Legislation · European Union · EU Directive & Regulation (Regulation (EU) 2016/679)

EU General Data Protection Regulation (GDPR)

The GDPR is not only a regulation for EU companies; it governs every company that sells to, provides services to, or monitors the online behaviour of, individuals in the EU. For companies operating from Türkiye towards the EU market, it forms a second compliance layer alongside the KVKK (Türkiye's Personal Data Protection Law).

In forceIn force · 25.05.2018Source · ABl. L 119, 4.5.2016Threshold · No threshold; targeting/monitoring suffices
In summary

The Regulation is built on the principles of lawfulness, transparency, purpose limitation and accountability. Companies outside the EU may fall within scope under Art. 3 and may need to appoint an EU representative under Art. 27. For infringements, fines reach up to €20 million or 4% of global turnover.

Overview

The GDPR is the regulation that binds the processing of personal data to uniform rules across the EU, and it is the global reference point of modern data protection law. Its importance for Turkish companies is twofold: it is directly applicable to activities aimed at the EU market, and in intra-group and customer relationships it has become a contractual standard.

Territorial scope

Under Article 3, the Regulation applies to companies not established in the EU when they offer goods or services to persons in the EU or monitor the behaviour of such persons. A Turkish-language website receiving orders from the EU may not, by itself, be sufficient; however, delivery to the EU, euro pricing, marketing aimed at the EU, or tracking via cookies are indicators of coverage.

Main obligations of a non-EU company

Priorities for a covered Turkish company: appointment of an Article 27 representative, adapting privacy notices to GDPR language, a processing inventory, data processor agreements, and transfer safeguards for the flow of data to Türkiye. A 72-hour notification regime must be ready in the event of a breach.

Critical point for the Turkish dimension

KVKK compliance does not automatically ensure GDPR compliance; matters such as the representative, DPIA and transfer mechanisms differ. Building the two bodies of legislation into a single scheme is the most efficient way to avoid duplicated cost.

Roadmap

Start with a scoping analysis; the representative, the set of notices, the inventory and the transfer architecture are then built in a single project. For companies engaged in e-commerce with the EU, the cookie/consent layer and marketing consents are the first items to audit.

Penalties

Breaches are penalised at two tiers: administrative fines of up to EUR 20 million or 4% of total worldwide annual turnover for breaches of the basic principles, data subject rights, and transfer rules; and up to EUR 10 million / 2% for other obligations. National authorities also exercise corrective powers extending as far as a ban on processing.

Related content

For the Turkish dimension, review the KVKK record, and for data-economy rules, the Data Act record. We build dual-legislation compliance into a single scheme in our Data focus area; for those selling online to the EU, our e-commerce guide is a practical starting point.

This record is provided for general information and monitoring only; it does not constitute legal advice or create an attorney–client relationship. The official text in force is authoritative. Contact our team for a scope and compliance assessment specific to your company.
01

Related Practice Areas

We address this regulation together with our expertise in the following practice areas.

02

Focus & Sector Links

This regulation creates a cross-disciplinary focus with a greater impact on certain sectors.

DC
Related Desk · Regional

Data & Cybersecurity Desk

Integrated advice spanning multiple jurisdictions in KVKK and GDPR compliance, cross-border data transfer, and cyber incident response.

Explore the regional desk
Legislation · European Union

EU General Data Protection Regulation (GDPR) — obtain the right legal support.

Let us assess the impact of this regulation on your business and establish a practical compliance framework.