Kooch helps foreign SaaS, fintech, and e-commerce companies — and Turkish startups — meet KVKK, GDPR, and ISO 27001 obligations. Senior-led, bilingual, and fast.
Comprehensive audit revealing compliance weaknesses.
Rapid onboarding to meet KVKK basics.
Your appointed KVKK representative in Türkiye for foreign data controllers — appointment, request intake, and regulator coordination, with clearly defined scope.
We build the ISMS and documentation that make you audit-ready. (Certification is issued by an accredited body — not by Kooch.)
Continuous data protection and compliance oversight.

Türkiye’s Personal Data Protection Authority has clarified how Principle Decision No. 2026/921 applies to employee biometric systems. Biometric attendance tracking should be replaced, while genuine critical-area access control requires a separate, documented assessment of legal basis, necessity, proportionality and security.

A practical 2026 guide to data protection laws across the Middle East, including the GCC, Türkiye, Egypt, Jordan and Israel. Compare the main regimes, understand what changed, and build a workable regional compliance programme.

Learn when a foreign-established controller may need a Türkiye data controller representative, what the role covers, and what remains with the controller.
.webp)