Kooch provides scoped privacy and information security services for foreign companies entering Türkiye, Turkish startups and SMEs, and teams preparing for ISO/IEC 27001. Each engagement defines its outputs, client responsibilities, exclusions and escalation points.
A scoped KVKK readiness programme for startups. We assess applicability, map processing, prepare agreed notices and controls, and support VERBİS work where registration is required. Timing depends on scope, evidence and client approvals.
Get a comprehensive audit of your data privacy practices. We identify compliance gaps against KVKK, GDPR, or both, and deliver a prioritized remediation plan to close them.
Build and test an ISO/IEC 27001:2022 ISMS with scoped policies, risk assessment, Statement of Applicability, evidence and readiness support. Certification audits and certification decisions remain with an independent accredited certification body.
Recurring privacy and compliance operations support, including scheduled reviews, evidence tracking, request and incident workflows, and regulatory monitoring. The client remains responsible for decisions and legal counsel handles legal opinions where needed.
For foreign controllers that are required to register with VERBİS, Kooch can serve as the Türkiye-based data controller representative, receive and forward communications, and maintain the agreed registry information. Read the DCR guide.
.webp)