Data Protection

Lawful Processing of Personal Data Under KVKK: The Legal Bases

If your company processes personal data connected to Türkiye, every processing activity must rest on a lawful basis set out in the Turkish Data Protection Law (Kişisel Verilerin Korunması Kanunu No. 6698, or "KVKKKVKKPersonal Data Protection Law No. 6698Türkiye's data protection statute — the rules on collecting, storing and transferring personal data, and the authority that enforces them.Glossary →"). For ordinary personal data, that means either the explicit consent of the person (açık rıza) or one of the alternative legal grounds listed in Article 5/2 — such as a legal obligation, performance of a contract, or your legitimate interest. Special categories of personal data (özel nitelikli kişisel veri) follow a stricter regime in Article 6, which was significantly broadened by Law No. 7499 in 2024. This guide explains each basis in plain terms so you can map your data flows to a defensible legal footing.

What "lawful processing" means under KVKK

Under the Turkish Data Protection Law (Kişisel Verilerin Korunması Kanunu No. 6698), you may not process personal data unless you have a lawful basis for doing so. "Processing" is defined very broadly — collecting, recording, storing, organising, transferring, disclosing, or even deleting data all count. So the question is not whether you process personal data; if you handle any information about an identified or identifiable person, you do. The real question is which legal ground supports each activity.

Two roles matter here. The data controller (veri sorumlusu) is the party that decides why and how data is processed — usually your company. The data processor (veri işleyen) processes data on the controller's behalf, under its instructions, such as a cloud host or payroll vendor. The duty to identify a lawful basis sits with the controller.

The structure of the law. Article 4 sets out the general principles every processing activity must respect. Article 5 governs the legal bases for ordinary personal data. Article 6 sets a stricter regime for special categories of personal data. You read these together: a valid basis under Article 5 or 6 is necessary, but you must also comply with the Article 4 principles.

The Article 4 principles that apply to every basis

Before you reach the legal bases, Article 4 imposes principles that bind all processing, whatever ground you rely on. Choosing a lawful basis does not excuse you from these. In plain terms, your processing must be:

  • Lawful and fair (hukuka ve dürüstlük kurallarına uygun). You process honestly, within the law, and in a way the person would reasonably expect.
  • Accurate and, where necessary, kept up to date. You take reasonable steps to correct wrong data.
  • Processed for specified, explicit and legitimate purposes (purpose limitation). You decide the purpose before you collect, and you do not quietly repurpose the data later.
  • Relevant, limited and proportionate to the purpose (data minimisation). You collect only what you actually need — not "everything, just in case."
  • Retained only as long as required (storage limitation). When the legal or business reason ends, you delete, destroy or anonymise the data.

A useful test: if you cannot explain, in one sentence, why you hold a particular field of data and how long you will keep it, that field probably fails Article 4 — regardless of which legal basis you wrote down.

The first basis people think of is explicit consent (açık rıza). Under KVKK, valid explicit consent must be (1) tied to a specific subject, (2) based on adequate information given beforehand, and (3) freely given. A pre-ticked box, a blanket "I accept everything" clause, or consent buried in unrelated terms will generally not qualify.

Two features of consent make it fragile as a basis for routine business processing:

  • It can be withdrawn. The person may take their consent back, and once they do, your lawful ground for that activity falls away. If you were relying solely on consent, you must stop.
  • It cannot be a condition of service where the processing is not genuinely necessary for that service. Consent that the person had no real choice but to give is not "freely given," and so is not valid.

For this reason, controllers usually reserve consent for processing that has no other home — for example, optional marketing — and look first to the alternative grounds in Article 5/2 for the processing they must do to run the relationship.

Do not stack consent on top of another valid basis "to be safe." If you tell a person their data is processed on the basis of consent and they withdraw it, you may have to stop even though a contractual or legal-obligation ground existed. Pick the basis that genuinely fits, and rely on that one.

The alternative legal bases in Article 5/2

Article 5/2 lets you process ordinary personal data without consent when one of its listed conditions applies. These are the workhorses of day-to-day compliance. In plain terms, you may process personal data where:

  • It is expressly provided for by law. A statute directly authorises or requires the processing.
  • It is necessary to protect the life or bodily integrity of a person who cannot give consent (for example, because of physical incapacity) or whose consent is not legally valid.
  • It is necessary for the performance of a contract — directly related to establishing or performing a contract with the person. Processing a customer's address to deliver an order is a classic example.
  • It is necessary for the controller to comply with a legal obligation. Tax, employment, and bookkeeping duties commonly fall here.
  • The data has been made public by the person themselves. You may process it consistently with the purpose of that disclosure.
  • It is necessary for the establishment, exercise or protection of a legal claim. For instance, retaining records to defend a future dispute.
  • It is necessary for the legitimate interests of the controller (meşru menfaat), provided this does not harm the fundamental rights and freedoms of the person.

The last ground — legitimate interest — is flexible but requires a real balancing exercise. You must weigh your business interest against the person's rights and expectations, and document why your interest does not override them. It is not a catch-all; it is a justified, recorded judgment.

Map each processing activity to one specific Article 5/2 ground, not several at once. "Sending the invoice" is contract necessity or legal obligation; "keeping a fraud-prevention log" is more likely legitimate interest. Clear mapping is what you will show if the authority asks.

Special-category data (Article 6) after Law No. 7499 (2024)

Special categories of personal data (özel nitelikli kişisel veri) are treated more strictly because misuse causes greater harm. Under KVKK, these include data on health and sexual life, racial or ethnic origin, political opinion, philosophical belief, religion or sect, appearance, association/foundation/union membership, criminal convictions and security measures, and biometric and genetic data.

The regime for this data changed materially with Law No. 7499 of 2024, which amended Article 6. Before the amendment, processing special-category data without explicit consent was possible only in narrow, category-specific situations. The amendment broadened the alternative legal grounds so that special-category data can now be processed without explicit consent in a wider set of defined circumstances — for example, where a law expressly permits it, to protect life or bodily integrity where consent cannot be obtained, in relation to data the person has made public, for the establishment or protection of legal claims, and for certain employment, public-health, and similar purposes set out in the article — each subject to its own conditions and, in some cases, to safeguards the Personal Data Protection Board may set.

Even after the 2024 broadening, Article 6 remains stricter than Article 5. The available grounds are narrower, several come with extra safeguards, and the Board may require additional adequate measures for processing special-category data. Treat any health, biometric, or belief-related data as high-risk and confirm the specific ground before you process it.

Because the amended text, its effective date, and the exact list of permitted grounds are detailed and were recently reformed, you should verify the current wording of Article 6 against the consolidated statute for your specific use case rather than relying on a general summary.

Practical steps for a foreign company processing Türkiye-linked data

If your company is established abroad but processes personal data connected to people or operations in Türkiye, the KVKK can still apply to you, and the duty to establish a lawful basis is the same. A workable approach:

  • Inventory your processing. List each activity — onboarding, payroll, marketing, support, analytics — and the data it touches.
  • Assign one legal basis per activity. For most operational processing, look to Article 5/2 (contract necessity, legal obligation, legitimate interest) before consent.
  • Flag special-category data separately. Any health, biometric, or belief-related field needs an Article 6 ground and, often, extra safeguards.
  • Honour Article 4 throughout. Minimise what you collect, fix retention periods, and write down your purposes.
  • Check transfers and registration duties. Cross-border transfer rules and any registration with the data controllers' registry (VERBİS) carry their own conditions and thresholds — these are technical and have been reformed, so confirm what currently applies to you.

The burden of demonstrating lawfulness sits with you as controller. "We had consent somewhere" is rarely enough. A short written record — activity, legal basis, purpose, retention period — is the practical difference between a defensible position and an exposed one.

Frequently asked questions

Do we always need consent to process personal data under KVKK?

No. Explicit consent (açık rıza) is only one of the lawful bases. For ordinary personal data, Article 5/2 of KVKK No. 6698 provides alternative grounds — such as legal obligation, performance of a contract, and the controller's legitimate interest — that let you process without consent when the conditions are met. For much routine business processing, these alternatives are a stronger footing than consent, which can be withdrawn.

What counts as special-category personal data in Türkiye?

Under KVKK, special categories (özel nitelikli kişisel veri) include data on health and sexual life, race or ethnic origin, political opinion, philosophical belief, religion or sect, appearance, membership of associations/foundations/unions, criminal convictions and security measures, and biometric and genetic data. This data follows the stricter Article 6 regime and generally requires extra care and safeguards.

What did Law No. 7499 change about special-category data in 2024?

Law No. 7499 amended Article 6 of KVKK to broaden the legal grounds for processing special-category data. Previously, processing such data without explicit consent was permitted only in narrow situations. The amendment added a wider set of defined conditions under which special-category data can be processed without explicit consent, each with its own requirements. Because the wording and effective date were recently reformed, the exact current grounds should be verified against the consolidated statute.

Can we rely on legitimate interest to process data in Türkiye?

Yes, for ordinary personal data, Article 5/2 of KVKK recognises the controller's legitimate interest (meşru menfaat) as a lawful basis — but only where processing does not harm the person's fundamental rights and freedoms. This requires a documented balancing exercise weighing your interest against the individual's rights and reasonable expectations. It is not a catch-all, and it does not apply to special-category data, which is governed by Article 6.

Does KVKK apply to a foreign company with no office in Türkiye?

It can. KVKK obligations may reach foreign controllers that process personal data connected to people or activities in Türkiye. If KVKK applies to your processing, you must establish a lawful basis under Article 5 or 6, comply with the Article 4 principles, and observe transfer and registration rules. Whether and how the law applies to your specific structure is a fact-specific question worth confirming with Turkish counsel.

Need a lawyer for this?We handle data protection (kvkk) for foreigners, end to end, in English, on a fixed fee.
Data Protection (KVKK)

Related articles

GDPR and Turkish Companies: Navigating ComplianceTurkey's Cybersecurity Law No. 7545: Scope & Principles
Let's begin

Speak to a Turkish lawyer who speaks your language.

Tell us your commercial, corporate or personal matter and get a clear, fixed-fee answer from a real Turkish lawyer — usually within one business day.

★★★★★ 4.9 from 60 Google reviews · Recognised on Mondaq, Clutch & Trustpilot
WhatsApp us
A real lawyer replies — usually within a day
WhatsAppEmailBook a consultation