A starter guide on where to begin with compliance under Turkey’s Personal Data Protection Law (KVKK, Law no. 6698) and in what order to take the steps. This guide is for general information and is not legal advice.

GuideAbout 7 min readKVKK

Key concepts

Personal data

Any information relating to an identified or identifiable natural person.

Data controller

The person or organisation that determines the purposes and means of processing.

Data processor

A party that processes data on behalf of the controller (e.g. cloud, payroll or e-mail providers).

Data subject

The individual whose data is processed: customer, employee, visitor, candidate, etc.

Compliance roadmap

Data inventoryWhat data, where, why?
Legal basis and noticeBasis for processing and transparency
Technical and admin measuresAccess, encryption, policies
Data subject rightsRequest process and response times
Records and disposalRetention policy, VERBİS
Training and auditAwareness, regular checks

How to build the data inventory

The foundation of compliance is knowing which personal data is processed in which process. Work process by process (HR, sales, accounting, website, CCTV, etc.) and record for each:

  • Categories of personal data processed (is any of it special-category data?)
  • Purpose and legal basis of processing
  • Who it is shared with and where (including abroad)
  • Retention period and disposal method
  • Systems that hold the data and roles with access

Notice and explicit consent

The duty to inform applies even when explicit consent is not needed. Explicit consent is not the only legal basis; data processed for performance of a contract or a legal obligation, for example, does not require separate consent. When consent is needed it must be informed, specific and freely given.

In practice: Website forms, cookies and job application processes are the first places most organisations should review.

Data security measures

Technical measures

Access authorisation, passwords and multi-factor authentication, encryption, logging, backup, vulnerability management.

Administrative measures

Policies and procedures, confidentiality undertakings, training, controller-processor contracts, audits.

Data subject requests and breach management

Requests from data subjects must be answered within the period set by law, at the latest within 30 days, so the request channel and internal process should be defined in advance. In case of a data breach, under Board decisions the Board must be notified as soon as possible and within 72 hours at the latest from when the breach is learned.

Note: VERBİS registration thresholds and deadlines can change; always check current Board decisions.

Starter checklist

  • Data inventory prepared
  • Privacy notices are current and published in the right channels
  • Retention and disposal policy ready
  • Access rights reviewed
  • Data subject request process defined
  • Breach response and notification plan ready
  • Staff trained on KVKK
  • Contracts with processors reviewed

Let’s plan your KVKK compliance together

We will assess your current state and build a prioritised compliance plan.