KVKK Standard Contracts and EU SCCs: The Cross-Border Transfer Document Set
Since 1 June 2024 Türkiye has run a three-tier transfer regime that mirrors the GDPR: an adequacy decision first, appropriate safeguards second, and narrow exceptions last. The workhorse safeguard is the standard contract, published by the Personal Data Protection Authority in four versions, which must be filed with the Authority within five business days of signature (Law No. 6698, Art. 9/5). A Turkish startup selling into Europe usually needs both sets: the KVKK standard contract for data leaving Türkiye, and the European Commission’s SCCs for data leaving the EEA, often for the same vendor. This page puts the official texts side by side and links every primary source.
Side by side
| Question | KVKK standard contracts (Türkiye) | EU SCCs (Decision 2021/914) |
|---|---|---|
| Versions | Four separate documents: controller→controller, controller→processor, processor→processor, processor→controller. | One document with four modules covering the same four relationships; parties select the module. |
| Can the text be changed? | No additions, deletions or amendments; only the annexes are completed (Art. 2 of each contract). Any change turns it into a bespoke undertaking that needs Board authorisation instead. | Clauses may not be modified except to select modules and options and to complete the annexes; parties may add clauses that do not contradict the SCCs (Clause 2). |
| Filing with the regulator | Mandatory: notify the Authority within five business days of signature through the online notification module. Changes to sub-processors or onward recipients listed in the annexes are notified too. | None. The SCCs are self-executing; supervisory authorities may ask to see them. |
| Multi-party use | Bilateral in design; group structures typically sign several contracts or use binding corporate rules. | Optional docking clause (Clause 7) lets new parties accede later. |
| Risk assessment of the destination | Not a separate formal step in the contract; the exporter warrants the importer’s ability to comply and the importer must notify if local law prevents compliance. | Transfer impact assessment is built in (Clause 14) and detailed in EDPB Recommendations 01/2020. |
| Data subjects’ position | Third-party beneficiary rights against exporter and importer (Art. 3 of each contract), with listed exceptions. | Third-party beneficiary rights (Clause 3), with listed exceptions. |
| Governing law and forum | Turkish law; disputes with data subjects are heard in Türkiye. | Law of an EU Member State that allows third-party beneficiary rights (Clause 17); courts of an EU Member State (Clause 18). |
| Alternatives at the same tier | Binding corporate rules (Board approval), agreements between public bodies, written undertakings with Board permission. | BCRs, approved codes of conduct, certification mechanisms, ad hoc clauses with authority approval (GDPR Art. 46). |
| Adequacy tier | Board adequacy decisions for countries, sectors or international organisations (Art. 9/2). Check the Authority’s published list before relying on this tier; in practice the standard contract carries most transfers. | Commission adequacy decisions for a limited list of jurisdictions, including the EU-US Data Privacy Framework (Decision 2023/1795). |
Turkish documents
Standard Contract 1: Controller to Controller
For transfers to a foreign company that will decide purposes and means itself: a group parent, a joint-venture partner, a buyer in an M&A data room.
Standard Contract 2: Controller to Processor
The one most startups sign: cloud hosting, CRM, analytics, payroll and model-API vendors outside Türkiye. Annex III lists sub-processors and must be kept current with the Authority.
Standard Contract 3: Processor to Processor
For a Turkish processor passing its client’s data to its own foreign sub-processor. The Turkish SaaS vendor’s document when the customer’s data leaves the country downstream.
Standard Contract 4: Processor to Controller
For a Turkish processor returning or sending data to a foreign controller, typically a Turkish service provider working for a foreign client.
Standard Contract Notification Module
Where the signed contract is filed within five business days. Filing is the exporter’s or the processor’s obligation and a common audit finding when missed.
KVKK: Transfers Abroad
The Authority’s explanatory page on the three-tier regime, the appropriate safeguards and the exceptions, with links to the Regulation on the Authority’s legislation pages.
EU documents
Commission Implementing Decision (EU) 2021/914
The SCCs for transfers to third countries under GDPR Art. 46(2)(c), with the four modules, the docking clause and the transfer impact assessment clause. The legally binding text.
European Commission SCC page
Editable versions of the clauses and the Commission’s questions and answers on choosing modules and completing annexes.
Commission Implementing Decision (EU) 2021/915
The other set of standard clauses: the controller-processor terms under GDPR Art. 28(7) for processors inside the EEA. Not a transfer tool, but often confused with the SCCs.
EDPB Recommendations 01/2020
The six-step method for the transfer impact assessment and the supplementary measures that make SCCs work in practice after Schrems II.
EU adequacy decisions
The countries that need no SCCs at all for EEA exports. Türkiye is not on the list, which is why EU customers ask Turkish vendors for SCCs.
EU-US Data Privacy Framework (Decision 2023/1795)
The adequacy decision for certified US companies. Relevant when your EU-origin data goes to a US model or cloud provider; irrelevant for Turkish-origin data, which still needs the KVKK standard contract.
A Turkish company using a US-hosted service exports data from Türkiye, so it needs the KVKK standard contract and the five-day filing, regardless of whether the vendor already offers EU SCCs. A Turkish company processing EU customers’ data is itself the third-country importer under the GDPR and will be asked to sign the EU SCCs as data importer. Read our guide on sending personal data to model APIs for the practical sequence, and the KVKK + GDPR Compliance Checklist for the wider programme.
Primary sources: Law No. 6698 (KVKK), Art. 9; Regulation on the Transfer of Personal Data Abroad (Official Gazette No. 32598, 10 July 2024), via the Authority’s regulations page; Regulation (EU) 2016/679, Arts. 44–49. Documents belong to the Personal Data Protection Authority and the European Commission and are linked for reference only.