Kooch Insights on Privacy, Compliance and Security

Learn what KVKK is, who must comply, and recent updates.

Phone Number Recycling Can Become an Account-Takeover Problem

Oman proposes new safeguards for recycled phone numbers. Understand the account-takeover risks and how to secure SMS login, recovery and number changes.

September 9, 2026

When Biometric and Genetic Data Appear in a Ransomware Breach

What the Yapı Merkezi breach notice establishes, why biometric and genetic data need a different response, and how to assess exposure and KVKK notifications.

September 8, 2026

Türkiye’s KVKK Clarifies Employee Biometrics: What Employers Must Change

Türkiye’s Personal Data Protection Authority has clarified how Principle Decision No. 2026/921 applies to employee biometric systems. Biometric attendance tracking should be replaced, while genuine critical-area access control requires a separate, documented assessment of legal basis, necessity, proportionality and security.

August 31, 2026

Middle East Data Protection Laws in 2026: A Practical Compliance Guide

A practical 2026 guide to data protection laws across the Middle East, including the GCC, Türkiye, Egypt, Jordan and Israel. Compare the main regimes, understand what changed, and build a workable regional compliance programme.

August 28, 2026

Data Controller Representative in Türkiye: What Foreign Companies Need to Know Under KVKK and VERBİS

Learn when a foreign-established controller may need a Türkiye data controller representative, what the role covers, and what remains with the controller.

KVKK Fines Company TRY 1 Million Over Referral Marketing

What KVKK Decision 2026/1183 means for referral, brand-ambassador and refer-a-friend programmes, call recording, SMS marketing, IYS and CRM deletion.

Saudi AI Cybersecurity Consultation Has Closed

Saudi Arabia’s AI cybersecurity consultation has closed, but the final text is pending. Learn what the draft covered and which controls to implement now.

Egypt’s Promotional-Call Enforcement

What Egypt’s NTRA caller-registration rules require, how device blocking works, and how consent, call centres and complaints fit into compliance.

August 10, 2026

Türkiye’s New KVKK Rule for Publishing Personal Data on Public Websites

What Türkiye’s 2026 KVKK principle decision means for public bodies publishing examination results, recruitment lists, notices and personal data online.

August 3, 2026

What Is Not Valid Marketing Consent Under KVKK?

Silence, listening to a sales call or failing to opt out does not establish valid marketing consent under KVKK. See practical call-centre and CRM examples.

July 28, 2026

Authorization Vulnerabilities and KVKK Breaches

What Türkiye’s July 2026 breach disclosure reveals about authorization weaknesses, access controls, incident response and KVKK notification duties.

July 27, 2026

Türkiye’s KVKK Referral Marketing Warning | 2026

Türkiye’s KVKK Authority has warned businesses about referral leads used for calls and SMS. Learn how to assess legal basis, notices, consent, IYS and vendors.

July 27, 2026

Türkiye’s 2026 KVKK Decision on Acview

Türkiye’s 2026 KVKK decision targets unlawful use of accident victims’ data. See what insurers, experts, hospitals and service providers should review.

July 13, 2026

Qatar’s Data Classification Policy C0–C4

Learn how to turn Qatar’s C0–C4 data labels into practical access, encryption, sharing, monitoring, retention and incident-response controls.

July 8, 2026

UAE Child Digital Safety Rules

A practical guide to the UAE’s new child digital safety rules, including the under-15 social media restriction, age assurance, privacy, advertising and product changes.

July 5, 2026

Oman PDPL 2026: Requirements and Compliance Roadmap

Oman’s PDPL is now enforceable. Learn who may be covered, the consent, DPO, breach, permit and transfer requirements, and what to prepare in 2026.

July 4, 2026

Kuwait NBCC 2026: Scope, Controls and Readiness Roadmap

Understand Kuwait’s 2026 National Basic Cybersecurity Controls, who may be covered, key cloud and security requirements, and how to build an 18-month compliance roadmap.

July 4, 2026

Top 10 Cybersecurity and GRC Developments in Türkiye - First Half of 2026 Recap

A practical H1 2026 recap of Türkiye’s top cybersecurity and GRC developments, covering Cybersecurity Law, KVKK decisions, VERBİS, CCTV, biometrics, data breaches, and compliance priorities.

June 19, 2026

Top 10 Cybersecurity and GRC News Since March 2026

A practical recap of the biggest cyber and GRC developments since March 2026.

April 10, 2026

State of Privacy 2026: The uncomfortable truth about “doing more with less”

Privacy risk is rising fast in 2026, but teams and budgets are shrinking—so the only way to keep up is to operationalize privacy (privacy-by-design, real training, smart automation) instead of treating it like a compliance checkbox.

January 22, 2026

Moody’s 2026 AI Outlook: The Real Risk Isn’t the Model

Moody’s makes it clear that AI is accelerating fast, but the biggest threats aren’t “which model you pick” — they’re the infrastructure costs, governance gaps, and cybersecurity exposure that come with scaling AI into real workflows.

January 10, 2026

Generative AI & Personal Data Protection Under KVKK

KVKK has released a detailed 15-question guide explaining how generative AI should be used under Turkish data protection law.

November 25, 2025

What Cloudflare's Global Outage Means for You

A global Cloudflare outage today disrupted major online services like ChatGPT and X, highlighting the internet's reliance on critical infrastructure and prompting calls for enhanced digital resilience.

November 18, 2025

Prompt Injections: The Security Risk Behind AI Systems

A practical deep-dive into why prompt injections remain one of the most serious security risks in modern AI systems—and what organizations must do to reduce exposure.

November 17, 2025

Egypt’s Personal Data Protection Law

Egypt’s Personal Data Protection Law (PDPL) sets strict rules for how organizations collect, store, and use personal data, requiring clear user consent, licensing for sensitive data, and fast responses to data breaches.

November 14, 2025

Saudi Arabia’s PDPL (2025): A Deep Dive

Saudi Arabia’s Personal Data Protection Law (PDPL)—fully enforceable since September 2024—sets out GDPR-style obligations for both local and foreign organizations processing Saudi residents’ data, including 72-hour breach notifications, controller registration, DPO appointments, and strict cross-border-transfer conditions.

November 12, 2025

Understanding the UAE’s Personal Data Protection Law (PDPL)

The UAE’s first federal privacy law, the PDPL, marks a major step toward GDPR-style data protection across all seven emirates. It establishes clear rules for consent, data rights, and cross-border transfers — reshaping how businesses handle personal data in the UAE and beyond.

November 11, 2025

Understanding Middle East Data Protection Laws for 2025

A 2025 overview of how Middle East countries—from the UAE and Saudi Arabia to Egypt, Jordan, and Israel—are shaping their data protection laws. The article compares regional frameworks to the EU’s GDPR and gives practical guidance for businesses on compliance, risks, and regulatory trends across MENA.

November 7, 2025

When “pseudonymised” doesn’t automatically mean “safe” for transparency obligations

The recent CJEU judgment in Case C-413/23 P clarifies that pseudonymised data can still qualify as personal data if the sender—or even the recipient—can reasonably re-identify individuals. Controllers must therefore maintain transparency obligations even when data appears anonymised, reshaping how compliance teams assess risk and disclosure duties.

November 4, 2025

China-linked “Tick Group” exploits new Lanscope zero-day

A new zero-day vulnerability in Motex Lanscope (CVE-2025-61932) is being actively exploited by the China-linked Tick Group to deploy backdoors and steal corporate data. Learn how the attack works and what organizations should do to stay protected.

November 1, 2025

Project: Empowering Teachers in Data Protection Awareness

KVKK has launched the “Digital Literacy for a Secure Future” project to train teachers and school administrators across Türkiye on digital literacy and personal data protection. The initiative aims to build a privacy-aware culture and empower educators to guide students safely through the digital world.

October 31, 2025

Germany Pushes EU to Ease GDPR: What It Means for Businesses

Germany urges the EU to ease GDPR compliance and launch broader reform. Learn how Berlin’s proposals could simplify data protection for SMEs while preserving privacy standards.

October 31, 2025

Cybersecurity Halloween

Every Halloween, we talk about ghosts and monsters — but in cybersecurity, the real nightmares hide inside your systems. This post reveals the 10 spookiest vulnerabilities haunting businesses in 2025 — from shadow IT and phishing vampires to AI-driven demons — and how to keep them from coming back from the dead.

October 28, 2025

GDPR in Turkiye: Complete 2025 Guide for Compliance, Rights & Penalties

This article explores the differences between GDPR and KVKK, the rights of individuals, compliance requirements, penalties for violations, and how organizations in Türkiye can adapt. Understanding GDPR in Türkiye is crucial for companies to build trust, avoid fines, and stay competitive in the global digital economy.

October 3, 2025

KVKK in Turkey: What It Is, Requirements & 2026 Compliance Guide

Understand Turkey’s KVKK, including lawful processing, VERBİS, data subject rights, breach notification, retention and international data transfers. Updated for 2026.

September 28, 2025

Understanding DPR in Turkey: What It Is, Who Needs It, and How Kooch Can Help

Foreign companies processing Turkish personal data must appoint a Data Protection Representative (DPR) in Turkey and register with VERBIS. This ensures legal compliance, smooth communication with the KVKK Authority, and proper handling of data subject requests. Kooch helps businesses manage DPR obligations end-to-end, from appointment and registration to ongoing compliance.

September 28, 2025