Personal Data Protection Law
KVKK compliance, privacy notices and data processing.
Scope
We advise on the lawful processing, protection and transfer of personal data.
We assess the obligations of companies and digital platforms under the KVKK, prepare the required documents and bring data processing in line with the legislation. We review data processing on websites, in mobile apps, in employment relationships and in business activities with regard to legal risks.
What we do in this area
- KVKK compliance review and action plan
- Privacy notices, explicit consent and cookie texts
- Personal data inventory, retention and destruction policy
- VERBİS registration
- Cross-border data transfers
- Responding to data subject requests
- Data breach notification and proceedings before the Board
Frequently asked questions
Do I have to register with VERBİS?
As a rule, natural and legal persons processing personal data must register with the Data Controllers' Registry (Veri Sorumluları Sicili – VERBİS) before they start processing (Personal Data Protection Act (Kişisel Verilerin Korunması Kanunu – KVKK, Law No. 6698) art. 16 (Official text, opens in a new tab)). The Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) has introduced exemptions from this obligation. Under Board Decision No. 2025/1572, those with fewer than 50 employees per year and an annual balance sheet total of less than 100 million TL, whose main activity is not the processing of special categories of personal data, are exempt from registration. For those whose main activity is the processing of special categories of data, the thresholds are 10 employees and 10 million TL; under Decision No. 2025/2393, for those that do not keep their books on a balance-sheet basis, only the number of employees is considered. Please refer to the official text for the current position.
Is a privacy notice the same as explicit consent?
No. The duty to inform means telling the person, when the data are collected, who processes their data, for what purpose and on what legal basis, to whom the data may be transferred, and what rights the person has (Personal Data Protection Act (Kişisel Verilerin Korunması Kanunu – KVKK, Law No. 6698) art. 10 (Official text, opens in a new tab)). This obligation applies whatever the legal ground on which the data are processed, and does not depend on a request by the person. Explicit consent, by contrast, is consent relating to a specific matter, based on information and given freely (KVKK art. 3 (Official text, opens in a new tab)). Where processing is based on explicit consent, the duty to inform and explicit consent are fulfilled separately (Communiqué on the Procedures and Principles for Fulfilling the Obligation to Inform (Aydınlatma Yükümlülüğünün Yerine Getirilmesinde Uyulacak Usul ve Esaslar Hakkında Tebliğ) art. 5 (Official text, opens in a new tab)).
How can I find out what data a company processes about me?
Anyone may apply to the data controller to find out whether their data are being processed, to request information, and to request rectification or erasure (Personal Data Protection Act (Kişisel Verilerin Korunması Kanunu – KVKK, Law No. 6698) art. 11 (Official text, opens in a new tab)). The application is made in writing or by other methods determined by the Personal Data Protection Board. The data controller concludes the request within 30 days at the latest and, as a rule, free of charge (KVKK art. 13 (Official text, opens in a new tab)). According to the announcement of the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) dated 1 October 2026, information given by telephone or in person does not count as a response; the response is communicated in writing or electronically.
What can I do if my application is not answered? Is there a time limit?
If the application is rejected, the response is found insufficient or no response is given in time, a complaint may be lodged with the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) (Personal Data Protection Act (Kişisel Verilerin Korunması Kanunu – KVKK, Law No. 6698) art. 14 (Official text, opens in a new tab)). The complaint must be lodged within 30 days of learning of the response and in any event within 60 days of the application date. A complaint cannot be lodged without first applying to the data controller. The right of persons whose personality rights have been infringed to claim compensation under the general provisions is reserved.
Is explicit consent required for all processing of personal data?
No. Explicit consent is not required where, for example, processing is expressly provided for by law, is necessary for the conclusion or performance of a contract, is required by a legal obligation of the data controller, is necessary for the establishment or protection of a right, or is based on legitimate interest (Personal Data Protection Act (Kişisel Verilerin Korunması Kanunu – KVKK, Law No. 6698) art. 5 (Official text, opens in a new tab)). The legitimate interest ground applies only if the fundamental rights and freedoms of the data subject are not harmed. The conditions for special categories of personal data are more limited (KVKK art. 6 (Official text, opens in a new tab)). Whichever ground applies, the duty to inform remains.
What should be done in the event of a data breach?
If data are obtained by others through unlawful means, the data controller notifies the data subjects concerned and the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) as soon as possible (Personal Data Protection Act (Kişisel Verilerin Korunması Kanunu – KVKK, Law No. 6698) art. 12 (Official text, opens in a new tab)). Under the Board's decision No. 2019/10, "as soon as possible" means 72 hours; the Board must be notified no later than 72 hours after the breach becomes known. The affected persons are notified within the shortest reasonable time after they have been identified. Any delay must be explained together with the notification; the breach and the measures taken are recorded.
Can I transfer personal data to a server or service abroad?
Data may be transferred abroad if one of the processing grounds exists and the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) has issued an adequacy decision for the destination country (Personal Data Protection Act (Kişisel Verilerin Korunması Kanunu – KVKK, Law No. 6698) art. 9 (Official text, opens in a new tab)). According to the website of the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu), no adequacy decision has yet been issued for any country. In that case, one of the appropriate safeguards, such as standard contracts or binding corporate rules, is required; a standard contract must be notified to the Authority within five business days of signature. Where none of these is available, a transfer may be made only in the incidental cases listed in the law; the details are governed by (Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad (Kişisel Verilerin Yurt Dışına Aktarılmasına İlişkin Usul ve Esaslar Hakkında Yönetmelik) (Official text, opens in a new tab)). Please refer to the official text for the current position.
Which data are special categories of personal data?
Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of an association, foundation or trade union, health, sex life, criminal convictions and security measures, as well as biometric and genetic data, are special categories of personal data (Personal Data Protection Act (Kişisel Verilerin Korunması Kanunu – KVKK, Law No. 6698) art. 6 (Official text, opens in a new tab)). Processing these data is, as a rule, prohibited. They may be processed in the cases listed, such as explicit consent, express provision by law, and legal obligations in the fields of health services and employment. In every case, the adequate measures determined by the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) must be taken.
What are the penalties for breaching the Turkish Personal Data Protection Law (KVKK)?
Breaches of the obligations relating to the duty to inform, data security, compliance with decisions of the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), VERBİS registration (Data Controllers' Registry) and notification of standard contracts are subject to administrative fines (Personal Data Protection Act (Kişisel Verilerin Korunması Kanunu – KVKK, Law No. 6698) art. 18 (Official text, opens in a new tab)). The amounts in the law are increased each year by the revaluation rate under the Law on Misdemeanours (Kabahatler Kanunu, No. 5326). Administrative fines imposed by the Board may be challenged before the administrative court. Unlawfully recording personal data (Turkish Criminal Code (Türk Ceza Kanunu – TCK, Law No. 5237) art. 135 (Official text, opens in a new tab)) and unlawfully giving, disseminating or obtaining such data are criminal offences (TCK art. 136 (Official text, opens in a new tab)). Please refer to the official text for the current position.
Related petition samples
The content of this website is for general information only and does not constitute legal advice. Please consult a lawyer about your specific situation.