Data protection compliance in Türkiye requires more than a set of privacy notices and internal policies. Companies must understand what personal data they process, why they process it, where it is stored, who can access it and whether it is transferred outside Türkiye.
HARVEY ARASAN advises Turkish and international companies on compliance with Turkish Personal Data Protection Law No. 6698, commonly known as the KVKK. We also advise on the EU General Data Protection Regulation (GDPR) where it applies to a company’s activities.
Our objective is to establish a data protection framework that reflects the company’s actual operations. We prepare clear documentation, allocate internal responsibilities and work with legal, technology, human resources and operational teams to ensure that the framework can be implemented in practice.
KVKK Compliance Projects
We begin a KVKK compliance project by identifying the company’s personal data processing activities and data flows. We review the organisation, business model, workforce, technology infrastructure, service providers and international operations before determining the applicable requirements.
Our compliance projects may include:
- Mapping personal data processing activities and data flows
- Identifying data controllers, processors and sub-processors
- Determining data categories, data subject groups and processing purposes
- Establishing the appropriate legal basis for each processing activity
- Preparing or updating the personal data processing inventory
- Assessing the obligation to register with the Data Controllers’ Registry, known as VERBIS
- Determining retention periods and disposal procedures
- Reviewing domestic and international data transfers
- Identifying deficiencies in contracts, policies and operational practices
- Preparing a company-specific compliance action plan
A personal data processing inventory should not be treated solely as a regulatory formality. A properly structured inventory allows the company to understand and manage its processing activities even when employees, service providers and internal systems change.
Privacy Notices, Policies and Internal Documentation
Data protection documentation must accurately reflect the company’s actual processing activities. Generic templates or documents copied from another organisation may not address the company’s data flows, technologies or legal obligations.
Depending on the company’s activities, we prepare and review:
- Employee and candidate privacy notices
- Customer, user and supplier privacy notices
- Explicit consent forms
- Website and mobile application privacy policies
- Cookie policies and consent mechanisms
- Personal data retention and disposal policies
- Data protection and security procedures
- Data subject request procedures
- Data breach response plans
- Employee confidentiality undertakings
- Access management and authorisation procedures
- Policies concerning CCTV, electronic communications and company devices
We focus on consistency between the documents and the company’s actual practices. We also use clear language so that the relevant employees and business teams can understand and apply the procedures.
Controller, Processor and Vendor Agreements
Cloud services, human resources platforms, CRM systems, call centres, consultants and other external service providers may create multiple personal data processing and transfer relationships.
The roles of the parties must be determined by reference to their actual activities and decision-making powers. Merely describing a party as a controller or processor in a contract does not necessarily determine its legal status.
Our services in this area include:
- Drafting and reviewing data processing agreements
- Determining controller, processor and sub-processor roles
- Preparing provisions governing the appointment of sub-processors
- Reviewing security, audit, notification and liability provisions
- Aligning data protection provisions with the underlying commercial agreement
- Preparing intra-group data transfer arrangements
- Reviewing vendor and technology procurement contracts from a data protection perspective
We assess the data processing terms together with the scope of the service, contractual liability, indemnities, technical infrastructure and use of subcontractors.
Further information is available in our article on Data Processing Agreements under Turkish Data Protection Law.
International Transfers of Personal Data
The use of international cloud providers, data hosting outside Türkiye or remote access by teams located abroad may constitute an international transfer of personal data under Turkish law.
We first identify where the data is stored, the countries from which it can be accessed and the legal roles of the parties involved. We then determine which international transfer mechanism may be used.
Our services include:
- Preparing data transfer maps
- Identifying the data exporter and data recipient
- Determining whether each party acts as a controller or processor
- Assessing the available appropriate safeguard mechanisms
- Preparing the applicable KVKK standard contract and its annexes
- Managing the required notification process before the Turkish Data Protection Authority
- Reviewing sub-processors and onward transfers
- Assessing whether binding corporate rules may be appropriate
- Preparing intra-group data transfer agreements
- Coordinating the Turkish transfer structure with GDPR transfer requirements
The location of the server is not the only relevant factor. Access from another country for maintenance, customer support, troubleshooting or other operational purposes must also be considered.
Data Protection for SaaS, Technology and AI Products
Technology companies frequently process personal data through cloud infrastructure, distributed teams, APIs, artificial intelligence tools and third-party service providers. These structures require both legal and technical data flows to be understood.
We advise SaaS providers, technology companies and digital platforms on:
- Mapping the processing activities carried out through the product
- Determining controller, processor and sub-processor roles
- Drafting customer-facing data processing agreements
- Preparing sub-processor lists and change notification procedures
- Reviewing international hosting, maintenance and support access
- Drafting privacy policies, cookie policies and user-facing notices
- Applying privacy by design principles during product development
- Assessing the use of personal data in AI systems, training datasets and user inputs
- Structuring data retention, deletion and export procedures
- Reviewing end-user terms and customer contracts for data protection consistency
For a foreign technology company entering the Turkish market, translating existing GDPR documentation into Turkish is rarely sufficient. The product’s processing structure must be assessed separately, and the documents must address requirements specific to the KVKK.
Our article on the responsibilities of data processors towards their customers provides further information on processor obligations under Turkish law.
GDPR and Multi-Jurisdictional Compliance
The GDPR may apply to a Turkish company because of its establishment, customers, users, employees or monitoring activities in the European Economic Area. International groups may also need to coordinate their Turkish compliance programme with their wider GDPR framework.
Where relevant, we advise on:
- Assessing whether the GDPR applies to particular activities
- Coordinating KVKK and GDPR documentation
- Identifying inconsistencies between Turkish and European processing structures
- Reviewing controller and processor arrangements
- Assessing international data transfers under both regimes
- Preparing group-level privacy documentation
- Coordinating with foreign counsel and data protection teams
- Adapting international policies to Turkish operations
We do not treat the KVKK as a Turkish translation of the GDPR. Although the two regimes share important concepts, their statutory requirements, regulatory procedures and international transfer mechanisms must be assessed separately.
Managing Data Subject Requests
Companies must respond to requests from employees, customers, users and other data subjects within the applicable statutory periods.
We assist companies with:
- Establishing data subject request procedures
- Assessing access, correction, deletion and objection requests
- Collecting the required information from internal departments
- Preparing legally compliant responses
- Coordinating the implementation of deletion or correction requests
- Assessing the risk of a subsequent complaint to the Turkish Data Protection Board
A clear internal procedure helps ensure that requests are directed to the correct teams and handled consistently.
Data Breach Response
Unauthorised access, disclosure to an incorrect recipient, loss of a device, cyberattacks or a vulnerability affecting a service provider may result in a personal data breach.
When a potential breach occurs, we assist with:
- Determining whether the incident constitutes a personal data breach
- Identifying the affected data and categories of data subjects
- Coordinating the legal, technology and information security teams
- Preparing notifications to the Turkish Data Protection Board
- Preparing communications to affected data subjects
- Reviewing contractual obligations towards customers and service providers
- Assessing liability under data processing and commercial agreements
- Determining the legal and organisational measures required following the incident
Preparing a response plan and allocating responsibilities before an incident occurs allows the company to act more quickly and consistently.
Training and Ongoing Data Protection Advice
Data protection compliance is an ongoing process. A company’s data processing structure changes as it introduces new products, hires employees, appoints service providers or adopts new technologies.
We provide:
- Employee awareness training
- Training for management and legal teams
- Tailored workshops for human resources, sales, marketing and technology teams
- Data protection assessments for new products and projects
- Updates on legislative and regulatory developments
- Ongoing advice on operational data protection questions
- Periodic reviews of existing documentation and practices
We tailor training sessions to the company’s actual activities. This helps employees understand how data protection requirements affect their daily responsibilities.
Investigations and Data Protection Disputes
We represent companies in investigations conducted by the Turkish Data Protection Board and in disputes arising from the processing of personal data.
Our services include:
- Reviewing requests for information and documents from the Authority
- Preparing written explanations and legal defences
- Managing proceedings arising from data subject complaints
- Assessing Board decisions and administrative sanctions
- Challenging administrative fines through the applicable legal procedures
- Handling claims for pecuniary and non-pecuniary damages
- Representing companies in disputes involving employees, customers and service providers
Our assessment considers the company’s documentation, technical records, contracts and actual practices. This is particularly important where the written policies and operational processes do not fully correspond.
Our Approach
Our first step is to understand the company’s business model and processing activities. We build the compliance framework around the company’s departments, systems, products and service-provider relationships.
Our work focuses on:
- Ensuring consistency between legal documents and operational practices
- Making internal responsibilities clear
- Preparing documentation that employees can understand and use
- Coordinating legal, technology and information security teams
- Identifying risks before launching new products or services
- Keeping the compliance framework capable of being updated as the business changes
When Should a Company Seek Data Protection Advice?
A legal review is particularly advisable where:
- The company is carrying out its first comprehensive KVKK compliance project
- Existing documentation has not been updated for a significant period
- A new software product, mobile application or SaaS service will be launched
- International hosting or service providers will be used
- A foreign company is entering the Turkish market
- Artificial intelligence systems or new data analysis tools will be introduced
- The company is preparing for an investment or M&A transaction
- A data breach or data subject complaint has occurred
- The company has received a request from the Turkish Data Protection Authority
To discuss your company’s data processing structure and the appropriate scope of legal support, please contact our team.
Read Our Personal Data Protection Guide.
Turkish Data Protection Law (KVKK): A Practical Guide for Businesses
Companies operating in Türkiye must comply with Turkish Personal Data Protection Law No. 6698, commonly known as the KVKK. This…
Public Event Footage and Privacy: A Look from Turkey
In the summer of 2025, data protection became a hot topic at public events. Concerts, festivals, and sports games sparked…
Turkish Constitutional Court Confirms Right to Protection of Personal Data and Imposes Positive Obligations on the State
In a recent ruling, Turkey’s Constitutional Court clarified the scope of constitutional protection for personal data. On 20 March 2025,…
New Cybersecurity Management Obligations and Liabilities under NIS2 Directive
The Directive (EU) 2022/2555 on measures for a common level of cybersecurity across the Union (the “NIS2 Directive”) was published…
Artificial Intelligence-Based Services and Security of Company Data
While we talk about the many benefits of AI technology, we should not ignore the data protection and privacy concerns…
New Adequacy Decision for EU-US Data Privacy Framework
The European Commission has adopted an adequacy decision for the European Union – United States (EU-US Data Privacy Framework (DPF).…
Amazon Turkey Decision and its implications on data transfers to third countries
The Turkish Personal Data Protection Board (“Board”) adopted a decision regarding Amazon Turkey at the beginning of this year, on…
Your responsibilities to your customers as a data processor
The Turkish Data Protection Law defines a data controller as “the natural or legal person who determines the purposes and…
Data Processing Agreement (DPA) Under Turkish Data Protection Law
Data controllers who wish to entrust their data processing activity to a third party must appoint such third party as…












