Title: The Law on the Protection of Personal Data (KVKK)
Author: Kriko
Published: Mar 4, 2021
Last modified: Jul 13, 2026

---

 1.  [Home](https://kriko.io/) /
 2.  [Glossary](https://kriko.io/glossary) /
 3.  T Letter

# The Law on the Protection of Personal Data **(KVKK)**

**The Law on the Protection of Personal Data**, commonly referred to in Turkey as
KVKK and regulated under Law No. 6698, is the main legal framework governing the
processing of personal data in Turkey. The law was adopted by the Turkish Grand 
National Assembly on March 24, 2016, and entered into force after being published
in the Official Gazette on April 7, 2016. The main purpose of KVKK is to protect
the fundamental rights and freedoms of individuals, especially the right to privacy,
and to regulate the obligations, procedures and principles that real and legal persons
processing personal data must follow.

KVKK aims to prevent personal data from being processed in an unlimited, arbitrary
or unclear manner. Individuals may share different types of personal data when using
social media, opening a bank account, shopping on an e-commerce website, visiting
a healthcare institution or using a mobile application. To prevent this data from
being used unlawfully, maliciously or outside its intended purpose, data processing
activities must be subject to clear rules. KVKK regulates both the rights of individuals
and the responsibilities of parties that process personal data.

Personal data means any information relating to an identified or identifiable natural
person. Name, surname, phone number, email address, address, Turkish identity number,
customer number, IP address, location data, financial information, transaction history,
image records and similar information may be considered personal data. The key point
is whether the data can be directly or indirectly linked to a real person. Data 
belonging to legal entities is not generally considered personal data under KVKK;
however, if such data makes a real person identifiable, it may fall within the scope
of protection.

Some data types are separately protected under KVKK as **special categories of personal
data**. These include data relating to race, ethnic origin, political opinion, philosophical
belief, religion, sect or other beliefs, appearance and dress, membership of associations,
foundations or trade unions, health, sexual life, criminal convictions and security
measures, as well as biometric and genetic data. These data types are subject to
stricter protection rules because they may create risks of discrimination or rights
violations. Therefore, the processing of special categories of personal data requires
careful compliance with the conditions and additional security measures set out 
in the law.

The processing of personal data is not based only on explicit consent. Explicit 
consent is one of the legal grounds under KVKK, but it is not the only one. Other
legal grounds may include processing being clearly provided for by law, being necessary
for the establishment or performance of a contract, being required to fulfil a legal
obligation, data being made public by the data subject, processing being necessary
for the establishment, exercise or protection of a right, or processing being necessary
for legitimate interests. Therefore, data controllers should first determine the
correct legal basis for each processing activity and rely on explicit consent only
where necessary.

Under KVKK, the **data controller** is the real or legal person that determines 
the purposes and methods of processing personal data. Data controllers are responsible
for ensuring that personal data is processed lawfully, informing data subjects, 
taking the necessary technical and administrative measures for data security, preparing
data processing inventories where required and fulfilling VERBIS obligations in 
cases specified by the legislation. Responding to data subject requests within the
legal period and deleting, destroying or anonymising personal data at the end of
the retention period are also among the key obligations.

The transfer of personal data is another important area under KVKK. Personal data
transfers within Turkey or abroad must comply with the conditions set out in the
law. In particular, the 2024 amendments created a clearer framework for international
data transfers, including adequacy decisions, appropriate safeguards, standard contractual
clauses, binding corporate rules and exceptional transfer cases. Therefore, international
data transfers should not be evaluated only through an explicit consent approach,
but together with the current legal transfer mechanisms.

Data subjects, meaning real persons whose personal data is processed, have various
rights under KVKK. These include the right to learn whether their personal data 
is being processed, request information if it has been processed, learn the purpose
of processing and whether the data is being used in accordance with that purpose,
request correction of incomplete or inaccurate data, request deletion or destruction
under certain conditions and claim compensation if they suffer damage due to unlawful
processing. These rights aim to strengthen individuals’ control over their own data.

In summary, **KVKK** is the fundamental data protection law in Turkey that aims 
to ensure personal data is processed lawfully, transparently, securely and proportionately.
For brands, institutions and all parties that process data, KVKK is not only a legal
obligation but also a critical issue for trust management. Proper KVKK compliance
cannot be achieved only by preparing explicit consent texts; data inventory, information
notices, data security, retention and destruction processes, transfer mechanisms
and data subject requests should be managed as a whole.

## Discover it in the dictionary

###  NoSQL

NoSQL refers to database systems that operate outside the traditional relational
database model and are used to store, manage and query different types of…

###  Blacklist

A blacklist, also increasingly referred to as a blocklist, is a list that includes
IP addresses, domains, URLs or email servers associated with spam,…

###  Customer Retention Rate

Customer Retention Rate is an important customer loyalty metric that shows how successfully
a business keeps its existing customers over a specific period. This…

###  Open Graph

Open Graph, commonly abbreviated as OG, is a metadata protocol used to define how
web pages appear on social media platforms and messaging applications.…

###  Data Warehouse

A data warehouse, commonly abbreviated as DWH, is a data management system that 
brings information from different sources together for analysis and reporting. Companies…

###  Agile Project Management

Agile project management is an approach in which projects are divided into smaller
parts and managed through continuous feedback and improvement cycles so that…

###  Google Display Network (GDN)

Google Display Network, commonly abbreviated as GDN, is an advertising network that
allows advertisers to show visual, text, responsive, video or rich media ads…

###  Natural Language Processing (NLP)

Natural Language Processing, or NLP, is a field of artificial intelligence that 
enables computer systems to understand and communicate using human language. It 
is…

###  Client-side Errors: 4xx

4xx status codes are the group of HTTP status codes that represent client-side error
responses. When a user tries to access a web page…

## Track the digital heartbeat  with Kriko

Subscribe to receive curated insights, news, and ideas shaping the digital landscape.

  By checking this box, you acknowledge and accept our [privacy policy](https://kriko.io/privacy-policy).