Data Protection

Responding to Data Subject Requests Under Turkey's KVKK

If your company processes personal data connected to Türkiye, individuals can ask you what you hold about them and demand that you act on it. Under Turkey's Personal Data Protection Law (Kişisel Verilerin Korunması Kanunu No. 6698, "KVKKKVKKPersonal Data Protection Law No. 6698Türkiye's data protection statute — the rules on collecting, storing and transferring personal data, and the authority that enforces them.Glossary →"), Article 11 gives every data subject (ilgili kişi) a set of rights — to learn whether their data is processed, to request information and copies, and to ask for correction, deletion, or to object — and Article 13 obliges you, as the data controller (veri sorumlusu), to receive their application and answer it within the period the law sets. This guide explains the process your company must run, the deadline you must meet, and what happens if the person escalates to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu).

What rights does a data subject have under KVKK Article 11?

Article 11 of Law No. 6698 lists the rights an individual can exercise against you. In plain terms, any person whose data you process can ask you to:

  • Confirm whether you process their data at all — a simple yes or no.
  • Request information about that processing if it exists, including the purpose and whether the data is used in line with that purpose.
  • Learn the recipients — to whom the data has been transferred, inside Türkiye or abroad.
  • Ask for rectification if the data is incomplete or inaccurate, and ask you to notify any third parties to whom you sent it.
  • Ask for erasure or destruction where the legal grounds for processing have disappeared, again with notification to recipients.
  • Object to a result produced solely by automated analysis that works against them.
  • Claim compensation for damage caused by unlawful processing (this part runs through the courts, not your internal desk).

The term "data subject" (ilgili kişi) simply means the living individual the data is about — a customer, an employee, a website visitor, a job applicant. These rights belong to the person, not to your company, and you cannot contract them away.

How an application reaches you under Article 13

Article 13 sets out the channel. The data subject makes a written application to the data controller — that is, to your company — or uses another method that the Board has approved for registered controllers. You cannot insist that the request take a particular form if the law and Board guidance allow others; what matters is that you can identify the person and understand what they want.

Your first job is verification. Before you reveal any personal data, confirm that the applicant is who they say they are. Handing someone else's data to an impostor is itself a breach. Keep your identity check proportionate — enough to be confident, not so heavy that you obstruct a genuine request.

Build the intake before the request arrives. Decide in advance: which inbox or address receives applications, who owns the file, how you verify identity, and where you record the clock starting. A request you cannot find is a request you will answer late.

Note that Article 13 directs the application to the controller first. A data subject normally cannot go straight to the Board without giving you the chance to respond. That makes your internal process the front line of compliance.

The response deadline — answer within the statutory period

This is the part companies most often get wrong. Article 13 requires you to conclude the request as soon as possible and, at the latest, within 30 days, free of charge in principle. If the response requires a separate cost, a tariff set by the Board may allow a fee.

The law: KVKK Article 13 requires the controller to conclude a data subject's application at the latest within 30 days of receiving it, free of charge in principle (the Board may set a fee tariff where the reply carries a genuine cost). The clock starts when a valid application reaches you.

"Conclude" means give a real answer — accept the request and act on it, or refuse it with reasons. Silence is not an option. If you reject, you must explain the legal basis for the refusal in writing. A late, vague, or unexplained answer is treated much like no answer at all and exposes you to a complaint.

Practical tip: log the date the valid application reached you, calendar the deadline immediately, and aim to respond well before it. Build in time for identity checks and for pulling data from systems and vendors — those steps often eat the schedule.

How to handle each type of request in practice

The right being exercised shapes your answer:

Access and information requests

Search your systems, confirm whether you hold the person's data, and explain the purpose, the legal ground, and the recipients (domestic and cross-border). Disclose the individual's own data — but be careful not to reveal third parties' personal data in the process.

Rectification requests

Correct inaccurate or incomplete data where the request is justified, and, where Article 11 requires, notify the third parties you previously shared it with.

Erasure and destruction requests

Assess whether a lawful ground for processing still exists. If a ground remains — for example, a statutory retention duty under tax, commercial, or employment law — you may lawfully decline and must say so with reasons. If no ground remains, delete or destroy the data and notify recipients.

Governing law: the substantive rights sit in Article 11 of Law No. 6698; the application and response duty sit in Article 13. Special-category (sensitive) data and cross-border transfers are governed by separate provisions (notably Articles 6 and 9), both of which were rewritten by Law No. 7499 of 2024 — apply the current text, not older commentary.

Where a request touches sensitive data (health, biometrics, religious or political information) or asks you to confirm an overseas transfer, the analysis is more delicate after the 2024 amendments. Treat those as cases for legal review rather than a routine desk reply.

When the data subject complains to the Board

If you refuse the request, miss the deadline, or give an inadequate response, the data subject's next step is a complaint to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu). The Law expects the person to apply to you first and then escalate — typically within set time windows running from your answer (or from the point your answer was due). The Board can examine the complaint, ask you for explanations and documents, and decide whether you complied.

If the Board finds a violation, it can order you to remedy it and can impose administrative fines. The fine bands are set in the Law and updated periodically.

Do not state fine amounts, complaint time-limits, or breach-notification timing from memory. The monetary penalty ranges, the days within which a data subject may complain after your reply, and any personal-data-breach notification deadline to the Board are all specific figures in Law No. 6698 and Board decisions. Confirm each against the current sources before you cite it.

The lesson for your company is preventive: a clean, documented, on-time response is your best protection. When the Board reviews a complaint, your dated intake log, your identity-verification steps, and your written reasons are the evidence that you met your Article 13 duty.

What foreign companies should put in place

If you are based outside Türkiye but process data connected to people there, you are not outside the KVKK's reach. Build the following before a request lands:

  • A named intake channel for data subject applications, monitored on working days.
  • An identity-verification step that is firm but proportionate.
  • A deadline tracker that starts the clock on receipt and flags the statutory day-limit early.
  • Response templates for accept, partial, and refusal answers — each giving reasons.
  • A data map so you can actually find and retrieve the person's data across your systems and vendors.
  • An escalation rule sending sensitive-data and cross-border questions to legal review.

Registered controllers must also keep their broader KVKK obligations current — your privacy notices, your lawful grounds, your transfer mechanisms, and, where applicable, your registration in the controllers' registry (VERBİS). Whether your processing crosses any registration threshold, and what the current rules require after the 2024 amendments, should be checked with a Turkish data protection lawyer rather than assumed.

A short legal review of your intake workflow and templates now is far cheaper than defending a Board complaint later. Lexin Legal advises foreign companies on building and running KVKK-compliant data subject request processes.

Frequently asked questions

What is a data subject request under KVKK?

It is a request an individual (the "data subject" / ilgili kişi) makes to your company under Article 11 of Law No. 6698 — for example, to learn whether you process their data, to get information about it, or to ask you to correct, delete, or stop certain processing. Article 13 requires you, as the data controller, to receive the application and respond within the period set by the Law.

How long does a company have to respond to a KVKK request?

Article 13 requires you to conclude a valid request as soon as possible and, at the latest, within the maximum period fixed in Law No. 6698. That period is a specific number of days stated in the Law — you should confirm the current figure against the live text before relying on it, because committing to the wrong number in a policy or reply creates risk. Aim to answer well before the deadline.

Can a foreign company be subject to KVKK data subject requests?

Yes. If your company processes personal data connected to people in Türkiye, the KVKK can apply to you even if you are based abroad. You should build a documented intake, verification, and response process, and take Turkish-law advice on whether you must register and on close cases involving sensitive data or transfers.

What happens if we refuse a data subject's request?

You may refuse where the law allows — for example, where a retention duty or another lawful ground still applies — but you must respond in writing with reasons within the statutory period. If the person disagrees, they can complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), which can investigate and, on finding a violation, order remedies and impose administrative fines.

Did the 2024 KVKK amendment change how we handle requests?

Law No. 7499 of 2024 changed important parts of the regime — notably the rules on special-category (sensitive) data and on cross-border transfers under Articles 6 and 9. The core Article 11 rights and the Article 13 response duty remain, but how you assess sensitive-data and transfer questions has shifted, so treat pre-2024 guidance with caution and verify the current rules.

Can we charge a fee for answering a request?

As a rule the response is free. If concluding the request involves a separate cost, the Law allows a fee within a tariff the Board may set. Confirm the current tariff before charging, and never use a fee to discourage a legitimate request.

Need a lawyer for this?We handle data protection (kvkk) for foreigners, end to end, in English, on a fixed fee.
Data Protection (KVKK)

Related articles

GDPR and Turkish Companies: Navigating ComplianceTurkey's Cybersecurity Law No. 7545: Scope & Principles
Let's begin

Speak to a Turkish lawyer who speaks your language.

Tell us your commercial, corporate or personal matter and get a clear, fixed-fee answer from a real Turkish lawyer — usually within one business day.

★★★★★ 4.9 from 60 Google reviews · Recognised on Mondaq, Clutch & Trustpilot
WhatsApp us
A real lawyer replies — usually within a day
WhatsAppEmailBook a consultation