Data Protection

Cross-Border Data Transfers From Türkiye Under the KVKK: The Post-2024 Regime

If your group sends HR, payroll or customer data out of Türkiye, you can now transfer it abroad under a tiered system that closely mirrors the GDPR. The governing law is the Turkish Personal Data Protection Law (Kişisel Verilerin Korunması Kanunu, KVKKKVKKPersonal Data Protection Law No. 6698Türkiye's data protection statute — the rules on collecting, storing and transferring personal data, and the authority that enforces them.Glossary → No. 6698), and its rules on international transfer were rewritten by Law No. 7499, with the new transfer regime taking effect from 1 June 2024. Under the new Article 9, you may transfer data abroad first on the basis of an adequacy decision (yeterlilik kararı) by the Board; if there is none, on the basis of appropriate safeguards (uygun güvenceler) such as standard contractual clauses or binding corporate rules; and, only when neither is available, on a narrow set of exceptional derogations. This guide explains, in plain terms, what each tier means and how it affects foreign companies moving data connected to Türkiye.

Who this affects and why it changed

If you are a foreign company or part of an international group and you move personal data out of Türkiye — employee records to a parent company's HR system, customer details to a cloud platform hosted abroad, or supplier and contact data to a shared CRM — these rules apply to you. They apply whether you are the data controller (veri sorumlusu), the party that decides why and how data is processed, or a data processor (veri işleyen) acting on a controller's instructions.

Before the 2024 reform, the KVKK's international-transfer rule was difficult to live with. In practice, transferring data abroad usually depended either on the data subject's explicit consent (açık rıza) or on a written undertaking combined with Board permission, and the adequacy mechanism the law described had not been put to practical use. That left many multinationals relying on consent for routine, group-wide data flows — a fragile basis, because consent can be withdrawn at any time.

Law No. 7499 replaced that framework with a layered model that closely tracks the structure of the EU General Data Protection Regulation (GDPR). The aim was to give businesses workable, repeatable transfer tools instead of forcing them to lean on consent. The governing statute remains Kişisel Verilerin Korunması Kanunu No. 6698; the amending instrument is Law No. 7499, and the new transfer provisions took effect on 1 June 2024.

Governing law: KVKK No. 6698, Article 9 (international transfer of personal data), as amended by Law No. 7499. The reform also touched related provisions, but Article 9 is the heart of the cross-border regime. A transitional rule (Geçici Madde 3) kept the former consent-based transfer route available only until 1 September 2024, after which it ceased — so consent is no longer a reliable basis for routine transfers abroad.

The new tiered structure at a glance

The post-7499 regime works as a sequence. You move to the next tier only when the one above it is not available for your particular transfer:

  • Tier 1 — Adequacy decision (yeterlilik kararı). The Board may decide that a country, a sector within a country, or an international organisation offers an adequate level of protection. If such a decision covers your destination, you may transfer on that basis (alongside the ordinary lawful-processing conditions in the KVKK).
  • Tier 2 — Appropriate safeguards (uygun güvenceler). If there is no adequacy decision, you may still transfer where the parties put appropriate safeguards in place and data subjects can exercise their rights and pursue effective legal remedies in the destination country.
  • Tier 3 — Exceptional situations (arızi haller). If neither an adequacy decision nor appropriate safeguards exist, a transfer is permitted only in specific, exceptional and non-routine circumstances.

This ordering matters. The derogations in Tier 3 are designed for one-off situations, not as a substitute for building a proper safeguard for data flows that repeat. If your group moves the same categories of data abroad month after month, Tier 1 or Tier 2 is where you should be.

Tier 1: Adequacy decisions

An adequacy decision is a determination by the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) — the body within the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, KVKK) — that a destination provides a level of protection comparable to Türkiye's. The decision can be made for a whole country, for particular sectors within a country, or for specific international organisations.

Where an adequacy decision covers your destination, a transfer there is treated much like a domestic processing operation for transfer-mechanism purposes: you do not need to layer on a separate transfer safeguard, although you still need a lawful basis for the underlying processing and must comply with the KVKK's general principles. Adequacy decisions are reviewed periodically and can be changed.

Do not assume any particular country is covered. The list of destinations with an adequacy decision, and the conditions attached, is set and updated by the Board over time. Confirm the current status for your specific destination before relying on adequacy, rather than assuming alignment with the EU's own adequacy list.

Tier 2: Appropriate safeguards (the everyday tools for groups)

For most foreign groups, this is the practical workhorse. Where there is no adequacy decision for the destination, you may transfer if appropriate safeguards are in place and the data subject is able to exercise their rights and access effective remedies. The KVKK now recognises several safeguard mechanisms:

Standard contractual clauses (standart sözleşme)

These are model clauses, in a form issued by the Authority, signed between the data exporter in Türkiye and the data importer abroad. They commit the importer to protect the data to a standard consistent with Turkish law. A distinctive feature of the Turkish system is a notification requirement: after signing standard contractual clauses, the parties are expected to notify the Authority within a defined period. Because that period and the exact filing mechanics are fixed by regulation and have changed during implementation, treat the deadline as a hard compliance step and verify the current timing.

Binding corporate rules (bağlayıcı şirket kuralları)

These are internal data-protection rules adopted across a corporate group, allowing transfers between group entities. They must be approved by the Board before you can rely on them. For a multinational that moves HR and intra-group data routinely, binding corporate rules can be an efficient long-term solution, though approval takes time and effort to obtain.

Other recognised safeguards

The framework also contemplates safeguards such as binding and enforceable undertakings between the parties, and arrangements between public authorities or bodies. Which mechanism fits depends on who is sending the data, who is receiving it, and whether the parties are within the same group.

For intra-group flows that repeat — payroll, global HR systems, shared customer databases — standard contractual clauses or binding corporate rules are usually a more stable foundation than relying on consent, because they do not collapse if an individual employee or customer later withdraws permission.

Tier 3: Exceptional, case-by-case transfers

Where neither an adequacy decision nor appropriate safeguards are available, the KVKK allows a transfer only in defined exceptional situations — for example, certain transfers based on the data subject's explicit consent after being informed of the risks, transfers necessary for the performance of a contract with or in the interest of the data subject, transfers necessary for an overriding public interest, the establishment or protection of a legal claim, or to protect the life or physical integrity of a person who cannot give consent.

These derogations are deliberately narrow. The law frames them as incidental or non-repetitive (arızi) — they are not meant to support a steady, ongoing pipeline of the same data abroad. If you find yourself relying on a derogation for a flow that recurs, that is usually a signal you should be putting a Tier 1 or Tier 2 mechanism in place instead.

Treating consent as a permanent transfer mechanism for routine flows is risky: it can be withdrawn, and using it to dress up what is really a repeating transfer can expose you to enforcement. Build a proper safeguard for anything that repeats.

Special categories and other obligations to keep in view

The transfer mechanism is only one layer. You also need a lawful basis for the underlying processing, and you must observe the KVKK's general principles — lawfulness and fairness, accuracy, purpose limitation, data minimisation and storage limitation.

Special categories of personal data (özel nitelikli kişisel veri) — such as health, biometric, religious or trade-union data — carry stricter conditions for processing and transfer. If your transfer includes sensitive data, the analysis is more demanding and should be checked carefully.

Several adjacent obligations commonly arise in transfer projects and each can carry its own filing duties, time limits and administrative-fine exposure:

  • Information (privacy) notices to data subjects describing the transfer and its basis.
  • Registration with VERBİS, the data controllers' registry, where applicable — registration duties depend on thresholds and exemptions that you should confirm for your organisation.
  • Responding to data-subject applications within the period the law allows.
  • Personal data breach notification to the Authority and to affected individuals within the timeframe the rules require.

The KVKK provides for administrative fines for breaches, including unlawful transfers abroad. We have stated the response period, breach-notification timing, VERBİS thresholds and fine levels qualitatively on purpose — the specific figures are set by statute and secondary regulation and are periodically updated. Confirm the current numbers before you rely on them.

A practical path for foreign groups

If you are mapping out compliant data flows, a workable sequence looks like this:

  • Map your transfers. Identify what personal data leaves Türkiye, to which countries and entities, for what purpose, and whether any of it is sensitive.
  • Check for an adequacy decision. If your destination is covered, that is your cleanest basis.
  • If not, choose a safeguard. For repeating intra-group flows, weigh standard contractual clauses against binding corporate rules. Remember the clauses carry a notification step, and binding corporate rules need Board approval.
  • Reserve derogations for genuine one-offs. Do not let them become the default for recurring transfers.
  • Align the rest of your compliance. Privacy notices, registry obligations, data-subject request handling and breach procedures should all reflect the transfer you have chosen.

The exact mechanism that fits your group depends on your structure, your destinations and the data involved, and the regulatory detail continues to develop as the Authority issues guidance. Where outcomes turn on facts and current Board practice, it is sensible to take tailored advice rather than apply a generic template.

Frequently asked questions

What law governs cross-border data transfers from Türkiye?

The Turkish Personal Data Protection Law (Kişisel Verilerin Korunması Kanunu No. 6698) governs the protection and transfer of personal data. Its rules on international transfer, in Article 9, were rewritten by Law No. 7499, with the new transfer regime taking effect from 1 June 2024.

Can we still rely on the data subject's explicit consent to transfer data abroad?

Consent is still recognised, but it now sits within the narrow exceptional-situations tier rather than being the default route. The reformed system expects you to use an adequacy decision or appropriate safeguards (such as standard contractual clauses or binding corporate rules) for routine, repeating transfers. Relying on consent for ongoing flows is fragile, because it can be withdrawn at any time.

What are standard contractual clauses under the KVKK?

They are model clauses, in a form issued by the Personal Data Protection Authority, signed between the exporter in Türkiye and the importer abroad, committing the importer to protect the data to a standard consistent with Turkish law. A distinctive feature is that the parties are expected to notify the Authority after signing, within a period set by regulation — you should confirm the current deadline, as it has changed during implementation.

Do binding corporate rules need approval?

Yes. Binding corporate rules are internal group-wide data-protection rules that allow transfers between group entities, and they must be approved by the Personal Data Protection Board before you can rely on them. They can be efficient for large multinationals but require time and effort to put in place.

Is the United States or the EU automatically an adequate destination?

No destination should be assumed to be adequate. The list of countries, sectors and organisations covered by an adequacy decision is set and updated by the Board, and Türkiye's adequacy decisions are not the same as the EU's. Always confirm the current status for your specific destination before relying on adequacy.

What happens if we transfer data abroad without a valid basis?

Unlawful cross-border transfers can attract administrative fines and other enforcement under the KVKK. The specific fine levels and procedural details are set by statute and secondary regulation and are periodically updated, so the exposure should be assessed on current figures for your situation. We do not guarantee any particular outcome.

Need a lawyer for this?We handle data protection (kvkk) for foreigners, end to end, in English, on a fixed fee.
Data Protection (KVKK)

Related articles

GDPR and Turkish Companies: Navigating ComplianceTurkey's Cybersecurity Law No. 7545: Scope & Principles
Let's begin

Speak to a Turkish lawyer who speaks your language.

Tell us your commercial, corporate or personal matter and get a clear, fixed-fee answer from a real Turkish lawyer — usually within one business day.

★★★★★ 4.9 from 60 Google reviews · Recognised on Mondaq, Clutch & Trustpilot
WhatsApp us
A real lawyer replies — usually within a day
WhatsAppEmailBook a consultation