Skip to content
GlanceDeskJurisdiction

Home › Law library › Turkey KVKK

TR

Turkey KVKK

Law No. 6698 on the Protection of Personal Data (as amended by Law No. 7499, 2024)

Sourced. Last verified 9 October 2026

Türkiye Privacy

Status
In force since 7 April 2016; 2024 amendments in force 1 June 2024 (new transfer regime fully from 1 Sep 2024).
Who it applies to
Anyone processing personal data of people in Türkiye, including foreign controllers processing Turkish-originated data.
Size thresholds
None for the law itself. VERBIS registry exemption: under 50 staff and under TRY 100m balance sheet (if sensitive data is the main activity: under 10 staff and TRY 10m, per Board decision of 1 Oct 2025).
Regulator
Personal Data Protection Authority (KVKK) and its Board
Breach or incident reporting
Notify the Board within 72 hours of learning of the breach (Board decision 2019/10), using the breach form; notify affected individuals as soon as reasonably possible (directly, or via website notice).
Deadline to answer personal data requests
As soon as possible and at the latest within 30 days, free of charge (Board tariff fee only if extra cost).
Data protection officer
No DPO required; registered controllers must appoint a contact person for communications with the Authority.
Local representative
Foreign controllers must appoint a data controller representative in Türkiye (Turkish legal entity or resident) and register in VERBIS.
Sending data abroad
Since 1 Sep 2024: adequacy decision by the Board, or appropriate safeguards (Board standard contract, BCRs, written undertaking), or incidental-only derogations. Standard contracts must be notified to the Authority within 5 business days.
Cookies and consent
No cookie-specific statute; general KVKK rules apply and the Authority has published a Guide on Cookie Practices (consent expected for non-essential cookies).
Maximum penalty
2026 administrative fines up to TRY 17,092,242 per violation (data security, VERBIS, non-compliance with Board decisions); amounts revalued every year.

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

Law 7499 (OG 12 Mar 2024) widened legal bases for sensitive data and replaced consent-based transfers with adequacy/safeguards/derogations (from 1 Sep 2024). Board narrowed VERBIS exemption for sensitive-data processors (OG 1 Oct 2025).

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].