Contact

What is KVKK (Turkish Data Protection Law)?

Definition

KVKK is the common abbreviation for Turkey's Law No. 6698 on the Protection of Personal Data, published in the Official Gazette on 7 April 2016. It sets the conditions under which data controllers may process personal data, their duties to inform people and keep data secure, and the rights of data subjects. It is enforced by the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) and its decision-making Board.

Also known as: Law No. 6698, Turkish Personal Data Protection Law, KVK Law, Turkish PDPL, Personal Data Protection Authority

Diagram of the Turkish data protection law's principles: lawfulness, accuracy, specific purpose, proportionality, limited retention and notice

Law, Authority and Board

In Turkish usage, “KVKK” refers both to Law No. 6698 and to the Personal Data Protection Authority that enforces it. The law covers any information relating to an identified or identifiable natural person, i.e. personal data. It works with three roles: the data controller, who decides why and how data is processed; the data processor, who processes it on the controller's behalf (a hosting company, an email provider, an agency); and the data subject. Decisions and administrative fines come from the Personal Data Protection Board.

This entry is general information, not legal advice. For a specific process, rely on the current legislation and a lawyer's review.

Article 4 sets principles for every processing activity: lawfulness and fairness, accuracy, specified and legitimate purposes, relevance and proportionality, and retention only as long as necessary. Article 5 lists the conditions that make processing lawful. The data subject's explicit consent is only one of them. Performance of a contract, a legal obligation of the controller, establishing or defending a right, and the controller's legitimate interests (provided the person's fundamental rights are not harmed) are equally valid. Processing a delivery address to ship an order rests on the contract, so asking for consent on top of that is unnecessary and potentially misleading.

Special categories such as health, biometric data, religion or criminal convictions are governed separately by Article 6, under narrower conditions.

What it means for a website

  • Duty to inform (Article 10): when data is collected, people must be told who the controller is, the purpose, to whom and why data may be transferred, how it is collected and on which legal ground, and what their rights are. Contact forms, sign-ups and newsletter boxes should link to this notice.
  • Cookies: the Authority's cookie guidance spells out when non-essential cookies need consent; the practical side is covered under cookie consent.
  • Data security (Article 12): controllers must take appropriate technical and organisational measures, such as access control, encryption, audit logs, backups, and contracts with staff and vendors.
  • Breaches: if data is obtained unlawfully, the controller must notify the data subjects and the Board “within the shortest time”. Board Decision 2019/10 reads this as 72 hours from becoming aware of the breach.
  • Requests (Articles 11 and 13): people can ask whether their data is processed and request correction or erasure; requests must be concluded within thirty days at the latest.

VERBİS registration and its exemptions

VERBİS is the online system for the Data Controllers' Registry required by Article 16. The Board defines exemptions by decision. According to the Authority's announcement, controllers with fewer than 50 employees a year and an annual balance sheet total below 100 million TL are exempt, as long as their main activity is not processing special category data. Decision 2025/1572 added a further exemption for controllers whose main activity is special category processing but who have fewer than 10 employees and a balance sheet below 10 million TL. Thresholds change, so check the Authority's latest announcements. An exemption from registration does not remove any other obligation under the law.

The 2024 amendment and cross-border transfers

Law No. 7499, adopted in March 2024, rewrote Articles 6 and 9, with the changes taking effect on 1 June 2024. Transfers abroad now follow a tiered model: an adequacy decision by the Board for the destination country or sector; failing that, appropriate safeguards such as standard contracts, binding corporate rules or written undertakings; and, as a last resort, incidental transfers only. A signed standard contract must be notified to the Authority within five business days. A regulation published on 10 July 2024 sets out the procedures.

This matters for web projects more often than people expect: servers hosted abroad, email and CRM platforms, analytics and ad tools frequently involve a transfer. Businesses serving users in the EU also need to consider the GDPR. The Authority publishes an English translation of the law, though the Turkish text is the binding one.

Related terms

← Back to the glossary