Turkey's Personal Data Protection Law No. 6698 (KVKK) divides the parties in a personal data processing operation into two core roles: the data controller and the data processor. This distinction is not merely a theoretical labelling exercise; each role gives rise to different legal obligations, different contract requirements and different levels of liability. Correctly identifying your own role is the precondition for doing everything else right, from VERBİS registration to the duty to inform, and from security measures to breach notification. In this article we define both roles, clarify the differences between them, and explain with examples which party must do what in practice.
Who Is the Data Controller?
The data controller is the party that determines the purposes and means of processing personal data. In other words, the controller is the decision-maker who answers the questions "which data, for what purpose, and for how long will it be processed?" If an e-commerce company decides to process customer data for marketing, that company is the controller.
Key features of the controller:
- Determines the purpose of processing
- Decides which tools and methods will be used
- Bears primary responsibility toward the data subject
- Is responsible for fulfilling the duty to inform
Who Is the Data Processor?
The data processor is the natural or legal person who processes personal data on the authority granted by the controller and in line with the controller's instructions. The processor does not set its own purposes; it merely carries out the assigned task within defined limits. A cloud service provider, an accounting firm providing payroll services, or a call centre are typical examples of processors.
Defining features of the processor:
- Works on the controller's instructions, not for its own purposes
- The limits of processing are set by the controller
- May not use the data outside those instructions
- Shares responsibility with the controller for data security
The Core Differences Between the Two Roles
The table below summarises the most critical distinctions:
| Criterion | Data Controller | Data Processor |
|---|---|---|
| Setting the means | Sets them | Acts within the controller's framework |
| Decision authority | Has it | Limited to instructions |
| Duty to inform | Rests with it | As a rule rests with the controller |
| VERBİS registration | Obliged if criteria are met | As a rule the controller registers |
| Liability to the data subject | Primary | Joint with controller (security) |
Why Does This Distinction Matter So Much?
Misidentifying the role leads to misallocating obligations. For example, an organisation that wrongly believes it is a "processor" may fail to meet the duty to inform even though it is in fact the controller. Conversely, a supplier acting as a processor that steps outside the controller's instructions and uses the data for its own purposes may itself become a controller for that processing. That is why role identification is something to settle before the contract is signed.
What a Data Processor Agreement Should Contain
A written contract between the controller and the processor is expected, and it should include security commitments. A good processor agreement should contain at minimum:
- A clear definition of the subject, duration and purpose of the processing
- A commitment that the processor will act only on the controller's instructions
- An obligation to apply appropriate technical and administrative security measures
- A confidentiality obligation binding on staff
- Sub-processor use made subject to the controller's approval
- Return or disposal of the data when processing ends
- Notification to the controller without delay in the event of a breach
Example Scenario
An online education platform collects student registrations and course-progress data for purposes it defines itself. The platform works with a newsletter provider to run its email campaigns and outsources invoicing to an accounting office.
In this scenario:
- The education platform is the controller: it decides which data to collect and for what purpose.
- The newsletter provider and the accounting office are processors: they use the transferred data only on the platform's instructions.
If the newsletter provider used this email list to market to another client without the platform's permission, it would become a controller for that processing and take on direct liability.
Frequently Asked Questions
Can an organisation be both a controller and a processor at the same time?
Yes. An organisation can be the controller for its own employees' data while acting as a processor for a client's data when serving that client. The role is assessed separately for each processing activity.
Whom does the processor notify in a breach?
The processor must notify the controller without delay of any breach it becomes aware of. Notifying the relevant authority and the affected individuals is, as a rule, the controller's responsibility.
Does the processor make the VERBİS registration?
As a rule, the obligation to register with VERBİS rests with the controller. The processor appears as part of the activities carried out under the controller's registration and is separately obliged to apply security measures.
Is an overseas cloud provider a processor?
A cloud provider is a processor if it processes data only on the controller's instructions and on its behalf. However, where a cross-border transfer is involved, the KVKK's transfer rules must be assessed separately.
This content is for general information only and does not constitute legal advice.
To clarify your roles, manage your processor agreements and track your compliance processes from one place, you can request a JUS. demo.