Guide

Field staff location tracking and KVKK

In field operations, location data is valuable for verifying and planning work, but an employee's location is personal data. This guide summarises what to watch within the general framework of Law No. 6698 on the Protection of Personal Data (KVKK).

Short answer

Location tracking should serve a specific and legitimate purpose, be limited and proportionate to that purpose, be preceded by informing the employee, and last only as long as necessary. The legal basis, the retention period and who has access should be set in writing. This guide is general information and not legal advice.

KVKK Art. 4

General principles of KVKK

Article 4 of KVKK lists the general principles for processing personal data. For location data they require answers to the following questions.

  • Lawfulness and fairness: is tracking open, and does the employee know about it?
  • Specific, explicit and legitimate purpose: which task needs the location?
  • Relevant, limited and proportionate: is location collected outside working hours or more often than needed?
  • Accurate and up to date: is faulty GPS data handled?
  • Kept only as long as needed: when are raw location points summarised or deleted?

KVKK Art. 10

The duty to inform employees

When collecting personal data, the controller must inform the person about who processes the data and why, to whom it may be transferred, how it is collected and on what legal basis, and the person's rights. For location tracking this notice should be given clearly before the app is used.

KVKK Art. 5

Choosing the legal basis

Article 5 of KVKK lists processing conditions other than explicit consent, such as being directly related to the formation or performance of a contract, a legal obligation, or the controller's legitimate interest. Since it can be debated whether consent in an employment relationship is freely given, decide the legal basis with your lawyer.

KVKK Art. 12

Data security and access

Only people who need it for their job should access location data. Permissions should be role-based, access should be logged, and the data should be kept separate from other companies' data.

  • Role-based access
  • Two-step verification for admin accounts
  • Summarising or deleting data when retention ends
  • Reviewing transfers to services abroad

Example

How SETS supports this process

The SETS panel includes an editable privacy notice template for location permission; the notice is shown to staff in the mobile app and the permission status can be reported from the panel. Panel access is role-based, two-step verification is available for administrators, and each company's data is kept separate. The company, as data controller, decides on retention and legal basis.

Last updated: 9 October 2026

Related Pages

You may also find these useful

SETS

Location Tracking and Field Reporting

Location records, reports and privacy support.

Explore
SETS

Field Route and Task Management

Assignments, route suggestions and location deviation.

Explore
Service

Cybersecurity Services

Review account, device and access security.

Explore
Company

Cookie policy

How we use cookies on this site.

Explore