Law No. 6698
KVKK is Türkiye’s principal personal-data protection law. It regulates how personal data is collected, used, stored, shared and deleted.

Last updated: August 17, 2026
If your business collects customer details, employee records, job applications, website leads, user analytics, support tickets, identification information or other data relating to people in Türkiye, the Turkish Personal Data Protection Law — commonly known as KVKK — may be relevant to how that information is collected, used, stored, shared and deleted.
The short answer: KVKK is Türkiye's principal personal-data protection law, Law No. 6698. It establishes rules for processing personal data, informing individuals, securing information, responding to data-subject requests, retaining and deleting data, registering certain controllers with VERBİS and transferring personal data outside Türkiye.
But KVKK compliance is not simply a privacy-policy exercise.
A functioning compliance programme connects legal requirements to real operations: CRM systems, HR processes, cloud infrastructure, marketing tools, SaaS vendors, access permissions, retention schedules, incident response and international data flows.
The key parts of Türkiye’s personal-data protection framework that businesses should understand before building a compliance programme.
KVKK is Türkiye’s principal personal-data protection law. It regulates how personal data is collected, used, stored, shared and deleted.
The framework is overseen by the Personal Data Protection Authority and the Personal Data Protection Board.
Every processing activity needs an appropriate legal condition. Explicit consent is not always required and should not be used as a default.
Individuals must be properly informed about processing and can exercise rights relating to access, correction, deletion and other matters.
Certain controllers must register with VERBİS. Registration is only one part of compliance and exemptions do not remove other KVKK duties.
International transfers must follow Article 9, while personal-data breaches require rapid assessment and may trigger notification duties.
KVKK stands for Kişisel Verilerin Korunması Kanunu, or the Turkish Personal Data Protection Law.
Law No. 6698 was adopted on 24 March 2016 and published in the Official Gazette on 7 April 2016. Its purpose is to protect fundamental rights and freedoms — particularly privacy — when personal data is processed.
The law applies to personal-data processing carried out wholly or partly by automated means and also to certain non-automated processing where the data forms part of a data filing system.
The regulatory structure includes the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) and the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu).
| Topic | What businesses should know |
|---|---|
| Law | Personal Data Protection Law No. 6698. |
| Regulator | Personal Data Protection Authority and Personal Data Protection Board. |
| Personal data | Any information relating to an identified or identifiable natural person. |
| Core obligations | Lawful processing, transparency, proportionality, security, retention, rights handling and compliant transfers. |
| Data-subject requests | Controllers must conclude requests as soon as possible and no later than 30 days. |
| Data breaches | The Board interprets notification to it as without delay and no later than 72 hours after awareness. |
| International transfers | Article 9 uses adequacy decisions, appropriate safeguards and limited incidental-transfer exceptions. |
| VERBİS | Certain controllers must register. Registration exemptions do not remove other KVKK obligations. |
Personal data means any information relating to an identified or identifiable natural person.
That can include obvious identifiers such as:
It can also include less obvious information when it relates to an identifiable person, such as account identifiers, transaction histories, device or usage information, support records or combinations of data that make an individual identifiable.
The important question is therefore not simply, “Does this database contain names?”
It is:
Can the information relate to an identified or identifiable person?
This distinction matters because responsibility under KVKK depends heavily on the role an organization performs.
A data controller determines the purposes and means of processing personal data.
A data processor processes personal data on behalf of a controller and under its authorization.
For example, a SaaS company deciding why and how it collects its own customers' account information may be the controller for that activity. A cloud or service provider processing information solely on that company's instructions may instead act as a processor for that particular activity.
One company can also be a controller for some processing operations and a processor for others.
Do not assign these roles based only on what a contract calls the parties. The actual processing arrangement matters.
Article 4 provides the foundation for almost every KVKK compliance decision.
Personal data must be:
These principles continue to matter even where a valid processing condition exists.
For example, having a lawful condition for collecting an employee's identification information does not automatically justify collecting every available piece of information about that employee.
A lawful basis is not permission to process data without limits.

No.
This is one of the most important practical points for organizations implementing KVKK.
Article 5 states that personal data cannot be processed without explicit consent, but it then provides several separate conditions under which processing can take place without seeking explicit consent.
Businesses should therefore identify the correct processing condition for each activity rather than treating consent as a universal default.
| Condition | What it means | Practical example |
|---|---|---|
| Explicit consent | Freely given, specific and informed consent. | An optional processing activity where no other Article 5 condition appropriately applies. |
| Expressly provided by law | The processing is expressly required or permitted by legislation. | Processing information required under a specific statutory requirement. |
| Life or physical integrity | Necessary to protect a person's life or physical integrity where valid consent cannot be given. | Processing information required during an emergency involving an incapacitated person. |
| Contract necessity | Necessary and directly related to establishing or performing a contract with the individual. | Using a customer's delivery address to fulfil an order. |
| Legal obligation | Necessary for the controller to comply with a legal obligation. | Processing employee information needed to meet statutory payroll obligations. |
| Made public by the individual | The personal data has been made public by the data subject. | Requires careful consideration of what the person actually made public and the processing purpose. |
| Establishment or protection of a right | Processing is necessary to establish, exercise or protect a legal right. | Retaining relevant records for the establishment or defence of a legal claim. |
| Legitimate interests | Necessary for the controller's legitimate interests, provided the individual's fundamental rights and freedoms are not harmed. | A narrowly defined operational interest supported by an appropriate balancing assessment. |
Suppose an employer must process payroll information because of employment and tax obligations.
Trying to base that essential processing on employee consent may create the wrong impression that the employee can freely refuse the processing while still expecting the employer to perform the legally required activity.
Similarly, an online retailer normally does not need customer consent merely to process the address necessary to deliver an order where the contractual-processing condition properly applies.
The practical exercise should therefore be:
processing activity → purpose → data → Article 5 or Article 6 condition → retention → recipients → security controls.
Consent should be used where consent is actually the appropriate processing condition — not as a shortcut for avoiding that analysis.
KVKK defines explicit consent as consent that is:
That means broad statements such as “I consent to all processing of my personal data” are particularly problematic.
Consent should relate to identifiable processing activities and should not be bundled unnecessarily with unrelated purposes.
It is also important to separate two concepts that are frequently confused:
A privacy notice informs the individual. Explicit consent, where required, provides a processing condition.
Providing a privacy notice does not itself create consent, and obtaining consent does not remove the controller's transparency obligations.
Article 6 covers special categories of personal data, including information concerning:
The 2024 amendments materially changed the processing framework for these categories.
The previous distinction applied to certain types of special-category information was removed and Article 6 now contains a broader set of processing conditions. Depending on the circumstances, processing may be possible based on explicit consent, an express legal provision, protection of life or physical integrity, establishment or protection of a right, specified health-related purposes, certain employment or social-security obligations, and other conditions listed in Article 6.
This does not make special-category data ordinary data.
Adequate measures determined by the Board must still be applied.
Organizations processing health information, biometrics, criminal-record information or other sensitive categories should therefore examine both:
Article 10 requires the controller, or an authorized person acting for it, to provide information when personal data is obtained.
The information includes:
The obligation applies whether processing relies on explicit consent or another processing condition.
This is why a generic website privacy policy is not necessarily enough for every processing activity.
A company may need context-specific notices for areas such as:
The timing and content need to match how the data is actually obtained and used.
Article 11 gives individuals several rights concerning their personal data.
Among other things, a person can ask a controller:
A data subject generally applies first to the controller.
Under Article 13, the controller must respond as soon as possible and no later than 30 days, taking the nature of the request into account.
For operational teams, that makes data-subject requests a workflow problem as much as a legal-document problem.
You need to know:
Article 12 requires controllers to take the necessary technical and organizational measures to provide an appropriate level of security.
The objectives include:
Where processing is carried out by another person on behalf of the controller, the controller also has responsibility under Article 12 concerning those security measures.
KVKK therefore should not sit only with legal or compliance teams.
A practical programme should involve security, IT, HR, product, procurement and operations where relevant.
Depending on the organization's risks, sensible controls can include:
The exact measures should reflect the data, technology, risks and processing environment rather than being copied mechanically from another organization.
Article 12 requires the controller to notify the Board and communicate the breach to affected individuals within the shortest time where processed personal data has been obtained by others through unlawful means.
The Board's Decision No. 2019/10 interprets the notification period to the Board as without delay and no later than 72 hours after the controller becomes aware of the breach.
If a notification cannot be submitted within that period for justified reasons, the reasons for delay should accompany the later notification.
Affected individuals should be informed within the shortest reasonable period once those affected have been identified.
This distinction matters:
72 hours is the Board's interpretation of “the shortest time” for notification to the Board — not simply wording copied directly from Article 12 itself.
A controller should therefore have an incident process capable of quickly answering:
Article 7 requires personal data to be erased, destroyed or anonymized when the reasons requiring its processing no longer exist, subject to other applicable legal requirements.
The deletion and destruction rules also create operational requirements.
For controllers with a personal-data storage and disposal policy, the interval between periodic disposal processes cannot exceed six months.
Controllers that are not required to issue such a policy must generally erase, destroy or anonymize the relevant personal data within three months after the obligation to do so arises.
Records concerning erasure, destruction and anonymization operations must generally be retained for at least three years, unless another legal requirement provides otherwise.
A useful retention schedule should therefore answer four questions for each data category:
Why do we have it? How long do we need it? What happens when that period expires? Can we prove the disposal occurred?
This is one of the areas where older KVKK articles most frequently become inaccurate.
Article 9 was substantially amended in 2024.
The current regime follows a hierarchy based on:
| Route | When it is used | Examples | Key point |
|---|---|---|---|
| 1. Adequacy | An Article 5 or 6 processing condition exists and the destination is covered by a Board adequacy decision. | Country, sector within a country, or international organization. | As of 17 August 2026, the Authority states that no adequacy determination has yet been made. |
| 2. Appropriate safeguard | No adequacy decision exists, but the required processing condition, enforceable rights and effective remedies exist and an approved safeguard route is available. | Board standard contract, binding corporate rules, written commitment, specified public-sector arrangements. | A standard contract must be notified to the Authority within five business days after signature. |
| 3. Incidental exception | Neither adequacy nor an appropriate safeguard is available and one of Article 9's limited exceptional circumstances applies. | Informed explicit consent to transfer risks, certain contract-related necessities, overriding public interest or protection of a right. | These routes are designed for incidental transfers and should not be treated as the default basis for recurring transfers. |
Are there currently KVKK adequate countries?
As of August 17, 2026, the Authority's current cross-border transfer page states that the Board has not yet made a determination identifying countries with adequate protection.
That makes the appropriate-safeguards route particularly important for recurring commercial transfers.
The amended regime introduced Board-published standard contracts as one of the principal appropriate safeguards for international transfers.
There are different contract structures covering:
A crucial practical point is that the standard contract itself does not follow the old prior-approval model.
Instead, Article 9(5) requires the signed standard contract to be notified to the Authority within five business days following signature.
Other appropriate-safeguard mechanisms — such as binding corporate rules or written commitments — have different approval requirements.

An international transfer is not limited to emailing a spreadsheet abroad.
Organizations should examine whether personal data can be accessed or received by organizations established outside Türkiye through:
The practical starting point is a data-flow map, not a contract template.
VERBİS is the Data Controllers' Registry Information System used for registration with the Data Controllers' Registry.
Registration is not itself the entirety of KVKK compliance.
A company can be registered with VERBİS and still have problems with lawful processing, notices, security, retention, international transfers or rights handling.
Conversely, being exempt from VERBİS registration does not automatically exempt an organization from KVKK's other obligations.
No.
The Board has created several registration exemptions.
One important current exemption covers certain Türkiye-established natural or legal person controllers with:
provided their main activity is not processing special categories of personal data.
Other category-specific exemptions also exist.
Because VERBİS criteria and Board decisions can change, registration should be checked against the current rules rather than decided from an old checklist.
Foreign companies should not assume that being incorporated outside Türkiye removes KVKK-related obligations.
At the same time, it is too broad to say that every foreign company processing any data connected with Türkiye automatically needs a Turkish representative.
Under the VERBİS framework, a foreign-established controller that is required to register follows the foreign-controller registration route through a representative in Türkiye.
The representative's functions include receiving Authority correspondence, transmitting requests and responses, supporting communications concerning data-subject applications and performing Registry operations on behalf of the foreign controller.
Whether a particular foreign company is subject to KVKK and whether registration and representation obligations apply should be evaluated from the company's actual processing activities, applicable exemptions, current Board criteria and regulatory practice.

No.
KVKK and the EU GDPR share many privacy concepts, including:
But they are separate legal frameworks.
Important Turkish-specific issues can include:
A GDPR-compliant global privacy programme can provide a strong foundation, but it should not simply be relabelled “KVKK compliant” without checking Turkish requirements.
KVKK may apply where cookies, advertising technologies, CRM activities, referral programmes or marketing campaigns involve personal-data processing.
But KVKK is not necessarily the only legal framework involved.
For example, commercial electronic communications can also involve separate requirements under Türkiye's electronic-commerce rules and the commercial-message regime.
This distinction matters because:
a KVKK processing condition is not automatically the same thing as permission to send a commercial electronic message.
Organizations should assess the complete activity rather than assuming that a privacy-policy checkbox solves every privacy and marketing requirement.
KVKK provides for administrative fines for several forms of non-compliance, including failures concerning transparency, data security, Board decisions, Registry obligations and the Article 9 standard-contract notification requirement.
The statutory fine ranges are subject to annual revaluation, so old articles frequently quote outdated amounts.
For that reason, businesses should check the Authority's current-year administrative-fine table rather than relying on figures copied from the original text of Article 18.
Personal-data conduct can also intersect with criminal provisions under the Turkish Penal Code in appropriate circumstances.
Financial penalties are only one part of the risk. The Board can also require identified infringements to be remedied and, in specified circumstances, can order processing or international transfers to stop.
If you are starting from limited documentation, do not begin by producing a large folder of policies.
Begin with the processing itself.
Identify:
Map each processing purpose to Article 5 or, where special-category data is involved, Article 6.
Do not automatically default to consent.
Review what individuals are told when information is obtained.
Match notices to real processing rather than copying a generic template.
Identify health, biometric, criminal-record and other special-category information and verify both the processing condition and additional safeguards.
Identify processors and other third parties.
Check contracts, security expectations, access arrangements and data locations.
Look beyond obvious transfers.
Cloud hosting, support access, analytics and global SaaS infrastructure can all be relevant.
Select the correct Article 9 transfer mechanism where required.
Assess current exemptions and registration requirements.
Foreign controllers should separately assess whether the representative route applies.
Define retention periods and create practical disposal workflows rather than relying only on a written retention policy.
Create an intake, identity-verification, search, review and response process capable of meeting the 30-day maximum period.
Ensure security and privacy teams can escalate suspected personal-data breaches quickly enough to assess the 72-hour Board notification window.
Use these ten areas to identify where your KVKK programme is already working and where implementation, evidence or ownership may still be missing.
Know what personal data you hold, where it enters the business, which systems use it and where it goes.
Map each processing purpose to the appropriate Article 5 or Article 6 condition instead of defaulting to consent.
Give individuals the right information at the right collection point and keep notices aligned with actual processing.
Identify sensitive data and verify both the processing condition and the additional organizational and technical safeguards.
Identify processors and other recipients, then review contracts, access, security expectations and data locations.
Map foreign hosting, SaaS access and overseas support, then determine the applicable Article 9 transfer mechanism.
Determine whether registration applies, whether an exemption is available and whether foreign-controller representation is relevant.
Set documented retention periods and make sure deletion, destruction or anonymization happens in practice.
Establish a repeatable intake, identity-verification, search, review and response process that can meet the legal timeline.
Ensure security controls, escalation routes and incident procedures support fast investigation and KVKK breach assessment.
KVKK stands for Kişisel Verilerin Korunması Kanunu, Türkiye's Personal Data Protection Law No. 6698.
Not technically. KVKK and GDPR share many concepts, but they are separate laws with different requirements, procedures and regulatory mechanisms.
No. Article 5 contains several conditions allowing personal data to be processed without explicit consent. The correct condition should be determined for the specific processing activity.
Potentially yes. An exemption from VERBİS registration does not remove the controller's other KVKK obligations.
No blanket rule should be stated that way. A foreign-established controller that is required to register with VERBİS uses the representative route. Whether registration applies should be evaluated against the company's activities, exemptions and current regulatory criteria.
Article 13 requires the controller to conclude the request as soon as possible and within 30 days at the latest.
The law requires notification within the shortest time. Board Decision No. 2019/10 interprets this for Board notification as without delay and no later than 72 hours after awareness.
Yes, but the requirements of Article 9 must be satisfied. Depending on the circumstances, the transfer may rely on an adequacy decision, an appropriate safeguard such as a Board standard contract, or a limited incidental-transfer exception.
The Board's standard contracts are an appropriate safeguard under Article 9 and do not use the old prior-approval model. The signed contract must instead be notified to the Authority within five business days. Other mechanisms, including binding corporate rules and written commitments, have separate approval requirements.
No. KVKK compliance involves processing conditions, transparency, security, retention, data-subject rights, vendor management, international transfers, incident response and, where applicable, VERBİS obligations.
The strongest KVKK programmes are not necessarily the ones with the most documents.
They are the ones where the documentation matches what actually happens.
A business should be able to explain:
That is the difference between having KVKK documents and having a functioning privacy programme.
Kooch helps Turkish and international companies turn KVKK requirements into practical implementation.
Depending on your situation, this can include a KVKK gap analysis, processing inventory and data-flow mapping, transparency review, international-transfer assessment, VERBİS readiness, security-control review and prioritized remediation roadmap.
For foreign controllers that are required to register with VERBİS, Kooch can also support the Data Controller Representative process in Türkiye.
The objective is not to generate more paperwork. It is to identify what actually applies, what is missing and what should be fixed first.
Start with a KVKK readiness assessment →
This article provides general compliance information and is not individualized legal advice. Where the interpretation of Turkish law materially affects a business decision or legal position, qualified Turkish legal counsel should be consulted.