Data Protection

KVKK vs GDPR: What Foreign Companies Need to Know

If you already know the GDPR, you have a head start on Turkey's data protection law (KVKKKVKKPersonal Data Protection Law No. 6698Türkiye's data protection statute — the rules on collecting, storing and transferring personal data, and the authority that enforces them.Glossary →, Law No. 6698) — but not a free pass. The two regimes share the same architecture: both are rights-based, both run on a data controller / data processor model, and both rest on the same core principles. The differences, though, are real and they catch foreign companies out. KVKK grew from an explicit-consent culture, it carries a registration step (VERBİS) that has no GDPR equivalent, it does not impose a Data Protection Officer mandate in the GDPR sense, and after the March 2024 reform (Law No. 7499) its cross-border transfer rules changed substantially. The single most important takeaway is this: being GDPR-compliant does not make you KVKK-compliant. This guide maps the overlaps and, more usefully, the gaps.

The Short Answer: Same Blueprint, Different Building

For a foreign company that already runs a GDPR programme, the honest summary is: you can reuse most of your thinking, but you cannot copy-paste your compliance. Turkey's Law on the Protection of Personal Data No. 6698 — the Kişisel Verilerin Korunması Kanunu, or KVKK — was built on the same European foundations as the GDPR. It protects the same right, uses the same vocabulary, and asks you to do many of the same things.

But KVKK is a sovereign Turkish law, enforced by a Turkish authority, with its own procedures, its own registry, and its own penalties denominated in Turkish lira. Where GDPR and KVKK diverge, the Turkish version controls inside Turkey — and assuming the two are interchangeable is the most common and most expensive mistake foreign businesses make.

The headline: Complying with the GDPR does not automatically make you compliant with KVKK. Treat them as two overlapping obligations, and build to the stricter standard in each area where they differ.

Where KVKK and GDPR Line Up

Start with the good news, because it is substantial. If your organisation is GDPR-mature, large parts of your framework will translate directly.

Both are rights-based regimes

KVKK, like the GDPR, treats data protection as a fundamental right of the individual rather than a mere compliance formality. In Turkey that right is anchored in the Constitution and given detail by Law No. 6698. Individuals (in KVKK language, the ilgili kişi — the "data subject" or "relevant person") hold enforceable rights: to learn whether their data is processed, to request information, to seek correction or erasure, and to object. These mirror the GDPR's data subject rights closely enough that a GDPR rights-handling process is a strong starting point.

The controller / processor model is the same

KVKK uses the same two-actor structure you know from the GDPR:

  • Data controller (veri sorumlusu) — the party that determines the purposes and means of processing. This is the GDPR "controller."
  • Data processor (veri işleyen) — the party that processes data on the controller's behalf and under its instruction. This is the GDPR "processor."

Allocating roles, papering processor relationships, and pinning down who is accountable for what all work the way your GDPR programme already does.

The core principles overlap

Both laws require that personal data be processed lawfully and fairly, for specified and legitimate purposes, kept accurate and up to date, limited to what is necessary, and retained no longer than needed. A GDPR data-protection-by-design mindset maps cleanly onto KVKK's principles. The destination is similar; it is the route and the paperwork that differ.

Where KVKK and GDPR Diverge — The Parts That Catch Foreign Companies

This is the section that matters. The similarities are comforting; the differences are where compliance fails. The table below is a high-level map, and the subsections that follow explain the four divergences that most often trip up foreign companies.

IssueGDPR (EU)KVKK (Turkey, Law No. 6698)
Lawful basesSix bases, including a flexible legitimate-interests groundExplicit consent plus a defined list of statutory exceptions; historically more consent-centric
RegistrationNo central registry of controllersVERBİS — a mandatory data controllers' registry for those over the thresholds
Designated officerData Protection Officer (DPO) mandate in defined casesNo DPO mandate in the GDPR sense; a registry "contact person" (irtibat kişisi) instead
Cross-border transfersAdequacy / safeguards / derogationsReformed in 2024 (Law No. 7499) into a tiered model with new instruments
PenaltiesEU-wide framework tied to global turnoverTurkish-lira administrative fines, re-indexed annually

1. The explicit-consent legacy

The most important cultural difference is how each law thinks about lawful basis. The GDPR deliberately offers six bases and lets you choose the most appropriate one; in practice many EU controllers rely on contract, legal obligation, or legitimate interests, keeping consent as a last resort.

KVKK grew up the other way around. For years it was read as explicit-consent-centric: explicit consent (açık rıza) sat at the centre, with a defined list of statutory exceptions around it, and the room to lean on something resembling the GDPR's "legitimate interests" was narrower. The 2024 reform moved KVKK closer to the GDPR's approach to lawful bases, but the wording is its own, and the practical habits of Turkish regulators and counterparties still reflect that consent-first history.

Practical trap: A processing activity you comfortably run on "legitimate interests" under the GDPR may not rest on the equivalent footing under KVKK. Re-map your lawful basis for each activity against Article 5 of Law No. 6698 rather than assuming your GDPR basis carries over.

2. VERBİS — a registry with no GDPR equivalent

There is no GDPR analogue to VERBİS (the Veri Sorumluları Sicili, the Data Controllers' Registry). The GDPR scrapped general notification-to-the-regulator years ago; Turkey kept a registry. Many data controllers operating in Turkey must enrol in VERBİS and keep their entry current.

Whether your organisation is obliged to register depends on thresholds set by the Board — typically tied to factors such as employee numbers and annual financial figures, with sector-specific exemptions. Because those thresholds are set qualitatively here and change over time, you should confirm your specific position rather than assume you fall in or out. A foreign company that is fully GDPR-compliant can still be in breach in Turkey purely for never having registered.

3. No DPO mandate — but a "contact person"

The GDPR requires a Data Protection Officer (DPO) in defined situations — an independent role with statutory tasks and protections. KVKK has no DPO mandate in that sense.

What KVKK requires instead, for controllers registered in VERBİS, is a contact person (irtibat kişisi). This is a narrower role: a liaison point between the company and the Authority, not an independent supervisor of the company's processing. Foreign controllers established outside Turkey may also need to designate a representative in Turkey. The practical point: do not assume your existing DPO satisfies KVKK, and do not assume a VERBİS contact person discharges your GDPR DPO duties. They are different roles solving different problems.

Tip: A group caught by both regimes can end up needing all of these at once — a GDPR DPO (where required), a VERBİS contact person in Turkey, and possibly a Turkish representative. They are not substitutes for one another.

4. Cross-border transfers — overhauled in 2024

This is the area where the two regimes have moved closest and yet where foreign companies most often breach KVKK. It deserves its own section, below.

The 2024 Reform and Cross-Border Transfers

On 12 March 2024, Law No. 7499 amended KVKK and, together with the implementing regulation that followed, replaced Turkey's old, heavily consent-based model for sending personal data abroad with a tiered framework that tracks the structure GDPR users already recognise.

At a high level, personal data may now leave Turkey through one of three routes:

  1. An adequacy decision — transfer to a country, sector, or international organisation the Board has formally recognised as providing adequate protection.
  2. Appropriate safeguards — where there is no adequacy decision, transfer based on instruments such as the Board's standard contractual clauses (SCCs), binding corporate rules (BCRs) for intra-group flows, or an approved undertaking.
  3. Exceptional cases — limited, occasional transfers resting on explicit consent or specific statutory grounds.

If you know GDPR Chapter V, this shape will feel familiar. But the instruments are Turkish: the Board's SCCs are not the EU Commission's SCCs, the Turkish text governs, and there are procedural steps — including a notification to the Authority within a set short period after signing the Board's SCCs — that have no GDPR equivalent.

Verify before you move data: The transitional arrangements, deadlines, the precise filing window, and the catalogue of approved instruments are detailed and have changed since 2024. Do not rely on a remembered figure — confirm the current mechanism and timing for your specific transfer before you act.

The two-direction problem

There is also a structural asymmetry GDPR-mature groups must plan for. Because the EU has not issued an adequacy decision recognising Turkey, data flowing into Turkey from the EU still needs its own GDPR safeguards (typically the EU Commission's SCCs put in place by the EU sender) — entirely separate from the Turkish instruments needed for data flowing out of Turkey. Many groups therefore run two parallel sets of transfer contracts.

Direction of dataGoverning regimeWhat you generally need
Leaving Turkey (to the EU or elsewhere)KVKK (Law No. 6698, as reformed)A Turkish transfer mechanism — e.g. the Board's SCCs (Turkish text) or BCRs, plus any required filing
Entering Turkey from the EUGDPRA GDPR safeguard (e.g. EU Commission SCCs) put in place by the EU sender

For the agreements that sit behind these flows, this overlaps with how we handle data-processing agreements and contractual clauses.

A Practical Mapping Exercise for GDPR-Mature Companies

Rather than rebuilding from scratch, treat KVKK readiness as a gap analysis against your existing GDPR programme. A defensible approach usually runs as follows:

  • Re-map lawful bases. Take each processing activity and check its basis against Article 5 of Law No. 6698 — do not assume your GDPR basis (especially legitimate interests) transfers.
  • Check VERBİS. Determine whether you meet the registration thresholds, register if so, appoint a contact person, and keep the entry current.
  • Localise your notices. KVKK requires its own clarification text (aydınlatma metni) and, where relied on, explicit consent forms — these are not the same documents as your GDPR privacy notice.
  • Rebuild transfers. Identify every flow that leaves Turkey, select a current 2024-regime mechanism, and complete any required filing; separately confirm the GDPR safeguards for flows into Turkey.
  • Sort out roles. Confirm whether you need a GDPR DPO, a VERBİS contact person, a Turkish representative — or some combination.
  • Align incident response. Both regimes require breach notification; build one procedure that satisfies the stricter of the two timelines (confirm the current Turkish requirement) and run it under realistic time pressure.
The law: The governing instrument in Turkey is the Personal Data Protection Law No. 6698 (Kişisel Verilerin Korunması Kanunu), as amended by Law No. 7499 of 2024. GDPR compliance is evidence of good data hygiene, but it is not a defence to a KVKK breach.

Penalties: Two Regimes, Two Separate Exposures

Non-compliance is assessed under each regime independently, and the two can bite at once.

Under KVKK, the Authority's Board can impose administrative fines — for example for security failures, registration failures, or breaches of its decisions — alongside corrective orders. These fines are set in Turkish lira and re-indexed each year, so any specific figure dates quickly; confirm the current bands before relying on them. Serious unlawful processing can additionally engage criminal provisions of the Turkish Penal Code (Law No. 5237).

Under the GDPR, EU supervisory authorities can impose their own fines and enforcement measures, and data subjects may bring civil claims. For an international group, the real danger is parallel exposure: a single misconfigured transfer or one missing notice can trigger consequences in Turkey and in the EU simultaneously.

Watch the figures: KVKK fine bands change every January and GDPR enforcement evolves. Treat any number you have seen quoted as a starting point to verify, not a fixed fact — and build your programme so that one operational slip does not cascade into double enforcement.

Data protection rarely sits alone. If you are setting up a foreign-owned company in Turkey, it is far cheaper to bake KVKK in from day one than to retrofit it; and in a deal it forms part of data-protection due diligence. For a structured KVKK-versus-GDPR gap review, speak with our Istanbul team.

Frequently asked questions

Does GDPR compliance mean my company is KVKK compliant?

No. KVKK (Law No. 6698) and the GDPR share the same architecture — both are rights-based and use the controller/processor model — but they are separate laws. KVKK has its own registration step (VERBİS), its own transfer rules (reformed in 2024 by Law No. 7499), its own lawful-basis wording, and its own Turkish-lira penalties. A fully GDPR-compliant company can still breach KVKK, for example by never registering with VERBİS. Treat KVKK readiness as a gap analysis against your GDPR programme, not a copy of it.

What is the main structural difference between KVKK and GDPR?

At the structural level they are very similar: both treat data protection as a fundamental right, both use the data controller (veri sorumlusu) / data processor (veri işleyen) split, and both share the same core processing principles. The practical differences are KVKK's historically explicit-consent-centric approach to lawful basis, the VERBİS registry (which has no GDPR equivalent), the absence of a Data Protection Officer mandate in the GDPR sense, and the 2024 overhaul of cross-border transfer rules.

What is VERBİS and does the GDPR have an equivalent?

VERBİS (the Veri Sorumluları Sicili, or Data Controllers' Registry) is a Turkish registry that many data controllers must enrol in and keep current. The GDPR has no equivalent — it abolished general notification to regulators. Whether your company must register depends on thresholds set by the Board, typically tied to factors such as employee numbers and annual financial figures, with some exemptions, so you should confirm your specific position rather than assume.

Does KVKK require a Data Protection Officer like the GDPR?

Not in the GDPR sense. KVKK does not impose a Data Protection Officer mandate. Instead, controllers registered in VERBİS must appoint a contact person (irtibat kişisi), which is a narrower liaison role with the Authority, not an independent supervisory officer. Foreign controllers may also need a representative in Turkey. A GDPR DPO and a VERBİS contact person are different roles and are not substitutes for each other.

How did the 2024 reform change cross-border data transfers from Turkey?

Law No. 7499 of 2024, with its implementing regulation, replaced the old, heavily consent-based model with a tiered framework: adequacy decisions, appropriate safeguards (such as the Board's standard contractual clauses or binding corporate rules), and limited exceptional cases. The structure resembles GDPR Chapter V, but the instruments are Turkish, the Turkish text governs, and there are procedural steps with no GDPR equivalent. Because deadlines and filing windows are detailed and have changed, confirm the current mechanism for your specific transfer before moving any data.

Can I transfer personal data from the EU into my Turkish company?

That direction is governed by the GDPR, not KVKK. Because the EU has not issued an adequacy decision for Turkey, transfers from the EU into Turkey generally need their own GDPR safeguards — commonly the EU Commission's standard contractual clauses, put in place by the EU sender. This is separate from the Turkish mechanism you need for data leaving Turkey, which is why many groups run two parallel sets of transfer contracts.

Need a lawyer for this?We handle data protection (kvkk) for foreigners, end to end, in English, on a fixed fee.
Data Protection (KVKK)

Related articles

GDPR and Turkish Companies: Navigating ComplianceTurkey's Cybersecurity Law No. 7545: Scope & Principles
Let's begin

Speak to a Turkish lawyer who speaks your language.

Tell us your commercial, corporate or personal matter and get a clear, fixed-fee answer from a real Turkish lawyer — usually within one business day.

★★★★★ 4.9 from 60 Google reviews · Recognised on Mondaq, Clutch & Trustpilot
WhatsApp us
A real lawyer replies — usually within a day
WhatsAppEmailBook a consultation