🔐 KVKK and Data Protection Law

KVKK compliance processes, privacy notices and explicit consent texts, data-breach management, and data-subject applications.

Today, the lawful collection, processing, storage, transfer and protection of personal data is an important area of legal obligation for companies, public institutions, employers, e-commerce businesses, healthcare institutions and all other natural and legal persons that process data.

The relevant legislation, first and foremost Law No. 6698 on the Protection of Personal Data (KVKK), imposes various obligations relating to the processing of personal data. The General Data Protection Regulation (GDPR), applicable within the European Union, may also be particularly important in data processing activities connected with persons resident in the European Union or with activities in the EU market.

The unlawful processing or failure to protect personal data may give rise to administrative sanctions, as well as compensation for material and non-pecuniary damage, loss of reputation, and various legal disputes.

Our firm provides legal consultancy and attorney services in the fields of KVKK compliance processes, data processing inventories, privacy notices, explicit consent texts, personal data processing policies, data controller and data processor relationships, VERBIS processes, personal data breaches, data-subject applications, special categories of personal data, employee data, commercial electronic communication processes, data transfer, and GDPR compliance.

Why Is the Protection of Personal Data Important?

Personal data may cover any information relating to an identified or identifiable natural person. Full name, contact information, identity information, customer information, employee records, camera footage, IP addresses, location data and many similar pieces of information may qualify as personal data. When processing personal data, companies must pay attention not only to the data-collection stage, but also to the purpose for which the data is processed, the legal basis for processing, how long the data is retained, with whom it is shared, whether it is transferred abroad, how data security is ensured, and the processes relating to the rights of data subjects.

What Is the KVKK?

Law No. 6698 on the Protection of Personal Data is the principal legislation that aims to protect individuals' fundamental rights and freedoms during the processing of personal data, and to establish the principles that must be observed by natural and legal persons who process data. Under the KVKK, data controllers and data processors are subject to various obligations, such as processing personal data lawfully, the obligation to inform, ensuring data security, responding to data-subject applications, retaining personal data for the necessary period, not keeping unnecessary data, and carrying out data transfers lawfully.

Our KVKK Compliance Services

1. KVKK Compliance Consultancy

For a company's personal data processing activities to be brought into compliance with the KVKK, its existing practices must be legally reviewed. As part of KVKK compliance work, data processing procedures, data categories, purposes of processing, conditions for processing, data transfer processes, retention and destruction practices, and technical and administrative measures are examined, and a compliance plan specific to the business may be developed.

2. Personal Data Processing Inventory

A personal data processing inventory is an important compliance tool that shows which personal data an organization collects, for what purposes, on what legal basis, from whom, by what methods, and to whom it transfers such data. Within the scope of the inventory, data categories, data subjects, processing purposes, legal grounds for processing, data transfers, retention periods and data processing activities may be determined.

3. VERBIS Consultancy

The Data Controllers' Registry Information System (VERBIS), established by the Personal Data Protection Authority, is the system through which the registration obligation is fulfilled by data controllers meeting certain conditions. Whether a registration obligation exists with respect to VERBIS, whether an exemption applies, the information that must be notified, data categories, processing purposes, transfer information and retention periods are assessed and the necessary legal process may be carried out.

4. Preparation of Privacy Notices

Informing data subjects during the processing of personal data is an important obligation under the KVKK. Depending on the business's field of activity, different notices may need to be prepared, such as an employee privacy notice, a customer privacy notice, a visitor privacy notice, a website privacy notice, a privacy notice relating to camera footage, and a job-application privacy notice. It is important that privacy notices reflect the actual data processing activities.

5. Explicit Consent Texts

Not every personal data processing activity needs to be based on explicit consent. It must first be assessed which of the legal grounds for processing specified in the KVKK may apply to the processing of personal data. Where explicit consent is required, it is important that the consent is obtained in compliance with the conditions that it relate to a specific matter, be based on information, and be given freely.

6. Personal Data Processing Policies

In order to systematize their personal data processing activities, companies may need to establish various policies and procedures, such as a personal data processing policy, a retention and destruction policy, a data-breach response procedure, an employee data security procedure, an access authorization procedure, and a data transfer procedure.

7. Retention, Erasure, Destruction and Anonymization of Personal Data

Retaining personal data for an indefinite period is not, as a rule, an appropriate approach. It must be determined for what purpose the data is retained, what the retention period is, whether a mandatory retention period is provided under the relevant legislation, and what will be done once the retention period ends. For data whose retention period has ended and for which no other legal ground exists, processes such as erasure (making the personal data inaccessible and unusable by the relevant users), destruction (making the data inaccessible, unrecoverable and unusable by anyone in any way), or anonymization (rendering the data incapable of being associated with an identified or identifiable natural person even when matched with other data) may come into question.

8. Special Categories of Personal Data

Special categories of personal data refer to data groups that require a higher level of protection. Race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, dress and appearance, membership of an association, foundation or trade union, health, sexual life, criminal conviction and security measures, and biometric and genetic data may be assessed within this scope. Stricter legal conditions apply to the processing of special categories of personal data.

9. Protection of Employees' Personal Data and the KVKK in Recruitment Processes

Employers may process a large number of personal data relating to their employees, such as identity information, contact information, personnel information, salary and payment information, leave records, performance information, camera footage, entry-exit records and health information. In processing employee data, a balance must be maintained between the employer's legitimate interests and the employee's fundamental rights and freedoms. With respect to the CVs, contact and education information received from candidates during job applications, the KVKK compliance of practices such as the retention of CVs, the sharing of candidate information, reference checks, recruitment tests, video interviews, and the processing of special categories of data must also be assessed.

10. Camera Footage, Websites and Cookies

As camera footage used for security purposes in workplaces, stores, sites, offices and other areas may qualify as personal data, matters such as the purpose of using cameras, the retention period of the footage, access authorizations, with whom the footage may be shared, and the obligation to inform must be assessed. KVKK compliance must also be ensured with respect to cookies, IP addresses, contact forms, membership information, analytics tools, advertising technologies and marketing activities relating to users' personal data and online activity through websites. The type of cookies used on websites, their purpose of use, retention period and relationship with third parties must be determined, and users must be properly informed.

11. Transfer of Personal Data Abroad

The transfer of personal data to persons or organizations located abroad is a matter that must be separately assessed under the KVKK. In particular, when using cloud services, software based abroad, email services, CRM systems, servers, and social media and advertising platforms, it is important to determine whether personal data is being transferred abroad. The legal mechanism to be applied to cross-border data transfers must be determined according to the current legislation.

12. Data Controller and Data Processor Relationships and Data Processing Agreements

It is important to correctly determine the concepts of data controller and data processor under the KVKK. A business may be regarded as a data controller if it processes personal data by determining its own purposes and means; service providers that process data on behalf of, and in accordance with the instructions of, another organization may be in the position of a data processor. This distinction is important with respect to liability, contracts, data security, data transfer and audit. Where companies outsource services such as accounting, human resources, cloud services, call centers, courier companies and technical service, it is important for the parties' responsibilities to be clearly set out in contracts.

13. Personal Data Breaches and the Response Process

The unlawful acquisition, loss, unauthorized access, or misdirection of personal data to the wrong recipients may give rise to a data security breach. Cyberattacks, ransomware, misdirected emails, loss of a computer or phone, unauthorized access, database leaks, and data transfers caused by employees may qualify as a data breach. When a data breach occurs, companies must act quickly not only with respect to technical security measures but also their legal obligations; processes that may need to be carried out include detecting the breach, determining its scope, identifying the affected data, conducting a risk assessment, assessing whether notification to the relevant authorities and data subjects is required, and determining measures to prevent recurrence of the breach.

14. Data-Subject Applications

Natural persons whose personal data is processed have rights under the KVKK, such as learning whether their personal data is being processed, requesting information about the data processed, learning the purpose of processing, learning the third parties to whom the data is transferred, requesting the correction of incomplete or inaccurate data, and, where the statutory conditions are met, requesting the erasure or destruction of the data. When such applications are made to a company, it is necessary to assess who made the application, which data it concerns, the legal basis of the request, and whether the company processes the relevant data, and to prepare a response that complies with the legislation within the procedure and time limits provided by law.

15. Personal Data Protection Board Processes and Administrative Sanctions

In processes before the Personal Data Protection Authority and the Personal Data Protection Board, it is important for a company's legal position to be correctly established. Our firm can provide legal support with respect to reviewing Board decisions, applications made to the Authority, responses to Board examinations, data-breach notifications, data-subject complaints, and legal assessments relating to administrative sanctions. Various administrative sanctions may arise in the event of non-compliance with the obligations provided under the KVKK; the amount and scope of the applicable sanction must be assessed according to the nature of the violation and the legislation in force at the relevant date.

16. GDPR and International Data Protection Law

Certain companies operating in Turkey may also process the data of natural persons located in the European Union. In such cases, whether the provisions of the GDPR apply must be separately assessed according to the specific features of the case. GDPR compliance may come into question, in particular, with respect to sales into the European Union, customers in Europe, employees abroad, business relationships with EU-based companies, digital services, and international data transfers.

17. Data Protection in Corporate Mergers and Acquisitions and E-Commerce

In corporate mergers and acquisitions, customer, employee and supplier data may be transferred to the new company; in these processes, the legal basis for the data transfer, the change of data controller, data security, retention periods, cross-border transfer and contracts must be separately assessed for KVKK compliance. E-commerce businesses may also need a comprehensive KVKK compliance process with respect to customer records, order information, address information, payment information, cookies, marketing data, membership systems and shipping processes.

18. Marketing and Commercial Electronic Communications

In marketing activities carried out through SMS, email and other electronic means of communication, not only the KVKK but also the legislation on commercial electronic communications must be taken into account. The necessary legal conditions for sending commercial communications to customers by SMS, email, phone call or notification must be separately assessed.

19. Mobile Applications, Artificial Intelligence and Data Governance

Mobile applications may process various data relating to users, such as location, device information, IP address, usage habits and contact information; the data collected by an application and the purposes for which it is used must be legally assessed. With the growing use of artificial intelligence systems, the transfer and processing of personal data within AI systems also gives rise to new legal risks; it is particularly important to assess data protection legislation with respect to training data, user and employee data, automated decision-making, profiling, data security and third-party AI services. For businesses, data protection compliance is not a one-off document-drafting exercise; an effective compliance process generally consists of stages such as mapping the data, identifying data processing activities, analyzing the legal grounds, identifying risks, preparing the necessary policies and texts, arranging contracts, assessing technical and administrative measures, informing employees, establishing data-breach procedures, and regularly updating the processes.

Our KVKK Compliance Process

Our firm can carry out a comprehensive KVKK compliance project tailored to the company's field of activity: through a current-state analysis, the company's personal data processing activities and existing documents are examined; through data mapping, which personal data is collected, from whom, by what methods and for what purposes is determined; through an analysis of the legal grounds, the legal grounds for processing applicable to each data processing activity are assessed; at the documentation stage, privacy notices, explicit consent texts, policies, procedures and contracts are prepared, or existing documents are revised; within the scope of data security, the legal requirements of technical and administrative measures are assessed; whether a registration obligation exists with respect to VERBIS is assessed and the necessary processes are carried out; employees may be given legal awareness training on the protection of personal data; and the compliance process is continuously updated in line with the legislation, Board decisions and changes in the company's data processing activities.

Our Legal Approach in KVKK and Data Protection Law

  • Data Identification: The personal data processed by the company is identified.
  • Legal-Grounds Analysis: The appropriate legal basis for each data processing activity is assessed.
  • Risk Analysis: Risks relating to the unlawful processing of personal data or breaches of its security are identified.
  • Documentation: Privacy notices, policies, contracts and procedures are prepared.
  • Data Security: The legal requirements for technical and administrative measures are assessed.
  • Breach Management: The legal process to be applied in the event of data security breaches is determined.
  • Board and Application Processes: Data-subject applications and, where necessary, Authority/Board processes are conducted.

Frequently Asked Questions

What is personal data under the KVKK?

Personal data is any information relating to an identified or identifiable natural person. Name, surname, phone number, email address, identity information, camera footage and certain online data may qualify as personal data.

Is explicit consent required for every item of personal data?

No. There is more than one legal ground for processing personal data under the KVKK. Whether explicit consent is required must be assessed according to the specific data processing activity.

Are a privacy notice and explicit consent the same thing?

No. The obligation to inform and explicit consent are different legal concepts. Informing refers to notifying the data subject about the processing of their personal data, while explicit consent refers to consent relating to a specific data processing activity.

What should I do to make my company KVKK-compliant?

First, it must be determined which personal data the company processes. Then, by examining the purposes of processing, the legal grounds, transfer processes and retention periods, the necessary policies, contracts, privacy notices and procedures must be prepared.

Is registration with VERBIS mandatory?

The registration obligation under VERBIS is not the same for every data controller. The registration obligation and exemptions must be assessed within the framework of the relevant legislation and Board decisions.

What happens in the event of a KVKK violation?

Depending on the nature of the violation, administrative sanctions and other legal consequences may arise. In addition, the person whose personal data has been violated may also have legal claims for compensation of material or non-pecuniary damage.

What should we do if we experience a data breach?

First, the scope and nature of the breach must be determined, the affected data identified, and a risk assessment carried out. It must then be assessed, under the relevant legislation, whether notification to the Authority and, where necessary, to the data subjects is required.

Is using camera footage contrary to the KVKK?

Using camera footage is not, by itself, contrary to the KVKK. However, the purpose of using the camera system, proportionality, informing data subjects, the retention period, access and other legal conditions must comply with the legislation.

Does the GDPR concern companies in Turkey?

In some cases, yes. Where a company located in Turkey processes the data of persons in the European Union, or carries out activities that fall within the scope of the GDPR, whether the GDPR applies must be assessed on the basis of the specific case.

Consultation with a KVKK and Data Protection Law Attorney

It is important to obtain professional legal support to start the KVKK compliance process for a company that processes personal data, to audit its existing practices from a legal standpoint, to respond to a data breach, or to assess data-subject applications. If you need legal support regarding KVKK compliance consultancy, VERBIS, the personal data processing inventory, privacy notices, explicit consent processes, employee data, camera footage, cookies, e-commerce, data transfer, data breaches, special categories of personal data, data-subject applications, Personal Data Protection Board processes or GDPR, you may contact us so that your company's data processing processes can be assessed.