Turkey
Turkey Data Privacy Laws: KVKK, Law 7499 & 2024 Cross-Border Transfer Reform
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 12 primary sources cited on this page. How we verify our legal content

Turkey's primary data privacy statute, Law No. 6698 (KVKK), governs personal data protection for all individuals located in Turkey. Law No. 7499, effective June 1, 2024, overhauled cross-border transfer rules and replaced the old consent-and-approval model with a three-tier framework of adequacy decisions, standard contractual clauses, and limited derogations.
Turkey's data privacy regime is built on a statute, a constitutional right, and an independent supervisory authority that has grown steadily more assertive since 2023. Understanding it requires grasping both the original 2016 law and the major 2024 reforms that fundamentally changed how personal data may be sent outside the country.
Quick Answer: Turkey's Data Protection Framework
Turkey's primary data protection law is the Kisisel Verilerin Korunmasi Kanunu, abbreviated KVKK and formally designated Law No. 6698. It entered force on April 7, 2016, and was Turkey's first comprehensive data protection statute.
The supervising body is the Personal Data Protection Authority (Kisisel Verileri Koruma Kurumu). Its nine-member decision-making arm, the Personal Data Protection Board (Kisisel Verileri Koruma Kurulu), issues binding decisions, conducts investigations, imposes fines, and publishes regulatory guidance.
In March 2024, the Turkish Grand National Assembly passed Law No. 7499, published in the Official Gazette on March 12, 2024 (No. 32487). The KVKK-related provisions took effect June 1, 2024, with a transitional compliance period running until September 1, 2024. This legislation was the most substantial amendment to the KVKK since its enactment.
Constitutional Basis: Article 20 and the 2010 Amendment
Turkey's data protection framework has an explicit constitutional foundation. The original Constitution of the Republic of Turkey, adopted in 1982, protected privacy in general terms under Article 20's provisions on the secrecy of private life. In 2010, a significant constitutional amendment added paragraph 3 to Article 20, published in Official Gazette No. 27580 on May 13, 2010.
Article 20(3) provides that everyone has the right to protection of their personal data. The provision expressly grants the right to be informed about personal data, to access that data, to request its correction or deletion, and to learn whether it has been used in accordance with a lawful purpose. It also states that personal data may be processed only in cases prescribed by law or with the explicit consent of the person concerned.
The 2010 amendment specifically required the legislature to enact a dedicated statute on the protection of personal data. That constitutional mandate produced the KVKK six years later, in 2016. The constitutional grounding distinguishes Turkey from many countries where data protection rests solely on ordinary legislation and places privacy and data protection in the highest tier of Turkish law.
Turkey is also a signatory to the Council of Europe's Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108), which reinforces the constitutional and statutory framework with international law obligations.
The KVKK: Scope and Coverage
The KVKK applies to any natural or legal person who processes the personal data of individuals located in Turkey. This includes Turkish companies, foreign entities offering goods or services to Turkish residents, and organizations that monitor the behavior of individuals in Turkey.
Personal data under the KVKK means any information relating to an identified or identifiable natural person. The definition is broad and covers names, identification numbers, email addresses, IP addresses, location data, and any other information that can directly or indirectly identify an individual.
The law applies to both automated processing and non-automated processing, provided the non-automated data forms part of a filing system. There is no revenue threshold or employee count that triggers or exempts organizations from the core obligations, though VERBIS registration thresholds do exist for domestic controllers.
Core Principles of Data Processing
Article 4 of the KVKK establishes the foundational principles governing all personal data processing. These principles are similar to those in most modern data protection frameworks.
Data must be processed lawfully and fairly. Processing must have a valid legal basis and must not deceive or mislead the data subject. All processing must be connected to a specific, explicit, and legitimate purpose. Controllers may not collect more data than is necessary for the stated purpose.
Accuracy is mandatory. Controllers must keep data up to date and correct inaccuracies when identified. Data may only be stored for as long as the purpose of processing requires. Once that purpose is fulfilled or the legal retention period expires, the data must be deleted, destroyed, or anonymized.
Legal Bases for Processing
Article 5 of the KVKK sets out the conditions under which personal data may be lawfully processed. The primary basis is explicit consent. However, several alternative grounds allow processing without consent.
Processing without consent is permitted when it is expressly prescribed by law, when it is necessary for the protection of life or physical integrity of a person unable to give consent, when it is necessary for the performance of a contract to which the data subject is party, when it is necessary for the controller to fulfill a legal obligation, when the data has been made public by the data subject, when processing is necessary for establishing or protecting a legal right, and when processing is necessary for the legitimate interests of the controller provided those interests do not violate the fundamental rights of the data subject.
The KVKK's legitimate interests ground is interpreted more narrowly than under the GDPR. The KVKK Board has historically emphasized explicit consent as the preferred legal ground, and organizations relying on legitimate interests carry a heavier justification burden.
Special Categories of Personal Data

Article 6 of the KVKK defines special categories of personal data and imposes stricter processing conditions. These categories include race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and dress, membership in associations or trade unions, health data, sexual life, criminal convictions and security measures, and biometric and genetic data.
Before Law No. 7499, the KVKK drew a further internal distinction between health and sexual life data on one side and all other sensitive categories on the other, applying different legal conditions to each group. The 2024 amendment abolished that internal distinction. All special-category data is now subject to a unified set of legal grounds.
Under the amended Article 6, sensitive data may be processed without explicit consent when expressly permitted by law, when necessary to protect the life or physical integrity of a person unable to give consent, when data has been made public by the subject, when processing is necessary for establishing or exercising a legal right, when necessary to fulfill employment or occupational health and safety obligations, or when processed by associations and foundations for their own members' purposes without disclosure to third parties.
The amendment also broadened the medical and public health exception, permitting processing by health professionals for preventive medicine, medical diagnosis, treatment and care services, and the planning and financing of health services, provided adequate confidentiality and technical safeguards are maintained.
All processing of special-category data continues to require compliance with additional safeguard measures that the KVKK Board has the authority to specify.
The Board's most consequential recent special-category ruling concerns biometrics at work. Principle Decision No. 2026/921, adopted April 29, 2026 and published in the Official Gazette on June 2, 2026, holds that processing employees' biometric data purely to track attendance or working hours satisfies none of the Article 6 conditions, and that even valid explicit consent does not save it because the processing fails the proportionality test in Article 4. In an August 2026 clarification the Authority added that palm-vein and fingerprint data remain biometric even when stored as a mathematical code, and that sites carrying genuine security risk may still use biometric identification where it is confined to critical areas and personnel and alternative methods are inadequate.
The KVKK Board and the Personal Data Protection Authority
The Personal Data Protection Authority (KVKK Authority) is the independent supervisory body. Its nine-member Board consists of five members elected by the Turkish Grand National Assembly and four appointed by the President of the Republic. Board members serve four-year terms under Article 21(8) of Law No. 6698 and may be re-elected. They are expected to act independently.
The Board's enforcement powers are broad. It investigates complaints, conducts ex officio investigations, issues binding decisions requiring remediation, imposes administrative fines, publishes guidelines and regulatory guidance, approves or rejects cross-border data transfer mechanisms, and maintains the VERBIS registry.
The Authority's Presidency handles day-to-day administration, processes VERBIS registrations, supports investigative work, and manages public communications including publication of breach notifications on the Authority's website.
Since 2023, the Board has accelerated enforcement. It has issued guidance on emerging technology topics including chatbots, deepfakes, and AI systems, and has expanded scrutiny of digital platforms and financial institutions.
VERBIS: The Data Controllers Registry
One of the KVKK's most distinctive features is the Veri Sorumlulari Sicil Bilgi Sistemi, known as VERBIS. This publicly accessible online registry requires data controllers to register before beginning to process personal data in Turkey.
Registration requires the controller to disclose the categories of personal data processed, the purposes of processing, the categories of data subjects, the recipients to whom data is disclosed, the anticipated retention periods, and any cross-border data transfers. Any changes to this information must be updated within seven days.
Domestic Registration Thresholds
For controllers established in Turkey, registration is required if they employ 50 or more people or have an annual balance sheet total of 100 million TRY or more. An exemption applies to smaller organizations, but only if their main activity is not the processing of special-category data. Controllers whose main business involves processing sensitive data must register if they have 10 or more employees or an annual balance sheet of at least 10 million TRY.
These thresholds were revised by Board Decision No. 2025/1572 of September 4, 2025, which took effect on October 1, 2025. The revision adjusted both the employee and financial thresholds and clarified the special-category processing criterion for smaller controllers.
A follow-up decision explains how the two criteria interact. Under Board Decision No. 2025/2393 of December 25, 2025, the employee-count and balance-sheet criteria are applied cumulatively only to controllers that keep books on a balance sheet basis. Controllers that do not keep balance sheet books have no annual balance sheet total, so they are assessed on employee count alone.
Foreign Controllers
The domestic thresholds do not apply to foreign data controllers. Any foreign entity that processes the personal data of individuals in Turkey must register with VERBIS regardless of its size, workforce, or annual revenue. Foreign controllers must also appoint a local representative who is resident in Turkey. The representative serves as the primary point of contact for the KVKK Authority and for data subjects seeking to exercise their rights.
VERBIS Enforcement
VERBIS enforcement did not begin in 2024. The Board set December 31, 2021 as the registration deadline for all non-exempt controllers, and registration fines have run every year since: 29.8 million TRY in 2022, 150.7 million TRY in 2023 and 421.9 million TRY in 2024, according to the Authority's 2024 Activity Report.
In a public announcement dated August 1, 2024, the Board reported that of roughly 130,600 controllers identified as owing registration, roughly 16,350 had been found non-compliant and were under rolling ex officio review, with fines set from an algorithm table keyed to annual balance sheet asset totals. Cumulative fines for registration failure had reached 503,935,000 TRY as of that date. That is a running programme total since 2022, not the result of a single August 2024 action, and the 16,350 figure counts controllers under review rather than controllers penalized.
Both domestic and foreign controllers, including public institutions, have faced sanctions. In March 2023 the Board fined Meta and WhatsApp 2,665,000 TRY each, 5.33 million TRY in total, for failing to meet their VERBIS registration obligation, and ordered both to register within 30 days.
The 2024 Amendment: Law No. 7499
Law No. 7499 was enacted as a broad multi-sector reform bill. Its KVKK provisions amended Articles 6, 9, and 18 of Law No. 6698, with the changes taking force on June 1, 2024 and a transition period ending September 1, 2024.
The amendment was driven by two goals: modernizing Turkey's cross-border transfer framework to align with GDPR Chapter V, and expanding the legal bases for sensitive data processing. Both were areas where the original 2016 law had created practical difficulties for businesses and friction with EU partners.
Cross-Border Data Transfers: The New Three-Tier Framework

The 2024 amendments to Article 9 represent the most consequential change in the KVKK's history. Before Law No. 7499, international data transfers required either the explicit consent of the data subject or a case-by-case undertaking approved by the KVKK Board. That process was slow, created uncertainty, and made systematic cross-border data flows difficult to manage. The new framework replaced it with a hierarchy of three mechanisms.
Tier 1: Adequacy Decisions
The KVKK Board may issue formal adequacy decisions recognizing that a specific country, a sector within a country, or an international organization provides a level of data protection essentially equivalent to the KVKK. When such a decision is in place, personal data may be transferred to that destination using the ordinary legal grounds under Articles 5 and 6, without additional authorization or contractual mechanisms.
A notable feature of the Turkish adequacy regime is that it can apply at a sectoral level. A specific industry within a country may receive an adequacy designation even if the country overall has not been found adequate. Adequacy decisions are subject to periodic review at least every four years.
As of early 2026, the KVKK Board had not yet published a finalized list of adequate countries or sectors. The designation landscape continues to develop, and organizations cannot yet rely on an adequacy decision for most transfer destinations.
Tier 2: Appropriate Safeguards
When no adequacy decision exists, Article 9(4) permits a transfer where one of four appropriate safeguards is in place. The first is a non-treaty agreement between foreign public bodies or international organizations and Turkish public bodies or public professional organizations, combined with Board permission. That route is open only to the public sector. The three that matter to private organizations are the standard contract, binding corporate rules, and a written undertaking authorized by the Board.
Standard contractual clauses (SCCs) are pre-approved template contracts published by the KVKK Board. The Board has published four modules: controller to controller, controller to processor, processor to processor, and processor to controller. The clauses must be adopted without modification. Supplementary annexes may be added to address operational details such as data categories, purposes, and security measures, but the core clause text cannot be altered.
Once the signatures are complete, the standard contract must be notified to the Authority within five business days. Article 14(5) of the cross-border transfer Regulation allows three channels: physical filing, registered electronic mail (KEP), or another method determined by the Board. The Board's electronic channel is the Standart Sozlesme Bildirim Modulu, the Standard Contract Notification Module, at standartsozlesme.kvkk.gov.tr, opened by Board Decision No. 2024/1793 of October 17, 2024. Physical filing and KEP remain equally valid.
The parties may state in the contract which of them files the notification. If they do not, the exporting party files it.
Uptake has built steadily rather than overnight. The Authority received 1,364 standard contracts in 2024 and 2,497 in 2025, per its Activity Reports for those years. Because the notification module did not open until October 2024, most 2024 filings arrived physically or by KEP.
Notification does not constitute Board approval. The transfer's legality derives from correct adoption of the Board-approved clause text. Notification is an administrative filing that supports Authority monitoring.
Binding corporate rules (BCRs) allow multinational organizations to establish intra-group transfer frameworks. BCRs must be submitted to the KVKK Board for approval and must demonstrate that adequate protection standards are maintained across all participating group entities, including commitments on data security, transparency, and data subject rights enforcement.
Written undertakings are a third option. A data controller or processor may draft a customized written agreement with the foreign recipient that commits both parties to adequate protection standards. Unlike SCCs, written undertakings are not based on a pre-approved Board template. They must be submitted to the Board for individual authorization before transfers begin. This mechanism provides flexibility for atypical transfer relationships but requires more lead time than SCCs.
Tier 3: Exceptional Derogations
When neither an adequacy decision nor a safeguard mechanism is available or practical, certain limited derogations permit transfers in specific circumstances. These include transfers based on the explicit informed consent of the data subject, transfers necessary for the performance of a contract between the data subject and the controller, transfers that are vital to protect the data subject's life or physical integrity when consent cannot be obtained, and transfers necessary for the establishment or exercise of legal rights.
As of September 1, 2024, explicit consent can no longer serve as a basis for regular or repeated international transfers. Consent in the derogation sense covers only occasional, non-systematic transfers. This eliminates the practice of using rolling blanket consent as a substitute for structural mechanisms.
The 2024 amendments also explicitly authorize data processors, and not only controllers, to engage in cross-border transfers, closing a gap in the original legislation.
The Cross-Border Transfer Regulation and Guideline
The KVKK published the Regulation on the Procedures and Principles Regarding Cross-Border Transfer of Personal Data on July 10, 2024, providing the operational detail behind the new Article 9 framework. In January 2025, the Authority issued accompanying guidelines clarifying the hierarchy of mechanisms and the procedural requirements for each. The guidelines instruct controllers to assess the protection level in the destination country, document that assessment, and select the applicable mechanism based on the outcome.
VERBIS and Cross-Border Transfers
Organizations engaged in cross-border data transfers must reflect those transfers in their VERBIS registration. The categories of foreign recipients, the countries involved, and the transfer mechanism used must all be disclosed. Any change to a transfer arrangement must be updated in VERBIS within seven days.
Data Breach Notification
The KVKK imposes strict breach notification obligations. When a personal data breach is discovered, the data controller must notify the KVKK Board within 72 hours using the official Personal Data Breach Notification Form. The 72-hour clock runs from the date the data controller learns of the breach. Board Decision No. 2019/10 draws no distinction between an IT team's detection and management's awareness, so a controller should not assume the clock is paused while its own security staff investigate.
Turkey's notification requirement is notably broader than the GDPR's. The GDPR requires notification only when a breach is likely to result in risk to the rights and freedoms of natural persons. The KVKK imposes no such risk threshold. All breaches must be reported to the Board regardless of severity or the likelihood of harm to individuals.
The notification must describe the nature of the breach, the categories and approximate number of personal data records affected, the approximate number of data subjects involved, the potential consequences, and the measures taken or proposed to address the breach. Where the controller cannot supply all of the form's information at once, Board Decision No. 2019/10 requires it to file in stages without delay rather than wait. If the controller cannot notify within 72 hours at all, the reasons for the delay must be explained to the Board with the notification.
Controllers must also notify affected data subjects within the shortest reasonable time so they can take protective measures. Under Board Decision No. 2019/10, notice goes directly to the individual where the controller can reach their contact address. Where it cannot, the controller must use another suitable method, such as publishing the notice on its own website.
Separately, Article 12(5) of Law No. 6698 lets the Board itself announce a breach, where necessary, on the Authority's own website or by another method it considers appropriate. That is a power the Board exercises, not an order it issues to the controller.
From December 25, 2025, breach notifications published on the KVKK Authority's website are removed after a maximum of 60 days. This change was introduced by Board Decision No. 2025/2451, replacing the previous practice of indefinite retention. Controllers who can demonstrate that all affected individuals were directly notified earlier may have notices removed sooner.
Every data controller subject to the KVKK is expected to maintain a tested breach response plan that identifies internal reporting chains, assigns notification responsibility, and establishes procedures for documenting and investigating incidents.
Data Subject Rights

Article 11 of the KVKK grants individuals a set of rights regarding their personal data. Law No. 7499 did not touch Article 11, so this list has stood unchanged since 2016.
Data subjects may learn whether their personal data is being processed. If it is, they may request information about the nature of the processing. They may learn the purpose of processing and whether data is used in accordance with its stated purpose. They may identify the third parties, whether domestic or foreign, to whom their data has been disclosed. They may request correction of incomplete or inaccurate data. They may request deletion or destruction of their data when the grounds for processing no longer exist or the retention period has expired.
Data subjects may request that the controller notify third parties of any corrections or deletions made. They may object to a result produced exclusively through automated processing when that result affects them adversely. They may also claim compensation for damages caused by unlawful processing.
Unlike the GDPR, the KVKK grants no right to data portability. Law No. 7499 changed only Articles 6, 9 and 18 and added Provisional Article 3, so it altered nothing in this list of rights. The automated-processing right is also narrower than its GDPR counterpart: Article 11(g) lets a person object to a result produced exclusively by automated analysis that is adverse to them, and goes no further.
To exercise these rights, the data subject must first submit a written application to the data controller. The controller must respond within 30 days. If the controller refuses, gives an inadequate response, or fails to respond, the data subject may file a complaint with the KVKK Board within 30 days of learning of the response, or within 60 days of the original request. Complaints are submitted through the KVKK Complaint Module.
KVKK vs. GDPR: Key Similarities and Differences
The KVKK and the EU's General Data Protection Regulation share a common lineage in European data protection tradition. Turkey's Convention 108 membership and its EU accession candidacy both shaped the KVKK's design. However, meaningful differences remain even after the 2024 reforms.
Territorial reach. The GDPR applies to any entity processing data of EU residents regardless of where the entity is based. The KVKK applies to foreign entities targeting Turkish residents, but its extraterritorial enforcement has been less developed in practice.
Legal bases. Both laws recognize explicit consent, contract performance, legal obligations, vital interests, and legitimate interests. The KVKK's legitimate interests ground is more narrowly interpreted, and the Board has historically preferred explicit consent.
Penalty levels. The GDPR allows fines up to 20 million EUR or 4% of global annual revenue. The KVKK's 2026 maximum administrative fine is 17,092,242 TRY, which was roughly 300,000 EUR at the Central Bank of Turkey's rate for September 9, 2026 of 56.31 TRY to the euro. The lira moves quickly enough that any euro figure should be recalculated against a current Central Bank bulletin before it is relied on. The KVKK supplements administrative fines with criminal penalties through the Turkish Penal Code, including imprisonment for individuals.
VERBIS vs. DPOs and DPIAs. The KVKK requires VERBIS registration, which has no direct GDPR equivalent. The GDPR requires Data Protection Impact Assessments and Data Protection Officers in certain high-risk or large-scale processing contexts. Neither DPOs nor DPIAs are formally mandated by the KVKK, though many practitioners recommend them as best practice.
Breach notification threshold. The GDPR uses a risk-based threshold. The KVKK requires notification for all breaches without any threshold.
Adequacy for transfers. Both laws use a tiered transfer framework culminating in adequacy decisions, SCCs, and BCRs. Turkey's framework was modeled on GDPR Chapter V after the 2024 reform. However, Turkey has not yet issued any adequacy decisions, leaving SCCs as the primary practical mechanism for most international transfers.
Penalties and Enforcement
Administrative Fines for 2026
Administrative fines under the KVKK are adjusted annually by Turkey's statutory revaluation rate. For 2026, the revaluation rate is 25.49%, applied on top of 2025 figures pursuant to Official Gazette No. 33090 (November 27, 2025). The exact 2026 fine ranges are:
- Failure to inform data subjects: 85,437 TRY minimum to 1,709,200 TRY maximum
- Failure to fulfill data security obligations: 256,357 TRY minimum to 17,092,242 TRY maximum
- Failure to comply with Board decisions: 427,263 TRY minimum to 17,092,242 TRY maximum
- Failure to register with or notify VERBIS: 341,809 TRY minimum to 17,092,242 TRY maximum
- Failure to notify the Authority of standard contractual clauses for cross-border transfers: 90,308 TRY minimum to 1,806,177 TRY maximum
The last category was added by the 2024 amendment as a dedicated enforcement tool for the SCC notification requirement.
Administrative fines were previously appealable to criminal courts of peace. Law No. 7499 changed this: fines are now appealable to administrative courts, a procedural shift that aligns with the administrative law character of the KVKK regime.
Criminal Penalties
Article 17 of the KVKK refers serious violations to the Turkish Penal Code (Law No. 5237), which prescribes imprisonment for data protection offenses:
- Unlawful recording of personal data: 1 to 3 years imprisonment; elevated sentences apply for sensitive categories
- Unlawful provision of personal data to others, or acquisition of data by unlawful means: 2 to 4 years imprisonment
- Failure to delete or anonymize data when legally required: 1 to 2 years imprisonment
These provisions apply to natural persons, meaning company directors and officers may face personal criminal liability for data protection violations.
Notable Enforcement Actions
Total KVKK Board fines came to 552,188,101 TRY across 862 controllers in 2024, of which 421.9 million TRY fell on 597 controllers for VERBIS registration failures. Enforcement then eased. The Authority's 2025 Activity Report puts 2025 fines at 352,510,494 TRY across 876 controllers, made up of 45.3 million TRY on complaints, 90.4 million TRY on breach notifications and 216.9 million TRY on VERBIS. The trend is not a straight line upward.
Notable individual actions include the March 2023 fines of 2,665,000 TRY each against Meta and WhatsApp, 5.33 million TRY in total, for failing to meet their VERBIS registration obligation. Twitch received a 2 million TRY fine in 2024 for a data breach affecting more than 35,000 Turkish users.
In 2025, the KVKK Authority signed a cooperation protocol with the Capital Markets Board (Sermaye Piyasasi Kurulu). This signals expanded joint oversight of financial institutions and publicly listed companies that process personal data, and foreshadows coordinated investigations and cross-agency enforcement in the financial sector.
Emerging Topics: AI, Chatbots, and Deepfakes
The KVKK Authority has begun issuing substantive guidance on emerging technology topics. In 2024, the Authority published information notes on chatbots including ChatGPT, deepfakes, and the legal bases for various categories of AI-driven data processing. This guidance does not yet take the form of binding regulations but signals the direction of future enforcement.
The Board's position is that AI systems which process personal data are subject to the full KVKK framework, including the requirements for lawful processing basis, data minimization, transparency, and data subject rights. Organizations deploying AI tools that process personal data of Turkish residents should document the legal basis, prepare data subject information disclosures, and assess whether data transfers to foreign AI providers comply with the cross-border transfer regime.
The Authority has also flagged the intersection of data protection and competition law, noting that investigations into large technology platforms increasingly have both dimensions, following the pattern of the META investigation and similar actions in the EU.
Compliance Checklist for Organizations
Organizations subject to the KVKK should address the following areas to build and maintain compliance.
Register with VERBIS before processing any personal data in Turkey. Foreign controllers must register regardless of size and must appoint a Turkish-resident representative. Domestic controllers below the general thresholds must still register if their main activity is special-category data processing and they have 10 or more employees or a balance sheet total of 10 million TRY or more.
Establish and document a lawful basis for every personal data processing activity. Explicit consent should not be the default choice where another ground is more appropriate and stable.
Map all cross-border data transfers and identify the applicable transfer mechanism. If using SCCs, execute them without modification and notify the KVKK within five business days, physically, by registered electronic mail (KEP), or through the Standard Contract Notification Module at standartsozlesme.kvkk.gov.tr. If using written undertakings, obtain Board authorization before transfers begin.
Implement technical and organizational data security measures. Maintain internal audit schedules and document compliance measures periodically.
Prepare and test a data breach response plan that supports 72-hour notification to the Board for all breaches regardless of severity. Review the plan at least annually.
Respond to data subject applications within 30 days. Maintain a process for receiving, authenticating, and processing applications.
Update VERBIS registration within seven days of any change to processing activities, data categories, recipients, or transfer arrangements.
Review AI and automated processing activities against KVKK requirements. Prepare transparency disclosures for processing involving chatbots or AI-driven tools that handle personal data of Turkish residents.
See Also
For recording law, wiretapping, and Turkish Penal Code consent rules, see Turkey Recording Laws.
Frequently Asked Questions
Does the KVKK apply to foreign companies?
Yes. The KVKK applies to any natural or legal person that processes the personal data of individuals located in Turkey, regardless of where the organization is based. Foreign data controllers must register with VERBIS before processing personal data in Turkey and must appoint a Turkish-resident local representative. There is no size exemption for foreign controllers.
What did the 2024 KVKK amendments (Law No. 7499) change?
Law No. 7499, effective June 1, 2024, made three major changes to the KVKK. First, it replaced the old cross-border transfer system with a three-tier framework: adequacy decisions, standard contractual clauses or binding corporate rules, and limited derogations. As of September 1, 2024, explicit consent is no longer valid for regular or repeated international transfers. Second, it expanded the legal bases for processing special-category personal data, abolishing the separate treatment of health and sexual life data. Third, it added a new fine category for failure to notify the KVKK Authority of executed standard contractual clauses within five business days.
How do standard contractual clauses work under the KVKK?
Standard contractual clauses are pre-approved template contracts published by the KVKK Board. There are four modules: controller to controller, controller to processor, processor to processor, and processor to controller. The clauses must be adopted without modification. Once the signatures are complete, the contract must be notified to the KVKK Authority within five business days, physically, by registered electronic mail (KEP), or through the Board's Standard Contract Notification Module at standartsozlesme.kvkk.gov.tr. Notification is not Board approval; it is an administrative filing. The legality of the transfer derives from correct execution of the Board-approved text.
What are the KVKK penalties for 2026?
Administrative fines for 2026 range from 85,437 TRY to 17,092,242 TRY depending on the violation category. The highest fines apply to data security failures, non-compliance with Board decisions, and VERBIS non-registration. Criminal penalties under the Turkish Penal Code include 1 to 3 years imprisonment for unlawful data recording, 2 to 4 years for unlawful data provision or acquisition, and 1 to 2 years for failure to delete data when required.
What is VERBIS and who must register?
VERBIS (Veri Sorumlulari Sicil Bilgi Sistemi) is Turkey's publicly accessible Data Controllers Registry. Data controllers must register before processing personal data. Domestic controllers must register if they have 50 or more employees or an annual balance sheet of 100 million TRY or more. Controllers whose main activity is processing special-category data must register at lower thresholds (10 employees or 10 million TRY balance sheet). Foreign controllers must register regardless of size. Thresholds were revised by Board Decision No. 2025/1572 of September 4, 2025, effective October 1, 2025. Under Board Decision No. 2025/2393 of December 25, 2025 the two criteria are applied together only to controllers that keep books on a balance sheet basis, and all others are assessed on employee count alone.
How does Turkey's breach notification requirement differ from the GDPR?
The KVKK requires data controllers to notify the KVKK Board within 72 hours of discovering any personal data breach. Unlike the GDPR, which requires notification only when a breach is likely to result in risk to individuals, the KVKK imposes no risk threshold. All breaches must be reported regardless of severity. From December 25, 2025, breach notices published on the KVKK website are removed after a maximum of 60 days under Board Decision No. 2025/2451, replacing the previous practice of indefinite retention.
What is the constitutional basis for data protection in Turkey?
Article 20(3) of the Turkish Constitution, added by a 2010 amendment, explicitly recognizes the right to protection of personal data. It grants every individual the right to be informed about their personal data, to access it, to request correction or deletion, and to learn whether it has been used for a lawful purpose. The provision also directed the legislature to enact a dedicated data protection statute, which produced the KVKK in 2016.
Updates
Corrected the cross-border transfer section (the notification channel is the Board's Standard Contract Notification Module, opened by Decision 2024/1793 of 17 October 2024, alongside physical filing and registered e-mail; there are four standard contract modules, not two; Article 9(4) lists four safeguards), removed the incorrect statement that the 2024 amendments strengthened data subject rights and created a portability right the KVKK does not grant, fixed the Board's term of office to four years, restated the VERBIS enforcement figures as the Authority reports them and added 2025 data, redated the Meta and WhatsApp fines to March 2023, corrected the maximum SCC-notification fine to 1,806,177 TRY and the euro conversion of the 17,092,242 TRY ceiling, corrected who may publish a breach notice and when the 72-hour clock starts, and added Board Decisions 2025/2393 and 2026/921.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Full refresh: expanded to ~6,200 words. Added constitutional basis (Article 20, 2010 amendment), Law 7499 deep-dive, written undertakings mechanism, VERBIS October 2025 threshold update, breach notice 60-day limit (Board Decision 2025/2451), AI and chatbot guidance, Capital Markets Board cooperation protocol, and exact 2026 fine figures.
Reviewed and approved by an editor
Initial publication.
Sources and References
- Personal Data Protection Law No. 6698 (KVKK) - Official English Text(kvkk.gov.tr).gov
- KVKK - Purpose and Scope of the Personal Data Protection Law No. 6698(kvkk.gov.tr).gov
- KVKK - Obligations Concerning Data Security(kvkk.gov.tr).gov
- KVKK - Board Decision No. 2019/10 on Personal Data Breach Notification(kvkk.gov.tr).gov
- KVKK - Conditions for Processing Special Categories of Personal Data(kvkk.gov.tr).gov
- KVKK - Rights of the Data Subject(kvkk.gov.tr).gov
- KVKK - Right to Lodge a Complaint with the Board(kvkk.gov.tr).gov
- KVKK - By-Law on Data Controllers Registry (VERBIS)(kvkk.gov.tr).gov
- KVKK - By-Law on Erasure, Destruction or Anonymization of Personal Data(kvkk.gov.tr).gov
- Constitution of the Republic of Turkey, Article 20 (as amended 2010)(mevzuat.gov.tr).gov
- Law No. 7499 - Amendments to the Code of Criminal Procedure and Certain Laws (Official Gazette No. 32487, 12 March 2024)(mevzuat.gov.tr).gov
- IAPP - The Long-Awaited Amendments in Turkish Data Protection Law(iapp.org)
- IAPP - Turkey Data Protection Amendments for 2024: A Closer Look(iapp.org)
- CottGroup - Administrative Fine Amounts in KVKK for 2026(cottgroup.com)
- KVKK - Public Announcement on the Standard Contract Notification Module (Board Decision No. 2024/1793 of 17 October 2024)(kvkk.gov.tr).gov
- IBA - Mandatory Data Protection Compliance in Turkey: VERBIS Registration and Enforcement Actions(ibanet.org)
- Erdem & Erdem - KVKK Guideline on Transfer of Personal Data Abroad (January 2025)(erdem-erdem.av.tr)
- Moral Law - Amendments to Law No. 6698 on the Protection of Personal Data (Law 7499)(moral.av.tr)
- CMS - KVKK Board Decision No. 2025/2451: Breach Notice Publication Limited to 60 Days(cms.law)