Home/Resources/Articles/KVKK Glossary: Key Concepts and Definitions
Back to Articles
KVKK10 min read

KVKK Glossary: Key Concepts and Definitions

A practical glossary that groups and explains the 25 most critical KVKK concepts, from data controller and explicit consent to VERBIS and cross-border transfer.

JUS. Hukuk Ekibi
Uyum ve Veri Koruma
January 15, 2026
KVKK Glossary: Key Concepts and Definitions

Why You Need a KVKK Glossary

Turkey's Personal Data Protection Law No. 6698 (KVKK) speaks its own language. Terms like "data controller", "explicit consent" and "special categories of personal data" may sound similar in everyday speech, but under the law each has a precise definition and triggers different obligations. Confusing these concepts can cause serious problems both in your compliance work and during a possible audit.

This glossary explains roughly 25 core concepts you will encounter most often in the KVKK compliance journey, organised into groups. The goal is to help your teams speak a common language and use each term in the correct context.

Actors and Roles

Data Controller

The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system. The party that decides "why and how" data is processed is the controller, and the vast majority of obligations rest with this party.

Data Processor

The natural or legal person who processes personal data on behalf of the controller based on the authority granted by it. A cloud provider, a payroll accounting firm or an email marketing tool is often a data processor. A processor acts only within the controller's instructions.

Data Subject

The natural person whose personal data is processed. Your customer, your employee, a visitor to your website; they are all data subjects. The rights under KVKK (to request information, rectification, erasure and so on) belong to the data subject.

Contact Person

The individual reported to represent a controller with a VERBIS registration obligation and to maintain communication with the Authority. A contact person is not the controller's legal representative; it is merely a point of contact.

Core Data Types

Personal Data

Any information relating to an identified or identifiable natural person. Name, national ID number, phone, email, location, IP address and even a cookie identifier can count as personal data.

Special Categories of Personal Data

Sensitive data that carries a risk of discrimination or harm to the data subject when processed. Data on health, sexual life, religion, sect, philosophical belief, political opinion, race, ethnic origin, appearance, association/foundation/union membership, criminal convictions and biometric-genetic data fall into this category. As a rule, such data cannot be processed without explicit consent or the limited exceptions set out in law, and it requires stronger security measures.

Anonymisation

Rendering personal data such that it can under no circumstances be linked to an identified or identifiable natural person, even when matched with other data. Anonymous data is no longer personal data and falls outside the scope of KVKK. Anonymisation must be irreversible.

Processing Activities

Processing

Any activity performed on personal data from collection to destruction: recording, storing, altering, disclosing, transferring and classifying are all "processing".

Transfer

The disclosure of personal data to another party. Sending data to a group company, a supplier or a service provider counts as a transfer and is subject to specific legal conditions.

Cross-Border Transfer

The transfer of personal data to a party outside Turkey. Even storing data on a cloud server located abroad constitutes a cross-border transfer and requires the additional conditions in the law to be met.

Destruction (Erasure / Disposal / Anonymisation)

Removing personal data once its retention period expires or the reason for processing disappears. Destruction is carried out through erasure, disposal or anonymisation, and should be run regularly via periodic destruction processes.

Retention Period

How long a piece of personal data will be kept, in line with the processing purpose and obligations in the relevant legislation. When the purpose ends and the legal retention period expires, the data must be destroyed.

Legal Grounds and Obligations

Explicit Consent

Consent on a specific matter, based on information and expressed with free will. Explicit consent cannot be made conditional, cannot be a precondition of a service and can be withdrawn at any time. Consent is only one of many grounds for processing; not every processing activity requires it.

Duty to Inform

The controller's obligation to inform the data subject, before processing, about its identity, the purposes of processing, the recipients, the collection method and legal ground, and the data subject's rights. The duty to inform is a one-way notice and must be fulfilled independently of consent.

Explicit Consent vs. the Duty to Inform

This is the most frequently confused pair. Informing is a notice and is mandatory in almost every processing activity; no approval is sought. Explicit consent, however, is a legal ground and is required only when no other processing condition exists. The information notice and the consent statement must be presented separately, never intertwined.

Legitimate Interest

Where a controller's legitimate interest can serve as a basis for processing, provided it does not harm the fundamental rights and freedoms of the data subject. A balancing test is expected when relying on this ground; legitimate interest is not an unlimited authority.

Registration, Risk and Breach

VERBIS

The Data Controllers Registry Information System. A public registry where controllers meeting the criteria set out in law record their processing activities.

Data Inventory

A detailed record in which the controller links the personal data it processes, the purposes, the data categories, the recipients and the retention periods. It forms the basis of the VERBIS notification and of the entire compliance effort.

DPIA / Data Impact Assessment

A structured assessment that analyses in advance the likely effects of high-risk processing on individuals in order to reduce risks. It is especially important in processes involving special categories of data or large-scale profiling.

Data Breach

The unlawful acquisition of personal data by others. As a rule, notification to the Board must be made as soon as possible and reasonably within 72 hours of becoming aware of the breach; notification to affected data subjects may also be required.

Institutional Structure

The Board

The Personal Data Protection Board. The decision-making body that applies the law, issues principle decisions and imposes sanctions.

The Authority

The Personal Data Protection Authority. The administrative organisation that carries out the Board's decisions.

Seeing the Concepts Together

ConceptShort DefinitionRelates To
Data processorProcesses on the controller's behalfService provider
Data subjectPerson whose data is processedRights holder
Explicit consentInformed approvalLegal ground
Duty to informPrior noticeObligation
Special category dataSensitive dataData type
VERBISPublic registryRegistration system

Steps to Use the Terms Correctly

  1. Clarify who is the controller and who is the processor in your processes.
  2. Determine a legal ground for each processing activity and avoid leaning on explicit consent unnecessarily.
  3. Design information notices and consent statements as separate documents.
  4. Flag special categories of data as a distinct category and plan additional security measures.
  5. Keep your data inventory current and define retention periods for each category.
  6. Put the notification flow to follow in a breach into writing in advance.

Example Scenario

A software company keeps employee payroll in a cloud-based HR tool hosted abroad. Here the company is the "data controller", the cloud provider is the "data processor" and the employees are the "data subjects". Keeping payroll data on a server abroad constitutes a "cross-border transfer". Because employees' medical reports are "special categories of data", additional security measures are needed. The company records its processing in a "data inventory" and declares it in VERBIS. If the system suffers a leak, it is a "data breach" and must be notified to the Board reasonably within 72 hours.

Frequently Asked Questions

Is explicit consent required for every processing activity?

No. Explicit consent is only one of the legal grounds. If another condition exists, such as performance of a contract, a legal obligation or legitimate interest, consent is not separately sought. Collecting unnecessary consent can make compliance harder.

Can the same party be both processor and controller?

An organisation can be a controller in some processes and a processor acting on behalf of another controller in others. What matters is determining the role correctly for each activity.

Is an IP address personal data?

To the extent it makes it possible to reach an identifiable person, an IP address can be treated as personal data. Online identifiers should therefore be handled with caution.

Is anonymous data within the scope of KVKK?

Data that is genuinely and irreversibly anonymised is not personal data and falls outside KVKK. However, if there is a re-identification risk, the data is still considered personal data.

This content is for general informational purposes only and does not constitute legal advice.

With JUS. you can request a free demo to manage your personal data inventory, information notices and consent processes from a single dashboard.

Share this article

Need Help?

JUS. can help you implement best practices for compliance.

Book a Demo
Request Demo