Companies operating in Türkiye must comply with Turkish Personal Data Protection Law No. 6698, commonly known as the KVKK. This applies not only to companies established in Türkiye, but may also affect foreign businesses that process the personal data of employees, customers, users or business partners in connection with their Turkish operations.
HARVEY ARASAN has prepared the Personal Data Protection Guide (KVKK): Practical Information and Best Practices to provide businesses with a clear and practical introduction to the Turkish data protection framework.
The guide is available in English and can be downloaded free of charge.

Download the Personal Data Protection Guide
What Does the Guide Cover?
The guide explains the principal concepts and obligations arising under the KVKK, supported by practical examples and selected decisions of the Turkish Personal Data Protection Board.
The main topics include:
- Fundamental principles applicable to the processing of personal data
- Legal grounds for processing personal data
- Processing of special categories of personal data
- Requirements for valid explicit consent
- The distinction between data controllers and data processors
- The obligation to inform data subjects
- Registration with the Data Controllers’ Registry, known as VERBIS
- Technical and organisational measures for data security
- International transfers of personal data
- Adequacy decisions, appropriate safeguards and exceptional transfers
- Standard contracts and binding corporate rules
- Rights of data subjects
- Complaints, legal remedies and compensation claims
Who Is This Guide For?
The guide has been prepared for:
- Foreign companies operating or planning to operate in Türkiye
- International groups with employees, customers or service providers in Türkiye
- Legal, compliance and data protection teams
- SaaS providers and technology companies
- Human resources and information technology teams
- Companies using international cloud and hosting services
- Data controllers and processors subject to the KVKK
- Investors carrying out legal due diligence on Turkish companies
It is also intended as a practical reference for managers who need to understand how Turkish data protection requirements affect their company’s day-to-day activities.
Is the KVKK the Same as the GDPR?
The KVKK and the EU General Data Protection Regulation share a number of fundamental concepts, including lawfulness, transparency, purpose limitation, data minimisation and the protection of data subject rights.
However, compliance with the GDPR does not automatically establish compliance with Turkish law. The KVKK has its own legal grounds, regulatory procedures, registration requirements and international transfer mechanisms.
International companies should therefore assess their Turkish processing activities separately rather than relying solely on existing GDPR documentation.
International Transfers under Turkish Data Protection Law
International data transfers are particularly relevant for companies using:
- Cloud infrastructure located outside Türkiye
- International human resources or CRM platforms
- Foreign group-company systems
- Customer support teams based abroad
- International technology and maintenance providers
- SaaS products involving overseas hosting or access
- External processors and sub-processors located in other countries
A transfer may occur not only where personal data is stored abroad, but also where it is made accessible to a recipient located outside Türkiye.
The guide explains the principal transfer mechanisms available under the revised Turkish framework, including:
- Adequacy decisions
- Standard contracts
- Binding corporate rules
- Written undertakings approved by the Turkish Personal Data Protection Board
- Exceptional transfers that are occasional and meet the statutory conditions
Before selecting a transfer mechanism, companies should identify their data flows and determine whether each party acts as a data controller or data processor.
Why Is a Practical Compliance Framework Important?
Data protection compliance should reflect how the company actually collects, uses, stores, shares and deletes personal data.
Preparing privacy notices and policies without first identifying the underlying processing activities may result in inconsistencies between the company’s documentation and its operations.
An effective compliance framework should therefore address:
- The company’s data processing activities and legal grounds
- Internal responsibility and access management
- Relationships with processors and service providers
- Retention and deletion procedures
- International data transfers
- Data subject requests
- Data breach response
- Employee awareness and training
- New products, technologies and processing activities
The guide provides an introduction to these requirements and highlights practical issues that companies should consider when reviewing their data protection structure.
Download the Guide
You can access the complete English-language guide below.
Download “Personal Data Protection Guide (KVKK): Practical Information and Best Practices”
The guide is provided for general informational purposes and does not constitute legal advice in relation to any specific processing activity or business.
Legal Advice on Turkish Data Protection Law
HARVEY ARASAN advises Turkish and international companies on:
- KVKK compliance projects
- Personal data processing inventories
- Privacy notices and internal policies
- Data processing agreements
- Controller and processor assessments
- International data transfers
- SaaS, technology and artificial intelligence products
- Data subject requests
- Data breach response
- Turkish Data Protection Board investigations
- Data protection training and ongoing compliance support
For further information, please visit our Turkish Data Protection Law and GDPR Advisory page or contact our team.



