KVKK Otomat

Turkish Data Protection Law (KVKK): A Guide for Foreign Companies

September 1, 2026 · 4 min read · KVKK Otomat

Turkish Data Protection Law (KVKK): A Guide for Foreign Companies

If your company employs people in Turkey, sells to Turkish customers, or processes data about individuals in Turkey, Law No. 6698 on the Protection of Personal Data — universally called KVKK — applies to you.

Most English-language material on this topic is either a machine translation of the statute or a law-firm brochure. This guide is the practical version: what the law asks for, and what you have to produce.

Note: General information, not legal advice. Turkish data protection practice is shaped by decisions of the Personal Data Protection Board; consult qualified Turkish counsel for your specific situation.

The short version

KVKK is structurally close to GDPR — same vocabulary of data controllers, data subjects, lawful bases and data subject rights — but differs in important operational details, especially around explicit consent, cross-border transfers and a public registry called VERBIS.

Four things you will need:

  1. A processing inventory covering every business process
  2. A privacy notice (aydınlatma metni) satisfying Article 10
  3. Explicit consent flows where no other lawful basis applies
  4. VERBIS registration, if you meet the registration criteria

Who is covered?

The law applies to data controllers processing personal data of individuals in Turkey. In practice this catches:

Being headquartered elsewhere does not remove the obligation, and GDPR compliance does not automatically satisfy KVKK. See KVKK vs GDPR.

Lawful bases (Article 5)

Processing is permitted without explicit consent when:

Otherwise, you need explicit consent — which must be specific, informed and freely given, and can be withdrawn at any time.

A frequent mistake by international teams: treating consent as the default basis. In Turkish practice, relying on consent where a contractual or legal basis exists actually weakens your position.

Special categories

Health, biometric, genetic, religious, philosophical, political, union membership, criminal record and similar data are special categories with stricter conditions. Processing them usually requires either explicit consent or a specific statutory basis, plus additional security measures determined by the Board.

The privacy notice (Article 10)

Your notice must state: the controller's identity, the categories of data processed, the purposes, the recipients of any transfers, the method and legal basis of collection, and the data subject's rights. It must be presented at the moment of collection — on the web form, in the employment file, at the reception desk.

VERBIS registration

VERBIS is a public registry of data controllers. Registration obligation depends on employee numbers, annual balance sheet totals and main activity, with specific rules for foreign-established controllers.

Two things international companies routinely miss:

  1. A foreign controller subject to registration may need to appoint a representative in Turkey.
  2. After registering, changes must be updated within 30 days.

Details: VERBIS registration for foreign companies.

Cross-border transfers

Transfers abroad are the area where KVKK and GDPR diverge most in practice. Transfers may be made on the basis of an adequacy decision, appropriate safeguards (including standard contractual clauses), or specific derogations — with notification requirements attached to some routes.

If your Turkish operation uses a cloud, CRM or email service hosted outside Turkey, you are making a cross-border transfer. Map these before you write your privacy notice.

Penalties

Administrative fines apply to failures in the privacy notice obligation, data security obligations, non-compliance with Board decisions, and registration obligations. Amounts are set in the law and increased annually by the revaluation rate. Separately, certain unlawful data acts carry criminal liability under the Turkish Penal Code.

What to do first: a practical order

  1. Map processes — HR, sales, support, marketing, security cameras, vendors
  2. Assign a lawful basis to each process (avoid defaulting to consent)
  3. List cross-border transfers explicitly
  4. Draft the privacy notice and publish it wherever data is collected
  5. Separate consent flows for marketing communications
  6. Check the registration criteria and register if required
  7. Set retention periods and a periodic deletion routine
  8. Have Turkish counsel review everything before it goes live

A ready-made checklist: KVKK compliance checklist.

FAQ

Does GDPR compliance cover KVKK?

No. The frameworks are similar but not equivalent — consent handling, transfer rules and the VERBIS registry all differ. GDPR work gives you a strong starting inventory, not compliance.

Do documents have to be in Turkish?

Privacy notices addressed to individuals in Turkey should be available in Turkish so they are genuinely understandable. Bilingual documents are common practice.

We only have customers, no office in Turkey. Are we in scope?

If you process personal data of individuals in Turkey, the law is generally considered applicable. Whether registration is also required depends on the criteria and your structure — take local advice.

Who signs off internally?

The data controller — meaning the company — remains responsible. Appointing a contact person for VERBIS does not transfer liability.


Produce the paperwork faster: KVKK Otomat turns your process map into a privacy notice, consent text, processing inventory, retention policy and VERBIS preparation list. Documents are drafts; review by Turkish counsel is recommended.