International Legal Advice

Are you looking for a law firm with international expertise? GEMS Schindhelm supports you with its international teams, providing competent, committed, and hands-on legal advice backed by valuable local experience. Find out more online about a wide range of topics in international business law.

 

Data Protection Law in Turkey (KVKK)

The Law on the Protection of Personal Data No. 6698 ("Kişisel Verilerin Korunması Kanunu" – KVKK) has been the central framework of Turkish data protection law since 2016. It was modelled on the EU Data Protection Directive and, with the March 2024 reform, brought closer to the General Data Protection Regulation (GDPR) in key respects – particularly on special categories of data and international transfers. For foreign companies with subsidiaries, customers or data processing operations in Turkey, KVKK compliance is a self-standing obligation: GDPR conformity alone is not enough, since the Turkish rules take their own path on procedures, registration duties and sanctions.

Table of contents

  • Who does the KVKK apply to?
  • Which principles and legal bases apply?
  • What applies to special categories of personal data?
  • What obligations does the data controller have?
  • What is VERBİS and who must register?
  • How are international data transfers regulated?
  • What rights do data subjects have?
  • What sanctions apply and how does judicial protection work?
  • What are the current enforcement priorities of the authority?
  • How do the KVKK and the GDPR differ?
  • What does the compliance roadmap for market entry look like?
  • How does the Court of Cassation assess employee-caused KVKK breaches?
  • Conclusion

Who does the KVKK apply to?

The KVKK applies to natural and legal persons who process personal data wholly or partly by automated means or as part of a filing system. The law contains no express extraterritoriality rule of the GDPR type; in its settled practice, however, the Data Protection Authority also applies it to foreign companies whose data processing affects individuals in Turkey – several international groups have already been fined. Foreign groups should therefore actively review their Turkish touchpoints – local companies, websites directed at Turkey, central HR and CRM systems – for KVKK obligations.

Which principles and legal bases apply?

Every processing operation must satisfy the general principles: lawfulness and fairness, accuracy and currency, purpose limitation, necessity and proportionality, and limited retention. Processing is permitted only where a legal basis exists – besides explicit consent, in particular: express provision by law, necessity for the conclusion or performance of a contract, a legal obligation of the controller, data made public by the data subject herself, necessity for the establishment or defence of rights, and the legitimate interest of the controller provided the fundamental rights of the data subject do not prevail. Consent must be informed and freely given; it may not be made a condition for services that could be provided without it, and it should be used subsidiarily to the statutory permission grounds.

What applies to special categories of personal data?

Special categories – race and ethnic origin, political opinion, religion, memberships, health and sexual life data, criminal data, and biometric and genetic data – are subject to stricter requirements. The 2024 reform expanded the previously very narrow catalogue of legal bases: processing is now permitted, inter alia, with explicit consent, where expressly provided by law, to protect vital interests, for purposes of employment, occupational health and safety and social security, in the health sector by persons under a duty of confidentiality, and by associations in relation to their members. In addition, the special security measures determined by the Data Protection Board must be implemented. Particularly relevant for companies are health data in the HR context and biometric access systems, which the authority accepts only where strictly necessary.

What obligations does the data controller have?

  • Duty to inform: at the time of collection, data subjects must be informed about the controller, the purposes, the recipients, the collection method and legal basis, and their rights – the Turkish catalogue of duties is self-standing; GDPR privacy notices cannot be adopted unchanged.
  • Data security: appropriate technical and organisational measures, contracts with processors, access concepts, logging and training.
  • Notification of data breaches: violations must be notified to the authority without delay – within 72 hours under Board practice – and to the data subjects concerned.
  • Deletion and destruction management: data must be deleted, destroyed or anonymised once the purpose has lapsed; controllers subject to registration require a retention and destruction policy with periodic deletion cycles.
  • Accountability and documentation: the processing inventory, policies and consent records form the line of defence in inspections.

What is VERBİS and who must register?

VERBİS is the public registry of data controllers. Subject to the thresholds and exemptions set by the Board, registration is required in particular for companies above a certain number of employees or balance sheet total, for entities whose main activity is processing special categories of data, and for foreign controllers processing the data of individuals in Turkey. Foreign companies must appoint a representative in Turkey for registration. Registration comprises notification of the processing purposes, data categories, recipient groups, transfers and retention periods on the basis of an internal processing inventory. Breach of the registration duty carries substantial fines and is easy for the authority to detect – in practice it is one of the most frequent grounds for sanctions against foreign companies.

How are international data transfers regulated?

The 2024 reform reorganised the previously de facto blocked transfer regime and aligned it with the GDPR systematics. Transfers abroad are permitted on the basis of an adequacy decision of the Board for the destination country, sector or international organisation; in the absence of one, on the basis of appropriate safeguards – in practice above all the standard contractual clauses published by the Board, which must be notified to the authority within five business days of signature, and approved binding corporate rules for groups. In exceptional cases, occasional transfers – for instance with explicit consent or for the performance of a contract – remain possible. International companies should map their transfer landscape (cloud services, central IT systems, group reporting) and migrate to the new instruments; failure to notify the standard contractual clauses is independently subject to fines.

What rights do data subjects have?

Data subjects may in particular demand from the controller information about the processing, rectification, erasure and notification of recipients, object to exclusively automated analysis to their detriment, and claim damages. Requests must be free of charge and answered in principle within 30 days. If the request is unsuccessful, the data subject may lodge a complaint with the Data Protection Authority. For companies, a documented data subject request process with identity verification, deadline control and coordinated response templates is recommended.

What sanctions apply and how does judicial protection work?

The supervisory authority is the Personal Data Protection Authority ("Kişisel Verileri Koruma Kurumu") with its decision-making Board ("Kurul"). It conducts inspections ex officio and upon complaint, publishes guidelines and imposes administrative fines whose ranges are indexed annually and – for instance for breaches of data security and registration duties – reach millions of lira. In addition, the Turkish Criminal Code contains offences for the unlawful recording, disclosure and non-deletion of data. Since the 2024 reform, Board decisions can be challenged before the administrative courts. Civil damages and moral damages claims by data subjects come on top.

What are the current enforcement priorities of the authority?

The Board's decision-making practice sets recognisable priorities that compliance programmes should follow: cookies and online tracking are measured against consent and information duties under the relevant guideline; biometric access and time-tracking systems are accepted only where strictly necessary and have repeatedly been the subject of sanctions; unsolicited marketing messages and the disclosure of customer data to third parties are among the most frequent subjects of complaints. Internationally active groups have repeatedly been fined for missed VERBİS registration and for transfers abroad without a valid instrument; late or omitted breach notifications are also consistently penalised. The published Board decisions are thus a valuable – and free – risk map for one's own prioritisation.

How do the KVKK and the GDPR differ?

  • VERBİS registration with a Turkish representative has no GDPR equivalent and is frequently overlooked.
  • The duty to inform follows its own substantive requirements; privacy notices must be localised.
  • Fines are linked to fixed, indexed ranges rather than group turnover; the amounts are lower but hit faster.
  • Certain GDPR institutions – such as the data protection impact assessment and the data protection officer – have not been adopted as formal duties but are functionally covered by the accountability and security obligations.
  • International transfers require Turkish instruments of their own despite the convergence – EU standard contractual clauses do not replace the Turkish ones.

What does the compliance roadmap for market entry look like?

  • Inventory: map data flows with a Turkish nexus – local company, website, HR, CRM and cloud systems, group reporting.
  • Create a processing inventory and check the VERBİS obligation; for foreign controllers, appoint and register a Turkish representative.
  • Localise information texts and consents – do not translate, but adapt to the Turkish catalogue of duties.
  • Migrate international transfers to standard contractual clauses or binding corporate rules and build the five-business-day notification deadline into internal processes.
  • Implement a retention and destruction policy, a data subject request process (30-day deadline) and a data breach notification path (72 hours).
  • Make processor agreements and HR processes (recruitment, monitoring, health data) KVKK-proof; document training.
  • Annual review against the current Board decisions and guidelines.

How does the Court of Cassation assess employee-caused KVKK breaches?

In practice, data protection breaches by no means always stem from direct action by company management: carelessness, inadequate training or procedural violations by employees in day-to-day business can also trigger serious data incidents. This, however, changes nothing about the administrative responsibility of the company as controller under Law No. 6698: even where an employee committed the breach, the sanctions of the Data Protection Authority are as a rule directed at the company. Companies must therefore not only take technical security measures but make their employees part of the data protection culture.

Instructive in this respect is the judgment of the Court of Cassation (9th Civil Chamber, judgment of 20 January 2025, E. 2024/13450, K. 2025/700): an employee of a financial company had mistakenly generated the account statement of another customer and forwarded it to the relevant unit; the employer then terminated the employment relationship under social security exit code 49 (summary dismissal for breach of duty). In the proceedings, however, the employer could not prove that the employee had intentionally violated the data security rules, had previously been warned, or had persistently refused to fulfil his duties despite admonition. The first-instance court, the Regional Court of Appeal and finally the Court of Cassation therefore held that the dismissal could not fall under code 49 and that the exit code had to be corrected.

The judgment shows: not every mistake leading to a data incident supports summary dismissal by itself. Rather, the employer must demonstrate with concrete evidence that it provided the necessary training, clearly communicated the data security rules and issued the required warnings – and that the employee nonetheless persistently refused. Documented internal KVKK processes are thus decisive not only under data protection law but also in employment disputes.

At the same time, the decision exposes an uncomfortable truth: fines, damages claims and reputational harm from employee-caused data incidents predominantly hit the company. KVKK compliance must therefore not exhaust itself in information texts and VERBİS registrations; it needs employee training, written internal procedures, data security policies and data protection clauses in employment contracts; the regular delivery and documentation of training is also an important building block of accountability.

In our KVKK compliance projects we accordingly do not confine ourselves to information texts and the design of processing operations: we develop role-based KVKK training, confidentiality and data protection undertakings, employment contract data protection clauses and additional awareness programmes for staff working with customer data, financial data or special categories of data. This holistic approach considerably lowers the risk of data incidents – and puts companies in a position to prove, in the event of a dispute, that the required technical and organisational measures were in place.

Conclusion

After the 2024 reform, the KVKK has become more modern and workable, but it remains a self-standing framework with its own registration, information and transfer obligations. For international companies this means: GDPR compliance provides the foundation but does not replace the Turkish implementation – what is required are localised information texts, a review of the VERBİS obligation including representative appointment, and the migration of data flows to the new transfer instruments.

Since the authority inspects actively and sanctions foreign companies as well, Turkey should be run as a separate compliance module within global data protection programmes and regularly adjusted to the Board's dynamic practice.

The IP/IT team at GEMS Schindhelm advises companies on KVKK compliance – from the inventory through VERBİS registration, information texts and transfer instruments to representation in proceedings before the Data Protection Authority.