KVKK Compliance Checklist
A working checklist for companies with operations, staff or customers in Turkey. Print it, assign owners, work through it.
Note: General information, not legal advice. Have the final package reviewed by qualified Turkish counsel.
Phase 1 — Map (week 1)
- List every business process that touches personal data (HR, recruitment, sales, support, marketing, finance, security cameras, visitor logs)
- For each process record: data categories, data subject groups, purpose, lawful basis, retention period, recipients
- Identify special category data (health, biometric, union membership, religious or political data, criminal records)
- List every system holding personal data (CRM, HRIS, email, cloud storage, ticketing, payroll, analytics)
- Flag every cross-border transfer — including foreign-hosted email and cloud services
Phase 2 — Legal basis (week 2)
- Assign an Article 5 lawful basis to each process
- Remove consent where a contractual or legal basis exists
- Identify processing that genuinely requires explicit consent (typically marketing communications)
- Check special category processing against the stricter conditions
- Document the reasoning — you may need to justify it later
Phase 3 — Documents (week 3)
- Privacy notice covering all Article 10 elements, in Turkish
- Explicit consent text, standalone and specific, with a withdrawal mechanism
- Processing inventory in a maintainable format
- Retention and destruction policy with periodic deletion cycles
- Employee privacy notice and confidentiality undertakings
- Data processing terms in contracts with vendors and processors
Phase 4 — Registry (week 4)
- Assess whether you meet the VERBIS registration criteria
- If a foreign-established controller: check whether a representative in Turkey is required
- Appoint a contact person
- Complete the declaration — it must match your privacy notice
- Diarise the 30-day update rule for any change
Details: VERBIS registration for foreign companies.
Phase 5 — Security and operations (ongoing)
- Role-based access control; least privilege
- MFA on all business-critical systems
- Encrypted backups, tested restores
- Staff awareness training, repeated annually
- Incident response plan including breach notification duties to the Board and affected individuals
- Periodic deletion runs for expired data, with records kept
- Data subject request procedure with a 30-day response clock
- Annual review of the entire package
Red flags that create real exposure
- Marketing emails without documented consent — the single most common source of complaints
- Ex-employee data kept indefinitely — the second most common
- A privacy notice that contradicts the VERBIS declaration — both are visible, and the inconsistency is the finding
- Untracked cloud transfers — "we use a US email provider" appearing nowhere in the documentation
- Cameras pointed at prohibited areas or recording without notice signage
Where teams underestimate effort
Mapping is the slow part, not drafting. Expect the inventory to take longer than every document combined — and expect to discover at least one system nobody remembered. That discovery is the point of the exercise.
FAQ
How long does full compliance take?
For a straightforward SME structure, three to five weeks of focused work. Complex groups with multiple entities and heavy special category processing take considerably longer.
Can we use our GDPR documents?
As raw material, yes. As a substitute, no — see KVKK vs GDPR.
Is there an official certification?
No. Turkish law does not provide a state-issued compliance certificate. Compliance is demonstrated by your documentation and actual practice.
What if we're not required to register with VERBIS?
Registration is only one obligation. Privacy notices, security measures, retention limits and data subject rights apply regardless.
Generate the document set: KVKK Otomat produces the Turkish-language privacy notice, consent text, inventory, retention policy and VERBIS preparation list from your process map. Start with the full legal overview.


