
KVKK (Law No. 6698) governs how personal data may be collected and used in Turkey and applies extraterritorially to any foreign company processing the data of individuals in Turkey, regardless of physical presence. Foreign data controllers must register with VERBİS regardless of size, and since a 2024 reform of Article 9, transferring data abroad requires either a Board-approved standard contract (notified within five business days of signing) or another lawful transfer basis; non-compliance fines currently reach roughly TRY 17 million.
Turkey's Personal Data Protection Law, KVKK (Law No. 6698), sets out who may collect and use personal data in Turkey, what they must tell people about it, and what happens when they get it wrong. It came into force in April 2016 and is enforced by the Personal Data Protection Board (Kurul), with fines that reach into the tens of millions of Turkish Lira for the most serious breaches.
KVKK is not limited to companies incorporated in Turkey. A foreign business with no office here can still fall within its scope simply by processing the personal data of people in Turkey: an e-commerce site with Turkish customers, an app with Turkish users, or a group company that receives HR records from a Turkish subsidiary. This guide sets out what the law actually requires, who must register, how data may lawfully leave Turkey after the 2024 reform, and what foreign companies get wrong most often.
KVKK applies to anyone who processes personal data wholly or partly by automated means, or manually as part of a filing system, in connection with activities in Turkey. "Processing" is defined broadly: collecting, recording, storing, adapting, disclosing, or even simply holding data counts. The law binds two kinds of actors differently:
KVKK applies extraterritorially: a foreign company with no Turkish entity can still be a data controller under the law if it processes the personal data of individuals in Turkey or targets the Turkish market. In practice this covers foreign e-commerce platforms selling to Turkish consumers, SaaS products with Turkish user accounts, and multinational groups whose Turkish subsidiary feeds employee or customer data to a parent company abroad.
Personal data is any information relating to an identified or identifiable natural person: names, national ID numbers, email addresses, IP addresses, and location data all qualify. A narrower category, special categories of personal data (özel nitelikli kişisel veri), covers race, ethnic origin, political opinion, philosophical belief, religion, sect, appearance, membership of associations or unions, health data, sexual life, criminal convictions, security measures, and biometric or genetic data. Processing this category requires either explicit consent or one of a narrow list of statutory grounds, and the Board treats breaches involving it more severely.
Under Article 5 of KVKK, personal data may be processed only where the data subject has given explicit consent (açık rıza), or where one of the following applies without consent being required:
In practice most Turkish employment contracts, customer onboarding flows, and supplier relationships rely on the contractual-necessity and legitimate-interest grounds rather than blanket consent, which the Board has repeatedly criticised as legally weak when used as a catch-all.
Article 10 requires controllers to inform data subjects, at or before the point of collection, of the controller's identity, the purpose of processing, to whom and for what purpose the data may be transferred, the method and legal basis of collection, and the data subject's rights under Article 11. This obligation exists independently of whether consent is the legal basis for processing; it applies even where processing rests on a contract or legal obligation. Most companies meet it through a written privacy notice (aydınlatma metni) provided at signup, on a website, or in an employment contract.
Anyone whose personal data is processed in Turkey may apply to the relevant data controller to:
A controller must respond to such a request free of charge and within thirty days, either complying with it or providing a reasoned refusal. If the request is rejected, or not answered in time, the individual may complain to the Board.
The Data Controllers' Registry (VERBİS) is the central registry every data controller in scope must join before processing personal data, under Article 16. Registration requires disclosing, among other things, the categories of personal data processed, the purposes of processing, the recipient groups data may be transferred to, and the technical and organisational security measures in place.
As of 2026, registration is mandatory for:
This last category is the one most foreign companies overlook. Enforcement in 2026 has been strict on it: the Board has fined foreign companies with minimal Turkish presence, including liaison offices with no direct commercial activity, for failing to register, simply because they processed employee or customer data connected to Turkey.
Article 9 governs the transfer of personal data outside Turkey, and it was substantially rewritten by Law No. 7499 in March 2024, replacing the old consent-heavy regime with a tiered structure closely modelled on the GDPR. Since 1 June 2024, a transfer abroad may proceed on one of three bases, applied in order:
This affects more companies than it appears to at first glance: sending HR records to a foreign parent company, hosting customer data on servers outside Turkey, or sharing analytics with an overseas affiliate all count as a regulated cross-border transfer, whatever the technical route the data takes.
If personal data processed by a controller is obtained by others through unlawful means, the controller must notify the affected data subjects and the Board as soon as possible. The Board's own guidance treats "as soon as possible" as, at the latest, 72 hours from the point the controller becomes aware of the breach, mirroring the GDPR standard even though the statutory text itself does not fix a number of hours. Notification must describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed in response.
The Personal Data Protection Board investigates complaints, conducts audits, and can order a controller to remedy a breach. Administrative fines are revalued annually and, for 2026, run broadly as follows depending on the violation:
Separately, KVKK Articles 17 and 18 attach criminal liability, via Articles 135 to 140 of the Turkish Penal Code, to the unlawful recording, disclosure, or acquisition of personal data, with prison sentences that can extend from one to six years depending on the offence and whether special categories of data are involved. Our separate guide covers KVKK penalties for data violations in more detail.
Foreign businesses operating in or selling into Turkey most often go wrong on three points: assuming that having no Turkish office removes them from KVKK's scope, when the law follows the data rather than the entity; treating VERBİS registration as optional for a small presence, when foreign controllers must register regardless of size; and moving data to a parent company or cloud provider abroad without the standard contract and the five-business-day notification that Article 9 now requires. A practical compliance review for a foreign company should map what personal data is collected from individuals in Turkey, confirm the lawful basis for each processing activity, check whether VERBİS registration is required, and verify that every cross-border data flow (HR, customer, or analytics) rests on one of the three lawful transfer bases.
Yes. KVKK applies extraterritorially to any controller that processes the personal data of individuals in Turkey or targets the Turkish market, regardless of where the company is established.
Yes, if they are established abroad. Unlike Turkish companies, which only need to register once they exceed the employee or turnover thresholds, foreign data controllers must register with VERBİS regardless of size once they process personal data connected to Turkey.
Yes, but the transfer must rest on one of the three bases in Article 9, most commonly the Board's standard contract, and the signed contract must be notified to the Board within five business days.
Missing this deadline is currently the most common trigger for enforcement fines related to cross-border transfers, with penalties for non-compliance with Board decisions reaching into the millions of Lira.
No. Article 5 allows processing without consent where it is necessary for a contract, a legal obligation, the controller's legitimate interests, or several other defined grounds: consent is only one of several lawful bases.
The Board's guidance treats 72 hours from the point the controller becomes aware of the breach as the practical outer limit for notifying both the Board and the affected individuals.
KVKK reaches further than its Turkish name suggests, and the 2024 reform of the cross-border transfer rules has made the paperwork around moving data abroad, not just the decision to collect it, a real compliance risk for foreign companies. Getting the registration, the notices, and the transfer mechanism right at the outset is far cheaper than correcting it after a Board investigation.
At Bayraktar Attorneys, we advise foreign companies and multinational groups on KVKK compliance from the ground up: VERBİS registration, privacy notices, data processing agreements, and the standard contracts and notifications required for lawful cross-border transfers. If your business collects or processes personal data connected to Turkey, contact us for a compliance assessment.