Turkey flag

Turkey

Turkey Data Privacy Laws: KVKK, Law 7499 & 2024 Cross-Border Transfer Reform

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 12 primary sources cited on this page. How we verify our legal content

Turkey Data Privacy Laws: KVKK, Law 7499 & 2024 Cross-Border Transfer Reform

Frequently Asked Questions

Does the KVKK apply to foreign companies?

Yes. The KVKK applies to any natural or legal person that processes the personal data of individuals located in Turkey, regardless of where the organization is based. Foreign data controllers must register with VERBIS before processing personal data in Turkey and must appoint a Turkish-resident local representative. There is no size exemption for foreign controllers.

What did the 2024 KVKK amendments (Law No. 7499) change?

Law No. 7499, effective June 1, 2024, made three major changes to the KVKK. First, it replaced the old cross-border transfer system with a three-tier framework: adequacy decisions, standard contractual clauses or binding corporate rules, and limited derogations. As of September 1, 2024, explicit consent is no longer valid for regular or repeated international transfers. Second, it expanded the legal bases for processing special-category personal data, abolishing the separate treatment of health and sexual life data. Third, it added a new fine category for failure to notify the KVKK Authority of executed standard contractual clauses within five business days.

How do standard contractual clauses work under the KVKK?

Standard contractual clauses are pre-approved template contracts published by the KVKK Board. There are four modules: controller to controller, controller to processor, processor to processor, and processor to controller. The clauses must be adopted without modification. Once the signatures are complete, the contract must be notified to the KVKK Authority within five business days, physically, by registered electronic mail (KEP), or through the Board's Standard Contract Notification Module at standartsozlesme.kvkk.gov.tr. Notification is not Board approval; it is an administrative filing. The legality of the transfer derives from correct execution of the Board-approved text.

What are the KVKK penalties for 2026?

Administrative fines for 2026 range from 85,437 TRY to 17,092,242 TRY depending on the violation category. The highest fines apply to data security failures, non-compliance with Board decisions, and VERBIS non-registration. Criminal penalties under the Turkish Penal Code include 1 to 3 years imprisonment for unlawful data recording, 2 to 4 years for unlawful data provision or acquisition, and 1 to 2 years for failure to delete data when required.

What is VERBIS and who must register?

VERBIS (Veri Sorumlulari Sicil Bilgi Sistemi) is Turkey's publicly accessible Data Controllers Registry. Data controllers must register before processing personal data. Domestic controllers must register if they have 50 or more employees or an annual balance sheet of 100 million TRY or more. Controllers whose main activity is processing special-category data must register at lower thresholds (10 employees or 10 million TRY balance sheet). Foreign controllers must register regardless of size. Thresholds were revised by Board Decision No. 2025/1572 of September 4, 2025, effective October 1, 2025. Under Board Decision No. 2025/2393 of December 25, 2025 the two criteria are applied together only to controllers that keep books on a balance sheet basis, and all others are assessed on employee count alone.

How does Turkey's breach notification requirement differ from the GDPR?

The KVKK requires data controllers to notify the KVKK Board within 72 hours of discovering any personal data breach. Unlike the GDPR, which requires notification only when a breach is likely to result in risk to individuals, the KVKK imposes no risk threshold. All breaches must be reported regardless of severity. From December 25, 2025, breach notices published on the KVKK website are removed after a maximum of 60 days under Board Decision No. 2025/2451, replacing the previous practice of indefinite retention.

What is the constitutional basis for data protection in Turkey?

Article 20(3) of the Turkish Constitution, added by a 2010 amendment, explicitly recognizes the right to protection of personal data. It grants every individual the right to be informed about their personal data, to access it, to request correction or deletion, and to learn whether it has been used for a lawful purpose. The provision also directed the legislature to enact a dedicated data protection statute, which produced the KVKK in 2016.

Updates

Corrected the cross-border transfer section (the notification channel is the Board's Standard Contract Notification Module, opened by Decision 2024/1793 of 17 October 2024, alongside physical filing and registered e-mail; there are four standard contract modules, not two; Article 9(4) lists four safeguards), removed the incorrect statement that the 2024 amendments strengthened data subject rights and created a portability right the KVKK does not grant, fixed the Board's term of office to four years, restated the VERBIS enforcement figures as the Authority reports them and added 2025 data, redated the Meta and WhatsApp fines to March 2023, corrected the maximum SCC-notification fine to 1,806,177 TRY and the euro conversion of the 17,092,242 TRY ceiling, corrected who may publish a breach notice and when the 72-hour clock starts, and added Board Decisions 2025/2393 and 2026/921.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Full refresh: expanded to ~6,200 words. Added constitutional basis (Article 20, 2010 amendment), Law 7499 deep-dive, written undertakings mechanism, VERBIS October 2025 threshold update, breach notice 60-day limit (Board Decision 2025/2451), AI and chatbot guidance, Capital Markets Board cooperation protocol, and exact 2026 fine figures.

Reviewed and approved by an editor

Initial publication.

Sources and References

  1. Personal Data Protection Law No. 6698 (KVKK) - Official English Text(kvkk.gov.tr).gov
  2. KVKK - Purpose and Scope of the Personal Data Protection Law No. 6698(kvkk.gov.tr).gov
  3. KVKK - Obligations Concerning Data Security(kvkk.gov.tr).gov
  4. KVKK - Board Decision No. 2019/10 on Personal Data Breach Notification(kvkk.gov.tr).gov
  5. KVKK - Conditions for Processing Special Categories of Personal Data(kvkk.gov.tr).gov
  6. KVKK - Rights of the Data Subject(kvkk.gov.tr).gov
  7. KVKK - Right to Lodge a Complaint with the Board(kvkk.gov.tr).gov
  8. KVKK - By-Law on Data Controllers Registry (VERBIS)(kvkk.gov.tr).gov
  9. KVKK - By-Law on Erasure, Destruction or Anonymization of Personal Data(kvkk.gov.tr).gov
  10. Constitution of the Republic of Turkey, Article 20 (as amended 2010)(mevzuat.gov.tr).gov
  11. Law No. 7499 - Amendments to the Code of Criminal Procedure and Certain Laws (Official Gazette No. 32487, 12 March 2024)(mevzuat.gov.tr).gov
  12. IAPP - The Long-Awaited Amendments in Turkish Data Protection Law(iapp.org)
  13. IAPP - Turkey Data Protection Amendments for 2024: A Closer Look(iapp.org)
  14. CottGroup - Administrative Fine Amounts in KVKK for 2026(cottgroup.com)
  15. KVKK - Public Announcement on the Standard Contract Notification Module (Board Decision No. 2024/1793 of 17 October 2024)(kvkk.gov.tr).gov
  16. IBA - Mandatory Data Protection Compliance in Turkey: VERBIS Registration and Enforcement Actions(ibanet.org)
  17. Erdem & Erdem - KVKK Guideline on Transfer of Personal Data Abroad (January 2025)(erdem-erdem.av.tr)
  18. Moral Law - Amendments to Law No. 6698 on the Protection of Personal Data (Law 7499)(moral.av.tr)
  19. CMS - KVKK Board Decision No. 2025/2451: Breach Notice Publication Limited to 60 Days(cms.law)
Share: