itself Is a Copying

Read this section with care, because no one else will write it.

In the operation computers, phones and digital material were seized. In a computing worker's language: the servers, the backups, the database images are now in the investigating authority's hands. What is on those servers? By the company's own advertising, the union membership records of more than two million people. Including the members of the opposition confederation. Including mother's and father's names, address, dues, date of membership, date of resignation.

That the company had leaked population data queried is a crime; investigating it is necessary. But if the form of the investigation results in the complete list of unionised public-sector workers in Turkey, together with their membership movements, being gathered in MİT's hands, this is not a "data-protection operation," it is a data-collection exercise done in the name of data protection. The same day, the same institution — four days after it shut which associations' which accounts in the "My Family Is Safe" operation — can today also see whom which union has organised. We wrote this in the censorship piece: since July 2026 the Cybersecurity Presidency has had the power of "apply first, judicial review later"; today that institution is a partner in an operation in which a union database was seized.

The first legal task the unions must do is to ask the fate of the seized data: was the data copied, by which court order, for how long will it be held, when and how will member records unrelated to the investigation be deleted, and who will audit that deletion? A union that does not ask this question cannot say to its member "I am protecting your data."

The first output of an operation in which the state says "we are protecting your data" is that your data is in the state.

Official Narrative / Class Reading

Official narrativeClass reading
"Operation against a company doing unlawful queries"The data being queried is data that leaked from the state's system in 2016; its source has still not accounted
"Access to the data of non-members"The data of those who are members was on the same server as well; it is now with the investigating authority
"A firm that also does KVKK consultancy"That the watchman and the seller are the same person is not an exception, it is the sector's business model
"Access to our data is not possible" (Memur-Sen)The company's site says "we manage 2 million+ people"; the two cannot be true at once
"No verified finding" (Eğitim Sen)Correct; but the code and the log with which to look for the finding are not at the union, they are at the company and at MİT
"The company owner is in detention"The management responsibility of the 25 unions that bought the software is not on the agenda
"The citizen's data is being protected"The citizen gave their data to the union; the union to the company, the company to the server, the server to MİT; no one asked the citizen

What Is Being Covered Over?

The source. The phrase "leaked data sets" does not say where the data leaked from. In ten years not a single public official has accounted for the 2016 MERNİS leak. While it has been documented by lawyers that the query panels obtained the data through "authorised user accounts," that is from inside, the operations always go down, to the seller; they do not go up, to the one who leaked. Aydo is a seller; the producer is the state.

The unions' responsibility. None of the unions that have issued statements so far has said "we will make a breach notification to our members." Article 12 of Law No. 6698 places on the data controller the duty to notify a breach to KVKK and to the persons concerned as soon as possible. The data controller is not the company, it is the union; the company is only the processor. That is, the duty to notify the member is the union's.

The contracts. Which union made a contract with this company in which year, at what price, with which clauses? Were there clauses in the contracts that "a sub-processor may not be used," "the data is the union's property," "it is deleted when the contract ends and the deletion is documented"? That these contracts, paid for with members' dues, are not open to the members is also a problem of inner-union democracy.

The computing worker. The people who wrote this software, who coded the query interface, who loaded the data set, are also workers. Of the five detentions, how many are "company owner," how many salaried employees? In Turkey the computing worker has no union that will protect them when they refuse to carry out the boss's decision. We told this in the Computing Worker's Handbook: preventing a sale from inside is in direct proportion to the computing worker's security. An employee who can say "do not load this data" is an employee who knows they will not be sacked. As we said in the piece on codes of conduct: their rule teaches the machine to say "no"; ours must protect the human who says no.

What Ought to Be: A Union Data Architecture Through a Computing Worker's Eyes

We will not end with complaint. The list below is of the kind a union's computing commission could put on the table tomorrow morning. We have separated the technical from the organisational; neither stands in for the other.

Technical principles

The data sits on the union's infrastructure. The membership list is held on a server under the union's own control; either with the union's own computing unit or with a not-for-profit infrastructure cooperative founded by the unions together. If a rented cloud is to be used the encryption key stays with the union; the provider does not see the data. We call this a "knowledge commons" and we discussed it in the Albatros Computing Cooperative example: computing infrastructure, too, cheapens and is made secure when it is built together, like a collective agreement.

The code is open, auditable. Membership-tracking software is open source; the union's own computing workers, a professional chamber or another union can read the code. There are open-source membership-management systems that unions and associations around the world have been using for years; it is not necessary to write from scratch. Open code is the antidote to the "secret query interface": a secret feature cannot be hidden in code that can be read.

Verification is not querying. Identity verification is done through KPS, with a "matched / not matched" answer. No data comes back, no population record is copied into a local table. If there is a local table labelled "NVİ," that table on its own is proof of a breach.

Collect little, keep little, keep it briefly. The fields needed for membership: name, surname, identity number, workplace, contact. Mother's and father's names, place of birth, address history are unnecessary; an unnecessary field is not in the software at all. The identity number is stored encrypted; a resigning member's data is deleted when the statutory retention period ends, and the deletion is written to the log.

Every look leaves a trace. Who saw which record, when: it is kept in an unalterable log, and this log is in the union's hands, not the company's. The member can see who looked at their record; in Estonia's public data system the citizen has been able to see this for ten years; there is no technical reason a union cannot.

Role-based access, least privilege. A branch officer sees only their own branch's members; headquarters sees the aggregate statistic; no account sees "everything." A permission defined as "query of non-members" does not exist in the software.

The mobile application with the fewest permissions. A union app does not ask for location, contacts, photograph permission; it carries no data beyond a device token for notifications; its code is open; which server it talks to is documented.

Supplier and auditor are separate. The one who writes the software cannot audit the compliance. Penetration testing and compliance audit are done by an independent body; the union chooses the auditor and discloses the report to the member.

Organisational principles

The contract is open to the member. The core clauses of the data-processing contract (where the data is, the ban on sub-processors, proof of deletion, the period for breach notification, the right of audit) are approved at the general assembly and sit on the union's site.

Breach notification is the union's duty. If there is a suspicion a written notification is made to the member within 72 hours; the sentence "no verified finding" does not stand in for notification.

Technical solidarity among unions. Rival confederations may divide politically; but that a membership list not leak to the employer is the common interest of all of them. A common technical standard, a common open-source project, a common audit pool; Memur-Sen's member and KESK's member are harmed by the same leak.

The computing worker's union. For the workers who write this software to be able to say "no," an organised union in the computing branch is needed. That the worker who writes a union's software is without a union is this affair's bitterest irony.

An account for the seized data. The unions together ask the investigating authority in writing: are there member records unrelated to the investigation in the copied data, when will they be deleted, who will audit? If no answer comes, this is taken to KVKK and to court as a breach.

Concrete Tasks

If you are a union member. Ask your union in writing: in which company, on which server, under which contract is my data held? Article 11 of Law No. 6698 gives you this right. Do not ask alone; ask together with your branch.

If you are a union officer. Do three things this week: make a breach notification to the members, open your contract to the member, ask in writing the fate of the seized data. A "no finding" statement stands in for none of these.

If you are a computing worker. Take on the technical load. Propose a computing commission to your union; ask for the software's access logs; pull the permission list of the mobile app; report the open-source options. This work cannot be done without a computing worker, and in most unions that computing worker is you.

If you work at a computing company. Think today what you will do when the boss says "load this data set." Do not think alone; think with the one beside you. The name of this is organising.

Among unions. Prepare a call for a common open-source membership-management project. KESK, Memur-Sen, Birleşik Kamu-İş, DİSK, Türk-İş: if one starts, the other will have to come.

To the professional chambers. Ask the TMMOB Chamber of Computer Engineers and the Chamber of Electrical Engineers for an independent technical-audit standard for union software; propose that they take this audit on as a voluntary public service.

To everyone. Do not forget the source. In every query-panel story turn the question back: who leaked in 2016, did they account? The company is detained, the source institution issues a statement; show the difference between the two every time.

Take the archive seriously. Save today's statements (including the company's references page); the page will be taken down tomorrow, the statement will change tomorrow. As we said in the censorship piece: if the text of the decision is not published, it is the volunteer's ledger that keeps the count.

Dear Young Comrades,

In this affair everyone's eye will be on "the company owner." Our eye is on two million records.

Those records are the list of whom Turkey's teachers, nurses, civil servants trusted. That list sat on a company's server; the company sold stolen population data on the same server; the state seized the server "to protect." At no link of this chain was the member asked.

A union's most valuable commons is not its money, it is the trust of its members in one another. If that trust sits on a server, whose the server is, theirs the trust is. Taking the server back, taking the data back, being able to read the code: these are not technical details, they are the material condition of freedom of association in the twenty-first century.

A union that keeps its membership list on a rented server has rented out the key as well. And the tenant opens not to the one who pays the rent, but to the one who knocks at the door.

Comradely.

Knowledge belongs to everyone.


Related Pieces

The data, surveillance and privacy linebilgimusterekleri.org/en/tag/kvkk/

The computing labour and organising line

Sources

Related Posts