SSS · Data Act Compliance

Our products are sold in the EU but our data servers are in Türkiye; does the scope change?

No. What decides scope is that the product or the related service is placed on the EU market and that the users are in the EU — not where the data physically sits. Servers in Türkiye do not…

Updated · July 20261 min readCategory · Data Act Compliance
Short answer

No — what is decisive is that the product is placed on the EU market; where the data is held does not remove the scope, it only adds a transfer layer.

No. What decides scope is that the product or the related service is placed on the EU market and that the users are in the EU — not where the data physically sits. Servers in Türkiye do not remove your obligations under the EU Data Act; they add a transfer and technical layer to how access and portability are delivered.

The access and portability rights of users of connected products sold in the EU apply wherever the data is stored. And where personal data is involved, the cross-border transfer rules of the Personal Data Protection Law (No. 6698) and of the GDPR come into play alongside. That layer is not a formality: because Türkiye is not on the EU adequacy list, moving EU-market personal data to Turkish servers needs a valid transfer tool — typically the standard contractual clauses — together with a transfer impact assessment. So the location of your servers is an architecture and compliance question. It is not a way out of scope.

Shall we apply this matter to your situation?

Tell us your specific situation in a few sentences; we'll assess it with the right team.

Get in touch
This content is for general information only and does not constitute legal advice. Please contact our team for an assessment of your specific circumstances.
Categories
Data Act Compliance

The right start means a predictable process.

From the first meeting to completion of the work; let's plan every step transparently.