KVKK compliance is the gap between what your documents say and what your systems actually do. Türkiye’s data protection law applies to every company processing personal data here, the 2024 amendment rebuilt the cross-border transfer regime along GDPR lines, and the 2026 fine schedule puts the ceiling for a single security-obligation breach above ₺17 million. For technology companies selling internationally, KVKK and GDPR are not two projects — they are one programme with two notification clocks.
Who carries which obligation
The law distinguishes the data controller (decides purposes and means — your company, for your customer and employee data) from the data processor (processes on the controller’s instructions — your cloud provider, your payroll firm). Controllers carry the heavy obligations: lawful basis, notices, registry, security, and answering to the Board. You cannot outsource controllership by contract, and “the vendor handles privacy” has never survived a Board investigation.
The compliance stack, in build order
- Data inventory and ROPA. Map what you actually collect, where it flows, how long it lives. Everything else is derived from this; documentation that contradicts real data flows is worse than none.
- Lawful bases. Map each processing purpose to a statutory basis. Explicit consent is the residual basis, not the default — over-reliance on consent is the most common design error, because consent can be withdrawn and invalidates itself when bundled with service access.
- Notices and consent flows. Layered aydınlatma texts wired into the actual product surfaces — signup, forms, cookies, HR onboarding — not PDFs in a folder.
- Security measures. The Board’s published technical and administrative measures list is the de facto audit checklist: access governance, encryption, logging, penetration testing discipline, personnel confidentiality undertakings.
- Vendor management. Data processing agreements with every processor, transfer mechanisms where they are abroad, and audit rights you can actually exercise.
- Retention and destruction. A schedule, plus periodic destruction logs the Board expects to see (typically six-month cycles under the registry regime).
Cross-border transfers after the 2024 amendment
The old regime — explicit consent or rarely-granted undertakings — is gone. Transfers now ride on three mechanisms, in order of preference:
- Adequacy decisions for countries, sectors or specific controllers (the list is still short);
- Appropriate safeguards, in practice the Board’s standard contractual clauses — which must be filed with the Authority within five business days of signature. Missing that filing is itself a fineable offence (₺90,308–₺1,806,177 in 2026). Dual-language (TR/EN) execution is accepted; the clauses cannot be modified;
- Binding corporate rules for intra-group transfers, with Board approval.
Explicit consent survives only as a narrow, non-repetitive fallback. Practical consequence: every US SaaS tool in your stack — analytics, CRM, e-mail, cloud — needs a transfer leg. Transfer arrangements built on old-regime consent need re-papering; most companies we audit still have at least one forgotten tool outside the framework.
VERBİS
Registration with the Data Controllers’ Registry is mandatory above the annual employee/turnover thresholds set by the Board, for controllers whose main activity involves special-category data, and for foreign controllers processing data in Türkiye — before processing begins. VERBİS entries must match your ROPA; inconsistencies are low-hanging fruit for investigators.
What non-compliance costs in 2026
Administrative fines are revalued annually (the 2026 revaluation rate was 25.49%). Current ranges: breach of the notice obligation ₺85,437–₺1,709,200; security obligations ₺256,357–₺17,092,242; failure to comply with Board decisions ₺427,263–₺17,092,242; VERBİS violations ₺341,809–₺17,092,242; SCC filing failure ₺90,308–₺1,806,177. Beyond fines: processing bans and deletion orders that can hurt more than the cheque, published decisions (reputational cost arrives with the sanction), and criminal exposure under the Penal Code for unlawful recording or disclosure. Most investigations start with a complaint — typically an ex-employee or a customer.
The first 72 hours of a breach
Contain, preserve evidence and logs, assess scope. KVKK requires notifying the Board “as soon as possible” — interpreted as 72 hours — and affected individuals without undue delay; GDPR runs a parallel 72-hour clock to the supervisory authority where it applies. Running both tracks with consistent wording is exactly what a pre-written incident-response plan buys you.
Core concepts
- KVKK and GDPR — where the regimes differ and overlap
- Data controller vs data processor
- VERBİS — registry mechanics
- Explicit consent — and why it is the last resort
- DPO — the GDPR role and Turkish near-equivalents
Live resources
- KVKK Decision Tracker — Board decisions, categorised and searchable
Deeper reading
When you need counsel
We run KVKK programmes end to end — gap analysis, documentation wired into real data flows, SCC filings under the 2024 transfer regime, breach response, and recurring audits. See KVKK & GDPR Compliance, KVKK Audit, and the broader Privacy & Cybersecurity practice.