KVKK Compliance for Foreign Companies in Türkiye: A Practical Guide
If your company processes the personal data of people located in Türkiye, Türkiye's data protection law can apply to you even if you have no office, server, or staff in the country. That law is the Personal Data Protection Law No. 6698, known by its Turkish initials KVKKKVKKPersonal Data Protection Law No. 6698Türkiye's data protection statute — the rules on collecting, storing and transferring personal data, and the authority that enforces them.Glossary → (Kişisel Verilerin Korunması Kanunu). This guide explains, in plain terms, what KVKK is, how it compares to the EU's GDPR, who it covers, and the headline duties a foreign business needs to plan for, including the important changes made by amending Law No. 7499 in 2024.
What is KVKK, and what does it regulate?
KVKK is the short name for Türkiye's Personal Data Protection Law No. 6698 (Kişisel Verilerin Korunması Kanunu), in force since 2016. It is the country's central law on how personal data may be collected, stored, used, shared, and deleted.
"Personal data" means any information relating to an identified or identifiable real person, for example a name, an ID number, an email address, location data, or an online identifier. "Processing" is read broadly: collecting, recording, storing, changing, sharing, transferring, or deleting data all count.
The law sets out core principles that any processing must respect, such as lawfulness and fairness, accuracy, purpose limitation, data minimisation, and storage only for as long as needed. It also lists the legal bases that make processing lawful, ranging from the explicit consent (açık rıza) of the person to several grounds that do not require consent, such as performance of a contract or compliance with a legal obligation.
The governing statute is the Kişisel Verilerin Korunması Kanunu No. 6698, substantially amended by Law No. 7499 of 2024. Detailed rules also come from secondary regulations and from binding decisions of the Personal Data Protection Board.
How does KVKK compare to the GDPR?
If you already know the EU's General Data Protection Regulation (GDPR), KVKK will feel familiar. It was built on the same European model and shares much of the same logic: a controller/processor split, lawful bases for processing, data subject rights, and an independent regulator. But it is a separate Turkish law, and the details differ.
Some practical differences that foreign teams notice:
- Consent culture. KVKK has historically leaned heavily on explicit consent (açık rıza) as a processing basis, and Turkish practice treats consent strictly. You should not assume a GDPR-style "legitimate interests" analysis maps one-to-one onto KVKK.
- A registry. KVKK operates a public controllers' registry, VERBİS, with which many controllers must register. The GDPR has no equivalent central registry.
- Its own regulator and case law. KVKK is interpreted and enforced by Türkiye's own Authority and Board, whose decisions guide compliance in Türkiye.
- Cross-border transfers. The rules for sending data outside Türkiye are KVKK's own, and they were reformed in 2024 (see below).
GDPR compliance is a useful starting point, but it is not a substitute for KVKK compliance. A foreign company may be subject to both at once, for example where it serves customers in the EU and in Türkiye.
Who must comply: data controllers and data processors
KVKK assigns duties based on your role in the data processing. The two key roles are the same concepts you may know from the GDPR.
Data controller (veri sorumlusu)
The data controller is the person or organisation that decides why and how personal data is processed. The controller carries the main legal responsibilities under KVKK, such as informing individuals, securing the data, responding to requests, and, where required, registering with VERBİS.
Data processor (veri işleyen)
The data processor is the person or organisation that processes data on the controller's behalf and on its instructions, for example a cloud host, a payroll provider, or an analytics vendor. Processors have their own security and confidentiality obligations and are typically bound to the controller through a written arrangement.
Getting this classification right matters, because it determines which duties fall on you. Many disputes start with a disagreement over who was really the controller.
Does KVKK reach foreign companies?
Yes, it can. KVKK is not limited to companies that are established in Türkiye. In practice, the Authority and the Board have taken the position that the law can apply where a foreign company processes the personal data of people who are in Türkiye, for example by offering goods or services to them or by monitoring their behaviour.
That means an e-commerce business selling into Türkiye, a SaaS platform with Turkish users, or a foreign employer with staff or contractors in Türkiye may all fall within KVKK's reach without having a registered Turkish entity.
"We have no office in Türkiye" is not, by itself, a reliable defence. If you direct services at people in Türkiye or handle their data, assume KVKK may apply and get the position assessed before you rely on being outside its scope.
A foreign controller that is within scope may also need to act through a representative in Türkiye and to meet local-facing obligations. Because the way these obligations attach to non-resident companies turns on the specific facts, this is one of the first points to confirm with Turkish counsel.
The regulator and the VERBİS registry
KVKK is supervised by the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, the "Kurum"). Inside the Authority, the decision-making body is the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu, the "Kurul").
The Board is the part you are most likely to encounter. It:
- investigates complaints and acts on its own initiative;
- issues binding decisions and general guidance that shape how the law is applied;
- can order processing to stop or data to be deleted; and
- can impose administrative fines for breaches.
The Board publishes summaries of many of its decisions, which show how abstract principles are applied to real situations, including those involving foreign companies and cross-border data flows.
VERBİS, the controllers' registry
VERBİS (Veri Sorumluları Sicil Bilgi Sistemi) is the Authority's online registry of data controllers. Many controllers must register before they begin processing and must keep their entry up to date, declaring information such as the categories of data they process, their purposes, the recipients, retention periods, and security measures. Not every controller has to register: KVKK and the Board set out exemptions and thresholds, for example based on the number of employees or the nature and scale of the processing, with specific rules for controllers without an establishment in Türkiye.
KVKK provides for administrative fines, and certain conduct can also carry consequences under separate provisions of Turkish criminal law. The exact fine amounts, and whether you cross the VERBİS registration threshold, depend on figures and criteria that change over time, so they should be confirmed against the current rules rather than assumed.
The headline compliance duties
If KVKK applies to your processing, the core duties of a controller typically include the following. Treat this as an orientation map, not a complete checklist.
- Have a lawful basis. Every processing activity needs a valid legal basis under KVKK, whether explicit consent or one of the consent-free grounds.
- Inform individuals. You must tell people, at the time of collection, who you are, what data you take, why, on what basis, and to whom it may be disclosed (the duty to inform, aydınlatma yükümlülüğü).
- Respect data subject rights. Individuals can ask whether you hold their data, request access and correction, and seek deletion in defined circumstances. You must have a process to receive and answer these requests within the time limit set by the law.
- Keep data secure. You must take appropriate technical and organisational measures to protect data, and the Board has issued guidance on what "appropriate" means in practice.
- Handle breaches. If a data breach occurs, KVKK requires notification to the Authority, and to affected individuals, within the timeframe set by the rules.
- Register with VERBİS where required, and document your processing through inventories and retention/destruction policies.
The exact response time for data subject requests and the deadline for notifying a data breach are fixed by the legislation and related decisions. Both are stated qualitatively here on purpose and must be confirmed against the current rules before you build them into your processes.
The 2024 amendment (Law No. 7499) and cross-border transfers
In 2024, KVKK was significantly amended by Law No. 7499. The amendment is important for foreign companies because it touched two of the most sensitive areas of the law.
Special categories of data
KVKK gives extra protection to "special categories" of personal data (özel nitelikli kişisel veriler), such as data on health, religion, ethnicity, biometrics, or trade-union membership. The 2024 amendment revised the conditions under which such data may be processed, broadening the situations beyond reliance on explicit consent alone. If your operations touch sensitive data, the old analysis may no longer be correct.
Transfers outside Türkiye
The amendment also reshaped the rules for sending personal data abroad (yurt dışına aktarım). The reformed regime is built around a layered approach that will look familiar from the GDPR: transfers on the basis of an adequacy decision; in the absence of one, transfers supported by appropriate safeguards (which can include standard contractual clauses, in Turkish standart sözleşme, as well as binding corporate rules and similar instruments); and, in limited situations, specific derogations.
The cross-border transfer rules, the available safeguards, any filing or notification steps tied to them, and the treatment of special-category data were all reworked by Law No. 7499 and are still settling through secondary regulation and Board practice. Re-verify every Türkiye-to-abroad data flow against the current regime; do not rely on a pre-2024 setup.
Because these are exactly the areas a typical foreign company depends on, moving data to head office, to a global cloud, or to a parent company, the safest course is to map your data flows and have them assessed under the post-2024 rules.
Practical next steps for a foreign company
If you suspect KVKK may apply to you, a sensible starting sequence is:
- Map your data. Identify what personal data of people in Türkiye you process, why, and where it goes.
- Settle your role. Decide for each activity whether you are a controller or a processor.
- Confirm scope and representation. Get a view on whether KVKK applies and whether you need a representative in Türkiye.
- Check VERBİS. Assess whether you must register, against the current thresholds.
- Re-check transfers and sensitive data under the 2024 regime.
- Build the basics: lawful bases, privacy notices, a request-handling process, security measures, and a breach plan.
KVKK rewards companies that plan early. The rules are detailed, they overlap only partly with the GDPR, and several key points were changed in 2024, so a short, focused review now is usually far cheaper than fixing a problem after a complaint or an audit. Our team can help you assess whether KVKK applies to your operations and what your obligations are under the current law.
Frequently asked questions
Does KVKK apply to my company if we have no office in Türkiye?
It can. KVKK is not limited to Turkish-established companies. If you process the personal data of people who are in Türkiye, for example by offering them goods or services or by monitoring their activity, the law may apply to you even without a local entity. Because this depends on the specific facts, it is worth confirming with Turkish counsel rather than assuming you are out of scope.
What is the difference between a data controller and a data processor under KVKK?
A data controller (veri sorumlusu) decides why and how personal data is processed and carries the main legal duties. A data processor (veri işleyen) processes data only on the controller's instructions, such as a cloud or payroll vendor, and has its own narrower security and confidentiality obligations. Your role determines which duties apply to you.
Is KVKK the same as the GDPR?
No. KVKK (Law No. 6698) is built on a similar European model and shares much of the GDPR's structure and vocabulary, but it is a separate Turkish law with its own regulator, its own VERBİS registry, and its own rules, including its own cross-border transfer regime. A company can be subject to both KVKK and the GDPR at the same time.
What is VERBİS, and do I have to register?
VERBİS is Türkiye's online registry of data controllers. Many controllers must register and keep their entry current, but KVKK and the Board set out exemptions and thresholds based on factors such as headcount and the nature of the processing, with specific rules for controllers not established in Türkiye. Whether you must register should be checked against the current criteria, which change over time.
What changed in the 2024 amendment to KVKK?
Law No. 7499 of 2024 significantly amended KVKK. It revised the conditions for processing special-category (sensitive) data and reformed the rules for transferring personal data outside Türkiye, introducing a layered approach based on adequacy decisions, appropriate safeguards such as standard contractual clauses, and limited derogations. Any cross-border data flow set up before 2024 should be re-checked against the current rules.
What happens if we breach KVKK?
The Personal Data Protection Board can investigate, order processing to stop or data to be deleted, and impose administrative fines. Certain conduct can also have consequences under separate provisions of Turkish criminal law. The specific fine amounts are set by statute and updated over time, so they should be confirmed against the current figures.