The 2024 reform of Turkey's Personal Data Protection Law (Law No. 6698) restructured cross-border transfers of personal data. Transfers now follow a tiered system: first an adequacy decision, then appropriate safeguards, and finally incidental (exceptional) situations. In practice, the appropriate-safeguard mechanism Turkish companies rely on most is the standard contract. This guide walks through what a standard contract is, how to prepare one, and how to notify it to the Board, step by step.
The Tiered System for Cross-Border Transfers
After the reform, cross-border transfers follow a three-tier logic. For each transfer you first assess whether the higher tier applies; if not, you move to the next one down.
- Adequacy decision: The Board decides that a given country, sector, or international organisation provides adequate protection. If such a decision exists, the transfer can be made directly.
- Appropriate safeguards: Absent an adequacy decision, data may be transferred using tools such as the standard contract, binding corporate rules, or an undertaking.
- Incidental (exceptional) situations: Where none of the above apply, transfer is possible only in limited cases (explicit consent, performance of a contract, public interest, and similar).
The standard contract sits in the second tier and is the most widely used tool, because adequacy decisions are still limited in number and binding corporate rules take longer due to their approval process.
What Is a Standard Contract?
A standard contract is a transfer instrument based on pre-set text announced by the Board that the parties cannot alter. Its purpose is to place the recipient abroad under obligations equivalent to the protection standards in Turkey.
The standard contract has different modules depending on the direction of the transfer and the roles of the parties:
| Module | Exporter (Turkey) | Importer (Abroad) |
|---|---|---|
| 2 | Data controller | Data processor |
| 3 | Data processor | Data processor |
| 4 | Data processor | Data controller |
Choosing the right module is critical: the capacity in which each party acts (controller or processor) determines the scope of the obligations.
What to Do Before Preparation
Building a solid foundation before signing prevents compliance gaps from surfacing later.
- Clarify the transferred data categories and data-subject groups in your inventory.
- Document the purpose, legal basis, and retention period of the transfer.
- Assess the level of protection under the legislation of the recipient's country.
- Define technical and administrative measures (encryption, access control, logging).
- Identify internal owners and the approval flow.
Step by Step: How to Prepare a Standard Contract
- Map the transfer. Determine what data, to whom, to which country, and for what purpose is being transferred.
- Select the correct module. Choose the module based on whether the parties are controllers or processors.
- Use the Board's text. Use the standard contract text published by the Board without changes; only the annexes and blank fields are filled in.
- Complete the annexes. Write the subject of the transfer, data categories, and technical and administrative measures in concrete terms.
- Have authorised signatories sign. The contract must be signed by both parties with a wet signature or a valid electronic signature.
- Notify the Board within the set period. Provide notification within a set period from the signing date (see below).
- Keep records. Store the signed contract and proof of notification in your accountability file.
The Notification Obligation to the Board
The standard contract itself is not subject to the Board's approval; however, once signed it must be notified to the Board within a set period. Notification is a procedural requirement for the contract to be recognised as a valid transfer safeguard.
Always confirm the current notification period from the Board's regulation in force; if the period is missed, the legal basis of the transfer may become disputable.
After notification, the parties' obligations continue: compliance with the contract terms, responding to data-subject rights, and meeting audit requests are ongoing.
Common Mistakes
In practice, the most frequent mistakes usually stem from procedural and documentation gaps. Knowing them in advance speeds up the process.
- Wrong module choice: Misjudging whether a party is a controller or processor can render the contract invalid from the outset.
- Altering the text: Changing the clauses in the Board's text weakens the validity of the safeguard; only the annexes should be filled in.
- Leaving annexes abstract: Writing data categories and technical measures vaguely may be treated as a deficiency in an audit.
- Neglecting notification: Failing to notify within the set period after signing makes the transfer's legal basis disputable.
- Not keeping records: Failing to retain the signed copy and proof of notification undermines the accountability principle.
Example Scenario
An Ankara-based e-commerce company processes customer support tickets on the servers of a SaaS provider located abroad. The company is the data controller and the provider is the data processor. No adequacy decision exists for the relevant country.
The company proceeds as follows: it first maps the transfer, then selects the Module 2 (controller to processor) standard contract. It fills in the annexes without altering the Board's text; the transferred data categories (name, email, order details) and technical measures (end-to-end encryption, role-based access) are written out concretely. The contract is signed by both parties and notified to the Board within the set period from the signing date. The company keeps the signed copy and proof of notification in its accountability file.
Frequently Asked Questions
Can I modify the text of the standard contract?
No. The standard contract is based on the text announced by the Board and its clauses cannot be changed. Only the blanks in the annexes (parties, data categories, measures, and so on) are filled in. Additional provisions contrary to the text may weaken the validity of the safeguard.
Is the standard contract subject to the Board's approval?
The standard contract is subject to notification, not approval. That is, it is enough to notify the Board within a set period after signing; you do not need to wait for a separate approval. In this respect it differs from binding corporate rules.
Is a single contract enough for multiple transfers to the same provider?
As long as the scope and purpose of the transfer and the parties' capacities remain the same, a single standard contract can cover multiple transfers. However, when new data categories or a different processing purpose are added, the contract and annexes must be updated.
What happens if I miss the notification period?
If the period is missed, the claim that the transfer rests on an appropriate safeguard becomes disputable and a non-compliance risk arises. In that case you should notify without delay, review the legal basis of the transfer, and seek legal support if necessary.
This content is for general information purposes only and does not constitute legal advice.
Request a demo of JUS. today to manage your cross-border transfer inventory, standard contract modules, and Board notification processes from a single dashboard.