Türkiye KVKK – Law on the Protection of Personal Data (Law No. 6698)
Türkiye’s Personal Data Protection Law No. 6698, commonly known as KVKK (Kişisel Verilerin Korunması Kanunu), is the primary data protection law in Türkiye. It regulates the collection, use, storage, disclosure, transfer and other processing of personal data and establishes obligations for data controllers and data processors.
The KVKK was enacted on 24 March 2016 and published in the Official Gazette on 7 April 2016. The framework has since been amended, including significant amendments that entered into force in 2024, particularly concerning special categories of personal data and international data transfers.
For businesses operating websites, mobile applications, SaaS platforms, e-commerce services or other digital products in Türkiye, KVKK compliance can involve consent management, privacy notices, processing-condition assessments, security controls, data-subject request handling, VERBİS obligations and international-transfer safeguards.
KVKK is Türkiye’s principal personal data protection framework.
It regulates how personal data relating to identified or identifiable individuals is processed and establishes requirements concerning:
Importantly, explicit consent is not required for every processing activity. Article 5 provides several circumstances in which personal data may be processed without explicit consent, including certain legal, contractual, vital-interest, rights-protection and legitimate-interest situations.
| Requirement | KVKK |
|---|---|
| Country | Türkiye |
| Full name | Personal Data Protection Law No. 6698 |
| Common name | KVKK |
| Enacted | 24 March 2016 |
| Published | 7 April 2016 |
| Primary regulator | Personal Data Protection Authority (KVKK) |
| Core regulator body | Personal Data Protection Board |
| Explicit consent | Required where no other statutory processing condition applies |
| Special-category data | Subject to additional processing conditions |
| Privacy notice | Required |
| Data-subject rights | Yes |
| Data security | Required |
| Breach notification | Required; Board interprets “shortest time” as no later than 72 hours |
| VERBİS | Required for controllers within the registration obligation |
| International transfers | Regulated under amended Article 9 |
| Individual request response | Generally within 30 days |
| Status | In force |
The current KVKK framework defines explicit consent as freely given, specific and informed consent and establishes several processing conditions that operate independently of consent.
The Law on the Protection of Personal Data No. 6698 is Türkiye’s comprehensive personal data protection law.
Its purpose is to protect fundamental rights and freedoms, particularly the right to privacy, while establishing the principles and obligations applicable to people and organisations processing personal data.
The law applies to processing carried out wholly or partly by automated means and to certain non-automated processing that forms part of a data filing system.
KVKK establishes the legal roles of:
Turkey
In force since 2016
Asia & Africa
KVKK applies to organisations and individuals that fall within its scope and process personal data covered by the law.
This can include:
Organisations established outside Türkiye may also have obligations under KVKK depending on their processing activities and relationship with Turkish data subjects.
The law defines personal data broadly as information relating to an identified or identifiable natural person.
KVKK covers personal data relating to an identified or identifiable individual.
Examples include:
Whether a particular technical identifier constitutes personal data depends on whether it relates to an identified or identifiable natural person.
KVKK also establishes additional requirements for special categories of personal data.
Article 4 establishes fundamental principles for processing personal data.
Personal data must be processed in accordance with the law and relevant legal principles, including:
Processing must comply with applicable legal requirements and be carried out fairly.
Personal data should be accurate and kept up to date where necessary.
Data should be processed for specified, explicit and legitimate purposes.
Personal data should be relevant, limited and proportionate to the purposes for which they are processed.
Data should be retained for the period required by applicable legislation or for the purposes for which the data are processed.
These principles should be considered across the entire data lifecycle, from collection and consent through storage, use, sharing and deletion.
Sometimes.
KVKK is often described as a consent-based privacy law, but this description is incomplete.
Article 5 states that personal data may not be processed without explicit consent unless one of the statutory conditions allowing processing without consent applies.
Personal data may be processed without explicit consent in circumstances including:
Therefore, organisations should identify the appropriate KVKK processing condition for each processing activity rather than requesting consent for every type of personal data processing.
KVKK defines explicit consent as consent that is:
Consent should therefore represent a positive and meaningful expression of the data subject's wishes.
Consent management should avoid:
The KVKK Authority has emphasised the three core elements of explicit consent: a specific subject, information and free choice.
Where processing is based on explicit consent, organisations should provide a practical mechanism for managing the consent relationship.
A consent management system should allow organisations to:
ConsentX can help organisations operationalise these technical controls.
KVKK provides additional protections for special categories of personal data.
These include data relating to:
Significant amendments to Article 6 entered into force in 2024.
The previous structure was replaced with a broader set of statutory conditions under which special categories may be processed without relying exclusively on explicit consent. These include certain legal requirements, public-health purposes, employment and social-security obligations, rights protection and other specified circumstances.
The 2024 amendments therefore make it particularly important for organisations to reassess legacy consent flows for special-category data.
Organisations should not automatically assume that every processing activity involving sensitive data must use the same consent mechanism.
Where special-category data is processed, organisations should determine:
KVKK also requires adequate measures determined by the Board when processing special categories of personal data.
KVKK Article 10 requires data controllers to inform data subjects when personal data is obtained.
The information includes:
For websites and applications, privacy notices should therefore be clear, accessible and appropriately connected to the data collection point.
Consent banners should not be treated as a substitute for a complete privacy notice.
KVKK does not mean that every cookie automatically requires explicit consent.
The appropriate legal treatment depends on:
For analytics, advertising and other non-essential tracking, organisations should assess the applicable KVKK processing condition and implement an appropriate consent or notice mechanism where required.
ConsentX can help organisations identify cookies and trackers and apply region-specific controls.
Article 11 provides data subjects with several rights.
Individuals may request:
Data subjects can submit requests to the data controller in accordance with the procedures established under KVKK.
The controller generally must conclude the request as soon as possible and within a maximum of 30 days. Requests are generally free of charge, although a fee may be permitted in circumstances defined by the applicable rules.
ConsentX can support operational workflows for:
Article 12 requires data controllers to take necessary technical and organisational measures to provide an appropriate level of security.
These measures are intended to prevent:
Data controllers must also conduct or arrange appropriate audits concerning compliance with data-security requirements.
Where processing is performed by a data processor, the data controller retains responsibility for appropriate security measures.
Where personal data processed by a controller is unlawfully obtained by others, the controller must notify the data subject and the Board within the shortest time.
The KVKK Board has interpreted the statutory expression “the shortest time” as no later than 72 hours after becoming aware of the breach. Where notification cannot be completed within 72 hours, the reasons for the delay should be included.
Organisations should maintain:
KVKK distinguishes between:
The organisation that determines the purposes and means of processing personal data.
A person or organisation processing personal data on behalf of the data controller.
Examples of processors can include:
The data controller should maintain appropriate oversight of processors and ensure that security and privacy obligations are addressed throughout the processing relationship.
International data transfers are a major area of KVKK compliance.
Article 9 was substantially amended in 2024, introducing a new framework for transfers of personal data abroad.
Under the amended framework, transfers may rely on mechanisms including:
Standard contracts are one of the safeguards available for international transfers.
The law requires the standard contract to be notified to the Authority within five business days following signature.
The KVKK Authority has published standard contract models covering different controller and processor relationships.
This is particularly important for organisations using international:
Explicit consent can be one of the exceptional mechanisms for transferring personal data abroad, but the amended Article 9 framework does not make consent the default solution for routine international transfers.
Where relying on the exceptional transfer conditions, the statutory requirements and limitations must be assessed carefully.
For ongoing international transfers, organisations should generally assess whether an adequacy decision or appropriate safeguard is available.
KVKK establishes the Data Controllers’ Registry, known as VERBİS.
Data controllers subject to the registration obligation must register and provide information concerning their processing activities.
The registration framework can require information such as:
However, the law allows the Board to establish exemptions based on objective criteria.
The KVKK Board has established exemptions using criteria including the nature and quantity of data, processing activities and organisational characteristics.
A significant 2025 Board decision also expanded the exemption framework for certain small controllers whose main activity involves processing special-category personal data, using employee-number and financial-balance criteria.
Businesses should therefore verify their current VERBİS registration status and applicable exemption criteria rather than relying on older employee or revenue thresholds published in legacy compliance materials.
KVKK requires personal data to be stored for the period established by relevant legislation or for the period required for the purpose of processing.
Where the reasons requiring processing no longer exist, personal data should be:
as applicable.
Türkiye also has a dedicated By-Law on Erasure, Destruction or Anonymization of Personal Data, which establishes procedures for these activities.
Organisations should therefore maintain documented retention schedules and deletion procedures.
KVKK recognises a data subject's right to object to a result against them arising from analysis of personal data processed solely through automated systems.
This is relevant to businesses using:
Organisations using AI or automated decision systems should assess the relevant KVKK processing conditions, transparency obligations, data-subject rights and security requirements.
Marketing activities can involve multiple categories of personal-data processing, including:
Organisations should determine the appropriate legal basis and ensure that marketing-related processing is consistent with KVKK transparency and processing requirements.
Where explicit consent is required, consent should be specific, informed and freely given.
Consent records should also be maintained as evidence.
Although KVKK does not simply replicate the GDPR's terminology, organisations should incorporate privacy and security considerations into systems and processes from the beginning.
A privacy-aware implementation can include:
Organisations should maintain visibility into:
For organisations subject to VERBİS registration, maintaining accurate processing information is particularly important because registry information is linked to the organisation's processing activities.
The Personal Data Protection Board is responsible for regulatory enforcement under the KVKK framework.
The law provides administrative fines for violations including:
The monetary amounts are subject to annual adjustment. The Authority publishes updated administrative fine amounts for each calendar year.
Serious compliance failures can therefore create significant financial and operational exposure.
KVKK is supervised and enforced by the:
Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu)
The Personal Data Protection Board performs important regulatory, supervisory and enforcement functions, including handling complaints, examining violations and imposing administrative sanctions.
ConsentX helps organisations operationalise key privacy and consent controls required for their digital properties.
Identify cookies, trackers and other technologies operating on your website.
Collect explicit, purpose-specific consent where required.
Maintain auditable records of consent choices and preference changes.
Prevent selected non-essential technologies from executing before the required consent signal is obtained.
Present relevant privacy and consent information within the user journey.
Apply appropriate consent experiences based on the visitor's region and configured compliance rules.
Give users a practical way to change or withdraw applicable consent choices.
Support the operational management of access, correction, deletion and related data-subject requests.
Maintain records that help demonstrate how consent and preference decisions were captured and managed.
Use ConsentX to identify cookies, scripts, trackers and other technologies operating across your website.
This helps establish visibility into what data-related technologies are actually running.
Classify technologies according to their purpose, such as:
Then assess the appropriate KVKK treatment for each category.
Create a clear consent interface for processing activities where explicit consent is the appropriate legal condition.
Consent should be:
Configure ConsentX to prevent applicable non-essential scripts from firing before the required consent signal is obtained.
Store evidence showing:
Allow users to revisit and change their applicable consent preferences.
Use ConsentX workflows to organise data-subject requests and monitor the applicable response deadline.
Keep appropriate records to demonstrate how privacy and consent controls operate across your digital environment.
Use this checklist as a starting point for your compliance programme:
Türkiye (Turkey)
KVKK is Türkiye's primary personal data protection framework.
Organisations operating internationally may also need to assess:
The applicable framework depends on factors including the organisation's location, the location of data subjects, services offered, processing activities and international data transfers.
For digital businesses, privacy compliance is not limited to publishing a privacy policy.
A website can involve dozens of technologies that collect or transmit information, including:
A robust consent-management system helps organisations understand these technologies, control applicable processing and maintain evidence of user choices.
ConsentX combines:
Cookie discovery + consent management + prior-script blocking + consent records + regional rules + DSAR workflows
to help businesses operationalise privacy controls across their digital properties.
Build a more transparent and auditable approach to consent and privacy compliance for users in Türkiye.
With ConsentX, organisations can:
ConsentX helps turn privacy requirements into operational controls.