KVKK for Foreign Companies: What Türkiye Requires Beyond GDPR Compliance
A company already compliant with the GDPR is not compliant with Turkish law. KVKK and the GDPR compared on lawful bases, cross-border transfer, registration, breach notification and fines — plus the Turkish obligations with no European equivalent.
On this page
A company that already complies with the GDPR is not compliant in Türkiye. Personal data processing here is governed by Law No. 6698 on the Protection of Personal Data (“KVKK”), enacted 24 March 2016 and substantially rewritten by Law No. 7499 with effect from 1 June 2024. The four obligations that most often catch European groups out have no direct GDPR equivalent: registration with the VERBİS registry before processing begins, appointment of a Türkiye-resident data controller representative for controllers not established here, notification of any cross-border standard contract within five business days of signature, and the fact that — as at July 2026 — the Turkish regulator has issued no adequacy decision for any country, so no transfer out of Türkiye can rest on one. The regulator is the Kişisel Verileri Koruma Kurumu, an autonomous public legal entity in Ankara whose Board (Kurul) exercises its powers independently under art. 21, and which may not be instructed by any organ or person.
Which lawful bases can you actually rely on?
Start by discarding one widespread myth: KVKK does contain a legitimate-interest basis. Article 5(2)(f) permits processing where it is necessary for the legitimate interests of the controller, provided this does not harm the data subject’s fundamental rights and freedoms.
What differs is the architecture. Article 5(1) states as a rule that personal data may not be processed without the data subject’s explicit consent (açık rıza); the other bases in art. 5(2) then operate as exceptions to that rule — an express provision of law, protection of life or bodily integrity, necessity for a contract to which the data subject is a party, a legal obligation of the controller, data made public by the subject, the establishment or exercise or protection of a right, and legitimate interests. The GDPR, by contrast, lists consent as one of six co-equal bases. In practice the outcome often converges, but the drafting of Turkish privacy notices and consent flows has to follow the Turkish structure, not the European one.
Special category data is where the divergence bites. Article 6 — as amended by Law No. 7499 — lists race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of an association, foundation or trade union, health, sex life, criminal convictions and security measures, and biometric and genetic data. Processing is prohibited unless one of the grounds in art. 6(3)(a)–(g) applies, and there is no legitimate-interest ground among them. Article 6(4) adds that the adequate measures determined by the Kurul must also be taken. A European analysis that leans on legitimate interest for, say, occupational health records will not survive translation.
How do you move data out of Türkiye after the 2024 reform?
Article 9 was replaced in its entirety by Law No. 7499, published in the Resmî Gazete of 12 March 2024, No. 32487. The detail sits in the Kişisel Verilerin Yurt Dışına Aktarılmasına İlişkin Usul ve Esaslar Hakkında Yönetmelik, published on 10 July 2024, No. 32598. The old regime survived alongside the new one only until 1 September 2024 under Provisional Article 3.
The result is a three-tier structure that will look familiar to any GDPR practitioner:
Tier 1 — adequacy decision. Under art. 9(1)–(3), transfer is permitted where an art. 5 or art. 6 condition exists and the Kurul has issued an adequacy decision for the destination country, a sector within it, or an international organisation. Decisions are published in the Resmî Gazete and reviewed at least every four years. The practical difficulty is stated on the Authority’s own cross-border transfer page: no such determination has yet been made. Tier 1 is, for now, empty.
Tier 2 — appropriate safeguards. Article 9(4) therefore does the work. Absent adequacy, transfer is possible where an art. 5/6 condition exists, the data subject can exercise rights and pursue effective remedies in the destination country, and one of four safeguards is in place: an agreement between foreign public bodies and Turkish public bodies with Kurul permission; binding corporate rules approved by the Kurul for a group of undertakings; the standard contract published by the Kurul; or a written undertaking with Kurul permission. The standard contract must be used without modification and covers data categories, transfer purposes, recipients, the recipient’s technical and administrative measures, and additional measures for special category data.
Tier 3 — derogations. Where neither applies, art. 9(6) permits transfer only on an incidental (arızi) basis: informed explicit consent to the transfer, necessity for a contract with the data subject or pre-contractual steps, a contract in the data subject’s interest, overriding public interest, establishment or exercise of a right, protection of life or bodily integrity, or transfer from a public register. Article 9(8) extends the same discipline to onward transfers — a point routinely missed when a Turkish subsidiary sends data to a European parent that then uses a US cloud provider.
The trap with the sharpest edge: under art. 9(5), a standard contract must be notified to the Authority by the controller or processor within five business days of signature. Article 14 of the 2024 Regulation repeats it, allowing physical delivery, registered electronic mail (KEP) or other methods set by the Kurul. Missing that window is its own offence, added to art. 18 by Law No. 7499, and carries a fine of TRY 90,308 to TRY 1,806,177 for 2026.
KVKK vs GDPR: where the two regimes diverge
| Dimension | KVKK (Law No. 6698) | GDPR |
|---|---|---|
| Lawful bases | Explicit consent is the rule under art. 5(1); the art. 5(2) bases operate as exceptions, including legitimate interest (art. 5(2)(f)) | Six co-equal bases under art. 6, consent among them |
| Special category data | Art. 6(3) grounds only — no legitimate-interest ground; Kurul-determined adequate measures also required | Art. 9(2) derogations |
| Cross-border transfer | Adequacy → appropriate safeguards → incidental derogations (art. 9); no adequacy decision issued as at July 2026 | Adequacy decisions in force for a number of third countries |
| Transfer paperwork | Standard contract must be notified to the Authority within 5 business days of signature (art. 9(5)) | Standard contractual clauses require no filing with a supervisory authority |
| Registration | VERBİS registration before processing begins (art. 16), subject to exemption thresholds | No general registration duty |
| Governance role | irtibat kişisi (contact person); foreign controllers need a Türkiye-resident veri sorumlusu temsilcisi | Data protection officer where art. 37 applies |
| Breach notification | Kurul within 72 hours; data subjects within the shortest reasonable time (Kurul decision 2019/10) | 72 hours to the supervisory authority |
| Fines | Fixed TRY bands under art. 18, revalued annually; no turnover-percentage fine | Up to a percentage of worldwide annual turnover |
| Appeal route | Administrative courts (idare mahkemeleri), art. 18(3), added 1 June 2024 | National procedures |
Who must register with VERBİS — and who is exempt?
Article 16 requires natural and legal persons processing personal data to enter the publicly accessible Data Controllers’ Registry before they begin processing, and empowers the Kurul to grant exemptions. Two decisions define the current position. By decision 06/07/2023 No. 2023/1154, controllers with fewer than 50 annual employees and an annual balance sheet total below TRY 100 million, whose main activity is not the processing of special category data, are exempt — that decision raised the balance-sheet figure from the TRY 25 million set in 2018. By decision 04/09/2025 No. 2025/1572, announced on 1 October 2025, controllers whose main activity is special category processing are also exempt if they have fewer than 10 annual employees and a balance sheet below TRY 10 million.
Registration is not merely a form. Controllers subject to it must prepare a Personal Data Processing Inventory (Kişisel Veri İşleme Envanteri), and a controller not resident in Türkiye must register through a data controller representative — a Türkiye-resident legal person or Turkish-citizen natural person whose certified appointment decision is filed with the Authority, and whose mandate must at minimum cover receiving the Authority’s notifications, relaying requests and responses, and receiving data subject applications. Foreign groups typically settle this at the same time they choose their Turkish market-entry vehicle, because a branch and a subsidiary sit differently in the registry. Where the Turkish entity is being formed from scratch, the registration analysis belongs alongside company formation, not months after it.
What happens when there is a breach?
Article 12(1) obliges the controller to take all necessary technical and administrative measures to prevent unlawful processing and unlawful access and to ensure preservation of the data; art. 12(2) makes the controller jointly liable with any processor acting on its behalf. When data is nevertheless obtained unlawfully, art. 12(5) requires notification to the data subject and to the Kurul “as soon as possible”.
Kurul decision dated 24.01.2019 No. 2019/10 puts a number on that phrase: notification to the Authority without delay and within 72 hours at the latest, on the Authority’s official Data Breach Notification Form, with reasons supplied if the deadline cannot be met. Information may be given in stages, controllers must keep records of breaches and remedial measures, and processors must inform the controller without delay. Notification to affected individuals is governed by a different standard — the shortest reasonable time once they have been identified, with no fixed day-count — while Kurul decision 18.09.2019 No. 2019/271 sets the minimum content of that notice and requires clear, plain language.
One 2026 development is worth knowing. By Kurul decision dated 25/12/2025 No. 2025/2451, announced on 20 January 2026, breach announcements published on the Authority’s own website — previously open-ended — are now published for a capped period of 60 days, and are removed earlier where the controller documents that it notified the affected data subjects within a shorter period. Prompt notification now shortens public exposure as well as reducing regulatory risk.
What do the fines look like in 2026?
Article 18 sets fixed Turkish lira bands, revalued every 1 January by the revaluation rate under repeated art. 298 of Tax Procedure Law No. 213, applied through art. 17(7) of the Misdemeanours Law No. 5326. The rate for 2026 is 25.49%. On the Authority’s official fine table, the 2026 bands are: information obligation, TRY 85,437–1,709,200; data security obligations, TRY 256,357–17,092,242; failure to comply with a Kurul decision, TRY 427,263–17,092,242; VERBİS registration and notification, TRY 341,809–17,092,242; and standard contract notification, TRY 90,308–1,806,177. Treat these as 2026 figures only — they change each January.
Two structural points matter for a European board. First, there is no percentage-of-turnover fine in KVKK; exposure is capped in lira terms, which for a large group is often less alarming than the operational disruption of a Kurul decision. Second, since Law No. 7499 added art. 18(3) with effect from 1 June 2024, fines are challenged before the administrative courts, not the criminal judgeships of peace that previously heard them.
Where a foreign group should start
The efficient sequence is to treat KVKK as a distinct programme built on the same evidence base as your GDPR file, rather than a translation exercise. Map the Turkish processing, re-test each activity against arts. 5 and 6, choose and paper the art. 9 mechanism, check the VERBİS thresholds and appoint the representative, then wire the 72-hour path into your incident plan. Employment data usually demands the earliest attention, because HR files combine special category data with intra-group transfer — a theme that runs through our guide to employing staff in Türkiye. Vendor and intra-group paperwork should be aligned at the same time, which is a drafting question as much as a compliance one and sits with commercial contracts.
Data protection is rarely the reason a foreign company comes to Türkiye, and it is often the item left until the Turkish entity is already processing. Our personal data protection practice advises on the gap between an existing European programme and what Law No. 6698 actually requires — the registration, the representative, the transfer mechanism and the notification clock.
Bringing a GDPR programme into KVKK compliance
- 01
Map the Turkish processing separately
Identify what your Turkish entity, branch or local partner actually processes and where it sits. A European record of processing rarely maps cleanly onto Turkish categories, and registrable controllers must prepare a Kişisel Veri İşleme Envanteri.
- 02
Re-run the lawful basis analysis under art. 5 and art. 6
Test each processing activity against art. 5(2), and treat special category data separately — art. 6(3) has no legitimate-interest ground, so a basis that works in Europe may fail in Türkiye.
- 03
Fix the transfer mechanism under the new art. 9
With no adequacy decision available, choose between the Kurul's standard contract, binding corporate rules or an undertaking with Kurul permission — and diarise the five-business-day notification for every standard contract signed.
- 04
Register, and appoint the right people
Check the VERBİS exemption thresholds; if registrable, appoint a Türkiye-resident data controller representative with a certified appointment decision, and notify a contact person.
- 05
Build the breach and response mechanics
Put a 72-hour internal escalation path in place, adopt the Authority's notification form, require processors to alert you without delay, and keep a record of every breach, its effects and the remedial measures taken.
Frequently asked questions
We are GDPR compliant — do we automatically comply with KVKK in Türkiye?
No. Law No. 6698 shares much of the GDPR's vocabulary, but it is a separate statute with separate obligations. Four requirements in particular have no direct European counterpart: registration with the VERBİS registry before processing begins, notification of a Turkish contact person (irtibat kişisi), appointment of a Türkiye-resident data controller representative if you are not established in Türkiye, and the five-business-day notification of any standard contract used for a transfer abroad. Cross-border transfer also works differently, because no adequacy decision has yet been issued for any destination.
Can we transfer personal data from Türkiye to the EU or the United States?
Yes, but not on the basis of an adequacy decision. As at July 2026 the Personal Data Protection Authority states that the Kurul has made no adequacy determination for any country, sector or international organisation. Transfers must therefore rely on one of the appropriate safeguards in art. 9(4) of Law No. 6698 — the Kurul's standard contract, binding corporate rules approved by the Kurul, an agreement between public bodies with Kurul permission, or a written undertaking with Kurul permission — and, failing that, only on the incidental derogations in art. 9(6), which include explicit consent given after the data subject has been informed of the risks.
Does Türkiye require a Data Protection Officer?
No. Law No. 6698 imposes no DPO obligation. What the Data Controllers' Registry Regulation requires instead is a contact person (irtibat kişisi), a natural person notified through VERBİS for communication with the Authority. The Authority states expressly that the contact person is not authorised to represent the controller and that responsibility for obligations and sanctions rests with the organ authorised to bind the legal entity. A controller not resident in Türkiye must additionally register through a data controller representative (veri sorumlusu temsilcisi) — a Türkiye-resident legal person or Turkish-citizen natural person — before it begins processing.
What is the deadline for reporting a data breach in Türkiye?
Article 12(5) of Law No. 6698 requires the controller to notify both the affected data subject and the Kurul "as soon as possible". Kurul decision dated 24.01.2019 No. 2019/10 interprets that as without delay and within 72 hours at the latest from the moment the controller becomes aware of the breach, using the Authority's official Data Breach Notification Form; if 72 hours cannot be met for justified reasons, the reasons for the delay must accompany the notification. Notification to the affected individuals has no fixed day-count — the rule is the shortest reasonable time once those affected have been identified.
How much are KVKK fines in 2026?
For calendar year 2026 the administrative fine bands under art. 18 of Law No. 6698 are: TRY 85,437 to 1,709,200 for breach of the information obligation; TRY 256,357 to 17,092,242 for breach of the data security obligations; TRY 427,263 to 17,092,242 for failure to comply with a Kurul decision; TRY 341,809 to 17,092,242 for breach of the VERBİS registration and notification obligation; and TRY 90,308 to 1,806,177 for failure to notify a standard contract under art. 9(5). These amounts are revalued every 1 January by the revaluation rate (25.49% for 2026), so they are current for 2026 only. There is no percentage-of-turnover fine under KVKK.
Does our foreign company have to register with VERBİS?
Article 16 of Law No. 6698 requires natural and legal persons who process personal data to register with the Data Controllers' Registry before processing begins, and a controller not resident in Türkiye registers through its data controller representative. The Kurul has granted exemptions: under decision 06/07/2023 No. 2023/1154, controllers with fewer than 50 annual employees and an annual balance sheet total below TRY 100 million, whose main activity is not the processing of special category data, are exempt; under decision 04/09/2025 No. 2025/1572 the exemption was extended to controllers whose main activity is special category processing where they have fewer than 10 employees and a balance sheet under TRY 10 million. Registrable controllers must also maintain a personal data processing inventory.