Home › Law library › Turkey KVKK
TR
Turkey KVKK
Law No. 6698 on the Protection of Personal Data (as amended by Law No. 7499, 2024)
Sourced. Last verified 9 October 2026
Türkiye Privacy
- Status
- In force since 7 April 2016; 2024 amendments in force 1 June 2024 (new transfer regime fully from 1 Sep 2024).
- Who it applies to
- Anyone processing personal data of people in Türkiye, including foreign controllers processing Turkish-originated data.
- Size thresholds
- None for the law itself. VERBIS registry exemption: under 50 staff and under TRY 100m balance sheet (if sensitive data is the main activity: under 10 staff and TRY 10m, per Board decision of 1 Oct 2025).
- Regulator
- Personal Data Protection Authority (KVKK) and its Board
- Breach or incident reporting
- Notify the Board within 72 hours of learning of the breach (Board decision 2019/10), using the breach form; notify affected individuals as soon as reasonably possible (directly, or via website notice).
- Deadline to answer personal data requests
- As soon as possible and at the latest within 30 days, free of charge (Board tariff fee only if extra cost).
- Data protection officer
- No DPO required; registered controllers must appoint a contact person for communications with the Authority.
- Local representative
- Foreign controllers must appoint a data controller representative in Türkiye (Turkish legal entity or resident) and register in VERBIS.
- Sending data abroad
- Since 1 Sep 2024: adequacy decision by the Board, or appropriate safeguards (Board standard contract, BCRs, written undertaking), or incidental-only derogations. Standard contracts must be notified to the Authority within 5 business days.
- Cookies and consent
- No cookie-specific statute; general KVKK rules apply and the Authority has published a Guide on Cookie Practices (consent expected for non-essential cookies).
- Maximum penalty
- 2026 administrative fines up to TRY 17,092,242 per violation (data security, VERBIS, non-compliance with Board decisions); amounts revalued every year.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Register in VERBIS unless an exemption applies; foreign controllers appoint a Turkish representative.
- Give a privacy (aydınlatma) notice when collecting data.
- Use the Board's standard contract for transfers abroad and notify it within 5 business days.
- Report breaches to the Board within 72 hours.
- Answer data subject applications within 30 days.
Recent changes
Law 7499 (OG 12 Mar 2024) widened legal bases for sensitive data and replaced consent-based transfers with adequacy/safeguards/derogations (from 1 Sep 2024). Board narrowed VERBIS exemption for sensitive-data processors (OG 1 Oct 2025).
Sources
- Primary source: https://prighter.com/resources/laws/turkish-kvkk/the-personal-data-protection-law/articles/article-13
- Second source: https://mondaq.com/turkey/data-protection/1442172/recent-amendments-to-the-law-on-the-protection-of-personal-data
- Regulator: Personal Data Protection Authority (KVKK) and its Board
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].