REFERENCE

KVKK Standard Contracts and EU SCCs: The Cross-Border Transfer Document Set

Since 1 June 2024 Türkiye has run a three-tier transfer regime that mirrors the GDPR: an adequacy decision first, appropriate safeguards second, and narrow exceptions last. The workhorse safeguard is the standard contract, published by the Personal Data Protection Authority in four versions, which must be filed with the Authority within five business days of signature (Law No. 6698, Art. 9/5). A Turkish startup selling into Europe usually needs both sets: the KVKK standard contract for data leaving Türkiye, and the European Commission’s SCCs for data leaving the EEA, often for the same vendor. This page puts the official texts side by side and links every primary source.

What changed and when. Law No. 7499 rewrote Article 9 of the KVKK with effect from 1 June 2024; the implementing Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad was published in the Official Gazette No. 32598 on 10 July 2024, and the Authority published the four standard contracts alongside it. Explicit consent stopped being a stand-alone transfer basis after the transitional period ended on 1 September 2024. In the EU, the current SCCs are Commission Implementing Decision (EU) 2021/914 of 4 June 2021, which replaced the 2001, 2004 and 2010 sets.

Side by side

QuestionKVKK standard contracts (Türkiye)EU SCCs (Decision 2021/914)
VersionsFour separate documents: controller→controller, controller→processor, processor→processor, processor→controller.One document with four modules covering the same four relationships; parties select the module.
Can the text be changed?No additions, deletions or amendments; only the annexes are completed (Art. 2 of each contract). Any change turns it into a bespoke undertaking that needs Board authorisation instead.Clauses may not be modified except to select modules and options and to complete the annexes; parties may add clauses that do not contradict the SCCs (Clause 2).
Filing with the regulatorMandatory: notify the Authority within five business days of signature through the online notification module. Changes to sub-processors or onward recipients listed in the annexes are notified too.None. The SCCs are self-executing; supervisory authorities may ask to see them.
Multi-party useBilateral in design; group structures typically sign several contracts or use binding corporate rules.Optional docking clause (Clause 7) lets new parties accede later.
Risk assessment of the destinationNot a separate formal step in the contract; the exporter warrants the importer’s ability to comply and the importer must notify if local law prevents compliance.Transfer impact assessment is built in (Clause 14) and detailed in EDPB Recommendations 01/2020.
Data subjects’ positionThird-party beneficiary rights against exporter and importer (Art. 3 of each contract), with listed exceptions.Third-party beneficiary rights (Clause 3), with listed exceptions.
Governing law and forumTurkish law; disputes with data subjects are heard in Türkiye.Law of an EU Member State that allows third-party beneficiary rights (Clause 17); courts of an EU Member State (Clause 18).
Alternatives at the same tierBinding corporate rules (Board approval), agreements between public bodies, written undertakings with Board permission.BCRs, approved codes of conduct, certification mechanisms, ad hoc clauses with authority approval (GDPR Art. 46).
Adequacy tierBoard adequacy decisions for countries, sectors or international organisations (Art. 9/2). Check the Authority’s published list before relying on this tier; in practice the standard contract carries most transfers.Commission adequacy decisions for a limited list of jurisdictions, including the EU-US Data Privacy Framework (Decision 2023/1795).

Turkish documents

EU documents

⚠ Two exports, two documents

A Turkish company using a US-hosted service exports data from Türkiye, so it needs the KVKK standard contract and the five-day filing, regardless of whether the vendor already offers EU SCCs. A Turkish company processing EU customers’ data is itself the third-country importer under the GDPR and will be asked to sign the EU SCCs as data importer. Read our guide on sending personal data to model APIs for the practical sequence, and the KVKK + GDPR Compliance Checklist for the wider programme.

Primary sources: Law No. 6698 (KVKK), Art. 9; Regulation on the Transfer of Personal Data Abroad (Official Gazette No. 32598, 10 July 2024), via the Authority’s regulations page; Regulation (EU) 2016/679, Arts. 44–49. Documents belong to the Personal Data Protection Authority and the European Commission and are linked for reference only.

Considering a similar matter?Talk to counsel that moves at the speed of your round.
Book a call →