Guide · Data Protection

Data protection compliance: KVKK and GDPR obligations

Essential compliance steps regarding data controllers' duty to inform, explicit consent, and cross-border data transfers.

20 January 20254 dk okumaBy Sven Köksal · Data Protection
Köksal Attorney Partnership — data, artificial intelligence, cybersecurity and legal tech work

Data controllers must manage the topics of the duty to inform, explicit consent, data processing conditions, data security, and cross-border transfers together with their operational processes.

Key steps in KVKK and GDPR compliance

This publication outlines, in general terms, the topics that companies should take into account in their decision-making process. Application may vary depending on the sector and the specific structure of the transaction.

Practical takeaways for companies

  • The relevant legislation and practice should be assessed on a current basis.
  • Contractual, compliance, and operational processes should be addressed together.
  • A file-based legal analysis should be carried out for the concrete situation.

Where to start with KVKK and GDPR compliance

The practical sequence is similar under both regimes. First, a data inventory: which personal data are processed, for which purposes, on which legal basis, and with which recipients. In Türkiye, for controllers that are subject to registration, this feeds the VERBİS filing; under the GDPR it feeds the record of processing activities. Second, the information layer: privacy notices for customers, employees and website visitors, aligned with the actual data flows. Third, the contract layer: data processing agreements with vendors and, for transfers abroad, the safeguards required by the Personal Data Protection Law (KVKK) and the GDPR.

Finally, compliance must be able to survive an incident: breach-response procedures built around the short statutory notification windows, a working process for data subject requests, and periodic training. A combined KVKK/GDPR compliance programme keeps the two regimes consistent instead of running two parallel projects.

The contract layer: processors and transfers

Once the inventory and the information-notice layer are in place, the contract layer follows: data processing clauses have to go into the agreements with suppliers acting as processors — the cloud provider, the call centre, the payroll and HR software, the marketing agency — the chain of sub-processors has to be made visible, and where data goes abroad the transfer safeguards the legislation provides for have to be chosen and documented. For controllers under a registration duty that same inventory is the basis of the VERBİS filing, and on the GDPR side of the record of processing activities — deriving both from one inventory rather than producing them separately cuts the cost and the risk of inconsistency at the same time.

Preparing for an incident

Compliance is tested in earnest at the moment of a breach. The short statutory notification windows mean the sequence has to be written down in advance: technical detection, legal assessment, notification to the authority and to the individuals concerned, and a record of each of those steps. Because the same incident is usually assessed under both regimes at once, the two notification flows belong in a single incident response plan rather than in two separate playbooks. Data subject requests need the same treatment: someone has to own the deadline.

Questions to ask internally

  • Which data are processed, for what purpose and on which legal basis — and is explicit consent genuinely needed?
  • Is a privacy notice shown on every channel through which data are collected?
  • Which vendors have access to personal data, and do their contracts contain data terms?
  • Do data leave the country, and if so, on which safeguard?
  • Are retention and deletion periods actually run, or do they exist only in the policy?
  • In the first hours of a breach, is it clear who decides?

The answers depend on the sector and on how processing is actually organised; the legislation in force and current regulator practice should be assessed file by file (as of July 2026).

Dual compliance on the Türkiye–Germany route

For Turkish companies with customers, a branch or a group company in Germany, both regimes apply to the same data flow at the same time. The most common failure is running two document sets — one for the KVKK, one for the GDPR — that never meet: one inventory, two sets of notices and a third reality in operations. A single process architecture closes that gap. For current developments on the data side, see our Data focus area.

Who owns compliance?

Data protection compliance slows down within the first quarter wherever no owner has been named. The model that works in practice is a small working group drawn from legal, IT and the business units, reporting to a single accountable person, with an annual review date in the calendar and a check step built into the process whenever a new product, channel or vendor is added. Once compliance stops being a project and becomes routine, its cost becomes predictable.

This content is for general information purposes only and does not constitute legal advice. Please get in touch with our team for an assessment regarding your specific situation.
Sven Köksal

Author

Sven Köksal

Legal Engineer

Advisory on legal technology, process design and digital business models.

Related Areas of Work

Explore this publication together with the relevant services, practice areas, focus areas, sectors and desks.

Services

Areas of work directly connected to this publication.

See all

Practice Areas

The legal disciplines the topic sits within.

See all

Focus Areas

Focus areas assessed together according to the client's needs.

See all

Sectors

The sectors this topic touches most often.

See all

Regional Desks

Regional desks that follow the matter with a cross-border or specialist focus.

See all
Knowledge Centre

Get a legal assessment on this matter.

Get in touch with our team for an assessment of your specific situation.