The Data Protection Law governs both the transfer of personal data to third parties and its transfer outside Türkiye. That matters to any business, Turkish or international, whose operations cross the national border. Companies should review their operations to establish where personal data is held and whether the legislation applies to it.
Customer data under banking law
Banking Law No. 5411 (only available in Turkish here) sets its own rules for the cross-border transfer of customer data. Under Article 73 of the Banking Law, data relating to natural and legal persons that comes into existence after a customer relationship has been established with a bank, exclusively for banking activities, becomes customer data and is subject to the restrictions in that Law. The Banking Law’s conditions for the cross-border transfer of customer data should therefore take precedence over those in the Data Protection Law.
Transfers to third parties
As a rule, the Data Protection Law requires the data subject’s explicit consent before personal data may be transferred to a third party. Consent is not required, however, where one of the following applies:
- expressly permitted under laws;
- necessary to protect the life or physical integrity of the data subject (or another person) where the data subject is physically or legally incapable of providing their consent;
- necessary to process data of the parties to a contract, if such processing is directly related to the execution or performance of the contract;
- necessary for the data controller to fulfil its legal obligations;
- already publicised by the individuals themselves;
- necessary to establish, use or protect a right; or
- necessary for the legitimate interests of the data controller, provided that such processing does not violate fundamental rights and freedoms.
Personal data concerning health and sexual life may be processed, and therefore transferred, without the data subject’s explicit consent only by persons under a duty of confidentiality or by authorised institutions and organisations, and then only for the purposes of:
- protecting public health;
- operating preventive medicine;
- medical diagnosis;
- treatment and care services; or
- planning and managing health services and financing.
Transfers outside of Türkiye
Article 9, as amended by Law 7499, builds the regime for data transfers outside of Türkiye in three tiers. A transfer may be made first where one of the conditions in Articles 5 and 6 is satisfied and the Board has issued an adequacy decision for the destination country, sector or international organisation. Where there is no adequacy decision, the transfer turns on one of the appropriate safeguards in Article 9(4): an agreement between public bodies, with the Board’s permission; binding corporate rules approved by the Board; the standard contract published by the Board; or a written undertaking, again with the Board’s permission. A standard contract must be notified to the Board within five business days of signature. Where neither an adequacy decision nor an appropriate safeguard is available, a transfer may be made only incidentally, in the cases listed in Article 9(6). As at July 2026 the Board has not published an adequacy decision for any country, sector or international organisation, so transfers abroad are in practice made under the appropriate safeguards or the incidental cases.
Decision No. 2019/125 sets out the criteria for identifying countries with an adequate level of protection (only available in Turkish here) and annexes a form to be used in making that assessment. The following are taken into account:
- reciprocity condition;
- legislation of the relevant country regarding the processing of personal data and its implementation;
- existence of an independent data protection authority;
- party status to international agreements on the protection of personal data;
- membership status to international organisations;
- membership status to global and regional organisations that Türkiye is a party to; and
- the volume of trade with the relevant country.
Between the entry into force of the Data Protection Law on 7 April 2016 and 1 June 2024, when Law 7499 took effect, 86 undertaking applications were made to the Board, of which 10 were accepted; none of the 3 binding corporate rules applications made in the same period was accepted (KVKK, Guide on Transfers of Personal Data Abroad, January 2025). The Board announced its first approval, to a vehicle fleet leasing company, on 9 February 2021 and its second, to an e-commerce and web services company (subsidiaries of Amazon), on 4 March 2021.
The Board reviews applications on both procedural and substantive grounds. On the substance, the critical question is whether the transfer runs from one data controller to another or from a data controller to a data processor, and applicants should analyse the transfer carefully on that point. Decision No. 2020/71 of 30 January 2020 is the reference for determining the relationship between a data controller and a data processor (only available in Turkish here).
Before granting permission, the Board must consider international treaties, reciprocity between the countries concerned, the measures taken by the data controller, and the duration and purpose of the processing.
The Board may restrict transfers to third countries where it considers that the public interest or individual interests would be violated. How it will set the criteria for such a violation remains unclear.
Binding Corporate Rules
Binding corporate rules are now one of the appropriate safeguards named in Article 9(4), and a transfer made under rules the Board has approved needs no further permission. They reached the statute by a longer route. On 10 April 2020 the KVKK announced Binding Corporate Rules (‘BCRs’), which allow intra-group data transfers within multinational groups. BCRs are data protection rules for cross-border transfers that enable the companies of a multinational group operating in countries without an adequate level of protection to achieve adequate protection for their intra-group transfers.
The cross-border transfer rules then in force had proved difficult to apply, and the KVKK responded to the needs of the sector by creating an alternative route for group companies, modelled on the Binding Corporate Rules recognised under the GDPR. Law 7499 subsequently gave that route a statutory basis.
The rules the KVKK proposed allow a multinational to transfer personal data from Türkiye to a member of the same corporate group located in a country with a low level of data protection. In that setting, binding corporate rules operate as an undertaking to protect the data properly in intra-group cross-border transfers.
Binding corporate rules must reflect all the general data protection principles and provide adequate safeguards for personal data within the corporate group. The KVKK has published guidance on their required content, together with a standard application form, on its official website (only available in Turkish here and here).


