Skip to main content

> kvkk_kanun_no._6698

KVKK Kanun No. 6698

Law on Protection of Personal Data (KVKK Law No. 6698)

SPEC // INSPECT: KVKK Kanun No. 6698REVIEWED: 2026-09-16
CATEGORY
JURISDICTIONTURKIYE
REGULATORY AUTHORITYKişisel Verileri Koruma Kurumu (KVKK)
LIFECYCLE STATUSCURRENT
EXECUTIVE BRIEF SPECIFICATION PDFDISTRIBUTION LOCKED
Fail-Closed Distribution Policy: Download control is visibly disabled until Cloudflare R2 CDN upload and remote SHA-256 verification complete.
[AI // ARCHITECTURAL SUMMARY]

KVKK (Law No. 6698) governs the processing, retention, and transfer of personal and special category data in Türkiye. Heavily inspired by EU Directive 95/46/EC and updated with modern GDPR-like cross-border transfer mechanisms (standard contractual clauses and binding corporate rules), it mandates VERBİS registration, explicit consent, technical and administrative security measures, and strict 72-hour breach reporting to the KVKK Board.

Scope & Applicability

All natural and legal persons processing personal data of individuals residing in Türkiye, including domestic enterprises and foreign cloud service providers targeting Turkish citizens.

Non-Coverage Boundaries

Does not cover purely personal data processing within the scope of personal domestic activities, or data processed exclusively for national defense, security, and intelligence purposes under statutory exemptions.

Key Clauses & Control Requirements

kvkk-madde-10

Article 10: Obligation to Inform (Aydınlatma Yükümlülüğü)

Mandatory presentation of data processing identity, purpose, recipients, method, legal basis, and individual rights under Article 11 before collecting personal data.

kvkk-madde-12

Article 12: Data Security Obligations (Teknik ve İdari Tedbirler)

Enforcing technical measures (encryption, masking, access control, DLP) and administrative measures (policies, NDAs, audits) to prevent unlawful processing and access.

kvkk-madde-9

Article 9: Cross-Border Transfers (Yurtdışına Aktarım)

Post-reform transfer mechanisms aligning with European adequacy, Standard Contractual Clauses (Standart Sözleşme), and explicit authorization.

[AUDIT // VERIFIABLE EVIDENCE CHECKLIST]

Required Regulatory & Audit Evidence Artifacts

  • [✓]VERBİS (Data Controllers Registry) filing confirmation and registered processing categories
  • [✓]Personal Data Processing Inventory (Kişisel Veri İşleme Envanteri) with retention schedules
  • [✓]Technical and Administrative Measures Audit Report based on the KVKK Security Guide
  • [✓]Standard Contractual Clause (SCC) notification filed with the KVKK Board for cloud SaaS tools
[LEADERSHIP TAKEAWAY // CTO & VP OF ENGINEERING DIRECTIVE]
KVKK compliance cannot be achieved by publishing a privacy policy on your website. Without an active data processing inventory, VERBİS synchronization, and verified cross-border cloud transfer contracts, organizations face multi-million TL administrative fines.
PRIMARY SOURCES & AUTHORITY

Frequently Asked Questions

What is the notification period for a data breach under KVKK?

The data controller must notify the KVKK Board within 72 hours of becoming aware of a personal data breach, and notify the affected data subjects as soon as reasonably practicable.