Platform AI governance Coverage Pricing Partners Sign in
Free readiness checkTalk to us
HomePrivacy laws › Turkey
Privacy law · Middle East & Turkey

🇹🇷 KVKK in Turkey

Turkey's Law No. 6698 on the Protection of Personal Data (KVKK) is a comprehensive, GDPR-influenced regime enforced by the Personal Data Protection Authority, covering lawful bases, registration, transfers and data-subject rights.

Verified - legal review completed
KVKK
Governing framework
KVKK (Kurul)
Supervisory authority
11
Controls this market requires
18
Required or strongly expected

What KVKK expects of you

22 of our 22 tracked controls apply in Turkey, graded by how firmly the law requires each one.

Required mandated by law Expected near-mandatory Prudent advisable Optional emerging
RecordsRequired

Records of processing (RoPA)

A living inventory of what personal data you hold, why, where it sits and where it flows.

Closes with: Records of Processing register
Lawful basisRequired

Lawful basis mapping

A valid legal reason for each use of personal data, mapped per activity.

Closes with: Lawful-basis mapping
ConsentRequired

Consent - specific, logged, withdrawable

Where you rely on consent it is freely given, specific, informed, unbundled and withdrawable, with a record.

Closes with: Consent notice + consent-record schema
TransparencyRequired

Privacy notice / transparency

A published, current privacy notice giving the prescribed information.

Closes with: Public privacy notice (per-market)
RightsRequired

Individual rights handling

Ability to find, correct and delete one person's data on request within the legal deadline.

Closes with: Rights-request procedure
Cross-borderRequired

Cross-border transfer mechanism

Every export of personal data is covered by a lawful transfer mechanism.

Closes with: Data-flow map + transfer pack (SCCs/TRA/adequacy)
SecurityRequired

Security controls (TOMs)

Encryption in transit and at rest, least-privilege access, and access logging.

Closes with: Security controls statement (TOMs)
BreachRequired

Breach detection & notification

A written breach plan and knowledge of each market's notification clock.

Closes with: Breach response plan + per-market templates
VendorsRequired

Vendor / processor agreements

DPAs with vendors handling your data, with controller/processor roles defined.

Closes with: Processor agreement template + role allocation
RegistrationRequired

Authority registration / filing

Registration or filing with the DPA where the market requires it.

Closes with: Registration pack (per market)
RepresentativeRequired

Local representative appointment

A local/EU representative where you have no establishment in a market that requires one.

Closes with: Representative appointment letter
GovernanceExpected

Accountable privacy owner / DPO

A named person or role accountable for data protection, with published contact where required.

Closes with: DPO / privacy-owner appointment letter
RetentionExpected

Retention & deletion schedule

Defined, enforced retention periods and deletion, balancing storage-limitation and legal keep-periods.

Closes with: Retention schedule + deletion runbook
ChildrenExpected

Children's-data safeguards

Age assurance and verifiable parental consent; no behavioural tracking of children.

Closes with: Children's-data procedure + age-gating
SensitiveExpected

Sensitive / special-category data

Explicit consent, tighter access, and often a DPIA for special-category data.

Closes with: Sensitive-data policy + DPIA where required
MarketingExpected

Direct-marketing consent

Lawful basis/consent for e-marketing and an unsubscribe route.

Closes with: Marketing consent + suppression list
DPIAExpected

Impact assessment / dossier

A DPIA/impact assessment for high-risk processing; some markets require a filed dossier.

Closes with: DPIA / transfer-impact assessment
PaymentsExpected

PCI / payment-card handling

Card data offloaded to a compliant processor; PCI-DSS scope controlled.

Closes with: PCI-DSS scope note + card-handling policy
GrievancePrudent

Grievance / complaints channel

A published route to raise a privacy complaint; India requires a grievance officer.

Closes with: Grievance / complaint notice
ePrivacyPrudent

Cookies / e-privacy consent

Cookie/tracker consent and an accurate cookie policy where required (esp. EU/UK).

Closes with: Cookie policy + consent banner
ADM/AIPrudent

Automated decisions / profiling

Safeguards and transparency for automated decision-making and profiling.

Closes with: ADM transparency + safeguards note
LocalisationOptional

Data localisation / residency

Local storage/residency requirements for certain data or sectors.

Closes with: Data-residency design note

Get Turkey-ready without the guesswork

Answer a few questions and PrivMatrix shows you exactly where you stand against KVKK, then generates the policies, notices and registers that close each gap - written for Turkey.

Other markets

See all 28 →
🇦🇪 UAE🇸🇦 Saudi Arabia🇶🇦 Qatar🇧🇭 Bahrain🇴🇲 Oman🇰🇼 Kuwait🇪🇺 EU / UK🇨🇭 Switzerland