Jump to

The Data Processing Agreement Under KVKK: How It Differs from GDPR Article 28 and What to Put in the Annexes

The Data Processing Agreement Under KVKK: How It Differs from GDPR Article 28 and What to Put in the Annexes

Every SaaS vendor, payroll bureau, cloud host and analytics tool that touches your customers’ or employees’ personal data on your instructions is a data processor, and under Turkish law you answer for what it does. Article 12(2) of the Personal Data Protection Law No. 6698 (KVKK) makes the controller jointly responsible with the processor for the security measures the Law requires, and the Board’s enforcement record shows that when a processor is breached, the controller is fined. Unlike Article 28 of the GDPR, the KVKK does not list what the contract with a processor must contain; it does not even require a written contract in express terms. That absence is not a licence to skip the document. It means the Turkish data processing agreement (DPA) has to be built from the controller’s own obligations, the Authority’s guidance and the practical need to prove, after an incident, who was supposed to do what. This article sets out what the KVKK does say, how the Turkish DPA differs from the GDPR Article 28 template most vendors send, what to put in the annexes, and how the DPA connects to the standard contract for transfers abroad.

What the KVKK actually says about processors

The Law defines the processor as the natural or legal person who processes personal data on behalf of the controller, on the basis of the controller’s authorisation (Article 3(1)(ğ)). Four consequences follow from the text. First, the controller must take every technical and organisational measure necessary to prevent unlawful processing and access and to preserve the data (Article 12(1)), and where processing is done on its behalf by another person, the controller is jointly responsible with that person for taking those measures (Article 12(2)). Second, controllers and processors alike may not disclose personal data contrary to the Law or use it outside the purpose of processing, and this duty survives the end of their role (Article 12(4)). Third, the controller must carry out or commission the audits necessary to ensure the Law is applied within its own organisation (Article 12(3)); the Authority reads this as including audits of processors. Fourth, when data is obtained unlawfully by others, the controller notifies the data subjects and the Board as soon as possible (Article 12(5)), which in practice means within the 72 hours set by the Board’s 2019 decision; the processor’s contractual duty to tell the controller fast is what makes that deadline achievable. Processors do not register in VERBİS and have no independent notification duty to the Board for breaches; everything runs through the controller.

The Authority’s Personal Data Security Guide lists, among the administrative measures a controller is expected to take, that relationships with processors be governed by written contracts containing data-security provisions, and the Board’s published decisions on service-provider breaches consistently examine whether such a contract existed and what it said. The DPA is therefore not a statutory form but the controller’s principal evidence of due diligence.

How the Turkish DPA differs from GDPR Article 28

The GDPR template that most international vendors attach was written for Article 28(3), which prescribes the content: processing only on documented instructions, confidentiality of personnel, Article 32 security, sub-processor conditions, assistance with data-subject rights and impact assessments, deletion or return at the end, and audit rights. Turkish companies can use that structure, and should, because it maps onto the KVKK obligations well, but four adjustments are needed. The transfer clause must refer to Article 9 of the KVKK and the Board’s standard contracts, not to the EU SCCs; a vendor that processes outside Türkiye needs the KVKK standard contract signed and notified within five business days in addition to the DPA. The breach-notification clause must be timed to the controller’s Turkish deadline, so a processor commitment of “without undue delay” should become a fixed number of hours, 24 or 48, with a defined content. The security annex should reference the measures in the Authority’s Security Guide, which Turkish inspectors use as a checklist, rather than only ISO 27001 or SOC 2 language. And the governing law and dispute clause should not push a Turkish controller into a foreign forum for a dispute about Turkish-law liability: the controller’s fine is imposed in Ankara, and its recourse claim against the processor should be litigable in Türkiye or in arbitration.

The clauses that carry the weight

Instructions: the processor acts only on the controller’s documented instructions and tells the controller if an instruction would breach the Law; the DPA itself and the service description are the standing instruction. Purpose limitation: no use of the data for the processor’s own purposes, including training of AI models, a point Turkish controllers now negotiate explicitly, as we discussed in the AI vendor clauses playbook. Confidentiality: personnel bound by written confidentiality undertakings, with the Article 12(4) survival built in. Security: a concrete annex, not a promise of “appropriate measures”. Sub-processors: prior written authorisation, general or specific, a current list, notice of changes with a right to object, and flow-down of the same obligations, so that the chain of joint responsibility under Article 12(2) is paper-backed at each link. Assistance: help with data-subject requests within the 30-day statutory response period, and with the controller’s breach notification. Audit: a right to audit, exercisable through documentation and certifications in the ordinary course and by on-site or third-party inspection after an incident or on reasonable notice. Return and deletion: at termination, with a certificate, subject only to retention the Law itself requires, and consistent with the Regulation on the deletion, destruction and anonymisation of personal data. Liability: an indemnity for administrative fines, data-subject claims and remediation costs caused by the processor’s breach, with any cap set by reference to the real exposure rather than to twelve months’ fees.

Annexes: where DPAs succeed or fail

A Turkish DPA needs three annexes and they must be filled in, not templated. The processing annex describes the data categories, data-subject categories, purposes, duration and the locations of processing, in the same vocabulary the controller uses in its VERBİS record and processing inventory, so that the two documents reconcile. The security annex lists the technical and administrative measures actually deployed, ideally in the order of the Authority’s Security Guide, with the processor’s certifications attached. The sub-processor annex names each sub-processor, its role, its location and the transfer safeguard relied on. When the same vendor is also the importer under a KVKK standard contract, the annexes to the two documents must match; a discrepancy between the data categories in the DPA and in the notified standard contract is the kind of detail an inspector picks up first.

Processor-to-processor and the controller who is also a processor

A Turkish SaaS company is usually a controller for its own employees and marketing data and a processor for its customers’ data. It therefore needs two documents facing in opposite directions: a DPA it imposes on its vendors and a DPA it offers to its customers, and the two must be consistent, because the customer-facing DPA’s promises are only deliverable if the vendor-facing DPA secures them. When the SaaS company engages a sub-processor abroad, it is the processor in a processor-to-processor transfer and signs the Board’s third standard contract; when it returns data to a foreign customer that is the controller, it signs the fourth. Our five-business-day filing guide covers the mechanics.

A vendor onboarding routine

Classify the vendor’s role before signing anything: processor, independent controller or joint controller, since only processors get a DPA. Require the DPA as a condition of go-live, not as an afterthought to the commercial agreement, and attach it to the master agreement so that termination of one terminates the other. Check the vendor’s location and sub-processor list for transfers abroad and start the standard-contract clock at signature. Record the vendor, the DPA date, the transfer safeguard and the security annex version in the processing inventory. Review annually and whenever the vendor changes sub-processors. The companies that pass Turkish breach investigations are not the ones with the best vendors; they are the ones with the best files.

Is a DPA needed for a vendor that only hosts encrypted data it cannot read?

Yes. Storage is processing under Article 3, and the host’s access to ciphertext and metadata is enough to make it a processor. The DPA can be short, but the security annex and breach clause still matter.

Can the processor refuse to sign because it “only accepts its own DPA”?

It can, and large vendors do. Use the vendor’s paper if it covers the clauses above, and add a Turkish addendum for the transfer safeguard, the breach timing and the Security Guide reference. What you cannot accept is a vendor DPA that disclaims processor status altogether.

Does the DPA need to be filed with the Authority?

No. Only the standard contract for transfers abroad is notified under Article 9(5). The DPA is an internal contract that the Authority may ask to see during an investigation.

Related: data processor · sub-processor · SaaS vendor management.

Sources. Personal Data Protection Law No. 6698 (Articles 3, 9, 12); Personal Data Protection Authority, Standard Contracts; Personal Data Protection Authority, Personal Data Security Guide (Technical and Administrative Measures); Regulation (EU) 2016/679 (GDPR), Article 28. Statute links open the official Turkish texts on mevzuat.gov.tr.

This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo

    View all posts
Considering a similar matter?See how we work on KVKK and GDPR compliance, or book a call directly.
Book a call →
Published: 2 October 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.