Knowledge Commons
HomeAboutGuidesPopularContact

KVKK's "80s Trend" Warning and Privacy in the Digital Age

Let Memories Live. Who Keeps the Data?

Author: Oğuz Demirkapı
KVKK's "80s Trend" Warning and Privacy in the Digital Age

Let Memories Live. Who Keeps the Data? KVKK's "80s Trend" Warning and Privacy in the Digital Age

Dear Young Comrades,

On 10 September 2026 the Personal Data Protection Authority (KVKK) posted from its official X account: "Before you turn your photographs into nostalgic frames with artificial-intelligence apps, consider your digital privacy as well. For the apps used in social-media trends such as "80lerchallenge" may cause your biometric data to be processed from your photographs." The Authority left the citizen two tasks: check the apps' access permissions, and find out for what purpose the data will be used. The post ends with this slogan: "Let memories live; what is yours, stay with you." The statement was picked up at once across the press.

A small but telling detail: this warning does not appear as a public announcement on the Authority's own website; it is only a social-media post. What is visible on the site's homepage in those same days is three separate data-breach notifications dated 9 September: a hotel, a health company, a cosmetics firm. So the Authority's real agenda is not the citizen uploading a photograph; it is data controllers losing the citizen's data. Keep that in mind; we will come back to it.

The trend itself looks innocent. You upload a photograph to an AI app; the app turns you into a 1980s still with puffy hair, a pastel jacket, and film grain. Fun. The warning is also technically correct: a face photograph is a source of biometric data, because facial geometry can be extracted from it.

But in this piece I want to tell you less about the warning's accuracy than about the context in which it was said. Because in the same week, in the same country, 31 lawyers were detained on the allegation that they had queried citizens' data through illegal systems called "query panels" (Euronews Turkish). The data queried on those panels was not your 80s photograph; it was your national ID number, your address, your family's information, your social-security record, your title deed. That is, the data the state holds, and for which it passed a law promising protection.

Set these two stories side by side and you will see what privacy means in the digital age, and why KVKK's warning looks comic. Let us go step by step.


What the warning says, and what it does not

The warning says three things. First, a face photograph is not an ordinary photograph; facial geometry can be extracted, and that is biometric data counted under Law No. 6698 as a "special category of personal data." Second, these apps often do not say clearly for what purpose the data is stored, or with whom it is shared. Third, the citizen should read the permissions and the policies before uploading.

What the warning does not say is more interesting. The Authority does not say which companies own these apps, where the data goes, or whether there is a data-controller representative in Turkey. It does not say it has opened an investigation into any app. It reminds the citizen of a duty; it reminds capital of none. The address of responsibility is hidden in the warning's grammar: the subject is "the user," the predicate is "must be careful."

This is the domestic version of a tendency data-protection regimes carry the world over: reducing privacy to a problem of individual attentiveness. Yet a privacy violation is not the result of carelessness; it is the result of a business model.

Why biometric data is different

If your password is stolen, you change it. You can change your phone number, even your address. You cannot change your face. The property of biometric data is permanence; once it has leaked, it has leaked for life.

A mathematical "face signature" (an embedding) extracted from a face photograph can be matched anywhere, against any other photograph. That is how the US company Clearview AI was able to build a face-search engine, sold to police forces, from billions of photographs scraped from the internet without consent; data-protection authorities in Italy, France, Greece, the United Kingdom and the Netherlands fined the company a total of more than a hundred million euros (TechCrunch). The company did not pay most of the fines and continued to operate. Write this down: the limit of data-protection law is the point at which capital's jurisdiction ends.

The "80s trend" apps are not on that scale, of course. But the mechanism is the same: the user gets entertainment; the company gets training data and a face signature. A free service is not free. This is the same thing we said when discussing Anthropic's survey of 81,000 people: the form in which a service is offered to you is the most effective way of hiding what is collected from you.

What does privacy mean in the digital age?

Let us pause here, because most young comrades have heard the sentence "I have nothing to hide," or have said it themselves. The sentence is wrong in three ways.

First, privacy is not hiding; it is governing context. Privacy is your boss not knowing what you told your doctor, human resources not knowing what you told your union, the state not knowing what you told a friend. The flow of information is bound to context; a privacy violation is information being moved from one context to another without your consent. The person who says "I have nothing to hide" is in fact saying "I do not know from which context it will be moved to which."

Second, privacy is not individual; it is relational. When you upload a photograph you upload not only your own face but the face of the friend beside you, the street behind you, the poster on the wall. When you open your phone contacts to an app you have handed over the numbers of five hundred people whose consent you never took. In the Cambridge Analytica scandal 270,000 people took a personality test and the data of 87 million people was collected, because the app also reached the participants' friend lists. Data, like labour, is social; it cannot be governed by individual consent.

Third, and most important, privacy is a class question. Whose data is collected, whose data is protected? The warehouse worker's step count, the courier's location, the call-centre worker's tone of voice, what the teacher said in class: these are on record. The company's board meeting, the holding's tax restructuring, the ministry's tender talks are protected as "trade secret" or "state secret." That is exactly what we call the digital panopticon: surveillance is transparent downward and opaque upward. As we said in "The Panopticon's Doorkeeper", when we told of Anthropic's activist-monitoring system, the first customer of surveillance technology is always the employer and the state; the citizen is told "be careful."

Seen in this frame, personal data is the digital shadow of your labour-power. Your habits, your movements, your relations, your face: these are collected and processed into a "profile," and that profile is sold or given to the advertiser, the insurer, the employer, the state. The twenty-first-century extension of the process Marx called "the commodification of labour-power" is the commodification of life itself as data. That is why data-protection law, like labour law, is the product of a struggle to draw a limit against capital; and, like labour law, it is a limit capital continually wears down.

What is happening in the world?

The world's experience can be summarised in three lines: Europe enlarges the fine but does not change the model; the United States protects the model and bargains state by state; China wires surveillance directly into the state apparatus. None of them has solved the problem, but all of them are a step ahead of Turkey.

The European Union: high fines, the same model. The General Data Protection Regulation (GDPR) has been in force since 2018. Meta was fined 1.2 billion euros in 2023 for transferring EU data to the United States; Amazon 746 million euros for unauthorised targeted advertising; Instagram 405 million euros for making children's data public; TikTok 345 million euros for collecting the data of children under 13 (Termly compilation). The EU AI Act banned building face-recognition databases by scraping face photographs from the internet. These matter. But in eight years the total in fines is around seven billion euros; Meta's profit in a single year is more than ten times that. For capital the fine is still a cost item, not a barrier.

The United States: no federal law, state-by-state bargaining. There is still no general federal data-protection law in the US. In its place there are state lawsuits and settlements: in August 2026 Meta reached a $16.68 billion settlement with 29 states in child-safety cases (Sabah, Timur Sırt). The figure is large, the structure the same: the company does not admit the offence, pays the money, continues the business model. Equifax's leak of 147 million people's credit data in 2017, and Cambridge Analytica's election manipulation, also showed the link in the US between "data protection" and "election security": losing your data is not only a private loss; it is a political loss.

China: the nationalisation of surveillance. In 2021 China passed a Personal Information Protection Law similar to the GDPR and enforced it genuinely hard against companies; but the law left the state's own surveillance systems outside its scope. Face-recognition cameras and the social-credit system are the example of company surveillance and state surveillance merging into a single apparatus. The reason we tell this is the following: running data-protection law against capital does not automatically bring protection from the state's surveillance. They are two separate struggles, and one does not stand in for the other.

The common lesson: nowhere in the world has privacy been protected by "let the user be careful." Where it has been protected, it has been protected by binding law, an independent supervisory authority, a fine that hurts capital, and the right to a class action.

Turkey: the protector itself cannot be protected

Now to why the warning looks comic. In Turkey the personal-data problem is, before the problem of companies collecting citizens' data, the problem that citizens' data in the state's hands is for sale. Let us look at the chronology.

2016: the MERNİS leak. The national ID numbers, names, parents' names, places and dates of birth, and addresses of about 50 million citizens dropped onto the internet as a file. The data had been taken from the system of the Directorate of Population and Citizenship Affairs, estimated to be from 2008–2010. Today the basic identity data of almost everyone registered in Turkey's civil registry has been in the public domain since that day. No public official was held to account for this leak.

2021: Yemeksepeti. The data of 21 million users was stolen. KVKK fined the company 1.9 million lira (Anadolu Agency). Nine kuruş per user.

2023: the "query panel" period. On panels sold as memberships for 600–1,000 lira a month over Telegram, it emerged that address, family, vehicle, title-deed, social-security and mobile-phone queries could be run from a national ID number. In June 2023 the claim that "the e-Government data of 85 million citizens was stolen" was brought to Parliament (Cumhuriyet). That the panels obtained the data not by external attack but through authorised-user accounts, that is from inside, was documented by lawyers (Forseti Hukuk).

2024: denial. In September 2024 the Directorate of Communications said "the claim that the data of 85 million citizens was stolen is entirely unfounded"; in the same statement it accepted that "declaration-based address information was reached by means of some of our citizens' passwords being stolen" (Directorate of Communications). So the data did not leak, but it leaked.

2025: operations and a new law. In January 2025, 69 people were detained in 25 provinces; 35 of them were children. Cybersecurity Law No. 7545, which entered into force in March 2025, defined "data trading" as a separate offence, but the same law also provided prison sentences for news of data leaks alleged to be "contrary to the truth," and so cast a shadow over the journalist who reports a leak. That same year KVKK received 328 data-breach notifications and 12,512 complaints; 68 percent of the applications concluded were rejected on grounds of "procedural defect" (summary of the KVKK 2025 Activity Report). The Authority's total fines for the year: 352 million lira; one percent of the fine the EU levied on Meta in a single stroke.

2026: the lawyers. On 4 September 2026, 31 lawyers were detained on the allegation that they had queried persons with whom they had no attorney–client relationship through panels named "HukukBİS" and "AsistBİS," and had sent blackmail messages. Six days later KVKK told the citizen: "read the permissions when you upload an 80s photograph."

Read the sequence this way and the comedy of the warning appears of itself. Before the citizen's face photograph went into an app, the citizen's ID number, address, family, title deed and social-security record were already being sold on Telegram. And what took that data to Telegram was not the citizen's carelessness; it was the state's data infrastructure being for sale from the inside.

Comparison: what is said and what is done

What KVKK tells the citizenWhat in fact happens in Turkey
"Check the app's permissions"In 2016 the identity data of 50 million citizens leaked from the state's system; no one was held to account
"Ask for what purpose your data is stored"State databases were entered with authorised-user accounts and the data was sold on Telegram by monthly membership
"Your biometric data may be processed"ID number, address, family information, title deed, social-security record have been on query panels for years
"What is yours, stay with you"Reply to the claim "the data of 85 million was stolen": "unfounded, but some passwords were stolen"
An 11.5 million lira fine on Meta for child accountsThe EU fine for the same act: 405 million euros
12,512 complaints68 percent dismissed on procedural grounds
Responsibility: the userResponsibility: the unaccountable institution and the company that profits

The table shows us one thing: in Turkey the data-protection regime operates not to protect the citizen against capital, but to protect the institution from responsibility. If the citizen uploaded a photograph and the data leaked, the line will be "we warned you." If it leaked from the state's system, the line will be "unfounded."

Why is it like this? A structural answer

It is easy to explain this situation by bad faith or incompetence, but it is wrong. There are three structural reasons.

First, the supervisor is not independent. KVKK's board members are appointed by Parliament, the President, and formerly the Council of Ministers. The largest data controller it is supposed to supervise is the state itself. That an institution which supervises the one who appoints it is silent in the state's leak and loud over the citizen's photograph is not an accident; it is the design.

Second, the political economy of data. Public data in Turkey was centralised (e-Government, MERNİS, UYAP, SGK, MEDULA), but this centralisation resulted less in the use of data for the public good than in data becoming leakable from a single point. In public institutions the security budget, security staff and merit grew in inverse proportion to the share allotted to computing infrastructure. That the query panels work from the inside is also a result of the computing worker's insecurity; we set out this link at length in The Computing Worker's Handbook.

Third, the class difference between the law and its application. On paper, Law No. 6698 copies the GDPR's 1995 predecessor; it was updated somewhat by the 2024 amendment. But the force of a law is measured by the force of the place where it is applied. 1.9 million to Yemeksepeti, 11.5 million lira to Meta; to the citizen, an identity leaked for life. The fine is a cost to capital, a fate to the citizen.

Concrete tasks

I will not ask you to be careful; being careful is necessary but not sufficient. Individual precaution must not stand in for collective demand. Still, let us list both together.

At the individual level, not giving your face and your contacts to random apps; distinguishing a durable identifier (ID number, biometrics) from a temporary one (password, phone); using a separate password and two-factor authentication on every account; taking a minute to look up who the app is before joining a trend. These will not protect you from a leak, but they will take you out of being the easiest target.

At the collective level, the real work is here. Asking in writing what data of yours is collected at your workplace; this is your right under Article 11 of Law No. 6698, and there is a mountain of difference between asking alone and asking as a union. Unions and professional chambers filing data-protection applications collectively; sharing standard application templates that will empty KVKK's excuse of "procedural defect." A campaign demanding that public institutions be held to account in the query-panel leaks; reminding people that MERNİS 2016 is still unanswered. The demand that the right to a class action be recognised for data breaches; today in Turkey citizens have in practice no means of suing together over a leak. For computing workers: asking, in the institution where you work, about the supervision of "authorised user" accounts, the log records, the access principle; preventing sale from the inside is more the computing worker's job than preventing attack from the outside.

At the political level, the demand that the data-protection authority be genuinely independent, that public institutions carry personal responsibility in a data leak, and that data be managed as public property — that is, as a knowledge common. This is our line: personal data is the property of neither the company nor the state; it is information society produces about itself, and it must be under society's supervision.

The right address of the problem

Dear Young Comrades, KVKK's slogan "Let memories live; what is yours, stay with you" is a fine slogan. The problem is not the slogan; it is to whom the slogan is said.

Every citizen living in Turkey knows, or ought to know, that their ID number, address, parents' names, date of birth and probably much more is being sold on a Telegram channel for a few hundred lira. They did not upload this data to an app themselves. They gave it to the state, because they had to. The state could not protect this data; it first denied the leak, then partly admitted it, and never found anyone responsible.

Under these conditions the reply the citizen should give KVKK is not to read the warning and delete the photograph, but to turn the question around:

"Should you not first protect our data that is in your hands, in the state's system?"

Let us ask this question not one by one but together. Because privacy, like labour, is a right that cannot be defended individually, and can be defended only together.

Comradely.


Sources

Related Posts