Home/Resources/Articles/International Data Transfers Under KVKK: The New Regime, Standard Contracts and Undertakings
Back to Articles
Uluslararası & Yurt Dışı Aktarım11 min read

International Data Transfers Under KVKK: The New Regime, Standard Contracts and Undertakings

A step-by-step explanation of KVKK's cross-border transfer regime after the 2024 reform — adequacy decisions, standard contracts, binding corporate rules and incidental derogations.

JUS. Hukuk Ekibi
Uyum ve Veri Koruma
June 2, 2026
International Data Transfers Under KVKK: The New Regime, Standard Contracts and Undertakings

Cross-border data transfer was historically the most debated topic under KVKK. With the 2024 amendment, the regime gained a tiered structure similar to the GDPR. You no longer have to obtain explicit consent for every transfer; choosing the right safeguard mechanism is a more sustainable path. This guide explains the tiers of the new regime, which mechanism to use when, and the practical steps.

What Is a Transfer and When Does It Arise?

Using a cloud provider, sending HR data to a group company abroad, writing customer data to a global CRM, or using a foreign e-mail/marketing tool are all cross-border transfers. What matters is where the data is physically processed/stored. Writing a Turkish user's data to a server abroad counts as a transfer.

Why the Old Approach Was Unsustainable

Before the reform, many companies tried to obtain explicit consent for every cross-border transfer. This was both legally fragile (consent can be withdrawn at any time) and practically near-impossible: collecting separate valid consent from all employees and customers for a single cloud service was unrealistic. The new regime resolves this bottleneck with appropriate safeguard mechanisms, as in the GDPR.

The Tiers of the New Regime

TierMechanismWhen?
2Appropriate safeguardsStandard contract, binding corporate rules, undertaking
3Incidental derogationsSpecific, limited and non-recurring situations

1) Adequacy Decision

If the Board has issued an adequacy decision for the destination country, international organisation or sector, the transfer can rely on it. This is the most practical route; but the areas covered by adequacy decisions may be limited.

2) Appropriate Safeguards

Where there is no adequacy decision, the parties provide one of the appropriate safeguards:

  • Standard contract: Signing the text published by the Board. After signing, there is an obligation to notify the Board within a set period. Skipping this notification step is the most common procedural mistake.
  • Binding corporate rules (BCR): Rules subject to Board approval for transfers among companies in the same group. Suitable for multinational groups.
  • Undertaking: A written undertaking subject to Board authorisation.

3) Incidental Derogations

In cases such as explicit consent, necessity for the performance of a contract, or overriding public interest, incidental (one-off/non-recurring) transfers are possible. These are not suitable for routine, continuous transfers — for example, day-to-day use of a cloud service cannot rely on an incidental derogation.

What Should You Do, Step by Step?

  1. Map your transfers: Which data goes to which country, to which provider? Don't forget cloud and SaaS tools.
  2. Determine the tier: Is there an adequacy decision for the destination? If not, which safeguard is appropriate?
  3. Apply the mechanism: Sign the standard contract or follow the BCR/undertaking route.
  4. Fulfil the notification obligation: Notify the standard contract to the Board within the deadline.
  5. Document and review: Keep the transfer inventory alive; repeat the process whenever a new provider is added.

Example Scenario: Migrating to a Global CRM

Your sales team wants to move to a foreign-headquartered CRM. The right order: first clarify the provider's data location, check whether an adequacy decision exists, and if not, sign the standard contract, notify the Board and record the transfer in your inventory. Moving customer data to the CRM before completing these steps creates a transfer without a lawful basis.

Common Mistakes

  • Reflexively obtaining explicit consent for every transfer.
  • Assuming cloud/SaaS use is "not a transfer".
  • Signing the standard contract but forgetting to notify the Board.
  • Using an incidental derogation for continuous transfers.
  • Overlooking sub-processor transfers (other foreign services the provider uses).

Frequently Asked Questions

Is using a cloud service a cross-border transfer?

If the servers are abroad, yes. Clarify the data location of the provider and any sub-processors.

Is explicit consent still a valid route?

Yes, within incidental derogations; but for routine and continuous transfers, appropriate safeguards (standard contract/BCR) should be preferred.

Is signing the standard contract enough?

Signing alone is not enough; you must also fulfil the obligation to notify the Board within the deadline.

What should I use for intra-group transfers?

For multinational groups, binding corporate rules (BCR) are an appropriate mechanism; they provide consistent protection across the group.

This content is for general information only and does not constitute legal advice. With JUS. you can build your transfer inventory and document the appropriate safeguard mechanism — request a demo.

Share this article

Need Help?

JUS. can help you implement best practices for compliance.

Book a Demo
Request Demo