All Regulations
🇹🇷

KVKK

Kişisel Verilerin Korunması Kanunu

Turkey
Effective: April 7, 2016
Active

Turkey's Personal Data Protection Law (KVKK) is the primary legislation governing the processing of personal data in Turkey. Inspired by the EU Data Protection Directive, it establishes a comprehensive framework for data protection, creating the Personal Data Protection Authority (KVKK) as the supervisory body. The law requires registration with VERBİS (Data Controllers Registry) and imposes strict requirements on cross-border data transfers.

Scope

  • Applies to all personal data processing in Turkey
  • Covers both natural and legal persons as data controllers
  • Applies to automated and non-automated processing
  • Extraterritorial application in certain cases
  • Covers special categories of personal data with stricter requirements

Data Subject Rights

  • Right to know whether personal data is processed
  • Right to request information about processing
  • Right to know the purpose of processing
  • Right to know third parties to whom data is transferred
  • Right to request rectification of incomplete or inaccurate data
  • Right to request erasure or destruction
  • Right to object to processing results obtained through automated systems
  • Right to claim compensation for damages

Key Obligations

  • Registration with VERBİS (Data Controllers Registry)
  • Explicit consent for special category data
  • Data breach notification to KVKK within 72 hours
  • Appointment of a data controller representative
  • Cross-border transfer restrictions and Board approval
  • Data retention limitations and destruction obligations
  • Privacy notice requirements (Aydınlatma Metni)
  • Implementation of technical and administrative measures

Penalties

KVKK provides for both administrative and criminal penalties for violations. Administrative fines are updated annually based on revaluation rates.

Maximum Fine
Administrative fines from 427,263 TL to 17,092,242 TL (2026 rates), plus criminal penalties including imprisonment for certain violations

Cross-Border Transfers

Cross-border transfers require explicit consent or adequate protection in the destination country. The KVKK Board maintains a list of countries with adequate protection (currently limited). Binding Corporate Rules (BCR) and undertaking letters can be used for transfers to countries without adequacy decisions.

Supervisory Authority

Personal Data Protection Authority (KVKK)

Visit website →

Need KVKK Compliance?

JUS. helps you comply with KVKK requirements efficiently.

Book a Demo

Compare Regulations

See how KVKK compares to other privacy laws.

Explore in Compliance Hub

View detailed data protection information for Turkey.

Go to Turkey

Simplify KVKK Compliance

Automate compliance workflows, manage data subject requests, and demonstrate compliance with JUS.

Request Demo