The Law on the Protection of Personal Data, commonly referred to in Turkey as KVKK and regulated under Law No. 6698, is the main legal framework governing the processing of personal data in Turkey. The law was adopted by the Turkish Grand National Assembly on March 24, 2016, and entered into force after being published in the Official Gazette on April 7, 2016. The main purpose of KVKK is to protect the fundamental rights and freedoms of individuals, especially the right to privacy, and to regulate the obligations, procedures and principles that real and legal persons processing personal data must follow.
KVKK aims to prevent personal data from being processed in an unlimited, arbitrary or unclear manner. Individuals may share different types of personal data when using social media, opening a bank account, shopping on an e-commerce website, visiting a healthcare institution or using a mobile application. To prevent this data from being used unlawfully, maliciously or outside its intended purpose, data processing activities must be subject to clear rules. KVKK regulates both the rights of individuals and the responsibilities of parties that process personal data.
Personal data means any information relating to an identified or identifiable natural person. Name, surname, phone number, email address, address, Turkish identity number, customer number, IP address, location data, financial information, transaction history, image records and similar information may be considered personal data. The key point is whether the data can be directly or indirectly linked to a real person. Data belonging to legal entities is not generally considered personal data under KVKK; however, if such data makes a real person identifiable, it may fall within the scope of protection.
Some data types are separately protected under KVKK as special categories of personal data. These include data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. These data types are subject to stricter protection rules because they may create risks of discrimination or rights violations. Therefore, the processing of special categories of personal data requires careful compliance with the conditions and additional security measures set out in the law.
The processing of personal data is not based only on explicit consent. Explicit consent is one of the legal grounds under KVKK, but it is not the only one. Other legal grounds may include processing being clearly provided for by law, being necessary for the establishment or performance of a contract, being required to fulfil a legal obligation, data being made public by the data subject, processing being necessary for the establishment, exercise or protection of a right, or processing being necessary for legitimate interests. Therefore, data controllers should first determine the correct legal basis for each processing activity and rely on explicit consent only where necessary.
Under KVKK, the data controller is the real or legal person that determines the purposes and methods of processing personal data. Data controllers are responsible for ensuring that personal data is processed lawfully, informing data subjects, taking the necessary technical and administrative measures for data security, preparing data processing inventories where required and fulfilling VERBIS obligations in cases specified by the legislation. Responding to data subject requests within the legal period and deleting, destroying or anonymising personal data at the end of the retention period are also among the key obligations.
The transfer of personal data is another important area under KVKK. Personal data transfers within Turkey or abroad must comply with the conditions set out in the law. In particular, the 2024 amendments created a clearer framework for international data transfers, including adequacy decisions, appropriate safeguards, standard contractual clauses, binding corporate rules and exceptional transfer cases. Therefore, international data transfers should not be evaluated only through an explicit consent approach, but together with the current legal transfer mechanisms.
Data subjects, meaning real persons whose personal data is processed, have various rights under KVKK. These include the right to learn whether their personal data is being processed, request information if it has been processed, learn the purpose of processing and whether the data is being used in accordance with that purpose, request correction of incomplete or inaccurate data, request deletion or destruction under certain conditions and claim compensation if they suffer damage due to unlawful processing. These rights aim to strengthen individuals’ control over their own data.
In summary, KVKK is the fundamental data protection law in Turkey that aims to ensure personal data is processed lawfully, transparently, securely and proportionately. For brands, institutions and all parties that process data, KVKK is not only a legal obligation but also a critical issue for trust management. Proper KVKK compliance cannot be achieved only by preparing explicit consent texts; data inventory, information notices, data security, retention and destruction processes, transfer mechanisms and data subject requests should be managed as a whole.