> kvkk_kanun_no._6698
KVKK Kanun No. 6698
Law on Protection of Personal Data (KVKK Law No. 6698)
KVKK (Law No. 6698) governs the processing, retention, and transfer of personal and special category data in Türkiye. Heavily inspired by EU Directive 95/46/EC and updated with modern GDPR-like cross-border transfer mechanisms (standard contractual clauses and binding corporate rules), it mandates VERBİS registration, explicit consent, technical and administrative security measures, and strict 72-hour breach reporting to the KVKK Board.
Scope & Applicability
All natural and legal persons processing personal data of individuals residing in Türkiye, including domestic enterprises and foreign cloud service providers targeting Turkish citizens.
Non-Coverage Boundaries
Does not cover purely personal data processing within the scope of personal domestic activities, or data processed exclusively for national defense, security, and intelligence purposes under statutory exemptions.
Key Clauses & Control Requirements
Article 10: Obligation to Inform (Aydınlatma Yükümlülüğü)
Mandatory presentation of data processing identity, purpose, recipients, method, legal basis, and individual rights under Article 11 before collecting personal data.
Article 12: Data Security Obligations (Teknik ve İdari Tedbirler)
Enforcing technical measures (encryption, masking, access control, DLP) and administrative measures (policies, NDAs, audits) to prevent unlawful processing and access.
Article 9: Cross-Border Transfers (Yurtdışına Aktarım)
Post-reform transfer mechanisms aligning with European adequacy, Standard Contractual Clauses (Standart Sözleşme), and explicit authorization.
Required Regulatory & Audit Evidence Artifacts
- [✓]VERBİS (Data Controllers Registry) filing confirmation and registered processing categories
- [✓]Personal Data Processing Inventory (Kişisel Veri İşleme Envanteri) with retention schedules
- [✓]Technical and Administrative Measures Audit Report based on the KVKK Security Guide
- [✓]Standard Contractual Clause (SCC) notification filed with the KVKK Board for cloud SaaS tools
“KVKK compliance cannot be achieved by publishing a privacy policy on your website. Without an active data processing inventory, VERBİS synchronization, and verified cross-border cloud transfer contracts, organizations face multi-million TL administrative fines.”
Cross-Surface Ecosystem Relationships
- 6698 Sayılı Kişisel Verilerin Korunması Kanunu ↗(Kişisel Verileri Koruma Kurumu)
Frequently Asked Questions
What is the notification period for a data breach under KVKK?
The data controller must notify the KVKK Board within 72 hours of becoming aware of a personal data breach, and notify the affected data subjects as soon as reasonably practicable.
