Since 1 September 2024, a Turkish company that sends personal data to a cloud provider, a group company or a SaaS vendor outside Türkiye needs one of the safeguards in Article 9 of the Personal Data Protection Law No. 6698 (KVKK). For almost every startup that safeguard is the standard contract: one of four fixed texts published by the Personal Data Protection Board, signed without alteration by the exporter and the importer, and, this is the step that gets missed, notified to the Authority within five business days of signature. Missing the notification is an independent offence with a 2026 fine range of TRY 90,308 to TRY 1,806,177, whatever the quality of the underlying contract. This article is the operational walk-through: which of the four texts to pick, how to fill it, who files, how and by when, and what to do about the contracts you signed but never notified. It is the practical companion to our KVKK standard contracts vs EU SCCs reference.
Where the standard contract sits in Article 9
Law No. 7499 rewrote Article 9 with effect from 1 June 2024. The new structure has three tiers. First, transfers to a country, sector or international organisation covered by an adequacy decision of the Board (Article 9(1)–(3)); the Authority’s own transfer page still records that the Board has made no such determination for any country. Second, in the absence of adequacy, transfers based on one of the appropriate safeguards in Article 9(4): an inter-authority agreement approved by the Board, Board-approved binding corporate rules, the Board’s standard contract, or a written undertaking approved by the Board. Third, incidental transfers under the derogations in Article 9(6), including explicit consent given after the data subject is informed of the risks. The old regime, in which explicit consent was the everyday basis for transfers, ended with the transitional period on 1 September 2024. For a company with a recurring transfer to a processor or a group affiliate, the standard contract is the only safeguard that does not require the Board’s prior approval, which is why it is the default.
Choosing among the four texts
The Board adopted the four standard contract texts by its decision of 4 June 2024 (No. 2024/959), one for each combination of roles: controller to controller, controller to processor, processor to processor, and processor to controller. The choice is dictated by the roles in the specific flow, not by the size or type of the parties. A Turkish SaaS company using a US hosting provider for customer data is a controller sending to a processor: text 2. A Turkish subsidiary sharing HR data with its parent for group reporting is controller to controller: text 1. A Turkish processor that subcontracts to a foreign sub-processor is processor to processor: text 3. The fourth text covers the less common case of a Turkish processor returning or sending data to a foreign controller, for example a Turkish development shop processing for a European client. Getting the role wrong is not a formality: the obligations in the text differ, and a controller-to-processor contract used for what is in substance a controller-to-controller flow leaves the importer’s independent obligations unaddressed.
Filling in the text without breaking it
The Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad (Official Gazette 10 July 2024, No. 32598) is explicit that the standard contract text must be used without any change; where it is also concluded in a foreign language, the Turkish text prevails. The parties’ room is confined to the annexes and the blanks: identification of the parties and of any sub-processors, data categories and data subject categories, purposes of the transfer, the technical and organisational measures the importer will apply, and the additional measures for special categories of data. Two habits from the GDPR world cause trouble here. Do not attach a master services agreement clause that “amends” the standard contract; the amendment is void and can be read as altering the text. And do not leave the annex on security measures generic: the Board expects measures that match the data actually transferred.
Filing: five business days, by whom, how
Article 9(5) of the Law says the standard contract is notified to the Authority by the controller or the processor within five business days of signature. The clock starts when the last signature is put on the document, not when the transfer starts, and Saturday and Sunday and public holidays are not counted. Article 14(5) of the Regulation lets the parties designate in the contract which of them will notify; if they do not, the data exporter must. In practice that is the Turkish party, and the Law treats controller and processor alike: a Turkish processor exporting under text 3 or 4 files its own notification. The notification must attach proof of the signatories’ authority and notarised Turkish translations of any foreign-language documents (Article 14(6)), and later changes to the parties or the annexes, and termination, must also be notified (Article 14(8)). Filing is done through the Authority’s online standard-contract portal (standartsozlesme.kvkk.gov.tr), which records the date of submission; keep the receipt in the transfer file alongside the signed contract, because the receipt is what an inspector will ask for first.
Under Article 18(1)(d), added by Law No. 7499, failing to make the notification is punishable with an administrative fine that in 2026 runs from TRY 90,308 to TRY 1,806,177 after the annual revaluation, and Article 18(2) makes clear that the fine can be imposed on processors as well as controllers, on both natural persons and private-law legal entities. Board decisions can be challenged before the administrative courts (Article 18(3)).
What if you signed but never filed?
A standard contract that was signed in, say, October 2024 and never notified is still a contract, and the transfer it covers may still be lawful between the parties, but the notification breach has already occurred. There is no statutory cure period. The sensible course is to file now, with the actual signature date, rather than to re-sign with today’s date to manufacture a fresh five-day window: the re-signing route creates a false record and leaves the original breach in place. Late filing does not erase the offence, but a self-initiated correction, documented in the file, is the strongest mitigation the company will have if the Board ever asks. The same logic applies to contracts that were amended in the annexes after filing: notify the amended version.
Running this as a process, not a project
The companies that get this right treat the standard contract as an onboarding step for every foreign vendor and every intra-group flow. The vendor questionnaire asks for role, location and sub-processors; the procurement checklist requires the correct text to be signed before data moves; the five-day filing is a calendar task owned by a named person, usually whoever maintains the VERBİS record and the processing inventory; and the transfer register lists every contract with its signature date, filing date and portal receipt number. When a flow changes, for instance a vendor adds a sub-processor in a new country, the annex is updated and re-filed. This is also the register that EU customers will ask to see when they run their own transfer impact assessments, so the same file serves two audiences.
Do we need a standard contract for data going to the EU?
Yes. Adequacy under Article 9 is decided by the Turkish Board, and no adequacy decision has been published for the EU or for any other jurisdiction. Until one is, a transfer from Türkiye to an EU processor needs a standard contract like any other transfer abroad.
Our US vendor refuses to sign a Turkish-law contract. What now?
The standard contract is the only Board-approved safeguard available without prior approval, and it cannot be altered. If the vendor will not sign, the alternatives are a Board-approved undertaking (which takes time), Board-approved binding corporate rules (only within a group), or restructuring the flow so that no personal data leaves Türkiye. “We signed the EU SCCs instead” is not a safeguard under Article 9.
Does the notification make the contract public?
No. The notification is a filing with the Authority, not a public register. Commercially sensitive annexes are disclosed to the Authority only.
Related: cross-border data transfer · data processor · model APIs and cross-border personal data.
Sources. Personal Data Protection Law No. 6698 (Articles 9 and 18, as amended by Law No. 7499); Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad (Official Gazette 10 July 2024, No. 32598); Personal Data Protection Authority, Standard Contracts (the four texts; Board decision of 4 June 2024, No. 2024/959); KVKK standard contract notification portal. 2026 fine amounts reflect the 25.49% revaluation rate for 2026 (Official Gazette 27 November 2025). Statute links open the official Turkish texts on mevzuat.gov.tr.
This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro callMore from Vircon Insights
The First 90 Days of Your US Company: EIN, Bank Account and Tax Calendar
September 11, 2026Closing a Venture Round: Step by Step from Signing to Money in the Bank
September 1, 2026The Family Member on the Payroll: Employment Contract, Arm’s-Length Pay and Disguised Profit Distribution
August 31, 2026The AI Vendor Contract: 12 Clauses That Decide Who Pays When the Model Fails
August 14, 2026Training Data and KVKK: Anonymization, Pseudonymization, and the "It Was Public" Myth
August 13, 2026Getting the IP Out of Founders' and Employees' Heads and Into the Company
September 22, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →US Company Formations & Flip-Ups
Delaware C-Corp, flip-up structures, SAFE/convertible notes, 83(b).
View service →