KVKK’s New Privacy Guide for Lawyers: What Law Firms Should Review

KVKK’s New Privacy Guide for Lawyers: What Law Firms Should Review




Last updated: 2026-09-28

A law firm may protect its client conversations carefully while leaving case documents in shared mailboxes, personal cloud accounts or an AI chat history. Its privacy review needs to cover all of those places.

On 22 September 2026, Türkiye’s Personal Data Protection Authority launched its practice guide on protecting personal data in lawyers’ professional activities. The Authority prepared it with the views and contributions of the Union of Turkish Bar Associations, Türkiye Barolar Birliği.

The publication addresses how Law No. 6698 applies to legal practice. It is guidance, rather than a new law with a separate commencement date. Its coverage includes professional roles, processing conditions, transfers, generative AI, security and controller obligations.

For a firm reviewing its position, the useful starting point is a real matter file: who supplied the information, why the firm needs it, who can access it, where it goes and what happens when the engagement ends. The implementation suggestions below are Kooch’s recommendations, alongside the applicable legal requirements.

Who is responsible for the data?

The guide distinguishes several working arrangements:

  • Independent practitioners generally act as controllers.
  • Sharing an office does not automatically make lawyers responsible for one another’s separate matters.
  • A legal partnership with legal personality can itself be the controller.
  • Employed lawyers, trainees and support staff acting within the employer’s organisation are generally neither separate controllers nor external processors for that work. Separately undertaken matters need their own assessment.
  • External delegated counsel working under the appointing lawyer’s instructions can be a processor. Independent decisions about a different purpose can make that lawyer a controller for that processing.

The practical task is to name the correct person or legal entity in the firm’s records, notices and contracts. A trading name alone may not answer the question.

A client’s supplier contract also cannot settle the issue simply by calling its external lawyers “processors”. A published Board decision concerning a legal partnership assessed the actual decision-making authority, despite the contract’s processor label. Control over the purpose and means of processing matters more than the heading chosen by the parties.

Before accepting a client’s data-processing addendum, compare it with the work being performed. Who decides what evidence to collect, how to use it and which people need access? Record the conclusion for that engagement.

VERBİS exemption has a limited scope

Board Decision 2018/32 exempts lawyers practising under the Attorneyship Law from registration in the Data Controllers’ Registry, commonly accessed through VERBİS. That is a registration exemption. It does not remove applicable duties concerning lawful processing, notices, security, transfers or deletion.

Do not extend that exemption automatically to a separate consultancy or technology business because a lawyer owns it. Identify the controller and activity before deciding which exemption applies.

A useful internal record can be much smaller than a complex compliance platform. Start with a list of processing activities, the people concerned, data categories, purposes, legal grounds, recipients, systems and retention rules. Give someone responsibility for updating it when the firm adopts a new tool or changes a workflow.

A case file needs more than the client’s consent

Article 5 provides several grounds for processing ordinary personal data without explicit consent. Relevant grounds can include a statutory provision, a legal obligation, necessary processing concerning the parties to a contract, or necessity for establishing, exercising or protecting a right. Choose the ground that actually fits the activity.

The contract ground concerns data about the contract’s parties. It does not automatically cover an opposing party or witness simply because the lawyer has a client engagement.

Necessary processing for a legal claim can support the use of relevant third-party information without that person’s consent. It does not justify collecting everything available about them. Article 4 still requires a defined purpose and proportionate processing.

For example, when preparing an employment dispute, ask the client for the records needed to establish the disputed events. A complete export of every employee’s mailbox may introduce unrelated correspondence and health information. Ask which accounts, dates and issues are relevant before collecting the material.

Avoid a blanket consent form as the default answer to every processing activity. Where another legal ground applies, explain and document it. The client’s signature cannot supply consent on behalf of all the other people mentioned in the file.

Special-category data require a separate check

Health information, criminal convictions, trade-union membership, biometric data and other categories listed in Article 6 need a qualifying Article 6 condition and the prescribed additional safeguards.

The amended Article 6 permits necessary processing for establishing, exercising or protecting a right. Consequently, explicit consent is not invariably required for relevant sensitive evidence in a legal matter.

However, professional secrecy does not by itself allow any use of health data. The Article 6 condition for persons under a secrecy duty is tied to specified health-related purposes; it is not a general permission for lawyers.

As an implementation measure, flag sensitive documents when they enter the file. Restrict their access and review whether the whole document is necessary before sending it outside the matter team.

Notices must cover more than onboarding

A privacy notice should identify the controller, purposes, collection method and legal grounds, intended recipient categories and transfer purposes, and the individual’s rights. Providing a notice and obtaining consent are different tasks. A non-consent legal ground does not automatically remove the notice obligation.

Plan notices for prospective clients and staff as well as retained clients. For information obtained indirectly, the applicable rules address notification within a reasonable period, at first contact when the data are used to communicate, or no later than the first transfer where the data are transferred.

Opposing-party and witness data therefore need deliberate handling. Do not assume the client’s notice reaches those individuals. Equally, do not send a template that exposes confidential case strategy. Where notification and the conduct of proceedings appear to conflict, the responsible lawyer should assess the particular facts and any applicable statutory exception.

A workable process should record which notice was supplied, when and through which channel. Keep the wording specific enough that a person can understand the firm’s actual use of their information.

Sharing with experts, counsel and service providers

Domestic disclosure requires an Article 8 assessment. Lawful collection does not, on its own, authorise every later recipient. The relevant Article 5 or Article 6 condition must support the transfer, with sufficient safeguards for special-category data.

Before sharing with an expert, translator, external lawyer or document-service provider, record the task and the information needed to perform it. Check the recipient’s role rather than treating every professional recipient as a processor. A court-appointed expert’s position may differ from that of a supplier following the firm’s instructions.

For an external processor, Kooch recommends written terms addressing permitted processing, confidentiality, access controls, subcontracting, incident escalation, return or deletion, and evidence of compliance. Match those terms to the service. A scanning company and a forensic investigator do not need identical permissions.

Article 12 makes the controller jointly responsible with a party processing on its behalf for the required security measures. Outsourcing therefore needs oversight as well as a contract.

For delegated counsel, include clear matter instructions and a secure handover process. For experts, consider whether a relevant extract or redacted document will answer the question before transferring the entire case archive.

Review cloud storage and SaaS as data flows

A software subscription can involve several recipients and locations. Ask providers where live files and backups are held, which entities operate the service, who can access content for support and whether subcontractors process it abroad. Include email, transcription, online translation, document review and messaging tools in this review.

Where the arrangement involves an international transfer, Article 9 must be addressed. In general, this means a qualifying processing condition together with an applicable adequacy decision or, in its absence, an appropriate safeguard and the other statutory conditions. Relevant special legislation and international agreements also need consideration.

The limited fallback grounds for occasional transfers are not a sound default for continuous overseas storage. A legal-claims ground for processing a case file does not automatically authorise routine international transfers of it.

Standard Contracts need an owner and a deadline

Türkiye’s published Standard Contracts cover four controller/processor combinations. Select the form that matches the actual exporter and importer. A vendor’s ordinary data-processing agreement or EU transfer clauses are not, by themselves, the Turkish Standard Contract mechanism.

Where this mechanism is used, the signed Standard Contract must be notified to the Authority within five business days of signing. Allocate responsibility before signature and retain the submission evidence.

For procurement, ask the provider to confirm its contracting entity and the available Turkish transfer arrangement before uploading live case files. If it cannot support the proposed arrangement, assess another lawful mechanism or change the service configuration or supplier.

Cloud, SaaS & AI

Before uploading a case file

Check the proposed use before sharing client or third-party data.

  1. Required data

    Identify the task and the minimum information needed. Remove unrelated material and assess special-category data separately.

  2. Recipient and role

    Identify the receiving legal entity, its role and any subcontractors. Check confidentiality and processing terms.

  3. Processing locations

    Confirm storage, backups and support access. Check whether any processing or access involves another country.

  4. Transfer arrangement

    Assess the applicable domestic or international transfer conditions. Document the mechanism and any notification duties.

  5. Approval owner

    Assign the review to a named person. Record the decision, approved account settings and any limits on use.

Material information missing? Resolve it before upload.Ask the provider for clarification or use an alternative arrangement that has been assessed.

An internal review aid, not a compliance certification. Completing these checks does not replace the legal assessment of the particular transfer.

‍

‍

Generative AI: examine both the input and the service

The guide recommends masking or anonymising inputs where possible, avoiding special-category uploads, minimising data, reviewing retention, training, human-review, subprocessor and security policies, and setting internal rules. It also identifies potential domestic or international transfers when documents are uploaded.

For implementation, distinguish a general research question from a request containing evidence from a live dispute. “Explain the structure of a witness statement” has a different data profile from uploading a witness interview and asking for a summary.

An internal AI approval process should test the actual account and product configuration. Record whether chat history is retained, whether administrators can control sharing, and what happens when an account is closed. Marketing descriptions are not enough to answer those operational questions.

Removing names is not necessarily anonymisation. An address, unusual event, employer, case number or combination of facts can still identify someone. Treat a document as personal data where identification remains possible.

For routine drafting, use fictional facts or a genuinely anonymous description where feasible. If identifiable information is necessary, require a documented review before use. Turning off model training should not be treated as approval of all the remaining processing and transfer conditions.

Professional secrecy and KVKK obligations coexist

Article 36 of the Attorneyship Law protects information learned through professional duties. KVKK separately regulates processing of personal data. A firm therefore needs to assess both confidentiality and the legal conditions for collecting, using, disclosing and retaining information.

The judicial-processing exception is not a blanket exemption for lawyers. In a published decision involving a lawyer’s disclosure of debt information to a relative, the Board rejected reliance on that exception. Representing a party does not turn every disclosure into an exempt judicial activity.

Privacy requests also need a controlled response. Applicable requests must be resolved as soon as possible and within 30 days. Verify the requester’s identity and scope, then assess what can lawfully be provided. A request about someone’s personal data should not trigger an unreviewed export of a client’s entire file. Record reasons for any refusal or limitation.

Closed files need a retention decision

Article 39 of the Attorneyship Law requires a lawyer to retain entrusted documents for three years after the mandate ends. Where the client has been notified in writing to collect them, that custody obligation ends three months after notification. The provision also addresses withholding documents where fees and expenses remain unpaid.

These rules should not be converted into an automatic instruction to delete every record three years after a case closes. Case closure and the end of the mandate may differ. Other applicable duties or a continuing need to establish or defend rights can affect retention.

The guide discusses five-year retention for a mandate-related receivable, subject to a case-specific assessment. This is not a universal five-year rule.

For each record category, document the reason for retention, the event that starts the period, the review date and who can authorise disposal. Distinguish original client documents from billing records, substantive evidence and duplicate working copies.

When the grounds for processing cease, KVKK requires deletion, destruction or anonymisation, even without a request from the individual. A practical disposal procedure should address email attachments, exported folders, local devices and backup expiry as well as the central matter system.

‍

‍

Make security controls fit the way lawyers work

Article 12 requires appropriate technical and organisational measures and internal compliance checks. Translate that duty into controls that work during hearings, remote work and urgent document exchanges.

Kooch recommends starting with individual accounts, multi-factor authentication for email and document systems, encrypted work devices and access limited to the relevant team. Remove access promptly when someone leaves a matter or the firm.

Test whether staff can accidentally create public document links. Check how a lost laptop would be locked or wiped, and whether backups can actually restore a matter folder. Include paper records: storage, transport, printing and secure disposal need named owners too.

Training should use the firm’s own workflows. Practise spotting a wrong email recipient, reviewing a sharing link and escalating a lost file. Record and address the failures the exercise reveals.

Prepare for the first hours of a breach

Where processed personal data have been unlawfully obtained by others, the controller must notify the Board without delay and no later than 72 hours after becoming aware. Affected people must also be informed within the shortest reasonable period after they are identified. These are distinct notification requirements.

Incomplete information is not a reason to wait for a finished forensic report: the procedure permits information to be supplied in stages without delay. A processor must notify the controller without delay. The firm should document the incident, its effects and the measures taken, and maintain a response plan.

For implementation, assign a lead and deputy who can act outside office hours. Give IT providers and staff one immediate escalation route. The initial record should capture when the firm learned of the incident, what is known about access or disclosure, affected systems and evidence that must be preserved.

Treat notification and containment as concurrent work. Someone needs to stop further exposure while someone else assesses the legal reporting requirements and prepares accurate communications.

A practical checklist for the next review

Use a small sample of live and closed matters to test the firm’s arrangements:

  • Responsibility: Is the correct controller identified, including for shared-office and delegated work?
  • Collection: Can the matter team explain why it holds each significant document and where it came from?
  • Legal grounds: Are third-party and special-category data assessed separately from the client engagement?
  • Notices: Is there evidence of delivery and a process for indirect collection?
  • Sharing: Do recipients receive only what their task requires, through an approved channel?
  • Technology: Are the actual cloud, SaaS and AI services known, including personal accounts used for work?
  • Transfers: Are the international arrangements documented, with any Standard Contract notification assigned and recorded?
  • Retention: Does each closed file have a reason to remain, a review date and a disposal owner?
  • Security: Can the firm demonstrate access removal, secure sharing and successful restoration from backup?
  • Response: Can staff reach the incident lead immediately, and can the firm process privacy requests within the applicable deadline?

Assign each gap to a person and a completion date. Repeat the sample after the changes; a rewritten policy is useful only if the working process follows it.

Start with the files and tools already in use

A focused review of one matter’s journey can reveal where the firm needs clearer instructions, different access settings or a better supplier arrangement. Resolve those findings before expanding the exercise across the practice.

Kooch can support the operational work through data mapping, security and supplier reviews, retention workflows and incident-response preparation. Contact Kooch to discuss a scoped KVKK gap assessment, with the firm’s lawyers retaining responsibility for professional-duty and case-specific legal decisions.

Sources / References

Official sources checked on 28 September 2026. Page numbers below refer to the guide’s printed pagination.

  1. KVKK — Launch announcement, 22 September 2026 and publication announcement. Confirm preparation, launch and subject coverage.
  2. KVKK — Avukatların Mesleki Faaliyetlerinde Kişisel Verilerin Korunmasına İlişkin Uygulama Rehberi. Roles: pp. 40–63; processing: pp. 71–92; transfers and AI: pp. 113–122 and 145–146; obligations: pp. 129–141. The imprint says July 2026; the official launch was in September.
  3. Law No. 6698 — Authority’s consolidated English text. Articles 4–12 and 28; includes amended Articles 6 and 9.
  4. KVKK — Ordinary personal-data processing conditions and special-category conditions. Legal grounds and additional safeguards.
  5. Board Decision 2018/32. Registration exemption for lawyers practising under Law No. 1136.
  6. Board Decision 2023/437. A legal partnership’s actual controller role despite a contractual processor label.
  7. Board Decision 2020/26. Disclosure by a lawyer and the limits of the judicial-processing exception.
  8. KVKK — Notice obligations and official specialist publication discussing indirect collection, pp. 403–404. Read the latter as supporting discussion; the notice requirements derive from the applicable communiqué.
  9. KVKK — International transfers, Standard Contract forms, and notification procedure. Transfer framework, role combinations and five-business-day deadline.
  10. KVKK — Security obligations, disposal duties, and responding to individuals.
  11. Board Decision 2019/10 — Breach notification procedure. Notification timing, staged information, processor escalation and response planning.
  12. Diyarbakır Bar Association — Attorneyship Law, Article 39, cross-checked against pp. 127–128 and 133–134 of the 2026 guide; Union of Turkish Bar Associations decision reproducing Article 36. Entrusted-document custody and professional secrecy.
Masoud Salmani