Why You Need a KVKK Glossary
Turkey's Personal Data Protection Law No. 6698 (KVKK) speaks its own language. Terms like "data controller", "explicit consent" and "special categories of personal data" may sound similar in everyday speech, but under the law each has a precise definition and triggers different obligations. Confusing these concepts can cause serious problems both in your compliance work and during a possible audit.
This glossary explains roughly 25 core concepts you will encounter most often in the KVKK compliance journey, organised into groups. The goal is to help your teams speak a common language and use each term in the correct context.
Actors and Roles
Data Controller
The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system. The party that decides "why and how" data is processed is the controller, and the vast majority of obligations rest with this party.
Data Processor
The natural or legal person who processes personal data on behalf of the controller based on the authority granted by it. A cloud provider, a payroll accounting firm or an email marketing tool is often a data processor. A processor acts only within the controller's instructions.
Data Subject
The natural person whose personal data is processed. Your customer, your employee, a visitor to your website; they are all data subjects. The rights under KVKK (to request information, rectification, erasure and so on) belong to the data subject.
Contact Person
The individual reported to represent a controller with a VERBIS registration obligation and to maintain communication with the Authority. A contact person is not the controller's legal representative; it is merely a point of contact.
Core Data Types
Personal Data
Any information relating to an identified or identifiable natural person. Name, national ID number, phone, email, location, IP address and even a cookie identifier can count as personal data.
Special Categories of Personal Data
Sensitive data that carries a risk of discrimination or harm to the data subject when processed. Data on health, sexual life, religion, sect, philosophical belief, political opinion, race, ethnic origin, appearance, association/foundation/union membership, criminal convictions and biometric-genetic data fall into this category. As a rule, such data cannot be processed without explicit consent or the limited exceptions set out in law, and it requires stronger security measures.
Anonymisation
Rendering personal data such that it can under no circumstances be linked to an identified or identifiable natural person, even when matched with other data. Anonymous data is no longer personal data and falls outside the scope of KVKK. Anonymisation must be irreversible.
Processing Activities
Processing
Any activity performed on personal data from collection to destruction: recording, storing, altering, disclosing, transferring and classifying are all "processing".
Transfer
The disclosure of personal data to another party. Sending data to a group company, a supplier or a service provider counts as a transfer and is subject to specific legal conditions.
Cross-Border Transfer
The transfer of personal data to a party outside Turkey. Even storing data on a cloud server located abroad constitutes a cross-border transfer and requires the additional conditions in the law to be met.
Destruction (Erasure / Disposal / Anonymisation)
Removing personal data once its retention period expires or the reason for processing disappears. Destruction is carried out through erasure, disposal or anonymisation, and should be run regularly via periodic destruction processes.
Retention Period
How long a piece of personal data will be kept, in line with the processing purpose and obligations in the relevant legislation. When the purpose ends and the legal retention period expires, the data must be destroyed.
Legal Grounds and Obligations
Explicit Consent
Consent on a specific matter, based on information and expressed with free will. Explicit consent cannot be made conditional, cannot be a precondition of a service and can be withdrawn at any time. Consent is only one of many grounds for processing; not every processing activity requires it.
Duty to Inform
The controller's obligation to inform the data subject, before processing, about its identity, the purposes of processing, the recipients, the collection method and legal ground, and the data subject's rights. The duty to inform is a one-way notice and must be fulfilled independently of consent.
Explicit Consent vs. the Duty to Inform
This is the most frequently confused pair. Informing is a notice and is mandatory in almost every processing activity; no approval is sought. Explicit consent, however, is a legal ground and is required only when no other processing condition exists. The information notice and the consent statement must be presented separately, never intertwined.
Legitimate Interest
Where a controller's legitimate interest can serve as a basis for processing, provided it does not harm the fundamental rights and freedoms of the data subject. A balancing test is expected when relying on this ground; legitimate interest is not an unlimited authority.
Registration, Risk and Breach
VERBIS
The Data Controllers Registry Information System. A public registry where controllers meeting the criteria set out in law record their processing activities.
Data Inventory
A detailed record in which the controller links the personal data it processes, the purposes, the data categories, the recipients and the retention periods. It forms the basis of the VERBIS notification and of the entire compliance effort.
DPIA / Data Impact Assessment
A structured assessment that analyses in advance the likely effects of high-risk processing on individuals in order to reduce risks. It is especially important in processes involving special categories of data or large-scale profiling.
Data Breach
The unlawful acquisition of personal data by others. As a rule, notification to the Board must be made as soon as possible and reasonably within 72 hours of becoming aware of the breach; notification to affected data subjects may also be required.
Institutional Structure
The Board
The Personal Data Protection Board. The decision-making body that applies the law, issues principle decisions and imposes sanctions.
The Authority
The Personal Data Protection Authority. The administrative organisation that carries out the Board's decisions.
Seeing the Concepts Together
| Concept | Short Definition | Relates To |
|---|---|---|
| Data processor | Processes on the controller's behalf | Service provider |
| Data subject | Person whose data is processed | Rights holder |
| Explicit consent | Informed approval | Legal ground |
| Duty to inform | Prior notice | Obligation |
| Special category data | Sensitive data | Data type |
| VERBIS | Public registry | Registration system |
Steps to Use the Terms Correctly
- Clarify who is the controller and who is the processor in your processes.
- Determine a legal ground for each processing activity and avoid leaning on explicit consent unnecessarily.
- Design information notices and consent statements as separate documents.
- Flag special categories of data as a distinct category and plan additional security measures.
- Keep your data inventory current and define retention periods for each category.
- Put the notification flow to follow in a breach into writing in advance.
Example Scenario
A software company keeps employee payroll in a cloud-based HR tool hosted abroad. Here the company is the "data controller", the cloud provider is the "data processor" and the employees are the "data subjects". Keeping payroll data on a server abroad constitutes a "cross-border transfer". Because employees' medical reports are "special categories of data", additional security measures are needed. The company records its processing in a "data inventory" and declares it in VERBIS. If the system suffers a leak, it is a "data breach" and must be notified to the Board reasonably within 72 hours.
Frequently Asked Questions
Is explicit consent required for every processing activity?
No. Explicit consent is only one of the legal grounds. If another condition exists, such as performance of a contract, a legal obligation or legitimate interest, consent is not separately sought. Collecting unnecessary consent can make compliance harder.
Can the same party be both processor and controller?
An organisation can be a controller in some processes and a processor acting on behalf of another controller in others. What matters is determining the role correctly for each activity.
Is an IP address personal data?
To the extent it makes it possible to reach an identifiable person, an IP address can be treated as personal data. Online identifiers should therefore be handled with caution.
Is anonymous data within the scope of KVKK?
Data that is genuinely and irreversibly anonymised is not personal data and falls outside KVKK. However, if there is a re-identification risk, the data is still considered personal data.
This content is for general informational purposes only and does not constitute legal advice.
With JUS. you can request a free demo to manage your personal data inventory, information notices and consent processes from a single dashboard.