KVKK
Türkiye KVKK – Law on the Protection of Personal Data (Law No. 6698)
Türkiye’s Personal Data Protection Law No. 6698, commonly known as KVKK (Kişisel Verilerin Korunması Kanunu), is the primary data protection law in Türkiye. It regulates the collection, use, storage, disclosure, transfer and other processing of personal data and establishes obligations for data controllers and data processors.
The KVKK was enacted on 24 March 2016 and published in the Official Gazette on 7 April 2016. The framework has since been amended, including significant amendments that entered into force in 2024, particularly concerning special categories of personal data and international data transfers.
For businesses operating websites, mobile applications, SaaS platforms, e-commerce services or other digital products in Türkiye, KVKK compliance can involve consent management, privacy notices, processing-condition assessments, security controls, data-subject request handling, VERBİS obligations and international-transfer safeguards.
KVKK is Türkiye’s principal personal data protection framework.
It regulates how personal data relating to identified or identifiable individuals is processed and establishes requirements concerning:
- Lawful and fair processing
- Explicit consent
- Transparency and privacy notices
- Processing of special categories of personal data
- Data minimisation and proportionality
- Data security
- Data-subject rights
- Domestic and international data transfers
- Data retention and deletion
- Data breach notification
- Data Controllers’ Registry (VERBİS)
- Administrative sanctions and regulatory oversight
Importantly, explicit consent is not required for every processing activity. Article 5 provides several circumstances in which personal data may be processed without explicit consent, including certain legal, contractual, vital-interest, rights-protection and legitimate-interest situations.
KVKK at a Glance
| Requirement | KVKK |
|---|---|
| Country | Türkiye |
| Full name | Personal Data Protection Law No. 6698 |
| Common name | KVKK |
| Enacted | 24 March 2016 |
| Published | 7 April 2016 |
| Primary regulator | Personal Data Protection Authority (KVKK) |
| Core regulator body | Personal Data Protection Board |
| Explicit consent | Required where no other statutory processing condition applies |
| Special-category data | Subject to additional processing conditions |
| Privacy notice | Required |
| Data-subject rights | Yes |
| Data security | Required |
| Breach notification | Required; Board interprets “shortest time” as no later than 72 hours |
| VERBİS | Required for controllers within the registration obligation |
| International transfers | Regulated under amended Article 9 |
| Individual request response | Generally within 30 days |
| Status | In force |
The current KVKK framework defines explicit consent as freely given, specific and informed consent and establishes several processing conditions that operate independently of consent.
What Is KVKK?
The Law on the Protection of Personal Data No. 6698 is Türkiye’s comprehensive personal data protection law.
Its purpose is to protect fundamental rights and freedoms, particularly the right to privacy, while establishing the principles and obligations applicable to people and organisations processing personal data.
The law applies to processing carried out wholly or partly by automated means and to certain non-automated processing that forms part of a data filing system.
KVKK establishes the legal roles of:
- Data Controller (Veri Sorumlusu) – determines the purposes and means of processing.
- Data Processor (Veri İşleyen) – processes personal data on behalf of a data controller.
- Data Subject – the individual whose personal data is processed.
- Personal Data Protection Board – the regulatory decision-making body.
- Personal Data Protection Authority – the institutional authority supporting the regulatory framework.
Turkey
In force since 2016
Asya ve Afrika
Who Must Comply With KVKK?
KVKK applies to organisations and individuals that fall within its scope and process personal data covered by the law.
This can include:
- Turkish companies
- Employers
- E-commerce businesses
- Banks and financial institutions
- Healthcare organisations
- Educational institutions
- Technology companies
- SaaS providers
- Advertising and marketing businesses
- Telecommunications companies
- Online marketplaces
- Mobile applications
- Websites and digital platforms
- Public institutions
- Organisations processing employee data
- Organisations using customer or prospect databases
Organisations established outside Türkiye may also have obligations under KVKK depending on their processing activities and relationship with Turkish data subjects.
The law defines personal data broadly as information relating to an identified or identifiable natural person.
What Data Does KVKK Protect?
KVKK covers personal data relating to an identified or identifiable individual.
Examples include:
- Name
- Email address
- Telephone number
- Postal address
- Identification information
- Customer account information
- Employee information
- IP addresses where they constitute personal data
- Online identifiers
- Location information
- Transaction information
- Device-related information
- Authentication information
- Customer records
- Marketing profiles
- Certain cookie and tracking information
Whether a particular technical identifier constitutes personal data depends on whether it relates to an identified or identifiable natural person.
KVKK also establishes additional requirements for special categories of personal data.
KVKK Processing Principles
Article 4 establishes fundamental principles for processing personal data.
Personal data must be processed in accordance with the law and relevant legal principles, including:
Lawfulness and fairness
Processing must comply with applicable legal requirements and be carried out fairly.
Accuracy
Personal data should be accurate and kept up to date where necessary.
Purpose limitation
Data should be processed for specified, explicit and legitimate purposes.
Data minimisation
Personal data should be relevant, limited and proportionate to the purposes for which they are processed.
Storage limitation
Data should be retained for the period required by applicable legislation or for the purposes for which the data are processed.
These principles should be considered across the entire data lifecycle, from collection and consent through storage, use, sharing and deletion.
Does KVKK Require Explicit Consent?
Sometimes.
KVKK is often described as a consent-based privacy law, but this description is incomplete.
Article 5 states that personal data may not be processed without explicit consent unless one of the statutory conditions allowing processing without consent applies.
Personal data may be processed without explicit consent in circumstances including:
- Processing expressly provided for by law
- Protection of life or physical integrity in specified circumstances
- Processing necessary to establish or perform a contract
- Compliance with a legal obligation
- Data made public by the data subject
- Establishment, exercise or protection of a legal right
- Legitimate interests of the data controller, provided these do not violate the fundamental rights and freedoms of the data subject
Therefore, organisations should identify the appropriate KVKK processing condition for each processing activity rather than requesting consent for every type of personal data processing.
What Is Explicit Consent Under KVKK?
KVKK defines explicit consent as consent that is:
- Freely given
- Specific
- Informed
Consent should therefore represent a positive and meaningful expression of the data subject's wishes.
Consent management should avoid:
- Pre-selected consent options
- Vague or blanket consent
- Unclear purposes
- Hidden consent mechanisms
- Consent bundled unnecessarily with unrelated processing
- Interfaces that make refusal unnecessarily difficult
The KVKK Authority has emphasised the three core elements of explicit consent: a specific subject, information and free choice.
Consent Withdrawal
Where processing is based on explicit consent, organisations should provide a practical mechanism for managing the consent relationship.
A consent management system should allow organisations to:
- Record when consent was given
- Record what the consent covered
- Record the relevant purpose
- Record the user's choice
- Maintain evidence of consent
- Support changes to consent preferences
- Maintain records of withdrawals
- Prevent subsequent processing where consent is the applicable legal basis and has been withdrawn
ConsentX can help organisations operationalise these technical controls.
Special Categories of Personal Data Under KVKK
KVKK provides additional protections for special categories of personal data.
These include data relating to:
- Race
- Ethnic origin
- Political opinion
- Philosophical belief
- Religion
- Religious sect or other belief
- Appearance
- Association, foundation or trade-union membership
- Health
- Sexual life
- Criminal convictions and security measures
- Biometric data
- Genetic data
2024 Changes to Special-Category Data
Significant amendments to Article 6 entered into force in 2024.
The previous structure was replaced with a broader set of statutory conditions under which special categories may be processed without relying exclusively on explicit consent. These include certain legal requirements, public-health purposes, employment and social-security obligations, rights protection and other specified circumstances.
The 2024 amendments therefore make it particularly important for organisations to reassess legacy consent flows for special-category data.
Organisations should not automatically assume that every processing activity involving sensitive data must use the same consent mechanism.
Processing Special Categories of Personal Data
Where special-category data is processed, organisations should determine:
- What category of data is involved?
- What is the purpose of processing?
- Which Article 6 condition applies?
- Is explicit consent required?
- What additional security measures apply?
- Who can access the information?
- How long should it be retained?
- Is the information transferred to another party?
- Is it transferred outside Türkiye?
- What evidence should be retained?
KVKK also requires adequate measures determined by the Board when processing special categories of personal data.
Privacy Notices and Transparency
KVKK Article 10 requires data controllers to inform data subjects when personal data is obtained.
The information includes:
- Identity of the data controller
- Identity of its representative, where applicable
- Purpose of processing
- Recipients and purposes of transfers
- Method and legal basis of collection
- Relevant data-subject rights
For websites and applications, privacy notices should therefore be clear, accessible and appropriately connected to the data collection point.
Consent banners should not be treated as a substitute for a complete privacy notice.
Cookies and Tracking Technologies Under KVKK
KVKK does not mean that every cookie automatically requires explicit consent.
The appropriate legal treatment depends on:
- What information the cookie or tracker collects
- Whether the information constitutes personal data
- Why it is used
- Whether another Article 5 processing condition applies
- Whether the data is transferred to third parties
- Whether the activity involves international transfers
- Whether special-category information is involved
For analytics, advertising and other non-essential tracking, organisations should assess the applicable KVKK processing condition and implement an appropriate consent or notice mechanism where required.
ConsentX can help organisations identify cookies and trackers and apply region-specific controls.
Data Subject Rights Under KVKK
Article 11 provides data subjects with several rights.
Individuals may request:
- Confirmation of whether their personal data is processed
- Information about processing
- Information about processing purposes
- Information about third parties receiving their data
- Correction of inaccurate or incomplete data
- Erasure or destruction where the legal conditions apply
- Notification of corrections or deletions to relevant third parties
- Objection to certain adverse results produced solely through automated processing
- Compensation for damage arising from unlawful processing
KVKK Data Subject Requests
Data subjects can submit requests to the data controller in accordance with the procedures established under KVKK.
The controller generally must conclude the request as soon as possible and within a maximum of 30 days. Requests are generally free of charge, although a fee may be permitted in circumstances defined by the applicable rules.
ConsentX can support operational workflows for:
- Request intake
- Identity verification workflows
- Request tracking
- Evidence collection
- Internal assignment
- Deadline monitoring
- Response documentation
- Audit trails
Data Security Under KVKK
Article 12 requires data controllers to take necessary technical and organisational measures to provide an appropriate level of security.
These measures are intended to prevent:
- Unlawful processing
- Unlawful access
- Loss or compromise of personal data
Data controllers must also conduct or arrange appropriate audits concerning compliance with data-security requirements.
Where processing is performed by a data processor, the data controller retains responsibility for appropriate security measures.
KVKK Data Breach Notification
Where personal data processed by a controller is unlawfully obtained by others, the controller must notify the data subject and the Board within the shortest time.
The KVKK Board has interpreted the statutory expression “the shortest time” as no later than 72 hours after becoming aware of the breach. Where notification cannot be completed within 72 hours, the reasons for the delay should be included.
Organisations should maintain:
- Breach detection procedures
- Incident response processes
- Breach documentation
- Internal escalation procedures
- Regulatory notification workflows
- Data-subject communication procedures
Data Controllers and Data Processors
KVKK distinguishes between:
Data Controller
The organisation that determines the purposes and means of processing personal data.
Data Processor
A person or organisation processing personal data on behalf of the data controller.
Examples of processors can include:
- Cloud service providers
- Hosting companies
- CRM providers
- Email platforms
- Analytics providers
- Marketing technology providers
- Customer-support platforms
The data controller should maintain appropriate oversight of processors and ensure that security and privacy obligations are addressed throughout the processing relationship.
International Data Transfers Under KVKK
International data transfers are a major area of KVKK compliance.
Article 9 was substantially amended in 2024, introducing a new framework for transfers of personal data abroad.
Under the amended framework, transfers may rely on mechanisms including:
- An adequacy decision
- Approved binding corporate rules
- Standard contracts published by the Board
- Certain approved written commitments
- Specified exceptional transfer circumstances
Standard Contracts
Standard contracts are one of the safeguards available for international transfers.
The law requires the standard contract to be notified to the Authority within five business days following signature.
The KVKK Authority has published standard contract models covering different controller and processor relationships.
This is particularly important for organisations using international:
- Cloud infrastructure
- SaaS tools
- CRM platforms
- Analytics services
- Advertising technology
- Email providers
- Customer-support systems
International Transfers and Consent
Explicit consent can be one of the exceptional mechanisms for transferring personal data abroad, but the amended Article 9 framework does not make consent the default solution for routine international transfers.
Where relying on the exceptional transfer conditions, the statutory requirements and limitations must be assessed carefully.
For ongoing international transfers, organisations should generally assess whether an adequacy decision or appropriate safeguard is available.
VERBİS – Data Controllers’ Registry
KVKK establishes the Data Controllers’ Registry, known as VERBİS.
Data controllers subject to the registration obligation must register and provide information concerning their processing activities.
The registration framework can require information such as:
- Controller identity
- Processing purposes
- Categories of data subjects
- Data categories
- Recipients
- International transfers
- Security measures
- Maximum storage periods
However, the law allows the Board to establish exemptions based on objective criteria.
Current VERBİS Exemptions
The KVKK Board has established exemptions using criteria including the nature and quantity of data, processing activities and organisational characteristics.
A significant 2025 Board decision also expanded the exemption framework for certain small controllers whose main activity involves processing special-category personal data, using employee-number and financial-balance criteria.
Businesses should therefore verify their current VERBİS registration status and applicable exemption criteria rather than relying on older employee or revenue thresholds published in legacy compliance materials.
Data Retention and Deletion
KVKK requires personal data to be stored for the period established by relevant legislation or for the period required for the purpose of processing.
Where the reasons requiring processing no longer exist, personal data should be:
- Erased
- Destroyed
- Anonymised
as applicable.
Türkiye also has a dedicated By-Law on Erasure, Destruction or Anonymization of Personal Data, which establishes procedures for these activities.
Organisations should therefore maintain documented retention schedules and deletion procedures.
Automated Decision-Making
KVKK recognises a data subject's right to object to a result against them arising from analysis of personal data processed solely through automated systems.
This is relevant to businesses using:
- AI systems
- Automated profiling
- Automated customer scoring
- Fraud detection
- Recruitment technology
- Personalisation systems
- Automated eligibility decisions
Organisations using AI or automated decision systems should assess the relevant KVKK processing conditions, transparency obligations, data-subject rights and security requirements.
Direct Marketing Under KVKK
Marketing activities can involve multiple categories of personal-data processing, including:
- Email addresses
- Telephone numbers
- Customer profiles
- Purchase history
- Behavioural information
- Advertising identifiers
- Website activity
Organisations should determine the appropriate legal basis and ensure that marketing-related processing is consistent with KVKK transparency and processing requirements.
Where explicit consent is required, consent should be specific, informed and freely given.
Consent records should also be maintained as evidence.
Privacy by Design Under KVKK
Although KVKK does not simply replicate the GDPR's terminology, organisations should incorporate privacy and security considerations into systems and processes from the beginning.
A privacy-aware implementation can include:
- Data minimisation
- Purpose-based collection
- Access controls
- Consent management
- Privacy notices
- Retention controls
- Data-subject request workflows
- Vendor assessments
- International-transfer assessments
- Security controls
- Audit logging
Data Processing Records and Governance
Organisations should maintain visibility into:
- What personal data they process
- Why they process it
- Where it is stored
- Who can access it
- Which vendors receive it
- Whether it leaves Türkiye
- How long it is retained
- What legal condition supports processing
- Whether explicit consent is required
- How consent is withdrawn
- How data-subject requests are handled
For organisations subject to VERBİS registration, maintaining accurate processing information is particularly important because registry information is linked to the organisation's processing activities.
KVKK Enforcement and Penalties
The Personal Data Protection Board is responsible for regulatory enforcement under the KVKK framework.
The law provides administrative fines for violations including:
- Failure to fulfil the information obligation
- Failure to meet data-security obligations
- Failure to comply with Board decisions
- Failure to comply with VERBİS obligations
- Failure to comply with the international-transfer standard-contract notification requirement
The monetary amounts are subject to annual adjustment. The Authority publishes updated administrative fine amounts for each calendar year.
Serious compliance failures can therefore create significant financial and operational exposure.
Who Enforces KVKK?
KVKK is supervised and enforced by the:
Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu)
The Personal Data Protection Board performs important regulatory, supervisory and enforcement functions, including handling complaints, examining violations and imposing administrative sanctions.
How ConsentX Helps With KVKK Compliance
ConsentX helps organisations operationalise key privacy and consent controls required for their digital properties.
Cookie and Tracker Discovery
Identify cookies, trackers and other technologies operating on your website.
Consent Management
Collect explicit, purpose-specific consent where required.
Consent Records
Maintain auditable records of consent choices and preference changes.
Prior-Script Blocking
Prevent selected non-essential technologies from executing before the required consent signal is obtained.
Privacy Notices
Present relevant privacy and consent information within the user journey.
Region-Based Rules
Apply appropriate consent experiences based on the visitor's region and configured compliance rules.
Consent Withdrawal
Give users a practical way to change or withdraw applicable consent choices.
DSAR Workflows
Support the operational management of access, correction, deletion and related data-subject requests.
Audit Evidence
Maintain records that help demonstrate how consent and preference decisions were captured and managed.
How to Comply With KVKK Using ConsentX
- 1
Scan Your Website
Use ConsentX to identify cookies, scripts, trackers and other technologies operating across your website.
This helps establish visibility into what data-related technologies are actually running.
- 2
Categorise Your Trackers
Classify technologies according to their purpose, such as:
- Necessary
- Analytics
- Functional
- Advertising
- Personalisation
- Social media
Then assess the appropriate KVKK treatment for each category.
- 3
Configure Your Consent Experience
Create a clear consent interface for processing activities where explicit consent is the appropriate legal condition.
Consent should be:
- Specific
- Informed
- Freely given
- Clearly expressed
- 4
Block Applicable Trackers Before Consent
Configure ConsentX to prevent applicable non-essential scripts from firing before the required consent signal is obtained.
- 5
Record Consent
Store evidence showing:
- What the user selected
- When the choice was made
- Which purposes were involved
- Which version of the consent interface was presented
- Whether the user subsequently changed their preference
- 6
Support Consent Withdrawal
Allow users to revisit and change their applicable consent preferences.
- 7
Manage Data Requests
Use ConsentX workflows to organise data-subject requests and monitor the applicable response deadline.
- 8
Maintain Audit Evidence
Keep appropriate records to demonstrate how privacy and consent controls operate across your digital environment.
KVKK Compliance Checklist
Use this checklist as a starting point for your compliance programme:
- Identify personal data processing activities
- Identify data controllers and processors
- Map processing purposes
- Determine the applicable Article 5 processing condition
- Identify special categories of personal data
- Assess Article 6 conditions where applicable
- Prepare appropriate privacy notices
- Review cookie and tracking technologies
- Determine where explicit consent is required
- Ensure consent is freely given, specific and informed
- Record consent decisions
- Provide mechanisms for applicable consent withdrawal
- Implement data-subject request procedures
- Monitor the 30-day response period
- Implement appropriate security measures
- Maintain a data-breach response process
- Assess international transfers
- Review standard-contract requirements where applicable
- Track the five-business-day notification requirement for applicable standard contracts
- Assess VERBİS registration requirements
- Maintain processing inventories
- Define retention periods
- Implement deletion/anonymisation procedures
- Review vendor and processor relationships
- Maintain appropriate audit evidence
- Monitor KVKK Board guidance and regulatory updates
Frequently Asked Questions
Country Under KVKK
Türkiye (Turkey)
KVKK is Türkiye's primary personal data protection framework.
Other Privacy Regulations
Organisations operating internationally may also need to assess:
- GDPR – European Union
- UK GDPR – United Kingdom
- CCPA/CPRA – California
- LGPD – Brazil
- PIPEDA – Canada
- FADP – Switzerland
- DPDPA – India
- PDPA – Singapore
- PDPA – Thailand
- POPIA – South Africa
- UAE PDPL – United Arab Emirates
- Qatar PDPPL – Qatar
- Other applicable national and regional privacy laws
The applicable framework depends on factors including the organisation's location, the location of data subjects, services offered, processing activities and international data transfers.
Why KVKK Consent Management Matters
For digital businesses, privacy compliance is not limited to publishing a privacy policy.
A website can involve dozens of technologies that collect or transmit information, including:
- Analytics tools
- Advertising pixels
- Social-media scripts
- Session-recording tools
- Personalisation technologies
- Marketing tags
- Embedded content
- CRM integrations
A robust consent-management system helps organisations understand these technologies, control applicable processing and maintain evidence of user choices.
ConsentX combines:
Cookie discovery + consent management + prior-script blocking + consent records + regional rules + DSAR workflows
to help businesses operationalise privacy controls across their digital properties.
Get KVKK Ready With ConsentX
Build a more transparent and auditable approach to consent and privacy compliance for users in Türkiye.
With ConsentX, organisations can:
- Discover website trackers
- Configure KVKK-aware consent experiences
- Block applicable technologies before consent
- Capture explicit consent
- Maintain consent records
- Manage preference changes
- Support data-subject requests
- Maintain audit evidence
- Apply region-specific privacy rules
ConsentX helps turn privacy requirements into operational controls.