KVKK in Turkey: What It Is, Requirements & 2026 Compliance Guide

KVKK in Turkey: What It Is, Requirements & 2026 Compliance Guide

Last updated: August 17, 2026

If your business collects customer details, employee records, job applications, website leads, user analytics, support tickets, identification information or other data relating to people in Türkiye, the Turkish Personal Data Protection Law — commonly known as KVKK — may be relevant to how that information is collected, used, stored, shared and deleted.

The short answer: KVKK is Türkiye's principal personal-data protection law, Law No. 6698. It establishes rules for processing personal data, informing individuals, securing information, responding to data-subject requests, retaining and deleting data, registering certain controllers with VERBİS and transferring personal data outside Türkiye.

But KVKK compliance is not simply a privacy-policy exercise.

A functioning compliance programme connects legal requirements to real operations: CRM systems, HR processes, cloud infrastructure, marketing tools, SaaS vendors, access permissions, retention schedules, incident response and international data flows.

Quick overview

KVKK in 60 seconds

The key parts of Türkiye’s personal-data protection framework that businesses should understand before building a compliance programme.

01

Law No. 6698

KVKK is Türkiye’s principal personal-data protection law. It regulates how personal data is collected, used, stored, shared and deleted.

02

Regulator

The framework is overseen by the Personal Data Protection Authority and the Personal Data Protection Board.

03

Lawful processing

Every processing activity needs an appropriate legal condition. Explicit consent is not always required and should not be used as a default.

04

Transparency & rights

Individuals must be properly informed about processing and can exercise rights relating to access, correction, deletion and other matters.

05

VERBİS & governance

Certain controllers must register with VERBİS. Registration is only one part of compliance and exemptions do not remove other KVKK duties.

06

Transfers & breaches

International transfers must follow Article 9, while personal-data breaches require rapid assessment and may trigger notification duties.



What does KVKK mean?

KVKK stands for Kişisel Verilerin Korunması Kanunu, or the Turkish Personal Data Protection Law.

Law No. 6698 was adopted on 24 March 2016 and published in the Official Gazette on 7 April 2016. Its purpose is to protect fundamental rights and freedoms — particularly privacy — when personal data is processed.

The law applies to personal-data processing carried out wholly or partly by automated means and also to certain non-automated processing where the data forms part of a data filing system.

The regulatory structure includes the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) and the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu).

KVKK at a glance
Topic What businesses should know
Law Personal Data Protection Law No. 6698.
Regulator Personal Data Protection Authority and Personal Data Protection Board.
Personal data Any information relating to an identified or identifiable natural person.
Core obligations Lawful processing, transparency, proportionality, security, retention, rights handling and compliant transfers.
Data-subject requests Controllers must conclude requests as soon as possible and no later than 30 days.
Data breaches The Board interprets notification to it as without delay and no later than 72 hours after awareness.
International transfers Article 9 uses adequacy decisions, appropriate safeguards and limited incidental-transfer exceptions.
VERBİS Certain controllers must register. Registration exemptions do not remove other KVKK obligations.


What counts as personal data under KVKK?

Personal data means any information relating to an identified or identifiable natural person.

That can include obvious identifiers such as:

  • name and surname;
  • telephone number;
  • email address;
  • national ID or passport information;
  • home or delivery address;
  • employee information;
  • customer records; and
  • photographs.

It can also include less obvious information when it relates to an identifiable person, such as account identifiers, transaction histories, device or usage information, support records or combinations of data that make an individual identifiable.

The important question is therefore not simply, “Does this database contain names?”

It is:

Can the information relate to an identified or identifiable person?



Data controller vs data processor

This distinction matters because responsibility under KVKK depends heavily on the role an organization performs.

A data controller determines the purposes and means of processing personal data.

A data processor processes personal data on behalf of a controller and under its authorization.

For example, a SaaS company deciding why and how it collects its own customers' account information may be the controller for that activity. A cloud or service provider processing information solely on that company's instructions may instead act as a processor for that particular activity.

One company can also be a controller for some processing operations and a processor for others.

Do not assign these roles based only on what a contract calls the parties. The actual processing arrangement matters.



The five fundamental KVKK processing principles

Article 4 provides the foundation for almost every KVKK compliance decision.

Personal data must be:

  1. processed lawfully and fairly;
  2. accurate and kept up to date where necessary;
  3. processed for specified, explicit and legitimate purposes;
  4. relevant, limited and proportionate to those purposes; and
  5. retained only for the period required by applicable legislation or necessary for the processing purpose.

These principles continue to matter even where a valid processing condition exists.

For example, having a lawful condition for collecting an employee's identification information does not automatically justify collecting every available piece of information about that employee.

A lawful basis is not permission to process data without limits.

__wf_reserved_inherit



Does KVKK always require explicit consent?

No.

This is one of the most important practical points for organizations implementing KVKK.

Article 5 states that personal data cannot be processed without explicit consent, but it then provides several separate conditions under which processing can take place without seeking explicit consent.

Businesses should therefore identify the correct processing condition for each activity rather than treating consent as a universal default.

KVKK Article 5 processing conditions
Condition What it means Practical example
Explicit consent Freely given, specific and informed consent. An optional processing activity where no other Article 5 condition appropriately applies.
Expressly provided by law The processing is expressly required or permitted by legislation. Processing information required under a specific statutory requirement.
Life or physical integrity Necessary to protect a person's life or physical integrity where valid consent cannot be given. Processing information required during an emergency involving an incapacitated person.
Contract necessity Necessary and directly related to establishing or performing a contract with the individual. Using a customer's delivery address to fulfil an order.
Legal obligation Necessary for the controller to comply with a legal obligation. Processing employee information needed to meet statutory payroll obligations.
Made public by the individual The personal data has been made public by the data subject. Requires careful consideration of what the person actually made public and the processing purpose.
Establishment or protection of a right Processing is necessary to establish, exercise or protect a legal right. Retaining relevant records for the establishment or defence of a legal claim.
Legitimate interests Necessary for the controller's legitimate interests, provided the individual's fundamental rights and freedoms are not harmed. A narrowly defined operational interest supported by an appropriate balancing assessment.


Why unnecessary consent can create problems

Suppose an employer must process payroll information because of employment and tax obligations.

Trying to base that essential processing on employee consent may create the wrong impression that the employee can freely refuse the processing while still expecting the employer to perform the legally required activity.

Similarly, an online retailer normally does not need customer consent merely to process the address necessary to deliver an order where the contractual-processing condition properly applies.

The practical exercise should therefore be:

processing activity → purpose → data → Article 5 or Article 6 condition → retention → recipients → security controls.

Consent should be used where consent is actually the appropriate processing condition — not as a shortcut for avoiding that analysis.



What is valid explicit consent under KVKK?

KVKK defines explicit consent as consent that is:

  • freely given;
  • specific; and
  • informed.

That means broad statements such as “I consent to all processing of my personal data” are particularly problematic.

Consent should relate to identifiable processing activities and should not be bundled unnecessarily with unrelated purposes.

It is also important to separate two concepts that are frequently confused:

A privacy notice informs the individual. Explicit consent, where required, provides a processing condition.

Providing a privacy notice does not itself create consent, and obtaining consent does not remove the controller's transparency obligations.



Special categories of personal data changed in 2024

Article 6 covers special categories of personal data, including information concerning:

  • race and ethnic origin;
  • political opinions;
  • philosophical beliefs;
  • religion or other beliefs;
  • appearance;
  • association, foundation or trade-union membership;
  • health;
  • sexual life;
  • criminal convictions and security measures;
  • biometric data; and
  • genetic data.

The 2024 amendments materially changed the processing framework for these categories.

The previous distinction applied to certain types of special-category information was removed and Article 6 now contains a broader set of processing conditions. Depending on the circumstances, processing may be possible based on explicit consent, an express legal provision, protection of life or physical integrity, establishment or protection of a right, specified health-related purposes, certain employment or social-security obligations, and other conditions listed in Article 6.

This does not make special-category data ordinary data.

Adequate measures determined by the Board must still be applied.

Organizations processing health information, biometrics, criminal-record information or other sensitive categories should therefore examine both:

  1. the processing condition; and
  2. the additional security and governance measures surrounding the data.



KVKK privacy notices: when must people be informed?

Article 10 requires the controller, or an authorized person acting for it, to provide information when personal data is obtained.

The information includes:

  • the identity of the controller and representative, if any;
  • the purposes of processing;
  • recipients and purposes of potential transfers;
  • the method and legal basis of collection; and
  • the rights available to the individual under Article 11.

The obligation applies whether processing relies on explicit consent or another processing condition.

This is why a generic website privacy policy is not necessarily enough for every processing activity.

A company may need context-specific notices for areas such as:

  • recruitment;
  • employees;
  • website forms;
  • customer onboarding;
  • CCTV;
  • events;
  • support systems; or
  • marketing and referral programmes.

The timing and content need to match how the data is actually obtained and used.



What rights do individuals have under KVKK?

Article 11 gives individuals several rights concerning their personal data.

Among other things, a person can ask a controller:

  • whether personal data concerning them is being processed;
  • for information about that processing;
  • why the information is processed and whether it is used consistently with that purpose;
  • which third parties have received the information in Türkiye or abroad;
  • to correct incomplete or inaccurate data;
  • to erase or destroy data where the applicable conditions are met;
  • to notify relevant third parties of certain correction or deletion operations;
  • to object to a result against them arising from analysis exclusively through automated systems; and
  • to seek compensation for damage caused by unlawful processing.

A data subject generally applies first to the controller.

Under Article 13, the controller must respond as soon as possible and no later than 30 days, taking the nature of the request into account.

For operational teams, that makes data-subject requests a workflow problem as much as a legal-document problem.

You need to know:

  • who receives requests;
  • how identity is verified;
  • where the person's information exists;
  • which teams need to search;
  • whether information has been transferred to third parties;
  • what can legally be deleted; and
  • who approves and records the response.



Data security is a direct KVKK obligation

Article 12 requires controllers to take the necessary technical and organizational measures to provide an appropriate level of security.

The objectives include:

  • preventing unlawful processing;
  • preventing unlawful access; and
  • ensuring the protection of personal data.

Where processing is carried out by another person on behalf of the controller, the controller also has responsibility under Article 12 concerning those security measures.

KVKK therefore should not sit only with legal or compliance teams.

A practical programme should involve security, IT, HR, product, procurement and operations where relevant.

Depending on the organization's risks, sensible controls can include:

  • least-privilege access;
  • multifactor authentication;
  • access reviews;
  • encryption;
  • secure backups;
  • vulnerability and patch management;
  • logging and monitoring;
  • supplier security review;
  • separation of production and test environments;
  • secure deletion;
  • incident-response procedures; and
  • employee awareness and access governance.

The exact measures should reflect the data, technology, risks and processing environment rather than being copied mechanically from another organization.



What is the KVKK data-breach notification deadline?

Article 12 requires the controller to notify the Board and communicate the breach to affected individuals within the shortest time where processed personal data has been obtained by others through unlawful means.

The Board's Decision No. 2019/10 interprets the notification period to the Board as without delay and no later than 72 hours after the controller becomes aware of the breach.

If a notification cannot be submitted within that period for justified reasons, the reasons for delay should accompany the later notification.

Affected individuals should be informed within the shortest reasonable period once those affected have been identified.

This distinction matters:

72 hours is the Board's interpretation of “the shortest time” for notification to the Board — not simply wording copied directly from Article 12 itself.

A controller should therefore have an incident process capable of quickly answering:

  • What happened?
  • When did we become aware?
  • Which systems are involved?
  • Which categories of data are affected?
  • How many individuals may be affected?
  • What are the likely consequences?
  • What containment steps have been taken?
  • Is Board notification required?
  • How and when should affected people be contacted?



Retention: KVKK does not mean “keep it just in case”

Article 7 requires personal data to be erased, destroyed or anonymized when the reasons requiring its processing no longer exist, subject to other applicable legal requirements.

The deletion and destruction rules also create operational requirements.

For controllers with a personal-data storage and disposal policy, the interval between periodic disposal processes cannot exceed six months.

Controllers that are not required to issue such a policy must generally erase, destroy or anonymize the relevant personal data within three months after the obligation to do so arises.

Records concerning erasure, destruction and anonymization operations must generally be retained for at least three years, unless another legal requirement provides otherwise.

A useful retention schedule should therefore answer four questions for each data category:

Why do we have it? How long do we need it? What happens when that period expires? Can we prove the disposal occurred?



Cross-border data transfers: the old KVKK model has changed

This is one of the areas where older KVKK articles most frequently become inaccurate.

Article 9 was substantially amended in 2024.

The current regime follows a hierarchy based on:

  1. an adequacy decision;
  2. specified appropriate safeguards where there is no adequacy decision; or
  3. limited incidental transfer exceptions where neither of the first two routes is available.

Current KVKK cross-border transfer framework
Route When it is used Examples Key point
1. Adequacy An Article 5 or 6 processing condition exists and the destination is covered by a Board adequacy decision. Country, sector within a country, or international organization. As of 17 August 2026, the Authority states that no adequacy determination has yet been made.
2. Appropriate safeguard No adequacy decision exists, but the required processing condition, enforceable rights and effective remedies exist and an approved safeguard route is available. Board standard contract, binding corporate rules, written commitment, specified public-sector arrangements. A standard contract must be notified to the Authority within five business days after signature.
3. Incidental exception Neither adequacy nor an appropriate safeguard is available and one of Article 9's limited exceptional circumstances applies. Informed explicit consent to transfer risks, certain contract-related necessities, overriding public interest or protection of a right. These routes are designed for incidental transfers and should not be treated as the default basis for recurring transfers.



Are there currently KVKK adequate countries?

As of August 17, 2026, the Authority's current cross-border transfer page states that the Board has not yet made a determination identifying countries with adequate protection.

That makes the appropriate-safeguards route particularly important for recurring commercial transfers.



KVKK standard contracts

The amended regime introduced Board-published standard contracts as one of the principal appropriate safeguards for international transfers.

There are different contract structures covering:

  • controller to controller;
  • controller to processor;
  • processor to processor; and
  • processor to controller transfers.

A crucial practical point is that the standard contract itself does not follow the old prior-approval model.

Instead, Article 9(5) requires the signed standard contract to be notified to the Authority within five business days following signature.

Other appropriate-safeguard mechanisms — such as binding corporate rules or written commitments — have different approval requirements.

__wf_reserved_inherit


Why cloud systems need to be mapped

An international transfer is not limited to emailing a spreadsheet abroad.

Organizations should examine whether personal data can be accessed or received by organizations established outside Türkiye through:

  • cloud hosting;
  • global CRM systems;
  • HR platforms;
  • helpdesk systems;
  • analytics tools;
  • overseas parent companies;
  • outsourced support;
  • development environments;
  • backup infrastructure; or
  • other SaaS vendors.

The practical starting point is a data-flow map, not a contract template.



What is VERBİS?

VERBİS is the Data Controllers' Registry Information System used for registration with the Data Controllers' Registry.

Registration is not itself the entirety of KVKK compliance.

A company can be registered with VERBİS and still have problems with lawful processing, notices, security, retention, international transfers or rights handling.

Conversely, being exempt from VERBİS registration does not automatically exempt an organization from KVKK's other obligations.



Does every small company have to register with VERBİS?

No.

The Board has created several registration exemptions.

One important current exemption covers certain Türkiye-established natural or legal person controllers with:

  • fewer than 50 employees; and
  • an annual financial balance-sheet total below TRY 100 million;

provided their main activity is not processing special categories of personal data.

Other category-specific exemptions also exist.

Because VERBİS criteria and Board decisions can change, registration should be checked against the current rules rather than decided from an old checklist.



What about foreign companies?

Foreign companies should not assume that being incorporated outside Türkiye removes KVKK-related obligations.

At the same time, it is too broad to say that every foreign company processing any data connected with Türkiye automatically needs a Turkish representative.

Under the VERBİS framework, a foreign-established controller that is required to register follows the foreign-controller registration route through a representative in Türkiye.

The representative's functions include receiving Authority correspondence, transmitting requests and responses, supporting communications concerning data-subject applications and performing Registry operations on behalf of the foreign controller.

Whether a particular foreign company is subject to KVKK and whether registration and representation obligations apply should be evaluated from the company's actual processing activities, applicable exemptions, current Board criteria and regulatory practice.

__wf_reserved_inherit

Is KVKK the same as GDPR?

No.

KVKK and the EU GDPR share many privacy concepts, including:

  • lawful processing;
  • transparency;
  • purpose limitation;
  • data minimization;
  • security;
  • data-subject rights;
  • controller and processor roles; and
  • restrictions around international transfers.

But they are separate legal frameworks.

Important Turkish-specific issues can include:

  • VERBİS registration;
  • the Turkish representative route for foreign controllers where applicable;
  • KVKK-specific Article 5 and Article 6 analysis;
  • Turkish transparency requirements;
  • the Article 9 international-transfer mechanism;
  • Board decisions and Authority guidance;
  • local request and complaint procedures; and
  • interactions with other Turkish legislation.

A GDPR-compliant global privacy programme can provide a strong foundation, but it should not simply be relabelled “KVKK compliant” without checking Turkish requirements.



What about cookies, marketing and electronic communications?

KVKK may apply where cookies, advertising technologies, CRM activities, referral programmes or marketing campaigns involve personal-data processing.

But KVKK is not necessarily the only legal framework involved.

For example, commercial electronic communications can also involve separate requirements under Türkiye's electronic-commerce rules and the commercial-message regime.

This distinction matters because:

a KVKK processing condition is not automatically the same thing as permission to send a commercial electronic message.

Organizations should assess the complete activity rather than assuming that a privacy-policy checkbox solves every privacy and marketing requirement.



KVKK penalties and enforcement

KVKK provides for administrative fines for several forms of non-compliance, including failures concerning transparency, data security, Board decisions, Registry obligations and the Article 9 standard-contract notification requirement.

The statutory fine ranges are subject to annual revaluation, so old articles frequently quote outdated amounts.

For that reason, businesses should check the Authority's current-year administrative-fine table rather than relying on figures copied from the original text of Article 18.

Personal-data conduct can also intersect with criminal provisions under the Turkish Penal Code in appropriate circumstances.

Financial penalties are only one part of the risk. The Board can also require identified infringements to be remedied and, in specified circumstances, can order processing or international transfers to stop.



A practical KVKK compliance roadmap

If you are starting from limited documentation, do not begin by producing a large folder of policies.

Begin with the processing itself.

1. Map your data

Identify:

  • data subjects;
  • data categories;
  • systems;
  • processing purposes;
  • collection channels;
  • recipients;
  • processors;
  • international transfers; and
  • retention periods.

2. Assign a processing condition

Map each processing purpose to Article 5 or, where special-category data is involved, Article 6.

Do not automatically default to consent.

3. Check transparency

Review what individuals are told when information is obtained.

Match notices to real processing rather than copying a generic template.

4. Review sensitive data

Identify health, biometric, criminal-record and other special-category information and verify both the processing condition and additional safeguards.

5. Review your vendors

Identify processors and other third parties.

Check contracts, security expectations, access arrangements and data locations.

6. Map international transfers

Look beyond obvious transfers.

Cloud hosting, support access, analytics and global SaaS infrastructure can all be relevant.

Select the correct Article 9 transfer mechanism where required.

7. Determine VERBİS status

Assess current exemptions and registration requirements.

Foreign controllers should separately assess whether the representative route applies.

8. Build retention and deletion into systems

Define retention periods and create practical disposal workflows rather than relying only on a written retention policy.

9. Prepare for rights requests

Create an intake, identity-verification, search, review and response process capable of meeting the 30-day maximum period.

10. Prepare for incidents

Ensure security and privacy teams can escalate suspected personal-data breaches quickly enough to assess the 72-hour Board notification window.

Practical self-assessment

KVKK readiness scorecard

Use these ten areas to identify where your KVKK programme is already working and where implementation, evidence or ownership may still be missing.

Not assessed In progress Implemented
01

Data inventory & mapping

Know what personal data you hold, where it enters the business, which systems use it and where it goes.

Data subjects Systems Data flows
02

Processing conditions

Map each processing purpose to the appropriate Article 5 or Article 6 condition instead of defaulting to consent.

Purpose Legal condition Evidence
03

Transparency notices

Give individuals the right information at the right collection point and keep notices aligned with actual processing.

Article 10 Timing Channels
04

Special-category data

Identify sensitive data and verify both the processing condition and the additional organizational and technical safeguards.

Health Biometric Article 6
05

Vendor & processor governance

Identify processors and other recipients, then review contracts, access, security expectations and data locations.

Contracts Security Third parties
06

International transfers

Map foreign hosting, SaaS access and overseas support, then determine the applicable Article 9 transfer mechanism.

Cloud SCCs Article 9
07

VERBİS status

Determine whether registration applies, whether an exemption is available and whether foreign-controller representation is relevant.

Registration Exemptions Representative
08

Retention & disposal

Set documented retention periods and make sure deletion, destruction or anonymization happens in practice.

Retention Deletion Evidence
09

Data-subject requests

Establish a repeatable intake, identity-verification, search, review and response process that can meet the legal timeline.

Intake 30 days Response log
10

Security & breach readiness

Ensure security controls, escalation routes and incident procedures support fast investigation and KVKK breach assessment.

Article 12 Incident response 72-hour assessment


Frequently asked questions about KVKK


What does KVKK stand for?

KVKK stands for Kişisel Verilerin Korunması Kanunu, Türkiye's Personal Data Protection Law No. 6698.


Is KVKK Turkey's GDPR?

Not technically. KVKK and GDPR share many concepts, but they are separate laws with different requirements, procedures and regulatory mechanisms.


Is explicit consent always required under KVKK?

No. Article 5 contains several conditions allowing personal data to be processed without explicit consent. The correct condition should be determined for the specific processing activity.


Does a small company still need to comply with KVKK?

Potentially yes. An exemption from VERBİS registration does not remove the controller's other KVKK obligations.


Does every foreign company need a data controller representative in Türkiye?

No blanket rule should be stated that way. A foreign-established controller that is required to register with VERBİS uses the representative route. Whether registration applies should be evaluated against the company's activities, exemptions and current regulatory criteria.


How quickly must a company respond to a KVKK data-subject request?

Article 13 requires the controller to conclude the request as soon as possible and within 30 days at the latest.


Is the KVKK breach deadline 72 hours?

The law requires notification within the shortest time. Board Decision No. 2019/10 interprets this for Board notification as without delay and no later than 72 hours after awareness.


Can personal data be transferred from Türkiye to another country?

Yes, but the requirements of Article 9 must be satisfied. Depending on the circumstances, the transfer may rely on an adequacy decision, an appropriate safeguard such as a Board standard contract, or a limited incidental-transfer exception.


Do KVKK standard contracts require prior Board approval?

The Board's standard contracts are an appropriate safeguard under Article 9 and do not use the old prior-approval model. The signed contract must instead be notified to the Authority within five business days. Other mechanisms, including binding corporate rules and written commitments, have separate approval requirements.


Is having a privacy policy enough for KVKK compliance?

No. KVKK compliance involves processing conditions, transparency, security, retention, data-subject rights, vendor management, international transfers, incident response and, where applicable, VERBİS obligations.


Build KVKK around operations, not paperwork

The strongest KVKK programmes are not necessarily the ones with the most documents.

They are the ones where the documentation matches what actually happens.

A business should be able to explain:

  • what personal data it has;
  • why it has it;
  • the processing condition;
  • what people were told;
  • who can access it;
  • where it is transferred;
  • how long it is retained;
  • how requests are handled; and
  • what happens when something goes wrong.

That is the difference between having KVKK documents and having a functioning privacy programme.


Need to understand where your organization stands?

Kooch helps Turkish and international companies turn KVKK requirements into practical implementation.

Depending on your situation, this can include a KVKK gap analysis, processing inventory and data-flow mapping, transparency review, international-transfer assessment, VERBİS readiness, security-control review and prioritized remediation roadmap.

For foreign controllers that are required to register with VERBİS, Kooch can also support the Data Controller Representative process in Türkiye.

The objective is not to generate more paperwork. It is to identify what actually applies, what is missing and what should be fixed first.

Start with a KVKK readiness assessment →

This article provides general compliance information and is not individualized legal advice. Where the interpretation of Turkish law materially affects a business decision or legal position, qualified Turkish legal counsel should be consulted.

Related guidance and practical next steps

Masoud Salmani