Jump to

The Medium-Term Programme Puts a Date on KVKK-GDPR Alignment: What Changes for Compliance Programmes Caught Between Two Laws

The Medium-Term Programme Puts a Date on KVKK-GDPR Alignment: What Changes for Compliance Programmes Caught Between Two Laws

In the years I have spent working in data protection, the hardest part of the job has never been interpreting a particular provision. The hard part has been managing two laws at once for the same company. Every business that operates in Turkey and touches a user, a customer or a group company in Europe lives at the intersection of the Personal Data Protection Law no. 6698 and the European Union’s General Data Protection Regulation. On paper that intersection looks wide, because both texts grew out of the same principles. In practice the two laws ask for different things at many points, and complying fully with one very often means moving some distance away from the other.

The Medium-Term Programme for 2027-2029, published in a supplementary issue of the Official Gazette on 6 September 2026, has now put a date on this picture. In the section devoted to the business and investment climate there is a single-sentence commitment: “The process of aligning the Personal Data Protection Law no. 6698 (KVKK) with the European Union General Data Protection Regulation (GDPR) will be completed.” In the table of regulatory measures in Annex 3 of the Programme, the entry opposite that sentence reads “Law/Administrative Regulation” and the third quarter of 2027. A footnote to the table explains what that date means: for items marked “Law”, the timetable refers to completing the technical and administrative work on the text to be placed before the Grand National Assembly. The third quarter of 2027 is therefore the date by which a draft is to be ready for Parliament, and does not have to be the date on which the law takes effect.

Two laws at the same table

A few examples show why the overlap is so tiring. In the architecture of the KVKK, explicit consent functioned for a long time as the default legal basis. The text of the law recognises legitimate interest too, but Turkish compliance culture preferred to collect consent whenever there was doubt. The GDPR, by contrast, treats consent as only one of six legal bases and requires that it be freely given and not made a condition of the service. The “get consent just in case” approach that counts as safe in Turkey can become, in a European audit, a finding that calls the validity of that consent into question. I have kept many inventories in which the Turkish column said consent and the European column said legitimate interest for the very same processing activity.

Cross-border transfers are the second example. Until 2024, a transfer to a group company in Europe under Article 9 of the KVKK had, in practice, no working route other than explicit consent. Undertakings approved by the Board remained the exception, and the list of countries offering adequate protection was never published. The same transfer had been running for years on the GDPR side under the established procedure of standard contractual clauses. Law no. 7499, published on 12 March 2024, rebuilt Article 9 around adequacy decisions, appropriate safeguards and derogations, and brought the two regimes noticeably closer. The gap has still not closed entirely. A standard contract signed in Turkey must be notified to the Authority within five business days, and there is no such notification in Europe. The same document follows two different procedures in two jurisdictions.

The list goes on. VERBİS registration has no counterpart in the GDPR. The records of processing activities under Article 30 of the GDPR and the personal data processing inventory on the KVKK side ask for the same information in different structures. The data protection officer of Article 37 of the GDPR is not a statutory requirement under the KVKK. A data protection impact assessment is mandatory for certain processing under the GDPR and is not an obligation under the KVKK. The right to data portability exists in the GDPR and is absent from Article 11 of the KVKK. Both sides work with 72 hours for breach notification, but on the KVKK side that period comes from a Board decision of 2019 rather than from the law itself. Each of these differences is manageable on its own. When all of them land on the same data controller at once, the result is a hybrid compliance programme that neither law would fully recognise as its own. That hybrid is what I have been managing for years.

What the Programme says, and what it does not

The verb in the Programme’s sentence is “will be completed”. The sentence describes alignment as work already under way that is to be finished. The amendments made by Law no. 7499, above all to Articles 6 and 9, were the first legislative step in that process. The Programme says that the legislative text and the administrative regulations that will close the remaining distance are to be prepared by the third quarter of 2027. Which provisions will change, and whether a new law or a comprehensive amendment package is coming, is not in the text. Nor is there any stated goal of obtaining an adequacy decision from the European Commission. It would be wrong to attribute those things to the Programme. My own reading is that preparing the transfer regime for such an assessment is the natural continuation of this commitment.

The placement of the item says something too. The commitment sits in the section on the business and investment climate, in the same list as the One-Stop Office, the Investment Coordination and Conciliation Board, the wider use of arbitration and the specialised courts. There is no heading devoted to fundamental rights in the Programme; the commitment is positioned as an investment-climate item. Elsewhere in the same Programme, artificial intelligence legislation is to be developed with EU alignment in mind and framework legislation on data governance is to be prepared. In the foreign trade section, the EU’s data protection and cybersecurity rules are named as part of the Turkey-EU trade relationship. Reading the document as a whole, the picture I see is this: in this Programme, data protection is treated as a precondition of economic integration with Europe.

Rebuilding the compliance programmes

The practical consequence of this commitment is plain. Every compliance programme built to date will have to be revisited. Privacy notices, explicit consent flows, inventories, retention and destruction policies, cross-border transfer agreements, the data protection clauses in supplier contracts and breach response plans were all written to two different finishing lines. As the law moves towards the GDPR, some of those documents will become redundant, some will fall short and some will rest on a different basis than they do today. Re-establishing the legal basis for processing that was built on consent but could in fact run on legitimate interest is, on its own, a task that will take months.

I find this exciting. A field that has spent years preparing two separate defences for two separate tables is about to gain a single coherent framework, and that will change the nature of the work for companies and advisers alike. A Turkish start-up entering the European market will be able to extend its existing programme instead of building its data protection file from scratch. The Turkish subsidiary of a European group will be spared a large part of the effort it spends today on localising group policy.

A painful transition

A fact has to be set beside the excitement. We are in a region where compliance culture is already weak. Years after the VERBİS registration obligation took effect, there are still controllers that have never registered. There are a great many companies whose privacy notice is a template copied onto a website. On that ground, raising the law to GDPR level does not close the existing gap by itself. It raises the target. Institutions such as the data protection officer, the impact assessment and data protection by design will not start working in practice merely because they have entered the text of the law. It takes no prophecy to say that the transition will be painful.

That is why the real burden of the coming period will fall on the Personal Data Protection Authority. The Authority will have to do two things at the same time during this transition. The first is effective supervision: following the new rules through sectoral and planned inspections without waiting for complaints. The second is education: a guidance programme that tells companies, in good time and in plain language, which provision takes effect when, what happens to existing stocks of consent and whether transfer agreements need to be signed again. The guidance work that national authorities in Europe did during the two-year transition before 2018 had as much to do with making the GDPR workable as the text of the regulation itself. Turkey needs a transition period of that kind, and the 2027 date in the Programme shows how short it is.

A short calendar and a large task

The Medium-Term Programme says that the legislative text and the administrative regulations that will align the KVKK with the GDPR are to be prepared by the third quarter of 2027. As someone who has managed the differences between the two laws by hand for years, I was expecting this, and it is good news. It also means that every compliance programme built so far will be rewritten, and that in an environment of weak compliance culture the transition will hurt. Companies have roughly a year until the draft reaches Parliament; the timetable for enactment and entry into force will only become clear after that. Keeping the inventory current, reviewing legal bases and questioning consent-based processing now will take much of the weight off the work to be done in 2027. Whether this transition happens on paper or in practice will be decided by the Authority’s capacity for supervision and training.

Source. The Medium-Term Programme (2027-2029) annexed to Presidential Decision no. 11752, published in the Official Gazette no. 33362 (supplementary) of 6 September 2026; the Personal Data Protection Law no. 6698; Law no. 7499, published in the Official Gazette no. 32487 of 12 March 2024; Regulation (EU) 2016/679 (General Data Protection Regulation).

This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo

    View all posts
Considering a similar matter?See how we work on KVKK and GDPR compliance, or book a call directly.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 8 September 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.