Legislation · Türkiye · Law (No. 6698)

Personal Data Protection Law (KVKK, 6698)

The KVKK (Türkiye's Personal Data Protection Law) is the foundational framework for every company that processes personal data in Türkiye. The March 2024 amendments introduced new legal grounds for special-category data and a new cross-border transfer regime that converges towards the GDPR.

In forceIn force · 07.04.2016Source · RG 29677, 07.04.2016Threshold · All data controllers
In summary

The Law requires a compliance framework built on privacy notices, a legal basis, data security, VERBİS registration and data-subject requests. After 2024, cross-border transfers rest on three pillars: an adequacy decision, appropriate safeguards (including the standard contract — notified to the Board within 5 business days of signature) and incidental situations.

Overview

Law No. 6698 on the Protection of Personal Data sets the framework for the processing of personal data in Türkiye and is supervised by the Personal Data Protection Authority. Although inspired by the GDPR, it operates with its own institutions (VERBİS, Board decisions) and its own procedures.

The 2024 amendments

Law No. 7499, adopted in March 2024, fundamentally amended two areas. In the processing of special-category data, new legal bases, including employment-law obligations, were recognised. For cross-border transfers, a new three-tier regime replaced the old system, which had become blocked in practice: an adequacy decision; appropriate safeguards (binding corporate rules, a standard contract announced by the Board, a written undertaking); and limited incidental cases.

The most critical detail in practice

The standard contract must be notified to the Board within 5 business days of its signing; failure to notify is, in itself, grounds for an administrative penalty. In intra-group flows, contract inventory and notification tracking should be run from a single centre.

Core compliance scheme

Sound KVKK compliance consists of a processing inventory, a privacy-notice and consent architecture, a retention-and-destruction policy, VERBİS registration, data processor agreements, and a breach response plan. Employee data and marketing consents (İYS) are the areas that most frequently give rise to disputes.

Running it together with the GDPR

For companies with German connections, the most efficient approach is to combine KVKK and GDPR requirements into a single compliance scheme, and to build the transfer instruments in both directions (TR→EU, EU→TR) with the same set of contracts.

Penalties

The Law provides for administrative fines — updated each year at the revaluation rate — for breaches relating to the information obligation, data security, VERBİS, and Board decisions; with the 2024 amendments, failure to notify the standard contract within the time limit has also become a separate category of penalty. The Board may also resort to measures such as halting the processing and publishing its decisions.

Related content

For the EU side, read this together with the GDPR record. We address the compliance scheme in our Data focus area, and breach and incident response in our Cybersecurity focus area.

This record is provided for general information and monitoring only; it does not constitute legal advice or create an attorney–client relationship. The official text in force is authoritative. Contact our team for a scope and compliance assessment specific to your company.
01

Related Practice Areas

We address this regulation together with our expertise in the following practice areas.

02

Focus & Sector Links

This regulation creates a cross-disciplinary focus with a greater impact on certain sectors.

DC
Related Desk · Regional

Data & Cybersecurity Desk

Integrated advice spanning multiple jurisdictions in KVKK and GDPR compliance, cross-border data transfer, and cyber incident response.

Explore the regional desk
Legislation · Türkiye

Personal Data Protection Law (KVKK, 6698) — obtain the right legal support.

Let us assess the impact of this regulation on your business and establish a practical compliance framework.