Privacy, security and AI governance across 50+ jurisdictionsTalk to us
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
Türkiye · KVKK · Law No. 6698

GDPR’s structure, with a distinctly Turkish procedure.

Law No. 6698 on the Protection of Personal Data borrows the European architecture of lawful bases, data subject rights and accountability, then adds mechanics with no EU equivalent: a public controllers’ registry, a five-day contract notification duty and a transfer regime rebuilt in 2024. Compliance failures in Türkiye are usually procedural, not conceptual.

Applicability

Who the KVKK reaches and in what role

The KVKK applies to natural and legal persons processing personal data wholly or partly by automated means, or non-automated means forming part of a filing system. There is no revenue or headcount threshold for the substantive duties; thresholds only affect certain domestic VERBIS exemptions. Foreign entities processing the data of people in Türkiye are squarely in scope.

Data controller (veri sorumlusu)

Determines the purposes and means of processing and is responsible for establishing the filing system. Carries the registration, notice, security, rights-handling and breach obligations.

Data processor (veri işleyen)

Processes on the controller’s authority. Jointly and severally liable with the controller for data security, which makes processor diligence and contractual allocation materially important.

Representative in Türkiye

Foreign controllers registering with VERBIS must appoint a Türkiye-based representative, a legal entity or Turkish citizen, whose details are publicly recorded in the registry.

Contact person (irtibat kişisi)

A domestic requirement distinct from an EU-style DPO. The contact person is the channel for the Authority and data subjects, not an independent supervisory role, and does not carry DPO-style protections.

Territorial reach

The Authority takes an expansive view: processing the data of individuals in Türkiye brings a foreign controller into scope, and fines have been issued against non-resident platforms.

Sectoral overlays

Banking, electronic communications, health and e-commerce rules impose additional localisation and confidentiality duties that sit on top of the KVKK.

Processing conditions

Six lawful bases, with consent as the fallback

Lawful bases for ordinary personal data under Article 5
BasisWhen it worksPractitioner caution
Explicit consentFreely given, informed and specific to the processing.Consent conditioned on service delivery is not freely given. It is the residual basis; the Authority expects you to use a non-consent basis where one fits.
Expressly provided by lawA statute directly mandates the processing.Cite the specific provision in the RoPA and the notice, not a general sectoral reference.
Protection of life or bodily integrityWhere the person cannot give consent due to actual impossibility or legal incapacity.Narrow and emergency-facing; not a general safety basis.
Necessary for a contractDirectly related to the conclusion or performance of a contract with the data subject.Covers performance, not marketing or analytics layered onto the contract.
Legal obligation of the controllerNecessary for the controller to fulfil its own legal obligation.Distinct from the ‘provided by law’ basis; document which obligation and which regulator.
Publicised by the data subjectThe individual has themselves made the data public.Limited to use consistent with the act of publicising; it does not unlock unrelated reuse.
Establishment or exercise of a rightMandatory for the establishment, exercise or protection of a right.Litigation and defence-facing; keep the matter reference.
Legitimate interestsMandatory for the controller’s legitimate interests, provided the data subject’s fundamental rights are not harmed.Requires a documented balancing test. It cannot be used for sensitive data.

Special categories

Sensitive data after the 2024 alignment

Sensitive personal data covers race, ethnic origin, political opinion, philosophical belief, religion, sect or other belief, appearance and dress, membership of an association, foundation or trade union, health, sexual life, criminal convictions and security measures, and biometric and genetic data. Law No. 7499 removed the old two-tier split under which health and sexual-life data had a narrower set of conditions than other sensitive categories.

Unified conditions

Sensitive data may now be processed on explicit consent, where expressly provided by law, for protection of life where consent is impossible, on data publicised by the data subject, for establishment or exercise of a right, or for specified public-health, occupational-medicine, public-security and social-services purposes under a duty of confidentiality.

Adequate measures still required

The Board’s adequate-measures decision continues to apply: separate access controls, two-factor authentication for access, encryption with segregated key management, and dedicated logging for sensitive stores.

Biometrics under scrutiny

Biometric access control has attracted repeated enforcement. The Authority expects a necessity and proportionality analysis and a genuine non-biometric alternative offered without detriment.

Registry

VERBIS: the obligation most often missed

VERBIS (Veri Sorumluları Sicil Bilgi Sistemi) is a public registry of data controllers. Registration is a precondition to processing for controllers in scope, and the register entry must be kept current. Enforcement data consistently shows registration failures as the largest single category of KVKK fines.

Who must register

Domestic controllers above the employee or financial thresholds, all controllers whose main activity is processing sensitive data, public institutions, and every foreign controller processing data of individuals in Türkiye without exemption.

What you declare

Controller and representative identity, purposes of processing, data categories, recipient groups, data transferred abroad, retention periods and the security measures taken. The declaration is public and is read by the Authority in investigations.

Keeping it accurate

Material changes must be reflected in the registry. A VERBIS entry that contradicts your actual processing or your privacy notice is an evidential gift to an investigator, so reconcile RoPA, notice and VERBIS on the same cycle.

Cross-border data

The three-tier framework under the reformed Article 9

Since 1 June 2024 international transfers follow a hierarchy. You may not jump to the bottom tier for convenience: derogations are expressly limited to non-recurrent transfers.

Article 9 transfer hierarchy
TierMechanismWhat it means in practice
Tier 1Adequacy decisionThe Board may recognise a country, a sector within a country, or an international organisation as providing essentially equivalent protection, subject to review at least every four years. Sectoral adequacy is a distinctive Turkish feature. In practice the designation landscape remains thin, so most organisations cannot yet rely on this tier.
Tier 2Appropriate safeguardsAvailable where there is no adequacy decision and the data subject has the opportunity to exercise rights and seek effective remedies in the destination. The routes are the Board’s published standard contract, binding corporate rules approved by the Board, a written undertaking authorised by the Board, and agreements between public authorities. The standard contract needs no prior approval but must be notified to the Authority within five business days of signature.
Tier 3DerogationsNarrow, and only where neither higher tier is available and the transfer is non-recurrent: explicit consent after being informed of the risks, contractual necessity, an overriding public interest, establishment or exercise of a right, protection of life where consent is impossible, or transfer from a public register.

Migration warning. Arrangements built on pre-2024 explicit consent or old Board undertakings do not automatically satisfy the current Article 9. Re-paper recurring cloud, payroll, CRM and intra-group flows onto a Tier 2 safeguard and file the standard-contract notifications.

Individuals and incidents

Rights, response windows and breach duties

Article 11 rights

Learn whether data is processed, request information, learn the purpose and whether it is used accordingly, know domestic and foreign recipients, request correction, request erasure or destruction, require corrections to be notified to recipients, object to adverse automated-only outcomes, and claim compensation for damage.

Application route

Requests go to the controller first. The controller must respond within 30 days at the latest and free of charge unless the response has a cost, in which case the Board’s tariff applies.

Escalation to the Board

If the request is refused, the response is unsatisfactory or no response arrives, the individual may complain to the Board within 30 days of the response and in any event within 60 days of the application. Exhausting the controller stage is a precondition to complaint.

Breach notification

Notify the Authority within 72 hours of becoming aware, explaining any delay, and notify affected data subjects in the shortest reasonable time. The Authority publishes breach summaries publicly.

Retention and destruction

Maintain a personal data retention and destruction policy, and run periodic destruction cycles, at six-month intervals for controllers required to have the policy, with records of deletion, destruction or anonymisation.

Enforcement exposure

Administrative fines apply for breaches of notice, security, Board decisions and registration duties, with registration and security failures dominating published decisions. Certain unlawful acts also carry criminal liability under the Turkish Penal Code.

Implementation

Where to start

1

Register or reconcile VERBIS

Confirm registration status, appoint the representative if foreign, and align the public entry with your actual RoPA and notice.

2

Re-base the processing

Replace bundled consent with a specific Article 5 basis wherever one fits, and document legitimate-interest balancing tests.

3

Re-paper transfers

Inventory destinations, select a Tier 2 safeguard, sign the standard contract and file the five-business-day notification.

4

Prove the 72-hour clock

Rehearse Authority notification with an incomplete picture, including the delay-justification wording.

Questions

Frequently asked questions

What changed under Law No. 7499?

Law No. 7499 was published in the Official Gazette on 12 March 2024 with the transfer provisions effective from 1 June 2024. It is the most significant overhaul in the KVKK’s history. It rewrote Article 9 to replace the old explicit-consent-or-Board-undertaking model with a three-tier framework of adequacy decisions, appropriate safeguards and narrow derogations. It also aligned the conditions for processing sensitive personal data, removing the previous split that treated health and sexual-life data differently from other sensitive categories.

Is VERBIS registration required for a foreign company?

Yes. Any data controller established abroad that processes the personal data of individuals in Türkiye must register with VERBIS, the Data Controllers Registry, regardless of size, headcount or revenue. Domestic controllers have threshold-based exemptions, but there is no equivalent exemption for foreign controllers. Failure to register is consistently the single largest category of KVKK administrative fines, so treat it as a first-order task rather than a formality.

Can I still rely on explicit consent for international transfers?

Only as a narrow derogation, not as a routine mechanism. Under the reformed Article 9 you must work down the hierarchy: an adequacy decision first, then an appropriate safeguard such as the Board’s standard contract, binding corporate rules or a Board-authorised written undertaking. Explicit consent survives only as an exceptional, one-off derogation for non-recurrent transfers after the individual is informed of the risks, so it cannot lawfully support ongoing cloud or intra-group flows.

What must I do after signing the Board’s standard contract?

The standard contract does not require prior Board approval, but it must be notified to the Authority within five business days of signature. Missing that notification is itself a breach exposing the controller to an administrative fine, so build the filing step into contract closure rather than leaving it to a periodic review.

What is the breach notification timeline?

The controller must notify the Authority within 72 hours of becoming aware of the breach, and must notify affected data subjects within the shortest reasonable time once the affected individuals are identified. Where the 72-hour deadline cannot be met, the notification must explain the reasons for the delay. The Authority publishes breach notification summaries on its website, so assume the incident becomes public.

Verify

Primary sources

General information, not legal advice. Secondary legislation, Board decisions, adequacy designations and the standard contract templates continue to develop after Law No. 7499. Verify the current instrument and any sectoral overlay before relying on this page. Researched 21 September 2026.

Preparing for the KVKK?

We run VERBIS registration, Article 9 transfer re-papering and 72-hour breach readiness for organisations processing Turkish personal data.

Talk to Vedhacon