Protecting personal data is not merely a matter of complying with a legal text; it is a continuously operating security function. Turkey's Personal Data Protection Law No. 6698 (KVKK) obliges data controllers to take all necessary technical and administrative measures to prevent the unlawful processing of and access to personal data and to ensure that data is stored securely. These two concepts complement each other: without technical measures, administrative rules remain on paper, and without an administrative framework, technical tools become scattered and unsustainable.
Drawing on the guidance approach of the Turkish Data Protection Board, this guide groups administrative and technical measures, offers an implementation roadmap and provides a practical checklist.
A Two-Pillar Approach: Administrative and Technical
Data security measures rest on two fundamental pillars. Administrative measures are people- and process-oriented; they define who accesses which data and why, how employees should behave and what to do in the event of a breach. Technical measures are system- and infrastructure-oriented; they cover tools such as encrypting data, restricting access and defending against attacks.
In the Board's approach, these two groups are assessed together rather than in isolation. Compliance is achieved not by buying a single tool but by designing the two pillars to reinforce each other.
Administrative Measures
Administrative measures establish the organization's rules and processes for data security. Key items include:
- Personal data processing inventory and policies: Documenting which data is processed, for what purpose and for how long, and putting retention and destruction policies in writing.
- Staff training and awareness: Regularly training employees on KVKK and data security, and raising awareness against threats such as phishing.
- Confidentiality agreements and undertakings: Signing agreements containing confidentiality clauses with employees and business partners.
- Authorization matrix and access policy: Defining who can access which data based on the "need to know" principle.
- Agreements with data processors: Written contracts regulating data security obligations with suppliers and service providers.
- Breach response plan: Defining in advance the steps and notification processes to follow in the event of a security breach.
Technical Measures
Technical measures put administrative decisions into practice across systems:
- Access control and authorization: User-based authorization, strong password policies and multi-factor authentication (MFA).
- Encryption: Encrypting data both at rest and in transit.
- Logging and monitoring: Keeping access and transaction records so that anomalous behavior can be detected.
- Backups: Resilience against data loss through regular, tested backups.
- Network security: Firewalls, intrusion detection/prevention systems and network segmentation.
- Penetration testing and vulnerability scanning: Regularly testing systems against external and internal threats.
- Physical security: Restricting physical access to server rooms and data storage areas.
- Up-to-date software and patch management: Closing known vulnerabilities in a timely manner.
Mapping Administrative to Technical Measures
The table below shows which technical measure supports each administrative objective:
| Administrative Objective | Supporting Technical Measure |
|---|---|
| Breach response plan | Logging, monitoring, alerting systems |
| Retention-destruction policy | Automated deletion, backup rotation |
| Supplier management | Network segmentation, access restrictions |
| Staff awareness | Phishing simulation, email filtering |
Implementation Roadmap
A practical sequence for putting the measures into practice:
- Build an inventory: Map all personal data processed, its sources and where it is stored.
- Perform a risk analysis: Assess possible threats and impact levels for each data category.
- Write the policies: Document access, retention, destruction and breach response policies.
- Deploy technical controls: Turn on encryption, access control, logging and backups.
- Train your staff: Launch regular training and awareness programs.
- Test: Validate the effectiveness of controls through penetration testing and vulnerability scanning.
- Monitor and improve: Continuously monitor logs and alerts and improve based on findings.
Example Scenario
A mid-sized e-commerce company begins by preparing a data inventory to protect customer data. The inventory reveals that payment information is stored unencrypted and that all employees can access the customer database. On the administrative side, the company creates an authorization matrix that limits access to relevant teams only and requires confidentiality undertakings to be signed. On the technical side, it encrypts the database, mandates MFA and starts monitoring access logs. A penetration test carried out a few months later uncovers a critical vulnerability before it reaches production. In this way, the two-pillar approach strengthens both processes and systems together.
Frequently Asked Questions
Which is more important, administrative or technical measures?
Both are equally necessary and complement each other. Technical measures implement administrative decisions; the administrative framework ensures consistent and sustainable use of technical tools. Focusing on only one means incomplete compliance.
Does a small business have to take all these measures?
The scope of measures should be proportionate to the nature and risk of the data processed. However, measures such as access control, backups, encryption and basic staff awareness are necessary for every business regardless of scale.
How often should penetration testing be performed?
The general approach is to test at regular intervals (for example, annually or after significant system changes). Continuous monitoring and vulnerability scanning maintain the security level between tests.
What should be done first if a breach occurs?
The pre-prepared breach response plan should be activated; the scope of the incident should be determined, affected systems isolated and the notification obligations set out in the legislation assessed. Logs are critical at this stage for understanding the scope of the incident.
This content is for general information purposes only and does not constitute legal advice.
Request a free demo to manage your administrative and technical data security measures in a single compliance dashboard with JUS.