Introduction
This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.
The subject of this article is the Board’s “Facebook decision” of 11 April 2019, No. 2019/104, which was published on 10 May 2019. The data breach at issue in the Board’s decision rests on the allegation, which was reported publicly and is referred to as the “Photo API” incident, that between 13 September and 25 September 2018 some third-party applications may have had access to photos on Facebook, for twelve days, beyond the scope of their authorisation. Facebook’s Engineering Director Tomer Bar confirmed this allegation in a statement published on 14 December 2018 at https://developers.facebook.com/blog/post/2018/12/14/notifying-our-developer-ecosystem-about-a-photo-api-bug/ under the title “Notifying our developer ecosystem about a photo API bug”.
The statement said that a photo API bug had been discovered which allowed third-party applications to access Facebook users’ photos and that the problem had been fixed, but that because of this flaw some third-party applications may have had access to photos beyond the scope of their authorisation for 12 days between 13 September and 25 September 2018. In addition, it emerged that, whereas a third-party application given permission by a Facebook user through the Facebook platform to access his or her photos should have had access only to the photos the user had shared on the timeline, during those 12 days third-party applications also gained access, as a result of the flaw described, to other photos shared on Marketplace or Facebook Stories.
Related publications
Dülger, Murat Volkan / Gümüş, Gülçin, Personal Data Protection Law (Kişisel Verilerin Korunması Hukuku), 4th ed., Seçkin Publishing, Ankara, 2026.
Dülger, Murat Volkan, Legislation on Information Technology, Personal Data Protection and Internet Communication (Bilişim, Kişisel Verilerin Korunması ve İnternet İletişimi Mevzuatı), 7th ed., Seçkin Publishing, Ankara, 2021.
Dülger, Murat Volkan, “The Use of Bulk Data and Metadata in Preventive Policing and Intelligence Work from the Standpoint of Human Rights, Personal Data Protection and Criminal Procedure Law” (İnsan Hakları, Kişisel Verilerin Korunması ve Ceza Muhakemesi Hukuku Açısından Önleyici Kolluk Hizmetleri ve İstihbari Çalışmalarda Toplu Veri ve Metadata Kullanımı), conference presentation, 2026.
Dülger, Murat Volkan, “Lawyers' Obligations under the KVKK in the Light of the Board's Decisions” (Kurul Kararları Işığında Avukatların KVKK Yükümlülükleri), conference presentation, 2025.
Dülger, Murat Volkan / Gümüş, Gülçin, “The Right to Be Forgotten”, Essays in Honour of Prof. Dr. Yadigar İzmirli (Prof. Dr. Yadigar İzmirli'ye Armağan), 2024.
