| name | turkey-kvkk |
| title | Turkey KVKK Compliance |
| description | Implements compliance with Turkey's Personal Data Protection Law (Kisisel Verilerin Korunmasi Kanunu, KVKK, Law No. 6698). Covers data controller obligations, data subject rights, VERBIS registration, cross-border transfer restrictions, Board decisions, and administrative fines. Keywords: KVKK, Turkey, VERBIS, data controller registry, Board decision, cross-border. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/plugins/privacy-skills-complete/skills/turkey-kvkk |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | tr |
| practice | data-protection |
| language | en |
Turkey KVKK Compliance
Overview
The Kisisel Verilerin Korunmasi Kanunu (KVKK), Law No. 6698, is Turkey's comprehensive personal data protection law. It was published in the Official Gazette on 7 April 2016 and entered into force on the same date. The KVKK is modelled on the EU Data Protection Directive 95/46/EC and shares structural similarities with the GDPR, though there are significant differences in cross-border transfer mechanisms, consent requirements, and the role of the Personal Data Protection Authority (Kisisel Verileri Koruma Kurumu, KVKK Authority) and its decision-making body, the Personal Data Protection Board (Kurul).
Turkey applied for EU membership in 1987, and the KVKK was enacted partly to align with EU data protection standards. However, Turkey has not received an adequacy decision from the European Commission under GDPR Article 45, which creates complexity for EU-Turkey data flows.
Key Definitions
| Turkish Term | English | GDPR Equivalent |
|---|
| Kisisel veri | Personal data | Personal data (Art. 4(1)) |
| Ozel nitelikli kisisel veri | Special category personal data | Special category data (Art. 9) |
| Veri sorumlusu | Data controller | Controller (Art. 4(7)) |
| Veri isleyen | Data processor | Processor (Art. 4(8)) |
| Ilgili kisi | Data subject / Relevant person | Data subject |
| Acik riza | Explicit consent | Consent |
| VERBIS | Data Controllers Registry | No direct equivalent (registration system) |
Lawful Bases for Processing (Article 5)
Processing of personal data is prohibited without the explicit consent of the data subject, except where:
- Expressly provided by law — processing is clearly laid down in legislation
- Necessary for protection of life or physical integrity — where the data subject or another person is physically or legally incapable of giving consent
- Necessary for performance of a contract — directly related to establishing or performing a contract
- Necessary for the controller to fulfil a legal obligation
- Data made public by the data subject — manifestly made public
- Necessary for establishment, exercise, or defence of a right
- — provided this does not violate fundamental rights and freedoms of the data subject